Live data from Hacker News

Apple’s Anti-Tracking Plans for iPhone

foundation.mozilla.org

251–260 of 403 posts

Re: Apple’s Anti-Tracking Plans for iPhone

#251
post #204

Earlier quoted context omitted.

Ad fraud... How exactly is this my problem as a consumer? This sounds pretty much like a "you" (ad networks and advertisers) problem... So why should you be allowed to spy on me - who never defrauded any advertisers - to fix your problem?

> How exactly is this my problem as a consumer? When you use a service that is funded by advertising, the service only gets that funding because the advertisers trust that they are getting their ads in front of real users. Some advertisers are able to precisely measure the quality of their traffic, for example by seeing whether the traffic they get buys things, but most are in businesses where that's not possible (no…

Since you seem persuaded by ends justifying means, realize that better business models are impractical because online surveillance is so easy and lucrative. One of the biggest changes correlated with the rise of web toxicity was the rise of online advertising. Maybe coincidence, but I'd love to see what happens if surveillance becomes the exception not the norm.

Re: Apple’s Anti-Tracking Plans for iPhone

#252
post #179
post #120

Earlier quoted context omitted.

Can you explain how Apple’s anti tracking measures are going to hurt small business and make fraud easier?

Most of the time, privacy and fraud both benefit from the same changes. To prevent tracking online, you want your device to look just like everybody else's devices. To prevent fraud, you want devices to look different so you can tell when a device does not represent a real user. At the extreme, imagine if every person has a unique identifier that was automatically sent whenever they used any device: preventing ad fra…

By fraud you mean ad fraud?

Re: Apple’s Anti-Tracking Plans for iPhone

#253
post #179
post #120

Earlier quoted context omitted.

Can you explain how Apple’s anti tracking measures are going to hurt small business and make fraud easier?

Most of the time, privacy and fraud both benefit from the same changes. To prevent tracking online, you want your device to look just like everybody else's devices. To prevent fraud, you want devices to look different so you can tell when a device does not represent a real user. At the extreme, imagine if every person has a unique identifier that was automatically sent whenever they used any device: preventing ad fra…

>but if you had headless browsers loading the ads on your site no one would be able to tell that those views were not from real users.

There is literally nothing in the world I care about less than this.

Re: Apple’s Anti-Tracking Plans for iPhone

#254
post #179
post #120

Earlier quoted context omitted.

Can you explain how Apple’s anti tracking measures are going to hurt small business and make fraud easier?

Most of the time, privacy and fraud both benefit from the same changes. To prevent tracking online, you want your device to look just like everybody else's devices. To prevent fraud, you want devices to look different so you can tell when a device does not represent a real user. At the extreme, imagine if every person has a unique identifier that was automatically sent whenever they used any device: preventing ad fra…

> if you had headless browsers loading the ads on your site no one would be able to tell that those views were not from real users

What users actually care about protecting your propaganda based business model though? Sounds like it's pretty much your problem and you want to reduce privacy to make manipulating their behavior a bit more profitable.

Re: Apple’s Anti-Tracking Plans for iPhone

#255
post #244

Earlier quoted context omitted.

This all presumes that the advertising business needs this level of granularity to succeed. It doesn't. Advertisers can purchase fixed display ads on reputable sites by contracting directly with the site owner. They can also sponsor content creators and provide them with an affiliate code which the viewers can use to receive a discount. These mechanisms do not expose the advertisers to fraud.

> Advertisers can purchase fixed display ads on reputable sites by contracting directly with the site owner. But what is a fair price? That depends on the traffic, but we are positing that detection of "is this a real user" is not possible, right? Traditionally, advertisers have gone by Nielsen style ratings for broadcast media (pay people to track what they consume, extrapolate) and circulation numbers for print med…

> But what is a fair price? That depends on the traffic, but we are positing that detection of "is this a real user" is not possible, right?

Couldn't the price just be based on the actual payoff the advertiser gets (aka increased product sales)? The publisher is incentivized to set the maximum price that the advertiser will pay, and the advertiser is incentivized to get the most bang for their buck, so at the very least they would never pay more than what the ad brings them in terms of revenue.

Over time, this should reach an equilibrium. Niche publications may have to charge low prices at the start as they build their reputation among advertisers, but I think that's a worthwhile price to pay if it means better privacy and eliminating a problematic advertising model of CPM/CPC (where fraud is possible and tracking is required to battle it).

Re: Apple’s Anti-Tracking Plans for iPhone

#256
post #219

Earlier quoted context omitted.

Short answer: apps are signed with a developer's certificate they get from Apple; the OCSP check for certificate validation went down. To put this in context, whenever you connect to a secure website, OCSP is used to make sure the certificate is still valid (unless OCSP stapling is used, but that's another issue). BTW, OCSP checks are unencrypted, but Apple says it will change to an encrypted protocol. And it wasn't…

> To put this in context, whenever you connect to a secure website, OCSP is used to make sure the certificate is still valid This is not how any browser implements it today. Browsers either do not check (Chrome, Safari) or check but fail open (Firefox, Edge). I'm not aware of any browser that fails closed in its default configuration. More: https://www.ssl.com/article/how-do-browsers-handle-revoked-s... Browsers prim…

Not CRLs, or rather, not directly.

Mozilla and Chrome have schemes to send a subset of revocations from the browser vendor to the user, Mozilla's is named OneCRL, the Chrome one is CRLSets.

For most websites if your end entity leaf certificate is revoked for some mundane reason Chrome likely simply won't know or care and it'll still work, because you aren't covered by CRLSets as the data would be too huge.

The long term fix, which site owners can implement, is OCSP Must Staple. What happens there is, when you request a certificate you insist on this "extension" and the extension tells client software "This certificate is only valid if accompanied by an up-to-date OCSP response". Then you set your server software to fetch OCSP responses for its own certificate and serve those to visitors.

This means excellent privacy (PornHub's certificate issuer still knows that PornHub is PornHub, not an invasion of privacy, and PornHub still knows that PornHub visitors visited PornHub, but the issuer doesn't learn who the visitors are) while being revocable (if the issuer provides REVOKED OCSP answers then you can't show that revoked certificate to a client once the last not-REVOKED OCSP answer expires)

Unfortunately, and this is a huge shame most especially for Apache, there are a lot of HTTPS servers that got OCSP Stapling badly wrong, meaning you need newer versions of software or have to install complicated workarounds because the early implementations were so stupid.

Re: Apple’s Anti-Tracking Plans for iPhone

#257
post #179
post #120

Earlier quoted context omitted.

Can you explain how Apple’s anti tracking measures are going to hurt small business and make fraud easier?

Most of the time, privacy and fraud both benefit from the same changes. To prevent tracking online, you want your device to look just like everybody else's devices. To prevent fraud, you want devices to look different so you can tell when a device does not represent a real user. At the extreme, imagine if every person has a unique identifier that was automatically sent whenever they used any device: preventing ad fra…

Google’s inability to protect its core revenue stream is squarely in the “not my problem” category. In fact, making internet advertising less desirable for businesses sounds like a benefit to me.

So, Apple’s decision is looking even better to me now.

Re: Apple’s Anti-Tracking Plans for iPhone

#258
post #213

Earlier quoted context omitted.

How do you propose to target ads without mining peoples' data?

One of the most common cases of targeting ads is remarketing: someone comes to your site, they start the process of buying a tablesaw but then leave for whatever reason. You pay to show ads of the saw so they can come back and finish their purchase if they want to. Traditionally, this has been implemented with third party cookies. The retailer drops a cookie on the users browser, and then buys ads to be shown to anyo…

> they start the process of buying a tablesaw but then leave for whatever reason

Is that something that people want?

Imagine someone wants to buy a table saw and their requirements changed and they no longer need it. It would be pretty annoying to have table saws follow them around the internet when they literally don't need them (and get in the way of other ads they would potentially be interested in).

It's also a privacy issue; if someone is searching for certain sensitive items they'd rather not have those follow them around for weeks down the line.

Re: Apple’s Anti-Tracking Plans for iPhone

#259

Earlier quoted context omitted.

One important implication of not using full encryption is that it protects users from themselves. If a user forgets their password, Apple can still unlock their data. From a security perspective, this obviously isn't ideal. But, from the perspective of the average user who has lost all of their data, this is great.

I should be given the choice to turn it on though. I understand Apple not wanting to deal with the annoying customer who forgets their password, loses everything, and blames Apple. I’ve seen enough forgotten password people while waiting at the Genius Bar to sympathize with Apple. But just because some of their customers can’t handle the responsibility doesn’t mean none of their customers should have the option. I en…

It is very typical of Apple, unfortunately, to leave out power features in order to focus on excelling at the basics. I switched to an iPhone from a rooted Android a few years ago, and while I do miss that level of control, I don't have to worry about the overhead that that type of Android device commands.

Re: Apple’s Anti-Tracking Plans for iPhone

#260
post #87

Earlier quoted context omitted.

> shameful that a device that is marketed as the gold standard in privacy It's being marketed this way, that's it. It doesn't mean Apple care about privacy, and they prove every once in a while that they don't respect anyone's privacy at all. They spy on their users as much as anyone else (and overall, they have access to much more information than everybody else except Google). All they want to do is prevent third-p…

> They spy on their users as much as anyone else (and overall, they have access to much more information than everybody else except Google). This is easily disproven by making a GDPR access request to see what various companies have retained on you, or if you’re extra paranoid inspecting what the device is sending back over the network.

> making a GDPR access request

Facebook collected data for ages using their SDK and lists of e-mail addresses/phone numbers submitted to them by advertisers but only started exposing them in their "download my data" tool (their GDPR SAR process basically) relatively recently.

GDPR access requests don't always tell the truth, often due to malice but in some cases incompetence too (there were a couple of times where my GDPR complaints have actually revealed to the company that their third-party SDKs leaked more data than they originally thought).

Post reply on HN