Live data from Hacker News

Privacy: Is That iPhone?

foundation.mozilla.org

101–110 of 188 posts

Re: Privacy: Is That iPhone?

#101

Earlier quoted context omitted.

I applied filters and took a screenshot of the screenshot to reduce image fidelity in case it contained any [covertly embedded]* identifying information [in the form of watermarks or hidden pixels] . *added for clarity.

In case people aren't aware, such a thing _is_ possible. Companies have used steganography techniques in the past to secretly embed identifiers into movies and other visual content. It's been used to track down the movie leakers, for example. Another example; most printers covertly embed an identifier in their prints. I have a vague memory of a pre-release video game doing it? Or maybe it was just debugging informati…

> Another example; most printers covertly embed an identifier in their prints.

This frustrates me a lot with my current printer. The yellow dots which "covertly" identifies my prints are way too visible in the print. So every time I look carefully at something I print I am reminded of how I am being watched.

Re: Privacy: Is That iPhone?

#102

> Phone users can currently disable the IDFA, but have to do so manually; Android users aren’t even given this option This actually false. You can change your Ad ID on Android. I just looked (and checked)If you go to Settings > Privacy > Ads you can see this IDFA. At the top (it looks like a header and not an option, so I will not fully fault Mozilla because this is a dark pattern) it says "Reset advertising ID". If…

There is no such option for me in Note9

Re: Privacy: Is That iPhone?

#103

> Phone users can currently disable the IDFA, but have to do so manually; Android users aren’t even given this option This actually false. You can change your Ad ID on Android. I just looked (and checked)If you go to Settings > Privacy > Ads you can see this IDFA. At the top (it looks like a header and not an option, so I will not fully fault Mozilla because this is a dark pattern) it says "Reset advertising ID". If…

I have this option on my Android 9 phone, and I can remember that this option has been there for a long time. Even older Android version have this option too.

Re: Privacy: Is That iPhone?

#104
post #60

Earlier quoted context omitted.

My Android 8 Pixel 2 XL has no privacy option in the settings. Upgrading would unfortunately come at the cost of losing root and AdAway (for the moment). I wonder which is more beneficial to have.

Well I'm also using a Pixel 2. So the good news is that this exists if you upgrade. I didn't realize root was not available on 10 (this is the first phone I haven't rooted and so I haven't been keeping up)

Root isn't available on on a Pixel 2 on Android 10? I also haven't upgraded yet but was going to, though that's a deal breaker for me. That said my light googling hasn't turned up verification of this yet.

Root does work just fine on Android 10 on the OnePlus 7 Pro (which is the best phone I've ever owned).

Re: Privacy: Is That iPhone?

#105
post #98
post #97

Earlier quoted context omitted.

> Finding the settings mentioned in the article is the sole dark pattern I can think of in iOS How about not being able to simply copy music to or from it without having its paired PC with iTunes on it? How about Apple's cat and mouse game of obfuscating their usb protocol to keep people from using Linux to copy music to and from the device? How about slowing down the OS when the device gets older to “save battery li…

> How about slowing down the OS when the device gets older to “save battery life”? This is false, it was to avoid situations where the battery couldn’t provide enough current and would likely cut out causing the phone to switch off. It seems the intentions were reasonable to keep older phones usable for longer and they fairly quickly rolled out a large discount on the cost of battery replacement when the public outra…

I strongly disagree. The intention may have been to avoid abrupt power downs but their implementation also made sure people upgraded their devices rather than buy a new battery because most people would never be able to imagine that a device could be slow because of a bad battery. This, IMO, was a dark pattern. A sudden power down would be clear indicator that something is wrong with the device while a gradual slow down of the device would seem like that the device is just getting older and needs to be upgraded to a newer one.

Re: Privacy: Is That iPhone?

#106
There a bunch more things Apple could do to improve privacy they haven't done (yet?)

They could require for example that unless you're specifically making a browser (Firefox, Chrome, Brave) that your in app webview have a whitelist of domains it's allowed to contact. That would force apps to launch Safari (or better the user's choice of browser) for external links. As it is nearly every app that supports external links launches an internal webview in which they can track 100% of the activity (urls, net requests, login credentials, etc...)

They could require apps that are not specifically a camera app or audio creation app not get access to the camera or mic and have to ask the OS take pictures/video and select pictures via the OS photos app. That way less apps would be able to record things in secret or upload any/all your photos without permission.

They could disallow scanning wifi SSIDs except for network tools. Scanning SSIDs is used to figuring out a user's location with with GPS off. In iOS 13 they did add bluetooth permissions so apps can be denied scanning bluetooth to do the same but AFAIK they have not done the same for SSIDs. Not sure what that would require but would love it if they'd work on it

They could disallow using the network at a low-level except for network tools. As it is, AFAIK, any app can use the network however it likes including scanning home networks for devices with vulnerabilities. I'm sure there are implications for things like Chromecast and other IoT like devices but I'm sure there could be more privacy oriented solutions.

Re: Privacy: Is That iPhone?

#107

> Phone users can currently disable the IDFA, but have to do so manually; Android users aren’t even given this option This actually false. You can change your Ad ID on Android. I just looked (and checked)If you go to Settings > Privacy > Ads you can see this IDFA. At the top (it looks like a header and not an option, so I will not fully fault Mozilla because this is a dark pattern) it says "Reset advertising ID". If…

For me it is on Settings > Google > Ads. Thank you.

Re: Privacy: Is That iPhone?

#108

There a bunch more things Apple could do to improve privacy they haven't done (yet?) They could require for example that unless you're specifically making a browser (Firefox, Chrome, Brave) that your in app webview have a whitelist of domains it's allowed to contact. That would force apps to launch Safari (or better the user's choice of browser) for external links. As it is nearly every app that supports external lin…

> As it is nearly every app that supports external links launches an internal webview in which they can track 100% of the activity (urls, net requests, login credentials, etc.

My understanding is that UIWebView (or WKWebView) allows the host app to do basically anything with the web view but since iOS 9 there's also SFSafariViewController that doesn't quite allow apps as much access. Many apps whose main purpose is not web browsing (like Twitter) use the latter.

> They could require apps that are not specifically a camera app or audio creation app not get access to the camera or mic and have to ask the OS take pictures/video and select pictures via the OS photos app.

This API (UIImagePickerController) also already exists since the very beginning but it is the app makers that think using a custom UI for photo taking or photo picking is more suitable. I personally refuse to grant apps access to my photo library except a small number of apps. (For apps like Messenger that could totally make do using the system-provided photo picker but does not, I initiate the sharing from Photos instead.)

Re: Privacy: Is That iPhone?

#109
post #66

Earlier quoted context omitted.

You don't need an IDFA to track someone in the same app. You can generate your own UUID to use. The value of the IDFA comes from coordinating user behavior across apps. Targeting ads is one use case, but it is also used in conversion tracking, which is very valuable to advertisers. They can know if ads in one app resulted in people buying things in another app. Edit: fixed typo

The point is that the app can just record the old IDFA, and when the IDFA changes whoever is doing the comparison between two apps knows that the old and new IDFA are one and the same.

A likely-good-enough fix would be for Apple to first make extremely clear that this is not allowed, then catch one ad framework/library provider violating the rule and ban every single app/publisher using it to ensure the rule is actually taken seriously.

Re: Privacy: Is That iPhone?

#110

> Phone users can currently disable the IDFA, but have to do so manually; Android users aren’t even given this option This actually false. You can change your Ad ID on Android. I just looked (and checked)If you go to Settings > Privacy > Ads you can see this IDFA. At the top (it looks like a header and not an option, so I will not fully fault Mozilla because this is a dark pattern) it says "Reset advertising ID". If…

I interpreted Mozilla's claim that Android users cannot disable the advertising identifier, but can reset it. The sentence talks about periodic resetting. I might be wrong in the intention of the author(s), but that is my interpretation.
Post reply on HN