Apple's privacy labels show WhatsApp and Facebook Messenger hunger for user data
techradar.com
techradar.com
https://www.macrumors.com/2021/01/05/google-hasnt-updated-io...
I really wonder why :)
And apparently iMessage has a privacy statement now, and it's much shorter than whatsapp's:
https://www.forbes.com/sites/zakdoffman/2021/01/03/whatsapp-...
(This is posted on HN too).
No big mystery there.
> iMessage has a privacy statement now, and it's much shorter than whatsapp's
Or there.
I wonder how effective these things really will be. Most people aren't going to scroll through these so the average person is going to ignore the everything below the fold. It's like the required disclaimers on medicines which people ignore. Once you get past the first few, nobody pays attention.
Once we have everyone actually publishing what they're doing it's a lot simpler to file complaints to DPA's and to verify they're actually compliant with legislation.
If they don't update the apps, do they have to update the privacy policy?
Whatever's already submitted stays like that.
Or perhaps we are back at Upton Sinclair: "It is difficult to get a man to understand something, when his salary depends on his not understanding it." and Facebook as an organisation is simply unable to acknowledge the problem, because doing so would ruin them.
Also, a more likely outcome would be Facebook charging $2 a month on top of their usual data collection practices.
Edit: tried to google concrete numbers what revenue was back then, could not find any clear answer, because it was doing some juggling with stocks etc. https://techcrunch.com/2014/10/28/whatsapp-revenue/
Most people don’t pay for air, therefore those people would be happy if their access to air was removed?
The problem seems to be that if competing services remain free, then users might start questioning the fee and eventually the base might migrate.
Really, while "free" internet services appear as if they are straight out of a post-work utopia, all they seem to be doing is trivializing the social cost of accurate and insidious targeting of groups jazzed up in sexy terms like "digital marketing" and "adtech".
Have you actually used cellphones? They're extremely expensive to actually communicate with, especially in the countries where WhatsApp is near ubiquitous (and we're talking within country, let's not even get into how horrendously expensive communicating with people internationally can be via regular cell service).
I really don't understand why so many people on HN are this adamant about trivialising the value that apps like Whatsapp provide.
I can easily envision a world where Facebook was a nonprofit along the lines of Wikipedia. Ad-free and supported by donations, the site would serve to connect the world (Facebook’s ostensible mission) without resorting to dark patterns or A/B testing for addictive engagement. I think there are plenty of wealthy people out there who would love to support such a site, if it existed.
Technology-wise, such a site could be built today, no problem. I have no idea what to do about the network effects that comprise Facebook’s moat, however.
Really, this must come from some utopian idea that company-founders really want to make the world better above else, but then profit-seeking—the modus operandi of all for-profit companies—intervenes just because the world is not pure enough for their vision.
It had explosive growth despite (or to some degree because of) the yearly $1 fee.
I'd happily also paid for my kids and a number of my friends to keep them on old WhatsApp, pre-Facebook, if they needed it.
Instead they sold out.
No, I'm extremely critical of many aspects of Facebook (and implicitly Whatsapp as an FB property, especially now) but to say they provide so little value based on how few people would possibly pay these amounts uses flawed assumptions. If people didn't pay it wouldn't be because they don't gain at least 1 or 2 dollars in value (many people almost certainly do, I certainly do with my own use), it would be because the model of offering high value for free in exchange for massive amounts of saleable user data is so lucrative that alternatives with free versions would quickly take over market share. In absolute terms, the use value of FB or Whatsapp to a user is often much more than 1 dollar per month, but compared to the ease of switching to someone who in the existing market again offers the same for free, it could quickly descend to less than 1 dollar.
Back of the envelope calculation suggests they make about $2 a month from each user (~$70B revenue/year divided by ~2.7B active users/month)
* Even if they didn't show you ads they have no reason to not still obsessively track you and monetize that data in other ways.
Long term, Facebook is dead. Perhaps internally they know that and are already planning for it.
Anyway, for reasons I don’t totally understand, in my experience this dad’s bunny-suit exasperation is how most people feel about paying for software of any kind. It’s not just frugality but indignation at the very idea that they be asked to pay for software.
Edit: there are approx. 1000 used bunny suits for sale on EBay, so...
I have met people who refuse to pay for digital music but have zero qualms buying records. Arguably the records have less use cases but they are YOURS and tangible.
1 - if it's like a Kigurumi (pajama), you can wear at home during winter, looking good/cute
2 - If you are female (can apply to males to maybe), Wear and post photos on instagram/twitter, make Only Fans/Patreon sets to make money
3 - if it flows your boat, wear during... you know...
I agree on 3, parents should get the kids real brick and mortar sex toys instead of the virtual DLC.
I really don't get this. Did you never buy a ringtone for your phone because you thought it was cool? Or some item of clothing that didn't serve a purely functional purpose. Do you not have any art or photos on your wall? I assume you still have your default desktop wallpaper and phone background.
Like I live my life surrounded by all sorts of random junk that brings me joy. How can you not?
If all users paid $2/month they’d be fine.
Problem is, not many people would shell out $2/month to socialize online.
This should help. I immediately bought the book.
https://www.wnycstudios.org/podcasts/otm/segments/living-und...
the point is, no one believes him, or really listens to him.
Its not Amazon where Bezos commands, and everyone jumps.
There doesn't have to internal coordination any more than FB has to coordinate with (e.g.) Google. Priorities drive action.
The mistake here is conflating price with value. The price people are willing to pay is relative to their means. The value, on the other hand, is relative to the utility they derive from it. Moreover, there is an additional external utility accrued to society from having a better educated, healthier population.
That was literally OP's point.
Most companies in this world choose not to willingly leave money on the table, and Facebook is simply taking the same position as millions of other businesses. The only way to get them to earn less than they could is by forcing them to do so through market forces (eg: iOS 14) or regulation.
Then we rationalize it by telling ourselves that we use it ethically. It's almost always true . . . except when it's not. If 99% of the time the data is used ethically, it's easy to write off that 1% even when the 1% is all that matters.
What a backwards analysis.
A social platform that is not already popular is worthless to most people. They have no use for it. Hence they are definitely unwilling to pay for it before it gets popular; there is absolutely no incentive to. And, of course, once a social media platform _already_ is popular, it must have gotten to that point by operating at a loss.
Forcing Facebook to clearly list all of this for the facebook account is great, but then failing to disclose this for their own account seems like double standard.
Just like having their own separate Ad Tracking switch which is on by default. (And even hidden under "System Services" on macOS!)
Unlike others os/phones where such things are turned on at every opportunity
Maybe I got to that state because I was being badgered? It’s been long enough though I can’t recall.
Might be worth a shot if the risk is acceptable enough to you vs the badger.
For me, it would go a long way towards seeing Apple as not just trying to leverage their platform to be anti-competitive, but as a company who is honestly protecting my privacy.
Some feature flags/settings across all the OSes get hidden, are non-obvious, on by default, or are flat out using dark patterns (looking at you Win10) but in general I assume the default state (for all OSes) is a combination of reducing support incidents, easiest on-boarding, and trying to push some corporate strategic objective summed up as keep the average user happy enough to stick around and possibly give us more money.
Any app I install on said OS, may want to access this information but without all the permissions explainers I have no idea what it’s going to want or why.
Again, I assume the OS has access to all of this because it’s the OS it either needs it or is the manager of the info and access broker.
To sum up my thought, I guess I agree that there’s a double standard but disagree that it’s necessarily bad or shady- but that’s because I already had a double standard in mind when I think about OS vs App.
Specific to ad-tracking and Apple: I have no proof for my belief but I believe Apple who primarily wants to sell me hardware and has made public acknowledgements of the importance of privacy, including making noticeable improvements to their OS, is significantly less likely to abuse my privacy than any other OS vendor out there.
I’m not saying this as a whataboutism, I just base it on my perceptions given all the things you just flat out can’t turn off in Win10 and that Google literally makes their money off of getting ads to your eyeballs and Android’s permissions are a dumpster fire nightmare for privacy.
I feel (again, no real proof) that the Apple eco-system is providing me the best _mainstream and low-effort_ steps to privacy protection vs the others, but I concede that it’s probably not good enough in many ways.
But do they bring all that data together, correlate it, and sell it?
"You want to advertise to 65 year old white people[1] in QAnon so you can pedal a very specific kind of fear? No problem."
"You want to buy access to black women under 30? We gotcha!"
That is what Facebook does which Apple doesn't.
[1] I know FB doesn't actually allow targeting based on race anymore. They do allow targeting based on interests though which can easily amount to the same thing.
If you choose to use iCloud to store your contacts (and you can choose any other service that implements the carddav standard) Apple declares the information is transmitted and stored encrypted and can’t be used for any other purpose.
iMessage can be MITM’d by Apple when requested by the government and you, the user, will have no way of verifying your correspondent’s public key (unlike whatsapp, signal, keybase etc).
it’s probably nothing to do with USA law enforcement. my reasonable guess is they don’t care much and would go full private. i think the reason here is china. that way they don’t have to have a separate china policy which would draw undue attention to that point.
No, what is constantly being brought out as a huge negative when talking about Google and Facebook is them using your data and data about you to make money.
If you do not want this to happen, do not turn on the optional iCloud backups.
But anyway, although Apple could decrypt the other data, they declare they don’t. Which is what the labels are about.
i like to call it end to end to end encryption. i came up with that for zoom but it applies to iMessage as well.
Maybe I misinterpret the idea behind this list.
To me, its not listing all the things that the company knows about you, its listing all the information that app reads about you.
In other terms, this is what Apple knows when I disable the iCloud and only use iMessage. And this is what Facebook knows when I only use it though that messenger and nothing else.
I understand what you’re saying. If the App is only collecting certain amount of information on its own, then they should only list that right? ... But that’s unfair with the rest of the vendors because they are forced to list everything they track, while iMessage obscures it by saying “the app doesn’t collect anything”...yet the phone is and iMessage is the default messaging system for iOS.
I’m a loyal Apple user but this is anti-competitive behavior. As much as I love Apple’s privacy focus, it seems that they’re using it as a proxy to unfairly compete with other companies and claim that they only care about the end’s user privacy, which is clearly not true.
Apple does and will use your data to push Apple products. They should be transparent about that.
Apple's News+ advertising empire? App Store advertising? Is there any evidence at all that they cross pollinate data in either of these contexts? If so, it certainly isn't clear based on the advertising I see in News+
Much of the stuff you are complaining about is "collected" because it's needed by other services. The real question is whether the data is reasonably siloed and how easy it is for Apple or third party's (governments, etc) to access and abuse.
Explain how?
I _do_ like these labels, I think they are good.
but
It is dishonest to say the least that imessenger only has access to just those details. To use imessenger, you need an icloud account.
Tie that to the location services and any payment information, Apple knows everything about you, even more than FB.
The issue is about trust. rightly people don't trust FB with their data. However I don't think we should be letting apple off so lightly, especially when they are pointing the blame at other people.
However, are we sure that Apple, in 30 years, will be the same proponent of privacy that they are today? Even if there's a 10% risk that they won't, they'll have your same data then that they have now.
Strong encryption with user-owned keys is the only way you can mitigate against this scenario. I'm optimistic that we'll get there eventually, but we aren't there yet.
That sounds like a familiar business model.
Granted I pay for an email service that could similarly abuse me.
I think the goal should be to create services/software that make it impossible for a company to abuse people, so we don't have to rely on their word, or have to worry about them changing their word later.
I don't give facebook my health, location or payment details. Apple gets all of that and extracts a fee.
I don't give a shit about advertising, advertising is always about the aggregate.
What I care about is someone getting access to my data directly to do something with it. For me, my main fear is hackers and corrupt insiders.
Facebook is going to spend the next five years transforming from a naive company that is/was loosey goosey with peoples data, to I suspect a fee extracting privacy first AR platform. You might laugh, but look at microsoft, look how they have changed.
However once you've got someones email or phone number you can ultimately tie it to any other data when you've used it elsewhere - medical records, phone calls to prostitutes, hacker news posts etc.
I think the difference is that Apple don't (or claim to not) use that data to categorise you and serve ads like Facebook. Apple make lots of money from hardware sales, a few cents from aggregating data is a drop in the ocean and they can take 'the moral highground' towards privacy.
Do you know what's the problem with God?
It would be better to be explicit: if it were not for the Apple 800 lb gorilla holding the Facebook 800 lb gorilla's feet to the fire here due to its self-appointed role as gatekeeper of the iOS App Store then this information would remain hidden from general consumers.
Google searches turn up stuff like this: https://www.zdnet.com/article/apple-data-collection-stored-r...
This must be handled correctly as it can this also lead to privacy violation.
Question is will this be ethical .. I will not be comfortable using a device that logs every API an app on it is calling.
If apple didn't restrict the OS so much, you'd have people making their own Facebook clients, wouldn't have mattered if Facebook liked it or not. The monopolization of Facebook's control on personal connections is partially because of closed OS's. And Apple's iOS is one of the most responsible OS's that gave rise to Facebook's data monopoly.
Had it been like Windows, there wouldn't be a way that Facebook could've maintained their monopoly.
The the answer is: a competitor could build their services on top of Facebook. They wouldn't have to start from scratch. Independent client's mean if the one user trusts you with their data, you can provide them a bigger value.
Today you cannot innovate on top of Facebook. Their network effects mean if your service is superior, you need to beat the network effects first.
And Facebook cannot reasonably offer independent access because: Cambridge Analytica.
Independent client's do what they want without Facebook taking a hit on their reputation. No one blames apple for the crimes committed using their phones/computers do they?
Hypotheticals can be argued either way but it’s just one possible option, not the only one.
Imagine if adblock wasn't allowed on those stores. Today the equivalent is alternative clients to Facebook not being allowed on iOS and the App Store.
Look at YC startups like motion being built on top of the web. They are building on top of the network effects of gmail/google/facebook/slack etc. We aren't allowed any of that on mobile. Had they been allowed more access to the mobile OS's, they could be a very successful company. We haven't even touched the tip of cross OS productivity integrations.
Like which ones? There's the AppStore, the PlayStore and that's it, nothing else is even worth being mentioned in terms of market share.
That didn’t happen before the App Store and isn’t happening anywhere else after the App Store either.
Instead it's probably more likely that FB would host Messenger and Whatsapp clients on their own app store with all the details hidden somewhere in the user agreement.
You're totally wrong on this. In fact, the first alternative FB clients I remember using sprang up on the iPad, before FB bothered to put a native app out for it.
What killed alternative FB clients was FB itself -- they've slowly closed off the APIs you'd need to access to make an alternative client optional. FB has also closed off their own alternative clients as well (FB Paper), and have been forcing users into their official web or native clients for a while.
How long before they ban ProtonMail because "You know what, we think our emails are "better for you". How long before they ban Signal because "You know what, IMessage has a better security than signal so it's "better for you".
Monopoly / tech dictatorship are the easy and tempting solution but nothing good ever came out of giving some dude total power over you. And even if you like those dude because you buy their propaganda, many other people might not share your view.
"We and our store and/or access information [...] and process personal data, such as unique identifiers and standard information sent by a device for personalised ads and content, ad and content measurement, and audience insights [...]
With your permission we and our partners may use precise geolocation data and identification through device scanning. You may click to consent to our and our partners’ processing as described above. Alternatively you may access more detailed information and change your preferences before consenting or to refuse consenting. Please note that some processing of your personal data may not require your consent, but you have a right to object to such processing."
I can then click "MORE OPTIONS" to enter the deceptive dialog, where you think everything is off, but really everything is hidden under "LEGITIMATE INTEREST" (another one of my favorite sneaky phrases). I don't know how you can really turn the tracking off.
Tracking in every form but the anonymous, opt-in, and truly optional (no restrictions (other than the obvious) if you decline) in not acceptable.
Have you tried clicking through those deceptive dialogs and have you seen the list of "trusted partners" that will receive and gather tracking data about you?
Do you at least know roughly what the number of those "trusted partners" is?
Take a look, it could be an eye-opener.
Install a good ad blocker like uBlock Origin. You may also want to disable third-party cookies for good measure.
It comes full circle...
[0] https://apps.apple.com/us/app/lockdown-privacy/id1469783711
https://www.forbes.com/sites/zakdoffman/2021/01/03/whatsapp-...
Also until iMessage is available on other platforms, what it slurps or doesn't slurp is academic for most users of WhatsApp.
Besides, China should not be your model if you care about privacy.
Same as an app may need disclose it can use you mic, but it only does it if you use specific features. (The model for such permissions used to be before installation on Android and improved over time, and perhaps something similar can be done for data collection permissions as well)
Right now, more features, whether you use them or not, will have their data collection appear on this screen, without context. So while these labels are a welcome addition, they can also be scarier than reality.
I think most WhatsApp users see WhatsApp like this and I'd guess article's authors assumed the same.
* Third-Party Advertising
* Developer’s Advertising or Marketing
* Analytics
* Product Personalization
* App Functionality
* Other Purposes
The features you mentioned would fall under "App Functionality" and as you imply it would be legitimate. The reservation with Facebook is all the data they collect for the five other purposes. In my own analysis of thousands apps[0] I explicitly excluded data collected for app functionality purposes because of this. FWIW most of Facebook's app collect 128 data types(by far the most of the ~5000 apps I've analysed) across those five purposes, WhatsApp collects only 18.
0: https://hugotunius.se/2021/01/03/an-analysis-of-privacy-on-t...
Now Apple has its own ad infrastructure, and this is a perfect strategic move by Apple.
However I have to ask, will this become another surgeon generals warning or calorie labeling of restaurant menu experience? By that I simply mean, people will not only click through it but also accept it as they don't see any real cost.
Eventually as with everything presented under dire warnings you drown your audience to the point they tune it all out and go right back their blissfully attitude of just accepting it under the guise of its not going to matter
This is why we need opt-in instead of opt-out as default.
https://exodus-privacy.eu.org/
https://f-droid.org/packages/org.eu.exodus_privacy.exoduspri...
In the EU (and UK), it's some fairly minor changes to do with business messaging.
Outside of the EU, it is much more significant, merging your WhatsApp data with your Facebook data (including the phantom profiles FB create for users who don't have accounts). They can't do this in the EU (yet) due to privacy laws.
MSFT and GOOG have been doing this too for years ofcourse.
While GOOG has had to be content only with what they can read from emails/calendars, texts, web searches, calls/voicemail, maps/location data and anything else that they can scrape from an Android device.
MSFT has had all of that a much, much more since they own the whole OS for workstation/server class devices where actual work gets done. MSFT will claim that all that data is for quality control and now security services but ofcourse they are going to squeeze every last drop of money they can from it. To expect otherwise would be like asking an alcoholic to guard a brewery and never sample the product, completely ridiculous. The US has no serious legal repercussions for doing so. Probably because the US intelligence community depends on that data since IT is forbidden from collecting it from Americans on its own.
Gee, I wonder why...
And the comparison to imessage is a bloody joke. You already paid a shitton of money for your iphone, they don't need your data for anything
Fucking yes! This should be the default. The default should be pay, with a free option that requires you to dump truck all your data.
Tech giants have completely ruined the internet economy. You can’t even pay for these things now. It’s just hand over all your data and secrets, or fuck off.
And the worst is that new businesses can’t compete unless they do the same. You can’t compete with free.
It should just be default to not collect unnecessary data, whatever that may be, while being free. Maybe make paid plans with premium features. Everything else will just mean that Big Tech can spy and manipulate poor people, because they can't afford to pay for every service they (have) to use. We should stop tying privilege to money.
Maybe I'm being too dramatical, but that's what came to my mind after reading your suggestion.
Moreover, paying for goods and services is how the economy works. Netflix does not have a free tier. Are they fucking over poor people?
2) It's not wrong, not to have a free tier. It's not wrong to have paid plans. What I think is wrong, is defining that surveillance should be the default. Give me the option to disable analytics etc. completely. Tying this mechanic to money is wrong. You shouldn't have to pay to not be spied on.
You do realize that this type data collection is almost always in service of displaying ads, in some way, to users, don’t you? There’s been reports about FB working to add ads to WhatsApp for a while now [0].
[0] https://www.techradar.com/news/whatsapp-could-be-getting-ads...
"Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple"
- If you want to hold the keys to your backups and set up the system to be private, you have the option to do so, and are presented with that option at the time the device is set up (and you are also presented with the option to use a local backup to restore or set up a device). The implications of the choice to use a cloud backup should be made more clear, though.
- For the vast, vast majority of users who don't have good backup hygiene, having someone else manage backups and hold decryption keys is a good trade-off, considering that the alternative is total data loss.
They don't need to. You identify yourself within the app with your login.
> It says Imessage can link to your device id
While iMessage is vulnerable to (certain) MiTM attacks, and storing your message archive in iCloud is (was ?) unencrypted, iMessage is surprisingly resilient to attacks (on the protocol itself).
Every iOS/Mac device generates it's own key and uploads the public certificate to Apple's keyserver, this is why they need your device id.
When you send messages with iMessage, your device then contacts Apple's keyservers, gets ALL public certificates for the recipient, and encrypts the message once for every key, and sends an encrypted message per device.
Attachments are handled a bit different. Insted of encrypting the attachment n times, a new key is generated, which is then used to encrypt the attachement, the encrypted attachment is uploaded to Apple, and the key is sent using normal iMessage messages (encrypted)
Your private keys NEVER leave your device, so iMessage is end to end encrypted as long as you don't enable iMessage in iCloud.
I said that iMessage was vulnerable to MiTM attacks, which it is. There's nothing stopping Apple from adding a "shadow" device to your list of devices with it's own set of keys, which would then receive a copy of every message sent to you, and that's probably how iMessage in iCloud works, but they have no way of retrieving your message history from before the shadow device was added.
There's a somewhat recent (2016) paper on it here : http://www.cs.tufts.edu/comp/116/archive/fall2016/xshi.pdf
By that logic even whatsapp/facebook don't need anything apart from login. So why do they collect all the other stuff? Signal is making an effort to make do with the minimum amount of data.
> While iMessage is vulnerable to (certain) MiTM attacks
Apple doesn't need to MITM Imessage. They own the app, service, and devices on both sides. That's why it's silly to compare it with whatsapp/facebook.