App Store on iOS 14.6 sends every tap you make in the app to Apple
twitter.com
twitter.com
> The strange thing is that Apple introduced strict measures in iOS 14.5 to prevent developers from fingerprinting users.
The dialog text in their screenshot reads:
> Allow “App” to track your activity across other companies’ apps and sites?
Users refusing this permission are not prohibiting tracking by the company that issued the dialog. They are prohibiting the company from tracking users beyond the boundary of their corporation. Apple’s App Store app is within the boundary of Apple Corporation, and so the tracking dialog shown is not relevant to their complaint.
(I have no viewpoint to offer on OP’s argument beyond the logical reasoning error described above.)
For example, I am seriously considering doing exactly what you describe as “nobody does that” — having to repurchase all my apps and redo all my settings — in order to complete my transgender name change. Apple refuses to purge my old deadname’s iCloud email address, and so if I want to remove it, I’ll need to start a new Apple account and re-purchase all of my apps and content.
If you truly have a request like this, send an email to the person in the executive team responsible for Apple accounts, they’ll probably have executive relations fix it for you.
Apple may or may not care if users switch accounts. Only Apple confidential knowledge can prove or disprove this argument with certainty. In the absence of certainty, a best-faith effort must be made to determine whether their actions support or contradict these assertions.
The claim “Sure they do” is unsupported both by available evidence and by a good faith interpretation of their material actions. Apple’s public statements and app store policies do not support the assertion “More data is better”. There is no indication that Apple is performing enrichment of accounts using third-party data.
The person you are replying to was merely offering an example to contradict a blanket statement without a factual basis, essentially that Apple does not track users because the user is already logged in. The respondent presented a situation in which that reason would not apply.
Also, your way of engaging people in this way is annoying -- specifically starting every reply with 'This argument’s logical error' and then coming up with a seems-right-at-a-glance breakdown of their argument's faults. Are you doing it on purpose to annoy people?
Unsupported arguments based on misconstrued statements and logical fallacies waste all our time here at HN. Do better, please.
So that will persist across devices and accounts.
And before you say that's crazy, location information can mean they only need to distinguish a handful of people at a time.
So switching accounts would not only mean you lose all of your App Store purchases, iCloud data etc. It would mean having to get a new credit card.
That would make the likelihood of this scenario happening being pretty slim.
Apple has access to the logged-in account’s properties, as you assert, but this does not rule out Apple having other incentives for tracking.
This doesn't look like tracking or fingerprinting at all to me - they're logging user interaction (that many apps and websites have done for decades).
Even if they didn't do this just about every click you make in the App Store results in a query to their backend for more information, presumably with the account id (so family, regional, parental control works).
Also, I recall a case where MacOS was asking Apple permission whenever the user wished to start an executable. This is nuts.
>Also, I recall a case where MacOS was asking Apple permission whenever the user wished to start an executable. This is nuts.
Not that nuts. It's intended to be able to blacklist malware and such and retroactively disable it, through notarization (basically, registering apps to Apple and them getting a kind of fingerprint).
They could have done it with a local cache (and they probably do in some capacity), but it would still need to ask/sync every now and then.
No, because you can make your phone work with other service providers. The dependence on the original hardware vendor is artificial.
> It's intended to be able to blacklist malware
Choice of blacklists, content filters etc. is also orthogonal to the vendor.
Yes. But then it wouldn't be a commercial commodity product, it would be more of a build-your-own DIY kit. Would it be as succesful?
>Choice of blacklists, content filters etc. is also orthogonal to the vendor.
Everything is orthogonal to the vendor, even choice of screen or disk.
But most people don't like choice, want something that mostly works as is. And even for those that do the optionally increases the product complexity, maintainance, and error condition space (integrated vs mix-and-match).
Plus, a few modular laptop and mobile phone designs never sold well.
Apple most definitely sells you a service, which is a managed computing platform. Alternatives exist. (And if they don’t, that’s not Apple’s problem.)
"Alternatives exists" sounds a lot like this fallacy: https://en.wikipedia.org/wiki/Ergo_decedo
The world isn't as simple as: there are companies and they can sell whatever they like, and there are consumers and they can buy whatever they like, because that would end very badly for the consumers.
Personally analytics don't bother me, I don't think they're a significant privacy issue. The service provider already knows almost everything you do with the service anyway, just as a requirement to provide the service. I don't believe that invasive regulation on the detailed behaviour and functions of a phone by governments is genuinely in the interests of users. I suspect that the detrimental effects would far outweigh the benefits, which would only be useful to a tiny fraction of users anyway.
But what confidence do you have if the product you bought is tethered to the original vendor? What if they decide to do something that makes you unable to use the product?
As for making the product unusable, they can do that anyway through OTA updates, which are applied at the user's discretion. If you think that's a problem then you should regulate that, not some other technical issues that may or may not be related.
Knowing is not the issue. The issue is they use that understanding to their advantage, not yours. Their duty is to maximize shareholder value, not your health, happiness, and well being.
I'm not saying don't use them. I am saying it's naive to trust so blindly.
The fact that an argument is superficially similar to an informal fallacy doesn't make the argument inherently fallacious. You can easily construct a variation of the same conversation which is structurally identical but is obviously not fallacious—
Critic: "I want a banana, but I don't like the texture."
Respondent: "If you don't like them, don't eat them."
What the respondent said is only a fallacy if the purpose was to counter the criticism. But the criticism wasn't rejected. What was rejected was the unstated but implied assertion that the critic was entitled to a banana which satisfies them.Now let's turn that into an "alternatives exist" argument and replay—
Critic: "I demand a banana that I do like."
Respondent: "I understand your desire for a banana which suits you. However nobody is obligated to supply you with such a banana. Thankfully, alternatives do exist, such as the nectarine."
That's not a fallacy. And it's not a fallacy to say that Apple is not obligated to make an iPhone which satisfies you. Especially because it's a statement of fact.If you don't like that you can't buy an Apple branded dumbphone, and you have failed to convince Apple to make it for you, perhaps try lobbying your government? They could pass a law which requires smartphone makers to also sell dumbphones.
However in many cases I can only do that via an app, and apps are only available on iOS or Android. Your argument a based upon me being able to buy something from an alternative manufacturer, yet here we are. And I have to purchase Apple or Android to be able to function in society.
If Apple isn't going to follow open standards yet be the largest phone manufacturer then we are going to have to regulate them. You don't have to be the only company to be a monopoly.
If you did, what has any of that got to do with anything I wrote? How does your complaint relate to what I’m talking about? Which open standard, specifically relevant to your ability to access your bank account and do your taxes, is Apple not following? And how is that relevant to concerns over privacy?
(Seriously, I’d like to engage with your argument but it seems like you’re confusing a discussion about the choice to buy a zero-tracking device with a unspecific complaint about standards.)
don't connect it to the internet.
It's not perfect, but at least I don't have to open the settings app each time.
To add insult to injury, when you automate WiFi and Bluetooth to turn off when you leave your home you need to manually affirm this action via a notification every time.
Super annoying.
If you search multiple times for the same term you will see a slight variation in search results, that's how they give apps a chance to move up or down. IE they move you down one slot but you still outperform the app above in CTR, you probably should remain in your current spot, or move up. Another app gets moved in front of their current ranking and the app that got moved down outperforms it in CTR, keep things as they are.
They can see where users are struggling with the app and where extra-guidance is necessary.
I'm assuming many many many other apps and web pages are doing the same thing.
Nothing to see here.
I really don't get the outrage about that, it's something that has existed for 15 or 20 years at least and is used a lot on most websites you go on.
What private information do you think is sent to the vendor that would not be otherwise?
If it only exposed information the user was already sending, the vendor wouldn't bother with the spyware.
> What private information do you think is sent to the vendor that would not be otherwise?
Depends on the app; I expect, for instance, market apps (Amazon, Walmart, etc.) to watch the user's every move to try and better model the user's mental state in an effort to get them to buy stuff that they wouldn't have done otherwise.
Not being funny but I think you’re vastly overestimating the capabilities of most engineering teams.
Just because they may be bad at something doesn't mean they don't attempt it.
You can see how valuable this tracking is by the amount of websites begging you to install their native apps. No thanks!
I just try to minimize it.
I'm not an app developer so I don't know specific, but by the amount of websites begging you to use their native apps it is quite obvious that there is something they get from the native apps they can't get from the website that they are very interested in.
Just try to go to the reddit website on a mobile (not old.) and see how fast they spam you with the app prompt.
If you block that data, most webapps, especially things like an app store, will be useless.
If the website is not using a third party site for tracking, you can’t block the owner from tracking and storing your interactions.
I personally use that + VPN that cuts the rest that sneaks in
They can see where users are struggling with the furniture and where extra-guidance is necessary.
It doesn’t necessarily require capturing video of the user.
A better analogy would be hooking up a door open/closed sensor to the cupboard, and capacitive sensors that log the location of touches, so that you can analyse what % of users struggle to find the door handle.
Tracking invades one of my most used tools, and what's worse I can't see all the tracking that happens.
Still think this isn't invasive?
I mean if you choose to use someone’s service, you’d want it to get better. And one of the reasons they get better is by collecting feedback of what’s working, what isn’t.
It’s very hard to nail down a good ux without feedback.
That's what you're doing to your users.
I'd consider that something to see.
(I don't have any evidence to believe LogRocket are doing this; LogRocket is just the example. Other tracking services exist, and they sure as hell do do this sort of thing.)
There is good book how it works in offline world. https://www.npr.org/2017/02/13/514322899/aisles-have-eyes-wa...
(via https://news.ycombinator.com/item?id=33527141, but we merged that thread hither)
I certainly did not think Apple would do this.
Their PR department certainly earns their keep.
I also wish they would've tried Lockdown Mode, at least.
Given that the app store comes installed by default and can't be uninstalled, it seems fairly reasonable to assume that it's part of the OS. Therefore it's not unreasonable to assume that disabling "device analytics" would also disable app store analytics.
On iOS, there is no mouse cursor, so there is nothing to track in the first place.
On macOS, you have to give permissions on a per-app and per-domain basis. For example, if I want to let Google Maps use my current location, first I will get a prompt to give that permission to the browser I am using in the OS settings, and then I have to give that permission again from within the browser specifically for Google Maps. Also, the web browser shows which specific permissions a page I am on has, and I can revoke them at any given time. Same thing for tracking mouse cursor movements, except it is governed by the macOS accessibility permissions iirc, rather than location permissions, and I don't remember Google Search ever requesting that. Just checked, and the only app that has those permissions on my machine is Discord, and it requested those only when I attempted screensharing.
Maybe I am mistaken, and there is some trick around needing permissions to track mouse cursor movements in a browser on macOS (especially given how complex in-browser JS execution behaviors have gotten over time). In which case, someone please correct me.
I agree though, tracking mouse cursor movements is definitely a bit more surprising and unexpected than tracking what you type in the website's search bar. Which I would be way more surprised by it not being tracked. It's like expecting Amazon or Steam or Twitter to not track what queries you search for in their search bars (which all of them definitely do, as evident by you being able to look at your search history from within the website).
Just like when you chat with a company through one of those web chat apps, they see everything you type, even if you delete it before you press enter to send it. That is tracking on the modern web.
Talk about feeling like a lab-rat.
You're asked whether you want to send analytics to Apple as soon as you set up any device.
If the "only thing" you can conlcude is user error, you must be unfamiliar with the insane amount of ambient telemetry iOS/MacOS collects even when disabling analytics (OCSP ring a bell?)
Personalized Ads is a different setting than the one I described, located in the "Apple Advertising" section, not the "Analytics & Improvements" section that I think the relevant setting lives in.
"Data usage" isn't the name of any setting on iOS, that phrase is too vague to be sure what they mean.
This is why I say that I'd like to see a screenshot of the relevant settings panes. How do I know this person didn't accidentally flip them back on during an update?
OCSP isn't relevant to this issue. It's not "analytics," it does not seem to collect personal data, anonymized or not.
OCSP is used to verify/revoke certificates, essentially for the purpose of removing malware and spam, which is a basic function consumer-friendly OS: https://apple.stackexchange.com/a/420002
To me that's a really legitimate use of a "phone home" when we're talking about commercial consumer operating systems.
It is disingenuous of them to use the word ‘Tracking’ for everyone else and ‘experience improving’ for themselves.
(this is regarding your comment not the article itself)
Really frustrating to live in a country that wants forced socialization if their is opportunity to make money off me, but otherwise I’m just a cost center.
In no way does my use of an Apple device act as an open door for anyone else.
I’m not interested in technology to help some coder feed himself but because tech is fun and intellectually interesting.
Sure, as long as your definition of "anyone else" excludes the NSA, FIVE EYES, China, anyone distributing Pegasus, Akamai and the rest of Apple's contractors.
You see a handful of corrupt government agents. I see a world where billions do not kill thousands of government agents.
The public has made its choice. Some vain apes on HN who see deluded masses in need of rescue may in fact be the deluded fools.
The text of the prompt people are talking about is "Allow MyApp to track your activity across other companies' apps and websites".
Third party tracking mandates permission. First party tracking and data sharing mandate disclosure.
The Tracking popup requests that the user allows an application to send a unique identifier which can be correlated by other apps, advertising networks, social media platforms (eg. like buttons, embeds, etc), in order to correlate a user's identity between different properties on the web in order to personalise advertising. AFAIK Apple does not participate in this form of tracking
Apple does ask users if they want to opt-in to analytics (for Apple) and separately for third-party developers. This refers to allowing an application to submit analytics data purely for that application or for the operating system and not in a way which tracks the user between apps owned by different companies
In this case Apple is violating their own opt-in analytics policy with regards to the App Store application. It appears to be collecting analytics data even when a user has opted out of submitting analytics
It's like someone breaking into your house and rummaging through your desk taking photos because that suits them and there is fine print. One day as a society having a networked cpu involved in someone doing something won't make nearly every lawmaker, lawyer, judge and customer have their brain fall out of their ear and they'll actually be able to think critically about it and respond.
"But facebrick/goog/the stasi are a little bit worse so..."
Apple is as american as apple-pie. "If you don't pay for it you're the product." Comes up whenever Apple create yet another problem for which the "best" solution is to pay apple even more money.
Apple customers are an Apple product they sell. Paying Apple does not remove you from that. No matter who is your provider you are the product right up until the point someone can go to jail for it. Fines are merely a business expense and treated as such.
CEO can do time for breaking the rules. Whole different approach ensues.
What rules? How to enforce? How to interpret? How to ensure the courts don't just have a mental breakdown, throw up their hands and pass because a cpu attached to a network is on the critical path of what was done that would be clearly, wholly and totally illegal if it were replaced with an army of workers and a mountain of paper and filing cabinets.
[0]https://www.nytimes.com/2020/10/25/technology/apple-google-s...
>google pays Apple "an estimated $8-12 billion"[0] to be default search and as a result track almost all iPhone users' searches
> Do they know that google pays Apple... to be default search
This statement comes off a bit ironic in the fact that you are pointing out a deal that Apple has with Google -- the current steward over Android -- as a reason that Apple isn't a bastion for privacy. This irony highlights the fact that one is often worse-off from a privacy perspective in using Android -- the main competitor to iOS -- because it is built with Google as a first party.
I absolutely agree that there is an exaggeration of privacy with Apple. But in most cases, iOS does actually do privacy better than Android. Private Relay, App Tracking Transparency and Google not being a first-party in the development in the Operating System are things that come to mind. Additionally, according to a research paper done in 2021, Google collects around 20x more data (around 1+ TB every 12 hours) on Android compared to iOS (around 6 GB)[0]. Even if the methodology behind the paper wasn't perfect (which Google claims) I don't think anyone would be surprised that Google collects more information than Apple.
My opinion is that the sweet spot for privacy on a mobile device is to buy a Pixel (for the great hardware security benefits) and go with a custom, de-Googled ROM like CalyxOS and try to use F-Droid for all your apps. For those who are even more hardcore, GrapheneOS is awesome.
In my opinion, stock Android is far worse for privacy than iOS simply because of Google's first-party influence. And then if you go with a vendor like Samsung you not only have Google as a first party on your mobile device but also Samsung.
The only option left if you want more privacy on mobile than an iPhone is to either flash a de-Googled ROM, like I said earlier, or to go with some sort of Linux distribution on mobile -- both of those alternatives come with huge downsides.
(Sorry for the rant, I always find this topic interesting)
>Your personal data should always be protected on your device and never shared without your permission. So we build encryption, on-device intelligence, and other tools into our products to let you share what you want on your terms.[0]
and
>In iOS 11 and macOS High Sierra, we introduced Intelligent Tracking Prevention. You may have noticed that when you look at something to buy online, you suddenly start seeing it everywhere else you go on the web. This happens when a third party tracks cookies and other website data to feed you ads across various websites. Intelligent Tracking Prevention uses the latest in machine learning and on-device intelligence to reduce this cross-site tracking. It works by separating the third-party content used to track you from other browsing data, so what you look at on the web remains your business — not an advertiser’s.
This second statement, even if technically true, is incredibly disingenuous and misleading in light of the fact that typing anything that is not a URL into the safari search bar will by default cause tracking. _That's_ the issue here. "We don't sell your data, we just sell you to somone else that does"
iMessage is perhaps the most annoying offender to me because it's not end-to-end encrypted if iCloud backups are enabled -- meaning that my iMessage conversations have a high chance of not being E2EE on the other person's end.
Hopefully it made sense why I compared to Android. Apple does seem like a bastion of privacy when compared to Android -- just because Android and iOS are the only mainstream options on mobile. I would love to see Linux become more mainstream in the mobile space but I don't think it ever will, unfortunately (even though Android runs a Linux kernel, I don't really consider it Linux).
>an institution, place, or person strongly defending or upholding particular principles, attitudes, or activities.
>I would love to see Linux become more mainstream in the mobile space but I don't think it ever will, unfortunately (even though Android runs a Linux kernel, I don't really consider it Linux).
You may be interested in Nestbox[0] (not affiliated) which makes use of the madatory kvm in android 13 assuming latest kernel to run Linux in a vm with no root on android on pixel 6 and 7