Live data from Hacker News

Apple allows some iOS apps to track user locations via lists of nearby SSIDs

wingu.se

241–250 of 327 posts

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#241
post #149
post #124

My most blocked domain in nextDNS (which runs on all my devices) is metrics.icloud.com. books-analytics-events.apple.com is in the top 5 as well.

Hmm … I don’t see that in my nextdns logs. Is that a custom block you put into place or are you using a different filter list then I am?

I’ve got the native blocking ruleset for Apple added.

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#242
post #222

Earlier quoted context omitted.

I've asked similar questions before and am usually told that this is how Apple does things and it's what makes their users happy. It's in fact why they love and choose Apple. They trust Apple to make the right decisions, and this is in fact a big part of the value add of their products. This is much related to the walled garden approach. For example, ask about why sideloading should remain not an option at all, rathe…

This mentality is fascinating to me. In a sense, nobody owns an Apple device. It's more like renting: the landlord keeps a bunch of doors locked and has strict rules, but the place comes pre-furnished and includes millennial-grade amenities. I can see the appeal if you don't particularly care about owning a device, but it blows my mind that people become so dedicated to this way of living.

It's unlikely that if you have a mobile phone, the landlord doesn't keep some doors locked.

At minimum - even if you're running de-Googled Android - the baseband blob has high levels of access and you have no control over it.

I'm not saying Apple isn't worse with this, but the illusion of phone ownership spreads a lot further.

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#243
post #220

Earlier quoted context omitted.

I've asked similar questions before and am usually told that this is how Apple does things and it's what makes their users happy. It's in fact why they love and choose Apple. They trust Apple to make the right decisions, and this is in fact a big part of the value add of their products. This is much related to the walled garden approach. For example, ask about why sideloading should remain not an option at all, rathe…

It’s not that I trust Apple, it’s that I trust Apple infinitely more than I trust the largest spy network on earth and existing without a smartphone today is difficult. If you need a smartphone, you can choose between a company that has some missteps, or a demonstrably evil spy network. I know who I am choosing.

Thanks, your position certainly makes sense to me regarding a Pixel phone with the stock software on it, but much less so when considering options like GrapheneOS or any of the Androids made by other non-Google companies (like OnePlus, etc). That's the point at which usually "user experience" or "I'm already in the Apple ecosystem" usually come to fore-front as the reason.

I don't really trust of those big companies, which is where GrapheneOS really shines. Open source, lots of enhanced privacy controls, but also as much of the Google ecosystem as the user wants. If you maximally distrust everyone, you can roll with pure FOSS. If you're somewhere in the middle like most people, you can pick and choose the pieces that are worth it to you (Google's Pixel Camera app is a common one for example). Graphene OS is also trivial to install now thanks to the web installer, so pretty much anybody who can load a web page, plug in a USB cable, and follow the explicit instructions to unlock the bootloader (which is stuff like, "open settings" -> "click about", etc) can do it.

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#244

My iPhone asks if I want to allow an app to access the Local Network. I assume that this 1) means that Apple does cover this situation and 2) my opinion that the phrasing "Apple allows applications to track user locations without authorization" is contemptible are both true.

I think that prompt is for something different.

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#245
post #195

Earlier quoted context omitted.

It’s a pretty obscure API, and Apple has a strong interest in at least being perceived as pro user privacy. And assuming for a second this is indeed an intentional backdoor in plain sight of the world: What’s in it for Apple? Hanlon’s razor still cuts in 2023, at least for me.

>Apple has a strong interest in at least being perceived as pro user privacy. Perceived is doing a lot of lifting there. The public largely cannot audit Apple's ACTUAL security.

That’s true, but arguably irrelevant here since this is a public, documented API that can be audited.

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#246
post #194

Earlier quoted context omitted.

Centralized superapps seem incredibly dangerous to privacy, given that the limited mobile privacy models are designed around per-app permissions. 1. Create app that does 1 thing 2. Add more features to app 3. Abuse superset of permissions 4. Gov leans on app owner 5. Gov abuses superset of permissions

I think if you're in China the centralized superapp is the least of your worries, privacy-wise. I agree that this is probably part of why these things will never really take off in the US though (no matter what Elon wants to wish for).

It is not the least of your worries, it is the abusive system working as intended. It is policy of the Chinese state to ingratiate itself into every aspect of its citizens' lives to exert control.

The fact the State is wholly evil in other ways does not lessen the worry; it multiplies it.

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#247
post #210

Earlier quoted context omitted.

As a developer, the annoying thing about the "Local Network" permission is that: 1) It's poorly implemented. Unlike other permissions, there's no way to explicitly trigger the prompt. It just pops up at Apple's discretion. There's no way to give it a "soft landing" for cases where it's necessary for core app features. And there's no way to check if the permission has been granted or not. 2) More importantly: Apple's…

The developer of the Camera app already has access to all the photos in your Photos app. What benefit would a prompt have for the user?

Not sure if this is what you mean, but there could be multiple apps installed that write to the device photo library. You may not want the developer of one camera app to be able to access all photos on the device.

But this raises a related point about how frustrating Apple's APIs are here: When an app is granted the "Write to photo library" permission by the user, it can only write. It can't read back what it's written, ever. You might expect that writing to the library might return a token that can be used to read that photo back. Nope.

Android, for all its faults, does a much better job here. The OS keeps track of the app that wrote the photo -- and that app can read that photo indefinitely, unless another app edits that photo (and thus becomes the owner). A much better design.

On iOS, to read back photos from the library, you have to ask for the "All photos" read permission, which few people will grant you. "Why does my camera want to read all the photos on my device?! Deny!".

And just like that, you can't compete with the built-in camera which shows thumbnails of recently taken photos and allows you to swipe through them.

Apple has no incentive to fix this either, because their own apps bypass this permission system.

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#248

Earlier quoted context omitted.

You want to change your location in every app manually, even when your device has a GPS receiver installed?

As someone who keeps GPS off, absolutely. Not that I think I can trust the phone actually disabled the GPS, but there is no reason my movements need to be tracked and recorded in detail. Make them go through the effort and pull up all the cellphone towers I ping. Day to day, there is a very good chance I am still in my home city as first configured.

What percent of users would agree with you, in your estimation?

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#249

Earlier quoted context omitted.

It's so hard to prioritize non-profits these days. EFF is huge and super relevant, but so are aid programs to Ukraine or I/P, and reproductive health orgs. There's a lot going on I want to contribute to.

I wonder if there is a service to automate small (or large) donations to multiple organizations on a regular basis similar to an investment service? Edit: I can only find services marketed towards the nonprofit, not for the donor. A service that aggregated and automated all the nonprofits I want to regularly donate small amounts to would be great. I think it would be important to not require the nonprofits direct inv…

https://www.charitynavigator.org/donor-basics/tools-for-givi... How's this look?

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#250

Earlier quoted context omitted.

Seems like Apple should give users the ability to download an app while rejecting an entitlement.

You can. iOS apps have to request individual permissions - I'm not sure about the specific level of granularity here, but you can deny location access while still letting the rest of the app run, and the app has to be able to deal with it.

As I understand it, this SSID feature does not require location services permissions.
Post reply on HN