I guess Apple's Marketing is doing its thing once again...
But I don't get you. You complained that droid makes it hard and apple makes it impossible. But it would be better for average user security if they could not do it (aka "did not own the device" in anti-apple propaganda), right?
Apple's mea-culpa is that unlike Android they do not ship an Open Source OS ROM for developers to modify. Google's telemetry can be entirely neutralized by removing Google Play services and using Android without Google software. iPhones don't have that escape hatch, leading to a pretty literal limitation of how you "own" your phone and the software on it. On top of that, iOS has a permissions architecture Apple designed to give the user second-class control over the network. You cannot MITM Apple services - they will go around whatever user-land profile you think you've set. On top of that, there are modem emissions that you're never going to catch with a MDM profile hack and certificate pinning. You have fully drank the kool-aid if you think an empty aircrack-ng screen means "you won" against the multitrillion dollar company and coalition of government regulatory bodies.
I didn't complain about anything, I just stated the facts, with a possible exception regarding the snark about how Apple "owns" the device, although I do think that's a defensible position since they have higher access to it than it's "owner". I do think it's shitty though that they don't provide a way (even with some hoops) for the "owner" of the device to get the highest level of access to it, but that wasn't in the comment.
> But it would be better for average user security if they could not do it (aka "did not own the device" in anti-apple propaganda), right?
Why would that be better? I highly doubt it would make any difference at all to the average user. I doubt it even impacts the majority of power users.
The people who are impacted by these restrictions are the technical users who want to capture and inspect their own device's traffic, usually on their own network. Conveniently, these are also the researchers who might publish blog posts and articles about what kind of data and surveillance the device is sending home about the user, without their knowledge.
But someone who slips in a custom CA cert maybe can. That's the point.
(It's still possible to compare how much a blank device phones home but perhaps we wouldn't know all the details of what it talks about)
This is basically the crux of your argument. I mostly agree with you - neither Apple nor Google do enough to protect user traffic in the big-picture. You can Wireshark a lot of data off both OSes, the throughput is even scarier when you track radio emissions.
That being said, a lot of people have taken notes from Apple's "protect user privacy" shtick. Many logging libraries contain the app-equivalent of screen-recording baked in to the app framework, enabling a pipeline where PII gets ingested as a part of the logging process. Startups that incorporate these processes then brag about their self-imposed security compliance as a result of their own ass-backwards philosophy. And these aren't even the bad guys!
Companies like TikTok and Facebook collect lord knows how much information, and use the same "security" tautology as their scrappy startup peers. They consciously stretch the limits of their API capabilities, and then turn around and make puppy-eyes whenever regulators act concerned. Meanwhile, the actual users of these smartphones aren't empowered to regulate their own device's security. They can't turn off their phone because the modem is still on. They can't firewall Facebook analytics when the app is closed. They can't even stop their notifications from being snooped on without disabling the feature altogether. Where's Apple or Google when that's under scrutiny?
It's a bit tangential, but this is why I think Apple made an enormous mistake attempting to commodity privacy. Privacy is idealistic - there will always be perennial exploits on the iPhone to prove them wrong. Because Apple commits to imperfect, conditional privacy, scummier-and-scummier companies can follow their imperfect lead and make the same claims. And because none of them are as big as Apple, they rarely take flak when their systems fail. Apple's attempts to market security is like watching a leading F1 driver start turning into a tailspin, and taking the rest of the racers with them in a firey crash.
Most marketing hinges on non commodities, take coca-cola for example, it's sugar water with a bit of caffeine, if they marketed that they'd be nothing, all of their marketing is about other stuff, intangibles
Kind of like Netflix's proverbial "chill"
Comparatively I'd say privacy is among better things to market
I can't even tell whether it's sarcasm… All those services are closed-source, exchanging over binary protocols, of which there is no public description/documentation, and no stability guarantee.
I believe on Android MITMing even most third party applications (that make zero-to-no effort to prevent this) requires a rooted phone or an emulator running and older Android (8) without Google Play Services and doing a little bit of RE (for instance using some Frida user scripts to patch the apk to circumvent the certificate pinning). I reckon MITMing the actual traffic Google itself can collect would require a lot more RE and network wizardry than I’m even aware of (feel free to link some reading though). Here’s a recent walkthrough I saw in the wild: https://youtu.be/c4wS9n7yilA?si=xAfwCyWIzdrvOiHc
For Apple devices afaict since rooting was…ahem rooted out, no viable amateur-DIY methods for monitoring your devices traffic exist.
I know everything is open source if you’re good enough at assembly but at some point it’s gone from something a tinkerer can do to something you need significant talent and in-depth knowledge to do.
I’d love to read any write-ups or guides to the contrary though.
Not familiar with the term, what does it mean?