https://web.archive.org/web/20210316035745/docs.trackingio.c...
https://web.archive.org/web/20210316035745/docs.trackingio.c...
You can tell from the code that the "exploit" here is abusing keychain sharing.
iOS has a feature where you can pack a surprising amount of generic data into keychain storage, intended for passwords or auth credentials.
iOS also lets app developers opt-in to shared credential storage, so that if you have multiple apps, the user only needs to login once. Here's a blog post on how to do it: https://evgenii.com/blog/sharing-keychain-in-ios/
A little-known quirk of the iOS keychain is that it persists across app installs. This is useful because if multiple apps share credentials in the keychain, you don't want uninstalling one app to log you out of other apps.
If an American company tried this (looking at you Branch.io), would it be banned by Apple? Maybe? That seems to be the controversy here.
Perhaps Apple needs to rethink its keychain sharing API and make the user opt-in to credential sharing.
Also a keychain management tool would be nice, so users can see what data apps are permanently storing on their devices (even if the app is uninstalled).
And remember, any trick abused to create tracking IDs stands the risk of being detected and blocked by Apple in the next iOS update. It has been announced, it has happened, it will keep happening.
That's right, but it does allow persisting an id through reinstalls of the same app, and sharing that id between apps of the same developer.
> So no, this does not allow an tracking ID usable by all apps.
It effectively does though. For example, imagine a mobile game company with 10 games. With this technique, you can track that user across app re-installs in each of those games.
Now imagine another game company doing the same trick. If both companies send up their independent tracking IDs to a central server along with any other info they can get about the user (email, screen name, IP, whatever), then you can strongly correlate users across multiple tracking IDs. The user has no way to reset these IDs even if they delete and reinstall the apps using them.