7 ms·
As an iPhone user I’d like to think iOS does not allow this. However, I understand there’s a private API that allows larger companies access to functions that a
by txsh 9y ago
As an iPhone user I’d like to think iOS does not allow this. However, I understand there’s a private API that allows larger companies access to functions that are not available to regular developers. It allows them access to the microphone without the red bar showing even when there’s not a call. Like others have, I’ve received ads for products spoken about near my phone but never typed into a device I own or on my router.
- jtbayly 9y agoThen download your data file and see. I don’t think FB has this data from iPhone users, but I’d be happy admit I was wrong if you proved it.
- shrumm 9y agodo you have any citations to back this up? that’s a serious claim. Huge breach of trust by Apple if true.
- hrrsn 9y agoiOS doesn't. Apps using private APIs are not allowed on the App Store. Apple granted Uber an entitlement for a private API, but no other app has this: https://twitter.com/chronic/status/915930211941781504 https://twitter.com/chronic/status/915930211941781504
- vbezhenar 9y agoThis believe based on trust to Apple, not on technical limitations. I always wondered about this concept of private API: available to anyone but theoretically forbidden to be used. I'm sure that there's a million ways to circumvent Apple's static code analysis and slip through their review. Why didn't Apple limit their API usage with technical restrictions.
- Klathmon 9y agoIt's pretty trivial to bypass Apples code analysis for private API usage, at least a few years ago it was.
- sjwright 9y agoTechnical limitations == trusting Apple. App store validation == trusting Apple.
- threeseed 9y ago> Why didn't Apple limit their API usage with technical restrictions. Because this was impossible without forcing users to stop using Objective-C. The language allows dynamic method dispatch and so it's always possible to allow internal API calls.
- TazeTSchnitzel 9y ago> This believe based on trust to Apple, not on technical limitations. I don't think you're right; “entitlement” is a technical term used for OS-enforced permissions on Apple platforms.
- hrrsn 9y ago>This believe based on trust to Apple, not on technical limitations. I trust Apple a lot more than Google/Facebook/etc.
- gambiting 9y agoIt's the same when developing for PS4/X1 - headers have methods which are not documented and you're not allowed to use them - if you do, the game will fail certification. I guess they just check if the executable is linked against them and won't certify the game.
- innagadadavida 9y agoIt is technically impossible to do what you are suggesting, otherwise many apps would already be doing it. If there any documented and known issues with the app validation process, please share links.
- vbezhenar 9y agoWhy is it technically impossible? Move functionality to kernel or to another blessed process and restrict interface via sysctls or any kind of RPC. It's like using SQL from JavaScript and forbid users to open developer console.
- txsh 9y agoIn the comment thread you linked to the author has a “faint recollection” of what I’m referring to, confirms Facebook has special access because of iOS integration. So I’m not sure why you posted that. Seems to undermine your argument.
- askvictor 9y agoWith iOS we have to trust/hope that Apple is doing the right thing. With Android we can audit the code. Yes, the early permissions model left a lot to be desired, and was subsequently revised. But we could always look at the OS source to see where things might be leaking. Unless, of course, these things are happening in the Google Framework level, at which point, we have to trust/hope that Google is doing the right thing.
- amluto 9y agoYou can audit Android and see that it leaks like a sieve. Ever seen “read phone state and identity”?
- askvictor 9y agoI'll take your word for it, but my point is that you _can_ audit it. You can't audit iOS.
- htormey 9y agoWell, you can’t audit the proprietary hardware drivers most android manufacturers use or the many proprietary apps from google etc that sit on top of android or the changes that the carriers make. I remember when I was an Android developer dealing with several issues relating to the fact that one carrier put a proxy in the networking stack. Here is a recent example: https://www.theregister.co.uk/2016/11/15/android_phoning_home_to_china/ https://www.theregister.co.uk/2016/11/15/android_phoning_hom...
- ayrx 9y agoYou can audit iOS. Security researchers do it all day long.
- askvictor 9y agoaudit the code?
- vanilla_nut 9y ago
- ceejayoz 9y ago> Like others have, I’ve received ads for products spoken about near my phone but never typed into a device I own or on my router. I've had this experience, and I still suspect it's likely to be confirmation bias. Chances are if you're speaking about something, there's a decent chance Facebook can figure out your likely interest in it in a variety of surprising and convoluted ways - your recent credit card purchases, news articles that may have mentioned it in passing, etc. We also don't really notice all the times Facebook totally whifs a recommendation.
- zeep 9y agoIf you are talking about the NSA, yes they do have a special channel with Apple... not sure who else does...