Live data from Hacker News

Apple Removes HKmap.live from the App Store

twitter.com

811–820 of 931 posts

Re: Apple Removes HKmap.live from the App Store

#811
post #788

Earlier quoted context omitted.

The app does not have root. It just requests a lot of permissions.

> An app analysis tool shows that this app––MFsocket.apk––gains ROOT access to an Android phone Source: https://chinadigitaltimes.net/2019/07/spyware-used-on-phones...

Fengcai is the app your original article talked about, which the police install when you enter Xinjiang. It does not try to get root access.

MFsocket is a separate app that has both an iPhone and Android version that police in Beijing use that does attempt to gain root on both platforms. It is unlikely to actually get root on an Android phone that a technologist would use.

Re: Apple Removes HKmap.live from the App Store

#812
post #324

Earlier quoted context omitted.

>And in one fell swoop, Apple has made it effectively impossible to install this app on your phone. There's no realistic workaround. Make the app a Web App and visit it in Safari. Apple has banned it being notarized and distributed from their App Store but iPhones still have access to the conventional web which Apple has no control over.

Or just switch to Android and you can install the APK, and likely unlock your bootloader and install a custom ROM.

Terrifically unhelpful suggestion for the actual users of hkmap

Re: Apple Removes HKmap.live from the App Store

#813

Earlier quoted context omitted.

It's not a secret. Apple even made a statement to reuters at the start of the migration process where they tried to get iCloud as an exception but failed - "“While we advocated against iCloud being subject to these laws, we were ultimately unsuccessful,” In early 2018, Apple forced their users to opt-in to migrating iCloud encryption keys and data to Chinese data centers: https://www.reuters.com/article/us-china-appl…

No, they still don't have access to the encryption keys, as reported after those articles you post: "Encryption for us is the same in every country in the world...We worked with a Chinese company to provide iCloud, but the keys [...] are ours...I wouldn't get caught up in 'where's the location of it,' I mean we have servers located in many different countries in the world. They're not easier to get data from being in…

Nothing in that quote backs up your statement.

Tim Cook is describing how encryption works - he is not saying that the Chinese government doesn't have access to the data at rest with the iCloud encryption keys. Amnesty International [1] sums it up:

>“By handing over its China iCloud service to a local company without sufficient safeguards, the Chinese authorities now have potentially unfettered access to all Apple’s Chinese customers’ iCloud data. Apple knows it, yet has not warned its customers in China of the risks.”

They raised this issue three full months before the Chinese government went ahead and nationalized all of the Apple user data and encryption keys.

[1] https://www.amnesty.org/en/latest/news/2018/03/apple-privacy...

Re: Apple Removes HKmap.live from the App Store

#814
post #628
post #324

Earlier quoted context omitted.

>And in one fell swoop, Apple has made it effectively impossible to install this app on your phone. There's no realistic workaround. Make the app a Web App and visit it in Safari. Apple has banned it being notarized and distributed from their App Store but iPhones still have access to the conventional web which Apple has no control over.

Web pages are trivially censorable directly by the Chinese government though. I don't see how that's responsive solution to the problem here.

Trivially? In Hong Kong?

I don't think this is accurate, though it may come to be in the future. Which is sort of the point, why allow the techno dystopia to come?

Re: Apple Removes HKmap.live from the App Store

#815
post #458

Earlier quoted context omitted.

There are a number of interesting use cases for PWAs, but part of Apple's fear is (potentially) many of their clients will migrate to PWA only, reducing App Store revenue severely. Apple also loses all code auditing and screening, meaning they can't ban GPL licensed PWAs like they ban alternative Linphone builds (as they are GPLv2), Signal Private Messenger builds (GPLv3) and only the official developer can build and…

I’ve been looking at the App Store Guidelines recently and I don’t see much in them that seems to block GPL specifically. Maybe it’s OK now?

If you have citations of GPLv2 or GPLv3 apps that are in the App Store, I would be highly interested.

As far as I can discern, Linphone is provided in the App Store under a proprietary license, VLC had to relicense as LGPL, and GNU Go is still not on the App Store.

Re: Apple Removes HKmap.live from the App Store

#816

Earlier quoted context omitted.

But isn't this all the same thing? Apple made a decision: "This form of speech is dangerous, so we're going to decide what our customers are allowed to see." And so Apple blocks both dangerous speech, and safe speech that could harm Apple's revenue, and safe speech that powerful individuals dislike. People always seem to think of this as a false dichotomy, so I want to emphasize again that I think Apple's curated App…

I don't think it's the same thing. Apple has at least three options: - Have a store with, say, quality control, and the option to side-load - Have a store with "quality control" (and, as I see it, some rather large levers to fight competition), no option to side-load, but don't bow to state actors - same, but bow to state actors. I wish it's the first, I thought it's the second, but we now see it's the third. I think…

The second is inevitable to the third.

This isn't new. Apple has always bowed to state actors in order to damage minorities, literally ever since the app store launched with it's censorship targeting sex workers and sexual minorities on behest of the US government.

This one is just more obvious, but not new.

Re: Apple Removes HKmap.live from the App Store

#817

Earlier quoted context omitted.

I don't think it's the same thing. Apple has at least three options: - Have a store with, say, quality control, and the option to side-load - Have a store with "quality control" (and, as I see it, some rather large levers to fight competition), no option to side-load, but don't bow to state actors - same, but bow to state actors. I wish it's the first, I thought it's the second, but we now see it's the third. I think…

But see, by saying "don't bow to state actors", you're making a moral judgement about when it is and is not okay to bow to pressure. Was it okay when Apple got rid of Alex Jones's app? He was spreading misinformation about vaccines, that's pretty darn dangerous. I guess you could argue that wasn't due to a "state actor", but is anti-Hong-Kong pressure from Chinese citizens all that different? And here's the thing—I d…

I fully agree that solution 1 would be much, much better. But I don't think I have to make a moral judgement when it is OK and when it is not OK: let's assume I think it's not OK in all cases, then it's still worse if they do it against Axel Jones AND HK than if they do it only against Axel Jones OR the HK.

In any case, I'm allowed to make a moral judgement. We do this all the time: Breaking the law is bad, but stealing is less "bad" than killing. And so on.

Re: Apple Removes HKmap.live from the App Store

#818

Earlier quoted context omitted.

Yes, they have. https://support.apple.com/en-us/HT208351 Can you link to a source showing that Apple didn't turn over control of iCloud in China to the CCP?

That link does not show that they've given control over encryption to the CCP. Apple is on record stating that they have not done this. "Encryption for us is the same in every country in the world...We worked with a Chinese company to provide iCloud, but the keys [...] are ours...I wouldn't get caught up in 'where's the location of it,' I mean we have servers located in many different countries in the world. They're…

Very interesting; thanks for sharing.

Re: Apple Removes HKmap.live from the App Store

#819

Earlier quoted context omitted.

Yeah, because you can just install Android on the iPhone you already possess.

Not all that relevant, but with the new BootROM exploit you may be able to do this at some point.

I expect that won't happen. Maybe as a proof of concept, but not as something anyone would ever want to use daily.

Documentation on iPhone hardware is basically nonexistent. Someone would need to reverse engineer it all and write drivers from scratch.

Re: Apple Removes HKmap.live from the App Store

#820

Earlier quoted context omitted.

That's funny: "Apple will always be a second-class citizen to Android" You don't hear about 14 million iPhones being infected by malware[0], do you? Or malware stealing users' bank credentials[1]? Heck, there are people whose brand new phone comes pre-loaded with malware[2]. Oh, this one was just posted five hours ago -- applications on the Google Play store load with trojans and spyware[3]. I can keep going, but the…

This argument reminds me of the gun control argument. People in favour of "more guns" are fully aware that more guns means a more dangerous society. But they consider the freedom to choose whether to own guns more important than living in a statistically safer society. Whereas, people in favour of "gun control" consider the safety of society overall to be much more important than the freedom to own devices designed t…

It has nothing to do with gun control. An analogy isn't necessary to understand that one platform regularly has software that was vetted and released on its _official software distribution platform_ that contains malware/spyware and trojans. Here's one from last year[0].

I don't expect my smartphone to be "open" and fulfilling my principles of "freedom". I do expect that from my _computer_, but I don't carry my computer in my pocket and across borders and put it in other peoples' hands to show them photos (for example).

I also don't connect my computer to unknown wireless networks, whereas my smartphone has bluetooth enabled[1] and is basically constantly connected to unfamiliar wireless networks (work/hotel/cafe/library/neighbour/etc.), any of which may include malicious actors who are scanning for vulnerable devices. A pretty solid use case for which I'll choose the device that is far less likely to be owned.

[0] https://www.symantec.com/blogs/expert-perspectives/ongoing-a... [1] https://techcrunch.com/2017/09/12/new-bluetooth-vulnerabilit...

Post reply on HN