Live data from Hacker News

Apple’s Anti-Tracking Plans for iPhone

foundation.mozilla.org

271–280 of 403 posts

Re: Apple’s Anti-Tracking Plans for iPhone

#271
post #83

Earlier quoted context omitted.

What do you think are the possible issues for full encryption of iCloud backups?

One important implication of not using full encryption is that it protects users from themselves. If a user forgets their password, Apple can still unlock their data. From a security perspective, this obviously isn't ideal. But, from the perspective of the average user who has lost all of their data, this is great.

This. As an example, my mother (who is over 90) got locked out of her icloud account a couple years ago, from getting unexpected password prompts on her ipad and not understanding which password was required, she entered the wrong one too many times. We had recorded our answers to the “security questions” when setting up the account, but they were not accepted either. In the end, we managed to restore access via a rather cumbersome process. No complaints about that, of course; the important part is that she did get her access back in the end.

Re: Apple’s Anti-Tracking Plans for iPhone

#272

Apple is the best huge corporation when it comes to protecting user rights. I would have gone “all in Linux and alternative phones” if not for Apple’s current policies. They would lose me as a customer if they change, but I don’t expect them to do that.

You mean like the right to repair? Or do you mean the user rights on your iOS device, not allowing you to install stuff from outside the app store?

Re: Apple’s Anti-Tracking Plans for iPhone

#273
post #217

Earlier quoted context omitted.

I would be thrilled if online advertising became unviable as a business model. Most of what makes the web suck today (megabytes of javascript on every page; clickbait articles; outrage-driven social media; warehouses of PII waiting to be bought/sold/stolen) is because of advertising. Yes, I do want to pay for the services I use.

How would you pay for the services and content you consume?

Advertisers would put stupid banners on my page because they cannot do anything else but still want to advertise. Maybe they spend less because they get less return. I actually think it would increase quality of content.

Re: Apple’s Anti-Tracking Plans for iPhone

#274
post #148

Earlier quoted context omitted.

This is about tracking your internet activity, not physical location/movements.

Your carrier has that correlation. They route all your packets. It doesn't matter if it is Comcast at home or Verizon/Att on the go. They know where you live and work and track you 24/7. Facebook is simply going to make a deal to have a unique ID added to URL metadata and then tracking is even more trivial. We need legislation to guarantee true net neutrality. Just like the electric company doesn't track/sell what I…

Well, if you want to protect yourself you should understand this in more detail.

At minimum you should be using https. Your ISP could generally know the domains you are communicating with (when and how much), but not about what. They also could not add metadata to requests. The ad tracking we're talking about in this post really needs those details, so the ISP isn't in a position to enable the kind of tracking Apple is blocking here.

You can go further and use a VPN. Then all your ISP knows is that you use a VPN, but would not be able to tell anything else. Of course, you need to trust your VPN provider (including to properly secure their service), but if you're paying for one, at least your interests are aligned. (You pay your ISP, but they operate as semi monopolies and your privacy is not their primary business concern, so your interests don't really align that well.)

I agree about not allowing ISPs to sell data, though I think it would be OK if properly anonymized.

Re: Apple’s Anti-Tracking Plans for iPhone

#275
post #179

Earlier quoted context omitted.

Most of the time, privacy and fraud both benefit from the same changes. To prevent tracking online, you want your device to look just like everybody else's devices. To prevent fraud, you want devices to look different so you can tell when a device does not represent a real user. At the extreme, imagine if every person has a unique identifier that was automatically sent whenever they used any device: preventing ad fra…

>but if you had headless browsers loading the ads on your site no one would be able to tell that those views were not from real users. There is literally nothing in the world I care about less than this.

Of course you don't care about it directly, but it is part of a chain that funds things you probably do care about?

Advertisers pay publishers to show their ads to real users. Publishers run their sites because they receive money from advertisers. We visit the sites because they're diverting/informative/useful/etc. If the advertisers can't tell whether their ads are instead shown to robots, the whole thing falls apart.

I like the trust tokens proposal as a way to exclude bot traffic without tracking: https://web.dev/trust-tokens/

Re: Apple’s Anti-Tracking Plans for iPhone

#276
post #153

Earlier quoted context omitted.

Having been on both sides of the table, I would slightly disagree here. Fraud prevention for example will get an order of magnitude harder, plus this move will further skew the playing field towards FAANG who have the resources to puzzle the scraps back together for decent conversion tracking with the help of logins, IPs, SDKs with First Party IDs and a massive dose of machine learning.

I don't know why you use a big word such as "fraud" when you mean "we want to be able to know which accounts are owned by the same person".

Ad fraud is a morally loaded term. What's considered ad fraud is not fraud, but labeling it as such lets advertisers point to individuals running bots and scripts as malicious internet abusers. If I used the term fraud like the ad industry uses ad fraud, I'd probably lose my law license or just get buried under unfavourable costs orders in court.

So why are they deploying the term? Because it's a great way to deflect thinking about a core failing of their business logic. We've known since the day of banner ads that 'views' are a tremendously flawed metric, so blaming online agents for WHY they're flawed lets them deflect blame.

The fact that we're in this thread trying to parse semantics when consumers don't even have a seat at the table when deciding where we should fall on the tracking/privacy spectrum should tell you all you need to know about how the industry operates.

Re: Apple’s Anti-Tracking Plans for iPhone

#277
post #20
post #6

To what extent are iPhones fingerprinted though? As we’ve seen with websites even no unique id is not necessarily game over

You can test your device browser fingerprint here: https://coveryourtracks.eff.org

It must still work to some extent because SDKs like Branch.io are able to deliver payload to your application after installing it from a "deep link". You click a link in Safari, which makes a fingerprint of your device from the browser (and bundles your IP) and sends a request to Branch.io, this redirects you to App Store and you install the app from the link. The app the uses Branch.io SDK to make the fingerprint again and asks the server to send the payload back to you. This way you can make deep links work even if you don't yet have the app installed. To my surprise it still works quite reliably on iOS 14. It has some issues with fingerprinting if there are multiple iPhones with similar fingerprint on same network (same IP).

Re: Apple’s Anti-Tracking Plans for iPhone

#278
post #140
post #125

Earlier quoted context omitted.

That's true, they do provide data to governments in compliance with local laws. Criminalising your employees isn't a good look.

they also don't encrypt when laws actually enables to encrypt... https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv... Besides, haven't facebook and google got ban from China because for not compiling with Chinese law?

As that article, and others on this have pointed out, there are a whole host of reasons why encrypting iCloud data is problematic that have nothing to do with law enforcement. As you have read the article, obviously you must know this very well. In many other areas, they absolutely do encrypt. The fact is encryption sometimes carries down sides, such as an increased risk of users permanently losing access to their data.

Web services companies face a ton of problems operating in China that are really specific to the kinds of services they offer. Apple simply doesn't offer those kinds of services.

Re: Apple’s Anti-Tracking Plans for iPhone

#279

In Europe, cross-app, cross-browser & cross-device tracking is on very thin ice legally under the GDPR, so I'm not surprised Apple finally curbs the use of "sticky" identifiers on their devices. Honestly, it's a bit shameful that a device that is marketed as the gold standard in privacy would even support such an identifier in the first place, it has literally no purpose beyond mining peoples' data. Now that the thir…

Having been on both sides of the table, I would slightly disagree here. Fraud prevention for example will get an order of magnitude harder, plus this move will further skew the playing field towards FAANG who have the resources to puzzle the scraps back together for decent conversion tracking with the help of logins, IPs, SDKs with First Party IDs and a massive dose of machine learning.

“Fraud”...uh-huh. Please be clear that you mean AD fraud and not fraud-fraud.

Also: boohoo

Re: Apple’s Anti-Tracking Plans for iPhone

#280
post #244

Earlier quoted context omitted.

> Advertisers can purchase fixed display ads on reputable sites by contracting directly with the site owner. But what is a fair price? That depends on the traffic, but we are positing that detection of "is this a real user" is not possible, right? Traditionally, advertisers have gone by Nielsen style ratings for broadcast media (pay people to track what they consume, extrapolate) and circulation numbers for print med…

> But what is a fair price? That depends on the traffic, but we are positing that detection of "is this a real user" is not possible, right? Couldn't the price just be based on the actual payoff the advertiser gets (aka increased product sales)? The publisher is incentivized to set the maximum price that the advertiser will pay, and the advertiser is incentivized to get the most bang for their buck, so at the very le…

Exactly this. When I advertise, I don’t care if a million users see it. I just care that Ad Spend Getting the initial price is going to be hard, but over time, rates will start to become known.
Post reply on HN