21 ms·
FYI, that API requires entitlements to be used, which are only available if you request them from Apple and justify their use. It's not a general-purpose API an
by coldcode 3y ago
FYI, that API requires entitlements to be used, which are only available if you request them from Apple and justify their use. It's not a general-purpose API any app can use.
- lxgr 3y agoThat’s not really any consolation, since (according to the article) Apple has granted that entitlement to WeChat and Alipay. Yes, these are “super-apps” and Wi-Fi hotspot services are probably part of their offerings, but that’s just more reason this should be a user-grantable permission like “local network access”. If I don’t care for the hotspot feature, I don’t want the app to have that capability.
- MBCook 3y agoCertain apps have always gotten special treatment. If it’s big enough to mess with phone sales they’re allowed nonsense a normal dev would be permanently banned for. Ex: all the stuff FB has been caught doing over the years My understanding (no first hand experience) is that WeChat and Alipay are basically required in China. If a phone doesn’t have them, it’s worthless and won’t sell. So naturally they too can do nonsense that would get the rest of us booted to space.
- stavros 3y agoWhy does apple get to decide which app gets automatic access to my private data, on my device, without needing to ask me?
- electric_mayhem 3y agoDoes your employer have a donation matching program? It’s a great time of year to donate to the EFF.
- stavros 3y agoI donate to NOYB, but I second your sentiment.
- BobaFloutist 3y agoIt's so hard to prioritize non-profits these days. EFF is huge and super relevant, but so are aid programs to Ukraine or I/P, and reproductive health orgs. There's a lot going on I want to contribute to.
- bear141 3y agoI wonder if there is a service to automate small (or large) donations to multiple organizations on a regular basis similar to an investment service? Edit: I can only find services marketed towards the nonprofit, not for the donor. A service that aggregated and automated all the nonprofits I want to regularly donate small amounts to would be great. I think it would be important to not require the nonprofits direct involvement in order to allow me to donate as diversely as I want.
- electric_mayhem 3y agoBenevity is a company that basically administers company matching donations. Database of approved nonprofits, can set up arbitrary amounts as recurring payments, and automatic matching if you do the donations through their site. It’s not quite “I got $500 this month to give back, scatter it amongst my chosen charities” but you could definitely use a service like that to set up baseline donations. I don’t do scheduled donations; prefer to spool it up and make a splash when employer offers 2:1 match. Don’t think I’ve seen that in all of ‘23, though, so settling for 1:1 now.
- bear141 3y agoThank you for this. I realize this suggestion fits the context of the thread, but I am currently self employed so I would love another suggestion that isn’t necessarily geared toward integrating with employer match programs.
- coldacid 3y agoBecause you bought a closed-source device by which you surrendered your privacy to whatever the source-controlling company wants.
- ben_w 3y agoQuite a few apps run tests to find out if they're running on a rooted device, and refuse to continue if they are. Dunno if these apps do that or not, but I can easily imagine that using them is a Hobson's Choice even in OSS utopia: take the horse offered (app with tracking) or don't have a horse.
- salawat 3y agoThere is no Hobson's choice in OSS utopia, as the outcome of "app with tracking offered only" is "fork app - tracking". You can sit there and stew over the gall of those people to do it, but if you piss them off enough, it will happen.
- ben_w 3y agoTo the extent you could ever replace WeChat and Alipay with OSS, that's already a possibility today even with closed OSes and App Stores. To the extent that you can't (network effects or legal obligations or whatever) you still won't be able to if the code of those apps is made available under any license of your choice.
- anileated 3y agoFWIW I used WeChat a few years ago and at that point it definitely asked for local network access (which is what this article is about; a mechanism for collecting SSIDs which can then later be correlated to locations). If there is an entitlement, it is as of yet unclear whether it means a consent dialog/privacy toggle or not. IIRC an entitlement only means you can ask for this sort of access, not get it automatically, but I may be wrong (I’ve never gotten far in iOS dev). We can argue that this feature is misnamed, regular users will not understand what it is and would not be giving informed consent, and I can get behind that, but “automatic access to my private data on my device” looks like jumping to conclusions.
- stavros 3y agoHm, I assume any app can ask for whatever it wants, but that's just an assumption. I don't know if app developers need to apply to be able to request permissions, but I don't own an iPhone.
- MBCook 3y agoCertain things require permission from Apple to be able to even use. The API in question here is one of them. Other things are just available to any developer but have to have a user prompt, for example saving to the photo library.
- anileated 3y agoI was remembering when trying out iOS development years back that entitlements were needed for many things and the ones I tried involved a consent screen. From looking at https://developer.apple.com/documentation/bundleresources/entitlements https://developer.apple.com/documentation/bundleresources/en... I would say there are many more entitlements than consent screens, the phrasing suggests there is no 1:1 mapping between them and is not clear on whether they reliably come with consent screens (I suspect not). It is very unfortunate that there is little clarity on that in the docs, and that entitlements are not exposed anywhere in the GUI. Sure, they are too technical, but they could at least be shown in some advanced info pane. I am seriously considering if I can dejail an old iPhone and perhaps inspect some big name apps for what they have been entitled to.
- ben_w 3y agoBecause there's no rule saying they can't. I think. Legal advice about what is and isn't legal under GDPR (and equivalents) varies a lot.
- pixl97 3y agoBecause this is how all operating systems work. If Microsoft wanted to give special apps access to your private data without asking, then that is exactly what would happen. The same thing is true in Linux, other than we'd expect that the open source nature would have users going "Yo, WTF"
- stavros 3y agoThat's like saying "because that's how locks work, the company who sold you the lock can just come open your door".
- pixl97 3y agoThis is exactly correct, though you don't want to admit it's the case it seems. I mean, we just allowed Car Manufactures to pump as much contact data and location data as they can off your phones and sell it to whomever they'd like risk free and legally. We have laws against physical trespassing, but when it comes to 'data' trespassing on applications that you install or come with your phone we're still in the wild west.
- freedomben 3y agoI think you're both right. the misunderstanding here is a difference between is and ought. pixl97 is describing the current state of things, not saying they ought be this way (please correct me if I'm wrong). stavros is describing the way things ought to be.
- stavros 3y agoYes, exactly. It is that way, but it should be illegal to do that.
- panarky 3y ago> and sell it to whomever they'd like Is there any evidence that car manufacturers are harvesting data from drivers' phones and selling it without consent?
- talldatethrow 3y agoProbably because you asked them for permission to use their phone and software.
- dns_snek 3y agoThey clearly purchased the phone, therefore it's not "their" (Apple's)
- talldatethrow 3y agoI honestly don't see it like that anymore. You paid in to buy the object but you're still asking for permission to use their overall ecosystem. I think it's more like a child buying a teams jersey so that he can play on the team, but he can still get kicked off the team if he doesnt follow the rules. You can't argue "but I paid for the uniform with your logo, you must let me play 1st base!" Sure the child still owns the uniform, and maybe he can get some use out of it or sell it off for spares (parts) to other people, but him paying doesn't make him own the team.
- dns_snek 3y agoI think we agree.
- freedomben 3y agoI've asked similar questions before and am usually told that this is how Apple does things and it's what makes their users happy. It's in fact why they love and choose Apple. They trust Apple to make the right decisions, and this is in fact a big part of the value add of their products. This is much related to the walled garden approach. For example, ask about why sideloading should remain not an option at all, rather than something like Android where you can enable it if you want to but "Grandma" isn't going to accidentally do it. Apple users actively don't want that capability. It doesn't make sense to me, but that's because "I'm not their target market."
- saiya-jin 3y agoI have to agree with this sentiment, I read it here on HN 'power' users more than once. Although most Apple users have no clue about what we discuss here, the part about actively wanting it is simply not true en masse. Needless to say that's not for me and I will probably keep sporting Androids (in my case I am happy with Samsung's top ultra offerings) since I actually use those added features, ie saving 500 bucks on proper expensive variometer for paragliding and instead hooking it up via OTG cable with basic one with good sensor but without display, for 10% of the price... needless to say relevant app isn't on play store neither. And so on. But we certainly have choice on the market. I just wish Apple would properly focus on user security and shielding them from the worst of internet, and less on milking advertising, what I see so far didn't convince me it isn't just sophisticated marketing and not much more. You already pay premium on the device, its a proper spit in the face to be so visibly milked more and more, thats pure corporate greed. What I mean - my wife with iphone pops up browser, I pop up mine with firefox and ublock origin. Internet is utterly useless and horrible place on her phone, while completely fine on mine (plus I get youtube ads blocking as a bonus)
- neilparikh 3y ago> my wife with iphone pops up browser, I pop up mine with firefox and ublock origin. Internet is utterly useless and horrible place on her phone, while completely fine on mine (plus I get youtube ads blocking as a bonus) I recently set up NextDNS on my iPhone and browsing the web has become much more usable (previously, I would get webpage crashes!). Something to look into in addition to or instead of Wipr.
- madeofpalk 3y agoYou buy Apple hardware, which is a pretty strong signal that you trust Apple.
- 0cf8612b2e1e 3y agoTwo party marketplace. I don’t trust Apple, but the competition is not any better.
- bear141 3y agoThere are alternatives. Privacy based software and hardware. But the inconveniences that come with it are not insignificant. I plan on moving in that direction at some point, but for now I’m not ready.
- rpigab 3y agoIf every big app had to interrupt users to ask for simple things like performing http calls, usability would take a little hit, the nice "UX flow" of apple is a major selling point, so a very small percentage would buy Android phones.
- lxgr 3y agoDetermining my house or even room level location is not at all equivalent to making an HTTP call. And Apple does generally prompt for location permissions, as does Google on Android.
- wredue 3y agoThe market decides by not buying devices that empower apps to spy on them.
- tempodox 3y agoWith Apple there's no such thing as “my device”.
- tick_tock_tick 3y agoBecause Apple fundamentally doesn't believe you own the device so the question makes no sense to them. They already own it why would they need to ask you?
- lxgr 3y agoNo app gets special treatment for any of the user-grantable permissions like location, Bluetooth, local network access, contacts, photos... What makes this any different? It really seems more like an oversight than a conscious decision, similarly to how (I believe) both iOS and Android have retroactively had to bucket some of the Bluetooth LE permissions into "location", since that's what you can effectively do with them.
- MBCook 3y agoIt could be. But the fact it’s behind a special permission you have to request from Apple tells me they likely think it’s secure enough.
- politician 3y agoWhat’s your basis for saying that Apple doesn’t provide special treatment to apps? I’ve directly experienced both of their special and their non public (phone calls only, refusal to communicate over email) processes.
- lxgr 3y agoI’m not claiming that at all in general, but I do believe it’s true when it comes to user-grantable permissions. Or do you have evidence to the contrary?
- facialwipe 3y agoGiving the world’s most valuable corporation the benefit of the doubt. This is an interesting worldview to have in 2023.
- lxgr 3y agoIt’s a pretty obscure API, and Apple has a strong interest in at least being perceived as pro user privacy. And assuming for a second this is indeed an intentional backdoor in plain sight of the world: What’s in it for Apple? Hanlon’s razor still cuts in 2023, at least for me.
- onlyrealcuzzo 3y agoInteresting that cutting monetary deals was a problem for Google, but special access APIs are fine.
- wodenokoto 3y agoThat doesn’t excuse anything! This is not “oh poor small time devs”, this is paying customers being lied to by Apple.
- kiririn 3y agoSee also McDonald’s being allowed to gate app functionality behind background location access
- lxgr 3y agoThat’s adjudication of “soft” rules around permission optionality, which is a big problem, but nothing that lets apps bypass permissions outright.
- bdd8f1df777b 3y agoThey are required in China, but the hotspot functionality isn’t. At least give me an option to turn it off.
- breakfastduck 3y agoChinese state supported spyware spies on you? I'm shocked!
- nottorp 3y ago> Adding another layer to the discussion is the fact that major apps like WeChat and Alipay have already implemented this capability. So only the big apps can spy on you? The poster is Chinese so he cares about those 2, but how about facebook and google?
- squarefoot 3y agoSpyware can be hidden in every piece of closed software, hardware, firmware with access to communications, so unless someone makes a 100% open device, from the first bit to the last screw, there's no 100% guarantee to be free from spyware.
- JKCalhoun 3y agoMost entitlements though trigger a privacy prompt to allow the user to disable the functionality. Without writing a test app, I don't know that this is the case with this entitlement. I think it should ask the user's permission.
- deleted 3y ago[deleted]
- salawat 3y agoKeep in mind that in a corporate context, not asking the user for permission or explaining what/why you are doing something is the (sociopathic imo, but nevertheless) norm. To the degree you do disclose something like that it is inevitably hidden away or obfuscated by being put somewhere in the UX that no one ever really goes. Like seriously. I had the argument before; Architect: we're going to fingerprint users. Me: are you going to disclose that? Architect: Of course not. Me: It's their device. You should ask. Architect: That defeats the point. Me: You either don't understand property rights, or clearly have issues with the concept of consent. The entire IT space has been decades of building while eliding the fact these experiences are fundamentally being driven on someone else's hardware. But that's just the world we live in I suppose.
- dcdc123 3y agoHow does that apply to thise case though? Asking for permissions on iOS is the norm and many apps include a message indicating what and why they are about to request something non-obvious before sending the request and triggering the popup.
- filleokus 3y agoBut if Facebook/Instagram/Messenger (or Alipay / WeChat as mentioned in the article) has this entitlement and does fishy stuff, I guess this can actually be a large privacy issue? Does Apple do any analysis of entitlement usage and withdraw them when abused? A similar thing I remember is the Facebook VPN "scandal" where I think Apple withdrew the Facebook enterprise signing certificate?
- qwytw 3y agoWhat do entitlements have to do with not asking for user permission though? Seems like separate issues.
- dataflow 3y ago[flagged]
- paxys 3y agoIs that better or worse? "Don't worry you or I cannot exploit this, only large corporations and data aggregators can."
- deleted 3y ago[deleted]
- j45 3y agoThat’s almost worse that it’s kind of a side door to the users rights. That’s generally only available to groups with the resources or know how to get it. I understand it’s not ubiquitous.
- lloeki 3y ago> that API requires entitlements to be used Lately I've witnessed a number of apps asking for Local Network permission ("Foo would like to find and connect to devices on your local network") when they have no business doing so in any possible way that I can think of.
- sroussey 3y agoMany do this if they play video, mostly to enable chrome cast.
- dwaite 3y agoChrome Cast. There is no OS-level service for it to introspect the network looking for screens to cast to, so each app has to drop in a SDK - which then has to have permission to search the local network looking for screens. This was improved in recent iOS, but I never count on Google updating their SDKs to take advantage of iOS features on any sort of schedule. Even when they do, it will require third party apps to individually update as well.
- gustavus 3y ago> FYI, that API requires entitlements to be used, which are only available if you request them from Apple and justify their use. It's not a general-purpose API any app can use. Well as long as it is just Apple that is deciding who can track me without my permission then that's okay I totally trust my corporate overlords for the wise and great Apple is incorruptible and without fault.
- thomastjeffery 3y agoDid Apple audit their code, then? Why in the world should anyone trust Apple to be responsible?