3 ms·
The problem is that Apple has absolutely no way to enforce the deletion. An app can say "your account is deleted" but not actually delete any data off their ser
by staunch 5y ago
The problem is that Apple has absolutely no way to enforce the deletion. An app can say "your account is deleted" but not actually delete any data off their servers.
What would really give users the control they deserve is the ability to restrict what data can be sent off the device by an app in the first place.
Apple should make it possible to deny internet access to an app entirely, and they should provide an API that allows apps to upload very specific kinds of data that a user has approved of, but nothing else. Of course, some apps need to be able to request unrestricted internet access.
Permitting apps to collect private data and have unrestricted internet access, by default, was always a terrible decision in terms of user privacy. Apple owes it to their users to fix the problem they created.
- Karunamon 5y agoThe test for that problem will be seeing what happens when one of these apps get breached. Unless Apple is willing to terminate developer accounts when it comes out that app makers are not actually deleting anything, this is completely toothless.
- jmull 5y ago> Permitting apps to collect private data and have unrestricted internet access What apps are left if this is forbidden? "private data" can mean pretty much any user input. "unrestricted internet access" means pretty much any internet access. We're left with apps that either cannot accept user input or cannot access the internet at all.
- staunch 5y agoA good system would probably have tiered permissions, something like: 1. No internet apps: store data locally on the device only, no upload or download. 2. Partial internet apps: store data locally, and only download data through an Apple proxy service that hides the user's IP address and any identifying info. 3. Full internet apps: store in the cloud, uploaded/downloaded through an Apple proxy that logs/filters everything. Or even stored in Apple's cloud. 4. Unrestricted internet apps: VPNs and web browsers, and whatever else actually needs arbitrary access to the internet. There's no reason my bluetooth scale app needs #4 (which it has today) when I would much prefer it have #1.
- jmull 5y agoI don't believe "only download data through an Apple proxy service" does much for user privacy/control of data. A seemingly benign request that appears to simply request information can encode a user's private, sensitive data in the request URL, e.g. I think there's no real distinction between your 2. 3. and 4. There's a place for no internet access at all. It would be good if they had a permission for that.
- staunch 5y agoThe entire request can be logged, displayed to advanced users (so they can report it), inspected by Apple's review teams and automated systems. Any app violating the rules, by uploading user data as GET query parameters (for example) could be detected and banned fairly easily.
- jmull 5y ago> could be detected and banned fairly easily No, it could not. Cryptography can make it as difficult as necessary. (Not even going to touch how unacceptable it would be for Apple to require that it be able to inspect all internet traffic from a person's phone.)
- staunch 5y ago> No, it could not. Cryptography can make it as difficult as necessary. This is just a failure of imagination. The API could be as restrictive as necessary to ensure privacy. For example, maybe an app is only authorized to upload specific fields of data and a maximum rate. How does an app only allowed to upload 10 int32 metrics per day going to secretly upload even a single photo? > Not even going to touch how unacceptable it would be for Apple to require that it be able to inspect all internet traffic from a person's phone. There are lots of options for how to implement things so that Apple isn't getting copies of private photos or chat messages. Apple is certainly more trustworthy and accountable than a random app developer from a random foreign country. Personally, I want a smartphone/app ecosystem that is completely free of any centralization. I'm just talking about how Apple could improve their proprietary/centralized system, which actually does make some of these kinds of things simpler.
- joebob42 5y agoIf you want to delete your account, and your primary goal is to prevent future data going to the owner of the app from your device, why not just delete the app?
- staunch 5y agoMy goal would be to keep my data on my device and in my control. It's crazy that giving an app access to your Photos or Health data means it can just start randomly uploading to anywhere on the internet without asking you. People in the future will be amazed we lived like this...
- otterley 5y agoDo you really think it's a good idea to lie to Apple and to the public about your data deletion policies? Do you really think bad actors won't be found out eventually? Is it worth the risk to your business?
- twobitshifter 5y agoI think there is a point there. “Soft” deletions are relatively common in relational databases. Do we know that Apple means a “hard” deletion of data? Apple says to include your retention and deletion policies in the App description, so maybe that’s where people would need to come clean on soft deletions?