iPhone apps harvest data when they send you notifications, researchers find
gizmodo.com
gizmodo.com
Allow me to disable notifications from an app unless I have opened it within the last X hours.
I’d set it to a couple hours. My food apps could then tell me the order is ready, but can’t spam me with “Special Offers For You” days later.
Maybe I can do this with an automation?
I also want something else that I wonder if I could dummy up myself. I want to change certain phone behaviors based on whether or not a given Bluetooth device is connected.
My use case is "when I'm on my motorcycle, connected to headset audio, I want (a) the phone to read me texts and (b) to turn on navigation audio." I do not want either of these things UNLESS I'm on the motorcycle with the Cardo turned on.
After all, topics like this are why we succumb to their curation and App Store monopoly instead of using more open devices.
But with all that said, don’t kid yourself with any thoughts that the “we” in your sentence refers to anything more than a practically immaterially small contingent of nerds. Poll 100 people off the street and for the vast majority of them, a more “open” mobile platform is—at best—some nebulous advantage of owning an Android phone that some dweeby family member ranted to them about. In reality, they are reality not directly making use of any of that “openness”, instead just using a worse, malware-infested iPhone alternative.
And I believe the "we" refers to far more people than you describe. It's ultimately a question of UX.
> Apple updated its App Store guidelines today with a change to its traditionally strict restrictions around push notifications. Apple has long banned apps from using notifications for “advertising, promotions, or direct marketing purposes,” but that changes today. Apps can now send marketing notifications when “customers have explicitly opted in to receive them.” Users must also be able to opt out of receiving the ads.
> The change follows a couple incidents over the past two years in which Apple bent its own rules by sending out push notifications that read a lot like ads. Since other companies’ apps could be banned or have their push notification privileges revoked for that behavior, the moves were criticized as another example of Apple getting away with special treatment because it controls the platform.
https://www.theverge.com/2020/3/4/21165087/ios-apple-push-no...
2.5.16 Widgets, extensions, and notifications should be related to the content and functionality of your app.
2.5.18 Display advertising should be limited to your main app binary, and should not be included in extensions, App Clips, widgets, notifications, keyboards, watchOS apps, etc.
I allow very few notifications on my phone, and nearly all the exceptions are iOS built-ins like Mail (which I still heavily restrict). Honestly, I think the only non-Apple exceptions are my VOIP softphone and Teams.
With how much Android and iOS have copied from each other, that seems like fertile ground to improve the experience.
In practice, apps also abuse the channels and tag things as (at least) direct messages when they are not.
Android is much better in notification config flexibility vs iOS.
Whenever I get a spammy notification from an app I'd prefer to not uninstall, it's always logged under a general category that is mixed in with notifications that I want. Amazon for example has channels for Alexa, account authentication, and then a notifications category.
A “good idea” that doesn’t stand up to adversarial actors isn’t a “good idea”. And I assure you that your developer buddies were just as complicit as the evil business-people and marketers in ruining it.
I've also been happy with my career. I've only had one scummy feature handed to me my first week at a job. I called out the product manager for it during a full engineering team meeting, asking him if he thought our customers were stupid, and earned a lot of good will with the other engineers for calling him on his shit. He was fired within the year, I'm still on the team, and that implementation is now gone.
If there's a clear benefit to society, I don't think it would be an absurd regulation at all, and there's precedent for equally fine-grained/detailed regulations in many industries.
Another one of that category I'd love to see: Mandate at least one secure 2FA method other than SMS-OTP.
Unfortunately I don't know how to do the same with notifications that are sent via SMS.
uBlock Origin shows 16 domains connected; most of them loading JavaScript. The real number is probably far higher when no ad-blocker is used.
All the outrage companies and people have is posturing in almost every case, in my opinion.
When one side doesn't listen, then these conversations are nonsense. The concept of having a conversation is coming to a close.
If anything, having a publication release an article like this shows that they’re not held back by conflicts of interest.
The gist of it is that apps are allowed to run a bit of code when they receive a notification and they can use that bit of code to send some telemetry back to the mothership.
> What many people don’t realize is that targeted advertising and other invasions of digital privacy are all about figuring out your identity.
And then they interviewed Facebook and LinkedIn. They already know who you are. Facebook knows a lot more about you because of what people voluntarily tell them about your personal life and LinkedIn already knows everything about your professional life.
As often as people tag exactly where they are real time in posts, it seems unnecessary to gather more information via IP addresses.
It's unclear what data the government tracks, but it's annoying that Apple allows such a trivial security hole when they keep bragging about "privacy".
Not that I ever want linked in notifications, I definitely don’t want linked in notifications at 3am in the morning because I crossed a few international date lines.
How does a server know when to send a push notification to a client if the server doesn’t know the users local Timezone.
Want a wake up call at 7am? How does the server know when to make the call? Want to avoid sending a study reminder at 3am, how does the server know when it is 3am? Most websites do some kind of location detection to show times back to the user that are likely in their current Timezone.
No one¹ reads those. I wouldn’t consider that informed consent.
¹ Not literally. I read them but personally know no one else who does.
I feel like "...when you interact..." is a very key part of this. If I understand it correctly, that to me really makes the headline seem less bad. So if you just delete the notification and never tap it, do they not get any data? That part is unclear but very important to this context.
These are apps that already are installed, the user chose to get notifications ... yes so when the notification runs the app runs and some telemetry is collected.
Cat is out of the bag already.
I'm concerned about this whole topic too but man that article is hard to read and really just kinda states the obvious. Why it is focused on notifications is sort of beyond me. There's nothing presented to say that users don't know that the notification from the app is ... the app.
It also seems like you have to interact with the notification for any of this to happen. That's not surprising as that usually leads to the app that you already have / know is there and so on, and now you interacted and opened the app. If you're opening facebook notifications, you have facebook installed, you likely logged in ... so yes there's tracking going on.
Article seems to imply this is some extra level sneaky way for apps to collect data but it doesn't seem to be that way anyway.
But if an institution wants to find out what devices subscribe to certain groups or pages
They could correspond the times that a pages media posts, with the times a range of devices received a notification from specific apps.
It’s that easy
In all honesty this is just one of the many ways companies feed the ads monster. coal is to steam train as user data to adtech.
Seems like you can make correlations with almost any type of data these days so I imagine even things that seem useless to capture could be valuable in the future.
https://developer.apple.com/notifications/push-notifications...
"But $App is free, and it's so cool, and ..."
"Who cares? That's how the world works now."
Etc.
I don’t think that people should be lining up to show sympathy in this scenario.
The question is whether I am able to convince anyone, but that is a separate part. I assume since you used word 'lecture', you are not convinced it is an issue worth discussing among your family, friends and peers?
edit: I thought a little more about what you wrote in:
'people might want a relationship with you without you lecturing them'
I am starting to wonder. Should humans have EULAs?
The phenomenon you describe is hardly new, it's just easier.
The safest "app store" would be one where all "apps" must be open sourced so that, optionally, if a customer dislikes a certain "feature" or other behaviour of the software, she can remove it from the source and compile her own version. Additonally, the customer could add "missing features". As it stands owners of Apple computers have no control over anything really . They delegate all of it to Apple. That is why every thread about these issues includes futile pleas to Apple. (That will go unaswered.) There is no DIY. That would be "unsafe" according to Apple's media spin. Perhaps the closest we have to an "open" app store is f-droid.org.
https://world.hey.com/dhh/apple-s-new-extortion-regime-to-ke...
I mean, first, they're disruptive. You don't need to know every time you get an email. Even on my laptop, I only get an email ding if it's from (a) a coworker (and it's a small company) or (b) my wife.
Second, the notification-spam ship has sailed. Apps behave TERRIBLY and abuse the privilege. DoorDash, for example, will spam you with ads using notifications if you turn it on. As a consequence, I just watch the app itself when food delivery is pending -- and so no notifications are required.