Live data from Hacker News

Oh, the Places Your Apple ID Will Go

pxlnv.com

1–10 of 164 posts

Re: Oh, the Places Your Apple ID Will Go

#4
> I may be getting something wildly wrong here, but I am not sure I see the presence of this Apple ID proxy in Apple’s services logs to be a violation of either its own policies or users’ expectations for using internet services in general.

I strongly disagree that the iOS App Store should be treated as an "internet service" rather than a part of the device. The iOS App Store only comes on iOS devices, it comes on all iOS devices, and it is the only way to access a crucial feature of the device. It is, for all meaningful purposes, part of the iPhone in the same way iOS is.

It would be a bit like Microsoft saying "explorer.exe? Policy A only covers the OS, and that is clearly not part of Windows! - so therefore you are covered by Policy B". While Apple may be legally in the right, I strongly believe they are morally in the wrong and have betrayed the trust their users put in them to safeguard their privacy.

I believe that a casual user of the iPhone would take a look at Apple's iPhone privacy policy and expect that to apply to the iOS App Store as well, as for all intents and purposes that is a part of the iPhone.

Re: Oh, the Places Your Apple ID Will Go

#5
post #3

Isn’t this a misunderstanding of what PII is? An evil entity, given this couldn’t unmake me the way they could with a name, e-mail, or even IP

If it can be traced to a natural person, it is PII. IP addresses are PII, ids are PII. It is in the name "Personally Identifiable Information." If it can be used to personally identify you, it's PII.

If you gave me this ID number, I could use it to locate your information in breached db dump, or if it is used in API requests, impersonate you.

Re: Oh, the Places Your Apple ID Will Go

#6
post #3

Isn’t this a misunderstanding of what PII is? An evil entity, given this couldn’t unmake me the way they could with a name, e-mail, or even IP

If it can be traced to a natural person, it is PII. IP addresses are PII, ids are PII. It is in the name "Personally Identifiable Information." If it can be used to personally identify you, it's PII. If you gave me this ID number, I could use it to locate your information in breached db dump, or if it is used in API requests, impersonate you.

> or if it is used in API requests, impersonate you

You're suggesting it's an authorization token - which it obviously is not.

Re: Oh, the Places Your Apple ID Will Go

#8

Can someone explain why the App Store doesn't show the "Ask App Not To Track" dialog? Why do 3rd party apps have to ask for permission to track, but Apple's apps do not?

The information Apple holds on users is valuable so they don't want third parties to get it for free.

Re: Oh, the Places Your Apple ID Will Go

#9

Can someone explain why the App Store doesn't show the "Ask App Not To Track" dialog? Why do 3rd party apps have to ask for permission to track, but Apple's apps do not?

I'm only picking things up passively but as far as I have read, it is because the App Store does not track you across OTHER COMPANIES apps and websites. If they only track you within their own Apple ecosystem, they don't need to ask for permission (same as other apps).

Re: Oh, the Places Your Apple ID Will Go

#10

> I may be getting something wildly wrong here, but I am not sure I see the presence of this Apple ID proxy in Apple’s services logs to be a violation of either its own policies or users’ expectations for using internet services in general. I strongly disagree that the iOS App Store should be treated as an "internet service" rather than a part of the device. The iOS App Store only comes on iOS devices, it comes on al…

>I strongly disagree that the iOS App Store should be treated as an "internet service"

It’s entire purpose is to look up data and download stuff across the internet. How can it not be an internet service? How much use could it be if it was cut off from internet connectivity, what would you even do in it?

Post reply on HN