I think Apple has also done good things with their strict app store policies (from my consumer point of view).
Apple has been for example putting limits on data collection and tracking. The main mechanism is to kick apps out from Apps store if they don't play by the rules.
I'm worried that side loading will be a step back here. Strong players, like Facebook, may just take their app away from the official store and distribute it through other ways. With their strong position I don't have much choice - it's not like there would be five competing apps serving the same purpose (connecting to the people and communities on Facebook).
The prime example is that apple gives apps unfettered access to network connections. And YOU are unable to block this in any meaningful way.
What apple doesn't give you is the ability to manage your own phone. You cannot really manage what apps are doing yourself. You cannot even find out what apps are doing. And you definitely will not be able to manage apple apps, they get a free pass in all ways.
But yes, if there's a sideloaded facebook app, or a facebook store, you will be given more rope to do with as you want.
It shows you per application what data they are accessing, which sensors they are accessing and which domains the app is contacting. It also reports when they were doing this and how often. You can even export this data as a JSON file.
Apparently first one has to turn it on to start gathering the usage data. I just turned it on and it started with no data. So I’ll see how it work’s going forward.
Worth noting maybe that although iOS 15 came out only in 2021, support for iOS 15 goes back to the iPhone 6S from 2015. Not very many people actively using iPhones older than that today.
The original poster asked about _fine-grained permissions_. Not about _runtime permissions_. Details matter.
Android did have very fine-grained permissions since first betas. Yes, they were install-time - a policy was generated at install time by the system, and the app itself was unable to change anything about it. Technically, it was a nice system, but users didn't understand that, they were asking for simplified model from iOS, so they got it in Android's 6.0 _runtime permissions_.
In the end, neither of these system (or: original Android did have it, but the simplified 6.0+ doesn't) has the most important permission: can an app talk to the network?
> Android did have very fine-grained permissions since first betas. Yes, they were install-time
They weren’t really that fine-grained from a user perspective. You could not accept/refuse individual permissions, you either accepted everything or simply not install the app.
iOS always had fine-grained permission in that you could grant/refuse individual permissions. For example: you could allow an app to access the camera but refuse location services. Android only recently gained that capability.
Even more important, iOS always put the permission request in context. If I install an app and it asks for a ton of permissions I have no idea why it needs them and if it makes sense for that app to have them. Why would a chat client need access to my photos ? But on iOS, I get that request the first time I choose to send a photo to someone. I immediately see by the context why it needs that permission and I can make an informed decision.
> They weren’t really that fine-grained from a user perspective. You could not accept/refuse individual permissions, you either accepted everything or simply not install the app.
They were fine grained: apps either had them in their manifest, or not. If not, they could not call the respective APIs without getting an exception.
Because there were so many, it would be a great burden to app developers to check for random mix of required permissions, whether it was granted or not. The complexity would shoot over the roof. When Android switched to runtime permissions, all the detailed permissions were grouped into fewer coarse ones; exactly because so much detail would be unbearable for both users (fatigue from the alerts) and developers (handling the enabled/disabled matrix).
As far as I remember, iOS originally didn't have any permissions. It got them once certain app was stealing users address books, so it got confirmation for accessing contacts, camera/photos and a third thing that escapes me at the moment (location?).
> But on iOS, I get that request the first time I choose to send a photo to someone. I immediately see by the context why it needs that permission and I can make an informed decision.
The app can also remember that it got the permissions and do the nefarious thing behind your back. While it may look better, it is really not; it also won't work if the permission system is fine-grained: too many types of permissions and users will get lost. Also, users accidentally pick the wrong choice and then wonder, why the app doesn't work like they expect, or how to change it.
Actually privacy relay is currently in public beta as a part of Apple iCloud subscriptions plans.
Unless I got it wrong when enabled it reroute all Apps trafic through this "limited VPN" to prevent tracking and access to local network.
Apps that require access to local network must ask that permission explicitly. Streaming service (Netflix, Disney+,etc) do that for obvious performance gain. I noticed Microsoft Teams did it also (and I just revoked that thanks to this thread, it's a work app I better keep that out of my home local network).
Latest moves seem to imply Apple might want a slice of the Ad network pie.
So I wouldn't bet on capitalistic ideals/incentives not overtaking idealistic consumer protections.
Defenders of Apple's policies always say you can just use other tech if you don't agree with them. The same principle applies here. If an app requires you to use a third party app store and you don't like it then choose another app.
If you feel compelled to use a product with policies you don't agree with then now you understand how many of us feel about iOS.
But there's no push, you can literally ignore Apple's existence and use none of their products and you'll have no care in the world. Apple's network effect is basically zero. There's always one Android user in the friend group that spoils iMessage and FaceTime so we have to use something else anyway.
If you mean you feel compelled to sell in their store which requires a laptop, a business relationship with Apple, and realistically a phone because emulator only sucks then that's a business decision if the juice is worth the squeeze.
Yes. That's literally my point. It's really hard for Apple to establish a network effect when any group above a certain size can't use iMessage or FaceTime and have to use a 3rd party app like Discord, Snap, or Messenger.
You can't be the "everyone else is one it" social network when every Apple user uses a 3rd party messenger and video chat app for at least one person. That app ends up being the winner.
No business with a mobile component can afford to ignore iOS.
And a lot of apps launch early on iOS or have better features on iOS or never even launch at all on Android. Less so these days but it's still a thing. I was just in Japan and you can use an iPhone to pay for mass transit but not a non Japanese Android phone, just as one recent example.
I hope I don't come across as snarky -- I am genuinely curious -- but why don't you have a choice? Are you unable to contact friends, family, etc. any other way outside of FB? The phrasing seems so strong, I am second guessing if I am just privileged/lucky (location, friend/family circumstances, etc?) to be off of social media but still have friends and family that I stay connected to.
I would normally agree with you, but a friend of mine is an immigrant from a south east Asian nation and the only way to easily communicate is through Facebook with the family there. It’s like saying, sure we can take away your phone and you can still write letters, but at some point communication is also about convenience.
You just tell your friends that you are not reachable on Facebook anymore and how you can be reached.
You don’t have to "convince" anyone.
Your real fear is that people will stop reaching you if they don’t want to install another app, send you an SMS, send you an email or to call you on the phone.
Well, if your friends stops reaching you because you uninstalled an app, honestly it looks that they are more acquaintances than real friends. And it’s ok. But it’s also ok if they are just an entry in your contacts list.
You’re making an awful lot of assumptions about how people think and behave en masse. When facebook is the primary communication factor for huge family groups, if you’re the only one not participating then you miss out on all those conversations. It’s not just about one on one communication, it’s about a virtual family presence.
I say this as someone who despises facebook but this is the reality we are in. Similarly, in most nations outside United States, you really cannot get rid of WhatsApp. If you don’t use WhatsApp, you are missing out on how much of your society operates.
It's not about being reachable in a 1-1 chat. It's about being excluded from group chats which are very important for keeping up the group and friendship in general. For example, if I deleted FB Messenger right now I would still get invited to the occasional event but there would be way fewer "yo, I'm at X, is anyone free to hang out?" type messages that I will see, or invitations from acquaintances in big group chats, or the current shitpost of the week that will become part of everyone's lexicon for the next 2 months other than yours, etc. For a lot of people (including me) such communication is a majority of their overall communication with their friends and breaking them does break a big part of their life.
By providing Signal with any phone number at which you can receive an SMS or text message, you can register a Signal account at that other phone number. For example, you can create a pseudonymous Google account, register a Google Voice VoIP number, and use that as your Signal number. Or you can even use a free throw-away SMS account and use that number when you sign up for your Signal account instead of your real phone number. The Signal service will happily send the throw-away number a text message with the verification code, letting you complete the account sign-up process.
That makes perfect sense, definitely sheds light on the fortunate circumstance I am in of not needing FB to conveniently communicate with my connections. Because, I agree, you should be able to conveniently communicate if you can.
Here is an example: we are invited to my kid’s friend’s birthday. They manage the event on facebook. They had to change location and time couple of times already. We don’t want to miss it and alternatives to facebook just aren’t any better. Sometimes it’s just convenient.
Calendar invites are cross-platform and reasonably convenient. You don’t even need to subscribe to someone’s calendar, updates are vCalendar files sent over email. At least iOS and Outlook parse your inbox for vCalendar files and may update the accepted event automatically.
Apple will make it annoying enough to sideload that no meaningful amount of users will do it, causing it to be largely irrelevant.
It’s only worth it to app makers to have side loading if they can do it for large numbers of users, bypass the app store’s rules, and bypass apple’s take. I’m expecting apple to set it up in a way they can do none of those things, by making it cumbersome to sideload, not giving entitlements to apps not published through the store, and by taking a cut for sales from sideloaded apps.
That's exactly the point, though: side loading is not something to worry about, since normal users won't and shouldn't care about it at all. It is not a threat to the Apple App Store.
But it does allow for niche applications such as NewPipe and F-Droid, for technical users who know the risks.
Almost everyone in China uses alternative stores, like Huawei or Xiaomi; how else do you think malicious PDD app got on their phones? The same applies to other counties in South-East Asia. I have seen our app for Android repackaged with malware and uploaded to an alternative store and listed there with hundreds of thousands downloads.
> how else do you think malicious PDD app got on their phones?
The malicious PDD app is really, actually, published to the alt stores by PDD Holdings itself. It loads the exploit config and post exploitation modules from PDD's own CDN.
It's not the same repackage-with-malware shit plaguing China/SEA market since forever. It's first party.
And the Google Play version contains the same exploit delivery codes, though no real evidence that it was activated.
You know who's really putting limits on data collecting? F-Droid.
If that's actually your argument, that's what you should use. It's quite practical.
> Strong players, like Facebook, may just take their app away from the official
That argument really has to explain why this has not happened on every other operating system under the sun, including Android. They all suffer pretty strong monopolistic network effects.
> I don't have much choice - it's not like there would be five competing apps serving the same purpose (connecting to the people and communities on Facebook).
The same legislation that is requiring Apple to allow sideloading also requires other large players (like Meta) to open their communication platforms up to other service or application developers.
In this hypothetical case, there actually would be five competing apps, some even still distributed on the App Store.
Every jailbreak ever has been on the magical secure "app store", too. It is really weird that people on here of all places believe in this garbage performative "app phrenology" they are doing over there.
> Strong players, like Facebook, may just take their app away from the official store and distribute it through other ways. With their strong position I don't have much choice - it's not like there would be five competing apps serving the same purpose (connecting to the people and communities on Facebook).
iPhone is THE hottest device on the planet, I can’t believe anyone can seriously consider Facebook challenging its position.
> I think Apple has also done good things with their strict app store policies
Apple could have hidden the settings to enable it behind two levels of menu settings and anyone like you would never get to it. The only reason they have "strict" policies, as has been shown over and over again, is for their commercial benefit.
> Apple has been for example putting limits on data collection and tracking.
I want to be tracked by apps, because it leads to better ads for products that I am actually looking for (than some random garbage that I don't care about)... and better usability in general. Apple put those rules in place so that their ad business has the edge over competitors. If Apple was running in a country that was not corrupt, this would be seen as anti-competitive and they would be sued.
> Strong players, like Facebook, may just take their app away from the official store and distribute it through other ways.
And? If you want clear rules on tracking, go talk to your politician. Apple is blocking competitors from tracking users while it has access to all of users data and uses it for their $5 billion revenue business.
Apple has been for example putting limits on data collection and tracking. The main mechanism is to kick apps out from Apps store if they don't play by the rules.
I'm worried that side loading will be a step back here. Strong players, like Facebook, may just take their app away from the official store and distribute it through other ways. With their strong position I don't have much choice - it's not like there would be five competing apps serving the same purpose (connecting to the people and communities on Facebook).