I don’t want to give Termius my location. I don’t want them tracking me everywhere I go. But apparently that’s the only way they can keep my SSH session alive when I need to switch to Safari for a few minutes?
I don’t want to give Termius my location. I don’t want them tracking me everywhere I go. But apparently that’s the only way they can keep my SSH session alive when I need to switch to Safari for a few minutes?
The correct solution here is for the app to request background processing and to schedule a local notification in 9 minutes saying that the app is about to run out of background time and pause (and then clean up the notification if the user returns to the app before it fires). This means you're not abusing anything, and it lets the user return before the connection is killed in order to keep it alive.
This also means if the user never returns, the app will naturally shut down the connection after 10 minutes instead of keeping it open indefinitely.
In any case, there's a property `UIApplication.backgroundTimeRemaining` that tells you how long you have, so you can use that to calculate the appropriate notification time.
And yes, the app in question of course does exactly that notification dance (I've used it since long before it got its current name). GP is talking about a new feature to keep sessions open in bg for a loong time. I've disabled it, not for fear of tracking but because it seems like a silly way to forget connections open and drain the battery for no reason.
App has indeed also always supported mosh... me I just attach to tmux. But I agree with whoever wrote it's better to have such a bg hack feature than not, for those who find it useful.
Termius works perfectly on Android without requesting my location.
This is why I'm an Apple user. Hate regarding Apple's policies like "use a platform that lets the app function correctly" (ie. drain battery running in background just to do more tracking, or because every developer assumes THEIR app is so special that it must never be unloaded from memory, in order to open instantly when being swapped back to... weeks after user's last interaction). With hilarious frequency, the complaints people have about Apple are precisely the reasons I prefer their products.
This doesn't happen on Android. The reason it doesn't is that the app has to display a persistent notification if it wants to run with high priority in the background. This is why I'm an Android user. It lets the user do what they need to do and prevents apps from being abusive.
Every excuse for Apple's platforms failings that I have seen so far has a better solution on Android that the Apple apologist has not heard of.
iPadOS was such a major leap forward for the iPad and there's not many features left I need to use it as a laptop replacement... but the aggressive app and tab killing ruins everything. I've never said this about iOS devices before, but it's time to start putting more RAM in these machines.
So I deny most apps use of this, as it's clearly just a ploy to keep their app running when it shouldn't be. Something like the Termius app you cite has a legitimate reason to run in the background though and has to ask for one of those permissions.
It's a weird grey area IMO. I'm sure if you asked the Termius developers they may tell you that they don't even use the location data and that it's just a mechanism to keep the app running. However, the fact that we as users don't know this for sure is a problem that Apple could fix by adding a specific background permission alert.
I was not aware of Mosh.
I definitely prefer the iOS model.
Android very recently -- at API level 26 -- added restrictions on background tasks for that platform (and it's much more involved than if you display a notification or not). Before that every app developer just spun up a background service for everything, and anyone who has done an iota of development on Android devices saw the tragedy of the commons that the platform became. So kudos to Google for cleaning it up a bit. Of course Samsung, Google and others just declare themselves immune from those restrictions and it's just a smaller problem, not a solved problem.
99.9999% of the time the most that is necessary is an occasional scheduled task. No, your picture of cats app doesn't need to run a busy loop pinging a server. Learn how to use the core messaging infrastructure of the platforms you target.
No, Chrome doesn't need to run a perpetual service just to check for updates.
These are not controversial claims.
mosh solves this use-case because there is no need for the client to remain connected to persist. It's like a tmux/screen terminal running in detached mode. When the app loads back up, it picks up the mosh session again.
> Mosh maintains the terminal session (not "connection" in the TCP-sense because Mosh uses UDP) even when a user loses their Internet connection or puts their client to "sleep." In comparison, SSH can lose its connection in such cases because TCP times out.[5]
Very sad, because the idea behind Mosh is great.
1. seems a egde case, never hit me while beeing a customer there. (funny way telefonica does throttling)
2. seems a edge case caused by the users vpn.
Apple is good at taking use-cases and creating cohesive stories around the right way to serve them; this one has been long-coming.
Even with opt-In messaging how many people just click “ok” thinking the app needs it.
Meanwhile Matrix gets by because they have a company with actual money subsidising the client app (Riot) and providing notifications for every user, no matter which homeserver they happen to be using. Without that benevolence provided for iOS, Matrix could well be another non-starter outside FOSS circles.
So, I'm reading this that regardless of using a separate 'homeserver', Matrix receives all traffic/notifications?
I loved Termius but didnt realize that keys were uploaded to their servers until I opened it on my laptop and saw it download all my keys.
Spent the day rotating all my keys.
Just stop paying...
I just hope the app review team doesn't throw us out again.
Apple needs to fix this.
On one hand I agree with you, that's crazy that your SSH program put that limit on there for clearly tracking purposes. But I guess I sort of disagree this is Apple's problem to solve. It's yours.
Apple made the changes to inform and educate you the customer that an app that is abusing your trust.
The solution is not to force Apple to police developers but for you to stop using Terminus. Call it a free market solution if you like.
The difference with real and ideal is that Terminus could absolutely find a "legitimate" use for location and it would scoot right by Apple review anyhow. So let them be upfront they're bad people being bad.
(Before it comes... I KNOW... Apple walled garden and how they do this a lot anyhow! But, as someone who has walled garden issues with Apple, we should encourage information and education over big brother protecting us. It might not be consistent for them, but I think it's the right move here)
If Apple is playing hands on, they deserve just as much blame.
So, report to Apple, file a review, stop using it.
If Apple comes to the rescue and characteristically fixes it, great, if they don't - they've already made great steps in allowing you to make informed decisions.
And I think the app is covered since it's saying "enabling location data means you can plot on a map where you've connected to a host" or something like that in settings - good enough a bs feature for Apple to let it slide, evidently.
Because they have clearly demonstrated they do not deserve your trust or support.
As someone presumably technically capable wouldn't the first step be ensuring sync is off, routing through a pi or whatever and firing up Wireshark to check whether it's even possible that something malicious is going on? I'm not saying it's not - I have no idea. But I'd certainly have a look before making any claims.
The actual scalable solution is for Congress or states to pass GDPR-style privacy legislation (or CCPA if your politicians are captured by tech industry interests).
It's always laws.