Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

The two most common things in the Universe are hydrogen and stupidity. -- Harlan Ellison


computers / misc.phone.mobile.iphone / iPhone Apps Secretly Harvest Data When They Send You Notifications

SubjectAuthor
* iPhone Apps Secretly Harvest Data When They Send You NotificationsWolf Greenblatt
`* Re: iPhone Apps Secretly Harvest Data When They Send You NotificationsAlan Browne
 +- Re: iPhone Apps Secretly Harvest Data When They Send You NotificationsFrankie
 `- Re: iPhone Apps Secretly Harvest Data When They Send You NotificationsJolly Roger

1
iPhone Apps Secretly Harvest Data When They Send You Notifications

<up225h$3i8ec$1@news.samoylyk.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=11980&group=misc.phone.mobile.iphone#11980

  copy link   Newsgroups: misc.phone.mobile.iphone alt.privacy
Path: i2pn2.org!i2pn.org!news.samoylyk.net!.POSTED.218.234.182.229!not-for-mail
From: wolf@greenblatt.net (Wolf Greenblatt)
Newsgroups: misc.phone.mobile.iphone,alt.privacy
Subject: iPhone Apps Secretly Harvest Data When They Send You Notifications
Date: Fri, 26 Jan 2024 23:52:00 -0500
Organization: Private News Server
Message-ID: <up225h$3i8ec$1@news.samoylyk.net>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Injection-Date: Sat, 27 Jan 2024 04:52:01 -0000 (UTC)
Injection-Info: news.samoylyk.net; posting-host="218.234.182.229";
logging-data="3744204"; mail-complaints-to="abuse@samoylyk.net"
 by: Wolf Greenblatt - Sat, 27 Jan 2024 04:52 UTC

https://gizmodo.com/iphone-apps-can-harvest-data-from-notifications-1851194537

iPhone apps are skirting Apple's privacy rules to collect user data through
notifications, according to tests by security researchers at Mysk Inc., an
app development company.

Users sometimes close apps to stop them from collecting data in the
background, but this technique gets around that protection.

The data is unnecessary for processing notifications, the researchers said,
and seems related to analytics, advertising, and tracking users across
different apps and devices.

"Who would have known that an innocuous action as simple as dismissing a
notification would trigger sending a lot of unique device information to
remote servers? It is worrying when you think about the fact that
developers can do that on-demand."

According to the researchers, it's a widespread problem plaguing the iPhone
ecosystem.

Re: iPhone Apps Secretly Harvest Data When They Send You Notifications

<za8tN.254530$7sbb.24583@fx16.iad>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=11983&group=misc.phone.mobile.iphone#11983

  copy link   Newsgroups: misc.phone.mobile.iphone alt.privacy
Path: i2pn2.org!i2pn.org!news.niel.me!tncsrv06.tnetconsulting.net!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!peer03.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx16.iad.POSTED!not-for-mail
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Subject: Re: iPhone Apps Secretly Harvest Data When They Send You
Notifications
Newsgroups: misc.phone.mobile.iphone,alt.privacy
References: <up225h$3i8ec$1@news.samoylyk.net>
Content-Language: en-US
From: bitbucket@blackhole.com (Alan Browne)
In-Reply-To: <up225h$3i8ec$1@news.samoylyk.net>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Lines: 30
Message-ID: <za8tN.254530$7sbb.24583@fx16.iad>
X-Complaints-To: abuse@usenetserver.com
NNTP-Posting-Date: Sat, 27 Jan 2024 14:11:43 UTC
Organization: UsenetServer - www.usenetserver.com
Date: Sat, 27 Jan 2024 09:11:43 -0500
X-Received-Bytes: 2025
 by: Alan Browne - Sat, 27 Jan 2024 14:11 UTC

On 2024-01-26 23:52, Wolf Greenblatt wrote:
> https://gizmodo.com/iphone-apps-can-harvest-data-from-notifications-1851194537
>
> iPhone apps are skirting Apple's privacy rules to collect user data through
> notifications, according to tests by security researchers at Mysk Inc., an
> app development company.
>
> Users sometimes close apps to stop them from collecting data in the
> background, but this technique gets around that protection.
>
> The data is unnecessary for processing notifications, the researchers said,
> and seems related to analytics, advertising, and tracking users across
> different apps and devices.
>
> "Who would have known that an innocuous action as simple as dismissing a
> notification would trigger sending a lot of unique device information to
> remote servers? It is worrying when you think about the fact that
> developers can do that on-demand."
>
> According to the researchers, it's a widespread problem plaguing the iPhone
> ecosystem.

If that is an issue, then they would not be in compliance with Apple's
rules and as such could have their apps withdrawn until fixed.
Hopefully Apple come down on them hard.

--
“Markets can remain irrational longer than your can remain solvent.”
- John Maynard Keynes.

Re: iPhone Apps Secretly Harvest Data When They Send You Notifications

<up38fm$1c2f$1@neodome.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=11984&group=misc.phone.mobile.iphone#11984

  copy link   Newsgroups: misc.phone.mobile.iphone alt.privacy
Path: i2pn2.org!i2pn.org!news.neodome.net!.POSTED!not-for-mail
From: frankie@nospam.usa (Frankie)
Newsgroups: misc.phone.mobile.iphone,alt.privacy
Subject: Re: iPhone Apps Secretly Harvest Data When They Send You Notifications
Date: Sat, 27 Jan 2024 09:45:56 -0600
Organization: Neodome
Message-ID: <up38fm$1c2f$1@neodome.net>
References: <up225h$3i8ec$1@news.samoylyk.net> <za8tN.254530$7sbb.24583@fx16.iad>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Injection-Date: Sat, 27 Jan 2024 15:45:58 -0000 (UTC)
Injection-Info: neodome.net; mail-complaints-to="abuse@neodome.net"
User-Agent: NewsTap/3.2 (iPad)
 by: Frankie - Sat, 27 Jan 2024 15:45 UTC

On 27/1/2024, Alan Browne wrote:

> Hopefully Apple come down on them hard.

I agree with you as the articles I saw said the frequency at which many iOS
apps collect device information is "mind-blowing" so Apple should put a
stop to it as they said the practice goes against Apple's terms of service.
(https://www.techradar.com/pro/security/some-of-the-most-popular-iphone-apps-are-stealing-your-data-using-ios-push-notifications)

Re: iPhone Apps Secretly Harvest Data When They Send You Notifications

<l1kp56F3j34U2@mid.individual.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=11986&group=misc.phone.mobile.iphone#11986

  copy link   Newsgroups: misc.phone.mobile.iphone alt.privacy
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: jollyroger@pobox.com (Jolly Roger)
Newsgroups: misc.phone.mobile.iphone,alt.privacy
Subject: Re: iPhone Apps Secretly Harvest Data When They Send You
Notifications
Date: 27 Jan 2024 16:26:14 GMT
Organization: People for the Ethical Treatment of Pirates
Lines: 75
Message-ID: <l1kp56F3j34U2@mid.individual.net>
References: <up225h$3i8ec$1@news.samoylyk.net>
<za8tN.254530$7sbb.24583@fx16.iad>
X-Trace: individual.net BbRgTk6rIlbPtjaQwGOLign7kDKmnxGF/J3uyOG8sNYdoVu/DR
Cancel-Lock: sha1:w8NXqjEDlZw7ylw/BT4bauhaA7s= sha256:YGzEXV/Nrg93hbPm3wpk74aDnbX2U7baHSodaNhDQHE=
Mail-Copies-To: nobody
X-Face: _.g>n!a$f3/H3jA]>9pN55*5<`}Tud57>1<n@LQ!aZ7vLO_nWbK~@T'XIS0,oAJcU.qLM
dk/j8Udo?O"o9B9Jyx+ez2:B<nx(k3EdHnTvB]'eoVaR495,Rv~/vPa[e^JI+^h5Zk*i`Q;ezqDW<
ZFs6kmAJWZjOH\8[$$7jm,Ogw3C_%QM'|H6nygNGhhl+@}n30Nz(^vWo@h>Y%b|b-Y~()~\t,LZ3e
up1/bO{=-)
User-Agent: slrn/1.0.3 (Darwin)
 by: Jolly Roger - Sat, 27 Jan 2024 16:26 UTC

On 2024-01-27, Alan Browne <bitbucket@blackhole.com> wrote:
> On 2024-01-26 23:52, Wolf Greenblatt wrote:
>> https://gizmodo.com/iphone-apps-can-harvest-data-from-notifications-1851194537
>>
>> iPhone apps are skirting Apple's privacy rules to collect user data through
>> notifications, according to tests by security researchers at Mysk Inc., an
>> app development company.
>>
>> Users sometimes close apps to stop them from collecting data in the
>> background, but this technique gets around that protection.
>>
>> The data is unnecessary for processing notifications, the researchers said,
>> and seems related to analytics, advertising, and tracking users across
>> different apps and devices.
>>
>> "Who would have known that an innocuous action as simple as dismissing a
>> notification would trigger sending a lot of unique device information to
>> remote servers? It is worrying when you think about the fact that
>> developers can do that on-demand."
>>
>> According to the researchers, it's a widespread problem plaguing the iPhone
>> ecosystem.
>
> If that is an issue, then they would not be in compliance with Apple's
> rules and as such could have their apps withdrawn until fixed.
> Hopefully Apple come down on them hard.

Apple's on record stating they are addressing this:

<https://www.bleepingcomputer.com/news/security/iphone-apps-abuse-ios-push-notifications-to-collect-user-data/>
---
Mitigating the issue

Apple will plug the gap and prevent further abuse of push notification
wake-ups by tightening restrictions on using APIs for device signals.

Mysk told BleepingComputer that starting in Spring 2024, apps will be
required to declare precisely why they need to use APIs that can be
abused for fingerprinting.

These APIs are used to retrieve information about a device, such as its
disk space, system boot time, file timestamps, active keyboards, and
user defaults.

If apps do not properly declare their use of these APIs and what they
are being used for, Apple says that they will be rejected from the App
Store.
---

Also for some perspective, it's perfectly normal for apps to gather some
details about devices during operation, and a lot of that information is
legitimately needed by app developers. In this case, this is the type of
data that is being transmitted during notification processing:

---
Depending on the app, this includes:
* system uptime
* locale
* keyboard language
* available memory
* battery status
* storage use
* device model
* display brightness
---

Apple reportedly will be requiring app developers to provide
justification for collecting this data, and if a developer fails to meet
this requirement, their app will not be approved for the App Store.

--
E-mail sent to this address may be devoured by my ravenous SPAM filter.
I often ignore posts from Google. Use a real news client instead.

JR

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor