←back to thread

530 points mdhb | 1 comments | | HN request time: 0.388s | source
Show context
nomilk ◴[] No.45063289[source]
IMO Apple should provide the user with audit logs of which photos/videos were accessed by each app. It might be a long list but it alleviates doubt and would put huge pressure on reputable developers to ensure they don’t get caught doing things the user wouldn’t have expected (even if the user technically allowed it).
replies(15): >>45063561 #>>45063763 #>>45064188 #>>45064202 #>>45064506 #>>45064799 #>>45065030 #>>45065872 #>>45066358 #>>45067299 #>>45067883 #>>45067957 #>>45068243 #>>45070026 #>>45075377 #
Razengan ◴[] No.45064799[source]
Apple should also stop letting apps know that we have given them a limited photos or contacts list:

Telegram refuses to work if you provide it with just 1 dummy contact.

Some other clingy apps also get pouty and demand full roll access each time you try to use a photo.

What's even worse: For years, Apple has also allowed many apps including Facebook/TikTok/Tinder to use the "iCloud Keychain" API to store invisible information that tracks you across app reinstalls and EVEN DEVICE RESETS, because it's stored in your iCloud account, and there's no way for you to see what is stored or manually delete it without going through FB/etc and no way to be sure that they are indeed deleting everything.

I've ranted about that a few times but people just shrug it off like wtf (I imagine other people who abuse these APIs want to keep it buried)

replies(1): >>45065151 #
ctippett ◴[] No.45065151[source]
Have you tried viewing your iCloud keychain on macOS? I'm not sure if it's inclusive of entries made from iPhone-only apps, but there's definitely an option to view entries synced to iCloud for other things.
replies(1): >>45065269 #
1. Razengan ◴[] No.45065269[source]
I think I tried that a long time ago, including various tricks to see the hidden folders on the iPhone file system, but it didn't work.

Now I'm not going to install any FB-related app on my new phone to test any other ways, because I'd rather not let them mark that device too if I can help it.