News: 1715043927

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google, Meta, Spotify break Apple's device fingerprinting rules – new claim

(2024/05/07)


Last week, Apple began requiring iOS developers justify the use of a specific set of APIs that could be used for device fingerprinting. Yet the iGiant doesn't appear to be making much effort to ensure that Google, Meta, and Spotify comply with the rules, it's claimed.

Device fingerprinting involves collecting information about various device settings and components, then combining those into a single identifier that's likely to be unique and thus useful for targeting people with ads and other stuff tailored to their individual interests and circumstances.

There are other forms of fingerprinting involving browser settings, the HTML Canvas element, WebGL, fonts, and so on, some of which have legitimate commercial applications, such as bot detection. But digital fingerprinting can also be used to violate privacy and track people online.

We found out that apps such as Google Chrome, Instagram, Spotify, and Threads don’t adhere to their declared reasons

While Apple allows user tracking if permission has been granted, it mostly [1]forbids device-level fingerprinting on iOS, at least in theory. It made that policy official in a recent [2]blog post .

As such the iBiz now requires app developers to supply among other things reasons for using any of its designated "required reason APIs" that can be used for device fingerprinting.

[3]

Crucially, data collected from these interfaces, which could be used for fingerprinting, must stay on the user's device to maximize privacy.

[4]

[5]

The iPhone maker explains as much in its developer documentation. "Some APIs that your app uses to deliver its core functionality — in code you write or included in a third-party SDK — have the potential of being misused to access device signals to try to identify the device or user, also known as fingerprinting," the Apple's developer website [6]states . "Regardless of whether a user gives your app permission to track, fingerprinting is not allowed."

Examples of these fingerprint-friendly APIs include: File timestamp APIs, System boot time APIs, Disk space APIs, Active keyboard APIs, and User defaults APIs.

[7]

As of May 1, 2024, apps that fail to include reasons for using these APIs in their privacy manifest file won't be accepted in the iOS App Store. Previously, Apple just sent non-compliant developers an email warning.

According to developers Talal Haj Bakry and Tommy Mysk, several major app makers are simply ignoring Apple's requirements, and using tracker-happy APIs without sticking to the rules. Big Tech players like Google, Meta, and Spotify - the duo claim - are providing reasons for this API usage, collecting that data, and then not abiding by the requirement to keep that information on the device.

In other words, Google, Meta, and Spotify are all collecting at least some info from these APIs and then sending that data off to base against Apple's rules, we're told.

[8]

"To prevent misuse of these APIs, Apple will reject apps that don’t describe their use of the APIs in their privacy manifest file," the pair explain in an [9]advisory . "However, we found out that apps such as Google Chrome, Instagram, Spotify, and Threads don’t adhere to their declared reasons."

[10]Apple demands app makers explain use of sensitive APIs

[11]Online tracking is alive and well in link decoration

[12]Apple iOS privacy clampdown 'did little' to reduce tracking

[13]What do iOS and Android have in common? Their apps suck at privacy, boffins say

The Register asked Google, Meta, and Spotify whether they are in fact using these "required reason APIs" for iOS device fingerprinting and beaming that data off to backend servers, and we've not heard back from the last two. A Google spokesperson confirmed it is looking into the report, but didn't immediately have a response.

"It's hard to tell if the apps are using the information for fingerprinting or not," said Mysk in a message to The Register . "But Apple already classified a set of APIs that can potentially be used for fingerprinting. Apps accessing such APIs must declare the reasons why they need such access."

Apple has published a [14]list of valid reasons for using certain APIs that reveal information useful for fingerprinting. For example, iOS provides an API called [15]systemUptime that can be queried to provide the time elapsed since the device was last restarted.

Developers who want to use this API can select from several allowed reasons, one which must be declared in a manifest file. Google for example has chosen 35F9.1, with italics added by us for emphasis:

Declare this reason to access the system boot time in order to measure the amount of time that has elapsed between events that occurred within the app or to perform calculations to enable timers.

Information accessed for this reason, or any derived information, may not be sent off-device. There is an exception for information about the amount of time that has elapsed between events that occurred within the app, which may be sent off-device.

Although Apple's rule plainly states that uptime data cannot be sent off-device, Google Chrome appears to be doing just that, based on network data analysis from Bakry and Mysk. The rule does allow for an exception, but one that doesn't apply to Chrome.

"No, this exception is about using the system uptime on-device locally to order events for example," Mysk told The Register , explaining that Google has the option to transmit relative time intervals between two events but not the absolute device uptime number.

Mysk argues that Apple's "required reason APIs," like its Privacy Nutrition Labels, amount to privacy theater because there appears to be no enforcement.

"Just like the Privacy Nutrition Labels, developers are free to enter what they please," said Mysk.

"Apple doesn't seem to review if the description is accurate or not. While the nutrition labels are visible to the users, the required reason API isn't. So, it is not clear how that is going to prevent fingerprinting and enhance user privacy if Apple doesn't check the reasons developers submit."

Cupertino did not respond to a request for comment. ®

Get our [16]Tech Resources



[1] https://developer.apple.com/videos/play/wwdc2023/10060/?time=457

[2] https://developer.apple.com/support/third-party-SDK-requirements/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZjmnXNuYnZ58lon0tciNYgAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjmnXNuYnZ58lon0tciNYgAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjmnXNuYnZ58lon0tciNYgAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://developer.apple.com/documentation/bundleresources/privacy_manifest_files/describing_use_of_required_reason_api

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjmnXNuYnZ58lon0tciNYgAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjmnXNuYnZ58lon0tciNYgAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.mysk.blog/2024/05/03/apple-required-reason-api/

[10] https://www.theregister.com/2023/07/29/apple_developer_api/

[11] https://www.theregister.com/2023/10/06/link_tracking_privacy/

[12] https://www.theregister.com/2022/04/08/apple_ios_privacy/

[13] https://www.theregister.com/2021/09/30/apple_google_privacy/

[14] https://developer.apple.com/documentation/bundleresources/privacy_manifest_files/describing_use_of_required_reason_api

[15] https://developer.apple.com/documentation/foundation/processinfo/1414553-systemuptime

[16] https://whitepapers.theregister.com/



aerogems

Apple has always had at least two sets of rules. There's one set of rules for the large players, and then there's the public rules that everyone else has to follow. Saw this back when I was doing hardware repairs for Apple laptops. The Foxconn-run repair depots could get parts I couldn't, didn't have to worry about all the metrics I did, and didn't have their Apple rep messaging them like every single day demanding that the company turn its entire business upside down just to accommodate Apple.

I wasn't actually in this meeting, but I was told by my manager immediately after how they brought up how a larger competitor didn't have Apple riding their ass like we did, and the rep basically said how the company I worked for didn't even compare to the other one. Real professional. It was true in a lot of ways, but still, you'd think they'd at least feign impartiality even if everyone knew it was a crock of shit.

Google is worth at least a couple billion in revenue for Apple with the default search engine deal and probably some other things. Facebook also likely pays Apple some kickbacks to make sure Facebook always appears at the top of curated lists on the App Store, and Spotify also has to be worth a decent chunk of change from the cut of subscription fees Apple takes.

Blessed are the forgetful: for they get the better even of their blunders.
-- Nietzsche