Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wow. I'd diligently turned off background location for virtually everything, but I had no idea so many apps did background refresh by default. Your IP address is nearly as good as your GPS coordinates. (Edit: Maybe one's IP address on a cellular connection doesn't matter as much as I thought. I just did a check and it didn't even get my city correct.)

Possibly the most surprising thing is that, unlike all other permissions, iOS didn't ask me directly before enabling background refresh. That's disturbing.

Also, while I sympathized with Apple outsourcing Maps' business info to Yelp, they really should hold their partners to a much higher standard given all of their privacy rhetoric.



For every app that I install I check if the app activated background app refresh. Most of the time it does not make any sense why an app would even need that, other than tracking me. Also disabling it for most apps is one of the best things you can do to extend your battery life.

In Apple's defense it is a hard thing to ask the user whether or not they want to permit "background app refresh". Many users might not understand at all what this means. It is not as easy to understand as "allow app to send you notifications" or "allow app to use your location".

Maybe Apple could force apps to request for each specific use case why they wants to be active in the background. Is it to enable basic functionality of the app or is it to track you? Would be great if the user could choose in which case to allow access and in which case not. Right now it is a blank check you give to each app and it is hard to tell whether the app abuses its permissions or not.


Yep. Still less of a blank check than Android though; it doesn't even distinguish background location from foreground location, last I checked.


Yeah that's a limitation of Android at present, but check out what's coming in Android Q: https://developer.android.com/preview/privacy/device-locatio...


Android is weird! I have to ask for that location permission if I want to connect to Bluetooth printer!


It kind of makes sense, in that it’s possible to use data on what radios you can see (particularly WiFi SSIDs) to work out a user’s location. Still causes no end of hassle from customers complaining about you requesting location permissions to connect to a WiFi device though.


I suspect they do this to be able to configure Bluetooth within regional regulations. In US / China you can transmit with up to 20dBm output power at 2.4 GHz, while in much of the world 10 dBm is max.


The location permission is not needed to use Bluetooth on Android, but apps must request it to be able to scan for nearby access points and beacons (both for wifi and for BT), since this information can be used to infer the device's location. Fun fact: turning off location services without revoking the location permission still allows apps to scan for wifi access points and infer your location with impressive precision. The list of apps that have the scanning permission is hidden somwhere deep in system settings.


Perhaps they could show which apps have used background refresh recently on the notification center/lock screen after you haven't used your phone for a while. "Facebook, Uber and 7 other apps have downloaded content in the background [Learn More]"


iOS already does this for GPS usage. Sounds smart to do the same for background activity.


does it though?

what happens if background refresh is on but location -> never?


It can probably be estimated from cell IP


> Maybe one's IP address on a cellular connection doesn't matter as much as I thought. I just did a check and it didn't even get my city correct.

It all depends on your cell provider. A lot of cellular providers use GCNATs so their whole customer base appears to connect from just a handful of IPs without any proxy headers (which is why doing a ip address geo location on yourself is giving you wrong info).

A few providers will give you a non nated IP on request (and usually for a fee). IPv6 should “fix” the issue.


"Your IP address is nearly as good as your GPS coordinates."

Are you only concerned about transmitting your IP address to other third parties besides Apple? iOS is configured to automatically transmit the user's IP address to various Apple servers on a continual basis, e.g. time-osx.g.aaplimg.com. iOS users cannot change that configuration.


The CNAME for time.apple.com and time.euro.apple.com (but not time.asia.apple.com -> time-ios.g.aaplimg.com).

I don't think there's something stopping you from redirecting 123/udp to your own NTP server. This is another of the problems that are easily solved with a VPN.


"I don't think there's something stopping you from redirecting 123/udp to your own NTP server."

Neither do I. I use local DNS and a router to block traffic to Apple servers.

Of course it would be easier to simply edit the operating system configuration files, if the device manufacturer did not try to prevent device owners from doing so.


> "Possibly the most surprising thing is that, unlike all other permissions, iOS didn't ask me directly before enabling background refresh. That's disturbing."

I believe it says so in the fine print of the terms and condition we do not read. I could be wrong ofcourse.


"Apple outsourcing Maps' business info to Yelp, they really should hold their partners to a much higher standard given all of their privacy rhetoric."

I could not agree more. I cannot stand Yelp and was pretty bummed when they integrated Yelp into Apple Maps.


Yeah, this is really a story about how apps take advantage of people who aren't judicious about what they install, and aren't careful about what background & location data behavior they allow for the apps they have.

My guess is that Apple is already working on a plan to curtail these abuses -- or, rather, working on ways to make it easier for normal people to do so. Obviously if you're reading HD, you understand these issues better, and are more apt to use the tools already in iOS to limit bad behavior.

>they really should hold their partners to a much higher standard given all of their privacy rhetoric.

Agreed.


> I'd diligently turned off background location for virtually everything

First thing I did with my wife's Iphone. I imagine that with that disabled and permissions set correctly , an iphone leaks less than an android.


My understanding is that this is correct.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: