I just don’t think it’s an effective way of solving the problem.
If internet access wasn't granted by default, a lot more apps would function without it.
Many other apps wouldn't exist at all, because their only reason to exist is to spy on users.
If you wanna go further, 20 years ago we didn’t have that much of distribution, users, or differences in software/hardware. Shipping speeds were also much slower.
Even if it's not the most effective way to raise awareness, it does put pressure on developers to be explicit about the connectivity requirements with users. It would also be a great way to audit an app's local-first / offline-first claim without having to do a network packet capture.
Want telemetry? Send it through Apple and Google. Given Apple's late history and latest trends in Android development, I see them both favoring this approach.
I just flat out think this is bullshit
Non-multiplayer games, clock, camera, contacts, phone, text message, file explorer, keyboard, launcher, notes, document viewer/editor, image viewer, audio recorder...
Most of the apps on my phone do not need internet access.
That said, I'd love to have a new "Internet access" permission for apps, so users had the choice. Perhaps even separate "Allow iCloud" and "Allow Internet" but that's probably too granular for Apple's taste.
I have no idea if this is what already happens, but I feel like it might be. (Why would each app have all these network connections when the system could just manage it instead?)
> you just don't use apps.
An app isn't an "app" if I don't install it?
I have banking "apps" and others which obviously do require internet access to function properly, but the hundreds of flashlight apps in the app store should not need the internet.
The app I use to back up my text messages and contacts does not need internet, but the other app that I use to copy those backup files and pictures off my phone to other computers does.
The sad thing is, even if I take steps to prevent others getting access to my contacts or text messages, sketchy companies will still get those same contacts and quite possibly most of those messages from everyone else.
We need "herd immunity" when it comes to digital privacy, but it's unlikely to ever happen.
Apple could refuse to publish them, then. Isn't that why we are forced to go through the App Store? Because Apple ensures every app there works in the best interest of the user?
The only way to prevent malicious apps from affecting your privacy is to not install them or not give them network access.
And yes, having the ability to deny any app network access on iOS would be great.
YouTube used to be separate domains for ads and then it got merged together so that you can’t block the ads network wide without blocking YouTube videos.
[0] https://old.reddit.com/r/ios/comments/aib10i/in_china_ios_al...
If Apple wanted to provide this willingly they would. That its only available in China due to government regulation tells you all you need to know.
You could of course disable network access to Play Services, but at least for me that broke a bunch of apps or made them unreliable.
What AOSP ROMs need besides the network permission toggle is IPC scopes functionality, akin to storage scopes.
Folks brings up 'IPC' as if this is some chink in the armour in AOSP. It isn't. 'Apps' pretty much on most consumer OSes can 'IPC' their way with other co-operating apps to 'achieve' network access from behind a firewall, just the same.
> since many apps communicate with Play Services and as far as I understand (but I may be mistaken) Play Services does work that involves internet access on behalf of other apps
If the OS or its privileged component will fchown the socket to the origin app, think the INTERNET permission will be enforced as expected.
I am not familiar with iOS internals, but does "very little IPC" mean "zero IPC"? Because if we are talking IPC in the context of bypassing permission checks, I imagine, 'very little' doesn't cut it?
If you want something less disruptive for isolation, there's Private Space. What I like is that this can stop apps there from working in the background on stock Android as well.
But yes, agreed it should be everywhere.
They also added the sensors permission.
(Yes, you can disable network access to Play Services, but it sometimes breaks things and the general point of IPC as a hole still stands.)
They were designed so multiple people could use one device.
Some people use them to separate identities or contain apps they view as bad. I'm not sure if the efficacy of this.
Grapheneos improves them significantly https://grapheneos.org/features#improved-user-profiles
It would severely depend on how you categorize "most apps" because I would say I pretty much only use apps that need the Internet, barring Calculator, Camera, and a PDF reader (only because I prefer how it zooms books vs browser. Everything else implicitly needs the Internet as that app is just a better UI to using their mobile web site, if they even offer one.
It is called app transport security. if you don't set it up your app boots in a sandbox with no network.
Settings -> Privacy Security -> App Privacy Report
Unfortunately 1 - as a _user_ you cannot opt-in or out. I wish Apple would take the next step and let us select which sites an app is not allowed to communicate with. Or ideally even globally for all apps.
Unfortunately 2 - the list of sites the app wants to communicate with is not clearly communicated upfront like before you install.
Unfortunately 3 - the list can also contain wildcard domains
Small steps - they really need to push this to the next phase IMO.
Problem is there's no way for users to actually know that. iOS has no "this app can't reach the internet" indicator, so the whole guarantee is invisible. I even had people assume the opposite — app reads your whole library, therefore it must be uploading it somewhere. Exactly backwards.
This is the Apple mindset. Make things easy. Do not make things complicated.
Citation needed.
Looking through my phone the vast majority of third party apps I have installed obviously require internet access:
- Social media
- Travel (rideshare/airlines/hotels)
- Streaming
- Finance (credit cards/banks)
- Shopping
Not counting built-in apps like the calculator I'd estimate 80-90% of the apps I have installed require internet access.
- Photo/Video editors - Snapsheed, Lightroom, Video trimmers etc.
- Document readers & scanners - PDF viewers, e-readers, OCR scanners
- Note taking - Obsidian
- File/Password managers - Authenticators etc.
- Single player games - Chess, puzzles etc.
- Audio/Video players - VLC players
We've just become conditioned to accept that every app needs to phone home for tracking and ad-delivery.
PDF viewers (like GoodReader) can download a PDF from a URL, or read it from a network drive.
Obsidian has functions that need internet access (e.g., connecting to the Obsidian sync servers, installing community plugins).
Password managers often have a sync feature.
A video player may be able to play files hosted on remote servers or network drives.
They should be useable without an internet connection, but it's entirely reasonable for them to request permissions for network access.
I do take photos on my phone but I want them automatically backed up to the cloud so I don't lose them if my phone is stolen.
Editing text/video/music I prefer to do on my computer not my phone.
> virtually none of this requires internet beyond icloud syncing/drive.
That's a weird counterargument. "This doesn't require internet except this feature does require internet."