Apple fights fingerprinting: new rules require developers to justify access to device data

Apple has just made life more difficult for mobile ad networks and other third parties who track you around the Web and push stuff to you or sell your data. With the latest change of rules for developers, Apple is taking aim at fingerprinting, a sneaky technique that some apps may use to covertly spy on you and your device.

Apple has announced that developers will need to explain why their apps have to use certain APIs (Application Programming Interfaces), which are ways for different apps to talk to each other and exchange information. Through these APIs developers can collect seemingly harmless data about your device, such as when you created and last edited a file, how much disk space you have left, when you turned on your phone last time, what keyboard you use, or what settings you prefer.

At first glance, this kind of information may seem completely useless: why would anyone want to know what keyboard you use, and why does Apple care about who knows that? However, while these bits of information may not seem very personal or private, when combined they can help companies create a unique profile or “fingerprint” of your device. This “fingerprint” can then be used to track you around the web and target you with ads.

Broadly defined, a device’s “fingerprint” is a combination of its hardware and software features. The more of these features are unique and known, the easier it is to track you. Of course, unlike your name or date of birth and your actual physical fingerprint, your device fingerprint is not set in stone. Its so-called “uniqueness” can fluctuate over time, which means it is not a foolproof way to track or identify you. Still, since Apple had already cracked down on other means of third-party tracking, this was a loophole that companies could use to continue snooping.

‘Approved reasons’ for using Apple APIs: what are they?

The requirement for developers to justify access to device information will apply not only to their own code, but also to third-party SDKs (software development kits) that they embed in their apps. SDKs are third-party tools or libraries that help developers add functionality to their applications. However, some SDKs — such as a massively popular Facebook Ads SDK and other advertising SDKs — also gather a lot of data about the app’s users and their devices. These SDKs are often chosen by developers who seek to monetize their apps through ads: developers can show personalized ads from a SDK vendor in their apps and get paid a portion of the ad revenue.

According to Apple’s new rules, both apps and third-party SDKs will need to write one or more “approved reasons” for why they need to access device information through specific APIs in separate documents called “privacy manifest files.” These reasons should be “consistent with the app’s functionality.” For example, a flashlight app does not need to access the disk space API to work, as it only needs to access the camera flash or the screen brightness. So, if a flashlight app wants to access the device’s memory, it might have some hidden or malicious purpose for that (such as displaying ads for disk cleanup apps, collecting data for fingerprinting or even installing malware). In this case, the reason for the flashlight app to use the disk space API will be inconsistent with the app’s functionality, and the app may be determined to have violated Apple’s policy and be removed.

Apple also said that app developers will have to write all the internet domains that they connect to for tracking purposes in the privacy manifest file. However, this only works if the user allows the app to track them. If the user does not allow tracking, the app won’t be able to connect to those domains at all.

Developers will need to list tracking domains their app connects to
Source: Apple developer rules

First and foremost, this new policy appears to be aimed at stopping apps that trick users into granting unnecessary permissions from using this data to serve ads or fingerprint them.

Of course, a tech-savvy user is unlikely to grant their apps any dubious permissions anyway, as any such request would raise a giant flailing red flag with them. But sometimes we are in a rush or not paying attention. Besides, most phone owners are not even aware of the dangers that granting a random app access to their phone’s data can bring.

Permission to track ≠ permission to fingerprint

Apple has made it clear that even if an app secures a user’s permission to track them — which is already rare, as over 90% of US iPhone users deny apps such permission after Apple made third-party tracking an opt-in feature in 2021 — that does not mean it can “fingerprint” them.

Regardless of whether a user gives your app permission to track, fingerprinting is not allowed.

Developers will have to comply with the new requirements by the spring of 2024 at the latest. Starting this fall, they may receive a notice from Apple asking them to provide reasons for using certain APIs. And if they don’t provide them by spring 2024, their apps will no longer be accepted in the App Store.

While Apple has stepped up to the plate on fingerprinting, the policy itself is not new. What’s new is Apple’s enforcement of the ban. Already at the 2022 Worldwide Developers Conference (WWDC) Apple stated: “Fingerprinting is never allowed. Regardless of whether a user gives your app permission to track, fingerprinting — or using signals from the device to try to identify the device or user — is not allowed per the Apple Developer Program License Agreement.”

In fact, one could see Apple going after device fingerprinting long before that. Back in 2017 Uber almost got itself kicked out of the App Store after its app was caught extracting iPhone serial numbers out of the device’s operating system.

How Apple is leading the way in privacy protection

The new anti-fingerprinting measure is just one in a series of other steps Apple has taken over the years to strengthen its users’ privacy and security. Cupertino has always styled itself as a champion of privacy, making its protection an inherent part of its marketing pitch. And while the iPhone maker has come under fire for allowing its own native apps to track users without their explicit permission, there’s no denying that Apple is on the cutting edge of privacy, at least among Big Tech.

Below are some of the key privacy-protecting features that help Apple users to take more control over their data and decrease their online footprint:

  • The App Tracking Transparency (ATT) feature, introduced in iOS 14.5 in April 2021, is perhaps the most important in terms of its impact on third-party tracking. It lets you choose whether you want to allow apps to track you or not. When you open an app that wants to track you, it will show you a pop-up message asking for your permission. You can either tap “allow” or “ask the app not to track”. Most Apple users chose the second option, which means they blocked the apps from tracking their IDFA (Identifier for Advertisers) — a code unique to each device. That dealt a blow to ad revenue for ad tech giants like Meta, which estimated its losses in the billions of dollars.

  • App Privacy Labels, launched by Apple in late 2020, allow you to see what information an app collects and for what purpose right in the App Store or on Apple’s website. The privacy labels are divided into three categories: data not linked to you, data linked to you, and data used to track you. The last category is the most telling, because it shows what data an app may use to track you across other apps or websites, including for targeted advertising. Note, however, that when you click “See Details” under the “App Privacy” section of an app’s description in the App Store, you will see the following warning: “This information has not been verified by Apple.” This means that, by and large, Apple is relying on developers to provide the correct privacy labels for their apps, and numerous reports have since exposed many of them as incomplete or misleading. In response to criticism, Apple says it regularly audits apps and makes developers correct inaccuracies.

  • Available since 2021 App Privacy Report is a feature that shows you how often apps use the permissions you’ve given them to access your location, camera, microphone, contacts, and other data. You are also able to see which internet domains apps contact most often, and check if these domains can be used for tracking or advertising purposes. Armed with this information, you can revoke permissions you’d granted your apps or stop using them altogether if you think they are spying on you. The App Privacy Report feature can be turned on in the device’s privacy settings.

  • Mail Privacy Protection is a feature that hides your IP address from email senders, preventing them from learning your exact location. The feature also helps users avoid letting senders know whether they opened an email and what they did with it. Marketers typically learn this information with the help of tracking pixels — tiny transparent images embedded in emails. The feature, first introduced in iOS 15, is an opt-in that must be enabled in the Mail app’s settings.

  • Intelligent Tracking Prevention (ITP) is a feature for Apple’s Safari browser that blocks third-party cookies and trackers from collecting data about your online behavior. Starting with iOS 15, it also began hiding your IP address from trackers, meaning they can’t tie your activity to your location or device and build your advertising profile. The feature is turned on in Safari by default.

  • Hide my Email feature is a service that lets users keep their real email address private when creating accounts with apps or websites. You can use this feature for free when signing in with Apple on third-party websites, provided they allow you to use your Apple account for sign-up.

  • Privacy Policy for all iOS apps. In 2018, Apple made it mandatory for all iOS apps to link their privacy policy in the App Store. Prior to that, the requirement applied only to subscription-based apps, which may seem dubious by today’s standards. Again, there seems to be a problem with enforcement of this policy. A 2022 study by Pixalate found that 13% of the surveyed apps in the App Store lacked privacy policies. However, it’s unclear how many of these apps were “abandoned” apps, meaning they may not have been updated in years and were uploaded to the store before 2018.

Of course, there are other Apple features that help boost your privacy — some are only available to paid users, such as Apple’s Private Relay, which helps obfuscate your browsing history from both Apple and third parties. Here we’ve mentioned just a few of Apple’s key features that are either on by default or available to all via Settings.

But they are proof enough that Apple, for all its flaws and controversy over its own tracking practices, is moving in the right direction in terms of protecting users from third-party tracking.

Hopefully, the move will inspire an industry-wide shift on fingerprinting, and prompt Apple’s main rival, Google, to consider similar measures.

喜歡這篇文章嗎?
20,891 20891 使用者評論
極好的!

AdGuard for Windows

Windows 版 AdGuard 不只是廣告封鎖程式,它是集成所有讓您享受最佳網路體驗的主要功能的多用途工具。其可封鎖廣告和危險網站,加速網頁載入速度,並且保護兒童的線上安全。
透過下載該程式,您接受授權協定的條款
閱讀更多
AdGuard for Windows 7.22 版本,14 天的試用期
20,891 20891 使用者評論
極好的!

AdGuard for Mac

Mac 版 AdGuard 是一款獨一無二的專為 MacOS 設計的廣告封鎖程式。除了保護使用者免受瀏覽器和應用程式裡惱人廣告的侵擾外,應用程式還能保護使用者免受追蹤、網路釣魚和詐騙。
透過下載該程式,您接受授權協定的條款
閱讀更多
AdGuard for Mac 2.17 版本,14 天的試用期
20,891 20891 使用者評論
極好的!

AdGuard for Android

Android 版的 AdGuard 是一個用於安卓裝置的完美解決方案。與其他大多數廣告封鎖器不同,AdGuard 不需要 Root 權限,提供廣泛的應用程式管理選項。
透過下載該程式,您接受授權協定的條款
閱讀更多
掃描下載
可以使用任何一款 QR 碼閱讀器
AdGuard for Android 4.12 版本,14 天的試用期
20,891 20891 使用者評論
極好的!

AdGuard for iOS

用於 iPhone 和 iPad 的最佳 iOS 廣告封鎖程式。AdGuard 可以清除 Safari 中的各種廣告,保護個人隱私,並加快頁面載入速度。iOS 版 AdGuard 廣告封鎖技術確保最高質量的過濾,並讓使用者同時使用多個過濾器。
透過下載該程式,您接受授權協定的條款
閱讀更多
掃描下載
可以使用任何一款 QR 碼閱讀器
AdGuard for iOS 版本 4.5
20,891 20891 使用者評論
極好的!

AdGuard 內容阻擋器

AdGuard 內容阻擋器可以全面阻止所有支援內容封鎖技術的行動瀏覽器中的廣告,目前包括 Samsung Internet 瀏覽器和 Yandex 瀏覽器。雖然其功能相比 Android 版 AdGuard 有所限制,但它完全免費、安裝簡單且封鎖高效。
透過下載該程式,您接受授權協定的條款
閱讀更多
AdGuard 內容阻擋器 版本 2.8
20,891 20891 使用者評論
極好的!

AdGuard 瀏覽器擴充功能

AdGuard 是有效地封鎖於全部網頁上的所有類型廣告之最快的和最輕量的廣告封鎖擴充功能!為您使用的瀏覽器選擇 AdGuard,然後取得無廣告的、快速的和安全的瀏覽。
AdGuard 瀏覽器擴充功能 版本 5.2
20,891 20891 使用者評論
極好的!

AdGuard 助理

AdGuard 桌面應用程式的配套瀏覽器擴充功能。它為瀏覽器提供了自訂的元件阻止的功能,將網站列入允許清單或傳送報告等功能。
AdGuard 助理 版本 1.4
20,891 20891 使用者評論
極好的!

AdGuard Home

AdGuard Home 是一款以網路為基礎的解決方案,用於封鎖廣告和追蹤器。只需在您的路由器上安裝一次,即可涵蓋家庭網路上的所有裝置——無需另外安裝客戶端軟體。這對於經常威脅您隱私的各類物聯網裝置來說尤為重要。
AdGuard Home 版本 0.107
20,891 20891 使用者評論
極好的!

AdGuard Pro iOS 版

AdGuard Pro iOS 版預置全部進階廣告封鎖防護功能,提供與 AdGuard iOS 版付費版完全相同的工具集。其卓越之處在於:不僅能精準封鎖 Safari 瀏覽器內的廣告,更支援自訂的 DNS 設定以精細化防護策略。該產品具備跨瀏覽器與應用的全方位廣告封鎖能力,有效防護兒童遠離不良內容,並全面保障個人資料安全。
透過下載該程式,您接受授權協定的條款
閱讀更多
AdGuard Pro iOS 版 版本 4.5
20,891 20891 使用者評論
極好的!

AdGuard for Safari

我們的 Safari 廣告封鎖程式已成功應對 Apple 強制採用新 SDK 的挑戰。這款 AdGuard 擴充功能旨在讓 Safari 重獲高品質廣告封鎖體驗。
AdGuard for Safari 版本 1.11
20,891 20891 使用者評論
極好的!

AdGuard Android TV 版

Android TV 版 AdGuard 是唯一一款能封鎖廣告、保護隱私並充當智慧電視防火墻的應用程式。取得網路威脅警告,使用安全 DNS,並受益於加密流量。有了安全性和零廣告的使用體驗,使用者就可以盡情享受最喜愛的節目了!
AdGuard Android TV 版 4.12 版本,14 天的試用期
20,891 20891 使用者評論
極好的!

AdGuard Linux 版

AdGuard Linux 版是世界上第一個系統級廣告封鎖器。封鎖廣告和追蹤器,選擇預設過濾器或新增自己的過濾器。管理流程通過命令行介面實現。
AdGuard Linux 版 版本 1.1
20,891 20891 使用者評論
極好的!

AdGuard Temp Mail

免費的臨時電子郵件地址產生器,保持匿名性並保護個人隱私。您的主收件匣中沒有垃圾郵件!
20,891 20891 使用者評論
極好的!

AdGuard DNS

AdGuard DNS 是一種不需要安裝任何的應用程式而封鎖網際網路廣告之極簡單的方式。它易於使用,完全地免費,被輕易地於任何的裝置上設置,並向您提供封鎖廣告、計數器、惡意網站和成人內容之最少必要的功能。
20,891 20891 使用者評論
極好的!

AdGuard Mail

保護個人身份,避免垃圾郵件,並使用我們的別名和臨時電子郵件地址保護收件箱。享受我們的免費電子信箱轉發服務和適用於所有作業系統的應用程式使用體驗。
20,891 20891 使用者評論
極好的!

AdGuard Wallet

一個安全且私密的加密貨幣錢包,讓您完全掌控資產。管理多個錢包,探索上千種加密貨幣以儲存、傳送及兌換。
已開始下載 AdGuard 點擊箭頭所指示的檔案開始安裝 AdGuard。 選擇"開啟"並點擊"確定",然後等待該檔案被下載。在被打開的視窗中,拖曳 AdGuard 圖像到"應用程式"檔案夾中。感謝您選擇 AdGuard! 選擇"開啟"並點擊"確定",然後等待該檔案被下載。在被打開的視窗中,點擊"安裝"。感謝您選擇 AdGuard!
在行動裝置上安裝 AdGuard