Apple requires account deletion within apps in AppStore starting January 31
developer.apple.com
developer.apple.com
Same is true for anything crypto. The account as it were exists on many devices, but it's not something you as the app creator can manage.
I think apple protecting privacy is good, but the effect on actually private systems is complicated.
Seems like a case where in 2021 this rule is good, but blocks the creation of new business/product/tools that don't confirm with the 2020 way of thinking... which is good for apple.
Well if you follow the GDPR: yes. Article 17.2
> Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.
It comes down to the individual to interpret and enforce a solution that may or may not be in compliance.
It's like doing taxes in the US. You may or may not doing it correctly and you'll only find out if they start knocking.
This is just not possible for a lot of data like SSB.
How would you do this if someone asked github to delete all their commits across repos?
> For the purposes of this Regulation:
> ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Deleting the account shouldn't be a problem if all the "account" info is stored on the device itself, so if your reviewers aren't completely incompetent I don't see why this would be a problem.
Assuming that information is only visible to the owner of the key anyways, then disposing of the key effectively renders that encrypted data as garbage. Not being able to delete it only enables some unknown future attack that can decrypt any data without the key.
So yeah, all you need is either a currently unknown mathematic weakness in the encryption scheme, or bug in implementation, or as you suggest some future quantum or other technical advance that defeats the encryption.
If the blockchain survives long enough, that info will become public in time.
Browsers have to frequently deprecate cryptosystems that have become insecure. That's not possible with data frozen inside the blockchain.
Also, we're at a point where quantom computers are just starting to become practically usable. So yes, I think the point of a "cryptographic breakthrough" that will crack some configurations is quite likely.
And if you're not encrypting data with AES (or one of a handful of other algorithms), then you should be worried _now_.
> If AES is broken in your lifetime, you're going to have _way_ bigger problems than somebody decrypting your blockchain ciphertext.
I'm not so sure about that. Not a lot of encrypted data is simply lying around at rest, available for everyone to run attacks against. Most encrypted data is either ephemeral (encrypted data connections) or secured by additional measures (e.g. to even get the raw bytes of an encrypted partition, you need access to the machine, appropriate permissions, etc) That gives the data owners various opportunities to react and mitigate the risks: Stop processes that send sensitive data, unmount sensitive partitions, detete data, etc.
You can't do a lot to protect data on the blockchain - it's literally out there for everyone to access.
My point was that data owners have options to limit damage - e.g. immediately stopping any data transmission and not producing any future ephemeral data.
And just to nitpick about blockchains, ledgers, etc.: they don’t need to be world-readable. You can protect them the same as you would a regular database.
Then you'll need some central entity to manage access to the chain. If you already have a central entity, you can just use a regular database instead of a blockchain and save yourself all the energy waste.
I think the key aspect is that it is a database that no single person or organisation can delete or alter - not even the developers or operators of the database themselves. The only operation possible is append.
But this property requires that the majority of nodes participating in the chain are not under your control. When the nodes are under your control, you could just order them to swap out the current chain with one you just made up. (Which is effectively how git's "history rewriting" features work) This doesn't provide any more integrity than an ordinary database.
On the other hand, if you want an append-only database and you already have a central gatekeeper that you trust (as required for access enforcement), you also can use an ordinary database and have the gatekeeper enforce the append-only property. No blockchain required.
Elliptic curve signatures of the blocks are _significantly_ more fragile to quantum attacks than AES.
No, that doesn't seem true.
… Okay, the digital-only ones, maybe. But virtually all other banks I've used make you go to a branch.
The account falls under all the regular retention and reporting requirements, although these companies mitigate some classes of issues with stricter limits, not paying any interest (even though that'd be miniscule), etc.
Try going to random bank websites and click on "open account".
Digital-only, but a "real" bank in every sense of the word.
In fact Wells Fargo is famous for opening account for you without you even thinking about it.
Now it’s only internet banks that do this. They still require lots of KYC documents to open an account.
“…must also allow users to INITIATE deletion of their account”
Capitals mine. So I can allow the initiation of deletion but never actually completely delete the account… and my app complies.
Just thinking out loud, of course cascading deletes will fail, so I guess you could avoid using true foreign keys to the user table for things which are truly related, and then you'd know what the user did but presumably no PII... Seems insanely sketchy though. Way cleaner to soft delete if you ever need to recover history, which the fintech context amongs many obviously requires
Anyone competent is storing both their requests to those external APIs, as well as those responses, for the entirety of the recordkeeping requirement period.
1: I can, nothing catastrophic happened. Other than the Meteor codebase.
They have specific regulation regarding record retention.
A lot of firms that deal with personal data may even have snapshots of every single change, sort of immutable - just not global. Again destroying the keys solves the issue of the immediate erasure. The latter is often times impossible due to tape back ups.
What you have is partial control of these funds, via instructions to your bank, electronic or otherwise, but since it is merely operated on your behalf, you can't unilaterally delete the account. What you can do, is terminate the relationship with your bank.
If you allow such a construct, then "deleting your account" could mean, your immediate personal details (or perhaps even just your access credentials) are erased in some fashion, but nothing else.
This is how legislation like the GDPR gets motivated, of course. The Apple guidelines reference "usage data" elsewhere, and I imagine that's for similar reasons. The deletion clause itself, rather notably, doesn't.
Yes, it's plainly true that the bank owns (or rents) the hardware, software, databases, etc. and that you're paying for a service through various fees.
But IP is much less clear, and the view that "it's my database so it's my data" is not actually universally legal when the data concerns humans.
The whole notion that someone could have a legal property interest in personal data collected by others is exceedingly modern. Even the most abstract scholarly work presaging the concept can only be traced back a few decades. Similarly, privacy as a concrete, distinct legal concept is only slightly older. (Notwithstanding the historical narrative gymnastics legal and social policy advocates often perform in their attempts to appeal to tradition.)
Suffice it to say, modern concepts regarding privacy and personal data aren't very useful in understanding banking practices and property regimes that can be traced centuries, if not millennia, in nearly identical forms.
This is a relatively straight forward request that maybe doesn't go as far as most people imagine here. Pressing "delete" doesn't instantly delete all user data and it's not expected to. In some cases there may be subsequent steps and some data may be kept for legal reasons*.
The point is very sensible, if I can request the creation of an account or subscription easily in the app, the reverse process should be just as straight forward. If an app can give a one button "create-subscribe-pay" experience then when it comes to deletion you shouldn't suddenly fill out paper forms, or send letters at specific times in the month. And that's if you can even find the info on how to do it in the first place.
Now you can trigger the deletion and know that they have to do something about it, at the very least get clear instructions on how to proceed.
*When it comes to banks, they are subject to laws and regulation that many other companies/services don't have to deal with. Which is why Apples makes this provision:
> We encourage you to review any laws that may require you to maintain certain types of data, and to make sure your app clearly explains what data your app collects, how it collects that data, all uses of that data, your data retention/deletion policies, and more as described in the guideline
Legislation like the GDPR is motivated in part to nullify such arguments.
Suppose you're an equipment rental service. But you can't delete the customer's account before they return the equipment (or pay for losing it).
Suppose you're a dog kennel. You can't delete the customer's account while you have their dog in your possession.
Suppose you're the parole division of the police department. Can the "customer" delete their "account"?
This is the problem with dictatorial fiat. The world is full of edge cases.
If the user is allowed according with their contract or law to delete their account they should be able to request that themselves from within the app. This is what I understand from what Apple is requiring the apps to do. It is very similar with GDPR "Right to erasure"/"right to be forgotten".
For your specific cases:
- if a user rented something then they should not be allowed legally to close their account until they return or pay the equipment. If that is in the contract then the delete my account button should be disabled until their contract is terminated/closed.
- if you're a dog kennel it is the same, the user should keep the account until the dog is returned.
- if you are a parole division of the police and the "customer" by law can have their records deleted they should be able to do so.
But now you're exposing the huge problem. It goes from "everybody has to be able to cancel their account in the app" to having to be a contract lawyer steeped in the specifics of every business arrangement and know the law in a hundred different countries to be able to determine if you're allowed to cancel within the app.
Then the app reviewers would either have to be lawyers with plenty of time to make an accurate determination, or they'll be getting it wrong left and right. And it'll obviously be the second one. So now what does the dog kennel owner do, or the OP above, when the app reviewer rejects their excuse?
I also think that the default should be that users should be able to delete their accounts and companies should provide evidence why they have that button disabled or removed.
So in case of review the rule maybe could be: if the user is creating an account in your app, then. the user should have the option to delete their account from the app, unless evidence is provided why the account cannot be deleted because of legal reasons.
In none of those cases are you creating the account within the app.
why not?
GDPR solved this years ago: right to be forgotten does not apply to legal requirements to keep records. Companies must keep those records only for the minimum time though.
And what has it got to do with GDPR. Apple are not the GDPR police in my country. But now you mention it, are the app reviewers going to be trained in GDPR and document retention exemptions, or are they just going to hand out bans?
Getting sick of the down voting from the Apple fanbois of hn.
maybe for you, but there are use cases...
¹: All of them are silly, or could be done better with something else, but that's not relevant to the point I'm trying to make.
> but that's not relevant to the point I'm trying to make.
why do you talk about it if it isn't relevant?
Can you give an example? “spread out and be somewhat resistant to censorship from governments” is just a description of blockchain's strengths¹.
> why do you talk about it if it isn't relevant?
If I didn't mention it, I'd be lying by omission. In order for this discussion to make sense, I have to make the implicit assumption that blockchain is good for anything. I have never, in my life, encountered a situation where blockchain is better than alternatives. Heck, I'm half-convinced that Bitcoin would've been better off with a block-graph (like Git); it models the dependencies better, and means attempted double-spend attacks have a lower impact on the rest of the ledger. (51% attacks would be a little easier, but only for very recent transactions, assuming even distribution of wealth² and a free market economy³.)
¹: though it isn't particularly good at either of those things in practice
²: this is a bad assumption, but it would only affect wealth hoarders so I don't care
³: this is a really bad assumption, but it wouldn't take much improvement to the world to make it a sufficiently reasonable assumption
it is very easy to find an example of censorship, not sure why you need one but let's say: "World marks 32 years since Tiananmen massacre as China censors all mention of it"
There is also daily examples of censorship on this website.
A new version of Scuttlebutt allows tombstoning too.
I think mutable should be the default. Make it all ephemeral with optional permanence.
If someone changes their system to avoid the data being deleted, presumably that would then have to accept the liability / responsibility for deletion. But that’s already moot anyway, because we’re not talking about a court of law, but a court of App Store publication, which it would already no-longer be a part of.
The reality is that most people don’t have hardcore enemies that go out of their way to do things like that. And if you do, you ideally would have them blocked anyway.
Regardless, not posting totally publicly is becoming the norm now anyway. Posting in some kind of context limits the danger of this level of malicious snooping.
The information is not deleted per se, but it is not usable anymore. Now, if you have access to new means that allow you to break the encryption, then yeah it could be a problem.
AES is considered "resistant" in that quantum does an effective square-rooting of the brute forcing effort (or if you prefer, halving of the binary key length). So, do not use anything under AES 256.
Asymmetric algorithms fall apart though, which is why NIST has had a multi-year effort to select new standardized asymmetric algorithms.
If you're a nation state that needs to protect information for 30+ years, then it's worth considering. For everyone on HN, it's not.
It never ceases to make me chuckle that it says that it's not a form of ID on front, and yet everyone considers it a form of ID. Even state governments. It's usually listed under one of the documents they accept to prove ID.
Even just transaction info on a public blockchain is odd to me. It's possible to remain anonymous, but all it takes is one slip-up and then anyone can perform blockchain analysis to trace all sorts of stuff back to me.
On some blockchains it's easy to map the account to the user, on others it's impossible. There are solutions which are completely secret with regards to transfers, so blockchain doesn't solve the taxes. (a specific blockchain may in theory)
That’s a significant slippage from the dystopian ideal of being able to calculate something that many think is none of your business.
The issue is with Apple being Apple as usual.
If that's the case, does it not run foul of GDPR?
You could probably get away with signing an “implode” message and appending it to the tree, instructing any conforming client to wipe the account upon receipt (or at least cease to retransmit). That would give users the option to request their data be removed.
There are three pieces, in fact:
1) The device keys - they should never leave the device
2) YOUR private keys - which you should be accessing and managing from multiple devices, and you can have many of these
3) User accounts on networks. This is where you actually authenticated some sessions, and they shouldn’t contain most of your personal info, only info necessary to operate the service.
For example at our company, we have a way for websites to display your name and friends back to yourself, while having no idea what they are. You can manage multiple identities across many services, and choose which to share with friends, and which not, and everything is automated so the Web turns into a social network:
That's kinda the whole point :).
That said, I would argue that there is no Ethereum "account" - it's just a crypto key. In that sense, use on Ethereum is similar to someone using an email address to sign up for mailing lists and to post on forums.
The counter-argument is that your wallet app likely provides the interfaces to do that functionality, which makes the Ethereum blockchains a proper system under consideration.
The post you're replying to says Apple believe it should. Unless you can persuade Apple to change their policy, it won't matter if you disagree.
(I’ll give you that Safari isn’t in the App Store but many other browsers are. It would viewed as anti-competitive for Apple to remove all competing browsers.)
This might be the weakest strawman argument I've ever seen. Well done.
The 'account' consists of the credentials required to add or modify data associated with a human.
In that case, the person deleting their private key would suffice for deleting an account.
There are plenty of things this doesn't cover, or even backfires. Just interested in what other perspectives people may have.
---
Scuttlebutt actually could allow for 'deletion' in the sense that a 'compliant' scuttlebutt client could choose to interpret a 'delete this account' message as a filter for any messages that match said public key. Many client's UX understand that the state of messages may be incomplete due to the P2P nature, so thats kinda nice too.
I’m planning to add a “delete my account” POST form, in the logged-in app.
I assume this will be fine.
If we ever get to the kind of scale that would require us to have automatic account creation, we’ll see. We certainly have the technical means to do it. Until then, we’ll have volunteer admins creating accounts.
I know that most services do everything they can, to push for massive scale, but we’re different. It’s an NPO, serving a fairly small subset of the population, and we need to be careful not to sacrifice quality for scale (heresy, I know).
The temp passwords are auto-generated and sent to the user, and stored in the traditional one-way hash. The dashboard can reset passwords, but we pretty much let the user do what they want, once the account is set up.
There’s a lot of arguments that people will make about whether this is justified or not, but from a plain rules standpoint, that’s not a permissible data management strategy if you want to publish an iOS app through Apple’s store.
If you do not implement account creation, then you're unlikely to be held responsible for account deletion, as a user would reasonably understand that your app is not responsible for creation or deletion of accounts.
EDIT: Elsethread, someone asked "What if I create accounts on the blockchain?", and since it's possible you'll come around to that idea next — the app would have to interact directly with the blockchain, so you'd probably get rejected for a whole array of reasons, such as but not limited to that you're storing account data on the blockchain. And I wouldn't envy you trying to explain why you shouldn't be continuously fined for GDPR violation in the EU, either.
This is kind of a bizarre thought to me. You think anyone who provides software that - without involving any services hosted by that person - should be liable for what users do with this software? If this were to hold up in court (which I'm confident it wouldn't), then open-source software would be done.
Or is this a problem of terminology? In the scuttlebutt case, there is no actual "account" - just a key. Maybe one should simply replace the string "Create account" (if there is such a string) with "Generate key/identity".
I realize many people are heavily invested in the Apple ecosystem, especially since Apple encourages that with the proprietary integrations between their different devices, but there's a point when one should realize they have a choice. It's a walled garden not a prison.
As an app developer, this isn't a choice I get to make. I myself have used Android ever since modern smartphones became a widespread phenomenon.
The rest of us will continue to because we want Apple policing apps on our behalf.
But in your case I’m not sure what exactly is the problem other than Apple doesn’t believe you… you can still delete the account it’s just deleted locally.
And you may be required to delete any server side identifiers if such exist.
Putting PII or UGC into immutable storage is poor design, unfortunately, both users and laws want this information destroyable.
If such data exists in an app under control of the user, then uninstallation is fine.
If you persist that data in your own systems, you must provide a way to withdraw that consent. Same with data shared with third parties.
If you create an account in first party systems, you must provide a way to delete that account.
If the account is created outside the app (say via your website), thats fine, but you may get the same regulatory pressures directly (from GDPR, from California, etc) to support deletion in the same context.
Can't the app be reset to a state as if it was just installed ?
Careful. If you didn’t properly terminate the contract, you still owe that money. I have a friend whose credit got hit because a service sold his debt to a collector.
You'll typically be OK with streaming services, newspapers, and mobile / web apps.
Definitely be careful with gyms, insurance companies, and any service that sends out invoices (instead of calling it a monthly subscription.)
I live in California and would have tried cancelling online but actually couldn’t find the option. I can’t say it was difficult to cancel though once I picked a process and initiated it. Maybe that was the online option now that I think about it? I was expecting a button or link.
This effect is real, and companies know it, and design their cancellation processes to extract extra money from people.
The best experience would have been no human intervention necessary, but for a process where someone was involved, it was incredibly straightforward. They gave me an offer, I refused it, and nobody had to be a dick about it and no phone calls were made.
Unfortunately that leaves the phone option as the remaining option for everyone else.
> I live in California and would have tried cancelling online but actually couldn’t find the option
The chatbox is the online option.
I went in via the normal support chat, said I wanted to cancel, and was immediately redirected to one. It was an outright lie.
Laws are good, but the lawmakers shouldn’t profit from them.
You do that by making it safe and comfortable for users (or in androids case maybe by doing deals with phone companies to pre-load their apps and make money off users there ).
Apple is only partly successful, they have 15% market share in phones or so. But one area they've been good at is trust - users on an iphone probably spend a lot more (it's also harder to pirate, so what developers give up in profits they make back in lack of pirating).
[1] https://deliverr.com/blog/costs-of-selling-on-walmart-vs-ama...
I can just go into the Google Play store and terminate the subscription for the NYTimes on Android in one click.
The law needs to be that you can cancel all recurring payments through a standard interface. It's ludicrous that my online banking account doesn't just show me all subscriptions and allow me to cancel all future payments of any of them.
You don't have such contracts with recurring payment products.
For example, Planet Fitness has “no commitment” memberships, but you still have to explicitly cancel.
> You may cancel according to our policy: Per the agreement, in order to cancel a membership, one must either go to your home club in person to fill out a cancellation form, or send a letter (preferably via certified mail) to the club, requesting cancellation. Please note: Memberships cannot be cancelled via fax, phone, or email.
https://www.reddit.com/r/personalfinance/comments/51m0e0/com...
Canada was the first to require simple unsubscribe for email lists... I'm surprised it still does not have a law to require online unsubscribe for media subscriptions.
Newspaper editorial endorsements are still a big thing in Canada.
> The Globe and Mail operates similarly.
But this is good to know. I was considering swapping another newspaper subscription for a Globe and Mail subscription, but after looking into it, the eventual unsubscribe hassle isn't worth it.
Back in one of the days, the PayPal TOOLBAR used to offer this feature, it was really convenient since you were essentially direct drawing from your bank account with it.
I signed up for a trial for another service which shall remain unnamed, and of course I couldn’t find anywhere on the site to cancel my trial once I wanted to. No problem, I just disabled the card. They’ve probably tried to bill me a dozen times since.
Privacy.com is free, but I’d pay quite a bit of money for it, it has saved me hundreds of dollars.
[0]: https://support.privacy.com/hc/en-us/articles/360012288214-F...
> To change or cancel your subscription, please contact Customer Care.
That is pretty anti-user. Comcast does this too.
"To change or cancel your subscription, please contact Customer Care."
As a free user, you still need an account to read certain free articles. So it's not really the same as canceling your subscription.
I also wouldn't be surprised if they deleted your account but kept billing you.
NY Times needs to get their shit together.
I was expecting a painful process based on what I'd read on HN and Reddit but it was just a couple of clicks.
But your spouse has to know you (or which family member) bought it and click on their name in “family sharing” to get it for free. Else spouse will pay for it again.
It doesn't quite work like that. When someone in your family goes to hit the purchase button, it pops up a window saying that someone else has already purchased it. I'm not sure why you have to hit the button first, maybe for some measure of privacy from your family members?
Likelihood of Gov doing better seems tied to how much they can get away from Wall St. funding/defunding their re-election campaigns.
Not the cost of facilitating the transaction.
Not a big fan of the gym itself, but I can't fault their cancellation process.
Honestly if you can subscribe with a button you should be able to unsubscribe with a button.
If all else fails, "I was just diagnosed with a terminal illness" or "I am required to report to the state penitentiary on Monday" will work.
Alternatively, if the US legal system allows it and you can find a number: Fax. This has the advantage that it can be automated on your end so it's not much more hassle than a quick e-mail, and the delivery receipt (yes, trivially spoofable in theory, but I would assume it's widely accepted in practice) also shows what the content of the message was.
There's probably a startup idea around unsubscribing from difficult companies but legislation and rules in general are likely more effective.
I only realized after hanging up how little sense this makes.
As long as that change cascades to every single site that the user could have registered with.
Otherwise, there could be hundreds or thousands of sites waiting to email confidential information to a new person.
Also, emails probably persist in some systems as a guid.
MANY people tie things like password resets to your email, not to you and may not have a retail store presence you can get to for a password reset.
He's telling you - once this email is gone, it is gone and no one, including you will get it again. That is good in the sense that no one can impersonate you, but bad if you have an "ooops" moment and want to do a password reset that needs that email.
I’d rather it work the way Apple does it than have someone try to recreate a deleted account.
Apple's announcement says:
must also allow users to initiate deletion of their account from within the app.
It's only "initiate" deletion, so if we treat that as Step #1, then if Step #2 is, as in the NYT example, to ring support to confirm your intention to delete you account, then this may not deter much user-hostile behavior. It just kind of smears it to a different part of the tablecloth.
It also specifically says 'deletion' rather than cancellation or disablement, but I doubt Apple are going to follow up on this eventual deletion (or alternative watered-down definition) of account past this "initiate" step.
Will users have recourse through Apple if their "initiated" account deletion request goes no further than step #1?
Microsoft, for all its faults, is much better than Apple or Google here.
Businesses take planning and strategy, and these things lead to drop-everything fires.
Economies rely on stability.
> This requirement applies to all app submissions starting January 31, 2022.
Unsure if this means new apps, or includes updates to existing apps. But I bet there'll be a bit more of a grace period if you don't have a new update to push.
if you provide a good and easy sign in functionality from your app, through native UI and the like, then you should be able to provide the same functionality for deleting that same account. That is at least what we have recommended one of our clients, but that client is also a public transport company, so they can't afford to be in gray area where the app is either rejected or taken down.
Details were very vague at the time and now we know when it will actually start being enforced, but overall it’s more like half a year notice.
However, in this case, they have ended up giving you 6 months and a courtesy reminder.
If you aren’t interested in maintaining your app annually, don’t publish apps on Apple’s store.
Whether or not their level of notice is enough, they’ve been consistent for years in this practice of 3 months notice for significant and breaking changes, and they seem comfortable compelling annual updates from developers. I would not expect them to care that 3 months is difficult in your circumstances, as they assume you’re prepared to maintain your app and proactively keep up with policy changes over time. It sounds like you did not attend to this year’s policy updates and may well have been out of compliance for months now. Fortunately, they offered a grace period rather than just refusing your next bugfix update. Lucky you!
(I am not sympathetic to your situation, because as a user of apps, I am exhausted of crappy apps and bottom-of-the-barrel behaviors from developers. I understand that others may feel otherwise, and that’s fine too, just as long as those feelings do not get in the way of being a responsive app developer.)
But I don't think it's particularly hostile. I think it's just that their focus on user experience requires them to accept the punishing annual cycle for developers.
> You have to be crazy to stake your company on apple's goodwill at this point
My company has an app on the app store. We do a few hundred million dollars in sales via the app. Are we crazy?
Apps are just a single frontend to a larger system, and Apple thinks they can dictate the workings of that entire system just because you want to let users access your system from an Apple device. It's bonkers.
Imagine microsoft going: "Microsoft edge will refuse to render your website unless there is a "delete account button". How would that make you feel?
That's exactly what I do. I avoid the app stores like the plaque.
> (I am not sympathetic to your situation, because as a user of apps, I am exhausted of crappy apps and bottom-of-the-barrel behaviors from developers. I understand that others may feel otherwise, and that’s fine too, just as long as those feelings do not get in the way of being a responsive app developer.)
I think the word here is 'entitled.' There are a few different groups here:
- Bottom-of-the-barrel scammers, whom I have no sympathy to
- Little kids and amateurs, who might want to put something out and move on
- Graduate students and research projects
- Little not-for-profits
- Internal-use small businesses and enterprise apps, where a they might be developed once and forgotten about for decades (yes, plural)
In my case, I don't need to have an app on the app store, and I don't care for Apple's behavior, so I don't have an app there. That hurts Apple (and you, if you're an iPhone user) more than it does me.
You're also confusing strictness with timelines. I'm all for super-strict policies. Just with:
- Backwards compatibility (e.g. grandfathering) of older apps
- Plenty of notice
I can’t imagine account deletion is straightforward for most of the implementation, even just from a legal standpoint when money changing hands is involved.
I think it’s a complicated enough issue that it should be tackled from the start (which is usually the case) and kept track of as the product/service evolves.
Wonder what that means for third-party HN client apps though, since HN accounts cannot be deleted.
Hopefully apple makes a more user-friendly announcement about this that will introduce people of the concept of data retention and how "deleting" an account isn't really deleting anything.
Thats the whole point :) Apple is saying they need to or no iphone app.
Capitals mine. So I can allow the initiation of deletion but never actually completely delete the account… and my app complies.
> ...all apps that allow for account creation must also allow users to initiate deletion...
So any third-party client that allows creating an HN account would need to stop. (Are there any?)
Edit: it's only for apps that allow account creation. If you expose the API for account management to third-parties, it would make sense to include account deletion.
(Android user, can't test it)
https://apps.apple.com/ca/app/hack-for-hacker-news-developer...
https://play.google.com/store/apps/details?id=com.pranapps.h...
I have no idea what happens to third party apps as Apple doesn't specify.
Priorities matter.
P.S. I do see Apple business model changing to services bringing in some bad behavior associated with that: for instance, push notifications now are used as a spam/marketing mechanism for Apple services similar to Android; iCloud Storage nag is another example.
The storage and other nags I hate, it's a real ethos breaker for me. Get that crap off my iphone. That's why I pay extra - for less crap (I like that they somehow can also block the carriers from installing unremovable apps, for some reason android phones sometimes come with weird apps from your carrier when you get them).
I remember when I discovered my Android phone wasn’t encrypted, and it had lasted for years. I suddenly stopped using it, changed my passwords/tokens and bought an iPhone. Never came back.
An extremely beneficial policy for the customers, right.
Oh, and of course you won't be able to use push notifications, because Apple.
edit: the apps expire after 1 week and need to be constantly reinstalled. This is abusing an exploit in apple's walled garden that will surely be "fixed".
The fact is that you are allowed to sign apps with a free dev account, the cert will just expire after a week.
AltStore’s been around since 2019, so they’ve had ample time to “fix” it.
Edit: they do not need to be reinstalled. With AltStore the cert update is automatic and wireless (your computer handles it and sends the updated cert to your phone). You will never notice their expiration, and never need to reinstall, unless you’re away from your computer for more than a week.
The point is as the device owner you have the ability to run code on your own device outside App Store without paying Apple. To be able to effectively distribute such code to the average iOS user who may not understand how to deploy unsigned app and the potential implications of it is a different story and one that you could argue is designed to protect the layperson against themselves (contrast this with users running random .exe from emails on Windows).
If Apple will allow third-party app stores or direct installation of applications on devices, dictatorships will lose this capability to harm Apple's customers.
But of course we all know that this policy was never intended to protect users, it was to protect Apple and their appstore monopoly, which also allows Apple to extort developers of 30% of all of their revenues by forcing them into Apple's payment services. Finally, the world has had enough of this and starts to fight back against it.
As someone who switched from the Samsung note line to iPhone, the only freedom I felt from the ability to install other apps was the freedom to deal with all the unrecoverable crap ware.
There’s other phones out there with greater freedom than the iPhone, people are aware of them, and are still choosing the iPhone.
The curation is a benefit in that I have a corporation with thousands of employees working to prevent the other corporations from making my user experience worse. If the curation goes away I’d probably switch to a cheaper phone next upgrade and I’m sure apples aware of that
The priorities have shown very clearly over time.
Nowadays on Android I try to search for apps on F-Droid first or search on Github as a shortcut to find open source apps. Why open source? They are often a barebones version, that will probably not sell me out and will not use dark patterns (I know it can still happen). I have nothing against paying for apps, I do have a couple I bought, but sometimes I have simple itch, that I know for sure someone else already scratched for everyone else and I do donate sometimes. This lousy state of app stores leads me often to search for some simple web apps on github.io. At the same time I sold whole open source category to Microsoft. In the end it seems that all I want is a smartphone shell scripting equivalent, but that is a totally different point.
There isn't metadata for this, as it is not part of Apple's relationship.
They are a seller of software, and the creator of the software is responsible for making sure the software can be compatible with the licensing and copyright terms of both Apple and any dependencies.
A semantic link to grab the source code for an app would be neat, but a pretty niche feature. That Apple can't verify that it is the same code (or that the separately hosted build process doesn't have malicious logic within it) probably quickly pushed them over the edge in terms of not supporting such a feature.
The litigation / cases / govt intervention has been on behalf of businesses not consumers. A lot of folks in the "alliance for app fairness" have just horrible billing practices. Understandably, if they can get out of the app store, they can stop you from being able to do things like delete your account or unsubscribe with a few clicks.
A lot of the newspapers make it easy to sign up, but then you have to call to cancel, the same papers that go on and on about how terrible the app store is. There is a REASON people spend fortunes, particularly in the apple app store - it's damn safe to do so in most cases.
Once that was removed, Steam Link went right back up
They don’t allow a native app for GeForce now, but it works with a browser.
Apple wanted to be the gatekeeper blocking out harmful apps, fine by me.
Apple then wanting to use that gatekeeper status to steal money from app developers, block apps that compete with apple internal apps, and enforce moral choices on what kinds of apps you can install on your phone, evil by me.
They could have done the former without doing the latter, but they fucked it up, and have to pay the piper.
I'd agree here, the majority of the policies are likable by consumers.
> The litigation / cases / govt intervention has been on behalf of businesses not consumers.
Consumers don't have millions to throw around on litigation against Apple so it's no surprise the litigation is focused around business cases. On the government intervention side I disagree though, of the very little intervention there has been it has been consumer focused IMO.
In either case there is also some overlap of "business interest" and "consumer interest" even if the vast majority of the time there isn't so blanketing that all litigation has been on behalf of businesses does not imply all litigation is about policies not in consumer interest. And I think the courts have been very conservative on which points are actually acted upon even if there is a bit of a "throw it at the wall and see what sticks" approach to many of the cases.
> A lot of the newspapers make it easy to sign up, but then you have to call to cancel, the same papers that go on and on about how terrible the app store is. There is a REASON people spend fortunes, particularly in the apple app store - it's damn safe to do so in most cases.
If people are truly buying Apple devices because they only want to purchase things from the controlled app store then the availability of alternative app stores wouldn't be a concern, they would simply go unused. The truth is most people don't actually buy the devices for this reason which is why Apple is so afraid to give that singular point of control up.
There is actually a class action suit against Apple regarding anti-trust brought by consumers. Unfortunately, while the suit was filed in 2011, it wasn't until 2019 that the Supreme Court ruled that consumers even do business with Apple in the App Store [0]. So, a lawsuit filed in 2011 was allowed to go forward in 2019. I don't know what methods Apple had used to hold up the case since then.
Except app developers are mostly small shops and startups. One-person operations.
How would we like it if the web were forced to behave according to some governing body? It feels like some North Korean 1984 dystopia and we've all got explosive collars around our necks.
It's anti-freedom, anti-American, anti-ownership, anti-Stallman. And I own five iPhones and an iMac.
I just want my stupid software on the stupid fucking software execution device. No tap dancing bear rules. No praise to Apple or forced induction to the Church of Jobs.
Steve Jobs made this artificial, ceremonious bullshit to make money. There is no other reason.
I curse history that his authoritarianism won. It's become pervasive throughout the industry now. It should be illegal.
I'll gladly charge 3x the price to Apple users for having to put up with this malarky.
In theory Apple sign-in is great. In reality, many apps now show several login options (Google, FB, Apple, e-mail) and I can't remember which one I used.
I've had many instances of trying to login with Apple, the app silently throws an error, and the app won't proceed. E-mail pw reset doesn't work. Did I use Apple Sign-In with my real e-mail or a forwarded (private) e-mail? Apple has made logins more complex and confusing.
Future guides will be like:
1) Buy an Apple device
2) Download and sign in to Facebook app
3) Click delete account buttonInstructions here (essentially, press "Permanently Delete Account" in settings and put in your password to confirm): https://www.facebook.com/help/224562897555674
Could be totally wrong here though...
Press release (emphasis mine): "all apps that allow for account creation must also allow users to _initiate_ deletion of their account from within the app."
Guidelines: "If your app supports account creation, you must also offer account deletion within the app."
Has anyone seen any clarification on what options might be acceptable? e.g. I'm wondering about something simple, like opening an email composer with the app support email address and a pre-filled message body requesting account deletion which would be performed async.
Effort on those requests might recover some users which may be especially valuable if you are a subscription business. If you can't benefit from interaction then immediately imitating deletion from an API seems the only thing that would pass muster.
It's not necessarily about recovering users who want to leave but rather minimizing the effort required to implement a more complex deletion flow that has a high probability of never being used by real users (in my case).
Earlier this year, I went through an attempt to purge myself from some internet services that I wasn't using.
Many of the SaaS-type services I tried to remove myself from didn't make account deletion obvious at all. All of them had an email address to contact in their Privacy Policies, but whether you got a response back or not was a different matter.
In practice, I could imagine apps just telling their users that their account deletion "will be processed in 24-48 hours" with a 50/50 chance of it getting processed.
That said, it's a pretty massive wipe.
Photos, videos, documents, and other content that you stored in iCloud are permanently deleted; you can't receive any messages or calls sent to your account via iMessage, FaceTime, or iCloud Mail; and you can't sign in to or use services such as iCloud, the App Store, iTunes Store, Apple Books, Apple Pay, iMessage, FaceTime, and Find My iPhone. In addition, any Apple Store appointments and AppleCare support cases are canceled.
Deleting your Apple ID is permanent. After your account is deleted, Apple can't reopen or reactivate your account or restore your data.
You lose all your credits with apple (if any) app updates will stop working even for apps already downloaded and more.
"Manage Your Data and Privacy." On the following page, select "Get started" under "Delete your account."
But on the other hand, I think they should also carefully disclose the info they collect at their OS level...
Just another case of that old CYA.
You can also view any collected system analytics in Settings -> Privacy- > Analytics & Improvements. Seems relatively fair to me.
"Explain its data retention/deletion policies and describe how a user can revoke consent and/or request deletion of the user’s data."
My first question before looking into it was, "What an auth tenant or some other service that stores user data?" or, "what about like a banking or healthcare app that is just a portal for another system?" And, "What does deleted even mean? IsDeleted=1?"
It would appear Apple's stance on those answers is a shrug emoji. I'm no appstore developer but I got a kick out of reading a lot this for the first time. This rule bearing no exception to a trend that for most part seems intended to give Apple the license to eliminate bad actors.
I got a new one for Apple. "Like, do what you gotta do but don't be a jerk."
Deleted means removing as much PII as you reasonably have authority to do so. It means purging all that data from all databases with a guarantee that you will be removed completely from all snapshots in a reasonable amount of time.
This should be the default, normal understanding of what it means to delete your account.
It doesn't mean set a flag in a database so when your company gets acquired in a few years your new owner has a nice little trove of data to mine of people that explicitly opted out.
In other words: if there is overlap, the right of one person's data to be forgotten supersedes the right of the other person's data to be remembered.
When an action such as a payment is taken, or the customer provides certain info that needs to be kept for legal purposes, two records are created. The former can be deleted at will by the user, the latter is completely separate and is kept for as long as needed to comply with laws/regulations.
If there is a known fraudster and you have their selfie image, email address, and ML face vectors, the fraudster requests their account to be deleted. What should the company delete? Maybe the company can keep a one-way hashed email and face vectors, but what about hash-collisions or false positives?
If there is a user that wants their account deleted, but then they come back to the platform (maybe abusing a referral bonus or first-time-only coupon), how do you stop this fraud?
I think looking at deletion as the solution to privacy concerns is the wrong way to go about it. Really, the problem is app developers think, "possession is 9/10ths of the law" when it comes to data, when in reality their relationship with the user never captured use of that data for purposes not related to the application. Just because you give your data to the bank when you make an account doesn't mean you consent to them selling it on the dark web. The same concept applies but it is much harder to police and you can even say you're going to misuse the data in the EULAs that nobody reads. In my opinion using user data for purposes unrelated to the application should straight up require explicit consent from every user, lest the seller and recipient be subjected to a fine.
1. Auth tenant. Common sense says that if the auth provider is operated by you, it’s your problem to handle deletions appropriately, either by removing their account or by warning the user that you’re only deleting the specific site account and providing a link to delete the SSO account at your website or whatever. If you do not operate the identity provider, such as Facebook, then you need do nothing about it at deletion time. Apple would likely approve any of those paths without comment, but to defend against rules lawyering and loophole seeking, there’s no way to be perfectly certain until it’s approved.
2. Banking or healthcare app. If you can sign up in-app, you’ll need to let people close/delete in-app, except where prohibited by contract or law. For corporate healthcare, you would pop a dialog that says “This account can only be closed through your employer”, which would be absolutely sufficient. Ditto for a banking account with non-zero balances or a safety deposit box or whatever. It seems likely Apple will not have cause to enforce the deletion clause against brick and mortar banks, since they all have help/faqs on how to close accounts already. App-only banks will be held to the more strict standard of having some way to initiate deletion, being app-only, though of course they’ll retain financial audit records as required by law.
3. Deleted means that all information not essential to compliance with financial and other auditing laws has been removed from your systems. Exceptions are understood to exist for recording that someone requested deletion, but you can’t use those records for marketing or training AI or any other purpose beyond managing your deletions. If you can’t explain in plain simple English how you handle deletions, they’re likely to reject your submission until you can.
All of this is obvious. It isn’t comfortable to consider that you’re at the mercy of human beings to evaluate your compliance — human beings that see a thousand scams a minute trying to hack loopholes in the guidelines. But that’s how it is today.
I don't provide a way for a user to delete their data in my app but that's because I don't want to have to deal with having to tell them "You shouldn't have pressed that button". But I'll gladly delete it they request I do.
That's a tough one to balance though. It's been very rare but I've had users call me a few years after their account expired asking if I still had their data, and in all those cases I did, and that saved their butts because they needed it.
In my case storing user data is very inexpensive so unless they ask me to delete it I'll let it sit for long time.
What's happened more often is I'll have users try to login and then renew their accounts after they've sat for over a year.
Example: You are a typical business. A fire completely destroys all of your data, including financial data. If the IRS comes knocking for financial records, you have an excellent reason for why you cannot provide it - force majeure. A law protecting the right of a human to be forgotten should be treated the same as a fire. You do not question it, and should forcefully comply.
E.g. 1) Download an app (N26, Revolut, etc...) 2) Create an account 3) After login, the option to delete the account should be there...
(Of course the bank should respect all data retention policies)
Basically: App allows account creation => App must allow account deletion.
They will throw the end-users (not actual end users but businesses who pay for phone app development) to the wolves in terms of forcing them to rewrite apps so that they can have a few blog posts about "user data security," despite the fact that we know there was at least one CIA backdoor in OSX in the early 2000s until ~2015 or so.
At some point all phone apps are going to be javascript web apps, Apple is just desperately trying to prolong the inevitable here.
Where can i read up more on this?
I call to all smart knowing license people of Hacker News. Is this a copy-left license attached to a person's data?
All mobile banking apps that allow signup seem to also allow account closure, so there isn’t exactly a problem there.
If I sign up for insurance in an app, I expect (and Apple will enforce) that I can cancel it in an app. Setting aside certain health insurance scenarios where I have no legal authority to terminate my insurance, I expect that Apple will absolutely start enforcing that insurance account management apps need to have a way to terminate coverage. But I think this isn’t the kind of business they’re concerned about, so they might focus on other business categories first.
Insurance and banks probably aren't affected, since your account is created outside of the app
So is this what often happens in a field with large players … only the current social networks can exist, no new ones may ever be launched in the App Store?
@dang is there a way to delete accounts on HN?
Bye bye Hootsuite and other apps for automating Facebook and Twitter posts.
I guess the precedent would be that they didn’t used to allow redirecting to a website with the purpose of avoid in-app charges. Although I think that’s over with now.
This almost forces all software that does anything on the internet to be subscription based (or free).
I wonder if the famously hard to delete Facebook account will comply!
Just yuck. All of it. Over and over again we see these antideveloper and anticonsumer moves - which always happen to be set in just the right way to take power and give it to apple under the guise of security or privacy.
Anyone got the link to delete your Apple ID? It's been years since I've had a need for mine.
big sigh of relief for me with a service companion app that delegates account creation to a web admin interface ...
anyone know ?
> (v) Account Sign-In: If your app doesn’t include significant account-based features, let people use it without a login. If your app supports account creation, you must also offer account deletion within the app. Apps may not require users to enter personal information to function, except when directly relevant to the core functionality of the app or required by law. If your core app functionality is not related to a specific social network (e.g. Facebook, WeChat, Weibo, Twitter, etc.), you must provide access without a login or via another mechanism. Pulling basic profile information, sharing to the social network, or inviting friends to use the app are not considered core app functionality. The app must also include a mechanism to revoke social network credentials and disable data access between the app and social network from within the app. An app may not store credentials or tokens to social networks off of the device and may only use such credentials or tokens to directly connect to the social network from the app itself while the app is in use.
Also interesting:
> (viii) Apps that compile personal information from any source that is not directly from the user or without the user’s explicit consent, even public databases, are not permitted on the App Store.
So why is Facebook still allowed? It still creates shadow profiles without permissions as far as I know.
Maybe because the app itself isn't doing it? I'm not sure what "apps that" vs using the information the app gives you are really different but in technical detail it might be.
> Apps that compile personal information from any source... without the user’s explicit consent
i wonder how far they will enforce this...for example, will they tolerate apps that refuse to function without said consent?
what about an eula and just tapping "ok i read it"?
just my bias maybe, but "free to use" but requiring "user consent" seems like a nice avenue for getting around restriction and rules designed to protect them
(1): At least to it's core functionality but I think even to more or less all parts not tightly bound to a social login.
This also has nothing to do with unapproved software. The idea that a user can actually delete their data from your servers should not be a controversial topic. But of course it is for businesses and developers, which is why Apple has to make a policy like this.
As a user I am very happy with this.
50+% of Americans for everything they do, say, buy, etc.
This is a monopoly by sheer volume and scale of their reach.
Businesses will continue to complain but this protects the user.
You're not going to find support in a forum with 60+% Apple users. A lot of these people work for or have stock in this company.
They don't see how this is a roadblock to competition and that this device is now in the critical path of 50+% of commerce. (Maybe they'll care more when they have to compete.)
You wouldn't happen to work or have stock in a company negatively impacted by this change?
I don't have any interest in apple and don't use their products, but I'm really struggling to see how preventing the scummy strat of making sign up easy but deletion/deactivation difficult is some how a 'roadblock to competition'.
You're gonna have to make a much stronger argument to get any traction.
What would really give users the control they deserve is the ability to restrict what data can be sent off the device by an app in the first place.
Apple should make it possible to deny internet access to an app entirely, and they should provide an API that allows apps to upload very specific kinds of data that a user has approved of, but nothing else. Of course, some apps need to be able to request unrestricted internet access.
Permitting apps to collect private data and have unrestricted internet access, by default, was always a terrible decision in terms of user privacy. Apple owes it to their users to fix the problem they created.
What apps are left if this is forbidden?
"private data" can mean pretty much any user input. "unrestricted internet access" means pretty much any internet access.
We're left with apps that either cannot accept user input or cannot access the internet at all.
1. No internet apps: store data locally on the device only, no upload or download.
2. Partial internet apps: store data locally, and only download data through an Apple proxy service that hides the user's IP address and any identifying info.
3. Full internet apps: store in the cloud, uploaded/downloaded through an Apple proxy that logs/filters everything. Or even stored in Apple's cloud.
4. Unrestricted internet apps: VPNs and web browsers, and whatever else actually needs arbitrary access to the internet.
There's no reason my bluetooth scale app needs #4 (which it has today) when I would much prefer it have #1.
A seemingly benign request that appears to simply request information can encode a user's private, sensitive data in the request URL, e.g.
I think there's no real distinction between your 2. 3. and 4.
There's a place for no internet access at all. It would be good if they had a permission for that.
No, it could not. Cryptography can make it as difficult as necessary.
(Not even going to touch how unacceptable it would be for Apple to require that it be able to inspect all internet traffic from a person's phone.)
This is just a failure of imagination. The API could be as restrictive as necessary to ensure privacy.
For example, maybe an app is only authorized to upload specific fields of data and a maximum rate.
How does an app only allowed to upload 10 int32 metrics per day going to secretly upload even a single photo?
> Not even going to touch how unacceptable it would be for Apple to require that it be able to inspect all internet traffic from a person's phone.
There are lots of options for how to implement things so that Apple isn't getting copies of private photos or chat messages. Apple is certainly more trustworthy and accountable than a random app developer from a random foreign country.
Personally, I want a smartphone/app ecosystem that is completely free of any centralization. I'm just talking about how Apple could improve their proprietary/centralized system, which actually does make some of these kinds of things simpler.
People in the future will be amazed we lived like this...