That’s a no for me, dog.
That’s a no for me, dog.
> Bouncer does not share, upload or send any of your personal information or SMS messages to a remote server. All the filtering happens locally on your phone, based on your own private word or regular expression list.
For some reason, that instills terror in me.
Verifiably open source packages are a net positive to security because it ensures the code running is the same code that has the public's eye on it.
People keep forgetting this, because they spend most their time thinking about security in the terms of a enterprise system, but for a personal usecase, an app extracting data to their servers that i was not expecting is a info leak security breach.
Its just that acknowledging that fact requires treating most operating systems (ubuntu, (but not debian) android, and ios included) as malware and this is a uncomfortable position.
But it's reproducible builds that scare you?
It's part of the glamour that Apple has built around its products, but it is mainly a marketing thing. After all Cellebrite and Pegasus manage to break through just fine.
The big benefit though of reproducible builds is that what you see in the code repo is actually what you get on your device. There is no reason to hide this code like Apple do, it's not 'magic' and having visibility helps against apps abusing the users' data.
This must be a new take on the word "private".
iOS: Disable WiFi (not just cellular) for specific apps without jailbreaking https://tinyapps.org/blog/202209100700_ios-disable-wifi-per-...
Sounds like a boilerplate warning for people that wouldn't consider the security implications.
(FYI, your email provider may have access to the contents of your email. I assume that's a "no" for you "dog?")
That said, Apple doesn't really handle the case of permissions changing with an app update very well, so launching your app purely device-local then updating to add something server-side a year later would probably let you get around that.
This app seems to not have the key that'd indicate it's capable of sending anything to a server: https://github.com/afterxleep/Bouncer/blob/master/Bouncer/In... (though, you know, that assumes that the build on the App Store is directly from the source we can see...)
Isn't App Store review supposed to at least catch things like that?