3 ms·
A good system would probably have tiered permissions, something like: 1. No internet apps: store data locally on the device only, no upload or download. 2. Pa
by staunch 5y ago
A good system would probably have tiered permissions, something like:
1. No internet apps: store data locally on the device only, no upload or download.
2. Partial internet apps: store data locally, and only download data through an Apple proxy service that hides the user's IP address and any identifying info.
3. Full internet apps: store in the cloud, uploaded/downloaded through an Apple proxy that logs/filters everything. Or even stored in Apple's cloud.
4. Unrestricted internet apps: VPNs and web browsers, and whatever else actually needs arbitrary access to the internet.
There's no reason my bluetooth scale app needs #4 (which it has today) when I would much prefer it have #1.
- jmull 5y agoI don't believe "only download data through an Apple proxy service" does much for user privacy/control of data. A seemingly benign request that appears to simply request information can encode a user's private, sensitive data in the request URL, e.g. I think there's no real distinction between your 2. 3. and 4. There's a place for no internet access at all. It would be good if they had a permission for that.
- staunch 5y agoThe entire request can be logged, displayed to advanced users (so they can report it), inspected by Apple's review teams and automated systems. Any app violating the rules, by uploading user data as GET query parameters (for example) could be detected and banned fairly easily.
- jmull 5y ago> could be detected and banned fairly easily No, it could not. Cryptography can make it as difficult as necessary. (Not even going to touch how unacceptable it would be for Apple to require that it be able to inspect all internet traffic from a person's phone.)
- staunch 5y ago> No, it could not. Cryptography can make it as difficult as necessary. This is just a failure of imagination. The API could be as restrictive as necessary to ensure privacy. For example, maybe an app is only authorized to upload specific fields of data and a maximum rate. How does an app only allowed to upload 10 int32 metrics per day going to secretly upload even a single photo? > Not even going to touch how unacceptable it would be for Apple to require that it be able to inspect all internet traffic from a person's phone. There are lots of options for how to implement things so that Apple isn't getting copies of private photos or chat messages. Apple is certainly more trustworthy and accountable than a random app developer from a random foreign country. Personally, I want a smartphone/app ecosystem that is completely free of any centralization. I'm just talking about how Apple could improve their proprietary/centralized system, which actually does make some of these kinds of things simpler.