Live data from Hacker News

Loupe – A iOS app that raises awareness about what native apps can see

github.com

171–180 of 263 posts

Re: Loupe – A iOS app that raises awareness about what native apps can see

#171

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

Because exposed, non-private, abused by-default is a business model. The company is incentivised to not provide restricted access - otherwise you can't have a cut from apps revenue. It's defective by design.

Shocked to see iPhones sold in China are less defective by design on this one point, from another comment. It has surely reduced Genius Bar visits but it’s also harmed my privacy.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#172
post #77

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

Better yet, a tool like Little Snitch should be built into the OS. Give me a detailed log of every network requests, to which domains, with what data.

Yes and it should work properly instead of making unwanted initial outbound connections (macOS firewalls are broken).

Re: Loupe – A iOS app that raises awareness about what native apps can see

#173
post #20

This is why I avoid installing apps and don’t have a lot of them.

...wouldn't it be better to have a pocket computer you own?

That’s not the problem though. The problem is that most apps are malware.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#174

Holy cow, did not know ios lets apps access so many finger printable information such as apps installed, last wipe and number of copy actions. Installed the browser as I am confident it will be good also. Thank you!

Idk, I actually got the opposite impression. Most of the info is just what I would expect everyone to see: date formats, languages, various webview kind of stuff, network info. This is already more than enough for fingerprinting

> information such as apps installed

This is what surprised me too, but if you read their hint, it’s not like list API. They probe various ‘open URL in app’ to see what apps registered them, so are installed. I guess this i) won’t allow you to track apps that don’t have ‘open in app’ urls, and ii) probably hard to limit without affecting UX

> number of copy actions

This is odd, yeah, not sure why is it exposed

> last wipe

They deduce this from the volume creation date. Probably possible to hide, but also not really that important, at least to me. Fingerprinting will work with way fewer info anyway

To summarize, I think iOS is still very solid in terms of involuntary info exposure (if you trust Apple itself). Most of really sensitive info requires separate permissions. Yes, you can harden it further, but that will be more like a paranoid mode

Re: Loupe – A iOS app that raises awareness about what native apps can see

#175

This is neat and interesting, truly, but the classic “what now?” emerges. I guess the only answer is “throw out my iPhone”? Otherwise this kind of seems like a circuitous ad to make people get worried and download Psylo, which I see has in-app purchases. I’m not trying to come at you here, but it’s just hard not to feel suspicious online these days.

Apple has been very good about public perception of its products and privacy. They just spent a lot of this year’s WWDC talking about the latter so I’m sure someone at Apple is aware of this.

I have not spent a lot of time thinking about why certain things like 50 apps install queries, boot volume timestamps, etc are provided to developers. But I think Apple will close these loopholes.

Also love the idea of outbound network connections being disabled by the user per app

Re: Loupe – A iOS app that raises awareness about what native apps can see

#178

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

iPhones purchased in mainland China (with model number ending in CH/A) do provide options for setting per-app Internet access permissions. There are three options [0]: Off, WLAN only, WLAN and Cellular. [0] https://old.reddit.com/r/ios/comments/aib10i/in_china_ios_al...

What? Why is this Chinese market only? This is exactly what I wanted. There are Apps I simply don't want them to touch internet.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#179
post #102
post #92

Earlier quoted context omitted.

But a single app can request to know the presence of up to 50 apps, right? And a data broker/aggregator can purchase such data from many (e.g. thousands) of apps and aggregate it, then sell it.

Yes indeed, the limit is 50 which is of course enough to fully profile "regular people" who only have a handful of apps. Also don't forget, Meta/Google/TikTok/WhateverPalantir are updated weekly which means they can tweak their LSApplicationQueriesSchemes list and cover even more apps if they want to.

Are there legitimate reasons why an App should know I have installed?

Re: Loupe – A iOS app that raises awareness about what native apps can see

#180

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

Because 99% of apps would request it & not function without it, desensitising users into blindly accepting it. Most apps do have a legitimate reason for accessing the internet, so a binary yes/no wouldn’t achieve much anyway. I just don’t think it’s an effective way of solving the problem.

> Most apps do have a legitimate reason for accessing the internet

I just flat out think this is bullshit

Post reply on HN