5 ms·
Apple App Store only. Developer has a statement about privacy concerns on Android: https://www.iceblock.app/android https://www.iceblock.app/android (Concerne
by ldoughty 1y ago
Apple App Store only. Developer has a statement about privacy concerns on Android:
https://www.iceblock.app/android https://www.iceblock.app/android
(Concerned that the information they would be required to store and handle may require they work with the government during a subpoena)
Apple also has to handle this (internally) to do push notifications, but I suppose that theory is Apple has pockets to fight the government (or it's at least out of the developers hands)
- i80and 1y agoGrapheneOS has a retort: https://bsky.app/profile/grapheneos.org/post/3lswujex4e22w https://bsky.app/profile/grapheneos.org/post/3lswujex4e22w
- ldoughty 1y agoYeah, that's basically what I deduced. They throw Android under the bus but _really_ it's not any more private, it just makes it up to Apple to comply, not the developer. There is an argument to be made that Apple is better positioned to fight financially... However, the current administration tends to threaten blocking or mergers/acquisitions, or other red tape unless they comply. I doubt Apple would accept such financially damaging threats to protect ICEBlock's users.
- fn-mote 1y agoApple has resisted pressure from law enforcement in the past. That gives me a real reason to believe that they will not fold in the future.
- kstrauser 1y agoAgreed, and they certainly have better lawyers than an indie dev could afford.
- realusername 1y agoThey also threw their Chinese users under the bus and complied with the russian government as part of their war censorship.
- redeeman 1y agotranslation: they followed local law where they operate
- realusername 1y agoYou can frame it like that if you want yes but they certainly aren't "resisting pressure from law enforcement". As a side note, they do fight sometimes, they fought the EU's DMA for example, but in Russia and China, they complied without a fight though to my knowledge.
- bigyabai 1y agoJust like Apple followed federal law installing the American backdoor for Push Notifications. See? No laws broken, perfectly safe.
- redeeman 1y agoblame the governments? the people of the US is responsible for what their government does. The people of China is responsible for their government.
- bigyabai 1y agoWhich pressure from law enforcement? Ron Wyden blew the whistle on Apple's warrantless Push Notification backdoor, which Apple did admit to implementing for the federal government: https://arstechnica.com/tech-policy/2023/12/apple-admits-to-secretly-giving-governments-push-notification-data/ https://arstechnica.com/tech-policy/2023/12/apple-admits-to-... Apple has since confirmed in a statement provided to Ars that the US federal government "prohibited" the company "from sharing any information," but now that Wyden has outed the feds, Apple has updated its transparency reporting and will "detail these kinds of requests" in a separate section on push notifications in its next report. As other commenters have noted, Apple's treatment of Russian and Chinese users should not give you hope for their resisting US federal oversight.
- jeroenhd 1y agoApple fought back against forced decryption orders. They could theoretically decrypt any iPhone they're given with new firmware but they don't want to. On the other hand, Google isn't exactly working with the authorities either. They moved Google Maps' location history to on-device storage because of the many warrants they were served, for instance, and they too refuse to decrypt phones. These companies know to pick their battles, but they did take on the government various times.
- 15155 1y ago> They could theoretically decrypt any iPhone they're given with new firmware but they don't want to. This is untrue at some technical level: Apple is currently unable to break AES-256. The San Bernadino case was about having Apple create and sign new firmware that would enable a brute force attack - which could easily be unsuccessful. I don't believe the Secure Enclave found in newer models even allows for a brute force attack (enforcing some delay, among other things) from BFU state.
- DownGoat 1y agoIt's a different risk calculation with the current government. Deny blocking this, and suddenly there are new tariffs designed to especially hurt Apple, or other punishments for not complying.
- A4ET8a8uTh0_v2 1y agoIf there is any silver lining in any of this, it may be that people will finally start taking privacy as not completely irrelevant trade-off to convenience. I am not really holding my breath, but if people do not have that level of self-preservation in relatively clear instances, it probably does not matter anyway.
- BlueTemplar 1y agoThe issue is much older than the current US administration : Apple has been listed as participating to PRISM since 2012, and considering the whole opacity of the Patriot Act (and its derivatives), the secret courts in particular, it makes whatever they (or any other US company) might say about their commitment to privacy (when the opponent is the US government) rather irrelevant. (Personally, I am suspecting that they do try much more than some other companies, but again, the opacity makes it impossible to verify.)
- johnklos 1y ago[flagged]
- miloignis 1y agoBut Google doesn't have to be involved! GrapheneOS is specifically a de-googled Android. Even for normal Google-y Android, you could provide the APK to side-load, so it doesn't go through the Play Store or Google's FCM at all, an option you don't have with Apple. I think this is what the Graphene posts are trying to say. As others mention, having a web app would make a lot of sense.
- jeroenhd 1y agoApple tracks user location too. If you log into your iCloud from a country you've never been to, you're going to have to need to provide your 2FA code even with a valid session token. They're not stupid. Apple is very much in favour of user privacy, as long as that privacy means "protecting your data from third parties". When it comes to the data Apple itself collects, they're far less conservative. They don't share information derived from their massive databases per se, but they do keep track. Thanks to Apple and Find My, stalking people is easier than ever. The company can look up where you are and where you've been. They'd probably fight a court order to provide live location data to ICE, but who knows what that'll mean with the current American government. Even on iOS, user data ends up in the hands of data brokers through ads. They're not supposed to collect all that data, but that's not stopping an unethical company from trying. Android's privacy issues are there, but only if you're protecting your privacy against companies. If you're trying to protect your privacy against the government, there's no difference, really.
- chaoskitty 1y agoThis is orthogonal to the discussion.
- ohdeargodno 1y agoICEBlock is actively lying, is not open source and is confidently misleading many. While I don't want to assume regular fed honeypot, we can at the very least be certain that it's an app made by an Apple Kool-Aid drinking person. iOS is, in many ways, more susceptible to governement subpoenas than an Android app would ever be. Sideloading, UnifiedPush, maintaining a connection to a server to handle notifications yourself are all more secure than just trusting that Apple will not just hand you over to the cops. In addition, if the author is worried about a subpoena, it means that they're US based. Which is an absurdly stupid thing to do if you're going to make a fascist-reporting app while living in a fascist country.
- ck2 1y agoEveryone can bypass Play store from side-load from a web download without root and they can make their own push system so that claim doesn't hold water?
- A4ET8a8uTh0_v2 1y agoThat.. is only technically true. For a huge population of Apple users, messing around with non-standard solutions is not exactly popular.
- jeroenhd 1y agoMaking your own push system on Android is rather unreliable. On phones from several brands (Samsung, for one) the system would constantly try to kill any long-running polling operation or background refresh daemon. I don't really see their point about device IDs, though. There are ways around that, from cryptography to on-device filtering. It's also not like Apple isn't storing device IDs to send these push messages. There's no difference to user privacy. All of that said, by leaving it up to Apple to keep track of device IDs, they're not going to be on the hook for warrants. The government can get that data from Apple instead, but they can claim innocence. It's CYA.
- OutOfHere 1y agoIt is a false statement since apps can trivially be side-loaded on Android.
- snickerdoodle12 1y agoYeah, it's absolute nonsense. Apple could be subpoenaed for the data, and we all know that Tim Apple is happy to jump when Trump says jump. Meanwhile on Android they could easily just distribute the app from their own website and if they really insist on push messages there are plenty of non-google options that are actually private.
- beefnugs 1y agoYeah people dont know what they dont know, but just the fact people are risking their freedom to do something is important. Someone explain to him that whatever he is doing, he needs to end to end encrypt so none of the infrastructure or middlemen can see anything but ips and who installed it (until they control the end device). (Better yet use veilid if it works yet, or i think there is some kind of tor routing over http these days) Also he is making a weird mistake by not being a website instead of obvious corporate controlled "app", also should have tried harder to keep anonymous
- UmGuys 1y agoOh shit. Graphene says it's a honeypot. Slick marketing.
- flotzam 1y agoThey're explicitly not saying that in a reply: https://bsky.app/profile/grapheneos.org/post/3lsyep3s4ac2x https://bsky.app/profile/grapheneos.org/post/3lsyep3s4ac2x
- seanalltogether 1y agoThis clearly demonstrates that the developer doesn't know what they're talking about. If anything, android is more secure because you can A. Sideload an app so that google play store doesn't know you've installed it. B: Run periodic background tasks to poll any https endpoint so no service provider has logs of device ids for push notifications. C: Create local notifications on the device. In this case the only logs that any company could be asked to produce is server logs which only show ip addresses.
- dzhiurgis 1y agoWhy does this need to be an app?
- IAmGraydon 1y agoI think this is a very good question to ask, along with why the Trump admin is threatening the developer rather than Apple. Forcing Apple to take it down is the only way to get rid of it now that it’s been published. Combine that with the fact that most people had never heard of this app before Trump made it go viral. I think we’ve all had enough conspiracy theories to last a lifetime, but it would be wise to exercise caution here. https://grapheneos.social/@GrapheneOS/114783982297156136 https://grapheneos.social/@GrapheneOS/114783982297156136
- skeledrew 1y agoInteresting. I was wondering about that. There are definitely solutions out there that'd make this feasible on Android from a privacy perspective, but may need a bit more work. Perhaps like ntfy. Also, as an offside, this is one of the things I hate about Google's handling of AOSP: they keep shuttling things into their proprietary layer, making it next to impossible for alternative approaches to gain traction.
- dirkc 1y agoI don't want to advocate for the Google Play store, but doesn't seem like legitimate technical / privacy reasons. I know it's possible to do push notifications without user accounts - I'm doing that in an app I maintain. But it is tedious to publish Android apps with a personal developer account - you need to run a 2 week test with 12 (used to be 20) users before you can release the app. What prevents law enforcement for ordering the developer to alter the application in a way that reveals user info, maybe the order is simply that they have to hand over their signing certificates for the app?