Live data from Hacker News

Oh, the Places Your Apple ID Will Go

pxlnv.com

71–80 of 164 posts

Re: Oh, the Places Your Apple ID Will Go

#71
post #52
post #26

Earlier quoted context omitted.

Finally, someone puts words on the irks I felt the last times this came up. Thank you. Apple is basically loopholing all the shitty ad-tech engagement surveillance bs that plagues the rest of the industry through the app store, pretending like it's any other app. Of course they can, but a lot of the hard-line privacy stuff goes down the drain with the hypocrisy. What bothers me is that Apple really doesn't have to mo…

The public dismissal of the evidence these researchers presented in the last few weeks was surprising. It isn't truly important whether the App Store is an integral component of iOS, which it practically is until Apple becomes compliant with the provisions of the Digital Markets Act, it merely compounds their legal issues due to ignoring user intent when iOS analytics are disabled. The main issue here is that Apple h…

In the longer term Apple has a bigger issue here (though related to GDPR) : being a US company it's effectively illegal in the UE.

And after several attempts to pretend that US laws like the Patriot Act that remove non-US citizen rights were compatible with the EU Charter of Fundamental Rights have been struck down by the Court of Justice of the EU (after the US has been caught violating these rights) it's starting to be hard to imagine what kind of agreement can possibly happen between the USA and the EU that would make US companies legal again...

Re: Oh, the Places Your Apple ID Will Go

#72

I see a lot of very intelligent people here unable to agree upon a matter that seems, in essence, simple enough. That is in itself troubling and partly answers a question. If developers on Hacker News cannot fathom whether Apple deceptively transmitted PII, or whether zealous journalists are over-egging the pudding, then we have another problem. Obfuscation is a form of deception through complexity. It can be hard to…

Can you show me where obfuscation was mentioned? The DSID is transmitted clearly in many web requests from iOS. SSL isn't a form of obfuscation.

I don't think there's anything wrong in transmitting an ID to a web service, but I'm not actually sure what Apple claimed about privacy.

Re: Oh, the Places Your Apple ID Will Go

#73
post #21

This "Directory Services Identifier" is not sent outside of Apple's services though right? And only sent to Apple services that need to know the identity of the user? If so I'm wondering what the issue is here.

It seems a little more leaky than I'd expect: Because that identifier is also used in some iCloud API requests, I also spotted the same value in activity logs for third-party applications using things in my iCloud account, as well as in metadata for local copies of documents I downloaded from my drive at iCloud.com.

It's a little unclear what they mean here, but that can easily be because of a service/system server model. The third party apps use things like "icloud daemon" (not sure that one actually exists) which does the iCloud request and passes along the data back to the app. Because the logs are generated with a high privilege level, they are also including what icloud daemon did for those specific apps, but those apps did not get access to that DSID, it was kept internal to icloudd.

If the journalists or whomever wants to claim the DSID is leaky, then they need to show a POC with an app actually obtaining that DSID, and not only in a system logger that only saves files sandboxed locally, or sends to Apple.

Re: Oh, the Places Your Apple ID Will Go

#74
post #68
post #16

Earlier quoted context omitted.

A cookie is not a PII identifier, it is an "identity discriminator". In other words cookies let them tell you the _same_ person 104898 that was already here in March, welcome back!, and not any other person e.g. 298472, but without telling them your actual name etc. In contrast, a PII identifier is a unique ID that is linked to personal attributes in real life like a person's name ("John Doe"), address ("6400 Bouleva…

> VISA 4879 5223 6537 9935 I'm curious where that number came from. It passes the Luhn check so it probably isn't just some random number, and has the right first few digits for Visa but doesn't match any of the Visa test card numbers that I happen to know. Looking up the issuing bank from the first 6 digits gives inconsistent results. Half of the several BIN lookup sites I tried just say it is from the US. The other…

i have been following up on that and for me too the results where inconclusive.

My bet is, that is a honeypot card.

Oh and by now we are the first result on google for it too :D

Re: Oh, the Places Your Apple ID Will Go

#75
post #3

Isn’t this a misunderstanding of what PII is? An evil entity, given this couldn’t unmake me the way they could with a name, e-mail, or even IP

If it can be traced to a natural person, it is PII. IP addresses are PII, ids are PII. It is in the name "Personally Identifiable Information." If it can be used to personally identify you, it's PII. If you gave me this ID number, I could use it to locate your information in breached db dump, or if it is used in API requests, impersonate you.

No, that's not the definition of PII. That the ID maps to a person doesn't mean they know that person's SSN, which is PII.

IP counts as metadata. It uniquely identifies you as an entity but does not reveal other details except geographic location. If IP addresses are PII, then any use of the internet is violating your privacy. Perhaps unplug your modem, turn off cell service on all devices and read a book instead.

Re: Oh, the Places Your Apple ID Will Go

#76

Allegedly it’s fine because they’re collecting information for internal use and not sharing with third parties, but really the industry is trying to redefine tracking as cross service/site tracking. Well I think they should set the same bar internally

Why? What is the value in anonymizing your voluntary engagement within a single corporate entity? As long as that entity provides me with an accurate reporting of access when I request it? Why for example would I want to make it any more difficult for my doctor at a hospital and the hospital pharmacy to share my confidential health information to ensure I get the right treatment?

1) tech companies should not be Doctors. Apple is not a doctor. 2) there are additional privacy protections around medical uses, for these reasons.

Re: Oh, the Places Your Apple ID Will Go

#77
post #26

> I may be getting something wildly wrong here, but I am not sure I see the presence of this Apple ID proxy in Apple’s services logs to be a violation of either its own policies or users’ expectations for using internet services in general. I strongly disagree that the iOS App Store should be treated as an "internet service" rather than a part of the device. The iOS App Store only comes on iOS devices, it comes on al…

Finally, someone puts words on the irks I felt the last times this came up. Thank you. Apple is basically loopholing all the shitty ad-tech engagement surveillance bs that plagues the rest of the industry through the app store, pretending like it's any other app. Of course they can, but a lot of the hard-line privacy stuff goes down the drain with the hypocrisy. What bothers me is that Apple really doesn't have to mo…

> Apple is basically loopholing all the shitty ad-tech engagement surveillance bs that plagues the rest of the industry

That's a pretty extreme description of what's happening here. I agree that they should not be doing this, and that App Store analytics should be opt-in like the rest of the device analytics, however, they are not correlating your unique identifier with other web properties — i.e. when you visit through Safari. I also doubt they are selling that data to third parties, allowing ads to target you on the basis of it, or using it to build a profile against other application analytics.

In fact, it seems like the article says: they do no clever stuff with it whatsoever. They should remove it in a future update

Re: Oh, the Places Your Apple ID Will Go

#78

Earlier quoted context omitted.

I think this can be explained by simple denial; Apple's reality distortion field, or some variation on "It is difficult to get a man to understand something, when his salary depends on his not understanding it." Maybe not salary, but a foundational world view, much like religion. I mean, people on HN will argue that it's wrong to block ads, a point of view that only makes sense to me through the lens of the above quo…

> I think this can be explained by simple denial; Apple's reality distortion field, or some variation on "It is difficult to get a man to understand something, when his salary depends on his not understanding it." Maybe not salary, but a foundational world view, much like religion. My personal view, which I presume is the same as many others, is that these things keep being a "if there is smoke, there's fire" situati…

>"if there is smoke, there's fire

I want you to take that sentence and throw it away and instead have a mental paradigm shift.

"Where there is fuel there is risk".

One day when you have a lot of time look up the USCSB (United States Chemical Saftey Board) channel on youtube and look at the decade of very well done videos on deadly industrial disasters they have done. People will ignore risk for years accepting the danger because it's "always been that way", they will turn off alarms because they are annoying, they will bypass safety controls because they slow the task down.

I don't care how dangerous FB/Google/whoever is, Apple is its on seperate factory capable of blowing up in it's own spectacular fashion, and much like a gasoline refinery they are building up a massive amount of fuel that is at risk of a spark.

Re: Oh, the Places Your Apple ID Will Go

#79

Earlier quoted context omitted.

> Instead, all mega corps seem to blend together and follow the same playbook. It's sad. Yet another glaring indicator identifying our species as not mature enough to manage our own society. If this occurs everywhere, no matter what, then it is us, our constitution, our chemistry, our maturity as a species that is at fault.

This mental leap is a bridge to far for me to understand. Can you fill in the steps in your logic?

Probably not now that he's come down from whatever he was smoking.

Re: Oh, the Places Your Apple ID Will Go

#80
post #26

Earlier quoted context omitted.

Finally, someone puts words on the irks I felt the last times this came up. Thank you. Apple is basically loopholing all the shitty ad-tech engagement surveillance bs that plagues the rest of the industry through the app store, pretending like it's any other app. Of course they can, but a lot of the hard-line privacy stuff goes down the drain with the hypocrisy. What bothers me is that Apple really doesn't have to mo…

> Instead, all mega corps seem to blend together and follow the same playbook. It's sad. Yet another glaring indicator identifying our species as not mature enough to manage our own society. If this occurs everywhere, no matter what, then it is us, our constitution, our chemistry, our maturity as a species that is at fault.

Not really, systems affect our behaviour. We created the system that is our current market economy, and we have the ability to construct new systems that encourage better behaviour. For example, studies show that cooperatively ran businesses are more ethical and more stable:

> [...] Additionally, "cooperative banks build up counter-cyclical buffers that function well in case of a crisis," and are less likely to lead members and clients towards a debt trap (p. 216). This is explained by their more democratic governance that reduces perverse incentives and subsequent contributions to economic bubbles.

> The cooperative banking sector had 20% market share of the European banking sector, but accounted for only 7 per cent of all the write-downs and losses between the third quarter of 2007 and first quarter of 2011. Cooperative banks were also over-represented in lending to small and medium-sized businesses in all of the 10 countries included in the report.

> [...] in France and Spain, worker cooperatives and social cooperatives "have been more resilient than conventional enterprises during the economic crisis".

> Public trust in credit unions stands at 60%, compared to 30% for big banks and small businesses are five times less likely to be dissatisfied with a credit union than with a big bank.

In other words, this behaviour doesn't happen everywhere. It's specific to certain types of businesses.

Paragraphs from here: https://en.wikipedia.org/wiki/Cooperative#Economic_stability

Post reply on HN