6 ms·
Apple's blog post about their plans: "We are committed to ensuring users can choose whether or not they allow an app to track them. To give developers time to
by firloop 6y ago
Apple's blog post about their plans:
"We are committed to ensuring users can choose whether or not they allow an app to track them. To give developers time to make necessary changes, apps will be required to obtain permission to track users starting early next year. More information, including an update to the App Store Review Guidelines, will follow this fall."
https://developer.apple.com/news/?id=hx9s63c5 https://developer.apple.com/news/?id=hx9s63c5
- dudus 6y agoThis reads as just another popup you'll need to click before you can use any app. Just like cookies.
- gowld 6y agoConsent is sexy.
- iainmerrick 6y agoExcept there will be an option to deny tracking. Hopefully Apple will require and enforce a genuine free choice and opt-in. With GDPR cookie warnings, you’re required to opt in, but everybody uses dark UI patterns to make you “opt in” (like forcing you to uncheck each tracker individually, and claiming it takes several minutes to “update your preferences”)
- Nextgrid 6y agoThe problem with the GDPR is the lack of enforcement which allows criminal companies to get away with bullshit like this. With the potential of huge fines (and the fact that the cases seem very straightforward and there's plenty of strong evidence of a breach) I think the only explanation for this blatant lack of enforcement is that the same people who are supposed to enforce the law are in bed with those that break this same law.
- kjakm 6y agoThis will be more similar to giving location or push permissions that a cookie warning. You have to actively opt-in to allowing an app access to your IDFA on an app-by-app basis. They can ask you to do this one time and if you say no the only way that setting will ever change is if you go to the iOS settings app and enable tracking for that app. Currently you can opt out on a system level. The change will make it opt in on an app level.
- ogre_codes 6y agoPresumably you would only see it once after installing the app versus every time you visit a website with a cookie policy.
- asutekku 6y agoThe pop-up is literally “allow tracking” and “disallow tracking” and disallowing does not give the advertisers any kind of information about cross-app usage. It is not something you can as a developer circumvent.
- MayeulC 6y agoThere are hundreds of ways to fingerprint you and your device, without an avertising ID. You just need a few (5-7?) To uniquely identify someone. A few examples that come to my mind: Current battery level, typing speed, phone model, OS version, battery wear (guessable from charge/discharge rate), charge rate (depends on the charger), finger width, propensy to use features differently (scrolling, zooming, selecting text), clipboard contents, RTC lag, microbenchmark performance... System preferences alone is probably enough (brightness level, airplane mode, dark mode). If a fingerprinting library is present in more than one app, I find it unlikely that both fingerprints couldn't be linked to the same user. If one of these apps has a log-in, they can probably link that up with the rest of browsing history, on-device and cross-device. Sounds far-fetched? I don't think so. I rather think I'm underestimating the issue. I think one technical answer to that would be to "taint" every measurement of a potential identifier, and track its usage across the program. If the app tries to submit information that is somewhat related, block it. Alternatively, compute a score and block it above a certain threshold (that will be gamed, but could help a transition). Or use a RR-like mechanism to change the measurement to a dummy value, and replay up to the exfiltration point.
- K0nserv 6y agoWhat you've said is accurate, but one thing that's different in this case compared to the web is Apple's walled garden. The walled garden certainly has problems but in this case a real benefit is that Apple forbids these kinds of technical workarounds. You can implement them, but do you want to run the risk of your app being banned from the only distribution channel on iOS because of it?
- Nextgrid 6y agoThat walled garden still appears to have major holes in its fences, as shown by the Facebook SDK having infected every single mainstream app for the sole purpose of stalking the user in the background (over time Facebook can correlate the traffic by date/time, IP address, device type, etc and link different instances of the SDK together).
- K0nserv 6y agoYou can turn off being asked in settings in which case it will just look like you asked not to be tracked to every app.