Live data from Hacker News

Apple: Apps should not require users to opt into tracking to access content

developer.apple.com

121–130 of 274 posts

Re: Apple: Apps should not require users to opt into tracking to access content

#121

Everybody complains about the walled garden, but damn I love to see things like this.

You do realise Apple could still do this in their app store AND allow 3rd party app stores?

Not to the same effect. It means if developers don’t want to play by Apple’s rules they don’t have to completely surrender the iOS market. A big enough name could just direct users to the third party App Store.

Re: Apple: Apps should not require users to opt into tracking to access content

#122

Everybody complains about the walled garden, but damn I love to see things like this.

Remember that app SDK that decided to hijack every URL open and leak auth tokens back to the mothership?

That's all right with Apple:

https://www.securityweek.com/malicious-behavior-found-advert...

These rules are not worth the bytes used to transfer them. It's the epitome of selective enforcement.

Re: Apple: Apps should not require users to opt into tracking to access content

#123
post #21

Earlier quoted context omitted.

Doesn't Apple track every app you install, access and run? Track you if you want to develop your own code for your own fully paid for device?

On iOS under: Privacy -> Analytics & Improvements They (a) show what data is being sent e.g. stack traces and (b) provide the privacy policies. At least on my device I am not seeing a list of apps being sent to Apple.

Your device doesn’t need to send it. They know what apps you’ve downloaded already and on what device. The real question is, does it send when you remove an app? If so, they are tracking your apps you have installed.

If your device offloads apps, they know when you download it again and thus can infer usage.

Re: Apple: Apps should not require users to opt into tracking to access content

#124
post #83

Earlier quoted context omitted.

You've bought the privilege of being allowed to accept the EULA.

It reminds me of a US visa, which is far from free, and you pay for applying whether you is granted it or not. It allows you travel to a border control and ask to be let in. They can refuse you without explanation.

All visas work this way afaik, at least in the few places I’ve traveled where I’ve needed a visa; notably Africa.

I met a Italian man at immigration control in Ethiopia, at the Addis Ababa airport, he had been traveling Africa and this was his third attempt to enter Ethiopia. The first two attempts were via land borders with Kenya and he had been turned around both times, despite having a visa, because border control felt it would be too dangerous for a white man to travel through southern Ethiopia at the time. So he had to travel to Nairobi and get a flight; he was admitted this time, but he had to pay for another visa at the airport. Unclear why? He wasn’t best pleased about the whole thing.

Re: Apple: Apps should not require users to opt into tracking to access content

#127
post #3

Full text of the clause: > 3.2.2 Unacceptable > (vi) Apps should allow a user to get what they’ve paid for without performing additional tasks, such as posting on social media, uploading contacts, checking in to the app a certain number of times, etc. Apps should not require users to rate the app, review the app, watch videos, download other apps, tap on advertisements, enable tracking, or take other similar actions…

I find that policy entirely acceptable, for the same reasons I think shrink-wrap EULAs should be illegal. This makes me curious about Apple and iOS / OS X. Does Apple try to require that the user accepts an EULA for the OS after buying Apple hardware?

IIRC the existence of such an EULA includes a clause which was the reason behind Apple's successful court case against a company who was selling pre assembled and configured Hackintosh boxes. (Does anyone remember what the name of the company was? It was like 2007-9 or something)

IMHO that EULA's main purpose atm is to tell you that you can only install MacOS on, and I quote, an 'Apple-branded computer'.

This led to a hilarious habit of Hackintosh users including myself just sticking the Apple stickers from their iPods or other Apple devices on their custom built machines. Wouldn't hold up in court, of course, we were just having fun with the wordplay.

Re: Apple: Apps should not require users to opt into tracking to access content

#128

Everybody complains about the walled garden, but damn I love to see things like this.

Remember that app SDK that decided to hijack every URL open and leak auth tokens back to the mothership? That's all right with Apple: https://www.securityweek.com/malicious-behavior-found-advert... These rules are not worth the bytes used to transfer them. It's the epitome of selective enforcement.

I’m not sure what your point is.

> […] the tech giant has found no evidence that apps using the Mintegral SDK are harming users. […] The company says app developers are responsible for the behavior of their products, including the behavior of third-party code, and they should exercise caution when using third-party code to insure it does not accidentally undermine security and privacy.

This seems to be correct. This is an SDK the application developer chose to use. Its behavior may be harmful to other ad networks, but doesn’t seem to have any effect on the user. Which is to say, the SDK isn’t doing anything the app itself couldn’t just do itself. The SDK may be doing stuff the developer isn’t aware of, but that’s true of any third-party code, and this is why developers need to ensure they validate third-party code appropriately.

Re: Apple: Apps should not require users to opt into tracking to access content

#130

Everybody complains about the walled garden, but damn I love to see things like this.

You do realise Apple could still do this in their app store AND allow 3rd party app stores?

That's a terrifying idea. Horrifying.

I absolutely detest this idea of third party app stores. Please tell me why this is a good idea when literally your entire life and its contents are contained in this palm sized device.

Do you really want sideloading of apps that asks average joes for ransomware?

We already have another sandbox - browsers. And you're seeing problems with extensions, popups, .dmg downloads and .exe virus scans, etc. So much so that browsers are constantly fighting against attacks for 20 years.

Post reply on HN