Live data from Hacker News

Apple cracking down on applications that send location data to third-parties

9to5mac.com

81–90 of 129 posts

Re: Apple cracking down on applications that send location data to third-parties

#81
post #80
post #66

Earlier quoted context omitted.

Disconnect was co-founded by an ex-Google DoubleClick (ad) engineer, and hired an ex-NSA (dragnet surveillance) engineer. There are tracker-blocking adblockers for every platform that aren't made by people with anti-privacy backgrounds.

And SELinux was designed by the NSA due to the 10 years or so of the Flask Security Architecture and made it into Linux. Under your tinfoil hat, does this mean that Linux is totally compromised?

there's no viable alternative to selinux, but there is for vpn adblocking apps.

Re: Apple cracking down on applications that send location data to third-parties

#82
post #65

Earlier quoted context omitted.

While the concept is good, I'd be extremely concerned of using any third party VPN service, free or paid. You are basically trusting your entire internet usage to a single entity, and I think this is way too risky. One alternative is setting up a raspberry-pi at home running pi-hole and OpenVPN. While it is still not risk-free, it is still better than one centralized entity taking everyone's traffic. On the other han…

I agree. “Don’t like being tracked? Just let us watch EVERYTHING you do and we promise to stop people from tracking you.” You’re putting someone in the perfect position to track you far better than anyone else could. You better REALLY trust them.

use an open source one:

https://github.com/julian-klode/dns66

https://github.com/M66B/NetGuard

Re: Apple cracking down on applications that send location data to third-parties

#83
post #81
post #80

Earlier quoted context omitted.

And SELinux was designed by the NSA due to the 10 years or so of the Flask Security Architecture and made it into Linux. Under your tinfoil hat, does this mean that Linux is totally compromised?

there's no viable alternative to selinux, but there is for vpn adblocking apps.

There are actually three relatively viable alternatives:

https://en.wikipedia.org/wiki/AppArmor

https://en.wikipedia.org/wiki/Tomoyo_Linux

https://en.wikipedia.org/wiki/Smack_(software)

All three implement MAC (mandatory access control) similar to SELinux, but the context bits in SELinux are pretty much standalone for information assurance (DoD Rainbow book series has more info). Note my username comes from my SELinux experience :)

Re: Apple cracking down on applications that send location data to third-parties

#84
post #60

Earlier quoted context omitted.

That sounds to me like you're saying Apples core beliefs are simply whatever they fancy depending on the time of the day.

Hmm. Let's consider the forces involved here: 1. Apple makes their hardware in China. 2. Apple sells their hardware in China. 3. If Apple doesn't comply with China, 1 could be affected, not just 2. 4. Apple cannot move their hardware manufacturing to US (now), without losing their competitive edge, because everybody makes their hardware in China. Do you think if Apple could be privacy oriented in China, it wouldn't?…

To unpack your #1 statement. Lets say that Apple makes their hardware and then ships it out of China. China makes money, gets some jobs out of it, some tech knowhow etc. China has no reason to stop that.

Now, apple's desire to sell devices in china that comply with chinese laws (which potentially compromise user privacy) is a separate issue altogether. Business wise, I don't think they can afford to avoid china altogether. So maybe they can simply say that "they're doing the best they can" and take the PR hit.

Re: Apple cracking down on applications that send location data to third-parties

#85
post #61

Earlier quoted context omitted.

Explain what with China? Apple are legally required to follow the law of countries they do business in. In China the law requires that the government, not third party apps, gains access to additional information. Apple can limit third party app privacy violations while still following the law. The only stand Apple could take here is: - Stop selling in China - Have executives go to jail Just as if they violated US law…

That is a poor argument. "Selling" a product is not a principle or a virtue that one is required to comply with. Protecting the privacy of users is. Being non-discriminatory is. What if they had to do business in a country that forbids gay people from working? Using your logic - "Oh well they had to fire all their gay employees to just follow the law". Its hypocritical of Apple to suggest they truly care about privac…

> "Selling" a product is not a principle or a virtue that one is required to comply with. Protecting the privacy of users is.

A foreign country has passed laws disagreeing with your value judgement. In any case, Apple is a business. As a consumer, I care first and foremost about my privacy and the privacy of those in my country. That is not impinged upon by China forcing Apple's hand in their own country. Perfect is the enemy of good.

Re: Apple cracking down on applications that send location data to third-parties

#86
post #2

I'm working for years as a developer building iOS applications. Apple got so strict the last months maybe last year it's just incredible. Lots of questions about monetization and background services, they really want you to have a solid business case for background location or just don't use it. As a consumer I'm happy they take those steps though. My privacy is worth money. Either somebody sells it and gives me a "f…

>Either somebody sells it and gives me a "free" OS or somebody sells me an OS and I don't "sell" my privacy.

Don't forget the Windows 10 model: You're forced to buy the OEM version on any new PC, and then you still get your privacy sold by MS.

Re: Apple cracking down on applications that send location data to third-parties

#87
post #83
post #81

Earlier quoted context omitted.

there's no viable alternative to selinux, but there is for vpn adblocking apps.

There are actually three relatively viable alternatives: https://en.wikipedia.org/wiki/AppArmor https://en.wikipedia.org/wiki/Tomoyo_Linux https://en.wikipedia.org/wiki/Smack_(software) All three implement MAC (mandatory access control) similar to SELinux, but the context bits in SELinux are pretty much standalone for information assurance (DoD Rainbow book series has more info). Note my username comes from my SELinu…

sorry, I meant to say that it's trivial to switch to another vpn firewall app, but it's much harder to switch from selinux to apparmor.

Re: Apple cracking down on applications that send location data to third-parties

#89
post #78

Earlier quoted context omitted.

It is also hypocritical for privacy advocates to purchase products from China. Their purchases directly fund a regime opposed to their moral positions, either through taxes and duties or payments to the many thousands of firms (like COSCO) that are controlled wholly or in part by the Chinese government or military. The hypocritical-ness doesn’t go away because corporations are larger than individuals, the transaction…

>It is also hypocritical for privacy advocates to purchase products from China. If you take Apple out of the argument for a second, thats quite a complex case. I think you can have two positions "we don't compromise on privacy" and "were trying to improve the situation the best way we know how". Under #2, you could make the argument that buying a general purpose tool such as a computer made in china, and using it to…

If it’s possible to buy the computer elsewhere and choose not to, it’s hypocritical.

Re: Apple cracking down on applications that send location data to third-parties

#90

Earlier quoted context omitted.

Explain what with China? Apple are legally required to follow the law of countries they do business in. In China the law requires that the government, not third party apps, gains access to additional information. Apple can limit third party app privacy violations while still following the law. The only stand Apple could take here is: - Stop selling in China - Have executives go to jail Just as if they violated US law…

So what you are saying that Apple's core beliefs are location-dependent. Personally, I think it is totally cool to have location-dependent core beliefs. I just think it is a total fan-boism not to acknowledge it.

Providing your users with the maximum freedom, privacy and security possible under the law is a reasonable and ethical position to take, especially if you believe your products provide the best security and privacy on the market and withdrawing them would leave your customers with only worse options available.

If you honestly believed that to be true, how could you justify withdrawing from that market on ethical grounds?

Post reply on HN