iPhone Apps Surreptitiously Communicated with Unknown Servers
schneier.com
schneier.com
Even in our connected world, there is no reason to provide blanket network access to every app on the device.
You'd be surprised that some of the most popular OEMs (Xiaomi, and the Oppo trifecta) have removed the ability to restrict specific apps from using data. Some OEMs do remove certain security and privacy oriented user settings like Private DNS, for instance.
If you can root a device, you're good to go. There's no such escape with Apple, for both the developers (a good thing given Apple's privacy charm offensive) and the users.
If you can root the device, bad actors can root the device, and all the nice security/isolation guarantees made by the OS are moot.
I don't see laptops sold without root due to security implications. Why the distinction for handheld devices? That said, I do get there's a lot of malware on laptops, and a malware being able to assume root is game over. So, I kind of get your point too (not necessarily agree with it).
Sure, open settings, scroll to the app you’re interested in, click it to access its individual settings (location, notifications, background refresh, etc), click “Wireless Data”, then select “Off”.
Also, it's a bit strange to me that we didn't/don't seem to have this explosion of data leakage for desktop apps despite them having unique ids just like on mobile (idfa/google ad id).
cloud firewalls are their own brand of yikes, unless you run them yourself
Network Traffic Encryption
Protect all passwords, communications, and other sensitive
network data with AES-256 encryption, mitigating any
attempts to monitor your electronic activity.> The Guardian Firewall app has been designed to simply act as a client for remotely hosted VPN servers running custom fully-featured firewall software...
(From https://guardianapp.com/blog/2019/06/introducing-guardian-fi...)
I wondered at first why the VPN was free but you had to pay for the firewall.
To be clear, Apple isn't purging apps that protect kids in favor of its own apps.
Its my understanding that Apple is purging apps that take over the phone entirely (including the ability to remotely control the camera and microphone) by misusing enterprise certificates. There are plenty of kid protection apps out there that play by the rules and will continue to work.
https://www.macrumors.com/2019/05/31/apple-to-limit-third-pa...
This was previously discussed here https://news.ycombinator.com/item?id=20108096
There's a privacy reason to do it but also a business reason. Apple shouldn't have apps on their platform with dependencies to major competitors like Google and Facebook. And it's probably going to be ruled illegal anyway after the GDPR cases get litigated, so it's better to get ahead of it.
The pricing for the firewall capability also seems to be on the higher side:
"The cost is $9.99/month (or $99.99 per year) for VPN + Firewall capabilities. VPN-only service will be available at no cost." [1]
[1]: https://guardianapp.com/blog/2019/06/introducing-guardian-fi...
There might be commercial products that do this for you. Setting this up is definitely outside of the comfort zone for the overwhelming majority of phone users.
https://discourse-cdn.pi-hole.net/uploads/default/original/2...
https://discourse.pi-hole.net/uploads/default/original/2X/5/...
of course they're sometimes violating their privacy policy -- no real history of punishment / legal consequences here except (1) at the highest size scale (FB / G), and even they get away with minor fines in the US. And (2) sometimes terms get read by courts in other matters, i.e. zappos.
Plus product probably doesn't know the policy at some small companies; lawyers don't get involved enough.
the solution here is much stronger OS-level permissions models that can track the provenance of sensitive information. very big difference between my location getting uploaded as part of a 'search nearby' (i.e. a click) vs in the background. sensitive information should audit every read and should be required to dump communication messages to an audit DB visible to the user.
this is an area where open source can lead because it's easier for us to both run a policy checker / privacy linter and prove that it's running.
There are some. For example, Marcel Bokhorst developed the following applications: NetGuard, XPrivacyLua, and FairEmail [1]
I'm sure the development experience is less extreme on android but smartphone development is nothing like the experience on the PC where dev tools (visual basic/TCL/python/bash even gcc) are very lightweight and easy to work with. On the iphone you actually have to send apple money and sometimes even fax them a copy of your drivers license.
Yes, you can have "open source smartphone apps" (although it's much closer to source available since the users really have no way to modify it) but you absolutely can't have community maintained software (again, on the iphone. You can on android in theory but the tooling really doesn't seem built for sharing with other people.)
This is not to absolve the company that incorporated the SDK of responsibility; but it's also worth noting that in a lot of cases they're probably not doing it deliberately, aren't benefiting directly, and may not even know that it's happening. We, as iOS developers selling an app to our users, absolutely should know, but don't always.
This is something that I think engineers should be pushing back on the business side whenever we can. These leaks that we open up aren't worth the gain. I would love it if Apple came up with a way to expand their extension model and let us easily sequester third-party code. We'll see if something like that develops.
My UniFi dashboard always shows spikes around 3-5am. I figured it was mostly iCloud backups.
Unless I am downloading something while I sleep, I disable the interfaces on computers while I am asleep. If I control the gateway that the mobile phone uses, then I can disable the interface on the gateway.
Not really keen on mobile phones because despite the deep cascades of settings I do not feel I am really in control of them. Prefer computers where can easily compile and install own choice of UNIX-like OS.
My guess is that it's because that's what the article is about. Specific, named apps (for example "DoorDash"), running on an iPhone, and sending specific, named data ("device name, model, ad identifier and memory size") to other companies servers. So it's a very accurate title.
It's bizarre to complain about this with whatabout statements. It's like reading an article about soldiers from a given country killing civilians and saying that we already knew this, and that soldiers from other countries do it too. So what? This story is about this specific instance of it.
And even your "whatabout" complaint seems disingenuous. This is more like reading an article that says that the US government is killing innocent civilians and then someone pointing out that the civilians were actually killed by an individual that worked for a contracting company that the US government hired. You can't, in good faith, make the connection that the actions of an individual somehow equate to the actions of the whole organization just because there was some tangential relationship.
Apple doesn't do this. Full stop. Specific apps do it and they do it regardless of the platform. This has nothing to do with Apple and the article, source and re-post, are simply dragging Apple into it for clickbait headlines.
The headline doesn't mention Apple at all. It's about iPhone apps. Your desire to defend Apple ("...the only company...actions of an individual....Apple doesn't so this"). is causing you to lose sight of the point of this story. The story is about iPhone apps communicating with unknown servers. You're welcome to write your own story about how good Apple is at stopping iPhone apps communicating with unknown servers, but that isn't what this story is about.
It's taking something that Apple said out of context and applying their actions to it as if they're somehow being duplicitous.
Articles like this put apple's claims in context: even if the OS is nicer to you, it's hard to tame the apps.
They could blacklist the common tracking app's domains/IPs. It might be futile since I'm sure they'd jump IPs daily/hour/etc if they need to. Perhaps they have a better way to detect them during app approval. Either way, the point is that Apple is trying to combat tracking in safari but it seems like they've completely missed this attack surface and that might be why they're being targeted.
But you're still right that a better article would also investigate Android apps since they're surely doing the same thing.
"What happens on an iPhone stays on an iPhone" is a blatant lie.