Live data from Hacker News

Loupe – A iOS app that raises awareness about what native apps can see

github.com

221–230 of 263 posts

Re: Loupe – A iOS app that raises awareness about what native apps can see

#221

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

Because 99% of apps would request it & not function without it, desensitising users into blindly accepting it. Most apps do have a legitimate reason for accessing the internet, so a binary yes/no wouldn’t achieve much anyway. I just don’t think it’s an effective way of solving the problem.

[deleted]

Re: Loupe – A iOS app that raises awareness about what native apps can see

#222
post #22

Earlier quoted context omitted.

Pasteboard counter exists to help apps to not ask again about the same item in the buffer. And nothing stops from using reset it every day.

Why do you need a count for that? Couldn’t they just generate a UUID every time the clipboard changes?

That’s even worse - now you have a tracking UUID that only changes when the user copies something.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#223
post #8

Damn. The "iPhone last setup or erased on ..." is really nasty. What can a user really do about that? I feel like this should be fudged somehow by the OS.

Maybe I'm being really thick, but why is this information that the OS would make available to apps?

It's likely allowed in some miscellaneous permissions file from a bygone era. The lines are probably over a decade old now.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#224

Earlier quoted context omitted.

100% of users have legitimate reasons to block internet access for some apps. If internet access wasn't granted by default, a lot more apps would function without it. Many other apps wouldn't exist at all, because their only reason to exist is to spy on users.

Not going to lie, it would be an absolute hell to develop an app that's actually used without getting crash/analytics.

Surely this could (or should) be facilitated through the app store.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#225

Yeah what's worse... I have a LG modern TV. Smart shit. I also use a Linux install on a NUC. HDMI. For some godsdamned reason, the TV was able to initiate an IP bridge with the Linux NUC and get an IP address on my network. Nobody typed it in the TV. And I'm unsure how it did so itself. What I do know is that Mikrotik allows DHCP-server blocks of wildcard MAC addresses. Blocked the whole fucking 24 bits of their allo…

This would be quite the scandal if you can substantiate/document it. People always say, "jUsT dO nOt CoNnEcT your TV to you WiFi" which is asinine. People say that theoretically TVs can get an internet connection through HDMI, but apparently none are actually doing so. The only solution I suggest is physically removing WiFi cards from the guts before turning on.

> theoretically TVs can get an internet connection through HDMI

What?! How on earth would this work?

Re: Loupe – A iOS app that raises awareness about what native apps can see

#226

Earlier quoted context omitted.

This is probably Keychain, right?

Probably, the most stupid thing with apple is there is no way to clear this keychain AFAIK without resetting whole phone.

[dead]

Re: Loupe – A iOS app that raises awareness about what native apps can see

#227

Earlier quoted context omitted.

Again, why is this something that an app would need access? The next test under the creation timestamp value is a test for getting the UUID of the volume. Again, why is an app allowed to access the unique identifier? Apple knows this type of thing is precisely what deanonymizing people would drool over, so why is this accessible. What part of iOS would even need to know this for a legitimate purpose? Are these calls…

To stop people from using apps they haven't paid for. As an honest person, if you want to use an app, you'd pay for it. Unfortunately, not everyone out there is honest, and there are various ways to get around having to pay for an app that costs money. Fingerprinting the device lets sellers of software find people who didn't pay for the software but are somehow using it.

I really hope you're being facetious. It' be pretty clever if you were, but for those that think this is serious...

If you want someone to pay for an app, don't make it free with in-app purchases. This is not something allowing for the OS to provide a unique identifier that can be abused available to app developers. App developers cannot be trusted. At. All. Ever.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#228

Earlier quoted context omitted.

This would be quite the scandal if you can substantiate/document it. People always say, "jUsT dO nOt CoNnEcT your TV to you WiFi" which is asinine. People say that theoretically TVs can get an internet connection through HDMI, but apparently none are actually doing so. The only solution I suggest is physically removing WiFi cards from the guts before turning on.

> theoretically TVs can get an internet connection through HDMI What?! How on earth would this work?

It was introduced in the HDMI 1.4 specification.

https://en.wikipedia.org/wiki/HDMI#Version_1.4

Re: Loupe – A iOS app that raises awareness about what native apps can see

#229

Earlier quoted context omitted.

Which politician? I want to read more

https://en.wikipedia.org/wiki/2025_shootings_of_Minnesota_le... search for 'data broker' in page. Nightmare world we live in.

If this had happened to a right wing politician there would immediately have been federal legislation exempting politicians from data tracking

Re: Loupe – A iOS app that raises awareness about what native apps can see

#230

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

Because 99% of apps would request it & not function without it, desensitising users into blindly accepting it. Most apps do have a legitimate reason for accessing the internet, so a binary yes/no wouldn’t achieve much anyway. I just don’t think it’s an effective way of solving the problem.

Internet access could be on by default for apps, with no prompt, but a toggle in Settings.
Post reply on HN