Live data from Hacker News

Loupe – A iOS app that raises awareness about what native apps can see

github.com

151–160 of 263 posts

Re: Loupe – A iOS app that raises awareness about what native apps can see

#151
post #40

Earlier quoted context omitted.

old.reddit.com

For now but you know they’re coming for that ass.

It used to be widely thought they were keeping it around because the most important users who actually posted the content preferred it. But they drove all those people away in 2023 by blocking apps except for their spyware one, and everything is posted by LLMs now anyway.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#152
post #16

Earlier quoted context omitted.

```Based on a binomial/Poisson distribution and a baseline of 21 million U.S. device sales per release, a fingerprint relying on "seconds since setup" fails to uniquely identify individuals. In the high-density Early Adopter phase, you will share your exact setup second with an average of 1.01 other people (a total matching pool of ~2 people). Six months into the cycle, you will still share that second with an averag…

Reminds me of a meeting I was party to with the Safari team. We worked with them on some standards stuff at an old job. They claimed to have creepy-level tracking of users back then. We were discussing how to identify users for an A/B test across millions of sites and comparing what fingerprints we could both derive to most likely end up on the same user. If you use a closed source browser. That’s the kinda shit they…

Are you claiming the Safari team is fingerprinting their users?

Re: Loupe – A iOS app that raises awareness about what native apps can see

#153
post #70

Earlier quoted context omitted.

Okay it's weird but the first thing that came to mind. Logic: if I can think of a monetisable, nefarious application in 10 seconds, then it stands to reason that very many nefarious applications would be possible with more time/effort.

Not just possible, currently being implemented. People are murdered every year using this information. Last year a US politician was assassinated by someone who tracked them by buying this information from aggregator. You thought of a tame use case!

Which politician? I want to read more

Re: Loupe – A iOS app that raises awareness about what native apps can see

#154

Earlier quoted context omitted.

...wouldn't it be better to have a pocket computer you own?

It would be even better if app devs weren't pieces of shit making apps whose sole purpose is to gather all of this data to sell to other pieces of shits while skinning their app as a game or other app to trick users into thinking it's worth installing. Fighting devs being able to make money in this manner is not dissimilar to getting made a drug dealers. As long as users want their product, they will sell the product…

Or if every time someone wrote an app that did this, we arrested them.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#155

Yea, it's infuriating that most of the HN crowd thinks the apps are better then web. Apps can spy on you way more than web. It's the reason every website says "please download the app". If it was better for them to spy on you via the website they wouldn't ask you to download the app.

They are technically better. They can do more stuff and integrate with the OS better in general. That includes fingerprinting stuff and fingerprinting integration.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#156
post #16

Earlier quoted context omitted.

```Based on a binomial/Poisson distribution and a baseline of 21 million U.S. device sales per release, a fingerprint relying on "seconds since setup" fails to uniquely identify individuals. In the high-density Early Adopter phase, you will share your exact setup second with an average of 1.01 other people (a total matching pool of ~2 people). Six months into the cycle, you will still share that second with an averag…

Just using IP address, device storage, device name, and similar signals, we can identify a user. It isn’t difficult to correlate these data points. Apps like Facebook also force developers to use their SDKs for even small features.

Yeah, but IP address is "obviously" correlated with a distinct/persistent tranche of users. It's surprising that volume c_time is both more persistent as well as more unique than IP.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#158
post #63

Earlier quoted context omitted.

GrapheneOS lets you restrict the internet access of any app on install. But yes, agreed it should be everywhere.

iOS lets you turn off data access (so outside of wifi) for apps as well, it's just not asked at install, which honestly makes sense given the demographics of iPhone users.

Which is useless for 99% of users since they use Wi-Fi at some point in the entire phones lifetime….

Re: Loupe – A iOS app that raises awareness about what native apps can see

#159

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

Because 99% of apps would request it & not function without it, desensitising users into blindly accepting it. Most apps do have a legitimate reason for accessing the internet, so a binary yes/no wouldn’t achieve much anyway. I just don’t think it’s an effective way of solving the problem.

100% of users have legitimate reasons to block internet access for some apps.

If internet access wasn't granted by default, a lot more apps would function without it.

Many other apps wouldn't exist at all, because their only reason to exist is to spy on users.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#160
post #77

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

Better yet, a tool like Little Snitch should be built into the OS. Give me a detailed log of every network requests, to which domains, with what data.

[deleted]
Post reply on HN