Apple’s crackdown on multicast
thomask.sdf.org
thomask.sdf.org
It's weird how a company can be so internally disconnected. This entitlement is a good privacy-preserving hurdle to prevent scummy apps from interfering with your local network and fingerprinting you. On the other hand, the on-device scanning of nudes in imessage and csam in iphoto is a total snitchware swatting-as-a-service piece of software which only serves to incriminate and harass the owner of the device. Such a shame.
For example, you can't locally develop a VPN app until you ask Apple permission to develop a VPN app. Almost certainly this is to appease China, which I find particularly egregious.
Fonts also require an entitlement, but I'm not sure if it's just something you need a paid dev account for or if you need to specifically grovel to Apple as to why you need it. I doubt "I want to submit a pull request to iSH" would be considered a valid reason (but correct me if I'm wrong).
Even things like camera access in multitasking views are entitlements that your dev account needs to be preapproved for. In fact, it wasn't even something that Apple even publicly mentioned for a while - only Zoom had it until someone reverse-engineered their app bundle and found out about it.
Can't you manually add a vpn without an app? I haven't needed to configure this myself but presumably if you're bundling your own vpn app you can do the manual configuration in settings which is significantly easier.
If your VPN uses a different protocol, you must (with an entitlement) develop an app that gets to execute its code for every packet sent and received. For example, if you want to create a "VPN" that sends and receives packages by audio like an oldschool modem, or if you want to implement the WireGuard protocol, or if you want to implement a dns tunnel, etc.
The good thing is that any random shady app can't just start hijacking and intercepting every network packet for the entire device. The bad thing is that it makes difficult as an outsider to contribute to open-source VPN apps, since you don't have access to the entitlement (which ultimately requires access the the private code signing keys and provisioning profiles for the developer that DID receive the grant (and the debug device must also be registered there)).
The restriction doesn’t stop you from using the NetService API (or friends) from listening for or advertising specific named mDNS services. You can continue to do that today without any extra entitlements. What it stops you from doing is listening for wildcards and sucking up everything — sadly, restricting multicast traffic on regular IP sockets is basically an extension of that.
“How can we ensure every request for multicast escalates to someone qualified to make a decision that we can stand behind?” An essay question is a great answer, even if people hate the uncertainty. Better that than a new guideline!
Apple doesn't know what every app does, they basically know what frameworks/syscalls get made. You can wrap entitlements around those things without explicitly knowing exactly what an application is actually up to.
If you want Facebook on your iPhone to call someone then Apple provides a Phone API.
If you want Facebook on your iPhone to stream to your TV then Apple should provide an Apple TV API for Facebook to use.
There is no reason whatsoever for Facebook to have any direct access to anything on your phone whether its your sensors, your microphone, your video, your network.
There is - AirPlay doesn't require local network access since it's an API apps can use. Un/fortunately, there are multiple competing standards like Chromecast (and other, manufacturer-specific casting standards) which require the app to do its own local network discovery to find available devices.
The way I see it, it just hashes them with whatever mechanism they came up with and there are additional mechanisms to verify it if for some fringe conincidence your cat pictures hash matches some CSAM hash which would be annoying but not the end of the world.
Now, in the other hand, let's say the snitch detects actual CSAM in someones phone, what's the problem? if it was sent without their consent an investigation can lead to who sent it, and if it was well, tough shit...
I know it sounds very 1984ish but honestly I don't think it's any worst than the kind of surveillance power google has with all their platforms combined (chrome, android, google, any web thing they didn't kill already).
I guess, what I'm asking for is for real arguments on why and how this truly violates privacy and to what extent it is problematic for a legit non CSAM consuming person.
I'm not trying to argue with you but to understand this point of view since I read so many comments against it but nothing that seriously made sense to me.
I read in other posts there's some sort of review process and a way to verify if the image is a match or a collision (I don't know much about he details) but I read the latest posts about the attacks that were being worked on.
I mean, with the complexity these attacks have I think it'd be easier for a ransomware gang to just infect you, plant the CSAM, find reliable contact info, verify it, lock your phone and extort your through an untrackable side channel (if this system didn't exist) or something a bit more elaborate / targeted (not even at NSO level).
IDK, I think the phone burns battery for dumber reasons at a higher rate, this should only be activated when there's a new picture written to disk and it's probably less expensive resource wise than whatsapp / telegram / imessage checking for new messages periodically don't you think?
I think if they don't royally fuck the process up or turn it into some idiotic fake way of getting the cops whatever paperwork they need to force you to give them access to your files it's a good thing.
I have read their papers, I understand the system and the safeguards they put in place, but none of them are good enough to have scanning on my device. There is nothing that is good enough. On device scanning for "illicit" content is a box that cannot be closed.
IIRC it's deeply entrenched in the system and no one reversed their way deep enough to be able to replicate it. Now this might sound silly, but it's just an example, a contrast maybe of how the hard work the people behind asahi are putting or the huge jailbreak community, but the idea I'm trying to convey is that the playfield is HUGE and they just don't need this.
The one thing I would be 100% concerned about is the investigation process for matches because that's mainly where human interaction and decision making com into play and we humans SUCK, we've put people behind bars for years for no reason and with all this AI crap there have been a lot of news articles about that kind of stuff and that's something we should definitely be worried about, but I guess it's less about the tech and more about the people in charge right?
In your example about planting CSAM, why would on/off device matter since the new feature only checks for items going to iCloud anyway? The planting CSAM attack vector is available right now for any device connected to FB, OneDrive, or Gmail, and I don't think planting material has been an issue.
If you're hit by an NSO client and they have an agent running in your phone checking in with their C2, what do you think would be easier :
1 - Run a reverse proxy in your phone, steal your credentials (or session data) and use that connection to upload the material 2 - Write it to disk and wait for the media scanner service to pick it up and act on it?
I mean, in the end it's not about the technology but the people operating it, if apple is really incompetent and law enforcement is shitty as usual then yeah, people might end up behind bars for no reason, which sucks but in that case I think the focus shouldn't be the technology itself but how shitty and unfair the system is.
Using Apple devices used to be all about how they serve the user to bring joy. Knowing they now spend even a single cpu instruction on trying to frame the user turns the device from something I loved to something I fear.
All the talk about human review and multiple failsafes does not smooth things over. App store review is a prime example of how their review process can be seriously flawed - scam apps and subscriptions sometimes even being FEATURED in editorials on the app store.
It does not matter that you will be found innocent in the end. Just being put under investigation for csam can make anyone's a life living hell. Getting your AppleID blocked, even if temporary, can cause severe problems.
When a company advertises that "what happens on your phone stays on your phone", and then proceeds to build snitchware into the phone that reports on received imessages to the "family head of household" and reports and UPLOADS photo roll items that were never intended to be shared, to human review, well... that company does not appear to be honest anymore.
In addition, this only works for <18 accounts. If the abusive figure goes as far as making other family members recreate Apple IDs and lie about their age every 5 years to keep getting access to iMessage (and other parental controls like screen time) then there's not much Apple can do.
Last case I heard about was cleaning personnel in a body expression workshop for kids with learning disabilities that was sharing new pictures he took of girls in a Telegram group. The group was infiltrated by an FBI agent that allegedly got the link from a Facebook group that they found because of Facebook scanning for known hashes and reporting.
This happened in argentina btw.
This should give you pause.
Why do you think something that sounds 1984ish should be acceptable to anyone? Why is it acceptable to you?
The fact that other companies also have advanced surveillance power should be reason to push back on that as well, not to cede more ground to surveillance.
I guess your logic doesn't make any kind of sense to me.
This is such an honor. I was starting to suspect no actual humans other than the developers and the managers work at FFANG at all given how hard it is to contact them. Perhaps in this case it is not a human either but a neural network of a sort.
Anyway, I believe everything should be done this way, through communicating with humans. Humans should study every ad and every app before it gets published (but I support side-loading for users willing to opt-out), humans should review every video before it gets de-monetized or removed, humans should communicate on every appeal. I would vote for a law mandating this.
PS: The more news of this kind the more I feel like buying an iPhone perhaps. I don't like how they restrict the users but I bloody adore how they restrict the apps (with exception of some cases like iDOS, terminal apps, alternative-engine web browsers etc - I certainly don't like Apple banning them).
This is like being asked to get permission from IETF in order to run an HTTP server on your computer, it just doesn't make sense.
The iPhone was never intended to cater to developers writing personal-use, general computing software on their own devices, though. I know it’s an unpopular opinion on HN, but I don’t expect my iPhone to be an open development platform and I’m fine with that, even though I’m also a developer and software enthusiast.
Realistically, how many people would even be impacted by this restriction on multicast packet sending for personally-developed apps for personal use only? The number is vanishingly small relative to the total iPhone user base. It makes sense that Apple wouldn’t go out of their way to cater to that ultra-niche use case which can still get the access they need by requesting the permission.
I know people get angry that the iPhone doesn’t cater to every single niche personal use case, but honestly I’m fine with that. If I need to write a custom app for personal use that does something unique, I’m not going to reach for an iPhone anyway. However, I use an iPhone as my primary phone because Apple has focused on the things that matter for making it a good phone that does phone things well, which is exactly what most of us actually need.
Well, its not about expecting Apple to put more effort to enable some feature. In many cases enabling that feature is less effort and Apple instead goes "out of their way" to disable such things. _That_ is the problem - and it is not specific to iPhone, things like this have happened in the past on MacBooks too (see https://github.com/onmomo/superdrive-enabler/blob/master/src...)
Is this really the future you want to see?
Why? This is actually one of the biggest complaints about the App Store review process, because it tends to produce a lot of inconsistent results if your app comes anywhere near the gray areas of the App Store guidelines.
Mandating human review for everything sounds like a good idea for those who imagine perfect, highly-skilled, consistent reviewers handling every step of every process, but that’s not how things work in the real world. You don’t actually want to legally mandate real humans handling every step of everything, unless you want to force everything back to the days of bureaucracy and endless back-and-forth communications to get everything done.
When you go into a Target or a Walmart or certainly any small retail shop, everything in there was selected for inventory by a human buyer. When you read a newspaper, every single article was reviewed by a human before it was published.
Product designs are reviewed by humans for utility and safety. Drugs are reviewed by humans for efficacy and safety. Cars and trains and airplanes were human-reviewed during design and assembly, and again at regular intervals. Every scientific article is reviewed by humans before publication.
Systems that try to run at scale without human review have problems with quality. Amazon tries to run a retail platform with minimal human review; it’s choked with fakes and scams. Social media companies try to run with minimal human review; they’re full of false information and scams.
Well, they only restrict apps for us peons. Companies with money can use undocumented apis no problem. Case in point:
https://www.macrumors.com/2021/05/09/zoom-ipad-camera-api-ac...
* Well, I'm somewhat surprised, because it's apple, and they tend to be overly idealistic... but there seems to be a bit less of that in the post-Jobs era
As well as Hulu https://www.macrumors.com/2021/05/06/apple-hulu-special-api-...
Have you seen Brazil? https://en.wikipedia.org/wiki/Brazil_(1985_film)
What you are describing sounds for me exactly like a bureaucratic nightmare.
> I don't like how they restrict the users but I bloody adore how they restrict the apps
Honestly, that brought me to go away from Apple. They reject apps randomly, allow terrible security holes that affect ALL applications over relying on safari mobile web views (Pegasus) and do nothing against scams (see discussions over family sharing): https://news.ycombinator.com/item?id=28203361
Brazil is fiction. Judging how you relate to things in the real world by comparing them with things that were made up to be funny is not how you achieve insight.
Its absolute nonsense to shoot someone down on the basis that they draw parallels to movies or other artforms. Especially if those works of fiction are intended as warnings / cautionary tales.
As it is i thought the parent comments comparison to Brazil was fairly apt in this situation...
Now I see the movie has been implemented into life almost precisely and the AI with mass surveillance has been introduced to make it even worse.
To make it more fun and looking realistic today they even portrayed people kinda watching Netflix on their office computers when the boss doesn't look (AFAIK computers were not actually capable of streaming videos over the network during the days the movie was filmed).
Just referencing a random piece of satire when discussing the real world gives absolutely no insight in and of itself.
How the hell can anyone come to that conclusion I don't know.
The time machine is about class division and class warfare.
1984 is about Stalin's style totalitarianism.
And so on...
Not saying that Brazil does this, but just because someone comments, does not mean they have something important to say.
So what is it then? Brazil does make interesting points about encroaching bureaucracy (and therefore the parents post is justified)? I think you took the point about Brazil a bit too literally, the poster was never suggesting that the world is suddenly exactly that way, more highlighting the parallels. I think you need to allow yourself to suspend disbelief a little more and realise the very deliberate allegorical nature of these movies...
I mean, judging by the greyed out appearance of all your posts on this topic I would say it seems you're in the minority with this kind of opinion.
Modern smartphone have a lot of potential that cannot be exploited only for policies. One example is network connections in general, it's so restricted that is barely usable. For example controlling the network interfaces is problematic. On iOS (and now also on Android) you can't tell the phone to connect to a particular Wi-Fi network, only to a network with a prefix and it's not even that reliable. Where that would be useful? Of course in an app that connects to some device that exposes a Wi-Fi AP.
I develop embedded devices and thanks to mobile phones network limitations everything has to pass trough a cloud. That is a big improvement for privacy if we ask Apple? I don't think so. But there are really no reliable ways to control something in your LAN. Well if you give Apple a ton of money to implement HomeKit by putting the Apple proprietary chip in your product of course, why do you think they impose this limitations?
They could automatically approve/reject and store the form in case they need to review it later.
Android phones are nice because they at least respect my pre-existing workflow. I can sync my Nextcloud server to keep my notes and photos distributed, I can install different shells to get work done on the go, Hell, I can even use it to send a firmware payload to my Nintendo Switch in RCM mode. It's my swiss-army knife for when it's impractical to carry a full Unix machine.
Or perhaps we should just have fines in case things go awry. I mean, if it works, AI should be allowed. The problem is that it doesn't work.
So, what's the attack vector? A back door, perhaps? Bonjour requires a user approval dialog. A misleading title of the dialog may allow someone to connect. Maybe extract private data.
Imagine a peer-to-peer chat app. Say, in Hong Kong -- during a protest. Or in Kabul -- during an evacuation.
Edit: Yes. "After its introduction in 2002 with Mac OS X 10.2 as Rendezvous, the software was renamed in 2005 to Bonjour following an out-of-court trademark dispute settlement." https://en.wikipedia.org/wiki/Bonjour_(software)
Damn, I'm getting old.
There are indeed a number of old routers out there that do not work with mDNS well. This is still a problem, but most <5yo routers seem to handle it okay (with the caveat that there are a number of cheap APs and extenders that are completely broken at basic TCP/IP when clients switch).
We use broadcast for device-to-device discovery, vs device-to-phone. It makes for noisy networks, but works better than mDNS on a wide range of hardware.
Maybe it is possible to abuse multicast for tracking/fingerprinting in some way and that's why Apple is locking it down to approved apps.
It would have been unfeasible to show a permission dialog. How would you even begin to explain multicast to the average user in 1-2 sentences?
Most people are not running local DNS services which a device without this permission could use to probe the local network, so it’s a fairly accurate description for the majority of users I would think?
Also, there is nothing mom would install that would legitimately require this permission ...
I guess one sentence is enough ;=)
(Sure it's not perfect in it's explanation, but that's basically what it boils down to in it's usage.)
My first thought was: how does multicast IP traffic interact on cell networks?
IPv6 makes heavy use of multicast (e.g., NDP), and a lot of mobile network are now IPv6-only (clients do no get IPv4 addresses), and so if apps can start sending tracking to "everyone" on the network (or a particular base station), could that cause problems.
Even in many enterprise Wi-Fi networks, it’s quite common to see either client isolation or multicast filtering in place (in part because multicast traffic is often sent at a very low data rate and that can have unintended side effects).
My limited knowledge of multicast from working with network software a while ago was that it’s local network only, and udp and you needed to “subscribe” to get the broadcast messages. There was also a keep alive component which is a little different from normal UDP.
I wrote a tool to help debug the system by subscribing and then dumping the messages. Perhaps this the problem Apple has with it?
My understanding was a lot of routers didn’t support multicast, I know we had some issues with our network configuration.
What happens on IPv6 is a interesting question.
Then simply drop multicast packets? That's also what your ISP does with them.
I assume some surveillance library recently changed to start asking for it, but am not sure.
I deleted both and realized it has been a while since I've watched my phone over an intercepting proxy; time to sweep for bugs again.
They may well be trying to stop something equally stupid happening where someone decided it would be a good idea to blast the user's name and phone number out over the local network.
I vaguely remember needing to fill something out to explain why I needed users to be able to load content from http (user generated content in an app). But it makes a bit more sense in that case.
When you try to launch a BLE service with the required identifier, the framework simply throws an error: "The specified UUID is not allowed for this operation." :-)
This is why there are no Bluetooth keyboard/mouse/trackpad apps in the AppStore, while there are many on Android.
They already have manual review process for submitting apps to the App Store, so I don't understand why I would also need permissions before I start developing apps using restricted features.
However, I was partially wrong (it's been some time since I needed this), you can actually use them in the simulator without an approval.
List of special entitlements needing an approval: https://stackoverflow.com/a/65330176
Additionally, I know that CarPlay entitlements need an approval: https://developer.apple.com/documentation/carplay/requesting...
Only if you want to create a wildcard listener. If you know the exact name of the service you want to listen out for, you do not need the entitlement.
Not sure if this is the solution tho..that's out of my realm of expertise.
They actually have big troubleshooting section for this cumbersome entitlement:
* Faceless multinational A, that gives lip service to privacy and doesn't give a shit about freedom
* Faceless multinational B, that gives lip service to freedom and doesn't give a shit about privacy
* Trying to kickstart an alternative ecosystem - a task that Microsoft, one of the richest companies in the world, was unsuccessful at.
* Not owning a smartphone
I'm talking one that actually works and is on par with linux desktops.
When that happens, the world might have more choices than just Google and Apple for smartphones, or Microsoft and Apple for desktop/laptops.
Lots of stuff just won't be available but that's going to be true no matter what non-Apple/Google platform you went to. Outside of that though, it should generally provide a fairly user-friendly experience.
YMMV but I do. That kind of hassle is the tax that I’m perfectly willing to pay for having FOSS stuff.
Let’s celebrate that we have options.
The issue here is that "we" are not many people.
https://techmonitor.ai/techonology/software/why-did-the-ubun...
https://appleinsider.com/articles/19/04/10/apple-agrees-to-o...
The market just does not have the ability to act here. Facebook literally incited genocide on the other side of the world and Facebook experienced zero repercussions
If you fall into that demographic, how do you avoid doing business with Apple? They're entrenched in the duopoly on desktop, the duopoly on mobile, and the duopoly on browsers.
Refusing to do business with Apple will only make you feel good about yourself, but it will significantly hurt your career prospects if you're a working developer, and ruin any hope of success if you're an entrepreneur trying to start or run a tech company.
For all intents and purposes, they're a monopoly. If you're a fan of the Hasbro game, you might disagree on the exact definition, but Apple (and peers) is unquestionably in a position where they're immune to market forces.
Capitalism doesn't work right when you have companies like that.
Fairly easily, I have an X1 running Linux as my dev machine (I'm backend/ML) and don't have a phone. No need to worry about my career, I'm doing OK thanks.
I know this is pure conjecture with regards to this particular situation, but I already had couple of clashes with operations people over use of multicast in my applications. They basically trying to tell me there is never valid case for multicast so they just outright filter it out everywhere with no possibility of enabling it.
Multicast has been a dream since the 1990s but has been a nightmare in practice.
I understand most office networks are broken and if I send multicast I would just be causing untold mayhem.
I have already resigned myself to the fact that the only way to have reliable communication with a client is to use HTTP.
But in a DC where you control all your networking devices, configuration and people who maintain it, it should be possible to find a configuration that works reliably and allows devices to talk to each other without too much hassle.
The number of multicast bugs in Cisco/Juniper/whatever enterprise gear is astonishing. It’s basically a DoS waiting to happen. And if you have multiple network vendors in your shop as all real networks do… forget it.
As I said, my long experience is that multicast just doesn’t work reliably in practice except maybe for small layer-2-only networks. The same places where broadcast storms aren’t noticeable.
Unicast with source replication is fast, cheap, and reliable.
Handling specialized permissions one at a time through specialized teams could make sense for distribution. allows the whole-app reviewers to not have to also become experts on multicast best practices/security and having a second reviewer handle that.
It's to prevent people bypassing this approval and distributing their app through other methods.
If you're just using the free developer program (by signing into Xcode with your Apple ID), this is all automated and you don't have to get into the nitty-gritty of certificate and profile management (but it's all still accessible if you want to).
There's some big restrictions on the free program though, not least being unable to use certain capabilities in your apps (e.g. multicast mentioned in the OP, but also background modes, push notifications, etc.) Most of these are self-service and don't require asking Apple nicely, but you don't have access to the developer portal so cannot add them to your app.
Maybe they use it to judge whether it's OK to allow me to broadcast stuff.
If they can make connecting to those devices a pain for developers, it will tip the balance in favour of apple TV and devices apple chooses to whitelist.
I remember being so frustrated with this process of trying to convince someone in Apple who just didn't seem to understand why this would make sense. They cited that it was a poor user experience but I can't imagine a worse experience than a messaging app that never received push notifications.
But as a customer I appreciate this stuff. I need some shortcuts to be able to maintain reasonable opsec without dedicating my life to dodging surveillance. I’m ok if it makes applications harder to develop because there are plenty on the App Store already.
If you want a device that can run arbitrary code, Android exists. Laptops exist. You have options. I don’t want a device like that in my pocket, however. It doesn’t fit in my personal security model.
Does anyone have any examples of using TCP with multicast? I'm not personally aware on any, and I wouldn't describe multicast as a staple of TCP.
I guess multicast is a staple of IP (not TCP)... but does Apple let your apps use raw IP? (I didn't think so.)
The thing you have to remember is that Apple has shown the world how to run a top-tier mobile platform that supports billions of users while, more or less, protecting everyone's privacy and data from bad actors. They have decided to err on the side of pissing off devs if it came down to that or compromising on this goal. And it's made them trillions of dollars.
Your dislike for a fact doesn't negate it
TL;DR It was a well reasoned privacy-focused decision, not "power-tripping" as the blog author puts it.
>The entitlement is needed only to be able to browse and advertise arbitrary or wildcard services. If you’ve added the one type you use to your Info.plist, as you detail, you do not need the entitlement.
i.e. the entitlement is only required if you are not willing or able to restrict your use of multicast to defined services.
Not with any sort of seriousness I think.
Some major internet peering exchanges used to have multicast LANs for whatever reason. I think LINX were one of the last ones to operate one, but eventually in 2020 they removed it after they reached a point where only two ports were connected to it with no significant traffic flowing !
This probably isn't as unlikely as you might initially think. I remember reading somewhere that Apple had been working on a user-space networking stack?
Edit: Apparently I saw it in https://developer.apple.com/forums/thread/79590?answerId=235... — Eskimo claiming "It came up during the iOS discussion on user space networking because NKEs are a major sticking point in bringing user space networking to the Mac"
Mostly because anything else gets filtered out at some edge.
- /from?site=thomask.sdf.org
- not /from?site=sdf.org
This just seems like Apple shooting themselves in the foot, imo.
Apple is seeing that they are in a position of responsibility here if they don’t draw lines in certain places.
That's funny, he believes he owns an Apple device. Sorry, no. Apple locks down the device with strong crypto and rents you limited permissions, they sell a computing service, not a device. Apple are the only ones who get to say what code ultimately runs on their hardware.
The confusion is common due to the specific way the lease agreement is structured: you pay a lump sum for the device custody and future rent, you lose that sum if you damage the device, and you are responsible for recycling the outdated hardware instead of returning it to the owner.
The state of federal law is that you own your iPhone and can run whatever software you want on it. Jailbreaking is legal, largely because you own your iPhone. The law just doesn’t force Apple to make it easy for you.
On a practical note, I’m interested in thoughts on why Apple might try to lock down multicast, specifically, but I have to scroll through dozens of comments arguing about a software system (iOS + App Store) that is now over 13 years old. Is there anyone on HN today who does not understand how iPhone software works? Why do we have to rehash a decade-old conversation on every single iPhone/iOS Apple story?
EDIT - Since I’m still in the edit window, I might as well link to a comment that seems actually useful and relevant to this blog post:
https://news.ycombinator.com/item?id=28287064
There are other interesting and useful comments if you scroll down…
Because people are mad - still, and baffled - still, that Apple is successful and prosperous despite not catering to the niche needs of your average HN commenter.
Because there's new people in the world every day and they need to hear this important conversation, which is new for them. If you are already aware, it does no harm to you to just ignore the conversation.
If there is such software is inside your civic then no, you don't own it. Honda does. The word "ownership" is in part defined by the ability to exert control. If Honda controls who drives the car, where, how and when, the owner is indisputable Honda.
It's entirely within the rights of a company to lock down their hardware if that's how they sell it to you, but it should be equally within the rights of the hardware owner to bypass those "protections". If Honda decides to lock ignition behind an arbitrary clearance check (pulling a John Deere), they shouldn't be able to retaliate if that lock gets bypassed -- as long as that distinction exists, we will always be proper owners of the things that we buy.
If we were to upgrade the saying "possession is 99% of ownership" to the digital ream, it would be something like "control is 99% of ownership." The distinction between possession and control is only relevant for smart devices.
They may be mandated to do so:
> U.S. Senate bill seeks to require anti-drunk driving vehicle tech
* https://www.reuters.com/world/us/us-senate-bill-seeks-requir...
See also BMW and microtransactions:
* https://www.theverge.com/2020/7/2/21311332/bmw-in-car-purcha...
Cars and their infotaiment systems aren't marketed as general-purpose computing devices in the first place. iOS devices very much are.
The specific question here is why Apple is putting new restrictions on multicast. Unfortunately all the informative comments are far below this rehash sub thread.
I can install any aftermarket parts I want to install in my Civic, because I own it.
Because this is the possibility of people to cash in on their "I told you so". Also, it is not too late to either change direction or jump ship; if we take this without complaining, the situation will only get worse.
You are bound by 17 U.S.C. § 1201 to not attempt to alter the car in ways Honda does not approve.
Not that simple. Since the DMCA/EUCD, it's complicated.
If something goes haywire in my phone, it can't possibly turn into a 2 ton death machine, which is something that can happen with a car. Cars have stringent safety regulations that cell phones do not. So... bad example.
It is not clear to me why it would it would be different from the “Local Network” permission.
When you buy a phone, you definitely own all the atoms in it. You can take it apart and use the bits to make jewelry. You can take all the phones you have and assemble them into a piece of wall art. Apple has no say in what you do with the object.
But your belief that physical ownership of the object should mean you can make it do anything you want is… bounded by your actual capability to do so.
You can probably extract some of the parts of your phone and reuse them - maybe with care and patience you could figure out how to use the screen, or the battery, or the camera as part of another device. Again, not something Apple can stop you doing.
But expecting to be able to use a device to do something you want to merely because you know the potential to do so is inside is an unrealistic expectation. A cotton t-shirt might contain enough thread to be able to be woven into a pair of shorts, but you can’t complain to the manufacturer that the way they made the t-shirt makes it hard for you to turn it into shorts. They sold it to you in a useful, valuable configuration. They’re not obligated to make it easy for you to reconfigure it to your will.
Apple actively design their products to not allow you to reconfigure them even if you have the tooling. The shirt manufacturers do not prevent me from taking a old shirt and making oil rags from the fabric.
Similarly, I own a car. Can I take off the seat belts? Physically, yes. But legally, a vehicle without a seat belts is no longer a car and I lose the right to enjoy driving it on public roads.
Ownership was never about physical possession. It's about gaining some rights.
Back to phones, the challenge is to demarcate what rights does an owner get when they buy a phone. To side with Epic Games, the discussion is even more complicated by Apple's (purposeful) confusion of owning a phone with having access to an ecosystem of apps for that phone. I can do whatever I am capable of with my iPhone, but I may lose access to the ecosystem of apps.
Under the DMCA, if you rearrange the atoms or attempt to describe how to rearrange the atoms in a way not approved by the phone manufacturer, you are a criminal.
Copyright, and in particular the DMCA, has superseded your ownership of the atoms. You must do with them as the true owner of the atoms (Apple for example) permits.
In the UK you can buy a freehold house for £250k and that's it. Or you can rent one for £800 a month, although that confers certain rights. But between those two, you can buy a leasehold house, which has obligations to pay a ground rent. You can buy a freehold house where you are obligated to pay a management company to maintain common areas.
"Buy" and "Rent" are certainly not clear cut.
With a car, I can rent a car from Hertz, or I can buy one for cash, or I can lease one, or I can buy one with a loan payment secured against the car, again there's no clear line between "buy" and "rent"
If they refuse to provide it for purely commercial reasons despite having full technical ability to do so, you might have a case that you were misled into purchasing a subscription service. Ideally, you would find some advertised capability that is only enabled for apps sold though the App Store, a hidden subscription fee especially considering its onerous value.
It seems to me that if Apple had no more than 10% of the mobile market anywhere this just wouldn't be an issue. If that's what some people wanted, fine, they could get it. The reason it's a problem is, as it turns out, this model works really well for a lot of people and is fantastically popular.
So I am open to arguments for regulating mobile phone platforms, if that proves to be necessary. I just don't think it is, none of the arguments Ive seen so far are compelling. They mostly seem to be sour grapes. "I want to buy X product with P, Q, R features and nobody is making one, we should force them to by law". No, that's not how that works.
This line of argument is frankly incoherent. That many, not all, available mobile devices remain firmly under the control of their makers after purchase is not because some free marketeer (or cabal thereof) foisted these devices onto unwilling recipients. This situation came about because the majority of mobile device users saw the deal on offer and decided they were better off taking it that walking. The real source of the status quo is the average consumer... no matter their ideology. That buyers weigh promises of "Just Works", the status of owning the cool new device that's in fashion, and some guardian supposedly lurking in the background keeping them safe over your own (seemingly apparent) priorities is a matter of each individual choice.
Private property rights haven't been cancelled at all or by anyone. There simply aren't enough people interested in owning devices that they fully control. Insofar as there are few alternatives to the status quo... blame the privacy activists and those clamoring for "full control" for not better convincing the masses that what they're giving up for iOS & Android is more than they're getting by buying these devices. As a free market extremist myself, I guarantee you: if people stop buying these devices because the deal is perceived as bad the situation will change.
Finally, if I try to infer what you might be for (rather than what you're against), which I do because it's the only reason to call out "free market extremists", is that you want a small group of "our betters" to decide what exactly a mobile device should be, over and above all those that find the current deal sufficiently satisfactory. You would have your priorities made the only choice over the interests of the majority of consumers. Ironically, perhaps, you'd eliminate the broader spectrum of choices by forcing what choices were allowed... wanted and valued or not. Naturally, I'm reading a lot into your short comment... but what solution do you really see that isn't a free market extremist position that doesn't come close to what I think you're saying?
Turns out a lot of people don't want to deal with the responsibilities of completely owning a device (updates, anti-malware, app origin), and are willing to give up some control/ownership in exchange for convenience and being able to get on with life. (Certainly not everyone of course.)
Whether this view of convenience is short-sighted and will be regretted long-term remains to be seen.
Many Android phones come with unlockable bootloaders. Again, how many of those who bought such a phone know about this capability?
What I'm trying to say that it's fine to sell a device in a locked down state. What's not fine, however, is not providing an unlocking mechanism, possibly deliberately well-hidden like it is in case of Android bootloaders, for those who know what they're doing.
On one hand, the locked down iOS clearly hurts a lot of businesses and broader market competition.
On the other hand, Apple has been open and honest (and rather boastful) of the locked down nature of iOS since Day 1. Consumers have very clearly voted with their wallet time and time again that this system (and it’s tradeoffs) is the one they prefer.
To force iOS open is to undo the choices that consumers have made. But to leave iOS restricted is to harm broader business competitiveness.
You’re right that if Apple had marginal market share, this behaviour would not be problematic.
Broadly speaking, I’m not all that sympathetic to the plight of the big-name developers like Facebook and Match Group. They’ve collectively made users so cynical about privacy, security and the general trustworthiness of software that it’s prompted users to take refuge behind these hardened walled gardens. I just hate to see good independent developers have to be harmed as a consequence of that as well.
I chose iphone because a string of bugs left a sour taste in my mouth with android, and inertia locked me in. I definitely don’t want this level of locking it down, and I doubt a majority of iphone buyers want this.
If you buy a car, is it your car? You very possibly cannot do things with it independently, on your own, without manufacturer involvement or without voiding any warranties you have. The same idea extends to many things. I'm defending Apple here, but this idea that it's not your own device is silly IMO.
(prediction: I'll probably get downvoted)
My argument is not about cars, really, it's just a point I'm trying to make.
Some people might want to have full access to the OS, but allowing custom software in the userspace would still be a huge step and enough for most people.
p.s. It's hard to compare a computing device to a car because what's an equivalent of usespace in car? Changing oil? Changing tires? You can do it yourself, you can even change spark plugs, without voiding your warranty.
By all means throw shade at Apple for tripping on a power complex that puts Battersea to shame, but insulting this writer’s awareness doesn’t fly. They are not such a fool as suggested.
You're not telling the truth.
Apple will recycle any device for you for free. They may even pay you for it if it's in reasonable condition and reasonably recent.
This is one of thoses cases where I agree with the free market people that competition is good. If there were more companies that made Apple devices, then you would be able to buy a non-defective Apple device, too.
And: In a rational society, I could just download the source code and make the change myself. Actually, in a rational society the people that make the computers would not be incentivized to artifically restrict them!
But if you make something for the world at large, you should stick to the rules. They're not unreasonable, and they are one reason why iOS devices are some of the most secure devices out there.
I grokked everything up to this comment. Apple has extensive trade-in and recycle programs [1],[2]. Or did you mean something else?
You own the hardware. You license but do not own the software (as is the case with almost all software nowadays, including FOSS software). If the software from Apple is not to your liking, jailbreak the hardware and install software that is more to your liking.
This might take some effort as newer releases of Apple software are harder to jailbreak so you might have to stop installing new Apple OS releases to give the jailbreaks a chance to catch up to what is on your phone.
In particular, the author complains about "prostrating" themselves, when they actually want to write apps that would run on ANY users device that could have relatively serious privacy implications because instead of providing a specific service they want to do a wildcard discovery.
Also the button on apple.com says "Buy now" not "Rent now".
> they sell a computing service
if anything its becoming more like "consumption" service than "computing"Nothing has changed, Apple maintained full control all the time. You have absolutely no power in this matter and no rights, you are simply a revenue source, the only thing you can do is cease supplying money to Apple.
I fully support Apple remote bricking all hardware past a certain age to drive the sales of newer models. It's just a matter of time until you will start to see phones with "3 years limited software support". Once the 3 years are done, a splashscreen appears warning you that the device is no longer supported and insecure, thus unusable.
It sounds remarkably like a video game console or a stereo receiver.
That makes sense really since the main purpose of a consumer computer at this point is to, well, 'consume'.
It's funny to think back on an era when the average privately-owned computer was bought to actually do something useful.
Whereas on Android you can simply download the APK from within the device. No host PC needed. No developer cert. No expiry.
Looks like its gotten worse the second half of the decade and even wages for it have stagnated (except for the FAANGs that pay everyone indiscriminately)
Try yourself:
ebtables -A INPUT -d ff:ff:ff:ff:ff:ff -j DROP
ebtables -A FORWARD -d ff:ff:ff:ff:ff:ff -j DROP
(Tried on standard ASUS router by adding ebtables rules using SSH)
To clean: ebtables —-flush Or restart the router, because this also flush ebtables
(Edit: Corrected multicast to broadcast)
If I remember rightly, apple devices when connecting to wifi
1) Get IP, router, DNS details (either static or via dhcp)
2) Attempt to load a http page to detect any portals
3a) If page loads, is connected.
3b) If page doesn't load but redirects, pops up the portal page (in a cut down browser), then eventually connects
3c) If it doesn't load at all it asks if you want to use the wifi even with no internet access
I suspect if it cant configure an IP at all (because you're blocking arp and dhcp), it doesn't fully bring the interface up. Are you saying that with a static IP entered in wifi you can't connect to a wireless network?