Specifically, these big companies revenue share with app companies who in turn increase monetization via selling your private information, esp via free apps. In exchange for Apple etc super high app store rake percentage fees, they claim to run security vetting programs and ToS that vet who they do business with and tell users & courts that things are safe, even when they know they're not.
It's not rocket science for phone OS's to figure out who these companies are and, as iOS / android os users already get tracked by apple/google/etc, triangulate to which apps are participating
Also, unlike facebook, they also weren't just caught running a dark money lobbyist network with the goal of forcing more collection of minors' private information.
[1] https://quickthoughts.ca/autotracko/ [2] https://www.eff.org/deeplinks/2026/03/targeted-advertising-g...
Just as importantly, apps aren't allowed to remove functionality if the user says no.
You need additional permissions to do things like access location data or scan local networks for device fingerprinting.
> consumer apps embed ad SDKs → those SDKs feed location signals into RTB ad exchanges → surveillance-oriented firms sit in the RTB pipeline and harvest bid request data even without winning auctions
Would you ban ad supported apps? Assuming the comment you're responding to is realistic, I'm not sure how the OS is to blame.
If Google & Apple & friends refused to take a rake and opened distribution, then I'd agree, net neutrality etc, not their problem
But they own so much, and so deep into the pipeline, and explain their fees to courts because "security"... and then don't do investigations. They employ some of the best security analysts in the world and have $10-30B/yr revenue tied to just the app store fees, so they very much can take a big bite out of this if they wanted.
> They employ some of the best security analysts in the world and have $10-30B/yr revenue
I'll never not be impressed by how many people will defend trillion dollar organizations and say that things are too expensive. Especially when open source projects (including forks!) implement such features.I'm completely with you, they could do these things if they wanted to. They have the money. They have the manpower. It is just a matter of priority. And we need to be honest, they're spending larger amounts on slop than actual fixes or even making their products better (for the user).
There's no need to ban ad supported apps when you can just ban the practice of using ads targeting users based on individual characteristics.
Ask yourself the same question about personal health data and the answer reveals itself: the CEO and CIO know (or should know) that the vendor needs to be HIPAA-compliant or it's their necks (the CEO's and CIO's), so they look for a vendor who advertises as being HIPAA-compliant.
Pass legislation to the same effect for all PII and the CEO and CIO will then make requirements of the vendor. If the vendor lies, they get fired because the company hiring them is culpable. The vendor may also be subject to civil and/or criminal penalties. It seems simple, other than the fact that we have a federal legislature with no apparent interest in solving this problem, alongside a populace which either doesn't notice or doesn't care about that.
To answer the question more pithily: communication.
In regulated industries, like finance and taxation, regulators deliberately assign responsibility to individuals, so misconduct doesn’t get lost inside the company or within its corporate stakeholder network. That removes a lot of friction once you want to hold someone liable.
I've read our parents comment as an implicit proposal to establish similar structures in tech.
However, I'd be shocked if a cursory audit comparing SDKs embedded in apps and disclosed data sales showed they were effectively enforcing anything at all.
Yes, I absolutely would. Advertisements are a scourge upon people's wellbeing on top of being ugly and intrusive.
If you want to build a free product, that's great. Build a free product.
If you want to make money from your product, then charge for your product.
And then you will get fired by the end of day.
Really these days it's 95% psychological manipulation to get people to buy inferior quality stuff they don't need. And 5% of people actually finding what they're looking for.
Don't forget, most advertising can work fine in a "pull" mode. I need something so I go out and look for it. These days something like Google (not ideal because results also manipulated by the highest bidder). Or I look for dedicated forums or a subreddit for real people's experiences. In the old days it would have been yellow pages or ask a friend.
Maybe one clear example is needing a permission once for setup and then it remaining persistent.
An easy demonstration is just looking at what Graphene has done. It's open source and you wana say Google can't protect their users better? Certainly Graphene has some advanced features but not everything can be dismissed so easily. Besides, just throw advanced features behind a hidden menu (which they already have!). There's no reason you can't many most users happy while also catering to power users (they'll always complain, but that's their job)
Apple does not let you restrict app network access[1]
You have no ability to know who your app is connecting to, and you cannot select or prevent it.
[1] except maybe the cellular data toggle
Read the TOS.
If I was simultaneously also the owner of the ad platform, I'd fix it & knock out the bad players, or get ready to be sued for a decade+ of knowing malpractice
And if I was a US citizen seeing the companies being involved be sued for being monopolies and abusing their position, and then seeing them cry security in court yet knowingly do this for a decade+, I'd feel frustrated by successive left + right US administrations & voters
Or for location, the cellular providers?
The interesting part is Google & Apple, as part of explaining to courts why their large app store fees are legit and not proof of monopoly positions, hid behind the security argument that they need to be the clearing house of what software runs on the devices. Except... they've knowingly punted on this one for 10+ years.
I would 100% agree that losing privacy through any utility-level carrier (credit cards, phone, OS provider, etc) should be default disallowed, and any opt-ins have a clear transparency mode with easy opt-out. At least two areas the US can learn from the EU on digital policy is digital marketplaces and consumer privacy protection, and this topic is at the intersection of both.
Fine, we'll force companies to allow a small little box to be added to their data center. Don't worry about what it does, but you cannot disconnect network/power to it once it is installed. Once it is operational, you'll no longer need to think about it ever again, and we recommend that you don't. You should also not talk about this box to users/customers/clients. In fact, you'd be better off if you didn't talk to your employees about it either.
Especially after Snowden, if anyone does not think the US govt TLAs are trying to read every bit that crosses a wire, then they are just deluding themselves. Even before Snowden, Echelon was known for telephonic intercepts. It didn't take much imagination to take it further for internet traffic. Snowden just removed the need for imagination.
Most people I've spoken with are either thinking "Apple/Google/Government would never allow apps to do something like that!" or they think "Everyone is already doing it so why bother trying to fight it. I'd only be inconveniencing myself for nothing"
That's the thing they don't just sit around, they all have run at start up and for Android I blame Google for not giving users the ability to block run at start up.
General Motors sold driving data to data brokers including LexisNexus. Anyone, private or government can buy data from LexisNexus.
As if I had a choice.
As if politicians of any party care now, in a meaningful way.
As if news orgs were ever interested in security experts who sounded the klaxons (for years and years and years).
That stupid game you installed a year ago, that's what gets you.
If you have a smartphone keep a very sharp eye on your location services, and whether they're in the state you expect them to be in. Also a great way to save your battery.
I'd be perfectly fine with going after companies that sell data to the government, but I don't think it would be fair to go after companies who were forced to hand data over unwillingly, even if they didn't inform the public it was going on out of fear of reproductions.
Everyone who has it is selling that info, and nearly everyone who collects it is selling it. Until there are laws that actually protect us, we should stop giving companies our location data every chance we get and push for laws that prevent it from being unnecessarily collected in the first place.
I don't see how we overcome that massive hurdle. It's not like those who ostensibly make the laws don't know and approve, and probably intentionally implemented that.
We now have full scale mass tracking and surveillance of the kind no one pre-9/11 would believe would have been allowed to exist in the form of the Flock cameras (of course it was an enemy Brit implementing surveillance in the USA) making anonymity quite literally as challenging as Winston Smith trying to move around without being detected to meet his love interest.
How are we going to get the de facto tyrants in the government to pass laws that materially disempower them by being unable to mass surveil everyone at any given time if they don't like what you are saying or thinking?
The problem with all the naysayers for all those decades is that once you have given up control over your own life and you have given away your rights protected by the Constitution, your enemies in the government are unlikely to simply give them back because you ask nicely. In fact, they will most likely aggressively move against anyone that even suggests that you nicely ask for your rights back.
In theory we should have to power to vote out those lawmakers and elect new ones who will pass the laws we want enacted and uphold the constitution. If we no longer have that power the founding fathers were pretty open about what was expected from us, but it isn't pretty.
Even the "reasonable person" standard for court would probably conclude that most people would never read it.
For example you can have a truthful statement: “all of the apps that you have are constantly spying on you”
And the rejoinder is “ any given app is not specifically selling my data to specifically the FBI and so therefore it is not spying”
To which the response would be: “that is correct however the aggregate data is bundled and sold off to specifically the FBI or intelligence agencies and so there cannot be a logical differentiation between apps.”
By that point the person has downloaded another rewards app and added their drivers license to it.
Its like saying murder is illegal but hiring a hitman perfectly legal. Its bullshit and everyone involved in these decisions should be in jail. There is no way anybody working for the FBI can claim ignorance to the constitution.