Facebook sued for skirting Apple privacy rules to snoop on users
bloomberg.com
bloomberg.com
A week or two ago I had to fight with app review over some functionality that was behind a login screen (they thought it should be public, I disagreed) and for my pre-permission-request screens (you know, the screen almost every app shows before firing the system prompt). Turns out you can have that screen but you can't ask a question on that screen or offer a way to dismiss and not get the system dialog. That was news to me since I had seen countless "Do you want to enable push notifications (yes|no)?" screens in top apps but that rule has changed and no longer allows you to pre-ask. I complied but the very next day I opened an app from a billion dollar company and I got a pre-ask that I was able to dismiss without popping the system dialog. wtf...
Why am I expected to bend over backwards for app review when these serial abusers get a free pass (no ban AND they can do things smaller apps get slapped down for)?
I know the answer is "money" but I fucking hate it.
Can you expand on this? I'm not exactly sure what you mean. To clarify, I had 2 issues:
* App review thought part of my app should not be being a login screen, the data on this screen was fetched via our API was was authenticated (not a super easy change to expose that and we don't expose it to unauthed clients on purpose.
* Our app asked the user if they wanted to allow location access to see nearby stores on our map page (only asked when they went to the map page). We didn't pop the system dialog unless they agreed first to our own permission prompt (since you can only pop the system dialog once). This is against the rules now, which is fine, my frustration stems from continuing to see this practice everywhere.
This kind of sounds like being mad that the cop pulled you over for speeding, despite everyone else also speeding. I know it sucks and it feels like you're being singled out, but generally "everyone else is breaking the rule, too" has never been convincing to rule enforcers.
I worked at a company that always tried to walk the line right up to the edge of Apple's rules, and unsurprisingly kept running into trouble with app reviews. The company kept wanting to dig in and fight because "our_competitor does the same thing". My advice was always that it's pointless, and we'd be better off just concentrating on our app and fixing it.
At this point in my career, I almost feel like I could make money simply being an "AppStore Rules Consultant" who flies into a company, says "Just Do What Apple Said In Their Message!" and take home my fee.
It's a little closer to being pulled over in a Honda Accord with 200K+ miles on it going 71 in a 70 zone while Tesla's and BMW's fly by at 90+. Also those Tesla/BMW owners have had hundreds of tickets but somehow keep their licenses.
Yes, I know this is actually probably completely/near accurate to the real world, money runs everything, but it doesn't mean I have to be ok with it. I'm not advocating I should be allowed to "speed", just that it's frustrating to be the only one getting pulled over with (ok, I've stretched this metaphor as far as I can stand) a tiny dev team while billion/trillion dollar companies, for which my entire team is less than a rounding error, get away with murder.
So that cop who pulled you over? Did he have a bad day with his wife that morning? You’re getting a ticket. Tomorrow? Possibly not.
It's different when every single app gets a review and these behaviors can be controlled at a bottleneck.
Your analogy is more apt if Apple decided they would only display websites that did X. And websites might pretend to do X for a little while, and then quit. And there's billions of them, not enough enforcers, and no simple bottleneck where they pass/fail BEFORE being released.
I'd not want to suggest that something is "minor" in a system I'm not familiar with.
I love the web, but users and companies just want apps, and I want to get paid.
Of course if you're doing client work you have to build what your clients are asking for and yeah the web is not a substitute for native in all cases.
Is it just for telemetry? Just for push notifications? Just because their competitor/idol has an app and they want one too?
It's not for telemetry (at least at the scale/size of companies I deal with). As far as I can tell it's the prestige. I know this because our initial app had no push notifications and the clients who paid for it wouldn't stop asking about an app and didn't even touch the (identical) web version.
Push notifications are part of it for sure but I just wanted to give an example of a case where there were no features that were app-only but all they cared about was the app. I'd say "Yeah, we have that new feature and you can see it at yourbrand.ourcompany.com" and they'd say "Ok, when will we have an app?", felt like I was taking crazy pills but I've seen this exact same conversation repeated at multiple companies, multiple clients. And lest someone thing this is a subdomain-related thing, it's not, I had the same questions when we setup the web version at theirdomain.com.
And then there is there is the polish level. Apple has spent god knows how long polishing each and every native interaction. All the animation curves are perfect. You lose all of that polish when you build a web app.
I think it is not primarily related to notifications and telemetry, although that's obviously part of it, or to access to your contacts or whatever, like in the case of FB. My theory is that it's much simpler and dumber than that: that "number of app installs" has simply become a metric that managers can use to promote themselves inside a company, and that companies can ultimately use to sell shares. It's an engagement metric, and since there is no metric for "home screen bookmarks made", there is no way for companies and managers to gamify the web site. Therefore, they simply don't care about the website, except as a means to get you to install the app. It's all a bullshit numbers game.
I know the users can create the icon themselves by saving a bookmark to the home screen, but for some reason they seem not to.
1. It puts an icon on your phone's home screen which reminds you it is there and encourages reuse.
2. They can put notification counters on said home-screen icon.
3. It is generally easier to convince people to enable notifications on the app than on the website.
4. User perception. Some users expect an app and look down on a website. (Even if functionally identical)
5. Blocking ads on websites is much easier than blocking them on mobile.
6. It can provide better tracking and analytics.
7. The app can provide a better experience.
7a. The ability to pre-download the application makes it less costly to provide more features and code. The just-in-time downloading of web applications means that the size of code, data and resources generally needs to be more carefully considered. Of course you can do careful code loading for webapps but it requires custom code instead of being managed by the store.
7b. Native apps generally have access to more APIs especially without needing to request special permission (contacts, device sensors, large amounts of storage, etc)
7c. Access to native UI toolkits can make the application fit into the expected UX better.
[1] https://developer.apple.com/documentation/usernotifications/...
*Interviewee exits, pursued by a door*
Interviewer: “HR? Yes, please make a note not to offer that candidate any other roles, thanks. Yeah, for some reason they seemed to think their personal preferences were more important than solving our customer needs. Would be a terrible fit.”
Places which make me feel the way that you’re describing, I don’t even reply to the recruiter.
I'm still not sure if the PWA push was the plan and they changed to the app store or if it was always something to tide people over. I believe the reporting has said they honestly thought PWAs would be good enough and then reversed course but it didn't take them long before they just went all-in on apps.
All that said I'm not really a "the web should be able to do everything apps can do"-guy, I think the constant permission requests would be incredibly tiring while browsing the web. Though maybe you, as a user, would need to first "promote" or "whitelist" a url before it could even ask. Idk, just sounds like hell.
1. Make the web a suitable platform for application delivery
- or -
2. Allow third-party alternatives to the App Store
Apple doesn't like it. No shit, their shareholders would throw a riot if they abandoned their 80-billion/year cash cow. Unfortunately, that exploitation is a very real consequence of first-party vendor abuse that we shouldn't have allowed to happen in the first place. Microsoft tried making the web into their "App Store" a few decades ago, and they were rightfully sued into oblivion and beaten with rolled-up newspapers. We should have done the same thing to Apple before they became so self-entitled.
If you don't want to use the web for apps, then don't. I'm sure Apple would be happy for you to spend that money on the App Store instead, where they can happily take their cut. But consumers need the option. That's just not up for debate. Apple will kick and scream and make it as ugly as possible, but that's purely because they're facing technologies that threaten their business model as they know it. How long can they continue to do this before the dam bursts?
This idea that web applications only “count” if they can send push notifications is bizarre. You know everybody was building web applications just fine without push notifications before 2009, right? And that native iPhone applications didn’t have push notifications either to begin with?
Just because Apple added push notifications to native iPhone applications, it doesn’t mean that all web applications suddenly ceased to be “real” applications because they couldn’t do it yet.
As for building apps for clients - I find just the opposite to be true. They don't want to be subject to the whims of the review process. They just want to deliver their service to their users.
What users think is not really relevant. They'll use it if they have to or if their friends are using it.
I also once got told (on the phone with a reviewer) that I couldn't say
Allow "My App" to use your location?
In the title of the permission dialog because I was "leading" the user to allow. Never mind that the title of that dialog is system-generated and you can only edit the description that shows underneath. I went 3-4 rounds with the reviewer saying I didn't control that while they insisted I did/could. I finally gave up, made 1 other change they requested, then resubmitted and it went through. Reviewer roulette sucks.If you care about privacy, small apps are much more dangerous (on average of course).
Have you seen data practices from smaller data brokers vs big tech?
Big tech uses your data, but they try to protect it (with various levels of success), as it’s more valuable to them. Small data brokers literally sell everything (and not like big tech, where they sell you services that utilize it, but raw data) they can, directly, to anyone.
Reddit is terrible, and Twitter is middle ground.
I wish it was applied fairly, but I am thankful for that rule, because it reduces the amount of “soft requests” where the app will continue to pester me relentlessly about enabling access to my contacts or something
If this behavior really is common, I suggest complaining to the relevant authorities.
I'm sure the parts of the EU trying to block Facebook spying and outlaw app stores would be extremely interested, for example.
Apple enforcement on rule changes has several different options:
a) only applied to new apps
b) only applied on next app submission
c) app will be removed on date unless it's fixed
This sort of change seems likely to be in category A, and then over time will be in category B and eventually the billion dollar apps will get an update denied until they fix it. They may drag their feet a little or a lot first.
Some of the subjective review things will get flagged only sometimes, so you might get through if you resubmit with no changes, or if you only address some of the requests. Inconsistent enforcement is frustrating, of course.
I completely understand and agree with the different options you outline but I don't think that was done in this case, at least publically. Please, if I'm wrong and someone has a link to an article about this I'd love to see it/know about it.
We regularly (multiple times per month) launch new applications in new Apple developer accounts where we present a screen explaining what notifications we send and two buttons, one of which says “Notify me” that triggers the system permissions prompt, and one of which says “Not now” and continues without triggering the system permissions prompt.
I’m not sure of the precise difference Apple sees between what you are doing and what we are doing, but this is not a roadblock for us, so perhaps copy that approach more closely and Apple will relax a bit?
I've shipped new apps that didn't have the ability to delete user data well after Apple's deadline and some sneak through ("sneak" but I wasn't trying to sneak, I just forgot to add it to one of my apps, I quickly added it in the next update so I didn't run into a brick wall later if they noticed) and some are caught.
[0] https://developer.apple.com/design/human-interface-guideline...
In my experience, Apple don’t really reject things based on the HIG any more. Last time they did for me was back in 2008. If they rejected things based on the HIG, they’d reject almost everything – look at how many applications abuse launch images to show a splash screen, for instance.
> Our screen also said "Enable Location" or "Not now"
is one of my pet peeves. It's that "not now" that does it for me. The lack of a "No" option, and having a "not now" option, is a big red flag to me. At best, it's just manipulative. At worst, it hints that I'm going to keep getting asked about it over time.
Either way, it's removing the ability to say "no", which feels scummy.
Same with "No, thanks" button on dialogs that are expected to be denied most of the time (plz subscribe to our newsletter). Sometimes I wish there would be a "No, f*ck off" button next to it, but I feel it's kinda the developers loss for not willing to collect sentiment feedback. Or just give me "No" button, but I am not thankful for being forced to dismiss your nagging.
What surprised a lot of tech execs was that when people understood how much data was collected they got creeped out and when given the option to opt-out of data collection they agreed at very high rates.
Apple's move to limit in-app tracking was genius because any lawsuit from FB or similar is counter-productive - consumers are given the option and they opt out at 99%. Suing Apple to force them to let FB track consumers would be a PR disaster.
I think we can apply this in real life with advanced AI bots, from whom Metas advanced scraping software can gather data which can then be used to show the bots relevant ads.
It's not like this is wrong. If you give consumers the choice of paying $5/month directly for some service vs. providing $5/month in personal data then they'll pretty much always choose the latter - I don't believe this has changed.
What has changed is that now third parties are better-able to disrupt companies from Meta from silently harvesting personal data as a default, and consumers generally don't mind this because they see the result as them getting to use the data-harvesting websites for free. Just like they're happy to use adblockers even if that collectively results in sites having to use heavy-handed subscription policies. If you give people the option to free ride, it's not surprising that they do it.
[1] https://www.esquire.com/uk/latest-news/a19490586/mark-zucker...
The sourcing for that claim is extremely poor. The Esquire article links to a Business Insider article from 2010, which in turn cites "anonymous sources" on a 2004 IM conversation:
> According to SAI sources, the following exchange is between a 19-year-old Mark Zuckerberg and a friend shortly after Mark launched The Facebook in his dorm room
https://www.merriam-webster.com/dictionary/might%20is%20righ...
They put out a vpn app targeting kids ... and when told not to do that they renamed it and put it back on the store a little while later.
If they can get it they'll do whatever it takes.
Sometimes an app needs to control some aspect of the external view - for instance listen to some Js event, or inject authorization - and this can be for totally legitimate reasons in the flow of the app. Then the application needs to use another type of embedded webview called a WKWebView, which by definition allows the app to see into the user's interactions in the embedded browser.
Most developers and apps use these for totally necessary reasons - but Facebook is deviously abusing this functionality.
Some of the posters in this thread are blaming Apple for Facebook's evil behavior, but a lot of totally legitimate functionality that needs this type of app/browser communication would be impossible without the ability to enable it for genuine and well-founded reasons.
If Apple wants to advertise security and privacy, as well as enforcing App reviews, then I consider that to be enough to hold them accountable if they fail their advertised promise. Apple did not respond by removing the offending app from their store either.
TikTok does the exact same thing.
As soon as they lose, they should be fined in the multi-billions of dollars again, much higher than the FTC fine that they got years ago.
Given that they won't ever change, the fines should just get higher.
Does it mean that Facebook can exfiltrate users’ passwords for any website?
And Apple has gone for the nuclear option of removing apps from the store; not long ago they booted Fortnite, one of the big earners (billions in revenue of which Apple got a percentage through their commissions), after they added a means to circumvent the app store fees, starting a long proceeding into getting it lowered or dismissed entirely - partially successful in specific jurisdictions.
Maybe as a workaround let Meta put up their own browser on the app store and make it possible for a user to choose to let let the FB app send links to the Meta browser for someone who really wants this behavior.
But don't allow the FB app to do this with no way for the user to stop it.
Chrome for iOS seems to exist for exactly the same reason, to provide a way for google to track users.
If apple were to address this, they might end up monitoring the inapp browser and prompting for the user to hop out into safari depending on the url. As of now, apps like FB discourage reopening sessions in safari. The worst ones are like LinkedIn which requires like 2-3 key presses to reopen in safari. It’s clear these apps have an incentive in keeping users within the inapp browser
I've only ever used Android, so I'm ignorant here to how iOS operates and, to a certain extent, the rules Apple has in place around this sort of thing. I would think, though, that this sentence is key:
>The Facebook app gets around Apple privacy rules by opening web links in an in-app browser, rather than the user’s default browser, according to Wednesday’s complaint.
If FB is supposed to follow iOS settings by opening links in the default browser set by the user, but is intentionally not doing that here so that they can maximize the data they collect, then yeah they'd be breaking rules.
This sounds bad...but the integrated webview is necessary for things like Cordova/Ionic/React Native/etc to exist on the platform. It's also a byproduct of iOS's pre-multitasking days where launching out to Safari was a big context change, vs now where you can just swipe back to the app you were in.
Users can't set a default browser on iOS. Apps can choose to open URLs in one of two in-app webviews (the old WKWebView or the newer SafariViewController), or they can use the "universal links" option to allow the system to open a URL (which can be redirected to another native app, should one be available to handle the domain). While SafariViewController is more full-featured (it forces the use of the system default share control and shows the URL), a lot of sketchier apps prefer to use the older WKWebView (where they can better customize the UI, hide system default controls, and hide the URL). Since WKWebView hides the URL, you can somewhat transparently route users through tracking domains (something I already observed Twitter doing), which may also be the vector Meta is using to inject JS.
All this said, the visual customization of WKWebView also has a legitimate use: many apps use it for showing regular in-app screens, not just for an internal browser.
Well-made third-party apps (Tweetbot for Twitter, Apollo for Reddit) generally let the user choose between SVC or just letting the system handle the URL, because they're not interested in monetizing user data in the same way.
Yes they can, starting with iOS 14: https://support.apple.com/en-us/HT211336
iOS doesn’t allow anything other than WebKit webviews described above. Android does support others, but that’s a different story.
No clue why I was downvoted for saying that, which was a perfectly valid answer in that context.
I fear that this will lead to an overreaction from Apple that results in blocking or severely limiting this feature, which will be a huge issue for apps that depend on it for legitimate reasons.
If apple were to address this, they might end up monitoring the inapp browser and prompting for the user to hop out into safari depending on the url. As of now, apps like FB discourage reopening sessions in safari. The worst ones are like LinkedIn which requires like 2-3 key presses to reopen in safari. It’s clear these apps have an incentive in keeping users within the inapp browser
I gotta find that article again...
They could have a privacy feature (default on) which blocks or poisons specific endpoints on specific hosts belonging to e.g. Meta, Alphabet, ByteDance.
Apple are in a unique position here to protect users' privacy since they control the browser of so many. It's unfortunate that they also have their own advertising agenda so any steps they take will always be scrutinzed as being anti competitive and simply making their own ads more profitable. But I'd still want Apple to pull the trigger on more drastic measures like these. The last round of privacy isolation should just be the start. I'd love to see apple e.g. block Facbook ads inside the facebook app and refer to privacy concerns and only unblock them if Meta follows all privacy guidelines elsewhere.
Right? If they actually cared about privacy they’d forego revenue for it. Sadly it’s just for marketing.
Slaps on the wrist are harmful especially for those receiving slaps on the wrist. No moral development.
How does this apply to a FAANG company? Nobody knows--better than another FAANG company. Yes they know each other yes they hire each other's employees yes cross-polination yes yes yes--but they also compete. And when they hold back on competition, they at least do the public the favor of doing so at a very high cost--like Apple taking $20,000,000,000 from Google in exchange for not entering the search engine market. So there the higher the price extolled, the better for the public. The higher the price, the harder for Google to pay it to avoid competition, and the more likely it will not be paid which leads to competition.
In practice every FAANG company competes against all the others on everything. This is a success! Google can't beat Apple on smartphones, and Apple can't beat Google on search (even if they wanted to), so both companies have money, so they duke it out in every battleground beyond their moat. If they don't have a moat, however, they go to shit and can't carry out that competition in every other field.