Loupe – A iOS app that raises awareness about what native apps can see (github.com)

443 points by Cider9986 a day ago

throwaway27448 10 hours ago

I don't understand why internet access isn't opt-in for apps. Preventing exfiltration would prevent much of this harm, and most apps don't have any need to access the internet in the first place. Why am I creating a GE account to read my blood pressure? At least I know it's taking advantage of me. But this is clearly abusive behavior

fizwidget 7 hours ago

Because 99% of apps would request it & not function without it, desensitising users into blindly accepting it. Most apps do have a legitimate reason for accessing the internet, so a binary yes/no wouldn’t achieve much anyway.

I just don’t think it’s an effective way of solving the problem.

fauigerzigerk 4 hours ago

100% of users have legitimate reasons to block internet access for some apps.

If internet access wasn't granted by default, a lot more apps would function without it.

Many other apps wouldn't exist at all, because their only reason to exist is to spy on users.

evanjrowley 3 hours ago

The internet access permission should be implemented. Users of macOS are already accustomed to the local network access permission.

Even if it's not the most effective way to raise awareness, it does put pressure on developers to be explicit about the connectivity requirements with users. It would also be a great way to audit an app's local-first / offline-first claim without having to do a network packet capture.

Want telemetry? Send it through Apple and Google. Given Apple's late history and latest trends in Android development, I see them both favoring this approach.

abecedarius 3 hours ago

Permission should be in the form of a capability, which need not end up on the built-in OS network capability. If an app insists on your car's steering wheel, you can be like "sure, kid, here's your Help Daddy Drive(TM)".

throwaway27448 an hour ago

> Most apps do have a legitimate reason for accessing the internet

I just flat out think this is bullshit

gyomu 9 hours ago

Better yet, a tool like Little Snitch should be built into the OS. Give me a detailed log of every network requests, to which domains, with what data.

Cider9986 9 hours ago

This isn't effective because Little Snitch only sees the domains so apps can just serve the trackers on the same domain as essential services making blocking impossible.

The only way to prevent malicious apps from affecting your privacy is to not install them or not give them network access.

gyomu 8 hours ago

inigyou 5 hours ago

CTDOCodebases 6 hours ago

If I remember correctly iPhone apps used to use the devices SSL certificates so you as a user could install your own and man-in-the-middle the traffic to see what was being sent. AFAIK now the apps use certificate pinning.

saagarjha 5 hours ago

Barbing 2 hours ago

Yes and it should work properly instead of making unwanted initial outbound connections (macOS firewalls are broken).

prime17569 6 hours ago

This exists already! You can see it by going to Settings > Privacy & Security and turning on the App Privacy Report at the bottom.

jtmarl1n 6 hours ago

fizwidget 7 hours ago

It’s not quite that detailed but iOS’s builtin “app privacy report” does give a fair amount of info, including a list of domains accessed.

nobody42 4 hours ago

Because exposed, non-private, abused by-default is a business model. The company is incentivised to not provide restricted access - otherwise you can't have a cut from apps revenue. It's defective by design.

Barbing 2 hours ago

Shocked to see iPhones sold in China are less defective by design on this one point, from another comment. It has surely reduced Genius Bar visits but it’s also harmed my privacy.

henryhchchc 7 hours ago

iPhones purchased in mainland China (with model number ending in CH/A) do provide options for setting per-app Internet access permissions. There are three options [0]: Off, WLAN only, WLAN and Cellular.

[0] https://old.reddit.com/r/ios/comments/aib10i/in_china_ios_al...

throwaway27448 an hour ago

Crazy. So they're explicitly selling crippled devices to most of the world.

ksec an hour ago

What? Why is this Chinese market only? This is exactly what I wanted. There are Apps I simply don't want them to touch internet.

reorder9695 9 hours ago

AOSP has network as a regular permission for apps, so on Lineage at least (idk about Graphene as I haven't used it) you can disable network for any app including google play services etc. I have no idea why most phone companies remove this permission from their roms but android itself supports it perfectly fine.

microtonal 9 hours ago

It's nice to be able to toggle it (it's also possible to revoke this permission on GrapheneOS). However, it is imperfect, since apps within the same profile can still communicate through IPC, so if apps cooperate, network access can still be achieved. I would guess that Play Services is one of the larger offenders, since many apps communicate with Play Services and as far as I understand (but I may be mistaken) Play Services does work that involves internet access on behalf of other apps.

You could of course disable network access to Play Services, but at least for me that broke a bunch of apps or made them unreliable.

What AOSP ROMs need besides the network permission toggle is IPC scopes functionality, akin to storage scopes.

inigyou 5 hours ago

ignoramous 7 hours ago

inigyou 5 hours ago

GrapheneOS not only has this permission, but it asks you every time you install an app.

Hoodedcrow 5 hours ago

Can confirm Graphene also has it

hellcow 10 hours ago

GrapheneOS lets you restrict the internet access of any app on install.

But yes, agreed it should be everywhere.

backscratches 9 hours ago

And you can limit which contacts you share with nosy app like WhatsApp, and give access to only specific scope of file folders. Horrifying to think all the years every app got everything it wanted and did not have to ask and couldn't be stopped (I had a rooted phone for firewall capability for a while )

microtonal 8 hours ago

See my comment upthread, it helps a bit, but does not close this hole since apps within the same profile can communicate through IPC, so other apps could provide network access on their behalf. I think the best example is probably Play Services, which provides functionality for a lot of apps and will communicate with Google, etc.

(Yes, you can disable network access to Play Services, but it sometimes breaks things and the general point of IPC as a hole still stands.)

deanishe 8 hours ago

Cider9986 10 hours ago

Yeah it asks on app install if you want to grant network permissions. It's just a little checkbox. You can of course manage it afterwards in app settings or permissions manager.

They also added the sensors permission.

nubinetwork 5 hours ago

You don't need graphene for this, I've been able to do this on plain android for ages.

iLoveOncall 7 hours ago

iOS lets you turn off data access (so outside of wifi) for apps as well, it's just not asked at install, which honestly makes sense given the demographics of iPhone users.

DavideNL 4 hours ago

nashashmi 3 hours ago

The evolution of development was to make things easy and simple for the consumer. If internet was an opt-in (and it cannot be opt-out), then app function would be ostensibly limited. And the user would be given a harder time setting things up.

This is the Apple mindset. Make things easy. Do not make things complicated.

throwaway27448 an hour ago

The attitude was never "don't give the user control", though. Until ios.

mazzystar 7 hours ago

This resonates from the dev side. I made an offline photo search app a while back — you search your library in plain language ("a boy and a girl by the river"), CLIP embeddings all computed on device. It needs full photo access but I deliberately requested zero network permission. Was kind of proud of that.

Problem is there's no way for users to actually know that. iOS has no "this app can't reach the internet" indicator, so the whole guarantee is invisible. I even had people assume the opposite — app reads your whole library, therefore it must be uploading it somewhere. Exactly backwards.

subscribed 5 hours ago

Fantastic work. I regret I can't use it, because this is exactly what I'm looking for for quite a while, but it seems to be an impossible task (I need it on android).

lapcat 5 hours ago

Curiously, the Mac App Store sandbox has a com.apple.security.network.client entitlement that a developer must justify to Apple, whereas the iOS App Store does not, allowing unrestricted access to the internet.

regecks 16 hours ago

Damn. The "iPhone last setup or erased on ..." is really nasty. What can a user really do about that? I feel like this should be fudged somehow by the OS.

Gigachad 15 hours ago

Seems like in general the iPhone was not designed to avoid fingerprinting from installed apps. Only protection would be avoid installing apps and use the web browser when possible.

camkego 12 hours ago

This. This is why everyone who wants to fingerprint and collect tons of data on end users pushes them hard on installing an app. The amount of valuable data is 10x what’s available in the browser

microtonal 10 hours ago

saturn8601 12 hours ago

Cut your selection of apps and find/build privacy respecting alternatives for the remainder. Im trying to do this. Music is now locally hosted, Youtube is sorta kinda coming along. I've been working on reversing some of my more basic iOS apps to extract the data/endpoints they use and write my own apps. Fable really helped with this and Opus just does not cut the mustard. I hope it comes back. :/

p-e-w 14 hours ago

The intended “protection” is the ToS, which requires apps to disclose what they are tracking and whether they perform cross-premise tracking.

paytonjjones 14 hours ago

Barbing 14 hours ago

cute_boi 14 hours ago

These days many things don't work on browser. Even reddit is very difficult as we get constant nagging.

Gigachad 13 hours ago

water-drummer 6 hours ago

Cider9986 10 hours ago

potatoproduct 13 hours ago

dylan604 12 hours ago

Maybe I'm being really thick, but why is this information that the OS would make available to apps?

UqWBcuFx6NV4r 11 hours ago

Maybe it’s derived

LoganDark 10 hours ago

matthewfcarlson 16 hours ago

Is the threat model tracking across multiple apps to correlate what you're doing? In that case, a single app wouldn't show you the fudging.

ramses0 15 hours ago

```Based on a binomial/Poisson distribution and a baseline of 21 million U.S. device sales per release, a fingerprint relying on "seconds since setup" fails to uniquely identify individuals. In the high-density Early Adopter phase, you will share your exact setup second with an average of 1.01 other people (a total matching pool of ~2 people). Six months into the cycle, you will still share that second with an average of 0.68 other people.```

In the U.S., device setup time (to the second) very conservatively gets you clubbed into a single group of 100 individuals as an "advanced persistent threat" tracker. Even compressing activations to "80/20 during business hours" the math kindof maxes out at a pool of ~5 people, and assuming worst case "20x" of that still means you're still pretty darned identifiable.

If you get ~6-8 more bits of entropy (eg: Device Type + Capacity is easily 2-3 bits, and Time Zone is probably another 2-3 bits) you're cooked!

withinboredom 6 hours ago

cute_boi 14 hours ago

aggregator-ios 9 hours ago

One correction to some comments here: an iOS app cannot list all apps that are installed. You can only check for specific apps/schemes (LSApplicationQueriesSchemes) by specifying apps you are looking to query for installation status or open. You cannot provide a large list of unrelated applications since Apple rejects that during app review.

Apple added these restrictions because installed app lists can be used for fingerprinting and privacy invasive profiling.

nomilk 9 hours ago

But a single app can request to know the presence of up to 50 apps, right?

And a data broker/aggregator can purchase such data from many (e.g. thousands) of apps and aggregate it, then sell it.

isodev 8 hours ago

Yes indeed, the limit is 50 which is of course enough to fully profile "regular people" who only have a handful of apps. Also don't forget, Meta/Google/TikTok/WhateverPalantir are updated weekly which means they can tweak their LSApplicationQueriesSchemes list and cover even more apps if they want to.

ksec an hour ago

microtonal 8 hours ago

You cannot provide a large list of unrelated applications since Apple rejects that during app review.

Thank you for the clarification!

You cannot provide a large list of unrelated applications since Apple rejects that during app review.

It does not need to be a large list though I think? You just need a small list that is very discriminative and adds enough additional entropy to uniquely identify you in combination with the other data leaked.

solarkraft 8 hours ago

It is terrifying to learn that apps are allowed knowledge about any other app being installed on my phone. Where can I see that list?

saagarjha 5 hours ago

Info.plist

NietTim 8 hours ago

> Apple added these restrictions because installed app lists can be used for fingerprinting and privacy invasive profiling.

And this was heavily exploited by Facebook before Apple patched it

RedComet 15 hours ago

Volume creation date is pretty egregious. I don't see any reason that and Pasteboard changeCount should be so granular.

The "Installed Apps Probe" leak also surprised me. It is better than the current state of Android, though.

xenator 14 hours ago

Pasteboard counter exists to help apps to not ask again about the same item in the buffer.

And nothing stops from using reset it every day.

echoangle 9 hours ago

Why do you need a count for that? Couldn’t they just generate a UUID every time the clipboard changes?

dylan604 12 hours ago

Allowing an app to access the pasteboard without the user explicitly pasting into the app is weird to me. Maybe the thing I have in the pasteboard is not for this app but left over from use in another app. Since there's no easy way to clear the pasteboard, this will happen often. Maybe it's because I'm not an app dev that this doesn't make sense to me????

aalimov_ 12 hours ago

Barbing 13 hours ago

Would you elaborate on both points?

Any way to reset it as an end user? (Not enough awareness of the issue for search engines to find much.)

RedComet 12 hours ago

I think something like a per boot delta added to a (per app?) random base would preserve such functionality.

echoangle 9 hours ago

backscratches 9 hours ago

Graphene is way ahead of this

Cider9986 9 hours ago

Apps on grapheneos can see a list of other apps in the same profile.

Cider9986 11 hours ago

coffeecoders 12 hours ago

This is excellent. Seeing this makes me appreciate how much visual awareness tools like this are needed.

I built something similar, for the web. https://neberej.github.io/exposedbydefault/

Github: https://github.com/neberej/exposedbydefault

nomilk 10 hours ago

Why does a random app (with no special permissions given to it) get access to so much info, and why doesn't Apple tell users this (important) info? Why can't Apple make a long list of check boxes so users can dis/allow on a per-category and per-app basis?

E.g. I had no idea a random app you install (and give no permissions to) instantly has a list of every app installed on the device (e.g. can infer whether you're dating [or cheating!] from presence of tinder/bumble/hinge). That alone seems instantly monetizable by unscrupulous actors via 'is-my-partner-cheating' as a service: charge $10 to give a probable answer.

wiseowise 9 hours ago

That’s a stupid idea, how would you even get this “is-my-partner-cheating” on your partners phone?

nomilk 9 hours ago

Loupe itself can see if you have tinder/bumble/hinge installed (verify for yourself: install tinder, then install loupe, don't give it any permissions, and it can tell if you have tinder installed or not). So the answer is: buy the data from any app your partner has installed! Or more easily, a data aggregator which will have already combined data from hundreds/thousands of apps.

So your partner only needs to have had 1 single app from the list that sells user data to a data aggregator for this to work. They do not need to have installed some special app.

Here's a random Slate article about apps getting your data and selling it to aggregators/brokers, who sell it to third-parties (you, or I, could be one of those third parties).

> How Shady Companies Guess Your Religion, Sexual Orientation, and Mental Health And sell that data to the highest bidder.

https://slate.com/technology/2023/04/data-broker-inference-p...

latexr 7 hours ago

It already happens all the time. It even has a name.

https://en.wikipedia.org/wiki/Stalkerware

echoangle 9 hours ago

And how would the is-my-partner-cheating get their app onto the victims device to detect the other apps?

nomilk 9 hours ago

They don't, utilise the fact that every single iPhone app has access to what other apps are installed! - purchase that info from literally any iPhone app or aggregator that has it for that user. Curious how much this would cost to purhcase - a working credit card goes for $5-10 on the black market so 'apps installed on X's iphone' might be, like, 10c?

echoangle 9 hours ago

latexr 7 hours ago

Ask any domestic abuser. Most of them seem to be successful at it.

https://www.npr.org/sections/alltechconsidered/2014/09/15/34...

It’s crazy to me that people are being so skeptical of the idea. A lot of people share their logins freely with their spouses. I have never done it nor would I condone it, but it would be trivial for me to install spyware on the devices of many people I know, because they rightfully trust me. Not only do I know some of their device passwords¹, being “the computer guy” I could just outright ask for it or get them to input it anywhere while fixing some issue they have.

¹ And many more I have forgotten, because I make it a point to not record them, even mentally.

echoangle 6 hours ago

maccard 5 hours ago

idiotsecant 9 hours ago

Of all things, this is where you went?

nomilk 9 hours ago

Okay it's weird but the first thing that came to mind. Logic: if I can think of a monetisable, nefarious application in 10 seconds, then it stands to reason that very many nefarious applications would be possible with more time/effort.

backscratches 9 hours ago

kamyarg 2 hours ago

Holy cow, did not know ios lets apps access so many finger printable information such as apps installed, last wipe and number of copy actions. Installed the browser as I am confident it will be good also.

Thank you!

ololobus 2 hours ago

Idk, I actually got the opposite impression. Most of the info is just what I would expect everyone to see: date formats, languages, various webview kind of stuff, network info. This is already more than enough for fingerprinting

> information such as apps installed

This is what surprised me too, but if you read their hint, it’s not like list API. They probe various ‘open URL in app’ to see what apps registered them, so are installed. I guess this i) won’t allow you to track apps that don’t have ‘open in app’ urls, and ii) probably hard to limit without affecting UX

> number of copy actions

This is odd, yeah, not sure why is it exposed

> last wipe

They deduce this from the volume creation date. Probably possible to hide, but also not really that important, at least to me. Fingerprinting will work with way fewer info anyway

To summarize, I think iOS is still very solid in terms of involuntary info exposure (if you trust Apple itself). Most of really sensitive info requires separate permissions. Yes, you can harden it further, but that will be more like a paranoid mode

jiri 9 hours ago

Is something similar already available for Android phones?

nobody42 4 hours ago

Outdated, but gives the general idea: https://github.com/nandan-desai-extras/PrivacyBreacher

hrideshmg 2 hours ago

Wonder if there's anything like this for Android? If not, it might make for a pretty fun/interesting side project

ChrisMarshallNY 6 hours ago

I must say, I like the Mysk team, and wish them well; AI or not.

It seems a bit quixotic, but anything that goes against $_BIGCORP is tilting at windmills, anyway.

Of course, the one narrative I almost never hear, no matter who it is, is "Simply don't collect any extra data."

It's that simple. If you don't have the data, your app could be Swiss cheese, and no one can get anything dangerous.

But, in today's tech world, data is money, so every app and Web site out there, goes to any length, to hoover up as much data as possible.

I regularly get prompted to join "teams," and "leaderboards," or do "challenges," on my solitaire games.

amelius 2 hours ago

Huh, I was under the impression that Apple protected us against all this through the app store review process.

api 14 hours ago

This is why I avoid installing apps and don’t have a lot of them.

iririririr 13 hours ago

...wouldn't it be better to have a pocket computer you own?

dylan604 12 hours ago

It would be even better if app devs weren't pieces of shit making apps whose sole purpose is to gather all of this data to sell to other pieces of shits while skinning their app as a game or other app to trick users into thinking it's worth installing.

Fighting devs being able to make money in this manner is not dissimilar to getting made a drug dealers. As long as users want their product, they will sell the product.

inigyou 4 hours ago

downrightmike 11 hours ago

throawayonthe 11 hours ago

if you think "desktop" operating systems aren't even worse on this, you're very mistaken

api 2 hours ago

That’s not the problem though. The problem is that most apps are malware.

NietTim 8 hours ago

Just use the browser, it's fine 99% of the time.

normie3000 13 hours ago

Phones are quite useful.

Barbing 14 hours ago

Sweet, been wanting this a while. Just mentioned last month and here it is! https://news.ycombinator.com/item?id=48187972

VaradD09 10 hours ago

Privacy is a real issue! Does the iOS allow an ext dev app to read its system info? If yes, does it easily comply?

lencastre 11 hours ago

/me wonders of the privacy label should actually mention that it reads everything and the kitchen sink!!!

cocoto 6 hours ago

Today I have simply given up trying not to share my personal information. What I do instead is simply blocking all ads and don’t use apps/websites that can’t be used without ad blocking. They may have many personal details like my favorite ice cream flavor but I get zero ads so I don’t care that much (I would prefer no one having this information but I’m pragmatic in such terrible society).

Cider9986 5 hours ago

Unfortunately ad blocking is not effective against current cross-site and anonymous user tracking.

Fingerprinting is extensively used and can't be defeated without a decent hit to browsing experience. Mullvad and Tor browser are likely the best at anti-fingerprinting.

The only completely reliable way to avoid this tracking is by not visiting websites with fingerprinting. A tool that can help with this is LibRedirect which redirects you from sites like Twitter to privacy front ends like xcancel.

The extensive web tracking is detrimental to privacy, but it doesn't compel you to add additional PII like phone numbers, which is much worse than cross-site tracking for a surveillance capitalism threat model.

paulirish 17 hours ago

Would love this for MacOS as well.

weikju 17 hours ago

Fortunately, if you read the README (and decide to go past the “this was mostly built by AI” part,

> Loupe also builds for macOS. The Mac version is mostly complete, but a few things still need work before it's polished.

heavensteeth 16 hours ago

> and decide to go past the “this was mostly built by AI” part

I got that feeling just seeing the title use "native" as a synonym of "not a website".

bethekidyouwant 17 hours ago

What “apps” do you use on a mac?

VertanaNinjai 17 hours ago

Probably a ton since macOS apps are literally distributed as .app bundles.

winstonwinston 16 hours ago

internet2000 16 hours ago

Google Chrome, VS Code, among others

bethekidyouwant 16 hours ago

socalgal2 13 hours ago

Yea, it's infuriating that most of the HN crowd thinks the apps are better then web. Apps can spy on you way more than web. It's the reason every website says "please download the app". If it was better for them to spy on you via the website they wouldn't ask you to download the app.

yreg 12 hours ago

There are plenty of other (better?) reasons why developers might want to push apps.

More APIs, less friction selling stuff, business presence right on the homescreen.

Gander5739 6 hours ago

And people want apps, believe it or not.

inigyou 4 hours ago

They are technically better. They can do more stuff and integrate with the OS better in general. That includes fingerprinting stuff and fingerprinting integration.

nekusar 5 hours ago

Yeah what's worse...

I have a LG modern TV. Smart shit. I also use a Linux install on a NUC. HDMI.

For some godsdamned reason, the TV was able to initiate an IP bridge with the Linux NUC and get an IP address on my network.

Nobody typed it in the TV. And I'm unsure how it did so itself.

What I do know is that Mikrotik allows DHCP-server blocks of wildcard MAC addresses. Blocked the whole fucking 24 bits of their allocation.

AND if it does get back online, I also shitcanned its routing on the IP side based on hostname.

Forgeties79 10 hours ago

This is neat and interesting, truly, but the classic “what now?” emerges. I guess the only answer is “throw out my iPhone”? Otherwise this kind of seems like a circuitous ad to make people get worried and download Psylo, which I see has in-app purchases. I’m not trying to come at you here, but it’s just hard not to feel suspicious online these days.

aggregator-ios 2 hours ago

Apple has been very good about public perception of its products and privacy. They just spent a lot of this year’s WWDC talking about the latter so I’m sure someone at Apple is aware of this.

I have not spent a lot of time thinking about why certain things like 50 apps install queries, boot volume timestamps, etc are provided to developers. But I think Apple will close these loopholes.

Also love the idea of outbound network connections being disabled by the user per app

microtonal 8 hours ago

Don't install apps outside trustable apps that don't embed tracking. Even if you cannot uninstall every app, the fewer you have, the less cross-app tracking. Also donate to and consider installing privacy-conscious alternative phone OSes. They may not have closed all holes (yet), but at least their incentives are aligned with yours.

Cider9986 10 hours ago

The only way to prevent this right now is to avoid installing apps that are doing this.

Forgeties79 9 hours ago

“Just don’t use it” only gets you so far and isn’t always an option. Also, as some have mentioned in this thread, many sites now make the mobile experience so painful (or remove key features) so as to force you onto the app.

I am against cars for the most part, but I can’t just get rid of my car. In this case, I can’t get rid of Slack (and other apps) because of work and unfortunately I do not work at a company that will buy me a work phone for work things.

Ultimately this has to start at a more root level. We need to claw back privacy.

Cider9986 8 hours ago

lencastre 11 hours ago

this is fantastic, just great really, and honestly makes one stick out so easily, reminfs me a lot of that license plate xkcd

fragmede 10 hours ago

cute_boi 14 hours ago

Apps like TikTok can know which username we logged in with, even if we uninstall and reinstall the app. This is egregious, as many companies like Facebook have SDKs embedded in many apps, allowing them to accurately interconnect user activity.

Apple should be ashamed that they aren't putting effort to randomize these fingerprints....

gene91 11 hours ago

That’s just keychain. It’s not even fingerprinting.

diebeforei485 12 hours ago

This is probably Keychain, right?

ChrisMarshallNY 16 hours ago

It's likely to be trolled by the WPA folks, who will insist that WPAs are just as insecure as native apps, so there's no difference ...

But very cool.

njsubedi 15 hours ago

You mean PWA?

ChrisMarshallNY 15 hours ago

Yes. Got my ps and ws mixed up. I was just reading about the Mt. Rushmore project (I was curious whether or not it was a WPA project -it wasn’t, officially).