Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I'm honestly less worried about Apple than others.

That's a pretty low bar. Yes, Apple at least gives lip service to security which other companies don't even bother to do, but Apple has had some pretty major security screwups lately (three in the last few weeks). You might be less worried about Apple than the competition, but you'd do well to be somewhat worried about them nonetheless.



Apple has had some pretty major security screwups lately

What I'm about to write does not invalidate your statement and concern, but to me there's a huge gulf between a bug and a willfully-designed feature that explicitly follows a security anti-pattern.


Two other issues I'm worried about with iOS:

- MAC address tracking (RTS packets thrwart MAC randomization[0], not immediately clear if WiFi is fully off[1])

- All-or-nothing access to photos on the phone (append-only for apps that request it)

Discord in particular is bad for the photo permission, as I don't trust China's Tencent with access to all the photos on my phone (which can include lots of frequent location information!), but pasting images doesn't work in the app.

I had assumed the "Photos" permission meant "permission to prompt this dialogue" and "permission to save to Camera Roll".

[0] https://arxiv.org/pdf/1703.02874v1.pdf [1] https://support.apple.com/en-us/HT208086


In iOS 11, there is a new permission that an app can ask for, which grants write-only access to the photo library. [0]

"To protect user privacy, an iOS app linked on or after iOS 10.0, and that accesses the user’s photo library, must statically declare the intent to do so."

[0] https://developer.apple.com/library/content/documentation/Ge...


Apple changed the WiFi in Control Center behavior in iOS 11.2 to be more clear: https://www.macrumors.com/2017/11/13/ios-11-2-beta-3-control...


That's actually a very good point about the frequent location information (or just location metadata in general). I've never thought about it, but I guess giving an app access to my photos gives them full access to the location metadata, and would allow them to put together a pretty accurate model of where I've been and where I live.


Does Tencent not have an extension that pops up in the sharing sheet for images?


Just checked again: not for Discord. No idea about other apps owned by Tencent.

It's notable Discord was developed as an American startup, and it's not clear what Tencent's involvement is. Regardless, for me it's too much access for a chat app to have in exchange for the convenince of sharing a photo from my phone.


A better solution would be for Apple to provide a decent photo picker that functions at the system level, and require a separate (special) permission to access all photos with the appropriate warning if that app needs a fancy dancy photo picker.

Why do I need to give snapchat access to all photos ever just to post from my camera roll?


It already does work like this in iOS 11. Apps can present the System photo picker to you and receive only your selected photo while having their Photos access set to "Never".

If you want to try it out install the Wire messenger (if you make the account with a web browser you don't need to provide a phone number), and try to attach a photo but deny Photo library permissions. (Here's the buttons to press: https://imgur.com/a/gc5Iq). Other apps work this way on iOS 11 but this is the one that came to mind.


For the longest time that was how I thought it worked :/


Indeed. Intent counts for nothing if the capability to secure the data is lacking. All companies claim to be secure, to respect your privacy yadda yadda...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: