Live data from Hacker News

Apple allows some iOS apps to track user locations via lists of nearby SSIDs

wingu.se

281–290 of 327 posts

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#281

Whenever location data collection comes up, I always think about that Seinfeld episode where Kramer is receiving misdialed MovieFone calls -- at first he just talks to the person and reads the movie times out of the newspaper. Very helpful. Eventually, he starts emulating the phone menus, asking the caller "Using your touch-tone keypad, please enter the first three letters of the movie title, now." When this doesn't…

You want to change your location in every app manually, even when your device has a GPS receiver installed?

Not every app -- but I feel like different apps demand different techniques, and tend to descend the gradient from most-intrusive to least in terms of permissions. That said, I'm not a privacy freak; I have no personal qualms about approving location services for a lot of apps. Go nuts, I don't care.

For instance, mapping or Waze needs your current GPS coordinate at all times. This doesn't bother me because I'm being tracked myriad other ways, even if I don't give permission -- cameras in every gas station and store, license-plate-reading cameras on police cars and traffic lights, StarLink in my Subaru, the SSID technique described in OP blog, credit card transactions at the pump, GPS coordinates from a passenger who did grant permissions (and we happen to be Instagram friends, so we're forever connected), an AirTag hidden in my gas tank, on and on and on.

It might seem like overreach for a paranoid person to need to grant location services to Papa Johns to order pizza, but that app may have legitimate reasons: expedited discovery of the nearest brick-and-mortar, realtime delivery tracking, order-abuse prevention or prediction (why are you placing orders repeatedly to locations all over the country, even if they're prepaid?), unwanted, craven marketing, backend revenue streams selling your data to Satan, etc.

Other types of apps, like Nextdoor or Tinder, don't actually need your exact location. They need to know generally where you are, but having precise coordinates isn't in the best interest of the user (see recent Feeld disaster where exact locations were prominently displayed on profiles [0]). On top of that, Nextdoor revolves around the neighborhood you live in; if you're traveling, it shouldn't update the feed based on your current location, nor let you join neighborhoods you're visiting in a transient manner just because of a GPS coordinate.

Then, consider that native-OS permissions popups are obtuse at best; many people simply want to have some tactile understanding of their choices.

My 70 year old father could understand if an app asks "Hey, generally where are you located? I'll send you coupons" and he can reply "XYZ, State" once, and that's the end of that. A boilerplate permissions modal that doesn't explain the difference between precise and approximate location, while simultaneously not visually showing what "approximate" even means (is it a loose radius centered on your precise location? how loose exactly? or is it a tile on a fixed grid? is it the entire city? etc) to him is no different than just constantly polling GPS+SSID in the background. "THEY know where I'm at!"

What I'm really getting at is most app permissions have terrible UX/UI, and operate opaquely.

It is not at all clear what you're sharing and with whom, and they tend to have three options: 0%, 1% and 100% (no access, access to one photo at a time when you choose, or access to every photo on your device; no location, give your location once and never be able to view what you submitted or update it, or precise location at all times, etc).

What if I only want to receive a specific segment of a brand's communications? (ex. let me know about upcoming events, but I'm not interested in new merch). Any bozo can implement that for an app that's willing to actively categorize their communications, but most have no interest in taking on the responsibility.

It's just a shame that users and user experience are rarely considered when designing most apps and websites. Corners are cut by design, liability is aggressively and intentionally limited from the top down, and decisions are made for structural and financial reasons at the expense of the humans wasting their time or money using any given app, when it could be so much better (with less effort!)

[0] https://mashable.com/article/feeld-app-down

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#282
post #59

Earlier quoted context omitted.

Why does apple get to decide which app gets automatic access to my private data, on my device, without needing to ask me?

I've asked similar questions before and am usually told that this is how Apple does things and it's what makes their users happy. It's in fact why they love and choose Apple. They trust Apple to make the right decisions, and this is in fact a big part of the value add of their products. This is much related to the walled garden approach. For example, ask about why sideloading should remain not an option at all, rathe…

You’re missing a probably sizable fraction of Apple users that don’t love this, but also don’t hate it enough to switch to something else for that reason alone.

It’s very similar to political parties: I have yet to find one that I 100% align with in all things, yet I still vote.

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#283
post #49
post #5

Earlier quoted context omitted.

That’s not really any consolation, since (according to the article) Apple has granted that entitlement to WeChat and Alipay. Yes, these are “super-apps” and Wi-Fi hotspot services are probably part of their offerings, but that’s just more reason this should be a user-grantable permission like “local network access”. If I don’t care for the hotspot feature, I don’t want the app to have that capability.

Certain apps have always gotten special treatment. If it’s big enough to mess with phone sales they’re allowed nonsense a normal dev would be permanently banned for. Ex: all the stuff FB has been caught doing over the years My understanding (no first hand experience) is that WeChat and Alipay are basically required in China. If a phone doesn’t have them, it’s worthless and won’t sell. So naturally they too can do non…

They are required in China, but the hotspot functionality isn’t. At least give me an option to turn it off.

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#284
post #222

Earlier quoted context omitted.

I've asked similar questions before and am usually told that this is how Apple does things and it's what makes their users happy. It's in fact why they love and choose Apple. They trust Apple to make the right decisions, and this is in fact a big part of the value add of their products. This is much related to the walled garden approach. For example, ask about why sideloading should remain not an option at all, rathe…

This mentality is fascinating to me. In a sense, nobody owns an Apple device. It's more like renting: the landlord keeps a bunch of doors locked and has strict rules, but the place comes pre-furnished and includes millennial-grade amenities. I can see the appeal if you don't particularly care about owning a device, but it blows my mind that people become so dedicated to this way of living.

I think you greatly overestimate how big of a deal this lack of user choice is to most people.

Nobody needs to be dedicated to a lack of choice/freedom for Apple's business model to work.

Being begrudgingly ok with it works just as well, just like they don’t price their products at “oh wow, that’s a steal, I’ll take one as a spare”, but rather somewhere close to “oh wow, but I guess I don’t buy this every day, and maybe with an installment plan…”

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#285
post #222

Earlier quoted context omitted.

This mentality is fascinating to me. In a sense, nobody owns an Apple device. It's more like renting: the landlord keeps a bunch of doors locked and has strict rules, but the place comes pre-furnished and includes millennial-grade amenities. I can see the appeal if you don't particularly care about owning a device, but it blows my mind that people become so dedicated to this way of living.

It's unlikely that if you have a mobile phone, the landlord doesn't keep some doors locked. At minimum - even if you're running de-Googled Android - the baseband blob has high levels of access and you have no control over it. I'm not saying Apple isn't worse with this, but the illusion of phone ownership spreads a lot further.

Not to get too philosophical, but the entire concept of ownership per se is always a social contract that's being renegotiated continuously by society. Almost every country in the world has limits on the things you can own, to give just one example.

I do see the value of having autonomy over the devices I conduct my digital life on (whether owned or rented, for that matter!), but I'm not sure if the concept of physical ownership is the right model here.

How my personal data is being processed in other people's and the government's systems is just as relevant to me, and conversely, I'm fine with some opaque blobs of other people running on my hardware, as long as they're properly sandboxed (i.e. can't phone home freely or access any of my data that's none of their business), and I see the mutual benefit in them.

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#286
post #173

Earlier quoted context omitted.

It wants precise location — which I take to mean war-driving WiFi. GPS I am okay with for a map app.

IIRC, Non-precise location is cell tower level location or the like, possibly a 12 square mile area. It is also very cheap if the device is already connected to a tower. Precise location may be from Apple's SSID database or from a GPS system. Non-precise location may help with getting more appropriate search results but won't help you with turn-by-turn navigation.

Reading the documentation I can't figure it out. It sounds like there are a lot of things that feed into "Precise Location" that go beyond GPS. It could be true though that only cell-tower reckoning is used without "Precise Location". I generally only pull up Google maps on longer road trips that aren't really turn-by-turn, so maybe I have the only use case for a map with weak location services.

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#288
post #44

Earlier quoted context omitted.

That’s for sending and receiving local network traffic, eg. talking to devices on the same subnet, and discovery of Chromecast and similar targets. Edit: AirPlay does not require this permission.

I don't believe it is necessary for airplay, but probably is for Chromecast, Sonos, and many devices to establish ad-hoc connectivity for setup and operation. I take this popup to mean that they want to fingerprint and locate my home network or backdoor it somehow. I ALWAYS deny this access unless the app specifically requires it, and that is rare. WiFi based geolocationing should be a well known privacy threat by no…

[deleted]

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#289
turn off location services, your phone still contacts ls.apple.com

deep links, they go deeper than you think.

ibeacons provide very precise indoor location, think of all the behavioral data a store app can collect.

apple is not really your friend.

seriously, apple should let you

- know what is running

- know what network traffic happens

- control these thigns

- run your own programs

I would love an ios firewall program or non-neutered little snitch

Re: Apple allows some iOS apps to track user locations via lists of nearby SSIDs

#290
post #275

Earlier quoted context omitted.

Even if only genuine hotspot apps got the entitlement, it is not a user-friendly privacy-first design. Such API use should trigger a user-visible permission dialog before apps get background-notified and user should be able to select the one of "allow-once, allow while using, allow-in-background, never" and the app activity should show up in app privacy reports.

Not sure I agree - in fact pretty sure I don’t. Having lots of permission dialogs just trains users to mindlessly click yes on everything, because they just want to do the thing, not think about how the sausage is made.

So just don't have them, and don't let them think about it?
Post reply on HN