42 comments

[ 0.24 ms ] story [ 74.5 ms ] thread
I see the regulators only regulated that first-party and third-party apps be treated equally, and didn’t specify how.

It’s a bummer (albeit an expected one) to see Apple reducing the burden for third-party publishers to collect personal data, rather than increasing the burden for themselves to collect it, thus overall raising the floor of user privacy. This is to say, when a regulator requests “everyone be treated equally to ensure competition” maybe they should also take into account how users are impacted and instead request something more nuanced like: if there are unequal standards, they must be equalized in a way that maximizes user benefit.

A good step.

Apple's own apps are still blessed with permissions that other apps have to ask for. This needs to be addressed too.

>Apple's own apps are still blessed with permissions that other apps have to ask for. This needs to be addressed too.

This is a strange position imo. Why would we expect third party apps written by totally unknown people with unknown goals to have the same permissions as apps written by Apple itself?

I thought the appstore was safe because of its vetting, at least that's what they officially say
I don't think that is contradictory either. By limiting 3rd-party permissions, Apple is able to prevent many potential issues before an application even makes it to the vetting process. The less there is to vet, the more robust the vetting process should be in theory.
Idk what their vetting includes but I doubt it's a full security audit of the codebase of each app for example and so without something like that why would you ever expect a 3p app to get the same permissions as an Apple internal one?
Personally I don't, I would just downgrade the Apple permissions to match normal apps, I'm just pointing the doublespeak
Which essentially makes the phone a brick and unusable for 99% of consumers. Average users don't care about your weird esoteric privacy and security concerns.
Because not doing so hampers competition, it gives Apple’s first-party apps an unfair advantage over third-party alternatives.

Also, I don’t actually know Apple’s developers and their goals.

But you likely feel somewhat comfortable with them if you purchased an iPhone.

Purchasing an iPhone self-selects people who are comfortable with the idea of the features it is marketed as having, such as being able to take, store and manipulate photos out of the box.

This is also an issue primarily because there is no third-party photo picker extension point. A third party only gets photo picker support if they store their photos into the Photos library. If third party photo apps could have similar integration points based on them maintaining their own first-party library, they would not need to ask permission to manipulate another program's data store.

I’m not more comfortable with them as with third-party apps that I choose. Either of them are products that I sought out.

I agree that the photo picker should integrate with third-party photo apps just the same.

Requiring Apple's own apps to use the same permission prompts as 3rd party apps does something very important: it incentivises Apple to improve the permissions experience for all developers.

Currently, the permissions APIs and user experience are designed horribly, and there's a disincentive for Apple to fix it.

Random example: if you write into the photo library, you don't have permission to read back what you wrote. You can't even deep link to that media in the photos app*

*Unless you are Apple.

Apple never hid the fact that their apps work better on their devices. They have access to APIs that third parties do not have.

I don’t think it’s a bad thing necessarily.

> With its operating systems and its App Store, Apple controls a key infrastructure for the distribution of apps on its devices. In addition, Apple offers its own apps and advertising space. This dual role makes Apple subject to specific competition law requirements.

> Under the commitments that have now been declared binding, Apple will align the consent prompts for its own offerings and for third-party apps much more closely.

Imagining my grandpa calling me because his camera doesn't work because he denied the camera permission on his camera app. But then he can't because he denied all the permissions his phone app needs.
Title doesn't match the article, which is currently "Apple changes its rules for personalised advertising in apps".

Apple gave itself better dialogs for the permission prompts, which they will now equalize (perhaps just in the EU?) with the prompts they use for their own apps.

My understanding of ATTF is that first-party tracking needed no disclosure other than the information declared in the app's App Store privacy section about the information gathered. If you made a suite of 20 apps, you could track usage across all of them without issue, as long as you didn't also share that info with a third party.

Apple didn't give itself better dialogs. It never did third-party tracking across across apps or websites so the ATT prompt would never apply to their apps. It also voluntarily showed a dialog explicitly asking you to opt into personalized advertising. Facebook doesn't show anything similar when you use Instagram or the Facebook app, because that would be undoubtedly bad for business.

The German regulator settled because the facts are simply on Apple's side. Apple settled because at the end of the day it's no skin off their back if the EU now wants to weaken privacy protections to benefit ad-tech.

Instagram does, in fact, have such a dialog in the EU. Because they are legally required to, like everybody else.
Nothing on page 1 of the faq supports any of the assertions in your comment.
> Title doesn't match the article, which is currently "Apple changes its rules for personalised advertising in apps".

The guy who made-up this incorrect title is an SEO marketer, who I'm sure has good-faith concerns about "competition", lmfao.

"Apple doesn't follow the rules it imposes on others" has never been the claim by any of these regulators (French[0], Italian[1], now German), yet everyone believes it thank to this impressive yearslong astroturfing campaign by the ad industry. The real argument was whether Apple was allowed to materially harm the interests of the ad industry. Well, great, now they've won. Will regulators take up the mantle which is rightfully theirs, and which they've now taken away from Apple? Somehow I doubt it.

[0]: The French ruling, for example, was that ATT was "neither necessary nor proportionate" from a privacy standpoint and disadvantaged small publishers.

[1]: The Italian ruling was that ATT "harm the interests of Apple’s commercial partners", and secondarily is "disproportionate to the [...] stated data protection objectives".

I'm already curious what kind of malicious compliance Apple will invent this time. When it comes to that, their creativity knows no bounds.
Smells like another successful lobby attempt by VG Wort. Disgusting.
A monthly headline could honestly just read "Apple treated its own better than rivals" and it would always be relevant
I used to work on an app with one of the largest repos of health data in the App Store. Their team specifically leaned on us to have more favorable text when the data sharing requests came through. Felt very inappropriate given we were often at Apple’s mercy. Seems like a consistent cultural issue.
They also do other things you aren’t allowed to do as a developer - eg. When they do a ‘free trial’ of Apple TV, if you cancel it cancels immediately. All proper subscriptions you retain the use of until the renewal date.
(comment deleted)
Meta would have a field day with this change, since it was the company that was most upset and angry when ATT was introduced.

Considering that ATT was about sharing an identifier to “track across other companies' apps and websites” (text definition of the ATT setting), I don’t believe this ruling is a good move for anyone on informed consent or privacy. In the name of improving competition, sometimes regulators may end up making things worse for users.

Meta, the same company that used to play silent audio so it wouldn't be killed in the background? I'm not super worried about them being upset about privacy laws changing.
There are arguments about how Apple has too much power and we need better app stores and anecdotes about I-built-an-app-it-was-a-nightmare

...but Meta is exactly the reason why IMO it's needed. Because of people like Zuckerberg who treat the internet and people's phones like his personal plaything. No granularity. Contacts uploaded whenever anyone does the slightest thing

There's widespread misunderstanding about this.

Apple doesn't do cross-company tracking, and ATT blocks third-parties from doing cross-company tracking. The rules are the same. The German anti-cartel authorities' issue is:

> In contrast, Apple’s own personalised advertising is subject to different conditions. Apple itself does not use the IDFA and cross-company data combination, but draws on user data from its own ecosystem – a wealth of data that is not available, in particular, to the large number of smaller app publishers.

> In addition, app publishers and content providers, such as media publishers, will be given more scope to explain to users what significance personalised advertising has for their offering and their business model.

Great, sounds like a new channel for marketing where I really just want to opt-out. Also, does this added scope include the mechanism to maliciously comply like so many websites do with cookies? (eg: You want our cookies? Here is a list of things you can de-select... with toggles that aren't clearly on or off)

Actual title: Apple changes its rules for personalised advertising in apps