Even if you don't log in. The Facebook SDK sends data back.
Hook your device up to an intercepting proxy and start up a few apps. 99% of them do this.
I really wish Apple would put an end to this.
Even if you don't log in. The Facebook SDK sends data back.
Hook your device up to an intercepting proxy and start up a few apps. 99% of them do this.
I really wish Apple would put an end to this.
This is what really gives lie to the whole walled garden thing. Its selling point is supposed to be in Apple preventing things like this, but here we are in reality and they don't. Meanwhile they do e.g. prevent Signal from replacing Apple's default app for SMS, which has no purpose other than to create barriers for cross-platform competitors to the default apps.
The question is whether your products and your supposed competitor's products are really the same market. In other words, are your customers the same individuals? Are the products substitutes for one another?
For Clorox bleach and other bleach they are. All bleach is the same, they're perfect substitutes, if the store is out of Clorox bleach and you buy some other bleach you'll never even know the difference.
For iOS app stores and Android app stores, they're completely different markets. The customers for iOS apps are people with iOS devices and the customers for Android apps are people with Android devices -- almost completely disjoint sets of people. If the iOS app store is down, it's infeasible for the average user to get an app from Google Play instead -- they would have to spend hundreds of dollars to buy an Android phone, then replace all of their other apps, just to substitute one app. It would be like saying AT&T didn't have a monopoly in 1970 because you could change carriers by moving to Canada. They're completely different markets.
https://www.cnbc.com/2020/03/16/apple-fined-1point2-billion-...
Difficult to figure out how to actually do this, especially so without a crazy UX.
They should figure out the default apps thing. Though I don't know what you'd need for SMS, there's not much system integration there besides Siri (which I think supports plugins) and maybe sms: links?
Have you read the guidelines? Many words requiring you to use and not discourage users from using Apple's in-app purchasing system (which they get a large cut of), prohibiting you from trying to compete with the App Store or similar, prohibiting app-alternatives they don't control (like remote desktop into a cloud server), requiring "Sign in with Apple" if you use another third party sign in service and that sort of thing.
There is a privacy section, but the dirty secret is that they have very little power to enforce it against premeditated abuses. Companies add a feature to their app that gives them a pretext for uploading your data to their servers, and then there is no way for the user or Apple to verify what happens to it from there or determine actual compliance with the privacy policy.
So the policies with a compliance enforcement mechanism are the ones that benefit Apple and the ones that are supposed to benefit users in practice don't have one.
> Difficult to figure out how to actually do this, especially so without a crazy UX.
Actually not so hard in that specific case. They could run the app and not sign in with a Facebook account, and if it tries to contact Facebook servers anyway, reject it.
> They should figure out the default apps thing. Though I don't know what you'd need for SMS, there's not much system integration there besides Siri (which I think supports plugins) and maybe sms: links?
They prohibit it on purpose. Signal isn't allowed to send and receive SMS on iOS:
https://support.signal.org/hc/en-us/articles/360007321171-Ca...
> Apple does not allow other apps to replace the default SMS/messaging app.
The "Firefox" on iOS isn't even actually Firefox, it's required to use Apple's browser engine.
Your proposed solution would not work, obviously, because how do you define what services an app is allowed to connect to? How do you know it's connecting to Facebook's servers? Just hope they always use facebook.com?
It's the true motive for the "walled garden" -- it explains why it continues to exist even though the stated reasons why it exists don't pan out in practice.
> Your proposed solution would not work, obviously, because how do you define what services an app is allowed to connect to?
Why is it allowed to connect to any services for no reason? If the app makes a network connection the developer should have to justify it by something other than enabling collection of user data.
> How do you know it's connecting to Facebook's servers? Just hope they always use facebook.com?
I feel confident that Apple has the resources to determine whether the servers every application using the Facebook SDK is contacting belong to Facebook.
I assume a lot of people just “slap” the SDK in there and call it a day and it starts sending data.
Zoom also buys ads on Facebook, so integrates the SDK for attribution.
[1] https://www.apple.com/privacy/ ("Privacy is a fundamental human right. At Apple, it’s also one of our core values. Your devices are important to so many parts of your life. What you share from those experiences, and who you share it with, should be up to you. We design Apple products to protect your privacy and give you control over your information. It’s not always easy. But that’s the kind of innovation we believe in.")
https://blog.gingerlime.com/2020/does-apple-care-about-your-...
It looks promising, and has been posted to HN a few times, but nobody has commented on it. https://news.ycombinator.com/item?id=20519456
https://9to5mac.com/2019/08/05/guardian-firewall-vpn-ios-app...
They choose not to because 1) it's easier and 2) Facebook gives them a "cut" of the revenue in the form of free analytics and insights into how their Facebook ads are performing.
The companies decided that the value they get out of Facebook ads & analytics are worth more than their customers' privacy. Until well-enforced regulations come into play (so not the GDPR) nothing will change.
There's a lot of developers that rely on these dependencies, and just blocking them would cause a major backlash.
If you know what that means, it means that I am a scarred, grizzled vet, with an eyepatch and a trick knee.
Anyone who has been an Apple developer for more than a couple of decades, has had the experience of having the rug pulled out from under them by Apple.
That's one reason that I'm not hurrying to adopt SwiftUI. I really like it, and hope that it makes it (I despise Auto-Layout), but I have also seen other promising tech smothered in the crib (OpenDoc? QuickDrawGX?).
Moreover, prohibiting this wouldn't actually remove the apps for more than five minutes because what would immediately follow is a version of the SDK that doesn't send any data to Facebook when you're not actually using a Facebook account.
For those who did not read about it: https://andregarzia.com/2020/03/private-client-side-only-pwa...
Then as a user, I can inspect what apps are sending and how frequently. I should be able to block requests or set myself as anonymous. Or allow apps for certain amounts of time etc.
And yet, we don't need to integrate Facebook's binary blobs to use this SDK's main features. How about we implement the open version of Facebook SDK that uses their APIs but doesn't do anything that we don't want it to?