Apps like TikTok can know which username we logged in with, even if we uninstall and reinstall the app. This is egregious, as many companies like Facebook have SDKs embedded in many apps, allowing them to accurately interconnect user activity. Apple should be ashamed that they aren't putting effort to randomize these fingerprints....
Loupe – A iOS app that raises awareness about what native apps can see
51–60 of 263 posts
Re: Loupe – A iOS app that raises awareness about what native apps can see
#52https://odysee.com/@techlore:3/permission-not-required-the-o...
https://www.youtube.com/watch?v=_n_SpEWtqog
Re: Loupe – A iOS app that raises awareness about what native apps can see
#53Re: Loupe – A iOS app that raises awareness about what native apps can see
#54Re: Loupe – A iOS app that raises awareness about what native apps can see
#55Earlier quoted context omitted.
Seems like in general the iPhone was not designed to avoid fingerprinting from installed apps. Only protection would be avoid installing apps and use the web browser when possible.
This. This is why everyone who wants to fingerprint and collect tons of data on end users pushes them hard on installing an app. The amount of valuable data is 10x what’s available in the browser
To make it worse, Apple's naming undermines consciousness about this issue, since they have an option to block cross-app/site tracking (which IIRC blocks access to the advertising identifier), but called it "Allow Apps to Request to Track". A lot of people seem to hold the belief that disabling this option blocks all in-app trackers. It just blocks one way to correlate, but as this app shows, there are other ways to correlate (as well as correlating server-side using IP addresses, etc.).
On this topic, I somehow missed that Apple added a generic URL filtering API to macOS/iOS 26, which extends Safari filtering to the whole OS (well, as long as apps are using Apple's APIs). It's not perfect, but a nice addition to DNS-based blocking:
https://adguard.com/en/blog/apple-url-filter-system-wide-fil...
The author of Wipr added support to Wipr 2 as an extra in-app purchase:
https://kaylees.site/wipr2-whats-new.html#filtr
Aside from technical methods to address this, all this in-app tracking must be a violation of the GDPR, no? I can't imagine this all falls under legitimate interest.
Re: Loupe – A iOS app that raises awareness about what native apps can see
#56Re: Loupe – A iOS app that raises awareness about what native apps can see
#57This is neat and interesting, truly, but the classic “what now?” emerges. I guess the only answer is “throw out my iPhone”? Otherwise this kind of seems like a circuitous ad to make people get worried and download Psylo, which I see has in-app purchases. I’m not trying to come at you here, but it’s just hard not to feel suspicious online these days.
Re: Loupe – A iOS app that raises awareness about what native apps can see
#58Earlier quoted context omitted.
Maybe I'm being really thick, but why is this information that the OS would make available to apps?
Maybe it’s derived
Edit: It's not a last modified timestamp, it's a volume creation timestamp: https://github.com/mysk-research/loupe/blob/2262efd4456ecba8...
Re: Loupe – A iOS app that raises awareness about what native apps can see
#59this is fantastic, just great really, and honestly makes one stick out so easily, reminfs me a lot of that license plate xkcd
Re: Loupe – A iOS app that raises awareness about what native apps can see
#60E.g. I had no idea a random app you install (and give no permissions to) instantly has a list of every app installed on the device (e.g. can infer whether you're dating [or cheating!] from presence of tinder/bumble/hinge). That alone seems instantly monetizable by unscrupulous actors via 'is-my-partner-cheating' as a service: charge $10 to give a probable answer.