Apple sends DSID with iPhone analytics data, tests show
gizmodo.com
gizmodo.com
While I think Apple's data collection within its apps is excessive, the only thing the researchers achieve by conflating it with device analytics is giving tech media an "Apple Lies!" headline cycle. People should be informed about how these analytics/surveillance systems work and how to effectively navigate and counter them, not be sold paranoia and the idea that the settings are always lying. They're misleading you with marketing, sure, but the truth in this case is written plainly in the prompt that pops up the first time you open the app store.
[1] https://www.apple.com/legal/privacy/data/en/app-store/, "We use information about your browsing, purchases, searches, and downloads. These records are stored with IP address, a random unique identifier (where that arises), and Apple ID"
[2] https://news.bloomberglaw.com/litigation/apple-hit-with-clas...
Yeah, um, so if Apple et al. cared like you seem to, perhaps enough to stop lying, then that might be a first step towards people trusting them? You expect the weaker party to trust first before the stronger party even proves they're trustworthy!?
>They're misleading you with marketing, sure [...] //
They have no obligation to mislead. You want us to treat liars like they're angels.
The app store is the only way to install software... trying to pass it off as just another App with a separate policy seems disingenuous at best.
That’s very different from, for example, tracking when/where you use apps or what you do in them.
Apple isn't just linking your App Store purchases to your account, they are tracking every single click and search term in the App Store and linking that to your account.
For all anyone knows they strip off the ID as soon as it hits their servers (which TFA also theorized) and only process the anonymous data.
Which, due to the excesses of big tech, they need to ensure users is happening because there is little trust left in that industry anymore.
2. "To protect your privacy, targeted ads are delivered only if more than 5,000 people meet the targeting criteria. The information used to determine which ads are relevant to you is tied to random identifiers and not tied to your Apple ID."
3. "Apple’s advertising platform receives information about the ads you tap and view against a random identifier not tied to your Apple ID."
4. It's also possible to reset this random, unique identifier or turn off personalization entirely.
Source: https://www.apple.com/legal/privacy/data/en/app-store/
"pregnancy tracker"
"miscarriage therapy app"
They have a list of people who are gay/Democrat/Republican/whatever and that list can be stolen?
You are trusting your medical info to an analytics team? One that probably doesn't have the best controls? That probably bulk shares their data across departments like marketing?
I mean, if you don't care, send me your medical records, I'm sure I can make some money off of them.
Live by sword...
The complaint does not allege that Apple failed to disclose how it collects and uses personal data. It alleges that Apple (a) provided a means for customers to opt-out, (b) some customers opted-out, and (c) Apple continued to collect data from customers who opted-out.
From the complaint:
"Even when consumers follow Apples own instructions and turn off Allow Apps to Request to Track and/or Share [Device] Analytics on their privacy controls, Apple nevertheless continues to record consumers app usage, app browsing communications, and personal information in its proprietary Apple apps, including the App Store, Apple Music, Apple TV, Books, and Stocks."
The complaint only applies to a subset of Apple customers who indicated that they did not consent:
"All individuals who during the Class Period (a) turned off Allow Apps to Request to Track, Share iPhone Analytics, Share iPhone & Watch Analytics, and/or Share iPad Analytics, and (b) whose mobile app activity was still tracked by Apple, (c) on an iPhone mobile device."
When Google was accused of wiretapping by scanning Gmail, it could not prove consent and it had to settle. When Google was accused to wiretapping by eavesdropping on open Wifi, again it had to settle. It does seem possible that a plaintiff could succeed against a "tech" company on a wiretapping claim.
Is collecting user information, app browing history and app usage history "communication" under a wiretap statute.
The suit may be dismissed, but the issue of Apple obtaining consent to collect data purportedly for analytics is still valid.
Then they should be sued for misleading in marketing?
It is one thing where it is legally to do so, it is another thing to have Apple turning on the speaker at highest volume for 5 years , largest attack on Ads and Facebook ( or Social Media ), finger pointing at tracking. And only to find out they are doing exactly the same.
- Single proof via a single device on a single OS version from a single API response.
- Claim on the latest version it is doing the same, but can't prove it. Just that requests are being sent when you interact with the application(ok?)
...And that's it.
I don't know the state of the jailbreaking scene, but a quick search seems to indicate that throughout 14.X and 15.X could have been checked, but they haven't. Would happily take this more seriously when reporting of issues is more sufficent. (or others proving more proof)
I wonder what log they got this from; i'm scrubbing through both my latest `Analytics-X.ips.ca.synced` files and `AppStore-X.ips` file and can't find dsId. This is even with every 'Share Analytics' checkbox ticked in settings, besides Improve Health Records. Unfortunately the name of that log file is cropped out.
I highly suspect there's something off about this and I will wait for others to corroborate these findings (should be easy if there's actually substance here).
I mean, it's what I'd do if I were Apple and/or Microsoft, and I knew that the US government was constantly compelling my employees through National Security Letters to do a bunch of extra off-the-books work to enable transparent one-off device-specific wiretaps. I'd productize that wiretap process, to get my employees' time back.
My point was that "security researchers examining network traffic" won't reveal de-anonymizing information leaks, if those leaks are not enabled on 99.99999% of devices, but rather only become enabled on specific devices when the OS vendor distributes those specific devices a "special" update.
Here's a Gizmodo article from 2 weeks ago talking about the same exact researcher: https://gizmodo.com/apple-iphone-analytics-tracking-even-whe...
The function he is talking about is undocumented, encrypted, can’t be turned off and uses different servers.
The whole thing might be illegal too, at least in the EU
Most people thing of anonymity like a boolean when is most like a gradient, for example, Tor not only needs onion routing, it also need to to present each user to the net alike, that is why they configure their version of firefox in a specific way and even a simple thing like changing the resolution of the window make you less anonymous. Even in perfect conditions you still vulnerable to correlation attacks and if you are the US, you can probably just use network flow data to deanonymize an user, obviously to do it the resources and implications would be enormous.
In the end is just a gradient of being anonymous to who? The ad conglomerate? A big state?
It would be literally impossible with a standard iphone to be anonymous to Apple, is just PR by Apple.
I know Meta is betting big on the Metaverse, but it's also wild to me that they similarly don't bet big here and keep their ad infrastructure.
For example, encrypted data can't be compressed. Columnar big data systems rely heavily on that to be performant.
They have huge incentives. Apple is positioning themselves as the privacy king. Meta has suffered huge losses because of their privacy abuses. Neither of these suggest no incentives. I'd argue that they suggest large incentives.
The technical downsides are a fair critique though. But this also is where competition excels. Our machines are getting faster. Other algorithms have also gotten extremely faster and it would be naive to assume that homormorphic algorithms similarly don't. This is why I say an arms race.
Apple know what they need to do to be successful, and that's continue to release updates to the iPhone that in a few small ways make it slightly better than the previous one.
I am willing to bet that it is a deal breaker only for very small minority of users. I would argue that search engine data is of much bigger privacy concern than OS, as compared to search history no OS action comes close in disclosing personal action, and google/bing almost has universal market presence even for Apple users.
> Meta has suffered huge losses because of their privacy abuses.
They had their revenue reduced, true. But it is not loss. They wouldn't be in any better position if they didn't used extra data when it was available.
An iphone user is _probably_ tracked by less ad agencies than a stock android user, but that’s it.
That's always how good studies start.
At the end of the day, even with HE, we have to trust Bob to be trustworthy, and to have designed and implemented it totally correctly (or else data will leak in the clear).
If it was Bob's small company then having a 3rd-party external auditor review the system would go a long way to gaining the public's trust, but unfortunately Meta has no such luxury. They could say they can't see your data until they were blue in the face, and they could even be telling the trust, but people don't currently believe they haven't sold your data (or the specific nuance there), so I'm not surprised they haven't made a large investment in HE. HE is also not quite there yet. It's ridiculously slow for anything but the most simple operations and Meta's data needs are far from simple.
I don't think we'll ever have fully trust-less systems. But I do think there's a big difference between saying "trust us, we don't look at the data" vs "we encrypted the data and use this method, trust us that we aren't decrypting it". The former method is worse because there's a lot of people that have clear access to the data. The latter is better because there are more speed bumps and the argument is more sound. A lot of trust is built from demonstrating good faith efforts.
For a survey, check out what firms are doing on "differential privacy" not just "homomorphic encryption". As a for instance, Apple -- since the OP is about them -- spent significant extra effort to make Maps anonymized.
Concept: https://www.apple.com/privacy/docs/Differential_Privacy_Over...
In Apple Maps: https://www.idownloadblog.com/2019/03/13/apple-maps-navigati...
btw. GrapheneOS is great!
Proposed class action alleges that Apple tracks users despite privacy assurances - https://news.ycombinator.com/item?id=33593455 - Nov 2022 (191 comments)
App Store on iOS 14.6 sends every tap you make in the app to Apple - https://news.ycombinator.com/item?id=33520775 - Nov 2022 (190 comments)
Every time you open the App store, you're opening a giant garden of advertisements. These ads are extremely lucrative to Apple. Every time you update the OS, it prompts you with ads to sign up with more services. Every time you open Apple News, the same thing happens: you're bombarded with ads to sign up for a premium subscription. When I still had an Apple laptop, it would constantly give me a popup asking me to signup for iCloud, even though I hadn't consciously ever used it.
At nearly every turn, engaging with Apple software leads to profitable ads for Apple. (Usually in the form of direct subscriptions, or commission based advertising.)
What do ad companies love? User data! This is as true for Apple as it is for Google. The difference: Apple has an iron grip on their advertisements like no other company in the world. This gives them the tools that let them pretend they're not an ad company. They are.
Calling the app store an ad is really stretching the truth. It‘s a store, of course it displays the products that are for sale.
0: https://searchads.apple.com/advanced
1: https://appleinsider.com/articles/22/11/14/apples-4b-ad-busi...
Curation and Ads are very different. When you walk into a Target and see a curated set of products like bath towels, they're not Ads. In fact, customers pay more to shop at Target because of Target's ability to curate quality products consistently.
Now the App Store does have Ads (mainly in search - one slot at the top). But it's far from a "giant garden every time you open it".
The first showcase is an actual showcase, but the second item is very much ads. And the way it's set up is to have something like 1/2 the image visible without the user scrolling, but the part that says is that it's an ad is not visible without scrolling. So the idea I guess is to have the user click on it to find out more based on 1/2 the image without them knowing that it was an ad.
[edit: not true at all, apologies]
Like countless others I’ve always been very sympathetic to the entire philosophy of the company - like how they’ve mostly kept to the high road in many important ways. It is going to be a huge shame when they go down that AD road.
But on the bright side - it might turn out that Apple will just have to be the first/main for anti-monopoly regulation.
That it is not true.
GOOG (1.2T) + NVDA (.38T) + META (.29T) + ADBE (.14T) + CRM (.14T) + NFLX (.12T) = 2.27T
Oracle makes or breaks this if you still want to consider them a Silicon Valley company (the headquarters was moved to Austin last year)
Perhaps the source I was remembering was also referring to SV companies, and I thought it meant the big ones above.
Bigger or smaller of a shame than the time they went down the surveillance road?
It's nice to think this is part of a transformation taking place at Apple. In truth, what is transforming is our perception of Apple. It's not like Analytics has recently changed how it operates.
But the others then make money by sharing/selling the data _to third parties_(incentive).
Does Apple use this data only for internal use, or do they also share (sell) it to third parties? With or without privacy?
Eg, Google has 80-90% (!) income from ads (incentive)
Prompts to buy additional products do not make a company an advertising company. If it did, every restaurant in the world would be an “advertising company” because wait staff, cashiers, and menus encourage customers to order additional food.
Even if rank and file Apple employees do not want to grow ads in iOS/App Store, clearly Apple leadership wants to sell more ads (and increase their services revenue). At App Store scale, their volume of ads is not trivial.
1. Apple Displays ads (Sales content for products.)
2. Apple gets paid when those ads convert into sales.
If Apple didn't get paid when Apps were sold through the app store, then I could see how it isn't an ad platform for them. Yet, the only option, if you want to sell a product listed on the app store is to pay Apple their cut, which fundamentally turns it into a paid advertising platform controlled by Apple.
But it's a channel cost not an advertising one.
Apple still gets their cut when an in-app purchase is made hence it's not tied to the App Store list.
IMO, both Microsoft and Apple are showing me ads I don't want to be shown.