This headline is ridiculous; I expect better from Ars Technica. You "admit" to things you shouldn't have done. In this case the government compelled Apple to disclose certain data and simultaneously prohibited Apple from disclosing the disclosure. Thanks to a senator's letter, Apple is now free to disclose something that they previously wanted to disclose, about something they were forced to do in the first place.
Compare to the Reuters headline: "Governments spying on Apple, Google users through push notifications - US senator." The emphasis and agency are correctly placed on the bad actors.
yeah, it looks like most of the other new agencies are attributing it correctly as the government. IMO it's the damn gag order that's most damning. You will spy on them for us and tell no-one.
To be fair Google was already making this information public via their transparency reports, albeit in aggregate, since 2010 [0].
"Google's transparency report, Ars confirmed, already documents requests for push notification data in aggregated data of all government requests for user information."
Apple conveniently played it safe until the coast was clear. Maybe they'd have been allowed to comment on this privacy issue if they published it in aggregate like Google - e.g. not specifically calling out the U.S. Govt? But that wasn't a risk Apple was willing to take for its users.
I actually scrolled straight to the bottom of the article to see if it was flagged as being "republished from another Condé Nast property." Just hoping there was an excuse for Ars.
A letter from a senator doesn't carry much legal force. From my understanding of the article, Apple claims they were prohibited from sharing this information, but a simple letter couldn't overturn something like a legal order or court mandate. The change here doesn't support the claim.
It reads more like Apple chose not to disclose in order to avoid the ire of the DOJ, even though it would have been morally more correct to tell the public sooner.
How are we not suing the ever living shit out of the government for violating peoples 4th ammendment rights? This is a gross violation of the unreasonable search and seizure clause in the constitution.
Third party doctrine for one: the data held by third parties has no expectation of privacy, even if it's about you.
From Wikipedia:
The third-party doctrine is a United States legal doctrine that holds that people who voluntarily give information to third parties—such as banks, phone companies, internet service providers (ISPs), and e-mail servers—have "no reasonable expectation of privacy" in that information. A lack of privacy protection allows the United States government to obtain information from third parties without a legal warrant and without otherwise complying with the Fourth Amendment prohibition against search and seizure without probable cause and a judicial search warrant.
Basically the government's argument: if you wanted it to remain private, you wouldn't have given it to someone else.
I'm reality, it's an area of law that desperately needs to be updated.
The problem is that you almost can't function in modern society without having a phone. So their argument is in bad faith, and really should be checked.
It will take someone being brought in on evidence gathered by this method to get it overturned. It would probably wind its way up to the Supreme Court.
Governments have been secretly tracking the app activity of an unknown number of people using Apple and Google smartphones, US Senator Ron Wyden (D-Ore.) revealed today.
According to Wyden, many app users do not realize that these instant alerts "aren't sent directly from the app provider to users’ smartphones" but instead "pass through a kind of digital post office run by the phone's operating system provider" to "ensure timely and efficient delivery of notifications."
Wyden said his office spent the past year investigating a "tip" received in spring 2022 claiming that "government agencies in foreign countries were demanding smartphone 'push' notification records from Google and Apple."
Ars verified that Apple's law enforcement guidelines now notes that push notification records "may be obtained with a subpoena or greater legal process."
It's unclear if either Apple or Google plans to provide any standalone reporting documenting all past requests for push notification data.
Wyden declined to comment further but wrote in his letter that he is pushing the DOJ to not just end the secrecy but also require even more transparency about these secretive requests.
The original article contains 694 words, the summary contains 182 words. Saved 74%. I'm a bot and I'm open source!
Pretty much any app that has message details in the notification. For instance, if I get a comment response on Lemmy, my app sends a push notification. If that notification contains details about the message, the government would supposedly be able to read that data.
Secure messaging apps have moved away from including message info specifically for this reason. For instance, Signal only sends a notification that you received a message. The push notification doesn’t say who the message was from, or what the message said.
But when Snapchat tells you that a specific friend is typing/has sent a message, the government could conceivably see that and connect you to that person. Maybe not a huge deal if it’s just a friend with nothing to hide. But we all know that “you have nothing to hide so you have nothing to fear” is a horrible excuse. Because it could land you on a list if that friend is a dealer, or becomes radicalized in the future, or has family who has ties to illegal activity, or any number of other things that the government may want to start watching them for.
…Signal only sends a notification that you received a message.
Signal on iOS shows previews by default. It even reads messages over AirPods as they come in.
iOS must be doing something special here, right? They can’t be sending message contents through the same route as push notification metadata, or it would be breaking end-to-end encryption… right?
Good thing I block/disable all of that crap and if a program does it I will just uninstall...I don't need some shit device to tell me what to do and when to do it.
It’s more than just one. It’s a trend. And I couldn’t care less what you do “in my presence.” You’re a random person on the internet trying to make a pointless point for no purpose other than to stir a pot.