Facebook still ‘secretly’ tracks your iPhone
forbes.com
forbes.com
Now that this vulnerability has been identified, they can fix it and solve the problem for their users.
So how can it reflect badly on their case?
The way it reflects well, is to notice that this is a small hole in their privacy measures which can easily be fixed, and the only reason we are talking about it is that for the most part their privacy controls work well. I.e. it demonstrates their seriousness about privacy.
Because these privacy violations are happening despite their locked down App Store.
> The way it reflects well, is to notice that this is a small hole in their privacy measures which can easily be fixed
Sure, it reflects well on Apple as a whole, but not on the app store. This issue is just as easy to fix for sideloaded apps because it's related to OS level permissions which sideloaded apps would still be subject to.
> Because these privacy violations are happening despite their locked down App Store.
That’s an obviously false comparison. You are comparing against a perfect world, not against the real world.
A valid comparison is against what privacy violations would be happening without the App Store.
As a simple example, we know for certain that Facebook would be a doing a lot more tracking without the App Store, because they have told us in public that they would.
Therefore the App Store is in fact protecting users against large categories of privacy concerns, and this easily corrected hole doesn’t change that.
No I'm not, I'm comparing against a world where Apple allows sideloading, and this privacy issue exists in both.
> because they have told us in public that they would.
Source? Apple's new add tracking opt-in thing is on the OS level the same way this location tracking issue is. It would still work if the Facebook app was sideloaded from what I understand.
You can trivially check this yourself.
> Apple's new add tracking opt-in thing is on the OS level the same way this location tracking issue is.
This is a complete misunderstanding of how it works. Apple provides a mechanism for apps to use to identify users who opt-in.
The only thing preventing developers from just ignoring this and using fingerprinting or other identifiers is the App Store rules. A whole bunch of apps have been banned or otherwise forced to stop doing this.
€ It would still work if the Facebook app was sideloaded from what I understand.
No. If the app were sideloaded, Facebook would just implement a fingerprinting solution or provide their own identifier, and ignore Apple’s mechanism.
I could not find any quote like this..not sure why you think it's so trivial to find.
> No. If the app were sideloaded, Facebook would just implement a fingerprinting solution or provide their own identifier, and ignore Apple’s mechanism.
You mean like how they ignored Apples location sharing mechanism and maliciously opened your photos to read metadata?
Or the one a few years back about playing silent audio tracks to stay open in the background?
You won’t find a ‘quote’, but it it’s trivial to educate yourself on this mechanism. E.g. Apple’s documentation. Various articles about ad tracking transparency, etc.
If you haven’t read the technical materials about the subject, why do you claim to understand it?
> You mean like how they ignored Apples location sharing mechanism and maliciously opened your photos to read metadata?
There is no rule against reading the metadata. Yes it’s malicious, but Apple doesn’t currently have grounds for removing the app. The correct solution is to stop leaving the metadata in the file.
> Or the one a few years back about playing silent audio tracks to stay open in the background?
That one was indeed solved by a rule change.
But why do you mention these?
Presumably to support your claim that sideloading would be no different from the App Store when it comes to privacy.
If you understood the mechanisms, you’d know this was false.
It’s not an ad hominem. The commenter made a false assertion about how the mechanism works, which is easily checked.
I’ve pointed to where they can check it. The App Store rules, and apples tech docs. There are also other articles with background.
> If it is true that iOS’s permission model is done on the App Store level and not the OS level, which I doubt by the way,
So you don’t know how this works.
> then that is a flaw on Apple’s part and should be fixed. Otherwise we are relying on arbitrary App Store rules to protect our privacy and security,
That’s exactly what many of the App Store rules are for.
> instead of baked in constructs in the OS.
They don’t rely on the App Store rules ‘instead’. They rely on them in conjunction.
It’s not as easy as you think to rely on baked in constructs in the OS.
A trivial example is that such constructs cannot detect text that lies to the user about why a permission is granted.
Another example is that such constructs can’t prevent an app from communicating with a fingerprinting service or using a
These have to be done by policy.
> I’m skeptical that Apple would do something so shortsighted.
Not really sure what to make of this comment, since you don’t present an accurate model of what Apple is actually ‘doing’.
Why would you think that?
Anyone following this would know that Facebook said this. They took out a full page ad in the New York Times.
>Not sure why you're referencing Apples docs for Facebooks supposed comment..
The reference to Apple’s docs is about the tracking mechanism which you wrongly claimed worked like location tracking.
It doesn’t, and you can check this in Apple’s docs.
> You can trivially check this yourself.
> You won’t find a ‘quote’
You're backpedalling and it's really unclear what you're talking about, leading me to assume you're making it up or misrepresenting something.
If it's so trivial to find why can't you produce it?
They have.
>> You can trivially check this yourself.
You can.
>> You won’t find a ‘quote’
You won’t find a ‘quote’ - that was your word. We’re talking about a technical and legal mechanism here. You will find documents. I’ve told you which ones.
> You're backpedalling
Clearly not.
> and it's really unclear what you're talking about,
That’s because you haven’t taken the steps needed to understand.
> leading me to assume you're making it up or misrepresenting something.
That’s and unfortunate and incorrect assumption. You can check but you choose not to.
Perhaps it’s not trivial for you to check this. Maybe you are unable to make sense of technical and legal documents for yourself. If so, I am sorry to have assumed that you could.
> If it's so trivial to find why can't you produce it?
I have told you where to look. It doesn’t seem like you want to. Perhaps you are unable.
The only difference is their size and capability to retaliate as compared to any other App developer.
Here's a thought experiement: If Facebook were malware, could you get rid of it?
Malware is any software intentionally designed to cause damage to a computer, server, client, or computer network. A wide variety of malware types exist, including computer viruses, worms, Trojan horses, ransomware, spyware, adware, rogue software, wiper and scareware.
Most advertising behaves like spyware for targeting purposes. It would be fine if it was consensual, but it's basically never the case.
> scareware
This is more about the ad's content than the concept of advertising itself, but online advertising is essentially the wild west and advertising platforms happen to get away with serving misleading ads that use scare tactics to get the user to do something against their best interests (sometimes even downloading actual malware).
As for me, I would use an alternative platform in a heartbeat, but all the privacy focused ones so far have not gained any traction.
Clearly most people aren't aware of that (nor are they happy with it) given that some people even have the impression that Facebook is literally listening to conversations.
In this case, they could very well be transparent about it, and comply with local laws/regulations (such as the GDPR).
When companies comply (or Apple forces them to - like with App Tracking Transparency), it's clear that the majority of people do not consider this a fair deal and opt-out.
"Facebook invades privacy" is still a minority opinion among their user base (whether we like it or not).
Apple has been aiming to become that product, because I've said before that Apple is primarily a privacy company with a bunch of entertainment features. It also means that competing with Apple isn't about design, it's also mainly about providing privacy. Their whole recipe is the complementary packaging of the two orthogonal concepts of entertainment and privacy.
I should start the next Apple.
Now, I noticed a weird behaviour. I am not sure if its a 'bug' due to jailbreak, or if it shows how apps can access location.
The setup is as follows: location services are completely deactivated system-wide. a spoof location is set.
This means, I am not able in any way to access/share my location, neither the real nor the spoofed one.
However, when someone shares a location with me, upon displaying it on a map, instead of the location shared the spoofed one will be displayed along the correct address of the shared location.
ok, i dont know how iOS manages location services. still it is not nice at all to see that somehow an app can access a location, even if its spoofed and by error.
regarding the article: you can tell your phone not to give fb any location data. but why would you take a picture with location data and upload it to facebook? its so obvious and straight-forward that the user simply undermines his own privacy.
It wasn't 6+ months later that I realized audio was also embedded in live photos. I just never noticed because my phone is always on silent mode.
The realization that I was sending audio clips to friends and family along with photos for months and month was... unnerving.
It's a problem when tech becomes so complex that the average (or in my case, even the above average) tech user can't keep up.
Whenever a video comes up that could play audio, it is automatically muted and a UI element appears for the user to unmute it. This means that I know if a video has audio along with it, even if my phone is on silent. It has the added bonus of not embarrassing me in public if a loud video comes on.
I'm not sure if this feature is turned on by default, but it's just a neat solution to this problem that I think it should be.
[0]: https://play.google.com/store/apps/details?id=free.reddit.ne...
If you take an image with a GPS enabled camera, yes that information along others can be saved as metadata.
Sure, tech companies try to abstract the functionalities, making it more difficult to see and understand. Still, this can not be an excuse to just do things not unknowingly.
Photo geolocation metadata has legitimate uses, the problem isn't that the metadata is there per-se but that it's being used for nefarious purposes without the user's knowledge nor consent.
You could argue that most people don't know the location data is there. But at the same time, if you're doing something you want to keep secret, you probably shouldn't be uploading pictures of it to Facebook anyway.
If you don't have an issue with Facebook then disregard and continue using their services. If you do have a problem then try being the change you want to see. Tend your garden. You cannot control other people but you can control yourself.
Being the change you want to see doesn't automatically mean the world changes. It just means live with principles regardless of external factors. You don't like Facebook? Then don't use Facebook. It's as simple as that. Others can take it or leave it.
I just see it as people complaining about Facebook while continuing to use Facebook so it must not be a very big deal to them.
2. Lead a movement to switch away from these apps. This has an insanely high overhead, and requires significant organisation of people and a large individual commitment. This would have a significant effect on Facebook.
This is how I view the problem. This is not an example of people being unwilling to act on their ideals. It's a situation where acting on their ideals would cause them a significant burden with no effect, and causing the intended change would require ridiculously large effort.
This is irrelevant to me and can be left out. My goal is not to hurt Facebook but to not betray my principles.
It’s hard though, because what alternative do people have?
I didn’t log in to my Facebook account for 7 years, and I got way out of touch with most of my old friends in different cities.
Sure, occasionally people get frustrated that you are not on these platforms, however I ended up being lot more responsive and attentive to non social media forms of communication. Social media is usually low effort, I rather have one person wishing me with personal email on my birthday, rather than hundreds of meaningless FB posts.
It was actually harder for business contacts than personal, customers want to chat in whatever works for them, harder to say no to someone paying you. However Teams/Slack has helped a lot and dose of compliance reasons which customers find easier to go along with.
Deleting the Facebook owned applications from my phone would achieve close to nothing positive. I may convince a few family members and good friends to use another application only for me, but I will lose a lot of relations and Facebook wouldn't care. However I also did work in small research studies to expose to everyone the bad practices of some companies about privacy. It's not much but it helps when our governments make laws such as the GDPR.
Even if SMS is expensive, email is still quite free. It works almost like SMS/messaging on phone, you get push notifications on your phone and you respond.
I move around about countries every few months, keeping a VOIP/Skype phone number as the number anyone can reach you at works for me, while my local number is more for getting an internet connection and occasionally for signups to local apps (like rideshares, food delivery etc) that reject some VoIP numbers .
See Beeper (bridges to various chat apps based on Matrix.org): https://news.ycombinator.com/item?id=25848278
I agree that FOSS doesn't solve all ills. It's a necessary step, though.
Everything is closed source, and you have no idea what is running on their servers, etc, so all your suppositions are worth basically nothing.
But a MITM should still be visible
More details?
https://www.aljazeera.com/news/2021/1/26/iran-blocks-signal-...
Q: Why would Iran block Signal but not WhatsApp if they actually use the exact same protocol? A: Because Facebook has cut a deal with the regime to give them access to things they could not get access to with Signal
I suppose it could be that blocking WhatsApp would cause too much disruption, so the Iranian regime tolerates it for now, but I put much more weight on Facebook just rolling over.
There are other instances of WhatsApp being allowed and other allegedly as-secure platforms being banned. It could be chance or network effects, but my guess is that Facebook has built in tools to comply with those regimes' spying demands. Perhaps they even push locale-specific versions of the app.
It’s probably done on the device, with suspicious links and media sent to the servers for further inspection.
We are also sure some of their engineers worked on methods to detect bypasses on the checks.
It’s a leak of data and metadata, a privacy invasion for sure, but not comparable to a MITM.
Why do you believe them?
Even if you put in no personal data to FB at all they create a ghost profile that will be very accurate based on who you are connected to.
Good thing that Beeper lets you self-host their (AGPLd) bridges.
Legally, I’m not sure how you can have it both ways, aside from either FB offering a paid tier (you pay cash instead of providing your data), or we shut FB down entirely.
What exactly do you believe is the solution?
Personally, I think social media is more harm than good. I don’t want to ban or control social media companies (my local officials aren’t even capable of keeping drugs and homeless addicts off school grounds, let alone dictating internet regulation). My personal choice is to not use it.
EDIT:
> And There’s FaceTime if your far from friend. Stop relying on Facebook to connect you…
I'm not even sure to describe how ignorant this comment is. Even if I stop relying on Facebook to connect me. Now I'm relying to Apple to connect me? Am I supposed to tell me friends that because I don't use Facebook, they should all buy an iPhone to connect with me?
Is phone and SMS considered 'difficult' now? Everyone I know simply uses SMS and phone calls.
I suppose if you have globally distributed friends groups, this could be difficult, otherwise I don't see why. You give up a few features and it's not the most secure but it's a viable alternative almost everyone has access to.
Plus, phone calls are quite different from general text messages. Messages allows anyone to reply on a time they’re free for it.
So in general, yes, SMS is considered difficult, in my situation.
The main thing that WhatsApp and Messenger gave me was the ability to stay in touch with anyone I knew, wherever they lived. SMS just doesn’t cut it; huge fees and no groups. There’s really no alternative.
It is kind of funny as every Andriod or iOS phone user effectively gets an email account as part of their access to the platform so it not like this generation doesn't have email.
Also everyone uses email for app registrations, bank accounts and for some formal communication so it not like they don't know how to use either.
It seems we have forgotten that we did live abroad and kept in touch via tools with no vendor lock twenty years ago, telecom (SMS/phone) was lot more expensive then as well.
Ultimately use what you like if you find WhatsApp more useful sure, however forcing a vendor locked in platform on to others I find is incredibly rude.
I am not forcing you to lock into a vendor when I call/SMS/email you.
I haven’t forgotten the days of SMS/email, it’s just that instant messaging made things a lot easier.
If you want large groups/numbers of people to do something, you have to make it as easy and frictionless as possible for them.
fill it in with alternate contacts
start using those contacts to reach out
wait until they switch too
???
profit!
I do have a few members of the family on Signal already though. They're just the ones that don't mind giving up stickers and the nice interface
About the time they added stickers, and message replies my friends group chats switched over.
I have no doubt signal will catch up though.
Family and friends adapted, most without prompting.
I'd say try it but be prepared for an ego check if nobody follows haha
I can't even figure out how to use it from my mobile device without installing an app.
I believe that's deliberate. The mobile web version of Facebook used to support personal messaging. In 2016 they removed it in an effort to push people onto the app.
https://techcrunch.com/2016/06/03/facebook-is-disabling-mess...
Going to https://mbasic.facebook.com/messages gets me the following:
> Your Page's Inbox is not currently available in the > Facebook app or mobile web browsers. You can access > your messages through a desktop browser, or by > downloading Facebook Business Suite or Messenger > from the app store.
In one comment on HN[0], a user suggested:
> You may need to access the page by clicking a link > from another mbasic page in order to have some kind > of checksum in the URL.
Another user replied that they were able to get access to the page with that method[1], but I haven't been able to replicate it.
[0]: https://news.ycombinator.com/item?id=25402316 [1]: https://news.ycombinator.com/item?id=25402354
It even has some extra features, like LaTeX support.
I guess you mean it doesn't work on mobile browsers? (Never tried that)
They removed that feature at the time their last big messenger outage happened.
messenger.com still works on Android Firefox as long as you switch to desktop mode.
Not sure for how long though, as it looks as if they are constantly sabotaging their platform. ..and it shows: Facebook Messenger feels far less relevant than maybe ten years ago.
In my German peer group everyone now uses either WhatsApp or Signal for private and Teams+email for work related communication.
It’s basic (like it says on the tin) but it works. I use it to avoid having to install the app, for all of them reasons discussed.
my proposal is more radical. rally to ban FB in that country. incentivize local companies to come up with alternative solutions.
zuck and his comrades have no business poking their noses into foreigners medical data anyway. it would also avoid less taxes being lost on facebooks Double Irish tax evasion. treat them like the cancer they are. don't celebrate FB engineers and call them out for the useful idiots they are.
Living in a country where local social networks are more popular with general population than foreign ones (Russia), I'd rather prefer FAANG. "Local companies" may sound good because the word "local" has some nice connotations, like your "local store" or "local coffee shop". But in reality, "local companies" do all the bad stuff that Facebook does, and also go above and beyond to cooperate with the state against the protesters or any political dissidents. And they're also not as good at writing software, so these networks have significantly worse design and a lot more bugs.
There are millions of example where people want to solve a problem, think that they will be able to do it with government regulation, and end up with a situation that is much worse. But even among them, this is a case where it could only make situation worse. And much, much worse.
Meanwhile, here in the real world, let's stick to the better one of the bad choices we have.
This is the basic idea behind zero-knowledge systems using homomorphic encryption to do very cool things.
One reason is because a lot of phone plans include few or no calls/SMS but include unlimited Whatsapp. When one app is completely ubiquitous in a society and free, people will simply not understand why you want to do something a different way and will often wonder if you’re trying to scam them.
I do not like that Google get to know when I need to visit the hospital, or collect information about my children's activities in school. But currently we do not have an option.
we 'd be truly screwed if crappy WA would be adamand for such in any given country, even Putinocchio's, Xi's or KJU's. that country 'd be even more crappier than WA, and all FB-associated, which in turn would be quite an achievement on quite a, literally and metaphorically, negative scale in its own right
Can't change my profile picture in the Messenger app though, so would need to reactivate if I felt the urgent need to.
I sure hope so. The EXIF data has to be part of the backups, it's important data.
The issue is that you are telling Facebook to not use your location data for marketing, then they are finding out your location via another method and then using it for marketing (based on a loophole in their privacy agreement).
(Non ad location business: hazard profile based on where you hang out. Frequency of pub visits may impact your life insurance rates)
I have much more faith in a company staying true to the latter. Not 100% faith, because their assessment of what business model to pursue can change, but it’s certainly not comparable in flakiness to corporate idealism.
It’s a matter of expectations: You’re handing your data over to Apple for them to back it up; You’re sending photos via Facebook to share it with friends, and location data isn’t shown anywhere.
The false equivalencies in this thread are almost overwhelming.
That’s why I back up mine to a NAS in my house and have that send encrypted backups off-site.
That's surprising. Facebook has a global reach and can run on damn near anything with a screen. I'm surprised iOS makes up such disproportionate part of its revenue.
The problem is that Facebook's business model is to sell out their userbase to the highest bidder, and the bids are significantly higher for iOS users who are considered good marks for ads compared to some generic feature-phone users.
Like mentioned in the article, there a lot of EXIF strips in Appstore too but I’m not sure if a regular user would take the road of take photo > go to exif stripper > delete exif on photo > save the photo > go to facebook > upload to facebook
I think the better option is:
(1) Make it obvious when location data is being included with a photograph, and exclude it by default - especially if the app doesn't already have Precise Location access.
(2) Apps that manage your entire photo library and all its EXIF data (think Amazon Photos / Google Photos, or an app to bulk import photos from a DSLR camera or something) should have to apply to Apple to get that specific entitlement- and social media apps should not qualify. But in this case, they shouldn't need Precise Location access to get access to all the EXIF data.
Personally, I use a Shortcut to be able to share photos without metadata. It works very well. It's the one included with iVerify, but there are free ones in the Shortcuts library.
Facebook would like to access your photos:
Select Photos
All Photos
Strip location and other metadataThe manage photos screen in apps does say metadata is included, but doesn’t yet give an option to strip it.
I believe the issue lies in giving apps permission to access photos directly. This bypasses the share sheet and you never see this option.
Then again, I don't use facebook and I do strip exif if I want to upload a photo somewhere I don't want to share my location. (and I can do this with termux and the same tool I'd use this on my PC, just run exiftool -all= foo.jpg)
I get that it is not a sensible solution for the average user. But the problem is not exif-tags. It is facebook and the current ad ecosystem.
On android a file-picker that could optionally remove exif-data when a file is chosen seems like an easy workaround for the time being.
Apple should update the photo permissions to allow enabling or disabling access to metadata as well.
Settings.app —> Privacy —> Location services —> Camera
and turning off the “precise location” option for the Camera app that way.
It would be ideal if there were an “EXIF data” toggle in the Camera section that could allow sharing pictures with apps but with all metadata removed.
I'm not shilling for them but just wondering whether some of these results are a direct consequence of the nature of the systems rather than nefarious design
A quick look at their privacy policy [1] brings up:
> Forbes may also process certain user information on the basis of the following legitimate interests, provided that such interests are not overridden by your privacy rights and interests: delivering and continuing to develop and improve the Site, learning from your behavior on the Site (e.g., analyzing traffic) to better serve you and other Site users, helping us modify or enhance the Site and its content, receiving insight as to what users do (and don’t) like about our Site or aspects thereof, and providing a stable, consistent, and secure user experience in connection with the Site.
I understood this as 'unless your privacy rights and interests prohibit us, we'll process your data' (TINLA). Still, would be nice to know how do they check for an individual's privacy rights.
edit: grammar
I am fortunate to have been able to delete Facebook and Instagram from my phone but being in Europe I have to use WhatsApp.
I have contacts in UK, Scotland, Germany, Norway, Pakistan, India, South Africa and probably a few more. They all have installed Telegram by now.
Of course I think we can do better than Telegram but at least I am not contributing to forcing everyone to give all their metadata to Facebook.
- back when I started moving groups WhatsApp wasn't E2E-encrypted
- one of those (Zuck and Durov) is a known bad guy and it isn't Durov. The other might or might not be a bad guy, but if he is he is truly hiding it well for now.
- also once I have managed to get people to understand that multiple messengers exist I hope much of the work is done already and the first groups have already been on Telegram so long that I might start to push them towards Matrix without triggering any bad feelings. (Yep, possible: the oldest one I've seen jumping from WhatsApp to Telegram with no issues at all must have been well over 80.)
But sure, let's continue to victim shame and blame here.
When my grandmother passed due to COVID, my family called and texted each other and offered support in plenty of ways outside of Facebook, despite most of them being heavy users.
Everyone’s situation is going to be different, but it may be be as impactful as you think to drop Facebook. It’s addictive to read about people’s updates all day but it may not actually add much to your life and you may find the connections you have with people instead more meaningful as I have.
I'll admit I use messenger because some people will try to contact me there, and it's necessary to be able to respond quickly if you're using Marketplace, but the main app? No way.
Two problems:
* there's a lot of misinformation around the GDPR even in the tech community
* some of this misinformation is most likely distributed intentionally, either to derail the GDPR itself or to continue profiting off nefarious things (marketing, etc) while pretending to comply and getting business via that (the majority of "GDPR compliance solutions" are absolutely not compliant, and yet companies pay for them)
* some GDPR criticism is clearly in bad faith by vested interests who currently make a lot of money from breaching it (including on this community)
* the regulators have been absolutely incompetent or unwilling to enforce it.
Interesting nugget: the author repeats the lies that apple doesn't collect/store/index your data.
I think the scepticism of facebook is a good thing, however I really wish it would be applied equally to every big company. Especially when they so clearly abuse privacy like Apple and Google.
The article states that FB all but confirmed that it is used for advertising purposes.
> the author repeats the lies that apple doesn't collect/store/index your data.
Where's the proof/evidence of this? Apps/OS have been found to leak/send some 'personal' data to Apple servers, but they say they don't track outside of apps (so app store ads use data from your app store usage etc), for them to do so without admitting it would be a huge commercial risk for very little gain (advertising revenue is still a small % of their total revenue).
This isn't about leaks, its about actual design. The itracker system scans your local area for tags, and reports back their IDs and your location. This was rolled out without consent.
By default apple collects "significant locations", which is then accessible to the itracker system ostensibly to warn you about tracking devices.
We accept this because apple are "trusted".
What if Apple are only trusted because they understand how to PR their way out of a bad narrative?
By default all your photos are sent to icloud. They are indexed and processed to give you faces, locations and other (useful) metadata tools.
In one of the OS upgrades, OSX uploaded all my passwords saved in my laptop keychain to icloud, without consent or warning. Not only that it shared them with my phone. My phone didn't at the time have a strong password set.
Just imagine the sheer breathless indignity if facebook, tiktok, or similar tried just one of these actions. However apple(and google) has impunity to do all.
That's my point, if we do care about privacy, then we need to apply the same level of criticism to _all_ companies.
Go into settings and turn off iCloud for photos, keychain and any other app you don't want it to work with.
The difference of all of these things is that Apple is doing it to improve its apps for YOU, uploading photos from your phone to iCloud so you can see on other devices, or face recognition to group your photos, keychain copying is used across devices that you've enabled it for. FB is using the data to create targeted ads, Apple isn't. If you don't like Apples cloud processing of your photos or passwords turn it off.
The data may be in Apples iCloud but is 'private' - it's probably as secure as your home or the phone in your pocket and at least as private as the information the phone companies have about your phone location.
if facebook did that, we'd all be up in arms, and if that was their answer to one's privacy concerns we wouldn't buy it (see tracking opt in).
I get what your saying, but the difference is trust. We trust apple to be private. We don't trust facebook. People are ambivalent to google.
> Apple is doing it to improve its apps for YOU
I mean yeah, you could argue that Facebook are doing the same thing. After all, if engagement decreases, so does advertising revenue. Much as my opinion is unpopular, I doubt facial recognition of photos has much advertising benefit, especially when the social graph is already mapped out for you.
All I'm asking is that we apply the _same_ level of scrutiny of features from apple as we do to facebook. Don't buy the narrative about Apple being friendly, they are a corporation that will deploy the lawyers at any opportunity.
This seems subjective; other companies could claim the same. E.g.: FB says they're trying to show YOU more relevant ads.
> The data may be in Apples iCloud but is 'private'
This seems more objective to me and a better indicator of actual privacy. Still, we should keep in mind that Apple's goals may change in future and that they might change their approach.
But how do we measure that?
Apple went into differential privacy a while ago, which really isn't about privacy, its about anonymisation. Which is not the same thing. Private means that no one else but you[1] can see your stuff
Anonymous means that people can see your stuff, but they don't know who you are. This is different.
[1] well mostly only you
Also: "I suggested to them that this data is used for advertising purposes, and that this is “regardless of the privacy settings selected by the user within the Facebook/Instagram app on their phones.” Facebook told me it was fine to proceed with those assumptions."
FB stance seems to be that the user has the option to strip EXIF data before uploading to FB. On the same token, can't strip your IP, guess that means a proxy.
Which is pretty poor. I'd be interesting to see what twitter, tiktok and snap do with similar data.
Although people seem pretty chilled with other companies doing it. We already know google indexes by location. That's how they do the real time busyness graphs.
I always wonder why the bias is always against facebook and apple. As if people don't realize that all the privacy smoke and mirrors was just about being able to compete with the Ad Industry. Apple Ads now does the same, in a non-blockable manner. I mean, it clearly was about business tactics all along.
I did not saw this in the article... Can you elaborate on this like copy/pasting the line(s) from the article please?
6th paragraph. However, I‘m not sure whether Apple or Facebook is „the data giants“.
It says that there are only four things linked to you when you use imessage.
one of those is "device id". It doesn't say thatit ties you to your icloud account. From that your location, passwords, icloud tabs, photos, purchases, etc, etc, etc are all indexable.
The difference between Apple and Facebook is that Facebook's entire business model is built on abusing the privacy of it's users.
but, apart from cambridge analytica, where actual data was leaked, what privacy abuses are unique to facebook?
Its not like they drove around harvesting your wifi to geolocate you, or deliberately hid breaches to protect it's "good name", or sells your location data to any and everyone who asks is it?
All big companies have done shitty things, but why do we let them off? shouldn't we hold them to account as well?