I also suspect that through browser fingerprinting that facebook can track everyone across the web anyway, particularly people who run a lot of customization on their desktop (O/S, graphics card, fonts, config settings, etc) that shows up in the fingerprint. If you're visiting sites which cause you to make requests to facebook servers you're leaking information to them, even if you've deleted your facebook account (and they can probably still track who you are).
This is an important point that raises the question of threat model.
For me, the threat is not "Facebook can track me," in the same way that my threat model doesn't include state-level actors. Because, let's be real, Facebook is as good as a state-level actor.
The threat is in showing me ads or content that modify my behavior. For this reason, I:
* Block facebook/insta at the DNS level * Don't have a Facebook account * Block all ads * Block all comment sections, like buttons, etc
I know this isn't something everyone can do. I know that there are tons of people out there who find value in Facebook. I just hope they are taking steps to at least block ads and are aware of when the platform is manipulating their emotions through targeted content, and have the sense to walk away from it from time to time. Perhaps that's asking too much, but I'm not going to stop making noise about it, not going to stop telling people they need to watch what they post / look at, because I think the platform is really damaging to people's attention and mental health.
For your grandmother -- I doubt it's making her buy stuff (fixed income) and I doubt it's making her turn to rage-tweeting about politics, so it's probably OK. And you're probably OK, too, being someone in tech who knows how this shit impacts people. But everyone else? I just worry, y'know?
mother. I'm old.
That said, I think the downside is still the walled garden. If Apple F/OSS their OS and let people modify it, and load applications outside the app store, I'd consider changing.
Until then, Lineage without Google apps is still a nicer experience than the walled gardens. For example, the Nexus 6 is still maintained (2014). It even recently got updated to 18.1 which is Android 11! Amazing.
Edit: Wow the Note3 and the LG G2 are still supported, too! They're from September 2013!
I view the walled garden as nothing but good. Build the walls higher. Hand me a brick and point me to the ladder.
And I'm fine with Apple siphoning off 30%. Make it 40%! I'd rather developers stop developing for iOS than to see any large changes in the App Store model. There are enough apps as it is.
While I don’t know the exact reason, this isn’t what’s happened on Android, which has always allowed multiple app stores. Everything mainstream is on Google’s Play Store, and quality FOSS apps get published to F-Droid. My theory is that users shy away from sideloading alternative app stores, even if it’s not very difficult to do so.
I don't think users would shy away from mainstream apps like Facebook if they moved to another app store platform.
The only thing a 3rd party store support will do is to ensure Apple couldn't abuse FOSS apps too much in their review process.
They could have all the same levels of security without the need to prevent competition.
Each app can track user behavior within the app itself, and can send this data to an aggregator who pays for it.
That way you are tracked across all participating apps.
This was common practice until Apple banned it.
This is false.
Apple can’t legally use Gatekeeper to ’reject’ apps which violate App Store policies.
They just need to time a new policy to a major release (say they make it apply only from that release on), and that would be no different then any other breaking change.
It wouldn't be popular on HN, but it's technically possible and legal. I'm sure that the Apple fans here will support it unreservedly.
> Nobody promised that OSX could run any software the user wishes.
In fact they have said this publicly in interviews.
> Does Apple steal software and "interfere with the business of suppliers" every time they break backward compatibility?
Apple doesn’t force you to install operating system upgrades, and many people don’t upgrade if it will break the software they work with.
>In fact they have said this publicly in interviews.
So I can sue them for not running Apple II programs? Cool! There were always programs that failed to run for some reason or another, and programs taken out of the Mac store, etc.
>Apple doesn’t force you to install operating system upgrades, and many people don’t upgrade if it will break the software they work with.
Sure, just apply a new rejection policy after an upgrade, and state it applies from that version on. That's what Apple would normally do anyway. So you're just admitting I'm right.
> So I can sue them for not running Apple II programs? Cool! There were always programs that failed to run for some reason or another, and programs taken out of the Mac store, etc.
No, you just don’t know much about Apple.
They haven’t promised to be backward compatible with everything, but they have promised not to stop you from running what you want to run.
I.e. they have promised not to do what you are saying they should do.
> Sure, just apply a new rejection policy after an upgrade, and state it applies from that version on. That's what Apple would normally do anyway.
Apple has never done this.
> So you're just admitting I'm right.
Obviously not. In fact you have proven yourself completely wrong, by acknowledging that they could not do it under their current license and with their current software and would need to get people to agree to a new contract.
Yes, Apple, (or anyone else) could offer a service for the Max that users sign up for to remotely disable software they disapprove of.
But that isn’t what you said.
Much of the security gained from having a single App Store is not technical in nature but rather reflects (conscious) security policy. This should be apparent. Fundamentally server people chafe at this but look at how much security work (and failure) goes into routinely running hostile code not written by you, particularly on the hosting side. Cloud providers have armies dedicated to the exact same security problems that app stores must solve and it is very often not good enough. That’s fine when nerds are involved but more people than nerds use phones.
This is absurdly false.
> The permissions settings are in the OS. They could have all the same levels of security without the need to prevent competition.
This is also completely false.
OS hardening can’t prevent fingerprinting or cross app tracking toolkits.
Those are prevented by policy and contract.
Having said that, google has no intention of waging war against facebook. They have an understanding already.
> This is absurdly false.
Forgive me, it's wget, a checksum check, and then install command.
This is absurdly false.
Stricter sandboxing makes it more difficult to fingerprint the user and lessens the burden and dependency on legal contracts and policies. Which is what Apple just did by blocking the access to unique device id.
You can accomplish even more by not installing their crap apps to begin with, and have always had that choice. You need google to save you from yourself and this is a compelling enough reason for you to switch phones, even though you're smart and actually know all of what's been going on and how to prevent it, but choose not to?
That being said, I've been tempted to get a Motorola Razr flip phone just for the sake of nostalgia, though I would have to root it and remove everything related to Google to feel comfortable with it.
I trust that Apple isn’t profiting off my data. It isn’t even close to their business model so it allows them to give their users privacy G and F can’t.
To give you an example, I recently implemented an allowlist on my firewall so only approved devices can access my WAN. I immediately started seeing frequent dropped packets from my wireless access point (Netgear Nighthawk AX200) and switch (Ubiquiti UniFi 8-port PoE) to Netgear and AWS IPs respectively. While some of that is probably them checking for updates, the volume didn't really seem warranted.
Going back to Apple though... sure, that's the exact reason why I switched. They already charge a premium, so they have less of an incentive to pad their quarterly earnings selling data. But they're still a company, still responding to shareholders, and they already collect certain amount of analytics. There's not that much of a jump from there to selling it, so being careful and mistrusting is probably a good thing IMO.
No need to pay someone to hold my hand in not clicking that button.
You don't really, though. Because who knows which applications listed in the app store have the FB SDK embedded inside.
There's no practical way for me to inspect every app listing that I might consider installing, to see if it contains the FB SDK.
OTOH it's sort of hard to live on FOSS Android software alone.
I'm very familiar with how advertising currently works, but the field is also one that seems to evolve quickly (no doubt why: lots of money to be made).
Am I smarter than all the engineers and startups and existing firms whose revenues depend on tracking? Most likely not.
The other more mundane reason is just I'm lazy and tired. I just want a phone that works without wondering about patching the OS or whatever. Maybe you enjoy doing that, I don't.
We don't live in an ideal bubble where I have full control over the tools I use. Its the same argument people make for video game moderation "if you don't like it, turn off chat" but then you're self-isolating.
Point is, this is a social problem.
Really I'd even consider creating a FaceBbook account if I could pay them not to use dark patterns. However I imagine there is already a shadow user profile of me, and Facebook is making making more money through sites that leak visitors' information than I'd be willing to pay for Facebook.
I just wish I didn't have to choose between control and privacy.
Heck maybe I should just give up on the entire concept of phones.
It would be hilarious if they actually started making more money because Apple forced their hand.
Could Facebook make it happen and profitable in a way to get around Apples rules? I think so... I think Apple would change the rules shortly after though...
AFAIK the rule is that users can subscribe to a service/product outside of an app and use their account's status on the app, but if the user wants to subscribe from within the app they need to go through the App Store subscription service.
https://www.statista.com/statistics/251328/facebooks-average...
($53 per US user)
If you are seriously considering paying for the poison that is Facebook, might I recommend you delete your Facebook account instead, and give your money to someone that needs it?
Now, whether asking users to pay for a social network at all is a viable business model, is another question.
0: https://drewdevault.com/2014/10/10/The-profitability-of-onli...
It's all petty landgrabs in the end, this is why I can't stand using MacOS. Can't Apple treat my computer like something other than a hostage for negotiation?
It's been done before. Remember in the 90's when thousands (millions?) of people got free computers in exchange for allowing banner ads at the top of their screens?
I like to refine this to say
"these user's attention is the product
How?
It opens up the perfect opportunity for some competitor burning VC cash to swoop in and grab a ton of market share in a hurry, with a free iOS app.
FB knows this, so yeah, it's a completely hollow threat. But, just the idea that one of the tech giants has been backed into a corner by the risk of competition from paying-for-marketshare VCs or operating-in-the-red-on-purpose other tech giants, is really, really funny to me. No fun, eh Facebook? Hahahaha.
Google had the search and moved upstream to own the OS and protect his search. But still has to beg Apple for 25% of its users (and 40% of its revenue, if I understand).
Content (films, instagram personalities) are at the mercy of apps; Apps, even on Heroku or Atlassian platforms, are at the mercy of the platforms; Platforms are at the mercy of cloud platforms (AWS, etc) who own the hardware.
The only counter-example is telecoms, who owned the hardware but became dumb pipes, after 20 years of extremely bad behavior (including modifying HTTP pages on the go and injecting JS to insert ads, for Verizon).
I won't be surprised if Facebook starts shopping for a phone manufacturer and spins their own Facebook mobile distro in the future.
Facebook could enter the actor/actress recruitment market, own contracts and manage their Instagram along all their artists’ public reputation and persona. It’s not hardware but at least it’s real-world assets that reinforce their network’s desirability.
Facebook could buy Homebrew or IntelliJ and become a tool that every developer for most languages need to use, and it would give it more leverage in negotiating with AWS/Azure (Oh, the SDK has bugs with GCP? too bad!)
Those are just examples that have not been implemented because they are half-ideas, but it’s the idea of attacking really sideways.
is this really the case? I know so many people who have the latest phones but the bank owns their house and car. lot of bling but empty pockets.