Apple’s Anti-Tracking Plans for iPhone
foundation.mozilla.org
foundation.mozilla.org
Now that the third-party tracking ecosystem is slowly drying out I'm curious what advertisers will come up with to circumvent these new measures. Anyone here that works in the industry and wants to share some plans?
First Ad Fraud != Fraud. It is low grade hacking.
Second. Trading the privacy of every iPhone user so that advertisers can prop up a sketchy/ poor industry is a terrible trade.
As someone alt-tabbing in from real fraud investigation work, no, it doesn't. Banning burner phones and reducing banking privacy regulations would move the needle there, but those aren't even on the radar.
"Someone's script opened a page" isn't fraud. Someone built a script specifically to spam click a competitor's ads, by contrast, is.
Getting around a ban is not Fraud.
Regardless, a cross app ad identifier is not needed to prevent this. There are ways within your app to save data per iOS user (this is not cross app data, it's specific to your app) which would allow you to prevent this. You could use sign in with Apple/ Google/ Facebook. You could require emails. etc etc.
Apple already has a privacy-preserving solution for that:
EDIT: I believe Apple's DeviceCheck API is what the parent refers to. Thank you!
Not his solution, but just grab the identifierForVendor off UIDevice and ban that.
Alternatively:
> "Using DeviceCheck API’s, in combination with a server-to-server APIs, developer can set and query two bits of data per device. It will also maintain the user privacy, by not disclosing any user or device information, which is the priority point for every Apple user and most point of concern of every mobile user."
https://codeburst.io/unique-identifier-for-the-ios-devices-5...
So if you want to exclude/ban a user, you can use the IMEI+account, but outside of excluding a user from using your service, you cannot access IMEI+account.
User privacy is preserved because there's no singular ID for advertisers, and services can still ban fraud because if it's present they can use the IMEI+account to ban a user.
Maybe even have that built into the OS? The app can ban someone based on an IMEI+account, but the IMEI+account info stays on the device. The device just certifies that the combination is unique without exposing that info to the app, and the app can still ban that hardware/account, so the user would need to buy new hardware to get around the ban.
Maybe that opens up some opportunities as well, but that's not necessarily particularly appetising for businesses that aren't focussed around those areas of opportunity.
At the extreme, imagine if every person has a unique identifier that was automatically sent whenever they used any device: preventing ad fraud would be really easy, and you would have essentially zero privacy. At the other extreme, imagine if every device looked exactly the same, with no user agent, no IP, no cookies, no way to tell my traffic from yours. In that situation, people would have pretty strong privacy, but if you had headless browsers loading the ads on your site no one would be able to tell that those views were not from real users.
As the GGP says, removing IDFA shifts the balance toward both privacy and fraud. See https://blog.cloudflare.com/cloudflare-supports-privacy-pass... and https://web.dev/trust-tokens/ for attempts to separate these.
(Disclosure: I work on ads at Google, speaking only for myself.)
So, Apple’s decision is looking even better to me now.
There is literally nothing in the world I care about less than this.
This seems like a problem with the current model of ads being paid for by impression/click, and switching to a model where ads are being paid for the time they're being displayed (pay X to have your ad appear here for Y time) the problem goes away.
Furthermore, the current advertiisng model also suffers from this problem even beyond malicious intent. Is it fraud if a real user "looks" at the ad but actually looks away from their screen? If they mute the sound? If they don't speak the language the ad is in? Etc.
Advertiser fraud is hardly the only type of fraud. It happens with services you directly pay for like ridesharing and food delivery as well. The cost of fraud becomes another cost for a service provider and prices for all users need to be raised to offset losses from fraud.
For smaller businesses without the brain power to combat fraud, their margins will be greatly hurt by fraud, making it harder to compete.
I'm in favor of what Apple is doing myself, but it's definitely a legitimate unintended consequence of this measure.
What would be useful is if Apple became the gatekeeper for tracking fraud and companies could report ephemeral identifiers for fraud that only Apple can de-anonymize and then Apple provides fraud scores for ephemeral identifiers on account signup.
Do you think iPhone users care that Apple is implementing anti-tracking?
It's becoming a real concern for normal people - they don't understand what it is or how it works but they really don't like it.
I was in shock when I saw it on Instagram on my brand new iPhone (switched from Android) which has all mic permissions off by default. So some 'smart' device in their home must of heard us. Some advertiser somewhere must have my voice profile hooked up to my Instagram account by now and they somehow share it in an "unidentified" way.
Edit: We need further research into these 'impossible' ads to see if devices from different software OS' and companies are listening and grabbing detail and showing ads based on what are supposed to be 100% private conversations.
You might have not googled it yourself, but I bet the person you had that conversation with did. If the conversation took place in real life, then that person's device was in physical proximity to yours (i.e., location data tracking; for example, if you enter a room full of people who googled tons of stuff about a certain subject, expect to see ads around that subject popping up on your device in the near future, even if you didn't google anything about that subject before and aren't planning to do so in the future). You also probably exchanged contacts and called (or texted) each other about other stuff in general (probable, but not necessary for the scenario I am describing). And if the conversation took place online, then it is even easier. Here you go, you just created a social link between yourself and the person who googled stuff about aircraft hangar gravel. In which case, it isn't surprising at all that you got that ad.
So in a sense, you are correct, it wasn't a coincidence. But I heavily doubt it has anything to do with smart devices listening and analyzing to what you said at all. It is much more trivial and less creepy to simply utilize your social links to figure out what kind of ads to display to you than listen in and try to analyze your conversations. More reliable too.
Maybe not all of us, but for me it's an important and differentiating feature.
What we don't really care about is hypothetical thinking about wether we care from people that apparently don't care.
I don't think they know each setting that is available, but they without doubt have the impression that "Apple is better with privacy"
A stable identifier makes identifying this sort of behavior much easier.
(Disclosure: I work on ads at Google, speaking only for myself)
When you use a service that is funded by advertising, the service only gets that funding because the advertisers trust that they are getting their ads in front of real users. Some advertisers are able to precisely measure the quality of their traffic, for example by seeing whether the traffic they get buys things, but most are in businesses where that's not possible (no one clicks on an ad for Coca-Cola and then places an order for Coke). Ad fraud means that advertisers are less willing to pay to be shown on the service, so the service's funding decreases.
Very likely, less funding for the service hurts you as a consumer: they are probably spending their funding in support of the site. For example, I believe that the ads here fund the moderators.
> why should you be allowed to spy on me - who never defrauded any advertisers - to fix your problem?
See my response to wil421: https://news.ycombinator.com/item?id=25430453 I think that fix here is some thing like https://blog.cloudflare.com/cloudflare-supports-privacy-pass... or https://web.dev/trust-tokens/ that allows detecting and preventing fraud in a privacy preserving manner.
Ad fraud really isn't my problem. So why should I be mercilessly tracked by everyone just to make your job easier?
So why are they deploying the term? Because it's a great way to deflect thinking about a core failing of their business logic. We've known since the day of banner ads that 'views' are a tremendously flawed metric, so blaming online agents for WHY they're flawed lets them deflect blame.
The fact that we're in this thread trying to parse semantics when consumers don't even have a seat at the table when deciding where we should fall on the tracking/privacy spectrum should tell you all you need to know about how the industry operates.
As someone who doesn't use an iphone it's really frustrating that online services are starting to expect one for this reason when it hasn't been necessary in the past.
They’re not supposed to do that. Their dogmatic refusal to see the writing on the wall is ridiculous.
Apple's privacy changes might seem like a good idea from the outside, but essentially or paradoxically leads to higher entry barriers for new competitors and cement the role the actual players have.
However, we do not have experience with so-called "big tech." It is relatively new, iPhone came to light in 2007. So I regard Apple's measurements as another experiment, and we will see how things further evolve.
Honestly, who cares if the barrier of entry for a shitty business model is raised. And can see only upside to this.
Also: boohoo
(I like where your head is at, fraud is just hard)
Those are not exempt from the GDPR either. Granted, at the moment there’s very little enforcement around these (especially IP addresses despite their huge tracking potential) but once enforcement is stepped up there shouldn’t be any difference whether it’s a FAANG or a small company doing it).
- contextual (target the content, make decisions based on _what I'm reading_ now, not who _I am_--less dubious ethically)
My favourite one: behavioural rebranded as contextual (I know some companies selling "contextual targeting", where some of the properties clearly define the user, these are mostly ML-based solutions, relying on mobile hardware)
Behavioural cross-platform targeting will exist but in a less deterministic form.
source: I used to work in AdTech and started a bunch of privacy-related initiatives.
I give good odds ad frameworks will again start trying to circumvent the platform security to get a UDID or equivalent.
* to say nothing about the fact that apps can easily get my first name without me knowing it being super creepy
https://www.verizonmedia.com/insights/overcoming-identity-he...
And probably a dozen other ID solutions out there that require you to be logged in and thus have some first party data to match you with.
Honestly I'm not sure what the value proposition is for the user if it's not required to log in, so who knows what the uptake will be.
Now that the third-party tracking ecosystem is slowly drying out I'm curious what advertisers will come up with to circumvent these new measures.
Probably fingerprinting – not to mention the fact that ad-people are lobbying both legislators (including the EU) and standards bodies (like W3C)... and in the latter case they're also directly contributing to the standards.Of course some smaller one will still try to do it, don't get me wrong.
Given the sorry state of privacy-compliance in general (whether that's ignorance of the law or consciously taking a risk) I seriously doubt that the field of adtech is much better.
Apple has been restricting things almost from day one, and creating the IDFA in the first place was part of that, but this seems like the biggest step forward by far.
Its main purpose is targeted ads while repurposing or reselling peoples’ data is a nefarious secondary use.
Multi-sided markets are important revenue models that are tailored to user preferences and behavior. We are trying to strike a balance; we don’t need to demonize all advertising centric business models to win the argument for better privacy options.
I think both Apple and Mozilla are more aligned with my personal preferences but their positions are also perfectly aligned with their core business models.
Traditionally, this has been implemented with third party cookies. The retailer drops a cookie on the users browser, and then buys ads to be shown to anyone matching that cookie. I don't know if I would call this data mining, but it is certainly not private.
It is possible to build a system that supports remarketing in a private way, however, with new browser APIs: https://github.com/WICG/turtledove
(Disclosure: I work on ads at Google, speaking only for myself)
Is that something that people want?
Imagine someone wants to buy a table saw and their requirements changed and they no longer need it. It would be pretty annoying to have table saws follow them around the internet when they literally don't need them (and get in the way of other ads they would potentially be interested in).
It's also a privacy issue; if someone is searching for certain sensitive items they'd rather not have those follow them around for weeks down the line.
Exactly and tracking companies such as Adjust or AppsFlyer carry on IFDA-ing/fingerprinting users. GDPR seems to be just a nice-to-have.
It's being marketed this way, that's it. It doesn't mean Apple care about privacy, and they prove every once in a while that they don't respect anyone's privacy at all. They spy on their users as much as anyone else (and overall, they have access to much more information than everybody else except Google).
All they want to do is prevent third-party tracking on their devices, so they have a monopoly on their users' data.
But they do collect those data and they share them with third party “partners”. Don't trust me, just look at their privacy policy, it's explicitly written there: https://www.apple.com/legal/privacy/en-ww/
This is so dishonest.
Please familiarise yourself with Apple's history in consumer privacy and what they've done so far, including inadvertently forcing others to follow (looking at you Google).
Yes, apple talking about apple... Lets see the facts, here mozilla is asking apple to commit what apple is advocating for all these years.
> "In 2019, Mozilla called on Apple to increase user privacy by automatically resetting the Identifier for Advertisers (IDFA) on iPhones."
It's 2021 very soon
Apple released IDFA to improve consumer privacy, to avoid advertisers being able to fingerprint iOS devices using Unique Device ID (UDID).
Access to UDID was deprecated in iOS 5 (that's 2011).
It has also given control to consumers since then to opt-out of providing IDFA by default.
In 2019, Mozilla asked Apple to take rotate the IDFA every month.
But Apple has taken it even further, which Mozilla publicly applauded https://foundation.mozilla.org/en/blog/applause-for-apples-i...
Apple is now making IDFA disabled by default and requiring users to enable it if they want to.
> Apple went even further than what Mozilla supporters had asked for when it announced that it will give consumers the option to opt-out of tracking in each app, essentially turning off IDFA and giving millions of consumers more privacy online.
> That’s where you come in: We need a massive outpouring of support for Apple’s decision to help strengthen its resolve to protect consumer privacy.
Why mozilla needs people like me and you in order for apple to fulfil their promises for consumer privacy?
As apple says “Privacy. That’s iPhone”, why it needs user attention for apple actions?
Apple is still going ahead with this regardless. My understanding the rollout was delayed because of ongoing financial hardship on everyone in the world because of COVID (and to give more time to advertisers, developers and others to prepare).
Mozilla is also asking everyone to publicly support Apple's decision because it's good for consumers, which in result would also force others to also adopt it (Android), but also because on the other end of this decision are advertisers, game developers and Facebook that are publicly telling everyone it's a bad thing since it'll hit their wallets.
And it's not gonna change: https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Besides, haven't facebook and google got ban from China because for not compiling with Chinese law?
Web services companies face a ton of problems operating in China that are really specific to the kinds of services they offer. Apple simply doesn't offer those kinds of services.
This is easily disproven by making a GDPR access request to see what various companies have retained on you, or if you’re extra paranoid inspecting what the device is sending back over the network.
Apple has access to all apps you open, your position, the content of your iCloud, etc. etc.
And it wasn't all apps—unsigned apps are allowed to run, so by definition, there's no way for Apple to "know" about them. Many people didn't know it was happening because they weren't affected.
Details: https://eclecticlight.co/2020/11/16/checks-on-executable-cod...
> Usage Data. Data about your activity on and use of our offerings, such as app launches within our services, including browsing history; search history; product interaction; crash data, performance and other diagnostic data; and other usage data
https://www.apple.com/legal/privacy/en-ww/
Or maybe Apple Lawyers don't understand either?
> BTW, OCSP checks are unencrypted, but Apple says it will change to an encrypted protocol.
“When caught, simply apologize and promise to do better next time, it will be fine”. It wasn't the first time, and it won't be the last.
As a sidenote: https://www.bbc.com/news/business-13416598
This is not how any browser implements it today. Browsers either do not check (Chrome, Safari) or check but fail open (Firefox, Edge). I'm not aware of any browser that fails closed in its default configuration. More: https://www.ssl.com/article/how-do-browsers-handle-revoked-s...
Browsers primarily handle revoked certs by pushing certificate revocation lists (CRLs).
Mozilla and Chrome have schemes to send a subset of revocations from the browser vendor to the user, Mozilla's is named OneCRL, the Chrome one is CRLSets.
For most websites if your end entity leaf certificate is revoked for some mundane reason Chrome likely simply won't know or care and it'll still work, because you aren't covered by CRLSets as the data would be too huge.
The long term fix, which site owners can implement, is OCSP Must Staple. What happens there is, when you request a certificate you insist on this "extension" and the extension tells client software "This certificate is only valid if accompanied by an up-to-date OCSP response". Then you set your server software to fetch OCSP responses for its own certificate and serve those to visitors.
This means excellent privacy (PornHub's certificate issuer still knows that PornHub is PornHub, not an invasion of privacy, and PornHub still knows that PornHub visitors visited PornHub, but the issuer doesn't learn who the visitors are) while being revocable (if the issuer provides REVOKED OCSP answers then you can't show that revoked certificate to a client once the last not-REVOKED OCSP answer expires)
Unfortunately, and this is a huge shame most especially for Apache, there are a lot of HTTPS servers that got OCSP Stapling badly wrong, meaning you need newer versions of software or have to install complicated workarounds because the early implementations were so stupid.
Incidentally did you know that web browsers tell certificate authorities about every website you visit that uses TLS with support for OCSP stapling.
OCSP stapling is exactly what enables the browser to verify the revocation status without contacting the cert authority. Also, not all browsers check OCSP.
Facebook collected data for ages using their SDK and lists of e-mail addresses/phone numbers submitted to them by advertisers but only started exposing them in their "download my data" tool (their GDPR SAR process basically) relatively recently.
GDPR access requests don't always tell the truth, often due to malice but in some cases incompetence too (there were a couple of times where my GDPR complaints have actually revealed to the company that their third-party SDKs leaked more data than they originally thought).
Sent from my Thinkpad.
Not entirely true anymore:
1) About $8-12 billion paid by Google to have their search engine default. [1]
2) About $20 billion from their 15-30% cut of third party app developers. Where the App Store is protected from competition. [2]
3) Apple services (like Apple TV+), which collects usage data for itself and third parties. [3]
[1] https://www.macrumors.com/2020/10/25/google-apple-search-def...
[2] https://www.theverge.com/2020/6/15/21292203/apple-app-store-...
As much as I would like them to default to and support DuckDuckGo instead (hell, it would be a match made in heaven if Apple were to buy DDG and make it their privacy centrepiece), a lot of people would be confused if they got DDG instead of Google, so I don't really think it's fair to make it out as some "chink in the armour". It's a business win-win in my eyes and doesn't affect me at all.
> those are revenue figures, not profit
> $10 billion from Google out of $60 billion in profit is significant
The trailing 12 month revenue for Mac, iPhone, iPad and Apple Watch (+ HomePod, AirPods, etc.) was over $220 billion.
And while $20 billion is not nothing, it's actually not that big a deal for Apple, especially when you consider its $2 trillion market cap.
Apple makes about 60 billion a year in the profit. The 10 billion they get from Google constitutes 16% of their annual profit. That’s significant!
Apple trades at a 37x P/E ratio. An additional $20B profit could be worth about an additional $760 billion in market cap. You can’t dismiss 10 billion in pure profit because their market cap. Those numbers are directly related and far closer in meaning than you give credit.
You're playing funny buggers with figures there. According to your standard the sales of physical devices constitutes over 350% of their annual profit.
The $10B Google money is basically pure profit. It costs Apple nothing. Maybe a few million in lawyer time to negotiate the fee each year.
Hardware sales generates enormous revenue and also very large profit. I believe more than half of Apple’s profit is still hardware sales. But they’re working very hard to increase their services income.
And Mozilla, who wrote this article, also gets the majority of their funding through paid search, mostly from Google.
> Precisely 94% of Mozilla revenues came through royalties received by search engines to be featured on its Mozilla Firefox browser.[0]
I don't understand why we should always have good guys and bad guys and we can't accept that none of those company respect us.
Nothing will change if we relay Apple's propaganda about privacy. People will think that the solution is already there and it's Apple. And it's not. Apple has catastrophic Privacy, just a bit less catastrophic than Google but that's it.
They don't even encrypt your cloud, how's that remotely close to "privacy focused company"
Anyone aware of Apple's history knows that Apple has always pushed consumer privacy forward, forcing others in the industry to follow.
I don't know any other consumer electronics company other than Apple that has been championing consumer privacy so much over the last 12-15 years.
If you learned about Apple's stance on privacy only in their recent marketing, that doesn't mean they haven't been doing it before.
I will admit that this action to change the advertising ID to default-off is a promising one though.
Sent from my Huawei.
https://uk.reuters.com/article/us-apple-fbi-icloud-exclusive...
Not saying I agree or disagree with it, but it's something worth highlighting
But, just like with FileVault, the roll out will most likely be relatively slow and progressive.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Sent from my Pinephone.
It’s also a good way to combat the push from companies like Google to bring down the prices of devices to allow for better tracking.
I haven't followed this very closely, has anyone determined exactly what is being sent?
I also think this is why Apple and Microsoft have bright futures but companies like Amazon, Google, and Facebook will only see more legal hurdles from here on out.
It's a lot of money, but it's pocket change for Apple in the scheme of things—$220 billion in hardware revenue and a $2 trillion market cap.
Google needs to pay it far more than Apple needs the money. Google knows Apple customers are far more lucrative than Android customers.
I wish they had come up with an alternate revenue stream.
Also people would want google anyway. After all it’s still the most useful search engine for almost everyone. Apple is primarily still a device maker for people who want stuff to justwerk and people who have no interest in tech.
You do not need to send Apple your drivers license to compile software for Apple hardware.
Please don't feel safe on iOS just because Apple marketing is blasting misleading claims at you.
https://www.facebook.com/off_facebook_activity/activity_list
(click "Manage Your Off-Facebook Activity" on the right if you're on desktop)
I wouldn't be surprised if they did not link email addresses (and other user-accessible identifiers such as a phone number) anymore just to avoid having to give you your data if you request it.
Clear your off-Facebook activity from your account?
Here are some things to know:
- Your activity history will be disconnected from your account. This does not currently include Oculus activity. We'll continue to receive your activity from the businesses and organisations that you visit in the future.
- Clearing your history may log you out of XXX and YYY other apps and websites. If this happens, you can still use Facebook to log back in.
- You'll still see the same number of ads. Your ad preferences and actions that you take on Facebook will be used to show you relevant ads.
If Apple really cared, they'd make IDFA opt-in only. Why are we now applauding the option to disable a feature that the EU deemed illegal from the start? [1]
If Apple really cared, they'd remove Google as the default search engine and forgo the $8-12 billion they make from Google. Then, allow a fair bid for privacy focused search engines (or make their own). [2]
If Apple really cared, they'd stop tracking you in Apple Services like Apple TV+ and stop sharing your data with third parties. [3]
[1] https://www.thehindu.com/sci-tech/technology/what-is-apples-...
[2] https://www.macrumors.com/2020/10/25/google-apple-search-def...
No, there is no privacy oriented, no anti-tracking, cell phone. None of them are capable of this. And no amount of "privacy" functions in the user computer will make up for the intrinsic nature of cell phones. Because cell phones are so incredibly useful people bend over backwards mentally to try to ignore this. They get angry when it's pointed out because it's "irrelevant". But it isn't. This is real tracking of you. Far worse than any "internet" tracking.
At minimum you should be using https. Your ISP could generally know the domains you are communicating with (when and how much), but not about what. They also could not add metadata to requests. The ad tracking we're talking about in this post really needs those details, so the ISP isn't in a position to enable the kind of tracking Apple is blocking here.
You can go further and use a VPN. Then all your ISP knows is that you use a VPN, but would not be able to tell anything else. Of course, you need to trust your VPN provider (including to properly secure their service), but if you're paying for one, at least your interests are aligned. (You pay your ISP, but they operate as semi monopolies and your privacy is not their primary business concern, so your interests don't really align that well.)
I agree about not allowing ISPs to sell data, though I think it would be OK if properly anonymized.
This is probably one of the dumber ideas I've come up with given that I have no idea how the different protocols for handshakes between cells and towers work. Looking to be educated on it here in the comments.
Cellular modem firmwares are also generally pretty closely guarded and not flashable.
First, your phone sends out a radio signal omnidirectionally. Then many basestations that know their own position and time very accurately receive it at slightly different times. They compare and use multi-lateration to determine where the broadcast had to come from.
It would be nice if there were regulations that protected my information from my telco provider.
What I heard was that at some point of time, Apple had an ambition for own advertising business.
I could be very much wrong, but this was my understanding.
Making the IDFA opt in is now a second, stronger step towards user privacy.
[[UIDevice mainDevice] uniqueIdentifier]
It was deprecated in iOS 5. [1][1] https://stackoverflow.com/questions/227590/unique-identifier...
It's now just split away from IDFA. Basically Apple is using this to attack competitors while leaving their own tracking on by default.
Yes. Let's not forget about iAd and iBeacon, where Apple was traveling down the same road as FB and Google.
Once you've done that your app activity will be exchanged behind the scenes associating your data with your email or account so I'm not sure how many people this is going to really help.
IIRC Apple was trying to fix this hole too by having login via Apple give each app a different user IDs. Unfortunately that's not useful for the majority of people who need to be able to use non Apple devices.
The privacy feature of “Sign In With Apple” uses an email address for each service that you can use to access your accounts from other non-Apple devices, as long as the site implements a Reset Password process that accepts account email addresses (which virtually all do). The private email addresses are under Settings > iCloud > Apps Using Apple ID for apps where you hide your email.
I can use Apple devices and still have the need to use non-apple devices so Apple's solution isn't helpful.
What's uncertain here is whether each third-party will correctly handle this workflow. I can't decide if it's worked every time because I'm lucky or because there's a regulation somewhere in the Sign In With Apple terms that requires it. I respect that this uncertainty may not be acceptable to everyone.
Wish people who downvote would at least take the time to tell what's wrong with the comment. I don't mind being corrected... quite the contrary!
Can anyone provide more context on this event? Is it not odd that Mozilla would call on Apple to "increase user privacy" when one of Mozilla's main(most important?) partners is Google which is the very antithesis of user privacy?
Then further down the post states" >"That’s where you come in: We need a massive outpouring of support for Apple’s decision to help strengthen its resolve to protect consumer privacy."
While I applaud these efforts I'm curious how does Mozilla reconcile taking hundreds of millions of dollars from Google while taking this principled stance on Apple? This seems to be a bit of cognitive dissonance.
Reality: Commercial and free software has existed for 70 years and ad supported software only arrived in the past 20 years. The app/ software market will do just fine without tracking.
Apples been so focused on revenue recently this could easily be just a shakedown of fb.
Apple seems to believe it will drive market share, and I think that's better than them believing in the principle (since public companies are not principle driven).
In the end, given enough money (or lacking enough scruples) it will still be possible to track individuals as a service, but it'll be more expensive because it has been made difficult by 'privacy-first' initiatives such as this.
So that finally, only very very large companies and governments can really afford to do this.
What about Google? Is Google also unhappy?
As we’ve seen with websites even no unique id is not necessarily game over
https://games.greggman.com/game/panopticlick-hyperbole/
TL;DR they don't get enough traffic for the numbers to represent anything useful.
Normally devs want everything running as fast as possible, and just leave it at that. But the more closely the software tracks the underlying hardware, the easier it would be to finger print too. And this is one area where iOS devices might well be at a disadvantage for a straight forward "best experience" implementation, precisely because they've put a lot of effort into minimizing things that can interfere with whatever is in the foreground.
I don't disagree that the relatively small (and undoubtedly skewed from the general population) size of the EFF's overall dataset is a limit for them, but "I have no idea but it seems fishy because my iPhone should be identical because I say so" isn't an analysis.
I'm not sure how the "analog reality" applies here. The CPUs and GPUs generate discrete results, and behave identically two other chips of the same model. You talked about variations in performance, but is there evidence that apple does this with iphones? They could very well running them at lower clocks than what they're capable of, ie. the chips come out of the fab being able to run at 1.6-1.8ghz, but apple runs all of them at 1.6ghz. Finally, even if the performance variation is there, the difference will have to be big enough that it doesn't get drowned out in the noise or other environmental variations. A phone that has been in a pocket would perform worse than one that's been sitting on a desk, because it's probably 10 degrees warmer, which means 10 less degrees of thermal headroom.
>I don't disagree that the relatively small (and undoubtedly skewed from the general population) size of the EFF's overall dataset is a limit for them, but "I have no idea but it seems fishy because my iPhone should be identical because I say so" isn't an analysis.
But the eff site tells you exactly what they're fingerprinting, and they're not fingerprinting performance. What you described might be possible, but is irrelevant to the discussion.
They would lose me as a customer if they change, but I don’t expect them to do that.
Delicious.
I'll only sign a thank you like this when Apple allows other browsers engines on iOS, which is actual consumer-friendly behaviour towards the Web.
I'd rather have hardware and OS I like, even if I can't control some aspects of it.
Of course a hardware/OS I like and which I control fully would be the holy grail (if the tradeoffs involved, e.g. it being FOSS, and thus underfunded for example, allowed for such a thing). Absent that, somewhere in between there is a nice balance for each person/business case.
Most free software OSes I know about generally give apps lots of access to the system they are running on, which makes tracking a lot easier.
Librem 5 phone: https://puri.sm/products/librem-5
Pinephone: https://www.pine64.org/pinephone/
Apple your new friend.
State of the art data protection looks different. Mozilla ain't asking for help for that thought. How unfortunate!
I don’t know the answer.
But Apple is picking for me, that’s for sure.
Edit: good replies, fair point on the choice, from a personal perspective. We all know though that 90% will opt out or more. Without knowing they are making this very choice.
My theory is that, collectively, our privacy and attention is worth far more to other people that to us. Making up numbers, a company may pay $1 to show a targeted ad to you while you are reading an article. But there is no way that you'd ever pay $1 to read that article. And, furthermore, you probably see viewing that ad as a minor annoyance, not $1 worth of value.
I think if most folks had to replace ad money out of their own pocket in order to consume the content they like, they'd never do it.
They sure do. But seeing the majority out there does want to see ads or doesn't care about seing them, it's not like they won't get paid at all. And indeed that majority won't pay for content but there are others who do, and it's not impossible to make a living out of it: there are proper independent online-only news channels out there with no ads and paid by their subscribers (plus a bunch of government subsidies usually).
just like a la carte TV, I think we'd find out that is much more expensive than we know.
Assuming you mean Netflix and the likes: that is actually way cheaper now than what 'a la carte' used to be for me. 20 years ago when I wanted to choose what I looked at on a screen, I'd be looking at DVD rental because there wasn't much of an alternative here. Or maybe even not an alternative at all, don't remember exactly, but there was just cable TV and apart from standard channels you could get some extra (a porn channel, a sports channel), but that's still not 'a la carte'. Anyway: I easily paid twice what Netflix costs me now per month, every week.
I think they literally mean a la carte TV, like paying for the Showtime package, the sports package, the premium sports package, etc. on top of your subscription, or paying to watch a movie on Prime
Literally _the opposite_ is happening:
> Now, with the option to opt-out of tracking at the point-of-use, consumers won’t have to sift through their phone’s settings to protect their privacy.
On most devices these settings are buried so deep that almost no one knows that they exist. Android used to go as far as only allow you to _reset_ your token, instead of removing it completely, IIRC.
This doesn’t make sense. We’re going from a situation where users are completely blind to what’s going on, to one where they are informed and given a choice - and your framing is that somehow, this makes them less informed?
What actually happen is that I got vaccum cleaner adds all over youtube & friend for weeks AFTER I ordered one online from a (so far) trusted brick and mortar shop.
This is both creepily invasive and very inefficient targeted add.
What this is about is that the advertisers collect your habits and build a profile based on your behaviour which can be sold to further third parties, among which can be banks, government institutions... which can consequently affect your life.
No, they're giving you the option.
> Now, with the option to opt-out of tracking at the point-of-use, consumers won’t have to sift through their phone’s settings to protect their privacy.
> Apple [...] will give consumers the option to opt-out of tracking in each app
Apple is giving you the option to choose.
Does anyone actually think that Apple cares at all about the few thousand people that leave their name here? Did the people writing this article think that?