Apple reveals App Store takedown demands by governments
techcrunch.com
techcrunch.com
I always knew you can only install apps from the store on Apple devices and strongly disliked this (I already use some apps which even Google won't approve, e.g. an open-source YouTube downloader only available on GitHub) but once I've found out you can't get some apps (and books) in particular countries (e.g. a book I wanted was only available in the US store) and a government can ban something from the store I facepalmed.
That's one of the main reason why I don't use smartphones: I wouldn't be in control of my own device. With iOS, Apple is in control. With Android, apparently nobody is in control.
But on my Linux machines, I'm arguably in control. If I can find stuff somewhere, I can install it. And nobody else can, unless they root them. It happens, I know. But with LUKS FDE, even booting is arguably hard unless they could read the key from RAM.
So how come we got this smartphone crap, instead of actual portable computers that could, among other things, work as cellphones?
A thousand times this.
The state of the mobile universe right now is such that you have to either effectively trust Apple, or you have to effectively trust everyone. That's why HN User qwerty456127's choice to go to Android was fine, if he wants to be able to install his own apps, but it seriously compromised his privacy and security.
What if you do not want to trust anyone?
Nope. Sorry. No easy to use options for you out there.
>Nope. Sorry. No easy to use options for you out there.
Sure but to an extent that's true about almost everything in modern society. If you don't want to have to trust those supplying you with food or water, there's really no easy options to completely supply yourself with either of those. And even with all the oversight and regulation there's still often good reasons not to fully trust (we all know about Flint at this point even if it was a bit overblown by the media)
It's hard to imagine a situation where someone would supply you with something without you needing to trust them on some level.
That's very different from trusting only Apple. I mean, if you want to use Apple's equipment, you must also use their software. And perhaps we can trust their software. They also curate apps in their store, but sometimes they miss stuff.
Given Apple's position vs the FBI, it seems pretty clear that they won't intentionally pwn their customers. But it's clear from TFA that they do remove apps when governments demand.
Maybe that doesn't directly pwn users, but some of the apps that they've pulled could have protected users better than remaining alternatives. For example, I gather that it's impossible to build custom email or VPN apps in iOS. You can just build wrappers for Apple's stuff. For email, that apparently limits ability to securely encrypt messages.
Imagine a Free Software utopia with open hardware running an open source OSes and apps. Someone is writing that code. Someone is manufacturing that device. Someone is compiling and packaging that distribution for you. Someone is running the network.
Having access to the (alleged) source code for everything, and being able to compile it all yourself, would surely be worth something. But it'd be way too much code for you to audit alone. So you're going to have to trust Someone (security researchers, open source contributors) to be doing this for you...
But it's not always rational, and sometimes it is more like they're LARPing through some exciting narrative about the world, and in that narrative they're the heroes who know stuff that the normies don't. They're more like survivalists living an adventure in their head than rational people making rational choices. And that's where people can also get into trouble, both for having a false sense of confidence about their ability to avoid risk, and for giving others bad advice based on excessive confidence or rose-colored glasses about the same things.
I'm all for better security practices based on ever more openness, but I agree 100% with your example: people are kidding themselves if they think just because they run binaries built by other people from open source, it's almost as good as if they had personally inspected every line of code themselves. And when people are making those sorts of utopian statements, it's generally coming from the LARPing survivalist narrative part of the mind rather than the skeptical rational part of the mind and should be viewed with that much more skepticism. Not rejected, but just considered with an extra dollop of skepticism, because they hopefully at least mean well.
But here's the thing: It's always just a game. So sure, call it LARPing. However, consider that the US came out of LARPing.
However, you can distribute trust. With open-source software, you distribute trust across many developers, researchers and other users. It doesn't always work. But you're not stuck trusting just one entity.
Another example is Tor. You can't trust any one relay operator. But Tor does onion routing through three relays (guard, middle and exit) and so it's the design that you're trusting. Basically, the difficulty is identifying what relays you're using, and getting data from them. Plus the fact that the routing changes frequently (10 minutes by default) so adversaries would need data from many relays.
Even so, Tor's design can't resist traffic analysis by adversaries with access to global network data, and global attack networks. That was an explicit choice. Because resisting such adversaries would require stuff (random mixing and latency, padding to provide ~constant throughput, etc) that makes the network far less usable, and not scale well.
Because we are not the average smartphone user. The market for people that cares about this is tiny.
The only smartphone that will approach a sane philosophy seems to be the Librem 5.
How so?
If you show up at the border and the agent demands you install the software or your machine will be confiscated and you will be denied entry, then they are just as much in control as they are with android. At current all systems seem vulnerable to this attack that shares something in spirit with rubber hose cryptography.
Even Apple could be, but I suspect it is a case of it not being worth the effort since androids are the majority of phones.
Anyone paying attention knows that it's foolish to take sensitive devices and data across borders.
I was talking about what stuff I can install on my gear.
I think because they care about milking users, not about them being creative. I myself is very disappointed about what smartphone could've been for people and what it actually is.
You can also use FDE on Android devices. That won't stop the border police from forcing you to unlock your device or deny entry, though.
That's the fine print that kind of makes FDE a bad fit for mobile. (At least FDE as it's typically implemented.) I don't think it's any secret that Trust Zone has a larger attack surface than Secure Enclave, but cold boot attacks to extract data from RAM are stupidly pedestrian. At least make it hard for them.
Apple's self destruct is extremely poor UX for any user cursed with the misfortune of forgetfulness, but it's a lot more secure than Android's Trust Zone.
So my comment about iOS vs Android only applies once the phone is unlocked. And I wouldn't be comfortable with just the root passphrase protecting me.
My main complaint is Apple -- and so anyone who can pressure Apple -- controlling what I can install on the device.
But Apple can revoke certificates, and then your stuff is gone. Right?
I have been looking for such a thing for a long time. Sadly, there is no good solution. If you want a not-horrible one, get a samsung tablet with cellular capabilities and run linux on dex on it.
It uses the radio "Quectel EG-25G with worldwide bands". I wonder how well isolated that is from the OS.
Better or worse than the Librem 5 radio?
"The iPhones are plugged into a reader that scans them, while Android phones have the app installed to do the same job."
Yes, they cannot install an app, but that doesn't make your data secure from being taken.
At that point they could jailbraik or install MDM.
Or just dump all your browsing history, apps and email.
I think the OP is looking to be the Apple in his Apple-style mobile-verse.
Today Android phones have this malware on them and iOS phones do not, so the actual facts in the real world are that iOS is free of this intrusion.
That might change, but the situation now is what it is. This is why you are getting downvoted.
We just don't have a sample to reverse-engineer yet.
Edit: when I wrote this comment, my original comment was at -4 points.
That’s all.
I mean, if you wanted a hidden, non-standard launchd type app, you'd have to modify the filesystem, install it, they'd need to create special tooling to do so, and modify the updaters to preserve it across an iOS update, etc. All without anyone at Apple speaking out.
Apple refused to create an unlock tool for the US government that was a one-off, to create spyware for China seems like they last thing they'd do. Could they? I guess. Once detected - and it definitely would be (as this was), or leaked by employees - Apple would get bowled over by buyers and the stock market. It's just not in their interests. Their current business model is selling privacy.
https://news.ycombinator.com/newsguidelines.html
These biases are in the eye of the beholder. People with opposite feelings about Apple (or whatever the corp of the moment is) see exactly the opposite bias.
But as Google's data mining practices have become increasingly invasive I've also become a lot less enthusiastic about using Android phones. I suppose I should probably run one of the stripped down Android variants that removes all that tracking but I also need a reliable phone that doesn't require hours of fiddling.
Minor and major upgrades both happen in place so no need to ever reinstall. However, major version upgrades do require you to flash an image from the Lineage website.
However my issue with iOS is, that people don't have the freedom to choose whether or not they want to be protected by this "walled garden".
Currently, you cannot opt-out, and the side effect is that Apple limits our freedom to choose to, for example, set Firefox as the default browser. Or set startpage.com as the default search engine in Safari. etc. etc.
I don't understand how a single company is allowed to have so much power to decide/enforce upon us what we may and may not do with our devices. And since it's an oligopoly (Apple or Google), we don't have any other alternatives.
But that’s just me. What concerns me is the tribalism of people. “OMG! You use THAT phone/computer/OS?!?! I would NEVER use that!” Then go on to explain why their buying choices are better than yours. Look at the replies here, they’re rife with it.
We can have both: live inside the wall and have the freedom to do with our devices what we want;
For example, in macOS i can disable 'System Integrity Protection' (SIP), make whatever modifications i want to make, and then re-enable SIP. The same thing could be done with iOS.
The real issue is that Apple wants to have control over our devices for economic/financial reasons.
Logging bugs would trash the flash storage in months or weeks. Other bugs and “features” would drain the battery so aggressively that several phones caught on fire, some injuring customers. We found ways to hide our actual power usage and circumvent protections that would have prevented rapid battery discharge.
In a meeting, it was said, “Stupid Apple won’t let us run background processes.” To which I thought, “Thank God.”
It was Apple’s approval checks and policies that prevented this app maker from potentially physically damaging their customers’ phones with this terrible software. Physical injuries weren’t enough to fix the bugs or stop messing with low level settings. Nope.
There are some “choices” that shouldn’t be put upon consumers. There are some profoundly bad developers out there. Shouldn’t there be protections from app makers that intentionally hide their shady tweaks that disable power protection safety?
Apple’s approval process does indeed root out many of the worst offenders, like my former employer.
Was it FIX Health? Their flagship app, The Outbreak[1] is literally the worst app I've ever installed on my phone.
I had to install it as a part of a company health incentive so I could get my HSA bonus, but that app is seriously so bad. If I opened it on my Nexus 5X with 30% battery remaining, the OS would immediately start shutting down. Sometimes it froze my phone at full battery such that I couldn't use it or even reach the lock screen again until I did a hard reset.
[1] https://play.google.com/store/apps/details?id=com.FIX.TheOut...
Maybe, maybe not. But I for one like this walled garden because it prevents a lot of stupid people from doing really stupid things. From a computer, infosec security angle.
Or, you know, having multiple trust sources installed on your phone. I'd like to download apps by microsoft without having to beg google for permission. Manually adding new stores/etc should come with drawbacks / be unacceptable complicated for average users, of cause.
The thing about being able to install code without permission from a third party is that it's like herd immunity in vaccination - individuals or small groups doing it is not actually very useful in order to ward off harmful effects, it needs to be a widespread, mainstream possibility.
Repressive governments are perfectly fine with draconian restrictions and attacks on minorities using computing platforms if they can succeed in 80% of cases. That means they have a much smaller base to attack with targeted "enforcement". Only mass civil disobedience through installation of prohibit code actually works.
Many of the fundamental freedoms we cherish only exist because of mass permissionless code installation of the 90s to mid-2000.
I wish I could sit there and say you can use whatever you want, I really do. But I think your choices negatively impact me and the rest of society.
Mkay...
It’s like complaining that Toyota gives you the option of reliability but Nissan doesn’t. You pick from the options available.
Imagine you could only buy 2 type of cars...
This "anyone" is you as only you are responsible for the applications you install in your own devices.
People need to learn personal responsibility for the stuff they install instead of enabling OS vendors to control what everyone can do with their devices in the name of protecting them by themselves.
Yeah they do but from what I've seen in my life, we're centuries or millennia away from the average person being like that.
So the mobile OS vendors adapt to the average human. It's only natural.
The trade offs are far from simplistic
The security and privacy on an iPhone is greater and comes at a flexibility factor.
And it isn't a matter of flexibility, it is a matter of utility: others not being able to take your phone from you and install apps also means you not being able to do it either.
Apps on the other hand you are totally right about. This censorship exists with app stores only. But in practical terms, is there really a difference between side loading iOS apps or installing android apps from binary? If anything I would prefer the open source nature of side loading
Being common does not make it acceptable, and it is alright to criticize "neutral" actors like Apple that partake in this censoring, even if they are only following orders.
And also celebrate those who do, even if it is prohibited.
I assume it is allowed because it does not pose a security threat to the device, nor user, as opposed to allowing apps from outside the Apple Store.
Edit: You can try it with Peter Watts' Blindsight ;). EPub download link is in the header:
That's Apple who has made this possible. If it was doing no distinction between countries (e.g. Google seemingly has just one Play store globally) then it would be not a party to blame.
By the way the book I wanted was free and not on any sensitive subject. Some kind of science fiction. I've just stumbled upon a Twitter post saying there is a curious new scifi book available for free in Apple store, so I've taken my wife's iPad and tried to get it but it said it was only available in the US store (we live in Europe).
- Harry Potter and the Philosopher's Stone is not available for purchase in the US: https://play.google.com/store/books/details/J_K_Rowling_Harr...
- Harry Potter and the Sorcerer's Stone is not available for purchase in the UK: https://play.google.com/store/books/details/J_K_Rowling_Harr...
I'm currently in the UK, with a US-based Google account. If I'm logged in, I only see a "buy" button the second link. If I'm not, I only see a "buy" button on the first link... but Google doesn't allow me to complete the purchase, as it forces me to log in and then recognizes that it doesn't sell that ebook to Americans.
One should consider smartphones unsafe devices and not trust important data to them.
Even most computers aren't really safe devices. With a lot of effort you can minimize risks (e.g. using core/libreboot, full disc encryption, live OSes etc.) but you'll never find a way to absolute security and privacy.
The discussion if Android or iOS is safer doesn't really matter that much in my opinion. I choose iOS because of their constraints. The pseudo-freedom Android gave me wasn't enough or that useful that I'd consider using that system again so soon. Also I like the fact that I can use an iDevice for a longer period including new OS- and security- updates. (just my personal opinion without any recommendation)
I would actually love to hear what apps you guys love but can't get on iOS
This couldn't be further from the truth. At least take the time to understand how the various platforms function before spewing inaccurate statements about them.
You've been able to side load apps on iOS since the App Store existed. The App Store has never been the "only" way to install apps.
And that some of them want a phone that can run some application ( where android is a PDA that can make some phone call )
Or someone can get an enterprise account and allow you to install their apps.
Also... what exactly do you even want to run what is not possible on iOS?
For simply €99 a year for the privilege to run your own code on your own device.
- Benjamin Franklin
But some of them are, and it is essential for a healthy society that this is always possible for them and for anybody who needs to.
Apple literally dictates acceptable expressions of sexuality to people.
How the hell is that not giving up an essential liberty?
https://www.npr.org/2015/03/02/390245038/ben-franklins-famou...
Not open source, but "YouTube Downloader" (thread on XDA [1]) has worked well for me.
1: https://forum.xda-developers.com/showthread.php?t=2137743
Note that on iOS you can download videos from YouTube using youtube-dl (installed in Pythonista). With Pythonista's share sheet extension, it's quite convenient.
I was surprised that there were zero App Store takedown requests from governments in North America, South America, and Australia.
All of the takedown requests came from China, Vietnam, and Europe; including Norway and Switzerland.
[1] https://www.apple.com/legal/transparency/pdf/requests-2018-H...
[1] https://gigaom.com/2014/09/18/apples-warrant-canary-disappea...
I'd work out the Europe total, but that would only depress me further.
Why does Germany stick out compared to other countries in Europe - some Stazi hangover mentality! Who knows, but some serious questions need to be asked as clearly some major disparity amongst EU countries at play here. But I'm sure they will get their shrills to bury that question, hmmmm.
Germany 12,343 requests Europe, Middle East, India,Africa Total 18,205
The inner cynic in me asks - Maybe that was the template they used for such requests.
In scenarios like this, is "... primarily due to ..." good enough? I'm inclined to say no: They need to all be accounted for.
> Apple said it received 29,183 demands from governments — down almost 10 percent on the last reporting period — to access 213,737 devices in the second half of last year.
On a second thought, how much detail should Apple get in the first place. If police suspects me of some wrongdoing, I probably wouldn't want any third party like Apple to get details about the cases as well.
It doesn't. The Apple report is broad, and lists all government requests.
The headline writer chose to focus on App Store takedowns only.
United States of America 4,680 requests Germany 12,343 requests
> Apple also received 4,875 requests for account data, such as information stored in iCloud — up by 16 percent on the previous reporting period — affecting 22,503 accounts.
I wish they were more specific. What does "access" mean? Location? All local data? Even encrypted data?
What data from iCloud? Email addresses, or the full contents of Notes and Drive?
Maybe I'm being naive, but I assumed that when something says "Apple can't read X data" it means under all circumstances. But if they have a backdoor, client-side encryption probably doesn't matter.
"there are bad governments in the world, and mobile phones should allow people who want to oppose their own bad governments to install apps that will help them in their opposition?"
Honestly if our goal is to rid the world of truly bad governments then phone apps are in not in anyway the first or most effective method.
and who makes the judgement on what a "truly" bad gov't is?
I say if you own the hardware, you should be allowed to install any app you wish on it.
Apple can claim that this voids your warranty, but they (or any other actor (including the gov't)) cannot be allowed to _prevent_ you from doing it. .
3rd option is abuse of enterprise development certificate (which is intended for $BIGCOMPANY's own employees only)
Maybe common sense, human freedom index, etc.
Are you really arguing that as Westerners we cannot tell a bad government from a good one?
What distinction are you trying to make here? Many Western governments ( namely, the US and its closest allies) engage in warrantless wiretapping, unlawful search and seizure, imprisonment without due process, warfare without democratic authorization and even taxation and regulation without representation. None of these matters register on the radar of public concern. So can we, as Westerners tell the difference? Apparently not, but we sure are smug about our geographic orientation.
Unless you're a college kid or just came out of college and you've just been brainwashed by your Marxist professors, I have no idea how you can have a vision that is so far from reality.
> All or vast majority of requests relate to illegal gambling investigations.
I hope they mean court orders than just some investigation.
I think the american investigation term is more broad than in other places where investigation just refers to police investigation.
Imagine if Windows wouldn’t let you install software until you updated your Paypal with a valid credit card.
They may have removed that restriction entirely now.
https://thehill.com/opinion/immigration/445766-government-su...
Not that I'd recommend trying that luck :)
Do companies own their past names indefinitely?
I guess he doesn't know a lot then.
To me this basically reads like "a company released some government documents". Is this typical of TechCrunch?