Live data from Hacker News

Loupe – A iOS app that raises awareness about what native apps can see

github.com

161–170 of 263 posts

Re: Loupe – A iOS app that raises awareness about what native apps can see

#161

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

Because exposed, non-private, abused by-default is a business model. The company is incentivised to not provide restricted access - otherwise you can't have a cut from apps revenue. It's defective by design.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#162

Earlier quoted context omitted.

This isn't effective because Little Snitch only sees the domains so apps can just serve the trackers on the same domain as essential services making blocking impossible. The only way to prevent malicious apps from affecting your privacy is to not install them or not give them network access.

Can, but they don't, because app developers are just as lazy and don't waste time to hide their trackers

They don’t because there is no reason to currently. If this was added then they would have a reason to and do it.

YouTube used to be separate domains for ads and then it got merged together so that you can’t block the ads network wide without blocking YouTube videos.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#163

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

Because 99% of apps would request it & not function without it, desensitising users into blindly accepting it. Most apps do have a legitimate reason for accessing the internet, so a binary yes/no wouldn’t achieve much anyway. I just don’t think it’s an effective way of solving the problem.

The internet access permission should be implemented. Users of macOS are already accustomed to the local network access permission.

Even if it's not the most effective way to raise awareness, it does put pressure on developers to be explicit about the connectivity requirements with users. It would also be a great way to audit an app's local-first / offline-first claim without having to do a network packet capture.

Want telemetry? Send it through Apple and Google. Given Apple's late history and latest trends in Android development, I see them both favoring this approach.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#165

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

The evolution of development was to make things easy and simple for the consumer. If internet was an opt-in (and it cannot be opt-out), then app function would be ostensibly limited. And the user would be given a harder time setting things up.

This is the Apple mindset. Make things easy. Do not make things complicated.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#166
post #117

Earlier quoted context omitted.

Ask any domestic abuser. Most of them seem to be successful at it. https://www.npr.org/sections/alltechconsidered/2014/09/15/34... It’s crazy to me that people are being so skeptical of the idea. A lot of people share their logins freely with their spouses. I have never done it nor would I condone it, but it would be trivial for me to install spyware on the devices of many people I know, because they rightfully trust…

If you can get the app onto my phone in person, you can also just check which apps I have on my phone

That assumes continued access, which may not be true. Installing spyware gives you information down the line.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#167

Earlier quoted context omitted.

Can, but they don't, because app developers are just as lazy and don't waste time to hide their trackers

They don’t because there is no reason to currently. If this was added then they would have a reason to and do it. YouTube used to be separate domains for ads and then it got merged together so that you can’t block the ads network wide without blocking YouTube videos.

That's YouTube. One of the unlaziest dev teams. Spiderman Solitaire isn't going to bother.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#168
post #117

Earlier quoted context omitted.

Ask any domestic abuser. Most of them seem to be successful at it. https://www.npr.org/sections/alltechconsidered/2014/09/15/34... It’s crazy to me that people are being so skeptical of the idea. A lot of people share their logins freely with their spouses. I have never done it nor would I condone it, but it would be trivial for me to install spyware on the devices of many people I know, because they rightfully trust…

But if you have credentials and physical access you can just ask for their phone and straight up read their messages/apps.

Yeah, once, possibly under time pressure, and not at all times. Spyware gives you continued access.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#169

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

Because 99% of apps would request it & not function without it, desensitising users into blindly accepting it. Most apps do have a legitimate reason for accessing the internet, so a binary yes/no wouldn’t achieve much anyway. I just don’t think it’s an effective way of solving the problem.

Permission should be in the form of a capability, which need not end up on the built-in OS network capability. If an app insists on your car's steering wheel, you can be like "sure, kid, here's your Help Daddy Drive(TM)".
Post reply on HN