It’s a bummer (albeit an expected one) to see Apple reducing the burden for third-party publishers to collect personal data, rather than increasing the burden for themselves to collect it, thus overall raising the floor of user privacy. This is to say, when a regulator requests “everyone be treated equally to ensure competition” maybe they should also take into account how users are impacted and instead request something more nuanced like: if there are unequal standards, they must be equalized in a way that maximizes user benefit.
I also delight in this highlighting Apple's hypocrisy
https://medium.com/@krvoller/how-iphone-violates-apples-acce...
1. The competition law people are not the data protection people. From the perspective of competition law, they only care that the playing field is leveled, they don't care if you equalize down or up.
2. The EU has fumbled the ball on GDPR by not enforcing it on the tech giants that it was intended to regulate[0], to the point where a tech company enforcing the intent of the law and not the letter of the law feels like singling out competitors.
[0] In particular, the Republic of Ireland is a rotten borough for Facebook, who has all their EU offices there.
Apple's own apps are still blessed with permissions that other apps have to ask for. This needs to be addressed too.
I don't even care if they make the dialogue look a little different since they're system apps you need to use the features of your phone, but the "extras" they support should default to "Ask First" in an ideal world that is.
Maybe you'd like to use a competitor to the Photos app and don't want to use the one Apple provides?
But what does the "Access to photos" permission really do here? It's not like not having that permission would stop Apple from accessing them against your will, as they have access via the OS anyway. And it's clear, that when you open the Apple Photos app, that it will access your photos.
On the other hand, when you open a third party app, it may not have been clear to you that it wants to access your photos, and the company did not have prior access to them.
I still think apps should only be pre-blessed sparingly. For example, the camera app should not have GPS permission by default, as many people probably aren't aware that camera apps use that information.
I don’t think it’s a bad thing necessarily.
You want to handle device rotation smoothly in your in-app browser?
Tough luck, WebKit's _beginAnimatedResizeWithUpdates is private, and only Apple gets to use it in Safari.
Good luck with the animation and scroll position handling. You better hope WkWebView's default behavior works for you, because you don't get to customize it and fix edge cases or the tab previews, like Apple did for their browser.
There are whole classes of applications that are not possible unless low level device data is exposed via APIs.
And since Apple doesn't provide the apps, the apps won't exist until Apple creates them.
Sometimes transparency and honesty get weaponized. Especially by actors with centralized power.
(Not arguing against transparency, but against misinterpreting it as always being used in good faith.)
https://news.ycombinator.com/item?id=43047952
Watchdog ponders why Apple doesn't apply its strict app tracking rules to itself (theregister.com)
161 points by Logans_Run on Feb 14, 2025 | 69 comments
> Under the commitments that have now been declared binding, Apple will align the consent prompts for its own offerings and for third-party apps much more closely.
> ... Apple's own apps are still blessed with permissions that other apps have to ask for. This needs to be addressed too.
Apple gave itself better dialogs for the permission prompts, which they will now equalize (perhaps just in the EU?) with the prompts they use for their own apps.
My understanding of ATTF is that first-party tracking needed no disclosure other than the information declared in the app's App Store privacy section about the information gathered. If you made a suite of 20 apps, you could track usage across all of them without issue, as long as you didn't also share that info with a third party.
"Access to Photos" is a complicated one: An app only needs this permission when building a custom photo selector. Like Facebook/WhatsApp/Instagram do, also Slack.
For every other app, they can use the system's default photo picker and it works without permission.
For example, the "Lunch Receipt Scanner" that my company uses: I'm happy to allow it on my phone, as it saves a lot of time, but I wouldn't want a company app having access to my entire camera roll!!!
I personally also don't like that WhatsApp/Instagram/Facebook/Slack asks for access to the whole album just to display the photo picker, but I'm pretty sure some designer or product manager made a strong case for it internally.
Ah, it was OpenHaystack: https://github.com/seemoo-lab/openhaystack#installation
Mail plugins are kind of a special case, they're REALLY "legacy", so they work by sharing process memory and being able to access way more than they should, like all your messages, possibly even passwords if the developer is clever enough.
Also notoriously difficult to build, since the Mail internal API breaks from time to time, so they're a rarity these days.
Also notoriously difficult to install.
They are doing nothing to stop the endless ads, and the pop-ups in the browser I want to kill turn them off not them grant equal access to have even more ads.
Another problem is the onward, march towards renting leasing, owning nothing endless upgrades for price, in the end I don’t expect a bunch of lawyers and bureaucrats to do anything about that. They have been paid off long time ago.
Recently in the last couple of years in particular it’s gotten to be completely out of control. I’m glad I bought a super drive before Apple discontinued it soon the way things are going you won’t even be able to have a large drive or even big memory you’ll be tied to that remote data center…
flipnotyk•55m ago
jareklupinski•37m ago