Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> They use it to apply many security and privacy policies!

Have you read the guidelines? Many words requiring you to use and not discourage users from using Apple's in-app purchasing system (which they get a large cut of), prohibiting you from trying to compete with the App Store or similar, prohibiting app-alternatives they don't control (like remote desktop into a cloud server), requiring "Sign in with Apple" if you use another third party sign in service and that sort of thing.

There is a privacy section, but the dirty secret is that they have very little power to enforce it against premeditated abuses. Companies add a feature to their app that gives them a pretext for uploading your data to their servers, and then there is no way for the user or Apple to verify what happens to it from there or determine actual compliance with the privacy policy.

So the policies with a compliance enforcement mechanism are the ones that benefit Apple and the ones that are supposed to benefit users in practice don't have one.

> Difficult to figure out how to actually do this, especially so without a crazy UX.

Actually not so hard in that specific case. They could run the app and not sign in with a Facebook account, and if it tries to contact Facebook servers anyway, reject it.

> They should figure out the default apps thing. Though I don't know what you'd need for SMS, there's not much system integration there besides Siri (which I think supports plugins) and maybe sms: links?

They prohibit it on purpose. Signal isn't allowed to send and receive SMS on iOS:

https://support.signal.org/hc/en-us/articles/360007321171-Ca...

> Apple does not allow other apps to replace the default SMS/messaging app.

The "Firefox" on iOS isn't even actually Firefox, it's required to use Apple's browser engine.



The App Store having additional restrictions doesn't have anything to do with the privacy aspect of the walled gardens being a "lie". You can go on a tirade about the app store's limitations if you want, but that's not relevant.

Your proposed solution would not work, obviously, because how do you define what services an app is allowed to connect to? How do you know it's connecting to Facebook's servers? Just hope they always use facebook.com?


> that's not relevant.

It's the true motive for the "walled garden" -- it explains why it continues to exist even though the stated reasons why it exists don't pan out in practice.

> Your proposed solution would not work, obviously, because how do you define what services an app is allowed to connect to?

Why is it allowed to connect to any services for no reason? If the app makes a network connection the developer should have to justify it by something other than enabling collection of user data.

> How do you know it's connecting to Facebook's servers? Just hope they always use facebook.com?

I feel confident that Apple has the resources to determine whether the servers every application using the Facebook SDK is contacting belong to Facebook.


Interesting. That clearly violates GDPR and CCPA if it extended to all digital options rather than just websites.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: