Live data from Hacker News

Privacy: Is That iPhone?

foundation.mozilla.org

141–150 of 188 posts

Re: Privacy: Is That iPhone?

#142
post #66

Earlier quoted context omitted.

You don't need an IDFA to track someone in the same app. You can generate your own UUID to use. The value of the IDFA comes from coordinating user behavior across apps. Targeting ads is one use case, but it is also used in conversion tracking, which is very valuable to advertisers. They can know if ads in one app resulted in people buying things in another app. Edit: fixed typo

The point is that the app can just record the old IDFA, and when the IDFA changes whoever is doing the comparison between two apps knows that the old and new IDFA are one and the same.

What I think is that if the ID would be reused this would be kinda eliminated? I don't see a reason to not make them reusable.

Re: Privacy: Is That iPhone?

#143

Earlier quoted context omitted.

Did you… print out a screenshot of your phone?!

I applied filters and took a screenshot of the screenshot to reduce image fidelity in case it contained any [covertly embedded]* identifying information [in the form of watermarks or hidden pixels] . *added for clarity.

So now everyone who sees an iPhone screenshot treated in such a way knows it's you, as there are probably not a lot of people who are paranoid about tracking pixels in their iOS settings menu.

Re: Privacy: Is That iPhone?

#144

Earlier quoted context omitted.

I applied filters and took a screenshot of the screenshot to reduce image fidelity in case it contained any [covertly embedded]* identifying information [in the form of watermarks or hidden pixels] . *added for clarity.

In case people aren't aware, such a thing _is_ possible. Companies have used steganography techniques in the past to secretly embed identifiers into movies and other visual content. It's been used to track down the movie leakers, for example. Another example; most printers covertly embed an identifier in their prints. I have a vague memory of a pre-release video game doing it? Or maybe it was just debugging informati…

>Another example; most printers covertly embed an identifier in their prints.

To be picky only colour printers, at least officially (though there are theories about similar ID for B/W laser printers):

https://en.wikipedia.org/wiki/Machine_Identification_Code

Re: Privacy: Is That iPhone?

#145
Oh yes the fun thing about iOS is that the browser is super private so Google & Co have a problem but the apps themselves are also rife with trackers and there is almost no limit to what they do and barely any way to block it. I mean they only banned screenshots being taken of actual users' screens, which basically means anything that's less worse than that still goes.

As a consumer I would love a good scandal that would force them to tighten up on in-app trackers as well. But it might hurt my employers.

Re: Privacy: Is That iPhone?

#146
post #40

Mozilla suggests resetting the IDFA once per month...but that seems pretty trivial to workaround? If an app you used previously starts up and sees that your IDFA changed, it's easy for that app to know that the old IDFA and the new IDFA refer to the same user! This tracking is all possible because iOS gives every app on the device the same IDFA (advertising identifier [1]). They can then correlate all your activity a…

There is in fact just such an identifier, it's called IDFV. ID For Vendor. It's shared between all apps from the same vendor, so your Facebook and Instagram apps know they're on the same device. Apple used to be quite strict that you had to actually have advertising in the app to ask for the IDFA permission. That seems to have disappeared.

There used to be a global ID that was free to use, then they switched to the vendor ID. The IDFA never had anything to do with the vendor ID and has way more checks. To me the vendor ID isn't that big of a problem.

Re: Privacy: Is That iPhone?

#147
post #2

To disable: Settings > Privacy > Advertising > Limit Ad Tracking You can also disable Location-Based Ads: Settings > Privacy > Location Services > System Services (at the bottom) > Location-Based Apple Ads Apple's ad tracking help doc: https://support.apple.com/en-us/HT205223 (Apparently they derive your gender based on your first name or the salutation on your iTunes account)

Remember to check that setting after each update, it often gets disabled after an update. I've pointed this out to Apple multiple times and its often fixed for a few releases until their fix regresses and the bug returns.

Re: Privacy: Is That iPhone?

#149

Earlier quoted context omitted.

A likely-good-enough fix would be for Apple to first make extremely clear that this is not allowed, then catch one ad framework/library provider violating the rule and ban every single app/publisher using it to ensure the rule is actually taken seriously.

How do you “catch” them? The ID is sent from the app and not in plaintext.

I imagine with the usual review process

Re: Privacy: Is That iPhone?

#150
post #136

Earlier quoted context omitted.

I strongly disagree. The intention may have been to avoid abrupt power downs but their implementation also made sure people upgraded their devices rather than buy a new battery because most people would never be able to imagine that a device could be slow because of a bad battery. This, IMO, was a dark pattern. A sudden power down would be clear indicator that something is wrong with the device while a gradual slow d…

Ok, you have a phone that got slower, but works. And you got phone which just switches off randomly. Which one are you more likely to replace sooner?

How about one that displays a message that the battery needs to be replaced?
Post reply on HN