Apple’s analytics data include an ID called “dsId”. We were able to verify that “dsId” is the “Directory Services Identifier”, an ID that uniquely identifies an iCloud account. Meaning, Apple’s analytics can personally identify you. Apple states in their Device Analytics & Privacy statement that the collected data does not identify you personally. Even if legal, this is obviously a very bad look for a company that cl…
Apple is only about privacy as a marketing differentiator.
Apple's software clearly demonstrates that they do not place a high value on user privacy. iPhones and Macs phone home constantly with all sorts of information even if you never use iCloud or the App Store or Apple's service offerings. It's ridiculous.
> The author of the article wrote that all he had to do was request his data from Apple You observation has nothing to do with what is being discussed, we have a right to inspect the network activity of our devices. I remember you posting in threads criticizing Apple, almost always coming to their defense. You've been doing this for years.
> one needs to hack the device to see what data has. This is a provably false claim based on the authors own experience. Guess what? You also have no idea what your phone is sending the carrier or any other service provider. But as far as you knowing who I am because of my posting history, “but for me it was Tuesday”
> You also have no idea what your phone is sending the carrier or any other service provider.
Ah, so now you play the fatalist backdoor card. Well, the good news is that we do know some of what your iPhone sends back home. We know that every time you launch an app, both Apple and Akamai receive data about what app you opened and when. We know that Apple has private API entitlements for circumventing your VPN rules. We know that Apple actively and directly works with the NSA and CCP to enable domestic surveillance capabilities.
So, you're right! Hacking your device only gives you a small window into the horrors of your software vendor. If we could totally decrypt all of Apple's traffic alongside the SIM's baseband transmissions, nobody would every say 'privacy' and 'iPhone' in the same sentence again.
Agreed that is the technical distinction made today, but for an end user that really is splitting hairs. When Apple is offering first-party services that compete with Netflix, Spotify, etc. my privacy concern is that someone is tracking and aggregating data on what I watch and listen to. As a user I don't really care if that's two separate corporations sharing unique identifiers or two departments in the same umbrell…
You don't think who the data is shared with, whether or not you know or consent to it, and how it is propagated is a significant factor in privacy concerns?
Not if we can't hold Apple accountable for that information, no.
I see a lot of very intelligent people here unable to agree upon a matter that seems, in essence, simple enough. That is in itself troubling and partly answers a question. If developers on Hacker News cannot fathom whether Apple deceptively transmitted PII, or whether zealous journalists are over-egging the pudding, then we have another problem. Obfuscation is a form of deception through complexity. It can be hard to…
And some would say this is a deliberate adversarial tactic to guide people to surrender their privacy and freedoms, because those that would defend them can't sufficiently explain the complexity to be more convincing than 'simple' messages.
We say that because Apple has a history of using deliberate adversarial tactics to abuse the market and claim dominance. It's almost as iconic as Google killing off their own products.
Not sure if sarcasm, but just in case... My friend you need to open a window and see the rest of the world that exists outside that binary choice...
Well, even if it's a binary choice ... Facebook is the weird bit to pick.
All roads lead to data collection. It wouldn't surprise me if stories like this pushed people onto Facebook or Android just because of the uncertainty that the iPhone now represents.
Can someone explain why the App Store doesn't show the "Ask App Not To Track" dialog? Why do 3rd party apps have to ask for permission to track, but Apple's apps do not?
I'm only picking things up passively but as far as I have read, it is because the App Store does not track you across OTHER COMPANIES apps and websites. If they only track you within their own Apple ecosystem, they don't need to ask for permission (same as other apps).
Facebook kept their shadow profiles to themselves, but that didn't make it any less gross. Defending Apple's data collection on the basis that "they don't share it" is like defending a guy taking creepshots of you in the bathroom because he doesn't look like the sort of person who would cause you trouble.
Allegedly it’s fine because they’re collecting information for internal use and not sharing with third parties, but really the industry is trying to redefine tracking as cross service/site tracking. Well I think they should set the same bar internally
IF it's fine then why was Google data collection ever an issue?
Ok yea agreed. I think it’s more than one thing, including an internet service
It's certainly multiple things, but some things take precedent. If Apple allowed people to install third-party App Stores, then the freedom would take precedent and nobody would be throwing rocks at them.
You can use enterprise provisioning, which uses the same mechanics, to install apps on devices you manage.
There are lots of places that run iOS on private networks with no internet access or Apple ID.
If it can be traced to a natural person, it is PII. IP addresses are PII, ids are PII. It is in the name "Personally Identifiable Information." If it can be used to personally identify you, it's PII. If you gave me this ID number, I could use it to locate your information in breached db dump, or if it is used in API requests, impersonate you.
No, that's not the definition of PII. That the ID maps to a person doesn't mean they know that person's SSN, which is PII. IP counts as metadata. It uniquely identifies you as an entity but does not reveal other details except geographic location. If IP addresses are PII, then any use of the internet is violating your privacy. Perhaps unplug your modem, turn off cell service on all devices and read a book instead.
That's literally the definition, it's in the name. If it can be used to personally identify you in any way, it's PII. Yes, IP addresses are PII and there's nothing that prevents you from storing PII for reasonable amounts of time (i.e., to process a packet, a purchase, or fulfill a contract). Where you get into trouble with various laws is when you store them for other purposes (such as in logs) and use them in ways they weren't intended (such as analytics) -- especially if you don't tell the person you're using it in that way. That last part is usually the basics of what is required. Not disclosing it is a sure way to find yourself in hot water, eventually. Most regulators don't seem to care atm, or are targeting big companies. I'm not a lawyer, but I've worked on software in this field, so take what I say with a grain of salt.
Apple’s analytics data include an ID called “dsId”. We were able to verify that “dsId” is the “Directory Services Identifier”, an ID that uniquely identifies an iCloud account. Meaning, Apple’s analytics can personally identify you. Apple states in their Device Analytics & Privacy statement that the collected data does not identify you personally. Even if legal, this is obviously a very bad look for a company that cl…
Apple is only about privacy as a marketing differentiator. Apple's software clearly demonstrates that they do not place a high value on user privacy. iPhones and Macs phone home constantly with all sorts of information even if you never use iCloud or the App Store or Apple's service offerings. It's ridiculous.
Yep. Set up Charles Proxy (GUI) or mitmproxy (CLI) if you want to take a look at the actual data. It's huge and non-stop. Some of this even Little Snitch can't stop because it's sent to random IPs inside huge blocks belonging to Apple with no DNS. Unless you go to extraordinary lengths it's the same with Firefox FYI.
These companies' privacy concerns are a marketing gimmick, and the situation is so out of control we have to be thankful even for those crumbs.