Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My solution is to buy an iPhone. I don't mean that as a snarky response, as I'd very much like to use an Android phone (And if it's just to be able to use Tasker). But I simply don't have time to bother with this stuff anymore, so I pay ~200$ more in exchange for my time (and privacy).

Secondly, I don't want to give anyone money that gives a crap about my device's security and privacy.

There was a similar article on HN a while ago that came to the same conclusion: https://news.ycombinator.com/item?id=13056288



I currently use an iPhone and it too isn't a good privacy solution either.

For example my pet peeve is that apps like Waze or Uber are allowed to only request full location tracking, even while running in the background. As a user you cannot restrict location tracking to happen only when the app is running. This is an either-or proposition. Either the user allows location tracking while in the background, or you cannot use the app.

And surely you can manually enable and disable location tracking per app, but that's way too cumbersome. Just imagine trying to start navigation while at a red light. Whereas with Android I used to be able to enable/disable location tracking globally, since you get a global shortcut that you can access in a swipe and tap.

I also use 1Password as a password manager. Well, iOS has the same problem as Android where apps can read the contents of your clipboard, including copied passwords. And compared with Android it's not common to see password managers use third-party keyboards or accessibility features to side-step copy/pasting passwords. And sure, apps have an API to integrate managers like 1Password or Lastpass, which is nice when it's there and it's surely nice when it works in Safari, but too few apps use it.

In other words, even though the privacy/security story is currently better for iOS, IMO it's not that good either and I hope that Apple and Google will work on improving this situation because I'm seriously thinking of going back to a dumb phone.


To be fair, those are app choices to require 'Always' for location tracking. You can most definitely restrict an app to use location only while using - you can't fault Apple or IOS for apps that (unnecessarily [1]) demand more.

One thing I really like about IOS is the reminder that an app has been using your location in the background for a while [2]

[1] http://www.theverge.com/2016/11/30/13763714/uber-location-da... [2] https://support.apple.com/library/content/dam/edam/applecare...


But Apple makes (seemingly) no effort to encourage developers to allow limited location access. Why can't iOS be in charge of when an app uses my location when the app is backgrounded?

The reminder only appears once per app, as far as I've noticed. I restored my phone recently for the first time in over a year, and had totally forgotten about the reminder feature.


No, allowing apps to require "Always" isn't fair at all and that's not a reasonable explanation or apology.

And yes, I can surely fault Apple and iOS for that.


And surely you can manually enable and disable location tracking per app, but that's way too cumbersome. Just imagine trying to start navigation while at a red light.

I do this with apps like Uber and Waze. It's really not that cumbersome. When the app starts up, it will prompt you to enable location tracking, and if you say OK, it will bring you right to the setting. Then, when you're done, close out the app and find the setting again. Only set up map instructions while parked before you leave.

To be honest, background location tracking on iOS is far, far worse than Android. It's really spotty, it requires the app be visibly running in the app list, and it also prompts the user to turn it off if your app uses it too much.


> apps like Waze or Uber are allowed to only request full location tracking, even while running in the background

That's their choice, iOS allows the app developer to request location access restricted to the app being in the foreground.

There was a round of articles about the privacy issues a month or two ago, and Uber just insisted they need to do it.


> As a user you cannot restrict location tracking to happen only when the app is running.

I'm pretty sure you can? I saw a friend do that exact thing yesterday, for the Foursquare app. I don't think it was in the Foursquare settings, it was in the OS settings.


You most certainly can indeed do that. It's just a bit buried (Settings -> Privacy -> Location Services -> [App] -> While Using).


Guys, that's not true ;-) please install Uber and Waze and check for yourself.


I'm trying to determine whether iOS apps could sniff my clipboard, and i haven't proven that they can't; it doesn't seem to be a specific permission that needs to be assigned or can be denied. And thus using 1Password on my iPhone to copy and paste passwords seems to have a bit of a risk to it.


Facebook reads the contents of your clipboard every time you open it. There should to be a permission for it, but there isn't.


Thanks. I didn't know that, but I don't install FB because of some other stuff I heard they did (like monitor the mic). Likewise messenger. I do access FB, but only from within Firefox, which I use soley for that purpose.


iOS Apps can read your clipboard (But only if the app is open i.e. not in the background, which was possible in earlier iOS versions). I would welcome it if they introduced a permission for clipboard handling.

Personally, I use Workflow to clear my clipboard after pasting a password.


But can apps sniff in what website or app you are using the password? Either for iOS or Android, if the password are just random strings unique for each site and they can't determine that then the attack vector diminishes.


A while back you could query the apps currently active on iOS and there was a big scandal that Twitter was doing it, being reported by the media as a secret vulnerability, which was bullshit since that "vulnerability" was fairly well known already and in use by ad platforms. And at a previous company we used it for more than a year I think, before being in the news. I don't know what happened after that, Apple must have closed that loophole and Android requires a specific permission. But there are always vulnerabilities that developers can exploit and you can't trust the OS on this one.

Plus it really doesn't matter, because when it comes to security, there's also the issue of the mono-culture and user technical stupidity. We know that many people use Gmail, Facebook, Twitter, etc, most of them reusing passwords across services. And logging the user's copy/pasted texts gives you such a specific dictionary that the probability of getting hacked approaches 1 fast.


I intensely dislike Apple as a company, and I dislike their products, but the honest truth is there is no such thing as a reasonably secure Android device, and I can't fathom recommending one to anyone ever again. After seven years on Android, my recommendation is "literally anything else".


I've stopped liking or disliking companies altogether. I try to look if a company isn't crossing my personal moral boundaries (child workers etc.) and whether it satisfies my needs. Then I buy their product. As for the moral part, Apple is the only company I've heard of that at least acknowledges there's a problem (http://www.apple.com/supplier-responsibility/).


Your solution for what? for privacy? Apple privacy? just nope.

Antivirus software are all bloatware, they don't do money anymore then they focus on other things "to secure".

Ok. your clipboard can be read by other software (like in Windows ...) then what? just don't copy password.

"Yes downvote my comment but don't argue. The solution buy an iPhone is still not valid solution."


You're getting downvotes for your "LA, LA, LA I'm not listening" attitude. Android and iOS have many very different advantages and disadvantages over each other, but security on iOS is very clearly vastly superior and this has been confirmed repeatedly by top security researchers. Trying to pretend that's not true or pick and choose 'whataboutist' issues and pretend that's all that matters to make false equivalences is really going to wind people up. The expected level of discourse here is quite a bit beyond that.


"security on iOS is very clearly vastly superior and this has been confirmed repeatedly by top security researchers"

The vast majority of this "superiority" only applies because the iOS ecosystem is a walled garden. Android devices typically allow sideloading, which obviously introduces an additional attack vector; reproducing this on iOS (i.e. by jailbreaking) brings you back to the same attack surface.

The other notable difference between iOS and Android security-wise has historically been the ability to selectively accept certain privileges, but recent Android versions have introduced this as well, and even the old permissions model was (and still is) much more up-front and fine-grained about which permissions an app requires. iOS also had (and probably still has) an edge for awhile when it came to OpenBSD-style exploit mitigations IIRC, but Android is getting these too by way of projects like CopperheadOS.

Other than those aspects, there are actually very few major differences (last I checked, at least; I haven't really been following the iOS world, so maybe Apple's done some crazy stuff while I wasn't looking) between their security models. Both implement some form of per-app sandboxing, both default to disallowing root access (in most cases, at least; third-party Android distros have a tendency to ship with root access, usually behind some toggle and/or some management app like SuperSU or whatever the latest hotness is), both default to a locked-down boot environment (in order to defend against rootkits), etc. Both have had their share of security-affecting bugs, too. There's no "clearly vastly superior" about it in either direction, at least on a platform level.

On an ecosystem level, sure; Google doesn't do quite as good a job as Apple when it comes to screening malware (there have been quite a few notorious examples of this), and the ability to sideload apps (as well as the much easier jailbreaking/rooting situation) means that more malware is actually viable. This isn't a security problem in the sense of the platform itself, but rather in the sense of allowing users to shoot themselves in the foot by installing trojans. Like I said above, these exact same problems happen on jailbroken iOS devices, too (I reckon with a very similar frequency, too, but I don't have statistical evidence to back it up, so take that with a grain of salt).


"Android devices typically allow sideloading,"

In the context of this discussion, sideloading is irrelevant. We're talking about the default happen-to-everybody case.

"Other than those aspects, there are actually very few major differences... between their security models"

It's not just about the security model, though. We have some reason to believe that Apple phones may actually be at least partially resistant to law enforcement. I say that not as an encouragement to use them that way, but to point out that's about the highest security bar possible and we at least have some reason to think the latest iPhones get there. (And I am carefully phrasing this as "some reason to believe" and "resistant" because we do not know for sure whether this is the case, and I wouldn't bet that even if the phone can stymie a local police investigation that it would block a full-powered Federal investigation.) We have no reason to believe any Android phone meets this standard of security, nor would the fact that a particular one rose to that standard meant any other ones would.

And if I'm pro-anything, I'm pro-Android in general. But that doesn't change the facts.


"We have some reason to believe that Apple phones may actually be at least partially resistant to law enforcement."

Clarification: we have some reason to believe that Apple itself may be resistant to law enforcement agencies trying to compel Apple into doing said LEAs' jobs. It's a good sign that Apple hasn't (to public knowledge, at least) disclosed any sort of backdoor in iOS' at-rest encryption, but the same thing can be said of Android devices, too (at least the ones that do indeed support encrypted storage, which should be all of them released within the last couple years per what I recall from Google's standards, plus a significant quantity of prior devices).

If we're going for the default happen-to-everybody case, iOS and Android are on equal footing here. If we're going for the security-conscious case, then Android has a huge leg up (due to the existence of completely-FOSS - and therefore completely-publicly-auditable - ROMs) relative to iOS (which lacks such a capability).

Transparency is a dependency of trust. Neither iOS nor Android are transparent in a typical deployment, but at least an Android device can be transparent, and thus can be trustworthy. iOS cannot, and therefore cannot be trusted to be secure.

Given that, I feel like - in this case - talking about "facts" when the publicly-available information on the lack of iOS backdoors (both at-rest and in-transit) is speculative at best does not seem to be logically consistent.


One significant difference is that iOS devices get security updates far longer than most Android devices.


Ok about this argument, but this have nothing to do with Android but the phone brand. If Samsung don't want to push update it's their fault and not the fault of Android to provide a open system. It's still why I don't have found any argument that "IPhone are the solution".


Maybe that iOS devices actualy do in reality get updates far beyond any actual Android devices? Yes in theory Android devices could get security updates as long as iOS devices. But arguably the fact that in reality none of them do is somewhat relevant to actual people's actual choices about their actual security.


Yup, that's about the only way in which iOS has an advantage though. There's no good privacy protection software on iOS, no way to block known bad hosts, etc. Go get an Android device with XPrivacy and AdAway, it's seriously the only tolerable way to use a phone these days. While the ability to add these things isn't default, it also isn't actively persecuted like on iOS.

The amount of information every app you install wants to harvest is ridiculous, on iOS they can do this unchecked, even if you'd rather they not, on Android if you're willing to do a bit of work, you can have near complete control.

Maybe not quite as much control as that feeling of hitting Ctrl+D for the first time after installing SoftICE, but... pretty damn good. :)


But that's exactly what content blockers in iOS are for, they also have the benefit of not being able to send information about what's being blocked back to their apps and servers.

I myself have been using Adblock Fast for quite some time now.


Correct me if I'm wrong, but those content blockers only apply to safari, not apps, right? Blocking ads while browsing isn't really the issue I'm talking about - web ads are already fairly restricted in what they can do, especially if you have a decent browser with extensions.

With adaway on Android I'm able to block inapp ads, statistics and demographics reporting services, crash reporting services and other privacy invading services.


You could have stopped that sentence after "get security updates."




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: