I see the regulators only regulated that first-party and third-party apps be treated equally, and didn’t specify how.
It’s a bummer (albeit an expected one) to see Apple reducing the burden for third-party publishers to collect personal data, rather than increasing the burden for themselves to collect it, thus overall raising the floor of user privacy. This is to say, when a regulator requests “everyone be treated equally to ensure competition” maybe they should also take into account how users are impacted and instead request something more nuanced like: if there are unequal standards, they must be equalized in a way that maximizes user benefit.
Apple's hypocrisy is a longstanding issue with regard to their apps vs 3rd party apps. As I recall when the Green Bubbles first happened in messages someone pointed out that Apples own design guidelines specified a minimum contrast in colors or they would reject apps, and the green bubbles with white text did not meet that threshold at the time, and it stayed that way for quite a while. And for all I know the light themed version of the app still does (I have mine on permanent dark theme).
1. The competition law people are not the data protection people. From the perspective of competition law, they only care that the playing field is leveled, they don't care if you equalize down or up.
2. The EU has fumbled the ball on GDPR by not enforcing it on the tech giants that it was intended to regulate[0], to the point where a tech company enforcing the intent of the law and not the letter of the law feels like singling out competitors.
[0] In particular, the Republic of Ireland is a rotten borough for Facebook, who has all their EU offices there.
Title doesn't match the article, which is currently "Apple changes its rules for personalised advertising in apps".
Apple gave itself better dialogs for the permission prompts, which they will now equalize (perhaps just in the EU?) with the prompts they use for their own apps.
My understanding of ATTF is that first-party tracking needed no disclosure other than the information declared in the app's App Store privacy section about the information gathered. If you made a suite of 20 apps, you could track usage across all of them without issue, as long as you didn't also share that info with a third party.
For me it depends on which app and which permissions, like "Photos" obviously needs to be able to see my photos... Camera needs my camera, but for location it should ask me before it turns it on.
I don't even care if they make the dialogue look a little different since they're system apps you need to use the features of your phone, but the "extras" they support should default to "Ask First" in an ideal world that is.
But what does the "Access to photos" permission really do here? It's not like not having that permission would stop Apple from accessing them against your will, as they have access via the OS anyway. And it's clear, that when you open the Apple Photos app, that it will access your photos.
On the other hand, when you open a third party app, it may not have been clear to you that it wants to access your photos, and the company did not have prior access to them.
I still think apps should only be pre-blessed sparingly. For example, the camera app should not have GPS permission by default, as many people probably aren't aware that camera apps use that information.
"Access to Photos" is a complicated one: An app only needs this permission when building a custom photo selector. Like Facebook/WhatsApp/Instagram do, also Slack.
For every other app, they can use the system's default photo picker and it works without permission.
For example, the "Lunch Receipt Scanner" that my company uses: I'm happy to allow it on my phone, as it saves a lot of time, but I wouldn't want a company app having access to my entire camera roll!!!
I personally also don't like that WhatsApp/Instagram/Facebook/Slack asks for access to the whole album just to display the photo picker, but I'm pretty sure some designer or product manager made a strong case for it internally.
That should be supported, but if its the only "Photo Gallery" app installed, I think its okay. Curious, do you use another one that's better? I have looked (though not very invested in looking) and didn't really see anything that caught my eye.
Fair, but when a 3p app has camera in the name and app description then why does it need to ask permission to use the camera?
*just to be clear I think that the stock camera app not asking for camera permission is fine but skipping permission about location tracking is wrong. Having the same standard should be applied to both 1p and 3p apps feel like a fair way to ensure that good practices are used in 1p apps and good policies are use in the 3p ecosystem
I remember somebody trying to hook into the Apple Find My network (that is, do things with AirTags). They did that by… being a Mail.app plug-in or something to get the correct entitlements? That certainly sounds like the wrong permissions.
Imagining my grandpa calling me because his camera doesn't work because he denied the camera permission on his camera app. But then he can't because he denied all the permissions his phone app needs.
What argument? Are you preemptively mad about something that's not happening? I just had a funny thought brother, I'd rather not be involved in your OS platform supremacy battle.
> With its operating systems and its App Store, Apple controls a key infrastructure for the distribution of apps on its devices. In addition, Apple offers its own apps and advertising space. This dual role makes Apple subject to specific competition law requirements.
> Under the commitments that have now been declared binding, Apple will align the consent prompts for its own offerings and for third-party apps much more closely.
As has been evident in many spheres of human activity recently, being brazen about conflicts of interest, is often used as a PR shield for those conflicts.
Sometimes transparency and honesty get weaponized. Especially by actors with centralized power.
(Not arguing against transparency, but against misinterpreting it as always being used in the interests of good faith.)
You want to handle device rotation smoothly in your in-app browser?
Tough luck, WebKit's _beginAnimatedResizeWithUpdates is private, and only Apple gets to use it in Safari.
Good luck with the animation and scroll position handling. You better hope WkWebView's default behavior works for you, because you don't get to customize it and fix edge cases or the tab previews, like Apple did for their browser.
I see the regulators only regulated that first-party and third-party apps be treated equally, and didn’t specify how.
It’s a bummer (albeit an expected one) to see Apple reducing the burden for third-party publishers to collect personal data, rather than increasing the burden for themselves to collect it, thus overall raising the floor of user privacy. This is to say, when a regulator requests “everyone be treated equally to ensure competition” maybe they should also take into account how users are impacted and instead request something more nuanced like: if there are unequal standards, they must be equalized in a way that maximizes user benefit.
Regulations for user privacy shouldn't be conflated with regulations for market competition.
I also delight in this highlighting Apple's hypocrisy
Apple's hypocrisy is a longstanding issue with regard to their apps vs 3rd party apps. As I recall when the Green Bubbles first happened in messages someone pointed out that Apples own design guidelines specified a minimum contrast in colors or they would reject apps, and the green bubbles with white text did not meet that threshold at the time, and it stayed that way for quite a while. And for all I know the light themed version of the app still does (I have mine on permanent dark theme).
https://medium.com/@krvoller/how-iphone-violates-apples-acce...
There's two problems here:
1. The competition law people are not the data protection people. From the perspective of competition law, they only care that the playing field is leveled, they don't care if you equalize down or up.
2. The EU has fumbled the ball on GDPR by not enforcing it on the tech giants that it was intended to regulate[0], to the point where a tech company enforcing the intent of the law and not the letter of the law feels like singling out competitors.
[0] In particular, the Republic of Ireland is a rotten borough for Facebook, who has all their EU offices there.
Title doesn't match the article, which is currently "Apple changes its rules for personalised advertising in apps".
Apple gave itself better dialogs for the permission prompts, which they will now equalize (perhaps just in the EU?) with the prompts they use for their own apps.
My understanding of ATTF is that first-party tracking needed no disclosure other than the information declared in the app's App Store privacy section about the information gathered. If you made a suite of 20 apps, you could track usage across all of them without issue, as long as you didn't also share that info with a third party.
A good step.
Apple's own apps are still blessed with permissions that other apps have to ask for. This needs to be addressed too.
For me it depends on which app and which permissions, like "Photos" obviously needs to be able to see my photos... Camera needs my camera, but for location it should ask me before it turns it on.
I don't even care if they make the dialogue look a little different since they're system apps you need to use the features of your phone, but the "extras" they support should default to "Ask First" in an ideal world that is.
> like "Photos" obviously needs to be able to see my photos...
Maybe you'd like to use a competitor to the Photos app and don't want to use the one Apple provides?
Maybe.
But what does the "Access to photos" permission really do here? It's not like not having that permission would stop Apple from accessing them against your will, as they have access via the OS anyway. And it's clear, that when you open the Apple Photos app, that it will access your photos.
On the other hand, when you open a third party app, it may not have been clear to you that it wants to access your photos, and the company did not have prior access to them.
I still think apps should only be pre-blessed sparingly. For example, the camera app should not have GPS permission by default, as many people probably aren't aware that camera apps use that information.
Tangential, but:
"Access to Photos" is a complicated one: An app only needs this permission when building a custom photo selector. Like Facebook/WhatsApp/Instagram do, also Slack.
For every other app, they can use the system's default photo picker and it works without permission.
For example, the "Lunch Receipt Scanner" that my company uses: I'm happy to allow it on my phone, as it saves a lot of time, but I wouldn't want a company app having access to my entire camera roll!!!
I personally also don't like that WhatsApp/Instagram/Facebook/Slack asks for access to the whole album just to display the photo picker, but I'm pretty sure some designer or product manager made a strong case for it internally.
That should be supported, but if its the only "Photo Gallery" app installed, I think its okay. Curious, do you use another one that's better? I have looked (though not very invested in looking) and didn't really see anything that caught my eye.
Fair, but when a 3p app has camera in the name and app description then why does it need to ask permission to use the camera? *just to be clear I think that the stock camera app not asking for camera permission is fine but skipping permission about location tracking is wrong. Having the same standard should be applied to both 1p and 3p apps feel like a fair way to ensure that good practices are used in 1p apps and good policies are use in the 3p ecosystem
I remember somebody trying to hook into the Apple Find My network (that is, do things with AirTags). They did that by… being a Mail.app plug-in or something to get the correct entitlements? That certainly sounds like the wrong permissions.
Ah, it was OpenHaystack: https://github.com/seemoo-lab/openhaystack#installation
Well you could argue all bundled OS apps should have a dialog similar to the browser selection Microsoft was forced to implement.
The nasty bit about location services is that it is trivially easy to turn it on but much harder to turn it off.
Imagining my grandpa calling me because his camera doesn't work because he denied the camera permission on his camera app. But then he can't because he denied all the permissions his phone app needs.
This is about tracking not actual functionality .
Yeah I messed up, was supposed to reply to https://news.ycombinator.com/item?id=49331222#49331921
> ... Apple's own apps are still blessed with permissions that other apps have to ask for. This needs to be addressed too.
Things that don't happen and that you make up for to win a hypothetical argument: this one.
What argument? Are you preemptively mad about something that's not happening? I just had a funny thought brother, I'd rather not be involved in your OS platform supremacy battle.
A monthly headline could honestly just read "Apple treated its own better than rivals" and it would always be relevant
> With its operating systems and its App Store, Apple controls a key infrastructure for the distribution of apps on its devices. In addition, Apple offers its own apps and advertising space. This dual role makes Apple subject to specific competition law requirements.
> Under the commitments that have now been declared binding, Apple will align the consent prompts for its own offerings and for third-party apps much more closely.
Fork found in kitchen.
spoon still missing
I'm already curious what kind of malicious compliance Apple will invent this time. When it comes to that, their creativity knows no bounds.
Apple never hid the fact that their apps work better on their devices. They have access to APIs that third parties do not have.
I don’t think it’s a bad thing necessarily.
As has been evident in many spheres of human activity recently, being brazen about conflicts of interest, is often used as a PR shield for those conflicts.
Sometimes transparency and honesty get weaponized. Especially by actors with centralized power.
(Not arguing against transparency, but against misinterpreting it as always being used in the interests of good faith.)
What makes it a "bad thing" if competitors have equal access? May the best implementation win.
I do think it's a bad thing and I believe the EU regulators agree.
There are whole classes of applications that are not possible unless low level device data is exposed via APIs.
And since Apple doesn't provide the apps, the apps won't exist until Apple creates them.
Isn’t the EU regulation specifically about this?
I think it's bad.
You want to handle device rotation smoothly in your in-app browser?
Tough luck, WebKit's _beginAnimatedResizeWithUpdates is private, and only Apple gets to use it in Safari.
Good luck with the animation and scroll position handling. You better hope WkWebView's default behavior works for you, because you don't get to customize it and fix edge cases or the tab previews, like Apple did for their browser.
Earlier:
https://news.ycombinator.com/item?id=43047952
Watchdog ponders why Apple doesn't apply its strict app tracking rules to itself (theregister.com)
161 points by Logans_Run on Feb 14, 2025 | 69 comments
Smells like another successful lobby attempt by VG Wort. Disgusting.