There are obvious reasons to do so to combat crime but at the expense of privacy, freedom, and anonymity.
And I've quite been happy to see Apple stand up against such government control but fear the trend this will set.
This is a continuous concern - some sectors of the EU indeed want to do that. So far, they've been mostly unsuccessful in getting their agenda through, either because other politicians have more influence, or due to listening to public protest/complaints. Still, that's no different than other healthy democracies - the people must vote, both in national elections (EU heads of state propose the European Commission's president to the Parliament), and European elections (who elect said Parliament) in order to keep reasonable people at the helm as much as possible.
Where, exactly?
Apple complies readily with thousands of warrantless surveillance requests[0] from around the world, every year. They've been a cardholding PRISM program member for over a decade, and just a few months ago admit that push notifications are also government-monitored[1].
Outside of eagerly marketed examples like San Bernadino, Apple appears utterly compliant with government control.
[0] https://www.apple.com/legal/transparency/
[1] https://www.macrumors.com/2023/12/06/apple-governments-surve...
by definition this is not direct representation
Most countries don’t elect their prime ministers directly, they’re appointed by their parliaments
This is effectively the same procedure that ministers/secretaries are appointed by on the national level. The only difference is that it is not the national legislature, but the EU parliament approving the appointment. And again: the EU parliamentarians are directly (!) elected by EU citizens, according to their national election laws.
So please, please shut up about stuff you obviously don't know anything about.
let's break this down into levels of appointments
how are commissioners selected?
> with the commission president, who then selects a team of commissioners.
ok, so that's one level of appointment (TOTAL: 1)
how is the commission president selected?
they're appointed, by the council (TOTAL: 2)
how are the council members selected? (obviously e.g. the land mass "Germany" can't vote for itself)
who has the council vote? the German Chancellor
how is the German Chancellor selected?
they're appointed by the German Parliament (TOTAL: 3)
who select members of the German Parliament? the German people, so they are directly elected
so that's three levels, matching what I originally said:
> so EU commissioners are "appointed by someone (commission president) who is appointed by someone (head of government) who is appointed by someone (parliament) who is elected"
the statement is accurate
the fact bits of this are rubber stamped by the EU parliament is beside the point, the spitzenkandidat idea was completely killed off in 2019
> So please, please shut up about stuff you obviously don't know anything about.
cough
"Comissioners are nominated by member states". That's it. Yes, the commission president is the one that presents the list of commissioners to the EU parliament, but the member states (effectively the heads of national governments) are nominating the actual candidates.
*Exactly" the same as secretaries/ministers on the national level, who are also nominated by the heads of their respective national governments. Which is fitting, because the commissioners are more or less the EU ministers, i.e. the heads of executive agencies. They are no more or less removed from the voters than their national counterparts. I really don't get what your problem is.
Or you start from the other direction: Voters select their (EU) parliamentarians, parliamentarians appoint the commissioners. End of story.
The vote of the EU parliament is hardly a "rubber stamp". The list of commissioners is negotiated with the parliament and there have been various occasions where the list had to be reshuffled because the parliament would not accept a certain nomination.
Those are the same regulators who keep trying to ban encryption, right? Just making sure.
> Is HN in the EU?
It doesn't matter as long as it's used by EU users.
Laws don't protect privacy. What protects privacy is technical mechanisms for people to do so.
There is even a country that intercepts and MITMs all TLS traffic (one of the stans, forget which one). Of course, browsers don't recognize their certificate. So, you have a choice: you either trust the government MITM cert yourself, or you don't access the web. Laws trump technology every time.
Laws that prevent technical mechanisms effectively prevent the enforcement of laws that protect privacy, because bad actors can still break the law. The law provides some means to get justice, in theory, after a bad actor has already violated your privacy. Technical means provide you a mechanism /you control/ to actually enforce that you have privacy. You need both, but the law alone is woefully insufficient.
But this concern requires a few things to be true:
- An alternative app store is created that does not employ any form of restriction to protect users from this
- Legitimate apps that an end user needs see value in publishing themselves on this alternative app store
- There is a critical mass of users that prefer the alternative app store, such that the legitimate app publisher no longer sees value in publishing to Apple's app store
- As a result, those users who would have preferred the privacy and safety that Apple provides are now forced to use the new app store
This is a possible doomsday scenario, but it's not clear to me that enforcing and protecting a market in which Apple is effectively guaranteed a profit on everyone else's apps is the right solution? If this were to happen, perhaps we address those apps through direct legislation that targets user privacy, akin to what the EU has started to move on? Or a solution similar to this.
So the Facebook app (and Instagram, WhatsApp, and whatever else Facebook owns these days) would be able to collect as much data as the OS itself allows, without any kind of warnings before install.
It could potentially even use private APIs of some sort to bypass Apple's OS-level permissions dialogs and collect data without even asking the user first—it's unclear, at this point, to what extent Apple would be able to police this sort of behavior from motivated bad actors like Facebook when they're not being distributed through Apple's App Store.
iOS is sandboxed so they can’t do anything outside of the context of that app. To use any APIs that would require a permission dialogue you have to make a request to get a handle on them which only happens after a user grants permission, you can’t just reach into these. This is baked into the OS. Apps like the ones you’re talking about already hoover up is much data as possible in this context.
iOS itself is actually really good at this and can be improved and hardened further, Apple wants you to believe it’s somehow their review process and strict distribution channel that makes this possible.
But beside that point, Facebook has been able to force side loading on Android for years and still distributes via the Play Store, so that’s probably at least some evidence that they believe that distribution channel to be worthwhile.
Right, and they hate it. There's a reason why the iPhone and App Store were such a massive hit. People will choose convenience and security over freedom most of the time.
And before you argue against this, Apple fans use the exact same argument: Apple knows best, we don't want to think for ourselves.
You seem to be ignoring this fact and blindly arguing that the Mac/Windows world of installing apps is superior.
Which many of us disagree with.
Apple helped the masses, and the masses reward Apple by being the most valuable user base in the world
That's what Apple thinks, yes.
> Apple helped the masses, and the masses reward Apple by being the most valuable user base in the world
Yes, rich people buy (perceived) luxury products. Apple's greatest skill is positioning itself as a luxury product.
Let’s not pretend Apple isn’t building the best consumer silicon in the world and the most secure and user-friendly consumer operating systems in the world. That’s not even considering their supply chain innovations.
Apple devices are superior to their competition in just about every objective measure.
Apple was in shambles before the iPod/iPhone. You think the iPhone succeeded because of marketing? You don’t think the fact that they made multi-touch displays easy to use was relevant to their success?
Apple products are so desired that people get resentful when they can’t afford them. Then they post moronic takes on HN from their Samsungs
Their vehement success in Xserve proved that Apple does so well in low-margin markets. Wait a minute...
Citation needed. People hate that they can buy games from Steam rather than having to go through the Windows app store?
People will choose convenience and security over freedom most of the time.
And if that's their choice, fine. But it should actually be a choice.
The idea that Apple is on the side of privacy here is not really realistic. In fact Apple has designed AirDrop etc. to make it easy for countries like China to control AirDrop traffic, and they have put down technological safeguards to prevent actually private tools like Briar from functioning.
This is massively misinformed. The majority of privacy controls exist in iOS itself completely independently of the distribution method, and many more unimplemented potentially beneficial privacy controls can also be implemented at that level. This has been true for years.
Many of the App Store privacy rules relate to what you are allowed to do with the user data after access is granted by the user. In other words they relate to data retention rather than access in the first place.
For example they recently added a rule saying if a user can create an account inside your app you have to also give them an option to delete the account from the app as well. This is a behavior enforced by app review, not by operating system privacy controls.
Sure, I never claimed that they were a panacea - just that the majority of privacy controls implemented by iDevices are actually in iOS and not Apple's App Store review process.
Additionally, those privacy controls are more fundamental than those in the App Store. It's more important that the app not be able to toggle the microphone at will than for you to be able to control what it does with that audio after capture.
> Many of the App Store privacy rules relate to what you are allowed to do with the user data after access is granted by the user
That's not an iOS problem, and Apple fundamentally cannot regulate that, App Store or no - after your personal information goes to a third party's servers, Apple has zero visibility into what happens.
This is also not an Apple-specific issue - this happens with Android, Windows, Chrome, and random online websites. Apple cannot and should not be responsible for fixing this - we need a good set of government regulations designed to restrict how your personal data is collected or used. Otherwise, just like you said, an entity (e.g. a bank) can ask for your personal data, then store it, and it gets leaked.
I mean both are equally important really. I might want to grant you access to my microphone to run a voice command but that doesn't mean I want you to collect my voice recordings and sell them to someone else. I might want to grant you access to my contacts so I can message my friends but that doesn't mean I want you to scrape my contact list to data mine my social network.
> That's not an iOS problem, and Apple fundamentally cannot regulate that, App Store or no - after your personal information goes to a third party's servers, Apple has zero visibility into what happens.
Yes they can. Maybe not perfectly but the App Store Review Guidelines define specific restrictions on what you can do with personal information, with the threat of having your developer account terminated if you violate those restrictions.
> Apple cannot and should not be responsible for fixing this - we need a good set of government regulations designed to restrict how your personal data is collected or used.
Sure, specific privacy regulations would be great, but the government moves very slowly and the government itself isn't going to be able to enforce such regulations on a massive scale in the same way that the app review process currently does.
Throughout this thread you’ve demonstrated that you don’t understand how the OS itself works and assume App Store review is somehow protecting you from this, the OS already prevents this.
1) The app requests access to the microphone.
2) The user grants the app access to the microphone.
3) The app, now having microphone access, processes the user's voice command and does what is requested.
4) The app also uploads the voice recording to their backend and later sells the voice recording to someone else.
What mechanism in the operating system do you believe prevents (4) from occurring?
> You can deny the permission all you want but that won’t stop them blocking features unless you tick the box
Many permissions (camera, mic, location, etc.) are trivial for the OS to spoof and don't require app store vetting.
Two wrongs don't make a right. The thing protecting people from abusive behaviour should be the government, not a "benevolent" monopoly.
I think they have been leading in this area and by virtue of competition have pushed other vendors to do the same. I can’t imagine Android based devices would be nearly as privacy focused today if it weren’t for users moving to the Apple ecosystem in search of better security.
Making exceptions like installing the Aurora Store or microG, defeat the point of a degoogled phone.
iOS can’t be hardened it to a 0 telemetry state like GrapheneOS, but it is a fully featured OS.
It strikes the right balance for general consumers, and prosumers like myself.
With Apple it’s just easier and I can focus on other areas of life and just use my phone as the tool it is rather than spending untold hours making everything work.
Truth be told there was a time in my life when I actually enjoyed fiddling with that but I got my fill and am on to other priorities. There is only so much time in the day.
I don't get it, what are some examples where Android is more misleading about charging you?
I think that's the main reason iOS is slowly eating Android's global market share, and why it remains the market leader in the US. As bad as iOS is for privacy and respecting user choice, Android is worse in practice. There's an argument that Android's openness benefits the end user, but it falls apart in practice: almost all third party apps (and certainly the ones that other people force you to use) depend on Play Services, which is a giant pile of surveillance capitalism and battery drain.
Having said that, I'd like to be able to toggle my iPhone into EU mode and sideload a few things.
This is like some weird 1984 double-speak. How does letting users install Apps from more stores "reduce their options"? Would you have "more options" if I told you that you're only allowed to shop at Amazon.com and your browser will block any competing online retailers? Are you being harmed by the fact that you can buy products from more than one online store?
And the whole secondary argument is some kind of joke right, as 80% of every "free" app in the App Store requests data on your location, sensitive privileges, and all of them use coercive techniques to trick users into accepting. Whatever approval process Apple is is using with the App Store is far from protecting users.
Right now, you can choose between getting Facebook from Apple's App Store, where Facebook has to comply with fairly strict privacy rules to remain available. Or, you can use Facebook on a non-Apple platform where no such rules exist (browser, Google Play). This choice exists because the App Store is the only way for Facebook to practically deliver its product to iPhone users.
If Apple is forced to allow third-party stores, then yes, users have more choices on where to get their apps. But it would allow Facebook to take their app off the iOS App Store and put it somewhere without Apple's stricter privacy rules, taking away the users option to choose a version that doesn't have things like cross-app behavior tracking.
I view it very much as a "pick your poison" scenario, where Apple is merely the lesser of two evils. I would much rather live in a world where government regulation renders Facebook's shitty business practices obsolete, then Apple wouldn't be able to use basic rights like privacy as a product differentiator.
I have an Android phone and I almost always install apps from the store but I have a very important handful of apps that I've sideloaded (or gotten from F-droid). Some of those apps do more to ensure my privacy than "official" ones.
The problem is, Facebook could easily take the iOS App Store option away and make the alt-store option mandatory. And they have the power to do so and get away with it. People are too entrenched in their ecosystem, and there's no viable path off of it. User protests like this on social media rarely end in favor of the users.
I'm one of the people that quit Facebook entirely, and it does actually hurt me IRL. Too many friends and family members coordinate events and share news exclusively through Facebook.
I feel like the argument falls a bit flat when sideloading exists on Android, Android has 70% of the global market share, and none of these supposed evils have happened.
In the US, if Android side-loading were more common, we'd already have this, except that companies would require it.
In the EU, they'd probably crack down on companies that tried to do this. However, although it's technically illegal for governments to do such things, apparently most governments routinely break the anti-mass-surveillance laws.
On iOS, Apple has banned many bad actors for such shenanigans (although they still allow spyware from large companies like meta and google).
iOS != App Store
The whole point is that the EU wants to take away Apple's ability to vet apps, since that's created an anti-competitive situation.
However, this doesn't have any bearing on the argument that user freedom doesn't significantly compromise security - this just shows that the EU made a bad law.
Even for me, setting this up and giving necessary permissions was non-obvious.
I don't believe any sane big company (except maybe a few with extremely loyal userbase for whom it would make big financial difference) will pull down their app from official app store and force people to go via an alternative store if they can just stay in regular store.
My counterargument to that is even the current status quo doesn't work for privacy. Facebook can still get less data from the browser version compared to the app and that's why they are pushing hard for an app install. What would work is tighter sandboxing similar to the web, not custom reviews.