15 ms·
Privacy: Is That iPhone?
- jedieaston 7y agoInteresting. My iPhone’s Limit Ad Tracking policy is already enabled with no option to disabled. Can this setting be controlled by Apps/MDM?
- varenc 7y agoTo disable: Settings > Privacy > Advertising > Limit Ad Tracking You can also disable Location-Based Ads: Settings > Privacy > Location Services > System Services (at the bottom) > Location-Based Apple Ads Apple's ad tracking help doc: https://support.apple.com/en-us/HT205223 https://support.apple.com/en-us/HT205223 (Apparently they derive your gender based on your first name or the salutation on your iTunes account)
- keyle 7y agoThanks, I was shocked that it wasn't mentioned in the Mozilla post.
- tuxone 7y agoIt is, at the very end of the article.
- pault 7y agoI just looked at the location tracking preferences and the default setting for Google maps is "always", as in "whenever your phone is on". O_o
- jorvi 7y agoRemember to check that setting after each update, it often gets disabled after an update. I've pointed this out to Apple multiple times and its often fixed for a few releases until their fix regresses and the bug returns.
- maram 7y agoWhy is it limit only? Why cannot I turn it off entirely? And why does it take 6 clicks of separation go get to these settings?
- r00fus 7y agoIs it possible to control from an admin perspective this if you have a managed device?
- varenc 7y agoYes! A configuration profile can set forceLimitAdTracking https://developer.apple.com/business/documentation/Configuration-Profile-Reference.pdf#page=72 https://developer.apple.com/business/documentation/Configura... On that topic...if you're really security conscious you can set allowHostPairing to False. This requires a supervised device, but then your phone will only pair a computer that has the supervising certificate, and if none exists, then all pairing is disabled. This might help defend against GrayKey like attacks.
- gorgoiler 7y agoFinding the settings mentioned in the article is the sole dark pattern I can think of in iOS — when you find them it’s like finding a secret level in Super Mario Land. They are under Settings...Privacy...Advertising https://imgur.com/a/EOvUzCS https://imgur.com/a/EOvUzCS The Advertising and Analytics options are only visible below the fold, if one scrolls down the privacy page. The fold itself is disguised as the bottom of the page to put you off scrolling. Unlike everything else, they do not have icons and only come after a paragraph of text almost perfectly large enough to fill out the vertical height where the tracking options would be.
- saagarjha 7y agoDid you…print out a screenshot of your phone?!
- gorgoiler 7y agoI applied filters and took a screenshot of the screenshot to reduce image fidelity in case it contained any [covertly embedded]* identifying information [in the form of watermarks or hidden pixels]. *added for clarity.
- saagarjha 7y agoWhat are trying to protect against? A screenshot of a screenshot with a filter applied to it isn’t going to help you if your name shows up somewhere in it.
- bilbo0s 7y agoOK, so, probably an ignorant question, but here I go anyway: What, exactly, does "turning off IDFA" do? Does it send just a dummy IDFA? Or does it give you nothing at all? Why is rotating it periodically better? (I'm assuming rotation is better because that is what Mozilla is apparently recommending.)
- saagarjha 7y agoIt sends a zeroed out identifier: https://developer.apple.com/documentation/adsupport/asidentifiermanager/1614151-advertisingidentifier https://developer.apple.com/documentation/adsupport/asidenti...
- antsar 7y ago> I'm assuming rotation is better because that is what Mozilla is apparently recommending. I'm (cynically) assuming something different. Was "monthly" chosen by accident, or is that just enough time for advertisers to connect/correlate activity from two different IDFAs? Mozilla has big-dollar deals with the ad industry (namely, Google). Perhaps they want to appear pro-privacy while really throwing a softball?
- zie 7y ago"When Limit Ad Tracking is enabled on iOS 10 or later, the Advertising Identifier is replaced with a non-unique value of all zeros to prevent the serving of targeted ads. It is automatically reset to a new random identifier if you disable Limit Ad Tracking." From: https://support.apple.com/en-us/HT205223 https://support.apple.com/en-us/HT205223
- retpirato 7y agoThe problem is that Apple has always claimed ios provides more privacy (& security) than android, but that's irrelevant if you don't make sure your users are capable of finding the settings. Apple has always marketed to people who are (at least perceived to be) largely tech illiterate (while claiming you have to be extremely tech savvy to use android which is a lie), so if they view their users that way they should make sure those settings are easy to find.
- saagarjha 7y agoIdeally the settings would be configured in such a way that people wouldn’t have to dig through them to have it like they wanted it: it’d be set that way by default. iOS’s usually much better than Android is at this.
- ogre_codes 7y agoAndroid phones pump tons of location info and usage info direct to one of the biggest advertising companies in the world. On top of that, a fair number of Android phones ship with third party spyware and outright malware which cannot be uninstalled. The iPhone is a lot better for privacy by default. It's just not as good as it should be, and I do agree it's not as good as their claims suggest.
- lonelappde 7y agoQuestion is, does it matter if my barn comes with a door that only closes half way, and your barn comes with a door that closes most of the way?
- jonas21 7y agoIt depends how on how wide your horses are. In other words, it depends on whether the difference in information leakage is information you actually care about.
- desyerious 7y agoThere’s also the difference between privacy and anonymity. Apple has tools in place for privacy, but none for anonymity. For example, requiring a full name and physical address to sign up for the App Store (Microsoft, despite all it’s telemetry, let’s you install apps from their store without an account). I’ve heard suggestions to give Apple a fake name/address, but what if they start verifying like Facebook by requiring government issued ID? Worst is new iCloud accounts now require a phone number for verification.
- saagarjha 7y agoCan we have a title that mentions “IDFA” in the title, please? (Also, I’d prefer something that wasn’t as clickbaity…)
- dredmorbius 7y agoEmail title change requests to hn@ycombinator.com. The mods are quite responsive to these.
- jrochkind1 7y ago> Phone users can currently disable the IDFA, but have to do so manually; Android users aren’t even given this option Huh. I have never heard of this.
- criddell 7y agoToo many incentives are wrong for Google. They are fundamentally an advertising company that has built their fortune monitoring users. They aren't going to build an operating system that actively works against their best interests.
- jonplackett 7y agoWhy does Apple have this as the default? Now they've mostly ditched their own advertising platforms, what do they have to gain from having these default settings?
- taurath 7y agoMaybe to prevent really nasty dark patterns from emerging? It would break a /lot/ of companies, I’d think
- MindTooth 7y agoOne thing I always check when using a new install.
- Nerada 7y agoI'm in the same boat. I went to check after reading this and I had already disabled both settings.
- oil25 7y agoAnyone disillusioned by the thought that Apple values privacy would be well served by reading iOS, The Future Of macOS, Freedom, Security And Privacy In An Increasingly Hostile Global Environment - https://gist.github.com/iosecure/357e724811fe04167332ef54e736670d https://gist.github.com/iosecure/357e724811fe04167332ef54e73... There is so much more to privacy than is made apparent to the user as a few OS knobs to "limit" ad tracking.
- zigzaggy 7y agoThank you for sharing this very helpful / valuable information. I’m always looking to go deeper down the rabbit hole of security.
- mariojv 7y agoSaved this writeup for future reference, thanks. Agreed that privacy needs more analysis than trusting a few rather opaque OS knobs. I am a little skeptical about some of the claims in that gist, though. One example is when they claim that APNS pushes require app access to a globally unique iOS activation identifier. That seems false. According to Apple’s dev docs at least, those tokens are device-and-app specific and have to be re-requested at app start time since they can be regenerated for a variety of reasons: https://developer.apple.com/library/archive/documentation/NetworkingInternet/Conceptual/RemoteNotificationsPG/APNSOverview.html https://developer.apple.com/library/archive/documentation/Ne... Seems to have nothing to do with an activation UUID from a quick glance. I appreciate a lot of the reference material in there, but this seeming mistake of conflating 2 different UUIDs makes me a little skeptical of some of the conclusions. Edit for correction: I think I misread this part of the gist. They never directly say that the activation UUID is given directly to the app developer, just that Apple can track your social networking app pseudonym over APNS, "and possibly the social networking service" will be able to, as well. This to me implied that the social networking service had the activation UUID, but the author never directly said that. If the notification has your pseudonym in it and Apple's storing that when a notification goes to APNS, it does seem like Apple would be able to tie that to your device if they're peeking inside the notification payload. The solution to this would be for the app developer to not include sensitive info in notifications or for the user to disable push notifications, but an E2E encrypted trustless notification solution provided by Apple would be much nicer.
- varenc 7y agoMozilla suggests resetting the IDFA once per month...but that seems pretty trivial to workaround? If an app you used previously starts up and sees that your IDFA changed, it's easy for that app to know that the old IDFA and the new IDFA refer to the same user! This tracking is all possible because iOS gives every app on the device the same IDFA (advertising identifier [1]). They can then correlate all your activity and target you for ads. I'd love if Apple just killed this feature, but barring that, why not change iOS so that it scopes these identifiers at the per-app level. Different apps on the same device see different IDFAs, but an app can still use an IDFA to target you for ads. Apple already has similar per-vendor scoping with identifierForVendor. [2] [1]: https://developer.apple.com/documentation/adsupport/asidentifiermanager/1614151-advertisingidentifier?language=objc https://developer.apple.com/documentation/adsupport/asidenti... [2]: https://developer.apple.com/documentation/uikit/uidevice/1620059-identifierforvendor https://developer.apple.com/documentation/uikit/uidevice/162...
- mojuba 7y agoUnfortunately the majority of more or less useful or popular apps are also linked against various analytics/attribution platforms, often many of them at once. Mixpanel, Amplitude, AppsFlyer, Branch to name a few, plus Facebook and/or Google. In fact having any of the Google's or Facebook's SDKs means tracking, e.g. Maps, Login etc. Somehow these platforms have no problem with identifying users across their client apps even without the IDFA. Maybe it's not 100% precise, but as far as I can tell these companies keep so much information about us away from our eyes, that even the big guys (G, FB) would be jealous. Analytics is one big dark corner of the mobile business whose significance is not fully appreciated (yet).
- api 7y agoMobile is all about surveillance as near as I can see. The whole purpose of it is to track users.
- kevin_thibedeau 7y agoHow else should a telescreen function?
- godelski 7y ago> Phone users can currently disable the IDFA, but have to do so manually; Android users aren’t even given this option This actually false. You can change your Ad ID on Android. I just looked (and checked)If you go to Settings > Privacy > Ads you can see this IDFA. At the top (it looks like a header and not an option, so I will not fully fault Mozilla because this is a dark pattern) it says "Reset advertising ID". If you press it you can see the grey "Your advertising ID" (at the bottom) change. Additionally, there's the option "Opt out of Ads Personalization". It has the text "Instruct apps not to use your advertising ID to build profiles or show you personalized ads." I would love if someone here could clarify this for me. Is this a suggestion to apps or is this a strict and enforceable thing? As in "Hey app, you should ignore this ID that I'm handing to you" vs "Hey app, you don't get to have this ID. Sorry." Does anyone know which it is? The language suggests to me that it is the former. Edit: This was done on a phone running Android 10
- COGlory 7y agoMy Android 8 Pixel 2 XL has no privacy option in the settings. Upgrading would unfortunately come at the cost of losing root and AdAway (for the moment). I wonder which is more beneficial to have.
- godelski 7y agoWell I'm also using a Pixel 2. So the good news is that this exists if you upgrade. I didn't realize root was not available on 10 (this is the first phone I haven't rooted and so I haven't been keeping up)
- freedomben 7y agoRoot isn't available on on a Pixel 2 on Android 10? I also haven't upgraded yet but was going to, though that's a deal breaker for me. That said my light googling hasn't turned up verification of this yet. Root does work just fine on Android 10 on the OnePlus 7 Pro (which is the best phone I've ever owned).
- 7y ago
- cloudyo 7y agoAnd on the topic of privacy and iPhone: what you can do to protect yourself from attacks: https://blog.duple.io/how-i-can-hack-your-phone/ https://blog.duple.io/how-i-can-hack-your-phone/
- syntheticcorp 7y agoThat article has some inaccuracies, particularly around brute forcing iPhones in DFU mode which is nowhere near as practical as they make it sound on newer models with Secure Enclaves.
- exabrial 7y agoIt would be really nice if we could modify our OSes (remove the stupid IDFA completely, or send garbage) This is coming to laptops and other computers soon though, sadly.
- kalleboo 7y agoiOS already has an option to just give out zeroes as the IDFA. Mozilla wants to change the default behavior for all the users who don't realize they can already do this.
- lonelappde 7y agoApple is all about heavy handed locking down the experience for the user's benefit as judged by Apple. Why do they even allow apps that exfiltrate data and serve ads? Just require all ads go through Apple's system, and ban apps that do anything remotely shady.
- dredmorbius 7y agoWhile that's one possible solution, the problem of creating one-stop shopping for any potential adversary (state actor, non-state actor, stalker, insider threat, etc.) might give pause to reconsider.
- epoll 7y agoIs IDFA carried in the http request header? Can government track this too?
- hardwaresofton 7y agoIf only someone had created a viable alternative to both Google and Apple's phones. Maybe they could base it on the browser? Web technologies are getting pretty good these days. One of the popular browsers that are an alternative to safari and google chrome... Like some sort of browser-OS.
- rimliu 7y agoHow do you carry a browser in your pocket?
- hardwaresofton 7y agoI'm not sure I understand this question but it's pretty doable -- https://developer.mozilla.org/en-US/docs/Archive/B2G_OS https://developer.mozilla.org/en-US/docs/Archive/B2G_OS The comment was tongue in cheek -- mozilla had already done everything I suggested (the effort was called FirefoxOS), but they mismanaged and abandoned it. The renewed focus on Firefox the browser (if that had anything to do with it) was good, but some of the other stuff they started pushing like WebVR is/was pretty short-sighted in my opinion. If mozilla wanted to set themselves up as the open alternative to apple/google, keeping a phone in the portfolio is/was pretty important. Maybe the cost was just too unsustainable but from what I can see it was mismanaged more than impossible to make profitable.
- scarface74 7y agoEvery platform that has tried that for the last decade has failed - Palm, Firefox, RIM, and Microsoft have all had development platforms “based on web technologies”.
- hardwaresofton 7y agoThis was a bit tongue-in-cheek -- I was referencing FirefoxOS, and insinuating that mozilla should have stuck to their guns (and maybe changed their batshit market strategy of racing other android vendors to the bottom-most market segment) and kept FirefoxOS in their portfolio. If a phone OS isn't a strategic bet, I don't know what is. All the people spending money on the librem would have happily bought FFOS phones, if they made proper high spec ones (I still have one of the highest spec FFOS phones ever made and it wasn't that impressive).
- greggman2 7y agoThere a bunch more things Apple could do to improve privacy they haven't done (yet?) They could require for example that unless you're specifically making a browser (Firefox, Chrome, Brave) that your in app webview have a whitelist of domains it's allowed to contact. That would force apps to launch Safari (or better the user's choice of browser) for external links. As it is nearly every app that supports external links launches an internal webview in which they can track 100% of the activity (urls, net requests, login credentials, etc...) They could require apps that are not specifically a camera app or audio creation app not get access to the camera or mic and have to ask the OS take pictures/video and select pictures via the OS photos app. That way less apps would be able to record things in secret or upload any/all your photos without permission. They could disallow scanning wifi SSIDs except for network tools. Scanning SSIDs is used to figuring out a user's location with with GPS off. In iOS 13 they did add bluetooth permissions so apps can be denied scanning bluetooth to do the same but AFAIK they have not done the same for SSIDs. Not sure what that would require but would love it if they'd work on it They could disallow using the network at a low-level except for network tools. As it is, AFAIK, any app can use the network however it likes including scanning home networks for devices with vulnerabilities. I'm sure there are implications for things like Chromecast and other IoT like devices but I'm sure there could be more privacy oriented solutions.
- kccqzy 7y ago> As it is nearly every app that supports external links launches an internal webview in which they can track 100% of the activity (urls, net requests, login credentials, etc. My understanding is that UIWebView (or WKWebView) allows the host app to do basically anything with the web view but since iOS 9 there's also SFSafariViewController that doesn't quite allow apps as much access. Many apps whose main purpose is not web browsing (like Twitter) use the latter. > They could require apps that are not specifically a camera app or audio creation app not get access to the camera or mic and have to ask the OS take pictures/video and select pictures via the OS photos app. This API (UIImagePickerController) also already exists since the very beginning but it is the app makers that think using a custom UI for photo taking or photo picking is more suitable. I personally refuse to grant apps access to my photo library except a small number of apps. (For apps like Messenger that could totally make do using the system-provided photo picker but does not, I initiate the sharing from Photos instead.)
- dredmorbius 7y agoFor Google's pitch (to advertisers) for IDFA / AAID (the Android equivalent), see: https://support.google.com/authorizedbuyers/answer/3221407?hl=en https://support.google.com/authorizedbuyers/answer/3221407?h...
- dep_b 7y agoOh yes the fun thing about iOS is that the browser is super private so Google & Co have a problem but the apps themselves are also rife with trackers and there is almost no limit to what they do and barely any way to block it. I mean they only banned screenshots being taken of actual users' screens, which basically means anything that's less worse than that still goes. As a consumer I would love a good scandal that would force them to tighten up on in-app trackers as well. But it might hurt my employers.
- neilsimp1 7y agoI saw a video on Youtube yesterday that dug into this ad campaign a bit: https://www.youtube.com/watch?v=82N5SiOvStI&t=791s https://www.youtube.com/watch?v=82N5SiOvStI&t=791s. I like the guy - he's a bit long-winded at times but I don't think he was incorrect about any of his points.
- zabhi 7y agoA Linux phone is what we need. FirefoxOS was a great initiative from Mozilla, but now it is in the hands of a company I do not trust.
- fghtr 7y agoYes, Librem 5 is our hope. Also, Pinephone.
- spurgu 7y agoYeah, but why can't anyone make sane size mobiles nowadays? There's literally nothing less than 5 inches on the market. I would love something like the SEX here: https://i.imgur.com/OKZiWrN.png https://i.imgur.com/OKZiWrN.png Source: https://news.ycombinator.com/item?id=20936147 https://news.ycombinator.com/item?id=20936147
- fghtr 7y agoAt least in case of Librem 5 there was no choice: the hardware working with free software is rare, which restricts the choice of SoC and the modules.
- rimliu 7y agoA Linux phone is what you want. We (for whatever that is) for sure do not need it.
- windthrown 7y agoUBPorts/Ubuntu Touch is trying!: https://ubports.com/ https://ubports.com/
- DavideNL 7y agoSomewhat related: when i re-install Youtube or Google Home i am automatically logged in to both apps. Even if i delete the apps and wait weeks/months and then reinstall, i'm logged in again when i first open them. I have enabled "Settings > Privacy > Advertising > Limit Ad Tracking" and also cleared all Safari history. How is this possible?
- inapis 7y agoI believe they store some data in your iCloud account. Uber used to do this too. The only way to get rid of it is to sign out and then again explicitly ask to delete account data on this device, then uninstall and reinstall to use the service without signing in.
- DavideNL 7y agoHmmm, there is no "Youtube" or "Google Home" item in "Settings > AppleID > iCloud" (where you can enable/disable iCloud access for specific apps.)
- v3v3 7y agoWhat Google does is store account data that is shared with all Google apps under "Google LLC". Go to "Settings > General > iPhone Storage" and you will find "Google LLC" where it explains the data stored is shared with all Google apps. Microsoft does the same thing to enable you to quickly sign-in to their different apps under the name "Microsoft Corporation".
- neoberg 7y agoThe use IDFV(id for vendor) for this. It's an identifier that is shared between all apps of the same vendor.
- deleted 7y ago[deleted]
- ozmbie 7y agoDo you have any other google apps installed in your phone? Apps from the same developer can share information.
- macrolime 7y agoEven if you opt out, then often opt you in again after iOS updates, so you need to check the setting regularly.
- macrolime 7y agoWhy the downvote? I had enabled limit ad tracking and at least when I updated to iOS 13, limit ad tracking was suddenly turned off.
- Ntrails 7y agoDoes this apply to webpages? As someone who installs barely any apps to what extent is this impactful?
- deleted 7y ago[deleted]
- rchaud 7y agoHow much of this, if any, applies when using the Facebook or IG mobile websites or PWAs? IG's PWA seems to be the same as the mobile website, except that it launches in fullscreen, with no browser address bar. When using those on Chrome, I have not received one of those dialog popups saying "m.facebook.com wants to know your location".