Wait a second, TFA itself talks about how obfuscation can limit the service area of data that third party apps can phone home with.
> Trackers can’t send data that they don’t have access to, so the most direct technical fix is to limit or eliminate app access to information that is used to fingerprint devices. In iOS 15, apps are allowed unlimited access to device data that are totally irrelevant to their functionality. For example, why would any app need access to the exact second that the user last restarted their iPhone? And why does iOS give apps access to this data in such a high degree of precision? Data such as an iPhone’s remaining battery and screen brightness (both accurate to 15 decimals), or an iPad’s remaining free space (down to the byte), serve no legitimate, non-fingerprinting purpose for most apps. And for the rare app that might need this level of precision, App Review should approve the usage on a case-by-case basis.
Even without App Review, Apple could build into the API the explicit use of a permission requests system (extending beyond the current one), that itemizes all of the types of permissions a developer can ask (to complete specifics), add that to the existing section in the Info.plist, and expose that to the user when downloaded into a UX that goes into specific details about what the user is exposing. Better yet, to turn off features as granular as access to "what keyboards are on this device."
Apple could build GDPR into its system itself, while obfuscating the data it leaves out, as with some of the aforementioned links. So I see now obfuscation is only part of the puzzle, the rest is making the permissions system even more robust.
> the only way to disincentivize this behaviour is with policies that ban it and the threat of expulsion from the App Store if you're caught.
If the claim is that only App Store review is sufficient, then the App Store does not go far enough. The article states "Apple also needs to take a hard line against closed-source trackers — especially the ones that further encrypt the data they’re sending to third-party servers [...] the only way to ensure the tracker isn’t stealing any of this, is for the tracker to reveal their source code." Mandate that tracking APIs and libraries must either be open source, or make themselves open to App Store review. If not, then the App Store is just a fig leaf, a half-measure.