Live data from Hacker News

What Apple and Google are doing to push notifications

jacquescorbytuech.com

411–420 of 428 posts

Re: What Apple and Google are doing to push notifications

#411
post #128

Earlier quoted context omitted.

Yeah, this entire article is pretty transparent that it's from the sender perspective, and worried about platforms taking over "sender control". Who is he kidding? The vast majority of apps have absolutely proven they can't be trusted to respect your attention. From my perspective, the more roadblocks the platforms put between unnecessary notifications and my phone, the better. And I don't think Apple or Google are s…

Notification categories are like mailing lists now. You may have unsubscribed from the daily deals email but you're still going to be auto subscribed to every new slightly modified category in perpetuity. Unless you fully disable notifications for an app (in Android at least, in my experience), new enabled by default notification categories are added all the time.

That's one of the reasons I simply do not allow anything on my phone to auto-update. 98% of app updates these days are effectively malicious. I'll only update individual apps when and if I deem it to be actually necessary.

Except F-Droid. I trust their moderation enough to allow auto updates.

Re: What Apple and Google are doing to push notifications

#412
post #31

Earlier quoted context omitted.

The biggest problem are apps that do both. For example, I want Uber to notify me when my driver has arrived, but I don't want it to notify me when they have a special 10% discount on my next 5 rides. It's not straightforward to block one but not the other.

If I order an Uber, I already know it is coming. I was the person who ordered it. This is how taxis worked for decades before smartphones existed. You phoned for a taxi, then remained vaguely aware that it would arrive shortly. The question is whether a single “it has arrived” notification is worth the surrounding noise: “driver accepted”, “driver is nearby”, “rate your driver”, “here’s 10% off your next ride”, and s…

> This is how taxis worked for decades before smartphones existed.

Seems like a useless observation in a world that has had smartphones for decades then, huh? The notification use here is a two way ping, communicating from the driver that they're here and to not needlessly waste your time looking around or "remain[ing] vaguely aware [they would] arrive shortly" and being inattentive, thereby wasting the drivers time and chance of profit. We're all glad you personally have a cute little value system that let's you frame your cute little acts of defiance as a war against big bad change, but no one here needs to defend to you why receiving a notification on an app needs to be helpful in a life-changing way for the feature to be considered useful. It's now considered useful for millions of people who arent you, so let's have a discussion about making it less distracting or better suited for tasks, instead of geriatric pining about the nostalgia of simpler times.

Re: What Apple and Google are doing to push notifications

#413

Earlier quoted context omitted.

I would, but I don't need to know immediately. Plus you have the other vector of my phone sitting on a table and showing the notification to a person who can see it when they are trying to login as me.

I find it to be a poor default that sensitive data is shown on the lock screen. I change that setting as a first order of business whenever I'm setting up a new phone.

SMS should not be considered sensitive data since it can be read by entities between you and the source.

Re: What Apple and Google are doing to push notifications

#414

Earlier quoted context omitted.

I recently had to setup Microsoft Authenticator. It refused to register a code unless I enabled notifications. You are a two factor app. I should never be in a situation where there is an unexpected login I need to verify.

Apps can know whether you granted permission?? That sounds like a security flaw.

Yes, and they’re bound to abuse it.

There’s a similar thing going on with emails. Dozens of services ”decide” that you need to update your email address, because ”they can’t reach you”. Many of them even stop sending you emails you explicitly subscribed to, perhaps to maintain an archive, ”because you don’t seem to open them”.

No, dear Linkedin and others, you’re reaching me just fine, and it’s none of your business whether, when and where I open them. Maybe I just read my emails offline and strip your tracking links (and avoid clicking on links in emails in general).

Inexplicably LinkedIn’s UX for changing the old email address, the one they cannot reach you at (!), to a new email address, starts with confirming your current email address (THE ONE THEY CANNOT REACH YOU AT). Brilliant.

Re: What Apple and Google are doing to push notifications

#415
post #414

Earlier quoted context omitted.

Apps can know whether you granted permission?? That sounds like a security flaw.

Yes, and they’re bound to abuse it. There’s a similar thing going on with emails. Dozens of services ”decide” that you need to update your email address, because ”they can’t reach you”. Many of them even stop sending you emails you explicitly subscribed to, perhaps to maintain an archive, ”because you don’t seem to open them”. No, dear Linkedin and others, you’re reaching me just fine, and it’s none of your business…

[flagged]

Re: What Apple and Google are doing to push notifications

#416
> Email gives you layout control via HTML; push gives you a small structured payload and little control over the collapsed lock-screen view beyond the platform's templates

Thank god for this. I absolutely do NOT want my notification center to become a playground for marketing people to try to manipulate my attention even more than they already do. Every notification would have flashy animations and should adhere to the brand guidelines of whatever app or company is sending them.

Re: What Apple and Google are doing to push notifications

#417

Earlier quoted context omitted.

I find it to be a poor default that sensitive data is shown on the lock screen. I change that setting as a first order of business whenever I'm setting up a new phone.

SMS should not be considered sensitive data since it can be read by entities between you and the source.

If someone texts me something that's not interesting to those MITMs but is sensitive to mom catching a glance while my phone is on the table, that's a problem this toggle creates/destroys. Threat models vary.

Re: What Apple and Google are doing to push notifications

#418
post #308

Earlier quoted context omitted.

I recently got an unsolicited OTP email from Microsoft, which led me to fear that someone had entered my password, but no: I eventually was able to confirm that the arrival of an OTP does not, in fact, require that someone enter anything beyond my email address. This is rather insane (I should not be having a blood pressure event due to Microsoft) but on the other hand I do understand the passwordless concept which i…

This also happened to me about a week ago and I had the same reaction/discovery process you did. OT but I wonder if there was a recent ramp up in these attacks. It was done against an email I do not regularly use that was attached to my account as an alternate and haveibeenpwned confirmed was in a data breach back in 2020.

I had been thinking someone with a similar address made a typo. But now I'm thinking Microsoft already considers this a known incident depending on whether a bazillion attempts were made in a detectable manner. I hope a successful launch at least demands a botnet and random delays/backoff.

Re: What Apple and Google are doing to push notifications

#419

Earlier quoted context omitted.

I recently got an unsolicited OTP email from Microsoft, which led me to fear that someone had entered my password, but no: I eventually was able to confirm that the arrival of an OTP does not, in fact, require that someone enter anything beyond my email address. This is rather insane (I should not be having a blood pressure event due to Microsoft) but on the other hand I do understand the passwordless concept which i…

Some providers (looking at you, Intuit) don't seem to understand TWO factor authentication and will allow someone to bypass your password if they can intercept the SMS or email, and treat it as a normal login.

I can imagine an evolution like:

1. Introduce passwords

2. Introduce email-based reset flow

3. Introduce 2FA (optional)

4. Someone says "take the password reset flow, trigger it automatically when a user tries to log in and has only given their email, hide the password field during login, and after the email is validated drop the user back to their previous journey instead of having them set a new password"

5. You see #4 as #3 failing, but when #3 was never applied it's not quite that. Aside: making #3 mandatory would be smart.

Re: What Apple and Google are doing to push notifications

#420

Earlier quoted context omitted.

> I’ve almost never encountered a marketing email that didn’t have an unsubscribe link Have you encountered a "marketing email" that you didn't sign up for? That's called phishing. Have you clicked on links in phishing emails? That's called getting pwned.

That’s also not relevant to the topic, which was transactional vs marketing app notifications, and making a correlation to email.

It's certainly relevant to the topic: notifications, and a claim of legal requirements.

Legal requirements are useless without enforcement.

Post reply on HN