Apple and Meta go to war over interoperability vs. privacy
techcrunch.com
techcrunch.com
And yes, Meta isn’t denying requesting everything under the sun. Their only retort is Apple’s privacy concerns are anticompetitive excuses. Two things can be true: Apple is only protecting their own interests, and Meta is a terrible would-be guardian of all the data they’re requesting.
I don't think that's true for their VR/MR hardware. That's Meta's attempt to get a product that is _not_ like that, but which instead gets them in a position similar to where Google and Apple are for phones. I.e., where they own the platform and can profit off of that.
That's a distinction without a difference to me. I will not be purchasing hardware that requires a cloud account. Especially not a peripheral.
They literally record the cameras and 'screen', then send it off to their servers.
The VR hardware absolutely spies on you. Even if you tell it not to, it still shows up in the mobile app.
You seriously think they will pass on this golden opportunity?
I wonder what specific examples you are aware of that are not disabled in this manner?
As if Meta has to suddenly show Apple all of its goods now too. Giving Apple access to all Facebook or Instagram data and letting them decide where to draw the line.
Stop letting the distaste for Apple effect reason and sanity.
Meta is running an app store on Instagram that Apple is using?
https://bsky.app/profile/matthewdgreen.bsky.social/post/3lef...
If enough blogs expose these things (if they are actual privacy concerns — I mean I am already storing the photos themselves on Apple's iCloud, so) then I expect Apple to back off and make the feature opt-in in an upcoming release.
I don't recall messages, photos, apple maps, notes, camera, calendar etc asking me detailed permissions. I think health did ask for some.
Installing equivalent Facebook messenger, Google photos, Google calendar, etc also of course did.
(Greediest award goes to whatsapp which basically doesn't work unless you grant it full access to contacts boo)
However, WhatsApp groups show a name, so that's a workaround if you are using WhatsApp with someone you know well: Make a group for the two of you.
When a friend went to install WhatsApp for their iPad, they succeeded!
Then they said it wasn't working properly. Unfortunately that's because app store search brought up misleading third-party WhatsApp apps for the iPad. If you weren't paying attention, it was too easy to think you were installing the official app from WhatsApp. I didn't notice the app was third-party at first either, and I was very surprised to find no app at all from WhatsApp itself on closer inspection, amidst a page of search resulrs all claiming to be it.
It was actually worse (at least as of a few years ago) because they didn't allow you to manually input phone numbers. You either need the other party to message you first, or use a wa.me deeplink (eg. wa.me/12125551234).
I guess it's debatable whether that's categorized as "it works" :>
That's easy to say, and much more difficult to implement than it sounds.
Careful: There's a lot of nuance in how these kinds of options are presented to the user. Depending on how they're designed, "the general public" will default to yes or no; or get frustrated / overwhelmed with pedantic permission dialogs.
Thus, part of "Let Apple offer users the option" is a commitment to studying how that option is presented, and the overall implications of such an option.
I don’t follow. What is wrong with the status quo?
Businesses are deciding who lives and who dies, instead of people being allowed to have their own choice in the matter. These businesses make decisions based on data stolen from users. If the data were on paper in a person's home, it would be considered private and inaccessible.
Why should a company decide that they should have access to your every move and every data, just because you purchased something from them? Why should a company decide what you're allowed to do with your device? A business shouldn't be permitted to decide these decisions for you without your fully informed consent.
That's what's wrong with the status quo.
The status quo is that Apple has this power on top of the power to collect 30% for all digital transactions (or be denied on the store) and the power to force Apple Pay support to be required (or be denied on the store). Apple also has the power to collect all the data but deny it to others.
That's the status quo that the EU is addressing.
Note: I don't want FB to have my data. I also don't want Apple to have those powers enumerated above.
> That's the status quo that the EU is addressing.
> Note: I don't want FB to have my data. I also don't want Apple to have those powers enumerated above.
Yes, and I concur.
In an ideal world that would be great. However, right now it is either Apple of Google when it comes to smart devices for average consumers. Kinda like political dichotomy in US politics.
Democracy will not function with an educated public. And dumbing down choices are just a way to get give power to megacorp and political institutions.
What makes you think that?
> dumbing down choices are just a way to get give power to megacorp and political institutions
Yes, and an educated public would find better ways to convey the same information because they can use their education to build a new thing, or build regulations or laws where they see a need, or build defenses against adversaries without sacrificing privacy. You can't do that with your local public (eg, citizens) if your citizens aren't able to comprehend the problems they're encountering.
Sorry now I can't edit the parent comment now. That was miss type (bad keyboard). Meant to say "Democracy will not function with OUT an educated public. Happy New Year!
This doesn't seem reasonable. Let's try to apply the logic elsewhere:
> Patients must take responsibility for knowing how medicine works and motivations of its creators/prescribers.
Requiring everyone to have deep technical knowledge about anything they use would prevent everyone from using more than the things they are experts in. So, there needs to be either a technological regression, or something to help defend users from unethical practices. The only entity really in a position to do that is a government, for better or worse.
This is true. If you blindly trust whatever your doctor says, you are going to have a bad time in the current medical system. Doctors are incentivized to push pills because they get kickbacks from the pharma industry. This is pretty well known (https://www.propublica.org/article/doctors-prescribe-more-of...)
When it comes to Elective surgeries, perscriptions. etc. you need to do your own research to how these things work and make an informed decision for yourself. Ultimately, if you're an adult, you are responsible for your own body and your own equipment.
It's not a matter of deep technical knowledge, it's shallow technical knowledge and political knowledge of what institutions are trustworthy.
Apps can and do detect this and deny access certain features. For instance the mcdonalds app won't give you offers if you choose approximate location.
I have to think if Apple were mandated to be more open to competitors they would not be allowed to reject apps on this basis.
This problem is just multifaceted and far reaching. Not sure how to go about solving it?
This is going to be irrelevant in the EU once sideloading gets popular.
EU can block payments from EU to Facebook.
So you want the EU to play whack-a-mole with fly by night IoT vendors, some of which might be shipping directly from China? Or do you want to fix this with even more regulation, like requiring licenses to import IoT products or whatever?
Yes
Like they do with other online criminals
I would expect them to use a heavier hammer to whack that mole....
We shall see — that may simply be a security mindset paranoia on my part.
Regulating the AppStore makes sense. Proliferating lots of them is the most inane policy decision ever.
Use flash to create seizures, nudity people realtime, hack your ex, damage the device, cheat at games, spam your enemies, etc.
There is an infinite use case for tiny malicious apps finding malicious or gullible users and with side loading there are going to be stores created to appear very legitimate when their intentions are actually illegal.
I think the EU has very noble intentions while completely failing to understand that society is a wreck and a lot of money is made through extortion and fraud. Their apparent fix is to make the OS developers still responsible for what is installed while taking away funding for it. I am guessing the end game is more taxes and government intrusion on private devices to fix the problems they are purposely creating.
As a tech person I find this weird, but then I remember the relevant XKCD: https://xkcd.com/2501/
Surely if normal people can't do a thing, even if only because it's too complicated or inconvenient, normal people aren't going to be a big source of security issues due to that thing.
If that doesn't work, set up a deposit requirement like Apple wanted for the 3rd party stores and then walked back. Do something wrong, lose the deposit and the entitlements.
1. characterizing this as a "discussion thread about Meta" is a stretch. While the OP is about meta specifically, it's fairly obvious that as of a comments up, the discussion is about the behaviors of app developers in general, rather than what Meta is specifically doing.
2. Discussing unintended side effects isn't "moving the goalposts". If we're talking about the student debt crisis, and someone brings up the idea of student loan forgiveness, it's not "moving the goalposts" to bring up concerns about inflation.
Imagine it. Fear it!
Article 7 https://gdpr-info.eu/art-7-gdpr/
Recital 43 https://gdpr-info.eu/recitals/no-43/
Those two in combination stop companies processing data for unrelated task to the services they provide. And it's indeed true and already been applied, see this: https://www.digitalguardian.com/blog/google-fined-57m-data-p...
[0]: https://en.wikipedia.org/wiki/Consent_or_pay [1]: https://uoou.gov.cz/urad/povinne-zverejnovane-informace/svob...
The last time I used iOS I found the app store quality was also really bad. People listing "free apps" that immediately require you to start an expensive monthly subscription to use. The effect on the mobile games industry has been so disastrous that people would rather carry an entirely separate mobile device on them just to play "real games".
On google play or the app store you can play a mobile version of minecraft with microtransactions for $7. With sideloading you can just play a full version of the more popular java edition PC game, for free. (pojavlauncherteam.github.io). I think that sums up the sideloading experience.
Syncing files with Syncthing is no longer possible on Android because the Android team won't fix the performance of storage access framework, for example. This is 100% on Google, not Syncthing.
But I can still use SyncThing-fork because it's on FDroid. Similarly for the Fossify apps, Quillnote, KeepassDX, Privacy Browser, and dozens of others.
Apple will never put in the effort to make a community that thrives on sharing open source apps that are not profit driven. It's simply not in their DNA. And I don't want to have to live in a world where every developer that wants to make a mobile app has to pay a tithe to the overlords of Google and Apple. They will always claim that they're fixing security problems by acting as an intermediary, but there's no way for them to do that without replacing my choices with theirs, and nothing in Google's or Apple's decision-making history indicates they're better equipped to make decisions governing my machines than I am.
So why would a normal person want to sideload? Because they don't want Google and Apple telling them what software they can install on devices they purchased.
This idea that apps are going to strong arm data out of users seems like one of those talking points which sounds good but doesn't pen out, but somehow simultaneously is used to prevent users from being able to increase either their freedom or their privacy. The status quo sucks, and is in the best interests of both overlords: Facebook knows if it has permission or not, and Apple can claim the only reason they won't abuse this knowledge is if you allow them curation control.
Not saying it doesn't suck, only that it is very ordinary and ubiquitous.
I thought the value proposition of the walled garden was that no app was malicious so this is a non-issue.
Do you have any examples of Meta misusing this sort of data in the last 7 years?
They want their glasses and headsets to integrate as tightly as an Apple Watch or Vision Pro to show messages and other notifications, connect to WiFi, and share files with an iPhone, but Apple uses private APIs for their own devices. Meta says that is anticompetitive and the APIs should be public.
Apple lays out their rebuttal in detail here and it’s clear Meta asked for everything in the hopes that Apple will settle for some of these things: https://developer.apple.com/support/downloads/DMA-Interopera...
3rd parties aren’t going to get the same access or treatment for a number of reasons…many of which Apple has outlined.
>They want their glasses and headsets to integrate as tightly as an Apple Watch or Vision Pro
Not agreeing or disagreeing but that makes much more sense.
I have WhatsApp to talk to some family and I recently disabled allowing all contacts in iOS 18. WhatsApp now has a persistent notification at the top of messages to "Allow All Contacts".
If Apple allows users to choose whether or not to give Meta access, and users choose "no", Meta can lock them out of the service entirely (e.g., "you can't use this Meta Quest headset without allowing access to your messages").
That being said, Apple is definitely fighting for its own interests here as well. It would obviously benefit them to sell their own watches, headsets, earbuds, etc.
*AirPlay Continuity Camera
*App Intents
*Devices connected with Bluetooth
*Apple Notification Center Service
*iPhone Mirroring
*CarPlay
*Connectivity to all of a user’s Apple devices
*Messaging
*Wi-Fi networks and properties
Now ignoring the obvious societal dangers in this request. (I mean really? Should you be using a Meta headset while you're driving?) The scope of data that they are asking for is breathtaking. All the data, wifi, messages and notifications of not only every iphone in the US, but all of the user's other devices as well. To potentially include their cars.
We need to really think deeply about how we set up access to Apple data and APIs. Requests like this are putting me more in the "deny all requests" camp. If tech companies can't be at least a little more reasonable, then I don't think they should have access to our data.
The Meta HUD glasses seem like they're definitely designed to be used while driving, and provide a safer way to access info like notifications than looking down at your iPhone. That isn't "Apple data and APIs" this is a notification that someone needs to display on their HUD.
Really, the fact that Apple doesn't want to allow this sort of thing pretty clearly demonstrates they're acting in bad faith.
If this is still possible, then Apple fucked up the implementation of this feature, as clearly there should be no way to differentiate not having bothered to fill out a ton of contacts and having limited access for an app to see your contacts; and since this is so obviously easy to do correctly, it frankly sounds actively malicious: there is a set -- probably a very small set -- of engineers and product managers who chose to build this incorrectly, in order to continue to maintain the status quo of the proxy war between Apple and Meta, to our detriment.
https://developer.apple.com/documentation/contacts/cnauthori...
The documentation for ContactAccessButton suggests only presenting it if you have limited access:
https://developer.apple.com/documentation/contactsui/contact...
edit: but that’s intended to be used specifically to respond to a contact search. I don’t use WhatsApp, but a “persistent notification” sounds unrelated to ContactAccessButton.
There are cases where you can fake data and cases where you need to be able to block access and the apps should respect that.
If you only allow a subset of your contact, WhatsApp proceeds to not display contact information for everyone and to disable the whole status feature.
[ ] Check here if you want to share all your data (or something more precise) with Meta. Warning: possibly insecure. Use at your own risk.
There's good reason to not have this prompt and not give these abilities to applications. Apple's reason to oppose the DMA and Meta here might be different, though.
Not if it's available in the developer options, or has more other sorts of friction to check the box. Or if it has a red warning label with the phrase "may increase the chance of hackers stealing your data and impersonating you".
One just has to make it unattractive enough to most.
2. The end goal of corporations is ultimate wealth concentration and the destruction of local economies.
3. Corporations combined with technology means too much technological growth at too fast a pace
The world would be better off without the biggest 10 of them for sure.
If it's anyone's job to limit how Meta can collect and use data despite the express consent of the user, it's governments, not Apple.
If such popups were introduced in iOS, they should be universal, of course, and the same danger prompts should show for Apple's software as for their competitors. Apple won't do that (outside of the EU) but it'd be a solution to the data hunger without compromising market accessibility too much.
A good alternative would be for Apple to remove APIs entirely, including for themselves. If they consider some data and some interactivity to be too dangerous for users, perhaps they shouldn't be messing with it either.
Apple makes a habit out of exaggerating the dangers of complying with any regulation. Just a bit of fear mongering gets their fans in a state where they'll maintain Apple's walled garden even when they stand to benefit from it being opened up.
> A good alternative would be for Apple to remove APIs entirely, including for themselves. If they consider some data and some interactivity to be too dangerous for users, perhaps they shouldn't be messing with it either.
I don’t want this and it doesn’t make any sense. I trust Apple as a vendor in a way I don’t trust third-party developers (or else I wouldn’t have purchased an iPhone), and it’s entirely reasonable to grant them permissions I don’t grant anybody else. Removing those entirely makes my phone considerably less useful.
The only part I disagree with is that it's limited to phones, it absolutely isn't. It's any computing device, be it a general purpose PC, a tablet, a phone, your car's infotainment system, what have you.
The large majority of the population does not understand how these devices work, and what kinds of problems they can create if used unsafely, and they don't care to know. And like, I get why: life is complicated enough as it is. Simple fact is when Joe Consumer pulls a new TV out of it's box and it comes with the contrast and color saturation through the ceiling so everything looks like shit, and motion smoothing is adding 60ms of delay to the response of connected hardware, he's fine with that. I don't like that for him, and I wish he wasn't, but most people just don't care. Most people want to speed run whatever damn things they gotta click to make the stupid light and noise machine do what they need it to do, so they can resume their idle time.
That's why if we actually want to make progress on reigning in these socially corrosive services, we need not just options, but a set of default settings, mandated by law, that respects user privacy. As a user of electricity, I do not need to be informed about how electricity works to safely use my outlets. As a user of water, I do not need to be informed about how plumbing works to safely take a shower. I shouldn't need to know jack about smartphones or computers either in order to not have my personal information used to sell me gross new flavors of Coke.
Users trust companies like Apple, Google etc not to place them in harm's way.
And so when prompts like this are shown they will quite happily approve without even reading the words.
https://developer.apple.com/support/downloads/DMA-Interopera...
AirPlay Continuity Camera
App Intents
Devices connected with Bluetooth
Apple Notification Center Service
iPhone Mirroring
CarPlay
Connectivity to all of a user’s Apple devices
Messaging
Wi-Fi networks and propertiesI mean, where does a company get the balls to demand total access like this to the phones, networks and data of every phone in the US? These companies have zero fear of us as a people.
(They have zero respect for us as well, but that's another issue.)
It's probably a bit of both. One part Apple being monopolistic jerks and one part Meta wanting to hoover up even more private data. One issue I can see is that the EU would side with Meta, knowing that the EU privacy laws will protect its citizens, but Apple has to consider the ramification for all users, including those not protect be the GDPR. So Apple is forced to open up and Meta will start using the opening to suck up private information on its American users.
If they are “forced to open up” in the EU it doesn’t mean they will here.
https://developer.apple.com/support/downloads/DMA-Interopera...
Earlier discussion: https://news.ycombinator.com/item?id=42457073
https://www.macobserver.com/tmo/article/apple_granted_patent...
it will burn down their own playhouse too of course
Framing it as being about `Apple vs Meta` is exactly the line of thinking that Apple wants, and it does a disservice to real Apple users, who have repeatedly been locked into a ecosystem where they have little control of their own data, where even sharing photos over Bluetooth isn't even an option! It's so locked in it's really unreasonable to frame this as being about Meta. Of course users should be able to give none / empty / fake or even real data to Meta if they so choose. But really this is about Apple, user rights, the EU, and a more fair playing field. If you read the PDF Apple put out, they are not offering any kind of middle solution, they are just saying they will, as usual, review case by case device partnership opportunities as it pleases them.
The AI becomes significantly more useful if it understands your digital life more. Only Apple has OS level access for agentic AI but Meta wants it too.
"Useful" is misleading. It should be "useful for the big corps for entrenching you further into proprietary technology so that they can take advantage of you later".
But isn’t this already the case right now? In my opinion this argument is kind of backwards because the lack of (or access to) APIs is precisely what’s preventing us from having alternatives!
Siri is proprietary, closed source, big corp, etc.
Want an open source, community based, interoperable, fully local, etc. assistant/AI? It cannot exist in today's world simply because it requires what Meta asks for.
I dislike Meta very much but I refuse to believe that creating or opening up such APIs would foster „entrenching you further into proprietary technology“.
Yes, it is. The entrenchment is an ongoing process designed to give us short-term benefits that appear harmless. But they slowly add up and produce an ecosystem that is actively harmful and not much better than before (on average).
By the way, I don't argue for or against Meta having access to APIs. I am against Meta entirely -- and the only logical answer to them is to dismantle them.
Yes, and because of that, it's the only voice assistant I want. I do not want a hyper-intelligent "friend that knows everything about me" because that, without fail, is being sold to me by companies who will need access to every last bit of data about me and my life, who will then host that data somewhere, with some level of security, which I'm not involved in and do not control. And tbh, given my thoughts about how users approach tech, I don't want that for other people either.
Putting aside my feelings about surveillance capitalism and how inherently exploitative and inhumane it is, with full knowledge that all my objections under that umbrella already, for me, constitute a wide and thoroughly researched opinion as to why this shit is horrific for privacy on it's face, but putting it aside:
If companies want access to every last drop of information, every last data point, even assuming an altruistic "we just want to make the best AI assistant we can" against all evidence to the contrary: then there needs to be set, and severe consequences for data breaches for these companies. No more of this "we put up a blog post about it and security researchers got an interview with CNN" no, fuck that shit. If Meta has a breach in it's AI product and as a result of that, whatever hacker org gets the full spread on let's say 5,000 individuals? Then those 5,000 individuals need to be entitled to damages. Firstly anything that impacts their lives needs to be unwound completely; new SSN, any money taken restored, help moving if required, whatever. Secondly they need to be compensated for the emotional toil of spending weeks or months sifting paperwork, sending letters, attending court dates to unwind whatever is done with their identity, and Meta is responsible for ALL of that.
If these companies want effectively root access to my life to provide these services, then I don't think it's unreasonable to say they need to be legally and financially responsible if their negligence causes people to get exposed. And if they're not prepared to take on that liability, then perhaps an AI assistant that knows everything about you is just a product that cannot be made.
I don't think this is an unreasonable view.