I see the regulators only regulated that first-party and third-party apps be treated equally, and didn’t specify how.
It’s a bummer (albeit an expected one) to see Apple reducing the burden for third-party publishers to collect personal data, rather than increasing the burden for themselves to collect it, thus overall raising the floor of user privacy. This is to say, when a regulator requests “everyone be treated equally to ensure competition” maybe they should also take into account how users are impacted and instead request something more nuanced like: if there are unequal standards, they must be equalized in a way that maximizes user benefit.
Apple's hypocrisy is a longstanding issue with regard to their apps vs 3rd party apps. As I recall when the Green Bubbles first happened in messages someone pointed out that Apples own design guidelines specified a minimum contrast in colors or they would reject apps, and the green bubbles with white text did not meet that threshold at the time, and it stayed that way for quite a while. And for all I know the light themed version of the app still does (I have mine on permanent dark theme).
1. The competition law people are not the data protection people. From the perspective of competition law, they only care that the playing field is leveled, they don't care if you equalize down or up.
2. The EU has fumbled the ball on GDPR by not enforcing it on the tech giants that it was intended to regulate[0], to the point where a tech company enforcing the intent of the law and not the letter of the law feels like singling out competitors.
[0] In particular, the Republic of Ireland is a rotten borough for Facebook, who has all their EU offices there.
Title doesn't match the article, which is currently "Apple changes its rules for personalised advertising in apps".
Apple gave itself better dialogs for the permission prompts, which they will now equalize (perhaps just in the EU?) with the prompts they use for their own apps.
My understanding of ATTF is that first-party tracking needed no disclosure other than the information declared in the app's App Store privacy section about the information gathered. If you made a suite of 20 apps, you could track usage across all of them without issue, as long as you didn't also share that info with a third party.
For me it depends on which app and which permissions, like "Photos" obviously needs to be able to see my photos... Camera needs my camera, but for location it should ask me before it turns it on.
I don't even care if they make the dialogue look a little different since they're system apps you need to use the features of your phone, but the "extras" they support should default to "Ask First" in an ideal world that is.
But what does the "Access to photos" permission really do here? It's not like not having that permission would stop Apple from accessing them against your will, as they have access via the OS anyway. And it's clear, that when you open the Apple Photos app, that it will access your photos.
On the other hand, when you open a third party app, it may not have been clear to you that it wants to access your photos, and the company did not have prior access to them.
I still think apps should only be pre-blessed sparingly. For example, the camera app should not have GPS permission by default, as many people probably aren't aware that camera apps use that information.
"Access to Photos" is a complicated one: An app only needs this permission when building a custom photo selector. Like Facebook/WhatsApp/Instagram do, also Slack.
For every other app, they can use the system's default photo picker and it works without permission.
For example, the "Lunch Receipt Scanner" that my company uses: I'm happy to allow it on my phone, as it saves a lot of time, but I wouldn't want a company app having access to my entire camera roll!!!
I personally also don't like that WhatsApp/Instagram/Facebook/Slack asks for access to the whole album just to display the photo picker, but I'm pretty sure some designer or product manager made a strong case for it internally.
That should be supported, but if its the only "Photo Gallery" app installed, I think its okay. Curious, do you use another one that's better? I have looked (though not very invested in looking) and didn't really see anything that caught my eye.
Fair, but when a 3p app has camera in the name and app description then why does it need to ask permission to use the camera?
*just to be clear I think that the stock camera app not asking for camera permission is fine but skipping permission about location tracking is wrong. Having the same standard should be applied to both 1p and 3p apps feel like a fair way to ensure that good practices are used in 1p apps and good policies are use in the 3p ecosystem
I remember somebody trying to hook into the Apple Find My network (that is, do things with AirTags). They did that by… being a Mail.app plug-in or something to get the correct entitlements? That certainly sounds like the wrong permissions.
Imagining my grandpa calling me because his camera doesn't work because he denied the camera permission on his camera app. But then he can't because he denied all the permissions his phone app needs.
What argument? Are you preemptively mad about something that's not happening? I just had a funny thought brother, I'd rather not be involved in your OS platform supremacy battle.
> With its operating systems and its App Store, Apple controls a key infrastructure for the distribution of apps on its devices. In addition, Apple offers its own apps and advertising space. This dual role makes Apple subject to specific competition law requirements.
> Under the commitments that have now been declared binding, Apple will align the consent prompts for its own offerings and for third-party apps much more closely.
As has been evident in many spheres of human activity recently, being brazen about conflicts of interest, is often used as a PR shield for those conflicts.
Sometimes transparency and honesty get weaponized. Especially by actors with centralized power.
(Not arguing against transparency, but against misinterpreting it as always being used in good faith.)
You want to handle device rotation smoothly in your in-app browser?
Tough luck, WebKit's _beginAnimatedResizeWithUpdates is private, and only Apple gets to use it in Safari.
Good luck with the animation and scroll position handling. You better hope WkWebView's default behavior works for you, because you don't get to customize it and fix edge cases or the tab previews, like Apple did for their browser.
It’s a bummer (albeit an expected one) to see Apple reducing the burden for third-party publishers to collect personal data, rather than increasing the burden for themselves to collect it, thus overall raising the floor of user privacy. This is to say, when a regulator requests “everyone be treated equally to ensure competition” maybe they should also take into account how users are impacted and instead request something more nuanced like: if there are unequal standards, they must be equalized in a way that maximizes user benefit.
I also delight in this highlighting Apple's hypocrisy
https://medium.com/@krvoller/how-iphone-violates-apples-acce...
1. The competition law people are not the data protection people. From the perspective of competition law, they only care that the playing field is leveled, they don't care if you equalize down or up.
2. The EU has fumbled the ball on GDPR by not enforcing it on the tech giants that it was intended to regulate[0], to the point where a tech company enforcing the intent of the law and not the letter of the law feels like singling out competitors.
[0] In particular, the Republic of Ireland is a rotten borough for Facebook, who has all their EU offices there.
Apple gave itself better dialogs for the permission prompts, which they will now equalize (perhaps just in the EU?) with the prompts they use for their own apps.
My understanding of ATTF is that first-party tracking needed no disclosure other than the information declared in the app's App Store privacy section about the information gathered. If you made a suite of 20 apps, you could track usage across all of them without issue, as long as you didn't also share that info with a third party.
Apple's own apps are still blessed with permissions that other apps have to ask for. This needs to be addressed too.
I don't even care if they make the dialogue look a little different since they're system apps you need to use the features of your phone, but the "extras" they support should default to "Ask First" in an ideal world that is.
Maybe you'd like to use a competitor to the Photos app and don't want to use the one Apple provides?
But what does the "Access to photos" permission really do here? It's not like not having that permission would stop Apple from accessing them against your will, as they have access via the OS anyway. And it's clear, that when you open the Apple Photos app, that it will access your photos.
On the other hand, when you open a third party app, it may not have been clear to you that it wants to access your photos, and the company did not have prior access to them.
I still think apps should only be pre-blessed sparingly. For example, the camera app should not have GPS permission by default, as many people probably aren't aware that camera apps use that information.
"Access to Photos" is a complicated one: An app only needs this permission when building a custom photo selector. Like Facebook/WhatsApp/Instagram do, also Slack.
For every other app, they can use the system's default photo picker and it works without permission.
For example, the "Lunch Receipt Scanner" that my company uses: I'm happy to allow it on my phone, as it saves a lot of time, but I wouldn't want a company app having access to my entire camera roll!!!
I personally also don't like that WhatsApp/Instagram/Facebook/Slack asks for access to the whole album just to display the photo picker, but I'm pretty sure some designer or product manager made a strong case for it internally.
Ah, it was OpenHaystack: https://github.com/seemoo-lab/openhaystack#installation
> ... Apple's own apps are still blessed with permissions that other apps have to ask for. This needs to be addressed too.
> Under the commitments that have now been declared binding, Apple will align the consent prompts for its own offerings and for third-party apps much more closely.
I don’t think it’s a bad thing necessarily.
Sometimes transparency and honesty get weaponized. Especially by actors with centralized power.
(Not arguing against transparency, but against misinterpreting it as always being used in good faith.)
There are whole classes of applications that are not possible unless low level device data is exposed via APIs.
And since Apple doesn't provide the apps, the apps won't exist until Apple creates them.
You want to handle device rotation smoothly in your in-app browser?
Tough luck, WebKit's _beginAnimatedResizeWithUpdates is private, and only Apple gets to use it in Safari.
Good luck with the animation and scroll position handling. You better hope WkWebView's default behavior works for you, because you don't get to customize it and fix edge cases or the tab previews, like Apple did for their browser.
https://news.ycombinator.com/item?id=43047952
Watchdog ponders why Apple doesn't apply its strict app tracking rules to itself (theregister.com)
161 points by Logans_Run on Feb 14, 2025 | 69 comments