Proposed class action alleges that Apple tracks users despite privacy assurances
news.bloomberglaw.com
news.bloomberglaw.com
But once they introduced new privacy controls, they seemed to suddenly start investing more seriously in their own advertising network. That, and the encryption slight-of-hand with iCloud, makes the cynic’s case for them.
App telemetry, metrics, etc might get handwaved away with a sinister phrase, like “essential for improving user experience.” But placing trust in a company on privacy due to the relative lack of financial incentive seems hopelessly naive.
Edit: just bought a desktop PC off ebay which I will install Ubuntu on and see how I get on.
Just remember, most distros have live usb stick distros so you can always try out a bunch before you decide on the right one for yourself.
For servers, these days I'd recommend Alpine on ARM architecture for a very good mix of high performance and having sane defaults set up so you can easily set up a reverse proxy, web server, etc.
No advantage, but Ubuntu is the most popular distro for regular users / tutorial customers. Ubuntu also has the widest availability of support resources, even though the information is often not Ubuntu-specific.
If you use a non-Ubuntu (or non-Debian-derived) distro, you'll need to do a little bit of package-name mapping to get the prerequisites installed. This is annoying but only has to be done once (take notes!).
The bigger problem I've had with ML libs is that they're very picky about version compatibilities. Once you settle on a set of working/compatible versions (libs, python, python pkgs), make some effort to preserve your sources. Package versions can get deleted from the official repos, be prepared to build from source, etc.
I don't know if it is as simple or if they have data checkout options. Good luck with it!
One thing I am looking forward to is a keyboard that isn't shit.
Also I never really got on with the keyboard layout. Some things are just better on other platforms like position of hash, usage of meta-keys and discoverability. I find, despite rarely using it, that I can navigate around windows 10 better on a keyboard than I can on a mac.
I mostly use my mac in "desktop mode" with an Apple studio display (that's the most difficult thing to give up) and a TKL Durgod K320 cherry MX red mechanical keyboard so I will reuse the keyboard for "the other platform"
You should be able to download the music you bought from iTunes DRM free. For the movies/etc, just pirate them. You already "bought" them so morally you're in the clear. For the software/etc, walk away from it. Sunk costs.
You can download icloud for windows as well. And slowly download shit off the web UI.
So your data is safe with Facebook too.
The only difference that I see between Apple and Facebook is that Apple is doing the labeling of its users on device, while Facebook does it on the cloud.
At the end the result is the same: targeted ads to specific classes of users.
Do you have a source for this?
How did the Apple server know what articles to serve me? I never asked for them explicitly.
So I was labeled as a user that likes tech news and cars, and the server automatically sends me stuff relevant (articles & ads) to these labels.
The data was collected through an app called "This Is Your Digital Life", developed by data scientist Aleksandr Kogan and his company Global Science Research in 2013. The app consisted of a series of questions to build psychological profiles on users, and collected the personal data of the users’ Facebook friends via Facebook's Open Graph platform. The app harvested the data of up to 87 million Facebook profiles.
[…]
Aleksandr Kogan, a data scientist at the University of Cambridge, was hired by Cambridge Analytica, an offshoot of SCL Group, to develop an app called "This Is Your Digital Life" (sometimes stylized as "thisisyourdigitallife"). Cambridge Analytica then arranged an informed consent process for research in which several hundred thousand Facebook users would agree to complete a survey for payment that was only for academic use. However, Facebook allowed this app not only to collect personal information from survey respondents but also from respondents’ Facebook friends. In this way, Cambridge Analytica acquired data from millions of Facebook users.”
https://en.wikipedia.org/wiki/Facebook%E2%80%93Cambridge_Ana...
"We ingested the entire U.S. social graph," Carol Davidsen, director of data integration and media analytics for Obama for America, told The Washington Post this week. "We would ask permission to basically scrape your profile, and also scrape your friends, basically anything that was available to scrape. We scraped it all." [2]
[0] https://www.businessinsider.com/facebook-zynga-sharing-priva...
[1] https://www.cbsnews.com/news/obama-harnessing-facebooks-soci...
[2] https://reason.com/2018/03/23/cambridge-analytics-dust-up-re...
Is there any evidence that Apple is using the unique identifier for advertising? Also isn’t the unique identifier necessary for users who actually opt-in to tracking?
Unless there's evidence that Apple has sustained a security breach as a result of this posture, it seems to me that they actually are caring about the user. The only incidents that I'm aware of with regard to Apple are social engineering and brute-forcing due to weak user passwords. Is there a situation or evidence that Apple is lying here?
1. "We care about your privacy"
2. Introduce a bunch of privacy tracking controls to restrict what other parties and apps can retrieve and use vis-a-vis data and you.
3. Heavily increase your investment in your own ad network that is not subject to the same restrictions.
My understanding was that Apple asks for user consent before letting ad networks track users across many apps run by different companies. Apple doesn’t do that themselves as far as I know?
2. The privacy tracking controls only restrict tracking across apps and websites. Individual apps are allowed to collect data and it would be impossible for Apple to guarantee that an app couldn't collect data since they clearly can't be aware of every since implementation within the app. Notice what the terms for end-users explicitly state since a company like Meta can't get info from Apple about users across FB and Insta, for example, but may have ways to tie users together based on data they're collecting on the platform itself. Apple can't really stop that. They can only make it more difficult (which they have, as evidence by FB's reaction to the new privacy controls).
3. Where do you get the idea that they're not subject to the same restrictions? I don't see any evidence that this is the case.
It declares:
Data Linked to You The following data, which may be collected and linked to your identity, may be used for the following purposes:
Analytics
Identifiers
User ID
Device ID
Usage Data
Product Interaction
Diagnostics
Performance Data
Other Diagnostic Data
App Functionality
Contact Info
Email Address
Name
Phone Number
User Content
Photos or Videos
Audio Data
Other User Content
Identifiers
User ID
My bet is that the Stocks app says the same thing, and that people are confusing OS data collection permissions with app data collection permissions.Is that a meaningful distinction? "Oh, yes, we _do_ collect data from you, but have no fear, it's from the OS, not from an app!"
Either way, data is collected.
It may be an Apple problem regardless, but OS settings about data collection do not control app settings about data collection. Should the apps have those data collection settings? Certainly. But now you’re getting into something that Apple would be building that you can guaran-damn-tee that they will force other applications to implement (because it’s good for the user).
I think it's about priorities. The way you can tell when a company cares about something is when you see them give up something else they want to have it. In the case of privacy, they could show that they care by not collecting gobs of telemetry about every time a user plugs in their laptop, every time an executable is run, and exactly what a user looks at in their app store, and for how long. But they do collect all this data because it helps them both with advertising and with "improving" the product (using scare quotes because it's not clear to me what metrics are used to gauge "improvement"). I don't see _any_ effort made to protect Apple's users from Apple itself, and that's the core privacy problem: the mere existence of a massive store of all this data presents a very real risk to users.
> Where do you get the idea that they're not subject to the same restrictions?
The lawsuit alleges that Apple is not subject to the same restrictions it imposes on others. From the article:
> Apple’s iPhones and other devices contain settings that purport to disable all tracking and sharing of app information, but the tech giant continues to collect, track, and monetize their data even after consumers have chosen to disable sharing, it said.
Logically, this suggests that iOS will restrict other apps from tracking behavior across apps/sites, but Apple is leveraging its privileged position as the device and OS manufacturer to remain immune to those exact restrictions.
You're assuming this massive store exists with no evidence for it. One of Apple's central tenets with regard to privacy is that all the telemetry is done on device and never leaves the device except in an anonymized form. Based on what's been shown, this is still accurate. Apple is able to still collect data about how its users behave without any data that's tied to an individual.
>The lawsuit alleges that Apple is not subject to the same restrictions it imposes on others.
That is not evidence that this is true. From the lawsuit itself, they seem to be misunderstanding both how that info is used and how users have consented to it. I don't have enough information to say for certain but, based on the way the article and others are talking about the data and the video that's been presented that shows what data is being sent, there seems to be a misunderstanding between the settings that Apple provides that are meant to prevent cross-application and cross-site data collection with data collection from a single source. Additionally, I think they're making an assumption that the IDs being sent to Apple are shared across applications because I haven't seen any evidence to suggest that that's the case. That means that, unless some evidence is presented that proves it is being shared across apps, Apple is being truthful in what it's saying. It's collecting anonymized data that is then aggregated.
>to remain immune to those exact restrictions.
Again, that's not what has been shown so far. Until it's actually shown, rather than assumed, that Apple is using this tracking information across apps or across sites, Apple is doing what they say they're doing in their privacy policies.
I don't think thats a strong argument. FB's security was never actually breeched during cambridge analyitica. It was information given to a study by paid subjects, plus scraping of their friends graph, plus a fucktonne of PR to say how great their data was. Sure they had information on n million people. But they didn't have _detailed_ information.
With apple, they have unrestricted access to the location of you, your laptop and tags. With that you can work out friendship graphs. Not only that but all the information that every app collects plus a boat load more metadata.
If they cared about the user, they wouldn't be collecting this information, instead they seem to be wanting to muscle into FB and google's advert game.
But, dont get this as me saying meta/google are good. No, they are just as bad as apple, but with varying levels of PR.
I doubt many companies that haven't been hit as hard as Meta have the same sort of systems set up.
This might about as clear-cut a case of unfair trade practices as there ever was.
I don't get why these are automatically considered sinister. Measuring how people actually behave is an excellent way to improve your product. If this is done with sufficient care and anonymity, with no financial incentive to betray the user, I don't see the issue at all.
Even if a public company somehow managed to pass all of those caveats today the moment their leadership changed it would all go back out the window. And even a private company might go public or change leadership.
People don't like being watched. There's additional cognitive load in having to decide all the ways you might later regret giving that information away.
Once the information is out the door, it's out. You can't recall it. Apple or whatever company can have a change of leadership, mission or strategy that's incompatible with your values. But they still have your data and likely still can claim they have permission to use it.
For those of us who are older, it's also just discomfiting. We had at least a plausible illusion of privacy in our homes and our comings and goings. Now you have to take drastic and active steps to preserve privacy.
That's not to say I am fully against telemetry, but you asked why they're considered sinister. I think companies or organizations have a lot of work to do in order to comfort users.
It might be if done correctly but often telemetry is only used to justify existing wants. A typical example is removing a feature that isn't use a lot even though a) users might want the feature but don't even know about it because it is too hidden (which might even have been done intentionally as a first step preceding the telemetry-based removal) or b) might not be needed often but is absolutely essential in some cases. Like other statistics, telemetry can be used to justify almost any choice.
Meanwhile the same people using telemetry will happily ignore users trying to talk to them directly, including those users that make it clear that they don't want telemetry. So if you aren't going to listen to users why should anyone believe that your use of telemetry is going to be in those user's interest.
> If this is done with sufficient care and anonymity
And as a user you have no way of knowing that it is.
> with no financial incentive to betray the user
When is there not a financial incentive to betray the user? Any use where telemetry even makes sense is already a few to many relationship where users are at least somewhat replaceable. Data breaches are common but usually there are no real consequences for those that collected the leaked data even though they didn't really need it. Even intentional acts like selling the data will be forgotten soon enough, that is if they even come to light in the first place.
All together, I don't see how that makes Apple's trustworthiness weak in this space. In the current state of the internet, advertisement runs everything so they're still delivering on ads to their customers without selling your data or even giving those third parties a way to track you as an individual. That, to me, still equals privacy, at least as far as what Apple is saying.
Without arguing about whether it should or shouldn't be and the other deeper considerations, I can't see that as a compelling use of marketing dollars.
Apple would undoubtably not be able to charge as much as they could if they had those sorts of metrics to give, but there is a value proposition there.
Now is where we all live. The fact that it wasn't like that before doesn't matter THAT much.
It matters very much that a company only stops selling or tracking your info because they got caught or had a data breach. Look at Google right now. They're being sued by several states for tracking location info for people and then selling it to advertisers without those users' consent. It matters very much to me if Google is suddenly claiming that they're privacy conscious because their actions explicitly speak to the fact that they're not.
>"We have to seriously challenge the claim by Facebook that they are not selling user data," commented Damian Collins MP, chair of the UK Parliament's Digital, Culture, Media and Sport Committee.
>"They may not be letting people take it away by the bucket load, but they do reward companies with access to data that others are denied, if they place a high value on the business they do together. This is just another form of selling."
But hey, at least I can game on my Windows PCs, so...
But there's also a bias, when presented with only two real options, of telling yourself that the less-bad option isn't just less-bad, it's actually good. Because it helps you sleep better at night and because there's nothing you could really do about it anyway. Same thing happens with two-party politics
Definitely. I think the correct way to think about public corporate behavior is as if they're psychopaths. I don't mean that necessarily with the negative popular culture connotations, but just that they will always behave in what they see as the optimal personal benefit regardless of what it does to others.
That's just what a large and for the most part anonymous ownership that expects growth coupled with a set of people to steer operations that is mandated to work in the best interest of those owners results in.
So, think about your relationship with companies as you would with a friend you suspect is a psychopath but is amiable and somewhat beneficial to associate with at the moment. Just because they don't have an incentive to spread all your private info around at the moment doesn't mean they won't have reason to later, so be careful what you expose, and trust them only as far as it makes sense to. They aren't a real friend, you're just using each other for mutual benefit, and that doesn't generally last forever.
1. Let's not forget vast majority ( if not all ) of people on the Internet, inclusive but not limited to Main-steam Media, HN, Reddit and Twitter who commented between 2017 and 2021 thought privacy meant anonymous. And before anyone disagree, very very few on HN even bother to downvote or stand up against the notion of privacy meant anonymous.
2. Apple play this card, both in PR and marketing, along with media ( Submarine Article or not ) as a tool against Facebook. Or Social Media but let's be honest we all know they mean Facebook. And of course, for people from US, after 2016 Facebook is the most evil company on planet earth. Any Facebook bashing equals great.
3. A lot of people were brought into the idea of privacy meant anonymous. So in other settings, Apple use the word "personalised" instead of Data Collection, cough, I mean tracking.
4. The good thing about all of these, anything illogical will have to unfold some day. ( Just like Crypto ) Apple of course collect Data from you. Apple of course has all the Data about your usage pattern. So when some people came to realise privacy doesn't mean anonymous, I guess they aren't so happy?
5. Apple's true definition of privacy is that All Apple's user Data belongs to Apple. Any data to third party are by definition "Tracking". Since Privacy is a Fundamental Human Right, I guess the only choice is to give Apple all your Data?
6. Most people, especially tech nerds will likely play the I trust Apple more than Google card. Because Apple are not in the Ad business! - That was 2017 to 2021 if not 2022. They have their ads business right infront of you for a long time. They have been preparing their Ads business for a long time. Most tech nerds, or Apple apologist just turns a blind eye to it.
If you look at their careers page, they have been hiring quite a few adtech talent in Texas for the last half year. I won't be surprised they are waiting for their competitors to die off before swooping in. Corporate strategy and PR teams deserves a raise.
Are we so naive to believe that we are not be tracked by the big tech companies all the time?
If I use Office 365 Microsoft knows about my document writing habits and may be privy to company secrets if I had to write some sensitive company memos.
Google has the vast majority of my email if not all since so much email goes through their mail servers. Even if I avoid using GMail, I can’t stop my contacts from doing so. Google knows all my search habits as well.
Amazon knows my spending habits, the list goes on and on. And then there are the traditional means of tracking someone via credit card expenditures or your cell phone provider knowing your whereabouts and usage patterns.
You give away tracking data all the time. The issue is how these companies use that data. If they are doing something nefarious like what Cambridge Analytica did then we should be outraged.
Otherwise it’s just hypocrisy to play the blame game on any one company.
All I hope is that the megacorp that I trust doesn’t go and sell off all my personal data to some nefarious people. What other course of action would you recommend to improve our privacy?
Regulation and enforcement is the only answer.
You cannot blindly trust in the continuing good intentions of executives who have as much power as Tim Cook does.
Meta and Alphabet are already committed to profiting from users' private information. Apple is not, at least not yet.
I'd be happy to have laws that enforce (at a minimum) the natural implications of the good behavior that Apple has claimed in marketing for years. But this would destroy Google and Facebook.
But my argument is more that we’ve already given up a lot of our privacy by interacting with today’s technology. ISPs, cellular providers, credit cards, banking, the list goes on and on regarding areas where we have give up privacy for the sake of convenience.
This is the thing that has blown me away as I've watch our privacy get flushed down the drain. When a handful of corps (not to mention Govt. TLAs) have access to everyone's data and comms, doesn't that enable them to spot and mitigate any possible disruptions to their business by upstarts?
You mean for the ones that voted against Trump in 2016 & 2020, and think FB won him the election (as opposed to reflecting what people who watch Fox News and listen to AM political radio talk think), not the flawed candidates who ran poor campaigns he was up against. Or the Electoral College.
Anyway, I know people who won't use Google but implicitly trust Apple for reasons you stated.
Reading the description in Settings for both of these switches, we learn the following:
1. Allow Apps to Request to Track specifically "Allow[s] apps to ask to track your activity across other companies' apps and websites." This clause clearly doesn't apply to any internal analytics process.
2. Share [Device] Analytics is a bigger issue, and is the problem. The switch says that it sends information about how the user uses the operating system and Apple services. That clearly includes the App Store, so switching this off should switch off App Store analytics.
Including the first point seems stupid, since it muddies the claim against Apple.
A note about the App Store privacy information. It (separately) indicates that they collect the information this article alleges - so Apple IS disclosing it. However that doesn't change the fact that the Analytics toggle reasonably seems to apply to the App Store as well.
Personally, I've always assumed that Device analytics (which I always turn off) referred to iOS, device and network performance, what apps are launched and crash etc. and that it didn't cover in app usage analytics.
The description is a little vague: https://www.apple.com/legal/privacy/data/en/device-analytics...
But the App Store privacy notes still state they record usage so they can personalise ads (which are optional) and show trending apps and searches etc (I think not optional)
1. Nothing here is being tracked "across other companies apps and websites", unless there's something here that shows Apple is cross-pollinating their data internally (which is possible but I don't see any evidence for here).
2. I disagree that this includes "App Store" app. The description given when you click the "About Analytics & Privacy" link explicitly states what the differentiation is and, to me, that does not include the App Store app.
And this is why "security" to prevent user control or even knowledge of "their" devices is so important.
You're right there is no oversight for compliance to their own terms and that is the real issue. It is also an issue if they're getting a competitive edge by bypassing their own rules. It wouldn't be surprising to me if they were but based on the articles there isn't a whole lot of proof.
When Apple was starting their machine learning division I'd heard they had trouble retaining top talent because the engineers would show up and "okay! where's the data?" and Apple would reply "uhh, we don't have any it all stays on-device".
But with Apple getting into advertising I don't think this could stay this way, if it ever actually was in the first place.
And it's not like that would be the first time they've done that. Pretty common on all sorts of levels.
My "favorite" was the ability of Apple apps on macOS to bypass most of the TCP/IP stack and send traffic directly, regardless of on-device filtering or firewalling. Apple claimed it was "a temporary measure while they dealt with updating software", but I'm still at a loss to explain why an app like TextEdit would have ever needed a kernel network extension in the first place. That to me was almost certainly a post-facto attempt at justification when they were caught with their hand in the cookie jar.
I know it seems weird to recommend a Google phone, but one can completely eschew the issues around Google tracking, by not using Google services, or using them within the on-device sandbox giving them standard privileges.
Personally I'm fine with a company I choose to do business with storing information about me and about how I interact with their services. It just seems obvious that they will need to do this in order to provide their services. I understand that some of this info may be more than the strictly necessary minimum, but I have no evidence so far that any of this info has been used for purposes I consider nefarious. If they do, ok I'll reconsider.
I do understand the argument that they're providing an option to opt out of tracking, and that some of this data appears to be what is reasonably considered tracking info. That's a potential concern, sure, but again are they actually using this for anything I'd consider nefarious? If so then again I'm interested, but if not then ok, they should stop doing it, but that's as far as my interest goes.
If you think it’s not a risk because they don’t sell it to advertisers, think of all of this lifestyle data, times a billion people, being used nefariously to undermine human rights by someone worse than whoever you think the most repugnant US president has been.
The collection of the data is the problem, because there is a player in the game who is not Apple but has 100% access to all data that Apple has.
If it were the FBI collecting all this dragnet data in bulk, would you be concerned or alarmed?
If you want to support the fight for freedom and free yourself from both Google and Apple, consider a GNU/Linux phone, Librem 5 or Pinephone.
It is kind of sketchy that they have a way to turn off "device" analytics which one would assume is tied to apple's apps but that doesn't seem to be the case.
They are very different - there's over a million websites that use Hotjar alone (which sounds similar to what Apple is recording in App), and every news site will record how many view people read each article if not using some analytics front end JS code to read for how long for. Macrumours.com itself is using Google Analytics, and the suit it links to is using Adobe Analytics which do much the same.
From what the article says I don't see how this breaks any of the Apples "Anti Tracking" policies - I'm not saying they're not recording too much just that it doesn't break their policies.
Apple puts constant pressure on the user to use an iCloud account. Apple puts constant pressure to manage apple Devices with a MDM profile based system. In both cases user privacy is lost.
I do think Apple's use of the term "privacy" is not completely honest. But we should note the difference between privacy and anonymity. Using iCloud provides privacy for the user; that is, Apple won't access your iCloud data. It is not however anonymous.
What once differentiated Apple from Google, Amazon and Facebook no longer exists. I can't imagine Steve ever going down this road.
I have to use a phone for apps like uber and I use one to browse random content like HN that has no privacy issue for me if the world saw most stuff I read but I have moved away all other use cases to a simpler harderned Linux laptop.
It feels a bit weird and more isolated with that plus no social media but I have seen improvments in my quality of life and I have confidence that the handful of privacy or securiry sensitive data or interactions I have are difficult to compromise.
I believe there needs to be a change in how terms and conditions are written - people need bullet points.
By clicking "I Agree", the user (you) agrees that:
1. [COMPANY] can sell your data to third-parties. This data includes [x, y, z]
2. [COMPANY] will retain your data for [X YEARS]
3. [COMPANY] will allow you to delete your data by visiting [WEBSITE]
That sort of thing. People don't read; right, wrong, or indifferent, people don't read. They especially don't read convoluted, exceedingly long terms and conditions that they HAVE to accept to use a product.
I read every single document I sign my name to, every time. I'm not alone either. I assume we're mostly engineers here, some of us maybe are involved in contractual things, so tell me: in your job do you sign your business's name or your own name as Officer to contracts you haven't read? Now tell me, if work is less important than your personal affairs why on earth would you review the terms for work agreements, but not for yourself? If I agreed to contracts without reading them in a job context, I'd be in the unemployment line so fast the IRS would send me their condolences.
This has to be a joke, right?
Do I read all work contracts and terms? Of course.
Do I read all contracts in my personal life related to property, finance, or other important things? Of course.
Do I read the 10 pages of EULA every time Angry Birds updates new levels? Absolutely not.
In the context of Apple: When you activate a phone, the salesperson who sets it up (most people in middle america still do go to the store to get their phones activated) literally flashes the screen at you and says something to the effect of, "do you agree? If not, you can't use this phone."
Of course that reality does not suit well companies and they try very hard to create their own bubble world of user contracts.
Proper country laws enforce consumer laws instead based on intent
"Real" contracts are another matter entirely.
Abso.fucking.lutely. I believe the state of technology has progressed to the point that EULA are just weasel words. People view them as necessary evils that don't really impact their lives (or, rather, shouldn't) but companies treat them like legal documents.
A court needs to settle this.
So ultimately when it comes to company-user relationships nothing short of making some rights including privacy inalienable will prevent this shit. That's why we need laws like the GDPR and similar ones in other regions. Because corporations have shown again and again that if there is a profit to be made of abusing users they will find a way to get away with it.
I guess my question is: what are you saying?
Also we are within the EU, IANAL but to me this seems like an obvious violation of GDPR.
*.iadsdk.apple.com
api-adservices.apple.com
news.iadsdk.apple.com
stocks-analytics-events.apple.com
weather-analytics-events.apple.com
Submitters: "Please submit the original source. If a post reports on something found on another site, submit the latter."
Won't be long before shady lawsuits along similar lines follow. It will soon be more about tapering Apple's ad-network ambitions than genuine concern about user privacy.
This is a for-profit organization, so I expect it to behave that way. Which includes maximizing profits made by showing ads to end-users.
I really don't care. The benefits I derive from being inside this walled garden outweigh any 'privacy' concerns.
You don't have privacy on the internet anyways. Your data is not safe on the internet.
You can influence the price tag adversaries need to pay to access your data, but that's it.
In short: Hardly a surprise and compared to the competition Apple is going for a good balance.