Apple cracking down on applications that send location data to third-parties
9to5mac.com
9to5mac.com
As a consumer I'm happy they take those steps though. My privacy is worth money. Either somebody sells it and gives me a "free" OS or somebody sells me an OS and I don't "sell" my privacy.
It's always good to sell a "feature" you've always had which costs you nothing.
Apple is being hypocritical in this case. Giving in to the demands of government when it hurts their business ( if it did take privacy as seriously as HN makes it out to be, they would take a stand in China) while advocating privacy in Western world.
Apple are legally required to follow the law of countries they do business in. In China the law requires that the government, not third party apps, gains access to additional information. Apple can limit third party app privacy violations while still following the law.
The only stand Apple could take here is:
- Stop selling in China
- Have executives go to jail
Just as if they violated US law or EU-member's law.
Personally, I think it is totally cool to have location-dependent core beliefs. I just think it is a total fan-boism not to acknowledge it.
Apple could choose to honor principles and not sell in China. But market share is more important.
This is a similar argument we had a couple decades ago about companies doing business in South Africa, which at the time had official racial segregation policies (Apartheid). There was a popular push for divestment and it was fairly successful.
They're a corporation, their sole ethic is "to make money," full stop, that is the only reason Apple exists. To ignore China as a market would cost them millions if not billions of dollars.
Tons of businesses with very ethical practices operate in and with China. China's current anti-privacy stances are unfortunate, but if we refuse to do business with them, all we're doing is giving a leg-up to Chinese corporations who don't even pretend to care about user privacy in the form of an insulated market.
That's a reductive and inaccurate trope which also seems at odds with and unrelated to the rest of your comment.
Do you think if Apple could be privacy oriented in China, it wouldn't? It simply doesn't have the power to do it in China. Don't equate it to Google, FB and numerous others who despite having a chance to be privacy oriented in US, won't.
This is like Cantor's infinities. Sure they are all infinities. But they aren't the same.
Now, apple's desire to sell devices in china that comply with chinese laws (which potentially compromise user privacy) is a separate issue altogether. Business wise, I don't think they can afford to avoid china altogether. So maybe they can simply say that "they're doing the best they can" and take the PR hit.
That we live in an area of the world where you can choose to make the decisions they do without serious repercussions should make you pause and think about how important the checks we have are, because in China there aren't many ways to get around the problem above besides ignoring the largest developing market in the world.
If you honestly believed that to be true, how could you justify withdrawing from that market on ethical grounds?
Its hypocritical of Apple to suggest they truly care about privacy other than as a means to simply differentiate themselves to sell some more shiny objects - which might well be a common cutthroat business tactic.
Are you arguing that one must always impute manipulative motives to a corporation? (And should therefore not reward consequentially better behavior, because it must be based on invalid motives?)
Or is your point that Apple is uniquely hypocritical? If so, on what evidence about Apple in particular?
Sure, I would agree that if the outcome is good, then the intention is not relevant. Apple might have a positive effect in China despite compromising on privacy.
>Are you arguing that one must always impute manipulative motives to a corporation? (And should therefore not reward consequentially better behavior, because it must be based on invalid motives?)
I'm saying recognize the hypocrisy instead of constructing weird arguments to justify it.
>Or is your point that Apple is uniquely hypocritical? (And if so, on what evidence?
Certainly not. I said its a common business tactic.
People with different priors on whether Apple's managers (or managers in general, or managers of large corporations in general) are likely to be hypocrites, will probably have opposite judgements about which explanation is a “weird argument”. So I don't think framing it in these terms will resolve any disagreement, unless there's some non-circular criterion (maybe you have one and I haven't seen it or am not understanding it) for judging an argument “weird”.
Their purchases directly fund a regime opposed to their moral positions, either through taxes and duties or payments to the many thousands of firms (like COSCO) that are controlled wholly or in part by the Chinese government or military.
The hypocritical-ness doesn’t go away because corporations are larger than individuals, the transaction is in a different direction, or because the moral position is privately-held.
If you take Apple out of the argument for a second, thats quite a complex case. I think you can have two positions "we don't compromise on privacy" and "were trying to improve the situation the best way we know how". Under #2, you could make the argument that buying a general purpose tool such as a computer made in china, and using it to promote privacy is a net benefit, than not having the tool to promote your cause.
You will have to be extremely particular and thorough to get rid of all chibese products.
A foreign country has passed laws disagreeing with your value judgement. In any case, Apple is a business. As a consumer, I care first and foremost about my privacy and the privacy of those in my country. That is not impinged upon by China forcing Apple's hand in their own country. Perfect is the enemy of good.
How is that necessarily any better for humanity than simply obeying the local laws, going along to get along, while making it clear to your Chinese customers that their counterparts in more enlightened countries enjoy more privacy, more features, and an overall better experience?
I spoke with some people at a certain well-known company working on satellite Internet service a while back, and I asked them the same question. "What are you going to do when the Chinese try to shut you down for providing uncensored Internet service?" It was hard to argue with their response. They feel it is possible to make money and be a positive influence in various closed totalitarian societies including China. I think that's basically Apple's take on it as well.
Overt disobedience to the regime is rarely a good option for companies operating at global scale. It will get your employees declared criminals in large areas of the planet, and it can literally get your customers killed.
>Overt disobedience to the regime is rarely a good option for companies operating at global scale.
To be sure, it is never a good option. People have tried to sue the Chinese government, unsuccessfully so far. Nobody is denying that the chinese government has a horrible human rights record too.
>It will get your employees declared criminals in large areas of the planet, and it can literally get your customers killed.
Are we still talking about Apple in China? I don't know which customer was killed, or which employee was declared a criminal..
--
No, I switched contexts to the satellite Internet service developer I mentioned. They are on track to deploy a significant LEO constellation over the next few years. If they succeed, they will effectively be the Internet for a large chunk of the world. So if they don't make arrangements to accommodate various countries' censorship regulations, then citizens of places like China, Iran or North Korea who are caught with their receivers will be in a great deal of trouble, and the company's executives will not be able to travel to those regions without fearing arrest.
Following your logic, every single company in the US is either ethically aligned with US law or horrible, awful hypocrites. Apparently there are no other possibilities.
-
The fact they're standing up for user rights when given a legal possibility is a good sign, compared to most major companies which are harvesting anything and everything even going beyond the scope of what's legally permissible.
If China demanded that someone from your company sacrifice a new-born baby in order to do business there, I'm positive that we'd still have many, many western companies doing business in China.
And of course they never asked users for consent about this, except by putting something in the end of their 15000 word EULA.
https://www.theguardian.com/technology/2011/apr/20/iphone-tr...
I can imagine theories that include this omission as part of deniability for a cover-up, or from a combination of incompetence and malevolence, but such theories seem overly complicated compared to the assumption of a simple log leak like Twitter's recent password logging bug.
Whether these theories are too complicated depends on your priors about the evil intent of Apple's management and employees. If you already assume they're hypocrites about privacy, the location logging confirms it. I doubt it's convincing otherwise. (It's not convincing to me, unless there's a simpler story that ties it into ill intent, and that I'm just not coming up with.)
I did notice that it was being used a lot, and it seemed like I had much worse battery life when using certain apps.
If you want exact location, then you'll be running the GPS, which indeed uses more battery. But even so, it's not that bad. I record detailed GPS for my runs quite often with a fitness app, and it only uses 5-7% battery an hour. (Key is to make sure it's not also hitting a data connection to download maps, and that the screen is off.)
Don't forget the Windows 10 model: You're forced to buy the OEM version on any new PC, and then you still get your privacy sold by MS.
Apple is about apps being for the benefit of the user.
Linux desktops show a viable 3rd option, they are free, libre and protect your privacy (usually). The also provide the halfway point I want between the iOS model and the android model the provide a set of core well vetted apps from the store and allow me to install whatever else I want.
Librem or whoever makes a mobile equivalent the linux desktop can't come soon enough.
...or are the big players exempt from the rules of the game?
> When someone checks in to a place on Swarm, Foursquare's newer app, the company records the user's coordinates, helping it determine all the different coordinates associated with a single business or other place.
> Foursquare says it can't disclose who its partners are, or how many different smartphone users' data it has acquired. But Rosenblatt says the company could, for example, create a list of "millions" of smartphone owners who frequently visit fast food restaurants by taking a pool of location data collected by its partners and comparing that to its database of fast food restaurant coordinates.
> Advertisers could then use that data to show those users ads for fast food chains, or perhaps healthier alternatives or gym memberships—all without those people ever having to install a Foursquare app.
[1](https://www.wired.com/2016/01/foursquares-plan-to-use-your-d...)
Since the user is actively telling Foursquare/Swarm where they are, I don't think Apple would mind.
I wish third-party analytics would be next. A lot of apps are using analytics from companies who’s business model is inherently incompatible with privacy (Facebook & Google) and that concerns me.
The fact Apple added a framework to help with analytics (IIRC) may be the first step towards REQUIRING people to only use that framework instead of 3rd party stuff so they can be sure it’s compliant with laws/Apple’s policies as well.
As a matter of fact, I'm pretty sure part of Google Analytics response to GDPR is "Don't put PII in there if you want to be GDPR compliant" (they are providing tools for compliance though).
Let’s take YouTube for example - I never had an account with them, yet they recommend me videos based on what I watched previously - fair enough. The creepy part is, on a totally different machine, from a different IP and country, watching just a few very specific videos (not popular at all, each maybe 2k views) suddenly brings all those suggestions over.
You could argue videos watched is anonymous data, but clearly a certain, unique “series” of videos is apparently enough to identify me.
There’s also no doubt Google associates that with all the other “anonymous” data they have on me (search, maps & which browsers/IPs I used) and has an extremely detailed profile of me; sure, they don’t have my name nor exact address (yet), but they can definitely tell me apart from everyone else just based on a few searches and that’s quite creepy IMO.
The “other computer” doesn’t actually exist, it was a test in an AWS VM that was only used once to prove/disprove my theory, so no way for them to have associated that computer or IP to me in advance.
Not only that, Google says they will terminate any account that puts PII in Analytics.
However, an app that collects data at best is getting your location and stereotype.
Around iOS 9, Apple deprecated some of the Captive Portal APIs, then re-instated them, a lot of changes that went back and forth, but my conclusion is that today, years later, way too many apps seem to read my SSID. Doesn't really matter how they do it, but I wish there was a prompt for it and no way for an app to directly fetch it.
From the documentation, it's not clear to me if apps have permission to see either other nearby SSIDs or the names of other networks that the device has previously connected to.
If the app has access to either one of those, it's equivalent to being given location data.
Furthermore, last I checked, both iOS and Android broadcast the list of previously-connected SSIDs to nearby routers when connecting. That enables companies which track people's physical location over time without them having to download an app (yes, these companies exist[0]).
[0] e.g. http://axper.com/
However, to answer your question, on iOS there is no API for accessing nearby not-connected wifi, and on Android it exists but I believe it requires location permission.
It's how the standard currently works and what enables fast reconnection. IIRC, the device sends out all available SSIDs, at the router responds with the one(s) it's able to use to connect.
I agree that this is backwards, and I'd rather have slightly slower WiFi reconnection in exchange for better privacy. I don't know what the OS-level behavior is if you delete all previous networks. I assume it works, but I haven't tested it.
Oh, and for what it's worth, this isn't just for mobile devices. Your laptop probably does it too. In fact, OS X has an annoying habit of connecting to WiFi networks in the background even when the laptop is closed and asleep, which means it's doing this broadcasting behavior as long as the WiFi setting is turned on.
https://apple.stackexchange.com/questions/244171/ios-10-warn...
We noticed a few weeks ago that Apple has changed their static analysis tool and has been more aggressive with rejections. Has anyone else actually seen their app retroactively pulled from the App Store?
Telecom companies are also another risk, and much larger one in that, because there is no opt out of location sharing with them. Same with analytics on your telco network traffic.
Or is this really just a case of rejecting apps that are asking for location even though the app has no real use for it?
https://www.nytimes.com/2018/04/11/technology/facebook-priva...
https://www.bloomberg.com/news/articles/2018-05-07/even-priv...
https://www.wsj.com/articles/who-has-more-of-your-personal-d...
https://www.forbes.com/sites/kalevleetaru/2018/05/03/what-th...
I worry a bit that we will go too far with things. Some want the benefits of having the data to make user experience better.
I am a perfect example of this.
https://lifehacker.com/disconnect-pro-eliminates-tracking-on...
It costs a few $$, but sets up a VPN profile that is generally always on. It just blocks all of the ads / "web bugs" / analytics stuff and gives you a UI to show how much. Apple cracking down is a good thing, but so is defense in depth. It estimates that it has blocked 8Mb of crap being downloaded on my phone just today.
Thanks for the link, I'll consider buying.
One alternative is setting up a raspberry-pi at home running pi-hole and OpenVPN. While it is still not risk-free, it is still better than one centralized entity taking everyone's traffic. On the other hand, setting that up is still not absolutely straightforward, but it is getting better.
“Don’t like being tracked? Just let us watch EVERYTHING you do and we promise to stop people from tracking you.”
You’re putting someone in the perfect position to track you far better than anyone else could. You better REALLY trust them.
And let me be the first to recognize the app store model makes auditing the app extremely difficult.
https://en.wikipedia.org/wiki/AppArmor
https://en.wikipedia.org/wiki/Tomoyo_Linux
https://en.wikipedia.org/wiki/Smack_(software)
All three implement MAC (mandatory access control) similar to SELinux, but the context bits in SELinux are pretty much standalone for information assurance (DoD Rainbow book series has more info). Note my username comes from my SELinux experience :)
[1] https://web.archive.org/web/20150315021851/https://disconnec...