Are iPhones Better for Privacy? Comparative Study of iOS and Android Apps
arxiv.org
arxiv.org
From page 5, "This is before the introduction of Apple's new opt-in mechanism for tracking in 2021. Our dataset therefore reflects privacy in the app ecosystem shortly before this policy change."
Personally, I would prefer to see the difference between apps monetized by customers paying directly and apps monetized by advertising. I take for granted advertiser will track, and I assume paid apps track less but I wonder if that's actually true in practice. It very well might not be.
This is not my field but one thing that I don't get when looking over the Transparency Matters report [1] is why do some apps have 9 trackers and others have 300 requests? Are they really so different? And are they able to get information that Starbucks didn't with only 3 trackers and 21 requests?
I guess in the end the magnitudes aren't so important but I found the large differences pretty amazing. If nothing else I would think they might want to reduce the amount of data they need to retain, reducing their costs. It seems like there has to be diminishing returns there.
It also shows how much data Google has as they show up on 8 of the 10 apps tracker lists and one can only assume they keep a copy of all that as well.
So perhaps the iOS/Andriod comparison is meaningless anyway as Google knows all about you either way.
[1] https://blog.lockdownprivacy.com/2021/09/22/study-effectiven...
ATT, when a user selects "no", blocks the app from accessing your device ID. This makes it so that even though the app can still track what you do in their app, they can't connect that to the data collected from other apps through your device ID, and therefore build a profile of you as a person.
0: https://hugotunius.se/2021/01/03/an-analysis-of-privacy-on-t...
Letting a third party run code on your system they don't permit you two or someone you trust to see is a bit like being asked to adopt a legal contract that has some amount of power over you you are not permitted to read.
If you want apps willing to prove you can trust them to respect your privacy and freedom, the reasonably strict process of apps in the F-Droid store are what you are likely looking for.
There is an accountable and privacy preserving alternative for almost everything.
However, as an app ecosystem, it's not tough at all. For example, there is not a single open source email app on iOS which supports GPG email. In the iOS app ecosystem, privacy and FLOSS is an afterthought, since iOS users are more likely to pay for proprietary software. On Android, there are a lot more options, including things like F-Droid which are full of FLOSS apps which are graded based on their patterns and anti-patterns.
Even an open source app on these stores can't be provably correlated to published source code and could have undocumented deviations at any time.
Put simply, there is no reasonably accountable privacy story on stock iOS or Android. You mostly just have to take each publishers biased word for it and that the permissions systems alone covers every potential way an app can abuse your trust.
And it doesn’t seem tough to generally diff privacy between the two OSes, as this paper seems to add some contributions.
But I agree andriod being in hands ads company has really no incentive to be privacy friendly. Apple mostly selling hard generally have incentive to be more privacy friendly.
You might say that people who really care about privacy would just get GrapheneOS, but the mainstream info available to help make these decisions is really poor as of now. Just seems like a Wild West.
All ship with piles of binary blobs mandated by Google, SoC vendors, and carriers that have god access to your device, as well as any entities they sell that access to, and this sort of power abuse has been caught publicly many times.
Apple has been caught doing similar in the past but it is much harder to regularly audit closed platforms.
Unless you run something best effort like CalyxOS or GrapheneOS you should not have any reasonable expectation of privacy on a handset.
Or use Pinephone if you want "actual" privacy. Librem 5 is an alternative as well, albeit an overpriced one.
I own a Chromebook where I leverage the Google ecosystem and do Googley stuff all day, then a Thinkpad with Qubes+Whonix when I want privacy & security & sometimes anonymity.
You don't have to be faithful to a single company/OS/provider/whatever. You can leverage all the things and compartmentalize.
One thing I can think of is most tracking algorithms probably assume each user has a single cell phone (either explicitly or the ML data is biased in that direction). So splitting your time across two devices probably messes with whatever user-behavior buckets they place you in. They might think you’re two people in the same household, for example.
If you truly need privacy and control then the right approach is to have neither of them and consider a GNU/Linux phone (Librem 5 or Pinephone).
Usability suffers indeed, but the software updates will never end and it is improving rapidly.
Even then, every program runs under your user account with no more fine-grained permissions, meaning any program has the ability to send your browser cache/ssh files/photos whatever to wherever it wants, or just simply encrypt them.
Slightly OT, but: is there a reason why you're spelling that with a numeral zero?
EDIT: I looked it up, it stands for "internet". From now on we should be referring to it as "internet OS" where space is not an issue.
Given that the abbreviation isn't literal, "internet OS" is not colloquial and you will confuse others.
This is something I’ve been wanting to do!
I’d love to own an iPhone and Android so I can get the best of both worlds.
Does anyone have any suggestions going this route? Ideally I’d like to keep a single number that can be used on both devices and I can just decide myself what device I want to drive for the day.
https://blog.lockdownprivacy.com/2021/09/22/study-effectiven...
That includes privacy, unfortunately.
Most cheaper phones will just get revenue from selling users info instead.
Invading privacy and using that pays. If your hi is to make lots of money while maximizing profit you’re going to invade privacy. If you don’t and you’re public shareholders might complain about leaving money on the table.
Then there are those who often focus on privacy tools. They often don’t end up building rolls with a user experience for the every person.
It’s complicated.
*: obviously paid with privacy, but that does mean less money leaves the user's bank account
It either has to be able to run one platform’s apps, or have some alternative support. The latter can be the open source world, but than why depart from Android, when its core is FOSS?
If this was more conservatively titled "who has the worst default app store" that'd be far more accurate.
>We find that third-party tracking and the sharing of unique user identifiers was widespread in apps from both ecosystems, even in apps aimed at children. In the children's category, iOS apps used much fewer advertising-related tracking than their Android counterparts, but could more often access children's location (by a factor of 7).
>Overall, we find that neither platform is clearly better than the other for privacy across the dimensions we studied.
Well, here's a novel idea: don't get children their own smartphones, uninstall/disable all apps bar the essentials, and keep your own usage to the bare minimum.
How many children have you raised?
That does not in any way mean any of this tracking is ok or acceptable. It means we need to keep up the public pressure and technical vigilance to publicise this issue, and try and get the industry and legislators/regulators moving in the right direction.
They also have a feature where if you walk a certain number of steps in a month, you can get a free drink. On iOS, the app asks for permission to read the step count data from the iOS system step counter. On Android, the app requires background location and the Coca Cola company can now know where you are at any time.
Both platforms are notorious (Apple more so due to its closed nature imo) and defending any is just weird.
I'm willing to limit what apps I use and carefully consider what I install. I'm not yet willing to abandon my smartphone.
Choosing the lesser of N evils is a pretty common and often rational choice, in life and in engineering. May be not in this case, and it's good to be unsatisfied, but disregarding the debate just because neither option is great makes no sense.
(Of course, this assumes people bother to switch. In reality, this isn't even true in oligopolist party politics, let alone in oligopolist markets. In practice, there need to be a lot more, smaller options before switching costs are forced down enough to encourage people to switch. In phone markets, this looks like how people switch somewhat easily between different Android device manufacturers for their next phone. If we could get phone Operating Systems working like that, we'd really have something!)
The companies that can best resist the NSA are located outside of the US and EU.
With Google, you at least know what to expect. How many promises has Apple broken now?
They are also working around the margins to improve privacy. Google is not.
How many promises has apple broken? #stuffyoumadeup
Well that cut-and-dries it then, I'll be sticking with Android/Linux until Apple puts up a meaningful resistance to government surveillance.
Even this, from an Apple fanboy website: https://www.macobserver.com/columns-opinions/devils-advocate...
US news orgs have a duty (implied by their extra-Constitutional protections) to ferret out NSA misdeeds but editors/journalists find celebs so much more intriguing.
There are no doubt some dead journalists and activists that would still be alive today if iPhones truly were secure and/or private.
iCloud Mail aliases versus Gmail aliases: Google exposes your main address at all times: HeyGuysLookWhoItIs+TotallyNotMe@gmail.com
iCloud lets you have completely different aliases all forwarded to the same main account which no one else ever has to see.
AND you can see which apps have been given which aliases from one convenient list.
But of course facts like this will get buried to maintain the tired “everything sucks the same” narrative here.
This zero-click iMessage exploit is unique to iPhones.
As I said, the zero-click exploit is exclusive to iPhones using iMessage. An Android device that receives a similar SMS requires the user's knowledge and willful intent in order to activate. The last zero-click SMS exploit had been patched back in 2015.
So the device (and protocol) does actually matter.
It was said that He would be alive if He wasn’t using an iPhone. This is stupid.
The end objective is that Saudi Intel wanted him dead.
If He used Android, an Android zero day might have been used, of which there are many.
In this case, He used an iPhone. A different phone, or no phone, would have made no difference to a state level actor.
There are objective reasons where Apple is better at privacy.
For example, one of the things that benefits me the most personally:
iCloud Mail aliases versus Gmail aliases: Google exposes your main address at all times:
HeyGuysLookWhoItIs+TotallyNotMe@gmail.com
What even is the fucking point?
iCloud lets you have completely different aliases all forwarded to the same main account which no one else ever has to see.
Worried about state actors? More power to you, but good luck with that. Most people don't have the time, energy or paranoia (justified or not) to figure that out and keep on top of it.
Worried about stalker capitalism? Google is eagerly selling your data to the highest bidder = I have zero faith that their OS isn't snarfing up everything it can to sell to anyone who will pay. Apple has a different business model = I have some faith that they aren't selling my data.
What they do do is use your data to decide what adverts to show you.
If they sold your data, they'd risk a rival company buying it and making a better ad network.
iOS 14 released anti-tracking features in April of 2021. This article is released at the end of september, almost october, of 2021.
Yet, the authors choose to specifically use a version of iOS that was prior to these changes.
This is proof enough for me that the authors purposely skewed the data. This skewed data does not reflect reality, and so the data from this study is not data.
I hope the rest of this community is savvy enough to realize this article is attempting to dupe the readers into a false conclusion.
Also, this is a preprint, so maybe they do expand on the final pub.