3 ms·
Here is the CAID spec: https://web.archive.org/web/20210316035745/docs.trackingio.com/CAID%E6%8E%A5%E5%85%A5%E8%AF%B4%E6%98%8E.html https://web.archive.org/web
by DLay 6y ago
Here is the CAID spec:
https://web.archive.org/web/20210316035745/docs.trackingio.com/CAID%E6%8E%A5%E5%85%A5%E8%AF%B4%E6%98%8E.html https://web.archive.org/web/20210316035745/docs.trackingio.c...
- anon9001 6y agoThat's very helpful and adds a lot of clarity. You can tell from the code that the "exploit" here is abusing keychain sharing. iOS has a feature where you can pack a surprising amount of generic data into keychain storage, intended for passwords or auth credentials. iOS also lets app developers opt-in to shared credential storage, so that if you have multiple apps, the user only needs to login once. Here's a blog post on how to do it: https://evgenii.com/blog/sharing-keychain-in-ios/ https://evgenii.com/blog/sharing-keychain-in-ios/ A little-known quirk of the iOS keychain is that it persists across app installs. This is useful because if multiple apps share credentials in the keychain, you don't want uninstalling one app to log you out of other apps. If an American company tried this (looking at you Branch.io), would it be banned by Apple? Maybe? That seems to be the controversy here. Perhaps Apple needs to rethink its keychain sharing API and make the user opt-in to credential sharing. Also a keychain management tool would be nice, so users can see what data apps are permanently storing on their devices (even if the app is uninstalled).
- tinus_hn 6y agoCredential sharing only works between apps registered to the same developer. So no, this does not allow an tracking ID usable by all apps. And remember, any trick abused to create tracking IDs stands the risk of being detected and blocked by Apple in the next iOS update. It has been announced, it has happened, it will keep happening.
- anon9001 6y ago> Credential sharing only works between apps registered to the same developer. That's right, but it does allow persisting an id through reinstalls of the same app, and sharing that id between apps of the same developer. > So no, this does not allow an tracking ID usable by all apps. It effectively does though. For example, imagine a mobile game company with 10 games. With this technique, you can track that user across app re-installs in each of those games. Now imagine another game company doing the same trick. If both companies send up their independent tracking IDs to a central server along with any other info they can get about the user (email, screen name, IP, whatever), then you can strongly correlate users across multiple tracking IDs. The user has no way to reset these IDs even if they delete and reinstall the apps using them.
- lilyball 6y agoApple tried removing the keychain persisting in an iOS beta a while back and there was a big outcry from developers as it broke their ability to detect and ban users across app reinstalls. Apple reverted that and responded by adding a new feature where developers could permanently track 2 boolean values for a device (per app) but I don’t know who has bothered to switch to that mechanism.