Earlier quoted context omitted.
What do you think are the possible issues for full encryption of iCloud backups?
One important implication of not using full encryption is that it protects users from themselves. If a user forgets their password, Apple can still unlock their data. From a security perspective, this obviously isn't ideal. But, from the perspective of the average user who has lost all of their data, this is great.
Apple’s Anti-Tracking Plans for iPhone
271–280 of 403 posts
Re: Apple’s Anti-Tracking Plans for iPhone
#272Apple is the best huge corporation when it comes to protecting user rights. I would have gone “all in Linux and alternative phones” if not for Apple’s current policies. They would lose me as a customer if they change, but I don’t expect them to do that.
Re: Apple’s Anti-Tracking Plans for iPhone
#273Earlier quoted context omitted.
I would be thrilled if online advertising became unviable as a business model. Most of what makes the web suck today (megabytes of javascript on every page; clickbait articles; outrage-driven social media; warehouses of PII waiting to be bought/sold/stolen) is because of advertising. Yes, I do want to pay for the services I use.
How would you pay for the services and content you consume?
Re: Apple’s Anti-Tracking Plans for iPhone
#274Earlier quoted context omitted.
This is about tracking your internet activity, not physical location/movements.
Your carrier has that correlation. They route all your packets. It doesn't matter if it is Comcast at home or Verizon/Att on the go. They know where you live and work and track you 24/7. Facebook is simply going to make a deal to have a unique ID added to URL metadata and then tracking is even more trivial. We need legislation to guarantee true net neutrality. Just like the electric company doesn't track/sell what I…
At minimum you should be using https. Your ISP could generally know the domains you are communicating with (when and how much), but not about what. They also could not add metadata to requests. The ad tracking we're talking about in this post really needs those details, so the ISP isn't in a position to enable the kind of tracking Apple is blocking here.
You can go further and use a VPN. Then all your ISP knows is that you use a VPN, but would not be able to tell anything else. Of course, you need to trust your VPN provider (including to properly secure their service), but if you're paying for one, at least your interests are aligned. (You pay your ISP, but they operate as semi monopolies and your privacy is not their primary business concern, so your interests don't really align that well.)
I agree about not allowing ISPs to sell data, though I think it would be OK if properly anonymized.
Re: Apple’s Anti-Tracking Plans for iPhone
#275Earlier quoted context omitted.
Most of the time, privacy and fraud both benefit from the same changes. To prevent tracking online, you want your device to look just like everybody else's devices. To prevent fraud, you want devices to look different so you can tell when a device does not represent a real user. At the extreme, imagine if every person has a unique identifier that was automatically sent whenever they used any device: preventing ad fra…
>but if you had headless browsers loading the ads on your site no one would be able to tell that those views were not from real users. There is literally nothing in the world I care about less than this.
Advertisers pay publishers to show their ads to real users. Publishers run their sites because they receive money from advertisers. We visit the sites because they're diverting/informative/useful/etc. If the advertisers can't tell whether their ads are instead shown to robots, the whole thing falls apart.
I like the trust tokens proposal as a way to exclude bot traffic without tracking: https://web.dev/trust-tokens/
Re: Apple’s Anti-Tracking Plans for iPhone
#276Earlier quoted context omitted.
Having been on both sides of the table, I would slightly disagree here. Fraud prevention for example will get an order of magnitude harder, plus this move will further skew the playing field towards FAANG who have the resources to puzzle the scraps back together for decent conversion tracking with the help of logins, IPs, SDKs with First Party IDs and a massive dose of machine learning.
I don't know why you use a big word such as "fraud" when you mean "we want to be able to know which accounts are owned by the same person".
So why are they deploying the term? Because it's a great way to deflect thinking about a core failing of their business logic. We've known since the day of banner ads that 'views' are a tremendously flawed metric, so blaming online agents for WHY they're flawed lets them deflect blame.
The fact that we're in this thread trying to parse semantics when consumers don't even have a seat at the table when deciding where we should fall on the tracking/privacy spectrum should tell you all you need to know about how the industry operates.
Re: Apple’s Anti-Tracking Plans for iPhone
#277To what extent are iPhones fingerprinted though? As we’ve seen with websites even no unique id is not necessarily game over
You can test your device browser fingerprint here: https://coveryourtracks.eff.org
Re: Apple’s Anti-Tracking Plans for iPhone
#278Earlier quoted context omitted.
That's true, they do provide data to governments in compliance with local laws. Criminalising your employees isn't a good look.
they also don't encrypt when laws actually enables to encrypt... https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv... Besides, haven't facebook and google got ban from China because for not compiling with Chinese law?
Web services companies face a ton of problems operating in China that are really specific to the kinds of services they offer. Apple simply doesn't offer those kinds of services.
Re: Apple’s Anti-Tracking Plans for iPhone
#279In Europe, cross-app, cross-browser & cross-device tracking is on very thin ice legally under the GDPR, so I'm not surprised Apple finally curbs the use of "sticky" identifiers on their devices. Honestly, it's a bit shameful that a device that is marketed as the gold standard in privacy would even support such an identifier in the first place, it has literally no purpose beyond mining peoples' data. Now that the thir…
Having been on both sides of the table, I would slightly disagree here. Fraud prevention for example will get an order of magnitude harder, plus this move will further skew the playing field towards FAANG who have the resources to puzzle the scraps back together for decent conversion tracking with the help of logins, IPs, SDKs with First Party IDs and a massive dose of machine learning.
Also: boohoo
Re: Apple’s Anti-Tracking Plans for iPhone
#280Earlier quoted context omitted.
> Advertisers can purchase fixed display ads on reputable sites by contracting directly with the site owner. But what is a fair price? That depends on the traffic, but we are positing that detection of "is this a real user" is not possible, right? Traditionally, advertisers have gone by Nielsen style ratings for broadcast media (pay people to track what they consume, extrapolate) and circulation numbers for print med…
> But what is a fair price? That depends on the traffic, but we are positing that detection of "is this a real user" is not possible, right? Couldn't the price just be based on the actual payoff the advertiser gets (aka increased product sales)? The publisher is incentivized to set the maximum price that the advertiser will pay, and the advertiser is incentivized to get the most bang for their buck, so at the very le…