surprised this didn’t even touch on how aggressive the banners are, how apps can’t take advantage of ad blockers, etc. there’s so much more to it than just “missing features”.
Ideally the OS sandboxing prevents mobile apps from collecting sensitive data without permission, but in practice there’s an awful lot of data that’s not gated behind permissions and wouldn’t be accessible to a website! I wish sensors (accelerometer, etc.) and persistent Keychain entries weren’t accessible to apps on iOS without an entitlement from Apple (to ensure it’s for a legitimate reason) and a user permission.
I don't know if there's an equivalent for iOS but the LinkedIn (or Facebook? tomato/tomahto/dumpsterfire) app was caught broadcasting Intents to determine what other applications were installed on the device as a mixture of "moar precious ad signal" and "fingerprinting"
I can't be bothered to look it up, since I'm sure both of those apps now do something much worse but I did want to draw attention that location data is arguably the least valuable signal that a native app can collect about you :(
What's the problem with sensors? Presumably you could use these to infer e.g. walking patterns, and maybe even infer location changes... except that iOS should throttle your background execution for battery reasons enough that you can't do that stuff anyway, no? I might be missing something!
Similar question for persistent Keychain entries - the main thing I can think of is that an app that doesn't have an obvious sign-in or anything like that should not be allowed to store a persistent identifier, but couldn't they store that with regular non-secure app data? (Unless apps can introspect Keychain entries of other apps? Which would be bonkers.)
If I uninstall and reinstall an app (and the others from the same developer), I’d like it to see my device as completely new. The persistent Keychain entry lets apps track you across sessions, so even if you have multiple accounts they’ll always be associated.
Sensors can allow apps to determine the user’s location (by correlating to other devices on a moving train, for example), and they can also be used for fingerprinting.
AdGuard Home has been great for me. Mentioning it partly because when I looked into it vs. Pi-hole, AdGuard Home seemed to be more... performant? Featureful? Something? I can't remember.
(The big driver for me to use it over Pi-hole, to be clear, was that it was packaged as a Home Assistant app and Pi-hole was not, so take me deciding it was better with a hefty grain of salt!)
I used to work exclusively on an ipad. The google slides app doesn't support putting transitions on slides, you can only do that from a computer. Loading the desktop site on ipad worked perfectly fine.
Ironically, I was setting up a new Venmo account recently and they don't even let you do identify verification or set up a business on the web. I called support since that's what it told me to do and they said those features are only available in the app with a shrug for if and when they'd come to the browser.
My employer sponsors a OneMedical membership for me, and they do this too. It's bonkers to me that I can't get some health care features without their proprietary app.
On the topic of Google Calendar grievances, the WearOS app for it does not sync anything except your Google calendars so if you use a CalDAV calendar using Davx5 you can see the events on the phone version of the app but not on the watch. Truly baffling choices are being made by this team.
lilac | 6 days ago
surprised this didn’t even touch on how aggressive the banners are, how apps can’t take advantage of ad blockers, etc. there’s so much more to it than just “missing features”.
hjvt | 6 days ago
Or, less outwardly annoying and more insidious, no way to limit data collection.
pgeorgi | 5 days ago
two major reasons why folks are "encouraged" to use the apps.
snazz | 5 days ago
Ideally the OS sandboxing prevents mobile apps from collecting sensitive data without permission, but in practice there’s an awful lot of data that’s not gated behind permissions and wouldn’t be accessible to a website! I wish sensors (accelerometer, etc.) and persistent Keychain entries weren’t accessible to apps on iOS without an entitlement from Apple (to ensure it’s for a legitimate reason) and a user permission.
diktomat | 5 days ago
There’s an app called Loupe that shows just how much data an app can gather without and with extra permission prompts.
snazz | 5 days ago
That is a fantastic way to visualize the problem, thank you for sharing!
strugee | 5 days ago
This looks awesome. I wish there was something that simple for Android!
mdaniel | 5 days ago
I don't know if there's an equivalent for iOS but the LinkedIn (or Facebook? tomato/tomahto/dumpsterfire) app was caught broadcasting Intents to determine what other applications were installed on the device as a mixture of "moar precious ad signal" and "fingerprinting"
I can't be bothered to look it up, since I'm sure both of those apps now do something much worse but I did want to draw attention that location data is arguably the least valuable signal that a native app can collect about you :(
hjvt | 5 days ago
I believe apps may also skirt around whatever laws manifested the cookie policy popups into existance
strugee | 4 days ago
What's the problem with sensors? Presumably you could use these to infer e.g. walking patterns, and maybe even infer location changes... except that iOS should throttle your background execution for battery reasons enough that you can't do that stuff anyway, no? I might be missing something!
Similar question for persistent Keychain entries - the main thing I can think of is that an app that doesn't have an obvious sign-in or anything like that should not be allowed to store a persistent identifier, but couldn't they store that with regular non-secure app data? (Unless apps can introspect Keychain entries of other apps? Which would be bonkers.)
snazz | 4 days ago
If I uninstall and reinstall an app (and the others from the same developer), I’d like it to see my device as completely new. The persistent Keychain entry lets apps track you across sessions, so even if you have multiple accounts they’ll always be associated.
Sensors can allow apps to determine the user’s location (by correlating to other devices on a moving train, for example), and they can also be used for fingerprinting.
fragmentcity | 5 days ago
You can get surprisingly far with Pi-hole!
lilac | 5 days ago
which I have, and it’s a good recommendation, but:
strugee | 4 days ago
AdGuard Home has been great for me. Mentioning it partly because when I looked into it vs. Pi-hole, AdGuard Home seemed to be more... performant? Featureful? Something? I can't remember.
(The big driver for me to use it over Pi-hole, to be clear, was that it was packaged as a Home Assistant app and Pi-hole was not, so take me deciding it was better with a hefty grain of salt!)
carlana | 5 days ago
If you get that joke, it's time for your mammogram/prostate test.
0x2ba22e11 | 5 days ago
Crap.
juliethefoxcoon | 5 days ago
I used to work exclusively on an ipad. The google slides app doesn't support putting transitions on slides, you can only do that from a computer. Loading the desktop site on ipad worked perfectly fine.
[OP] abnercoimbre | 5 days ago
Tangential but why did you stop working on the iPad?
Halkcyon | 5 days ago
Ironically, I was setting up a new Venmo account recently and they don't even let you do identify verification or set up a business on the web. I called support since that's what it told me to do and they said those features are only available in the app with a shrug for if and when they'd come to the browser.
[OP] abnercoimbre | 5 days ago
Oh this is true. Mobile-app-only features are kind of a plague too. Damned if you do..
strugee | 4 days ago
My employer sponsors a OneMedical membership for me, and they do this too. It's bonkers to me that I can't get some health care features without their proprietary app.
squarism | 5 days ago
Engagement, KPIs. OP got the incentives. I like the article's point, I'll probably notice it more now.
msfjarvis | 5 days ago
On the topic of Google Calendar grievances, the WearOS app for it does not sync anything except your Google calendars so if you use a CalDAV calendar using Davx5 you can see the events on the phone version of the app but not on the watch. Truly baffling choices are being made by this team.