Live data from Hacker News

Apple cracking down on applications that send location data to third-parties

9to5mac.com

111–120 of 129 posts

Re: Apple cracking down on applications that send location data to third-parties

#111
post #96

Earlier quoted context omitted.

If people simply admitted that Apple (like many others) will compromise on their privacy principles in exchange for commercial gain - we would never have been having a conversation on this topic. People want to hold Apple to a higher standard.. maybe thats also part of the problem.

Is it really that simple? Put yourself in the execs' shoes for a few minutes. You can obey the laws of China and do business in China... or you can take a stand on principle and leave the market, giving up not only the revenue, but the small amount of positive influence you might have on their society as a whole. How is that necessarily any better for humanity than simply obeying the local laws, going along to get al…

There is another option. Just abandon any principle of data privacy and continue to sell their products (although GDPR in EU is an issue).

Re: Apple cracking down on applications that send location data to third-parties

#112
post #5

Earlier quoted context omitted.

Apple always took location privacy seriously. I remember an interview between Steve Jobs and Walt Mossberg years ago on this subject. I looked it up again: https://www.youtube.com/watch?v=39iKLwlUqBo

Serious in the sense that they seriously wanted it? July 2010 was when they rolled out their silent tracking of all ios 4 users in an unencrypted database on the device for up to 10 months. In a happy coincidence, a bug ensured that the (presumably untested) feature of turning of location serviced didn't actually prevent the tracking. And of course they never asked users for consent about this, except by putting some…

This was the dumbest privacy scandal ever. The database was on your phone. It wasn't sent anywhere. What good does that do Apple? What do they have to gain? It's obvious it was just a bug.

Re: Apple cracking down on applications that send location data to third-parties

#113

Does this include apps like Foursquare/Swarm that sell aggregated location data to hedge funds? [1] ...or are the big players exempt from the rules of the game? [1] https://www.entrepreneur.com/article/290543

While Swarm has an auto-check in feature where it tracks your location, location services isn't really required to use the app.

Since the user is actively telling Foursquare/Swarm where they are, I don't think Apple would mind.

Re: Apple cracking down on applications that send location data to third-parties

#114
post #80
post #66

Earlier quoted context omitted.

Disconnect was co-founded by an ex-Google DoubleClick (ad) engineer, and hired an ex-NSA (dragnet surveillance) engineer. There are tracker-blocking adblockers for every platform that aren't made by people with anti-privacy backgrounds.

And SELinux was designed by the NSA due to the 10 years or so of the Flask Security Architecture and made it into Linux. Under your tinfoil hat, does this mean that Linux is totally compromised?

I didn’t mean to imply that Disconnect is compromised. But I think the background of the team would prompt a fully open source product on every platform in order to establish trust. Until that happens, why not use a blocker whose team does not have an anti-privacy background? (The Disconnect website has said “Code available soon” for the apps since at least March 2015 [1])

[1] https://web.archive.org/web/20150315021851/https://disconnec...

Re: Apple cracking down on applications that send location data to third-parties

#115

Earlier quoted context omitted.

Explain China then. Apple is being hypocritical in this case. Giving in to the demands of government when it hurts their business ( if it did take privacy as seriously as HN makes it out to be, they would take a stand in China) while advocating privacy in Western world.

Explain what with China? Apple are legally required to follow the law of countries they do business in. In China the law requires that the government, not third party apps, gains access to additional information. Apple can limit third party app privacy violations while still following the law. The only stand Apple could take here is: - Stop selling in China - Have executives go to jail Just as if they violated US law…

If they were serious they would stop selling in China.

Re: Apple cracking down on applications that send location data to third-parties

#116
post #102

Earlier quoted context omitted.

Is it really that simple? Put yourself in the execs' shoes for a few minutes. You can obey the laws of China and do business in China... or you can take a stand on principle and leave the market, giving up not only the revenue, but the small amount of positive influence you might have on their society as a whole. How is that necessarily any better for humanity than simply obeying the local laws, going along to get al…

Well, I'm saying that we should probably ignore Apple when they say[1] stuff like "At Apple, we believe privacy is a fundamental human right." My cynical reading would be "At Apple, we're going to compromise on what we believe to be a fundamental human right, to make a few bucks, and if in the process we happen to have a positive impact on some dictatorial regimes, that would be cool too". >Overt disobedience to the…

Are we still talking about Apple in China? I don't know which customer was killed, or which employee was declared a criminal..

No, I switched contexts to the satellite Internet service developer I mentioned. They are on track to deploy a significant LEO constellation over the next few years. If they succeed, they will effectively be the Internet for a large chunk of the world. So if they don't make arrangements to accommodate various countries' censorship regulations, then citizens of places like China, Iran or North Korea who are caught with their receivers will be in a great deal of trouble, and the company's executives will not be able to travel to those regions without fearing arrest.

Re: Apple cracking down on applications that send location data to third-parties

#117
post #37

Hey, are there any other developers experiencing this besides the one in the article? We noticed a few weeks ago that Apple has changed their static analysis tool and has been more aggressive with rejections. Has anyone else actually seen their app retroactively pulled from the App Store?

I haven't had the exact issue discussed in the article, but I have noticed that they have been really aggressive with rejections lately. Just this last week an app I'm trying to get into the store has been rejected 4 times, with the same exact automated message. I respond with an assertion of my apps compliance, but get the same automated response. These are the first rejections I've received in 7 years of submitting…

Do you have an idea what rules you could be violating? Even with a good history, there's no guarantee an update is still good so they have to stay vigilant. Chrome store is a good example of this where popular extensions are sometimes bought and an update is pushed out with malware or spyware.

Re: Apple cracking down on applications that send location data to third-parties

#118

I'm curious as to how this behaviour is actually detected. I mean are they checking for outgoing network requests that contain something that looks like co-ordinates because presumably that would be trivial to obfuscate. Or is this really just a case of rejecting apps that are asking for location even though the app has no real use for it?

Apps are required to have an entry in the Info plist for location (both “while in use” and “always”). This is enforced by the kernel. So they are most likely looking there.

Re: Apple cracking down on applications that send location data to third-parties

#120
post #57
post #44

Earlier quoted context omitted.

GDPR doesn't regulate anonymous data. Unless you put PII in your analytics (not the default, and you really shouldn't) you won't have a problem. As a matter of fact, I'm pretty sure part of Google Analytics response to GDPR is "Don't put PII in there if you want to be GDPR compliant" (they are providing tools for compliance though).

The problem is anonymous data is an ambiguous term, as enough randomness in the “anonymous” data can still uniquely identify that individual. Let’s take YouTube for example - I never had an account with them, yet they recommend me videos based on what I watched previously - fair enough. The creepy part is, on a totally different machine, from a different IP and country, watching just a few very specific videos (not p…

You’re jumping to unwarranted conclusions. A more reasonable explanation is simply that the unpopular videos you watched triggered recommendations similar to them, and based only on them - and that being what you typically watch no your other computer, the result was familiar to you.
Post reply on HN