Live data from Hacker News

Loupe – A iOS app that raises awareness about what native apps can see

github.com

251–260 of 263 posts

Re: Loupe – A iOS app that raises awareness about what native apps can see

#251

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

It is opt-in on iOS for Applications. Applications have to declare upfront what sites they will communicate with.

It is called app transport security. if you don't set it up your app boots in a sandbox with no network.

Settings -> Privacy Security -> App Privacy Report

Unfortunately 1 - as a _user_ you cannot opt-in or out. I wish Apple would take the next step and let us select which sites an app is not allowed to communicate with. Or ideally even globally for all apps.

Unfortunately 2 - the list of sites the app wants to communicate with is not clearly communicated upfront like before you install.

Unfortunately 3 - the list can also contain wildcard domains

Small steps - they really need to push this to the next phase IMO.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#252
post #8

Damn. The "iPhone last setup or erased on ..." is really nasty. What can a user really do about that? I feel like this should be fudged somehow by the OS.

Seems like in general the iPhone was not designed to avoid fingerprinting from installed apps. Only protection would be avoid installing apps and use the web browser when possible.

Browsers are also a continuous finger printing target.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#253
post #16

Earlier quoted context omitted.

```Based on a binomial/Poisson distribution and a baseline of 21 million U.S. device sales per release, a fingerprint relying on "seconds since setup" fails to uniquely identify individuals. In the high-density Early Adopter phase, you will share your exact setup second with an average of 1.01 other people (a total matching pool of ~2 people). Six months into the cycle, you will still share that second with an averag…

Reminds me of a meeting I was party to with the Safari team. We worked with them on some standards stuff at an old job. They claimed to have creepy-level tracking of users back then. We were discussing how to identify users for an A/B test across millions of sites and comparing what fingerprints we could both derive to most likely end up on the same user. If you use a closed source browser. That’s the kinda shit they…

I call BS on that story

Re: Loupe – A iOS app that raises awareness about what native apps can see

#254

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

iPhones purchased in mainland China (with model number ending in CH/A) do provide options for setting per-app Internet access permissions. There are three options [0]: Off, WLAN only, WLAN and Cellular. [0] https://old.reddit.com/r/ios/comments/aib10i/in_china_ios_al...

Many Chinese users actually hate this feature because of how it's designed. There's a mandatory pop-up upon the first launch of every app to ask for your choice, which can be clumsy if you're setting up a new device. If you tap the wrong option (which is common since the dialog is small and crowded), you have to go deep into system settings to restore internet access. Moreover, many foreign app developers know nothing of this and have their apps throw an error even before a Chinese user has the chance to give permission, forcing them to manually kill and reopen the app to be online, adding to the errands.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#255

Earlier quoted context omitted.

> theoretically TVs can get an internet connection through HDMI What?! How on earth would this work?

It was introduced in the HDMI 1.4 specification. https://en.wikipedia.org/wiki/HDMI#Version_1.4

HDMI Ethernet was never adopted or implemented on consumer devices.

Re: Loupe – A iOS app that raises awareness about what native apps can see

#256

Earlier quoted context omitted.

To stop people from using apps they haven't paid for. As an honest person, if you want to use an app, you'd pay for it. Unfortunately, not everyone out there is honest, and there are various ways to get around having to pay for an app that costs money. Fingerprinting the device lets sellers of software find people who didn't pay for the software but are somehow using it.

I really hope you're being facetious. It' be pretty clever if you were, but for those that think this is serious... If you want someone to pay for an app, don't make it free with in-app purchases. This is not something allowing for the OS to provide a unique identifier that can be abused available to app developers. App developers cannot be trusted. At. All. Ever.

These aren't free apps. It's not theoretical that people are not paying for programs on iOS.

https://thepiratebay.org/search.php?cat=305&q=ipa

Re: Loupe – A iOS app that raises awareness about what native apps can see

#257
post #16

Earlier quoted context omitted.

```Based on a binomial/Poisson distribution and a baseline of 21 million U.S. device sales per release, a fingerprint relying on "seconds since setup" fails to uniquely identify individuals. In the high-density Early Adopter phase, you will share your exact setup second with an average of 1.01 other people (a total matching pool of ~2 people). Six months into the cycle, you will still share that second with an averag…

Reminds me of a meeting I was party to with the Safari team. We worked with them on some standards stuff at an old job. They claimed to have creepy-level tracking of users back then. We were discussing how to identify users for an A/B test across millions of sites and comparing what fingerprints we could both derive to most likely end up on the same user. If you use a closed source browser. That’s the kinda shit they…

Safari isn’t closed source…

Re: Loupe – A iOS app that raises awareness about what native apps can see

#258
post #246

Earlier quoted context omitted.

This would be quite the scandal if you can substantiate/document it. People always say, "jUsT dO nOt CoNnEcT your TV to you WiFi" which is asinine. People say that theoretically TVs can get an internet connection through HDMI, but apparently none are actually doing so. The only solution I suggest is physically removing WiFi cards from the guts before turning on.

HDMI ethernet channel is a thing, though semi-obsolete. It's unusual for a PC graphics card to support it. Intel website suggests they don't support it: https://www.intel.com/content/www/us/en/support/articles/000... Why is not connecting your TV to wifi asinine? Generally works fine but I suppose there are rumors that some TVs scan for open networks and connect to them automatically. > The only solution I suggest is…

Because it doesn't prevent anyone else from connecting your TV to any other WiFi (and apparently that actually happened to someone according to their comment in another HN thread).

Re: Loupe – A iOS app that raises awareness about what native apps can see

#260

Earlier quoted context omitted.

It was introduced in the HDMI 1.4 specification. https://en.wikipedia.org/wiki/HDMI#Version_1.4

HDMI Ethernet was never adopted or implemented on consumer devices.

Source?
Post reply on HN