Study: Effectiveness of Apple's app tracking transparency
blog.lockdownprivacy.com
blog.lockdownprivacy.com
>...
>Not only do these trackers allow their clients to break Apple’s rules, but they specifically built features to help their clients easily circumvent Apple’s ATT privacy rules.
>First, we created a dummy app that used the Kochava tracking service. With just a few clicks, we configured Kochava to violate Apple’s “ATT Opt-Out” by asking it to tracking users across apps (using “IP address” and “User Agent”) for the purpose of ad targeting (“Paid Media”). Basically, Kochava made it really convenient for any app developer to violate even Apple’s narrow definition of tracking.
>We later performed the same test with the AppsFlyer tracking service (which, as previously mentioned, hides the data it sends off your device), and it was even easier to enable “privacy cheat mode” and track users against their consent — all it took was clicking a single button.
Wow.
I know some of these tracking APIs send data to third parties directly, but if that was banned all this traffic would just be re-routed through the app developer's back end so it would just sweep the problem under the carpet.
We can see from history with Facebook that shady dealings with data to third parties has been caught in the past, it's quite possible to get away with it but also we know that it also has a tendency to come to light.
Anyway, what's the alternative?
In the end this is not a technical problem but a juristical one.
Then despite all of the anger against restrictive App Store policies and behaviors, the App Store is still insufficient to prevent intrusive user tracking.
> Anyway, what's the alternative?
OS-level protections that obfuscate on-device data in such a way that third party apps cannot collect the actual data. Or restricting developer access to that information in the first place.
https://venturebeat.com/2012/06/20/new-patent-will-apple-clo...
Looks like they have a recent patent for obfuscating location data, too
Let's say I have a calendar app and ask users for permission to access their address book, how would obfuscated address data be useful to the app? Of if I have a navigation app and need access to location data, how would you obfuscate that and still have it capable of navigation? I suspect you haven't thought this through.
https://www.patentlyapple.com/patently-apple/2012/01/apple-w...
https://patents.google.com/patent/US20110206285A1/en
And a follow-up: "gaze-dependent visual encryption"
https://appleinsider.com/articles/20/03/12/gaze-detection-ma...
And even more articles:
https://www.patentlyapple.com/patently-apple/2011/05/apple-w...
https://www.patentlyapple.com/patently-apple/2011/08/apple-i...
Can you give me an example of how obfuscation prevents an app, with access to data it needs to function, from sharing that data with the developers. Because as far as I can see it’s irrelevant to this issue.
> Trackers can’t send data that they don’t have access to, so the most direct technical fix is to limit or eliminate app access to information that is used to fingerprint devices. In iOS 15, apps are allowed unlimited access to device data that are totally irrelevant to their functionality. For example, why would any app need access to the exact second that the user last restarted their iPhone? And why does iOS give apps access to this data in such a high degree of precision? Data such as an iPhone’s remaining battery and screen brightness (both accurate to 15 decimals), or an iPad’s remaining free space (down to the byte), serve no legitimate, non-fingerprinting purpose for most apps. And for the rare app that might need this level of precision, App Review should approve the usage on a case-by-case basis.
Even without App Review, Apple could build into the API the explicit use of a permission requests system (extending beyond the current one), that itemizes all of the types of permissions a developer can ask (to complete specifics), add that to the existing section in the Info.plist, and expose that to the user when downloaded into a UX that goes into specific details about what the user is exposing. Better yet, to turn off features as granular as access to "what keyboards are on this device."
Apple could build GDPR into its system itself, while obfuscating the data it leaves out, as with some of the aforementioned links. So I see now obfuscation is only part of the puzzle, the rest is making the permissions system even more robust.
> the only way to disincentivize this behaviour is with policies that ban it and the threat of expulsion from the App Store if you're caught.
If the claim is that only App Store review is sufficient, then the App Store does not go far enough. The article states "Apple also needs to take a hard line against closed-source trackers — especially the ones that further encrypt the data they’re sending to third-party servers [...] the only way to ensure the tracker isn’t stealing any of this, is for the tracker to reveal their source code." Mandate that tracking APIs and libraries must either be open source, or make themselves open to App Store review. If not, then the App Store is just a fig leaf, a half-measure.
I quit a job over this. I don't remember exactly which service it was we were using (mixpanel maybe?) and we found out some users where blocking access to service servers (either at router level or something else). The solution? make a proxy api endpoint that would just re-route the calls to the service.
I beg and begged, saying 'look, these are users that specifically blocked 'service', lets respect that and get our data from the users that haven't' (this was before the Apple privacy changes a couple years ago). I was steamrolled because they knew better than users. I handed my notice the moment the ticket landed in the board.
I care deeply about this stuff, and I’ve read a couple of contemporary public studies - both corporate and state funded - that suggest that end-users really do care about this stuff too, and that abandonment due to poor privacy policies can be on the order of 40%. Forty percent!!
So I started my last business with this in mind: a pro-privacy fintech business. We were gonna be proud of our privacy policy and implement it using technical means.
But the moment the investors came along, I got stonewalled. They didn’t care about the research. They didn’t care about the users. They just had this belief that a user friendly privacy policy would somehow hurt the business and they refused to commit to what I saw as a key advantage of the product. Our privacy policy was a nightmare. We had almost nothing to give users.
I quit too, and to this day, I have no idea what could possibly be worse than 40% abandonment in a sales oriented fintech.
Maybe something like small stockholders would work, as they are not even allowed to vote in the direction the company takes, so their only influence is selling stock (voting with their wallet). It would certainly widen the door for fraud, but it's not like fraud in uncommon with the current system, and I'm tired of seeing how this tale keeps repeating in practically any area of commerce.
If it's any consolation, running a proxy at least increases the baseline cost of using 3P trackers. User telemetry and other data is small, but for popular apps that adds up and gets factored into the equation on whether or not to use 3P.
Before that happens Apple's privacy campaign is just a lot of hot air.
And location, including demanding “precise” tracking (why does Apple even let them detect that?)
i.e. Has the right intentions but just ends up forcing a worse user experience for everyone.
Even with tracking disabled, apps will still contact third party ad/tracking servers. Just this morning on iOS:
- app-measurement.com
- play.googleapis.com
- googleads.g.doubleclick.net
- mobile-collector.newrelic.com
- inapps.appsflyer.com
- api.mixpanel.com
- graph.facebook.com (this is a major offender, even if you don't have Facebook apps installed, other apps love to feed FB data)
Another thing, the "ask app not to track" doesn't mean that data won't be collected. It means that this particular user must not be identifiable across different apps / web sites, even if personally identifiable data is being sent. Authors completely ignore this point.
It is the major visible prevention method.
App developers who track anyway live in fear of Apple finding out and executing its nuclear option: banning them from the App Store.
Smart companies don't risk $10,000,000 in app revenue in order to sell $10,000 in user data.
I also have no clue why those apps work (aside from the vague notion it triggers our lizard brains to gamble even with fake money), but I'd sure recommend you listening to the linked talk if the subject entertains you, I had found it really interesting and the speaker is a great story teller (IMO anyway).
https://www.theverge.com/2017/4/23/15399438/apple-uber-app-s...
Though I may be remembering that wrong. It was discussed extensively on HN at the time.
Someone on HN wrote that they always look at how a company is funded before engaging with them so they know where their incentives are. I thought that's a pretty good idea and am trying to apply the same idea here.
I can find the backstory but I don't know how the company is able to operate and continue developing.
The fact that stuff like this isn't caught in the automated portion of review is fairly appalling though.