We’re asking Apple to change the advertising ID for each iPhone every month
blog.mozilla.org
blog.mozilla.org
This is not on iPhone but on a MBP so it's still quite relevant to Apple. I had disabled the "apsd" process, which serves as Apple's push notifications service, completely blocked it off using Little Snitch, and yet the process still found its own way to reactivate itself and keeping a persistent connection back to Apple servers in the background. I personally don't use FaceTime or Notifications on MBP, why couldn't Apple just let me disable this, and instead the process even circumvented around my firewall protection to make sure it could communicate back to their data center? This practice is a little shady and does not promote trust or transparency. If I have blocked a process permanently then I expect it to remain always blocked.
Their EmbeddedOS on the Touch Bar also keeps a couple always-on connections that utilize its own bridged network interface which users are completely blocked off and do not have access to. They were supposedly for TouchID, but I was viewing bandwidth usage the other day and these connections used up to almost 10MB of data. Why would something like TouchID need to send 10MB of data back to Apple? Again, this makes no sense and does not promote trust.
Apple Push Notification service (APNs) is the centerpiece of the remote notifications feature. It is a robust, secure, and highly efficient service for app developers to propagate information to iOS (and, indirectly, watchOS), tvOS, and macOS devices.
You may not be using FaceTime or Notifications, but someone you know will be using them.
Maybe that's not what [netwanderer3] want though. Maybe [netwanderer3] just want to use [netwanderer3] computer without a constant connection to all of [netwanderer3] other devices and servers
English has some plural and possessive agreement rules that make this sound like faux caveman speak, let's fix those:
Maybe that's not what [netwanderer3] wants though. Maybe [netwanderer3] just wants to use [netwanderer3]'s computer without a constant connection to all of [netwanderer3]'s other devices and servers
They weren't referring to their phone, but being able to, quite reasonably, have control over what their MacBook is making outbound connections to.
> there's even corded dumb phones one could use.
That's a somewhat facetious and unnecessary remark. And you know, not everyone has a POTS landline these days.
non-issue? simply block out the ports? https://support.apple.com/en-gb/HT203609
i dispute the assumption that people don't have control over their computers. there are literally millions of things anyone of us can do about every aspect of their computer.
> That's a somewhat facetious and unnecessary remark.
You're right and I apologise.
From the top-level comment:
> the process even circumvented around my firewall protection to make sure it could communicate back to their data center
It seems like either this doesn't work or the firewall was configured incorrectly. Obviously we have know way of knowing for sure what happened in this case, but have you verified yourself that blocking the ports actually works for this?
Edit: Actually, launchctl apparently does use a separate preference these days; it used to modify the plist. Not sure when that changed or when you tried this.
If this was implemented, it wouldn't be very difficult to associate a cycled out profile with a new one. Only days of behavioral information. So if out of a 30 day month, 3 days are used to re-associate user profiles, they're only using a partial profile 10% of the time?
I don't even get why Moz thinks IDFAs are particularly bad for privacy anyways. They're only shared across apps that come from the same developer; your Facebook and Snapchat apps see different tokens. They don't expose any personal information, they only identify a unique piece of hardware. It wouldn't be particularly difficult for apps themselves to generate and persist their own random token; how often do people reinstall apps anyways?
It's even worse than that. The IDFA might reset every month, but there's nothing preventing apps from storing a persistent identifier in its data. As soon as there's a new IDFA, the ad network can immediately link that back to the old IDFA. As long as you have one app that belongs to the ad network, you can be linked back. You can even combine this with keychain data to persist across reinstalls (technically you're not supposed to use the keychain for this purpose, but storing the currently logged in user's credentials is fine, so you can use that instead).
Can't link the PDF since it's behind a login wall, but the developer agreement already prohibits this (3.3.12):
> If a user resets the Advertising Identifier, then You agree not to combine, correlate, link or otherwise associate, either directly or indirectly, the prior Advertising Identifier and any derived information with the reset Advertising Identifier.
I believe in technical measures over pinky-swears in cases like this.
That said, this is engineering-oriented security thinking in a behavioral playing field. People's habits don't change very rapidly, and I'd expect that (with the exception of life-changing events) a month's worth of data would tell you 95% of what a (device) lifetime of data would.
Apple was aware of the privacy challenges of this, and laid out the rules for using IDFA in this WWDC 2014 presentation. https://developer.apple.com/videos/play/wwdc2014/715/
It's a video with no transcript, but if you click the link to the slides, you can see on slide 7 that the lifetime of the Advertising ID is "Reset Advertising ID."
Each time you submit an app binary to Apple for review, you have to click a box that solemnly swears that you're using the IDFA to attribute activity to an advertisement, proving that the advertisement did its job. "I, USER NAME, confirm…"
I don't know whether the solemn vows really do anything; I get the impression that IDFA abuse is detected via privacy researchers making noise in the tech press. But it has been enforced a few times.
While Apple only started posting transcripts of WWDC presentations last year, https://asciiwwdc.com has been around for a while and is a great searchable archive of WWDC transcripts. Here's the transcript for the presentation you referenced: https://asciiwwdc.com/2014/sessions/715?q=user%20privacy%20i....
I would love to run my own Pocket server ...
2 years and counting.
Oh I'd love to run my own Pocket server. The service seems useful but I stopped using chrome and disabled most of the utilities I reasonably could to avoid centralizing my data again.
A self-hosted Pocket could help some of that.
Search for pocket. You'll see extensions.pocket.enabled
Double click to set it to false. That's all.
Serious question - would you object as much if it was called “Firefox save page”? Because I’ve never heard HN complain about Firefox sync, which has all your passwords, your history etc.
Their description: wallabag - a self hostable application for saving web pages
No idea on how good it is or how it compares to pocket but it seems to be what you're after. And you can import your data from pocket.
Counterpoint: if a data collector stores the ad id or derivative of it with anonymous activity then later links it to a user account with PII that could break a lot of basic assumptions the user may have about their privacy. That would be difficult to prevent from happening with a technical solution.
(Edit: Apparently I was wrong - I’d swear it was per device? Hence the single global “reset the id “ option. If it’s per app/app group/developer ID then rolling doesn’t help because they can always just generate and store their own ID)
So I am irked I didn’t research before editing :-/
The APIs for this are very clear:
var advertisingIdentifier: UUID { get }
"Unlike the identifierForVendor property of the UIDevice, the same value is returned to all vendors. This identifier may change—for example, if the user erases the device—so you should not cache it."
The problem is periodic rolling of the ID doesn’t get you anything as any tracking service is simply going to track when the value changes in all the apps, and so all different IDFA tokens can always be tied to a single individual. Rolling, automatic or not, and irrespective of frequency gains you nothing. Tracking companies have repeatedly demonstrated a complete disregard for user privacy.
The /only/ way to fix this is to remove device centric ids from the platform. Then tracking frameworks can’t tied one user to multiple different app installs.
None of this “automatic rolling” nonsense - the API should not be there at all.
I think the biggest factor will be if they can convince the US population (their core demographic / market) that privacy matters. If it does, then it will be worth it to their bottom line - if not, they may have to capitulate to market forces and return to squeezing as much data as they can from their users.
The next few years could be very interesting from a privacy standpoint.
So... what exactly did we lose with buying an iPhone in the context of this conversation? The ability to change the launcher?
Because their message isn’t “we offer privacy to everyone in the world” but “we offer privacy to our customers”.
I'd say Apple's got this one figured out.
[1] https://www.forbes.com/sites/chuckjones/2018/03/02/apple-con...
I think the real reason why might be something along the lines of anti SPAM or botting; iMessage seems to require an authentic, unleaked serial number to connect, as I found out a while ago when connecting my Hackintosh. (I succeeded but I have a feeling many real Mac serial numbers get banned from iCloud by Hackintosh users sniping them out of pictures in eBay listings and whatnot.
Not suggesting there hasn't been more security issues with Android overall, but there's also more devices and more available source code with Android, and iOS is far from having a clean track record for exploits either. If it did, you wouldn't be so limited in which versions of iOS you could restore in iTunes...
Google, or whatever ad tech, gets data from an app which sends an email or oauth data to the IDFA. The email or oauth data stays the same even if the ad uuid changes month to month. Over many many apps.
I personally would actually rather have Apple control this and start competing with FB as a mobile ad network. I think they could present a solution which fits with their privacy appeal while also cleaning up fraud and dictating better ads formats / rules
I would like to think that space isn't totally won yet.
If we're gatekeeping who is allowed to criticize Apple, perhaps it would be enlightening to give some examples of people or entities who attain a high enough level of moral purity to do so. If an organization like Mozilla fails to reach it, I just want to get a sense of where the bar is set.
Telemetry that's not on by default would certainly be one measure, I don't know about apple but mozilla certainly fails. If they don't understand the need to gain consent before collecting statistics on their users then they don't understand privacy.
What I find curious about many comments in this thread is that few want to address the issue itself, but instead would rather either shoot the messenger or argue that even raising the issue is unacceptable.
Why are people so opposed to discussing this and why is Mozilla's record or reputation even relevant here?
As for the actual criticism I'd agree with the blog, the fact that phones come with an advertiser ID at all is a sad sign of the state of our industry.
- Should Apple do it? Yes. No downsides are apparent.
- Will it help many users? Yes. Many users will benefit.
- Is it a panacea? No. Rulebreaking apps will rulebreak.
Thus the career detractors are forced to invoke unrelated topics to continue their press conferencing.
If Mozilla speaks out against Apple while staying silent against Google it gives the appearance that they are at best not willing to bite the hand that feeds them. But at worst may raise concern that they are barking at the behest of their master.
That would be one possibility
a.) generate a uuid that is stored in the keychain upon first launch
b.) send the users iphone name to thier tracking servers
c.) other uniquing information such as screen size, device make, os version etc
so you can bet that idfa doesnt matter one iota and is totally besides the point...
https://developer.apple.com/documentation/adsupport/asidenti...
A sane default would be nice but there's a lot of other information that can be used to fingerprint a user from their device, device names and carrier names along with a bunch of other device settings are accessible without asking for permission. Unfortunately there's no current way to limit these.
geo.enabled ,false,disable asking to share location
extensions.pocket.enabled,false,disable pocket