Privacy: Is That iPhone?
foundation.mozilla.org
foundation.mozilla.org
This tracking is all possible because iOS gives every app on the device the same IDFA (advertising identifier [1]). They can then correlate all your activity and target you for ads.
I'd love if Apple just killed this feature, but barring that, why not change iOS so that it scopes these identifiers at the per-app level. Different apps on the same device see different IDFAs, but an app can still use an IDFA to target you for ads. Apple already has similar per-vendor scoping with identifierForVendor. [2]
[1]: https://developer.apple.com/documentation/adsupport/asidenti...
[2]: https://developer.apple.com/documentation/uikit/uidevice/162...
Somehow these platforms have no problem with identifying users across their client apps even without the IDFA. Maybe it's not 100% precise, but as far as I can tell these companies keep so much information about us away from our eyes, that even the big guys (G, FB) would be jealous.
Analytics is one big dark corner of the mobile business whose significance is not fully appreciated (yet).
Has anyone been using Cloudflare's Warp VPN? I wonder if this is the best approach. Paying a private company to act as a one hop TOR to minimize fingerprinting. If the cell networks just see all CF traffic, they may know where I am but not who I'm connecting too. I get that this means I must trust CF but I trust them more than ATT/Verizon anyway. I just want some open source from CF on the mobile side that shows that the private keys are kept in the device's SecureEnclave and not anywhere on disk.
Ooooh, think of the GDPR fines!
Sure, once they exist, there are secondary effects who are important in themselves.
Apple used to be quite strict that you had to actually have advertising in the app to ask for the IDFA permission. That seems to have disappeared.
https://developer.apple.com/documentation/uikit/uidevice/162...
The value of the IDFA comes from coordinating user behavior across apps.
Targeting ads is one use case, but it is also used in conversion tracking, which is very valuable to advertisers. They can know if ads in one app resulted in people buying things in another app.
Edit: fixed typo
What if apple sandboxed it to each app to make it safer/easier?
Besides the IDFA Apples seem to have tried hard to get rid of the obvious ways for different apps to link activity between their users. Of course if you login or provide an email it becomes easy...and there's plenty of trickier less reliable ways like looking at IP address
You can also disable Location-Based Ads: Settings > Privacy > Location Services > System Services (at the bottom) > Location-Based Apple Ads
Apple's ad tracking help doc: https://support.apple.com/en-us/HT205223 (Apparently they derive your gender based on your first name or the salutation on your iTunes account)
There is so much more to privacy than is made apparent to the user as a few OS knobs to "limit" ad tracking.
I am a little skeptical about some of the claims in that gist, though. One example is when they claim that APNS pushes require app access to a globally unique iOS activation identifier. That seems false. According to Apple’s dev docs at least, those tokens are device-and-app specific and have to be re-requested at app start time since they can be regenerated for a variety of reasons: https://developer.apple.com/library/archive/documentation/Ne...
Seems to have nothing to do with an activation UUID from a quick glance.
I appreciate a lot of the reference material in there, but this seeming mistake of conflating 2 different UUIDs makes me a little skeptical of some of the conclusions.
Edit for correction: I think I misread this part of the gist. They never directly say that the activation UUID is given directly to the app developer, just that Apple can track your social networking app pseudonym over APNS, "and possibly the social networking service" will be able to, as well.
This to me implied that the social networking service had the activation UUID, but the author never directly said that. If the notification has your pseudonym in it and Apple's storing that when a notification goes to APNS, it does seem like Apple would be able to tie that to your device if they're peeking inside the notification payload. The solution to this would be for the app developer to not include sensitive info in notifications or for the user to disable push notifications, but an E2E encrypted trustless notification solution provided by Apple would be much nicer.
I'm not sure about this, either; all recent iOS devices have a DMA AES engine that performs encryption on anything that travels between storage and memory.
Edit: I’m going to revise this and say that having read the whole thing there is very little of substance other than “Apple has a ton of metadata about your devices” at all, and the author doesn’t do a good job of quantifying the impact of that information exposure. On top of that, they cite iOS being closed source as a reason for its purported insecurity. Honestly the part about not having FDE is enough to make me question their competence more broadly.
This actually false. You can change your Ad ID on Android. I just looked (and checked)If you go to Settings > Privacy > Ads you can see this IDFA. At the top (it looks like a header and not an option, so I will not fully fault Mozilla because this is a dark pattern) it says "Reset advertising ID". If you press it you can see the grey "Your advertising ID" (at the bottom) change.
Additionally, there's the option "Opt out of Ads Personalization". It has the text "Instruct apps not to use your advertising ID to build profiles or show you personalized ads." I would love if someone here could clarify this for me. Is this a suggestion to apps or is this a strict and enforceable thing? As in "Hey app, you should ignore this ID that I'm handing to you" vs "Hey app, you don't get to have this ID. Sorry." Does anyone know which it is? The language suggests to me that it is the former.
Edit: This was done on a phone running Android 10
Root does work just fine on Android 10 on the OnePlus 7 Pro (which is the best phone I've ever owned).
Knowing where and when this was added to Android would be helpful.
A Samsung device.
Obsolute when new, no OS update ever available.
I am less than pleased.
They are under Settings...Privacy...Advertising
The Advertising and Analytics options are only visible below the fold, if one scrolls down the privacy page. The fold itself is disguised as the bottom of the page to put you off scrolling.
Unlike everything else, they do not have icons and only come after a paragraph of text almost perfectly large enough to fill out the vertical height where the tracking options would be.
Where would you put it?
*added for clarity.
Another example; most printers covertly embed an identifier in their prints.
I have a vague memory of a pre-release video game doing it? Or maybe it was just debugging information that they were embedding. shrug
Personally I don't believe Apple is doing what you describe (though maybe they might do it to a prototype iPhone). But it's certainly your right to hold that belief and take measurements to protect yourself. Shame you're getting downvoted for explaining yourself.
EDIT: Fixed a typo; thank you.
To be picky only colour printers, at least officially (though there are theories about similar ID for B/W laser printers):
This frustrates me a lot with my current printer. The yellow dots which "covertly" identifies my prints are way too visible in the print. So every time I look carefully at something I print I am reminded of how I am being watched.
Something that actually protects your privacy (and doesn't make you stick out like a sore thumb) is getting the screenshot from an image search and posting from a regularly rotated HN account, all the while using tor.
The main thing I would worry about is actually not Apple; instead (1) what information might Apple hide in plaintext in the image that a third party could extract?; and (2) what identifiers might there be that a third party could use to correlate multiple images as being from gorgoiler’s phone?
But honestly it just feels odd to upload a screenshot without doing something to scrub it. I find it helpful to practice good security even when, as you point out, the probability of it being necessary is very low.
e.g.: if you use an encrypted chat app ONLY after a murder occurred, then this would be suspicious. If you always use encrypted chat apps, then there's no information hint being given about your possible involvement with the murder.
A lot, actually. But why Apple would take the engineering resources to implement this, and risk all the reputation damage? If they're doing it for the money, how would they monetize it? If they're being coerced by the government, what's the government's motivations? In both cases, is smuggling bits in screenshots really the most plausible way to do it? Surely there must be some better way stenography in screenshots?
>But honestly it just feels odd to upload a screenshot without doing something to scrub it. I find it helpful to practice good security even when, as you point out, the probability of it being necessary is very low.
On the flip side, if you do unusual obfuscation of your uploaded image (eg. heavy post processing), that in itself is an identifying characteristic. You're going to be that guy who uploads his screenshots in greyscale, with heavy compression and blurring. https://xkcd.com/1105/
A “watermark” is simply a version of that designed to be invisible or imperceptible to the human eye, for example by embedding information in the least significant bits of the pixel colors.
“Digital Watermark Steganography” is a good search term for further investigation. As is the case with many security topics, there is an ongoing arms race between technology used to hide information, and technology used to detect information hiding.
At the end of the day if you truly wanted to share a screenshot of the iOS settings UI and remain anonymous, you should probably consider just drawing it with crayons. Except then someone will come along and process the crayon marks to recover your fingerprints etc. etc.
In this case however, it's hard to imagine how you'd do this without being detected. If you loaded the screenshot into mspaint and used the paint bucket tool, any color differences will become apparent. You could limit your modification to the edges, but detail there is going to get wiped by jpeg compression (if any).
Are they actually incapable of learning the right way to do things? Is neuroplasticity playing a role here? Do they not care that their images look terrible when zoomed in on? I guess they grew up in an era when photos frequently had time and date stamps, and if their eyesight is going... I guess that explains both points.
Or I can just hit two physical buttons on my phone and grab the image in the form of a screenshot. Because I don't care about the image fidelity, I usually just want to share the thing on Discord or Slack or wherever.
Don't be so arrogant as to assume that people doing things differently than you must be too stupid or old or blind to do it "the right way".
I thought some apps and iOS had already responded to this workflow by doing smart things when users try to create screenshots. If they haven't yet, they should. There's no need in the common case for "screenshot" and "share main image" to have different UI entry points. Just pop up a menu asking the user that they want when they push the button.
No.
They could, for example, sign a deal with an ad network that gives them beneficial rates on the condition that Apple show there is less than 1% churn in device IDFAs per month. Hiding the IDFA reset button would help with that.
It could also quite easily be some PM’s H2 goal to move the needle on IDFA retention. If they provably impact IDFA resets and they get an exceeds expectations rating in that performance review cycle! Bonus stock options all round! Tech companies are weird like that.
I’ve commented before accusing Apple of using growth and engagement tactics with iOS’s Mail.app, presumably to improve mean-time-before-replying-to-grandma metrics, so color me conspiracy theorist / jaded about Silicon Valley performance metrics.
They could require for example that unless you're specifically making a browser (Firefox, Chrome, Brave) that your in app webview have a whitelist of domains it's allowed to contact. That would force apps to launch Safari (or better the user's choice of browser) for external links. As it is nearly every app that supports external links launches an internal webview in which they can track 100% of the activity (urls, net requests, login credentials, etc...)
They could require apps that are not specifically a camera app or audio creation app not get access to the camera or mic and have to ask the OS take pictures/video and select pictures via the OS photos app. That way less apps would be able to record things in secret or upload any/all your photos without permission.
They could disallow scanning wifi SSIDs except for network tools. Scanning SSIDs is used to figuring out a user's location with with GPS off. In iOS 13 they did add bluetooth permissions so apps can be denied scanning bluetooth to do the same but AFAIK they have not done the same for SSIDs. Not sure what that would require but would love it if they'd work on it
They could disallow using the network at a low-level except for network tools. As it is, AFAIK, any app can use the network however it likes including scanning home networks for devices with vulnerabilities. I'm sure there are implications for things like Chromecast and other IoT like devices but I'm sure there could be more privacy oriented solutions.
My understanding is that UIWebView (or WKWebView) allows the host app to do basically anything with the web view but since iOS 9 there's also SFSafariViewController that doesn't quite allow apps as much access. Many apps whose main purpose is not web browsing (like Twitter) use the latter.
> They could require apps that are not specifically a camera app or audio creation app not get access to the camera or mic and have to ask the OS take pictures/video and select pictures via the OS photos app.
This API (UIImagePickerController) also already exists since the very beginning but it is the app makers that think using a custom UI for photo taking or photo picking is more suitable. I personally refuse to grant apps access to my photo library except a small number of apps. (For apps like Messenger that could totally make do using the system-provided photo picker but does not, I initiate the sharing from Photos instead.)
I think default behavior has to be block all 3rd party domains from all sites, but it's a ways away.
What, exactly, does "turning off IDFA" do? Does it send just a dummy IDFA? Or does it give you nothing at all? Why is rotating it periodically better? (I'm assuming rotation is better because that is what Mozilla is apparently recommending.)
I'm (cynically) assuming something different. Was "monthly" chosen by accident, or is that just enough time for advertisers to connect/correlate activity from two different IDFAs?
Mozilla has big-dollar deals with the ad industry (namely, Google). Perhaps they want to appear pro-privacy while really throwing a softball?
As a consumer I would love a good scandal that would force them to tighten up on in-app trackers as well. But it might hurt my employers.
The iPhone is a lot better for privacy by default. It's just not as good as it should be, and I do agree it's not as good as their claims suggest.
In other words, it depends on whether the difference in information leakage is information you actually care about.
Apple has tools in place for privacy, but none for anonymity. For example, requiring a full name and physical address to sign up for the App Store (Microsoft, despite all it’s telemetry, let’s you install apps from their store without an account).
I’ve heard suggestions to give Apple a fake name/address, but what if they start verifying like Facebook by requiring government issued ID?
Worst is new iCloud accounts now require a phone number for verification.
I would love something like the SEX here: https://i.imgur.com/OKZiWrN.png
Even if i delete the apps and wait weeks/months and then reinstall, i'm logged in again when i first open them.
I have enabled "Settings > Privacy > Advertising > Limit Ad Tracking" and also cleared all Safari history.
How is this possible?
Go to "Settings > General > iPhone Storage" and you will find "Google LLC" where it explains the data stored is shared with all Google apps.
Microsoft does the same thing to enable you to quickly sign-in to their different apps under the name "Microsoft Corporation".
On the list of apps you will see "Google LLC". This is where Google stores account data and this is shared with all Google apps.
Under Google LLC it says "Data shared by X apps".
However, still i see no "Google LLC" in "Settings > General > iPhone Storage".
(i do see Youtube and Google Home. But after deleting them and reinstalling Youtube i am automatically logged in again.)
I just noticed something else though: when i drag down from the home screen and enter "google" in the search bar, the result list displays a "Settings" item named "Google Home" with the gray ios-settings icon next to it. If i click it to open it, the settings app opens but it doesn't show me anything specific, just the main setting screen.
Note that Google Home is not installed on any of my devices (i removed them a long time ago after ditching the Chromecast).
https://support.google.com/authorizedbuyers/answer/3221407?h...
Now they've mostly ditched their own advertising platforms, what do they have to gain from having these default settings?
Huh. I have never heard of this.
The mods are quite responsive to these.
https://developer.apple.com/business/documentation/Configura...
On that topic...if you're really security conscious you can set allowHostPairing to False. This requires a supervised device, but then your phone will only pair a computer that has the supervising certificate, and if none exists, then all pairing is disabled. This might help defend against GrayKey like attacks.
If a phone OS isn't a strategic bet, I don't know what is. All the people spending money on the librem would have happily bought FFOS phones, if they made proper high spec ones (I still have one of the highest spec FFOS phones ever made and it wasn't that impressive).
The comment was tongue in cheek -- mozilla had already done everything I suggested (the effort was called FirefoxOS), but they mismanaged and abandoned it. The renewed focus on Firefox the browser (if that had anything to do with it) was good, but some of the other stuff they started pushing like WebVR is/was pretty short-sighted in my opinion.
If mozilla wanted to set themselves up as the open alternative to apple/google, keeping a phone in the portfolio is/was pretty important. Maybe the cost was just too unsustainable but from what I can see it was mismanaged more than impossible to make profitable.