11 ms·
Oh, the Places Your Apple ID Will Go
- newaccount74 4y agoCan someone explain why the App Store doesn't show the "Ask App Not To Track" dialog? Why do 3rd party apps have to ask for permission to track, but Apple's apps do not?
- chrischen 4y agoThe information Apple holds on users is valuable so they don't want third parties to get it for free.
- wingerlang 4y agoI'm only picking things up passively but as far as I have read, it is because the App Store does not track you across OTHER COMPANIES apps and websites. If they only track you within their own Apple ecosystem, they don't need to ask for permission (same as other apps).
- smoldesu 4y agoFacebook kept their shadow profiles to themselves, but that didn't make it any less gross. Defending Apple's data collection on the basis that "they don't share it" is like defending a guy taking creepshots of you in the bathroom because he doesn't look like the sort of person who would cause you trouble.
- yamtaddle 4y agoThe sharing's not what makes it "tracking", by Apple's definition, it's collecting data on other companies' sites and apps. As in, following you around wherever you go. Tracking. It's the difference between Wal-Mart recording you with camaras in their stores, and recording you with camaras in all stores... and at the public park, and in your home, and.... FWIW I think a whole hell of a lot more than what Apple calls "tracking" ought to simply be illegal, but they've been pretty clear about what they mean by the term, and their definition does make sense, and that is one of the worse behaviors among the spyware industry (which is basically all software, at this point, which, WTF, how did norms change so incredibly fast?)
- simonh 4y agoTracking is about following breadcrumbs across activity in third party apps. So if the Facebook app uses identifiers in common with Uber, and can see what you do in Uber or something, that’s tracking. Recording what you do in a single app, or apps from one company that isn’t strictly necessary for providing the service is telemetry. Apple doesn’t share user data and identifiers with third parties except as necessary to provide specific services, so it doesn’t track. It does record telemetry though, most of that is in a non personally identifying way, but some of it can be traced to a user. Obviously identifying information necessary to provide a service is different. If I buy an app off the App Store, they need to identify who bought it. The edge cases are things like, do they need to know I searched for fitness apps on the App Store and associate that with my ID. Amazon does on their web site so they can show ads related to my recent searches, but it’s not strictly necessary for providing the service.
- _heimdall 4y agoAgreed that is the technical distinction made today, but for an end user that really is splitting hairs. When Apple is offering first-party services that compete with Netflix, Spotify, etc. my privacy concern is that someone is tracking and aggregating data on what I watch and listen to. As a user I don't really care if that's two separate corporations sharing unique identifiers or two departments in the same umbrella corporation, it's still a privacy concern.
- Cthulhu_ 4y agoThere's probably a line in the T's and C's that nobody reads when you first start up the phone where you give them permission. Reading the other comments, it will be in there if they even need to ask; on websites, websites do not need to ask for permission for functional cookies.
- rahoulb 4y agoI read somewhere (sorry can't remember where but it was quite recent) that Apple has defined "tracking" as "allowing third parties to monitor you over multiple sites and apps". My that definition, Apple, as a first party, is not tracking you (and likewise, I can monitor you over my apps but not allow anyone else access to that data) UPDATE: It was from AppStore Connect itself, when you fill out the privacy data form. Also here: https://support.apple.com/en-gb/HT211970 https://support.apple.com/en-gb/HT211970 "data from the app that is linked with your data collected from other companies’ apps, websites or offline properties, and used for ads or shared with a data broker."
- mtts 4y agoThis definition is not necessarily wrong. It’s easier for them to argue that they need telemetry to provide (and improve) their own services than it is to argue some third party advertising behemoth needs it. The former is perfectly acceptable, also according to the GDPR (first party advertising is also A-Ok according to he GDPR, btw).
- rahoulb 4y agoTechnically it's fine, but it sits badly with me. Ultimately their business model - we don't need to log/track/whatever your behaviour to show you advertising because we make our money off hardware - was a big differentiator for them compared to all the other tech companies. If they remove that, then they're removing one of the main reasons I stay with them. And that's really the point - at some time soon they will stop being the "iPhone company" and they'll become "just another company" and this is just them preparing for that day.
- taneq 4y agoSounds exactly like Google’s definition. “Private” means “just between you and Google.”
- amelius 4y agoWhy don't apps show the EU cookie banner? It seems that apps have an unfair advantage over websites.
- Aaargh20318 4y agoApp do not have an advantage here. the EU 'cookie law' doesn't mention cookies at all. All it says is that you cannot track users without permission, and that this permission must be freely and explicitly given. It's just that this is usually done using cookies on websites, but the specifics don't matter. Apps absolutely have to ask for permission before tracking a user. Now if this is actually enforced or not is a different matter.
- scarface74 4y agoUnfair advantage == it isn’t a usability nightmare caused by ignorant lawmakers
- newaccount74 4y agoThe usability nightmare is not caused by lawmakers. The usability nightmare is caused by businesses who think they need to put Google analytics on every single page. It is possible to create websites completely without cookie banners. You just have to not track your customers unnecessarily.
- scarface74 4y agoI love how GDPR apologists love to deflect blame from the law and lawmakers who were the initial cause of the problem. And what affect did have? Did the 99 section 11 chapter law have any deleterious affect on adTech? Did it make browsing better or worse? We see the effect that of an effective strategy, when Apple made tracking opt in, publicly traded companies like FB admitted that it caused billions in lost revenue. The only thing the GDPR did was give us cookie banners.
- ezfe 4y agoBecause "Ask App Not To Track" refers to (for all apps, not just the App Store) tracking across different systems/companies. For example, a Weather app collaborating with an ad sales company to provide them tracking data would violate "Ask App Not To Track," but Facebook tracking you within the Facebook app does not because it's all internal. The reason for this is just about the practicality of enforcement: You cannot enforce companies not doing internal tracking because they still have to collect data for their business, so how do you distinguish it.
- flyingsky 4y agoReason x why I'm rooting for Zack and his metaverse bet! I love the iPhone & Mac but I dislike apples approach to "privacy" feels hypocritical
- headsoup 4y agoNot sure if sarcasm, but just in case... My friend you need to open a window and see the rest of the world that exists outside that binary choice...
- Ensorceled 4y agoWell, even if it's a binary choice ... Facebook is the weird bit to pick.
- smoldesu 4y agoAll roads lead to data collection. It wouldn't surprise me if stories like this pushed people onto Facebook or Android just because of the uncertainty that the iPhone now represents.
- deleted 4y ago[deleted]
- lapcat 4y agoSome trivia: the "DS" in DSID is "Directory Services", which is a giant Apple-internal database. Apple employees and contractors have a DSID too. It's basically a database of all people that Apple knows, and it's very old.
- trollied 4y agoGood to see somebody talking sense. Lots of journalists jumped on this, framing Apple as evil. At a high level, the whole thing is no different to a website using a cookie to keep you logged in.
- kleiba 4y agoBut cookies I can choose not to allow, right?
- Cthulhu_ 4y agoWell yeah, your browser, your rules; it'll just come at a convenience fee of having to log back in every time, and that for the duration of your session you HAVE to have a cookie or your login won't work. There used to be an alternative of a session ID in every URL, but I haven't seen that in years.
- jll29 4y agoA cookie is not a PII identifier, it is an "identity discriminator". In other words cookies let them tell you the _same_ person 104898 that was already here in March, welcome back!, and not any other person e.g. 298472, but without telling them your actual name etc. In contrast, a PII identifier is a unique ID that is linked to personal attributes in real life like a person's name ("John Doe"), address ("6400 Boulevard Court, Beverly Hills, CA"), e-mail address ("john.doe@acm.org") or credit card number ("VISA 4879 5223 6537 9935"). So, this is indeed different from visiting a Website that places a cookie.
- Rygian 4y agoPII is never black or white. "_same_ person 104898" will become PII at any moment when the site can collate it on a one-to-one mapping with some other PII of yours (e.g. your email or login). From GDPR Recital 30: "Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them." So your Apple ID becomes PII for a specific site at the precise instant you share any other PII to that site, that they are able to link to the Apple ID.
- TylerE 4y agoIsn’t this a misunderstanding of what PII is? An evil entity, given this couldn’t unmake me the way they could with a name, e-mail, or even IP
- withinboredom 4y agoIf it can be traced to a natural person, it is PII. IP addresses are PII, ids are PII. It is in the name "Personally Identifiable Information." If it can be used to personally identify you, it's PII. If you gave me this ID number, I could use it to locate your information in breached db dump, or if it is used in API requests, impersonate you.
- null_object 4y ago> or if it is used in API requests, impersonate you You're suggesting it's an authorization token - which it obviously is not.
- 867-5309 4y agodepends on the authentication mechanism
- withinboredom 4y agoIt depends, but I was imagining a vulnerability where I authenticate to the API as myself, but use your ID. Or I sed my usage/diagnostic logs and replace my ID with yours. This might sound really boring, but as an example, I could send logs/activity as someone else, placing them at a scene of a crime that would show up in a subpoena. I doubt this vulnerability exists, but these IDs (and any IDs by any company) should be guarded just like any other PII for exactly this sort of reason.
- glitchc 4y agoNo, that's not the definition of PII. That the ID maps to a person doesn't mean they know that person's SSN, which is PII. IP counts as metadata. It uniquely identifies you as an entity but does not reveal other details except geographic location. If IP addresses are PII, then any use of the internet is violating your privacy. Perhaps unplug your modem, turn off cell service on all devices and read a book instead.
- cmeacham98 4y ago> I may be getting something wildly wrong here, but I am not sure I see the presence of this Apple ID proxy in Apple’s services logs to be a violation of either its own policies or users’ expectations for using internet services in general. I strongly disagree that the iOS App Store should be treated as an "internet service" rather than a part of the device. The iOS App Store only comes on iOS devices, it comes on all iOS devices, and it is the only way to access a crucial feature of the device. It is, for all meaningful purposes, part of the iPhone in the same way iOS is. It would be a bit like Microsoft saying "explorer.exe? Policy A only covers the OS, and that is clearly not part of Windows! - so therefore you are covered by Policy B". While Apple may be legally in the right, I strongly believe they are morally in the wrong and have betrayed the trust their users put in them to safeguard their privacy. I believe that a casual user of the iPhone would take a look at Apple's iPhone privacy policy and expect that to apply to the iOS App Store as well, as for all intents and purposes that is a part of the iPhone.
- simonh 4y ago>I strongly disagree that the iOS App Store should be treated as an "internet service" It’s entire purpose is to look up data and download stuff across the internet. How can it not be an internet service? How much use could it be if it was cut off from internet connectivity, what would you even do in it?
- Lukas_Skywalker 4y agoSure, it requires internet for it to work, just as the phone itself requires cellular service so you can make a call. Calling is still part of the phone. Of how much use is an iPhone without the App Store? You can still use the preinstalled apps, but your expectation as a consumer is that you can install new apps. This expectation is broken without the App Store.
- verisimi 4y agoWith a name like yours, I was expecting you to point this out: "These are not device analytics, they are services analytics." "These Are Not the Droids You Are Looking For"
- nonrandomstring 4y agoI see a lot of very intelligent people here unable to agree upon a matter that seems, in essence, simple enough. That is in itself troubling and partly answers a question. If developers on Hacker News cannot fathom whether Apple deceptively transmitted PII, or whether zealous journalists are over-egging the pudding, then we have another problem. Obfuscation is a form of deception through complexity. It can be hard to tell from the outside whether that complexity is "necessary" and whether its ill effects are deliberate or accidental. Nevertheless, it remains a form of deception if you present a system as simple, with controls that apparently do understandable things as a front for another system that even you, as a developer, no longer understand. This same theme is coming up in AI, social algorithms, moderation/censorship of speech. We are muddying the waters in the hope that people believe they are shallow.
- sendfoods 4y agoCould not have expressed my thoughts more clearly.
- headsoup 4y agoAnd some would say this is a deliberate adversarial tactic to guide people to surrender their privacy and freedoms, because those that would defend them can't sufficiently explain the complexity to be more convincing than 'simple' messages.
- smoldesu 4y agoWe say that because Apple has a history of using deliberate adversarial tactics to abuse the market and claim dominance. It's almost as iconic as Google killing off their own products.
- BLKNSLVR 4y agoI think this can be explained by simple denial; Apple's reality distortion field, or some variation on "It is difficult to get a man to understand something, when his salary depends on his not understanding it." Maybe not salary, but a foundational world view, much like religion. I mean, people on HN will argue that it's wrong to block ads, a point of view that only makes sense to me through the lens of the above quote. But, yes, it's a big problem because people that don't factor in the inherent biases of those making the arguments will take on those biases without the salary that makes it make sense. Is that like a Stand Alone Complex?
- knorl 4y agoThis "Directory Services Identifier" is not sent outside of Apple's services though right? And only sent to Apple services that need to know the identity of the user? If so I'm wondering what the issue is here.
- Ensorceled 4y agoThe issue is that iCloud knows that I'm the same Apple user coming to get my files from iCloud as accessed the App Store!!! With my Apple account! Wait ... I'm also not sure what the issue is. Fundamentally this is only a problem because Apple is too big and controls the App Store, iCloud and all the rest of your device. This is a reasonable artifact of an unreasonable situation. I also think Apple is too big but I'm more concerned about Big Pharma, Big Oil, Big Banks, Ad Tech, Growing Fascism, ... Big Apple is a worry way down on my list.
- rkagerer 4y agoIt seems a little more leaky than I'd expect: Because that identifier is also used in some iCloud API requests, I also spotted the same value in activity logs for third-party applications using things in my iCloud account, as well as in metadata for local copies of documents I downloaded from my drive at iCloud.com.
- eugenekolo 4y agoIt's a little unclear what they mean here, but that can easily be because of a service/system server model. The third party apps use things like "icloud daemon" (not sure that one actually exists) which does the iCloud request and passes along the data back to the app. Because the logs are generated with a high privilege level, they are also including what icloud daemon did for those specific apps, but those apps did not get access to that DSID, it was kept internal to icloudd. If the journalists or whomever wants to claim the DSID is leaky, then they need to show a POC with an app actually obtaining that DSID, and not only in a system logger that only saves files sandboxed locally, or sends to Apple.
- RektBoy 4y ago
- deleted 4y ago[deleted]
- coldtea 4y ago>They blindly trust in Apple security. I spoke with people and they think you can't have an exploit/virus for iOS. Lol. Statistically they are right. Such exploits are so few and insignificant that they doesn't really matter... It's more like the danger of dying from swallowing your food. It exists, but it's not really something you need to worry about...
- sdze 4y agoThat's why I turned all this junk OFF on all my apple devices. Why would I help them better their software? Hire more test engineers.
- emsixteen 4y ago> We also showed earlier that the #AppStore keeps sending detailed analytics to Apple even when sharing analytics is switched off.
- charcircuit 4y ago>Why would I help them better their software? Because you too benefit from the software you use getting better.
- emsixteen 4y agoThat's completely besides the points. When you choose to opt out you're explicitly indicating you don't want this to happen.
- jawadch93 4y ago[dead]
- BirAdam 4y agoWell, I’m not surprised. All the megacorps seem to be crap at privacy because privacy interferes with their lucre. So, Apple is just another Google, Microsoft, Meta, Amazon, etc. I know that they advertised otherwise, but that’s a matter for court and truth in advertising laws; personally I’ve always assumed that every phone is a passive surveillance device.
- deleted 4y ago[deleted]
- pacifika 4y agoAllegedly it’s fine because they’re collecting information for internal use and not sharing with third parties, but really the industry is trying to redefine tracking as cross service/site tracking. Well I think they should set the same bar internally
- shawn-butler 4y agoWhy? What is the value in anonymizing your voluntary engagement within a single corporate entity? As long as that entity provides me with an accurate reporting of access when I request it? Why for example would I want to make it any more difficult for my doctor at a hospital and the hospital pharmacy to share my confidential health information to ensure I get the right treatment?
- pacifika 4y ago1) tech companies should not be Doctors. Apple is not a doctor. 2) there are additional privacy protections around medical uses, for these reasons.
- hellfish 4y ago> What is the value in anonymizing your voluntary engagement within a single corporate entity? Because up to a certain point it isn't voluntary > Why for example would I want to make it any more difficult for my doctor at a hospital and the hospital pharmacy to share my confidential health information to ensure I get the right treatment? Because principle of least privilege. This is one example, another could be the doctor sharing health data with an internal hospital logging service, which is utilizing some cloud service, which is utilizing some other cloud service, etc
- jensensbutton 4y agoIF it's fine then why was Google data collection ever an issue?
- JKCalhoun 4y ago> I am also shocked by the granularity of information in these storefront analytics. It is relevant to Apple’s recommendation engine if I listened to an album or song and whether I finished it, but it is hard to see what value it has in knowing my track playback to the millisecond. Not surprised. As soon as it was possible to get this kind of information about app usage (thanks, Internet!) of course management wanted everything. Apple has its own privacy teams that work with the teams developing apps. Data collection is treated as a Big Deal and "Privacy" will grill you on every single byte that you want to collect. And any bit of data that might reveal personally-identifiable-information is a nonstarter. As an example, we could not report back error messages from the OS, only error codes. Why? Error code might be "123" but error message could be "Error 123, You just removed hard drive 'Calhoun Data' without unmounting..." Perhaps the downside of this gatekeeping though is that I feel it causes management to come to the table asking for everything, letting privacy whittle it down. With major app release cycles 6 or 12 months apart, I think management sometimes don't know what data they might want - would rather not have to wait perhaps up to a year for the new metric to be included.
- yencabulator 4y ago> Data collection is treated as a Big Deal and "Privacy" will grill you on every single byte that you want to collect. I find this optimistic view hard to reconcile with the article. It seems collecting personally identifying data is the default mode. For example: > I have a spreadsheet of the nearly nine hundred times me and my DSID ignored Apple’s attempts to upsell me on Apple One
- hellfish 4y agoThis isn't really all that surprising Anyone who uses Apple/Google/Microsoft/other products as intended will have no privacy. By as intended, I mean using chrome while logged into a google account, using MacOS while logged into an apple account (and using all of apple's internal applications), using android with a google account, etc I wouldn't be surprised if the usage data, health data, from e.g. iOS+services goes straight to data brokers. I can't prove this, but it wouldn't surprise me. Even if it didn't, there's no guarantee of how the data will be used internally (or whether it's given to law enforcement, for example) If someone uses these products as intended and has even the slightest expectation of privacy (e.g. believing any of the vague BS in the TOS), they're probably not the sharpest knife in the drawer (or at the very least, grossly misinformed)
- talkingtab 4y agoLeaving behind the discussion of whether this is a problem, it is a problem for me. I paid Apple for a device. I don't want Apple to use devices to track me or target me with ads or anything else. That is my personal take. But what can you do assuming that you want or need a phone? Android is no better. Class action lawsuits enrich law firms and get users a gift card for $0.20 (sarcasm). I just wonder what would happen if everyone who doesn't want this decides to take Apple to small claims court? These companies, Google, Apple, Microsoft, Facebook continue to violate fundamental rights to privacy because they have no reason to stop. There are no significant penalties. Or perhaps we need a bill of rights. Anyone know of such a thing?
- giancarlostoro 4y agoAnyone reading this article from Illinois is about to have a fun time with Apple, their privacy laws are reasonably strict. Of course, I'm not a layer, so maybe they found the one legal "loophole" or lawful way to do it.
- raxxorraxor 4y agoI think in case of any smartphone OS, you are sadly not really the owner of the device and in contrast the manufacturer has wide reaching permissions for everything. That is partially true for desktop OS as well, but at least here you can override everything to your liking. Those that argued for these mechanism in the interest of security do not get any sympathy from me. Complaining after that fact seems pointless. If you had administrative rights, you wouldn't have as many issues with being tracked. Being able to freely modify the software running the device and accessing its hardware in the same manner would paint a different landscape.
- gunapologist99 4y ago> But what can you do assuming that you want or need a phone? Android is no better. GrapheneOS, Calyx, and LineageOS would like a word..
- lern_too_spel 4y ago> Android is no better. You don't have to use an app store that violates your privacy on Android. You don't have to send your location to Google every time you get your GPS location, unlike how iOS sends all your GPS lookups to Apple. Android is far better. The key difference is user control.
- ProAm 4y agoThe irony of Tim Cook only a few years ago claiming they don't want your data [1] "We treasure your data. We wanna help you keep it private and keep it safe." [A] https://observer.com/2019/05/tim-cook-apple-data-privacy-crusade/ https://observer.com/2019/05/tim-cook-apple-data-privacy-cru...
- gunapologist99 4y agoApple’s analytics data include an ID called “dsId”. We were able to verify that “dsId” is the “Directory Services Identifier”, an ID that uniquely identifies an iCloud account. Meaning, Apple’s analytics can personally identify you. Apple states in their Device Analytics & Privacy statement that the collected data does not identify you personally. Even if legal, this is obviously a very bad look for a company that claimed they were all about privacy and took actions against competitors to protect users' privacy.
- sneak 4y agoApple is only about privacy as a marketing differentiator. Apple's software clearly demonstrates that they do not place a high value on user privacy. iPhones and Macs phone home constantly with all sorts of information even if you never use iCloud or the App Store or Apple's service offerings. It's ridiculous.
- user3939382 4y agoYep. Set up Charles Proxy (GUI) or mitmproxy (CLI) if you want to take a look at the actual data. It's huge and non-stop. Some of this even Little Snitch can't stop because it's sent to random IPs inside huge blocks belonging to Apple with no DNS. Unless you go to extraordinary lengths it's the same with Firefox FYI. These companies' privacy concerns are a marketing gimmick, and the situation is so out of control we have to be thankful even for those crumbs.
- sneak 4y agoLittle Snitch can still block those. The huge block is 17./8 and is easily identified.
- gcanyon 4y agoI'm curious: do you think Apple is exactly as invasive as the companies they compare themselves to? Or are they not as invasive, but still not as non-invasive as their marketing materials claim?
- beders 4y agoI really don't get the outrage. I assumed that by stepping into Apple's walled garden, they would know and store: - where my devices are - what I'm doing with them (i.e. apps downloaded and started, which features I use yadda yadda yadda - any app I download and use will independently log all my taps and interactions within that app - and since I use iCloud: where all my data is What would make you think otherwise?
- Helmut10001 4y agoAll of these issues with UIDs make me believe that we should maybe transition to Probabilistic Data Structures and group users randomly together, e.g. based on HyperLogLog abstracted UIDs. Only the user device itself would have the full ID, the service would get an abstracted, probabilistic version of it, which can (and will) collide with other abstracted IDs. Thus, the service could never be 100% sure who exactly a single user is - out of a group of (e.g.) 12 people that happen to yield the same probabilistic representation. (I know there're also many issues with this approach, so take it with a grain of salt)
- dang 4y agoRecent and related: Apple sends DSID with iPhone analytics data, tests show - https://news.ycombinator.com/item?id=33695937 https://news.ycombinator.com/item?id=33695937 - Nov 2022 (111 comments) Proposed class action alleges that Apple tracks users despite privacy assurances - https://news.ycombinator.com/item?id=33593455 https://news.ycombinator.com/item?id=33593455 - Nov 2022 (191 comments) App Store on iOS 14.6 sends every tap you make in the app to Apple - https://news.ycombinator.com/item?id=33520775 https://news.ycombinator.com/item?id=33520775 - Nov 2022 (190 comments)
- rswail 4y agoThe use of tracking is acceptable under the GDPR if it is necessary for providing the product/service. The Apple ID, being necessary for determining the applications you have bought/are installing would be considered necessary. Permission to have it is not required. If the Apple ID is shared to another 3rd party by Apple, then it is not just being used for providing the product/service. So it would be required to get permission under GDPR. Apple sells a service which is iPhone+iOS+App Store. While it is technically possible to separate, Apple doesn't. It's all required. So the Apple ID is required for doing that. The fact that the Apple ID can be associated to an individual and their PII is something that theoretically could be isolated, but Apple are not required by law or regulation to do so as long as their use of the ID stays unshared and "necessary".