The Apple Worldwide Developers Conference in San Jose, California. The firm didn't mention its new privacy updates. David Paul Morris/Bloomberg
The Apple Worldwide Developers Conference in San Jose, California. The firm didn't mention its new privacy updates. David Paul Morris/Bloomberg

Apple quietly closes personal data mining loophole



Apple changed its App Store rules last week to limit how developers use information about iPhone owners’ friends and other contacts, quietly closing a loophole that let app makers store and share data without many people’s consent.

The move cracks down on a practice that’s been employed for years. Developers ask users for access to their phone contacts, then use it for marketing and sometimes share or sell the information - without permission from the other people listed on those digital address books. On both Apple’s iOS and Google’s Android, the world’s largest smartphone operating systems, the tactic is sometimes used to juice growth and make money.

Sharing of friends’ data without their consent is what got Facebook into so much trouble when one of its outside developers gave information on millions of people to Cambridge Analytica, the political consultancy. Apple has criticised the social network for that lapse and other missteps, while announcing new privacy updates to boost its reputation for safeguarding user data. The iPhone maker hasn’t drawn as much attention to the recent change to its App Store rules, though.

As Apple’s annual developer conference got underway on June 4, the California-based company made many new pronouncements on stage, including new controls that limit tracking of web browsing. But the phone maker didn’t publicly mention updated App Store Review Guidelines that now bar developers from making databases of address book information they gather from iPhone users. Sharing and selling that database with third parties is also now forbidden. And an app can’t get a user’s contact list, say it’s being used for one thing, and then use it for something else - unless the developer gets consent again. Anyone caught breaking the rules may be banned.

IPhone contact lists contain phone numbers, email addresses and profile photos of family, friends, colleagues and other acquaintances. When users install apps and then consent, developers get dozens of potential data points on people’s friends. That’s a trove of information that developers have been able to use, beyond Apple’s control.

In the years following the launch of the App Store in 2008, contact-list abuse surfaced from time to time, and in 2012, Apple added a way for users to explicitly approve their contacts, photos, location information, and other data being uploaded by developers. Some apps, including Uber and Facebook, let users remove contacts that have been uploaded. Even so, there’s no mechanism to do that for all apps that have been installed on an iPhone.

Aside from that, Apple’s rules on contact lists have remained relatively consistent for a decade. Balancing user privacy with the needs of developers has helped the company build a profitable app ecosystem. Apple said last week that developers have generated $100 billion since the App Store launched. The company typically takes 30 per cent of app revenue and runs search ads in its App Store.

“They have a huge ecosystem making money through the developer channels and these apps, and until the developers get better on privacy, Apple is complicit," said Domingo Guerra, president of Appthority, which advises governments and companies on mobile phone security. “When someone shares your info as part of their address book, you have no say in it, and you have no knowledge of it."

While Apple is acting now, the company can’t go back and retrieve the data that may have been shared so far. After giving permission to a developer, an iPhone user can go into their settings and turn off apps’ contacts permissions. That turns off the data faucet, but doesn’t return information already gathered.

The Google app store works a similar way. On the company’s help page about app permissions, under “Important” it says, “If you remove permission for an app, this action won’t delete the info the app already has. However, the app can’t use new info or take actions from that point on.”

The difference is that Google mostly keeps quiet about how it uses people’s data for advertising, while Apple often talks about not collecting user information or building profiles of them. The iPhone maker also rolled out extra privacy controls to comply with a strict new European law earlier this year and has fought US government efforts to access user data on its devices.

One developer contacted Bloomberg News in the aftermath of Facebook’s Cambridge Analytica scandal, expressing concern that Apple users may not understand what developers can see when they provide access to their contacts. The developer requested anonymity for fear of retribution from Apple or the developer’s employer.

_______________

Read more:

New iPhone features to include ways to use it less

Tencent, the global tech giant few might have heard of

_______________

Once a user clicks OK, developers can download the information the user keeps about everyone in their address book. That might include not only names and phone numbers, but other data such as birth dates, home and work addresses. If people attached a photo to their friends’ profiles, the developers get that, too. The app-maker can also learn when a contact entry was created and edited, giving clues on the accuracy of the phone number, and whether this is a new or old acquaintance.

“The address book is the Wild West of data,’’ the iOS developer said. “I am able to instantly transfer all the contacts info into some random server or upload it to Dropbox if I wanted to, the very moment a user says OK to giving contacts permission. Apple doesn’t track it, nor do they know where it went.’’

Another developer said they’ve only seen one app that collected user contact lists for dishonest purposes. And many uses for contact information are well understood. When downloading a game, the games-maker may ask for contacts permission to show you friends who also have the app who you can play with, or they may build an easy way for you to text a friend about joining you on the app. Apps like Instagram and Snapchat ask for contact information to help users build social networks. The Bloomberg News app also asks for access to users’ contact lists, and other web services access email address books, so it’s not just an Apple or Google problem.

After Bloomberg reported Apple’s rule changes, US Senator Mark Warner said the company “should be applauded - for this, and for other user-empowering moves Apple has made that will give consumers better control over how their data is used”.

"More companies should follow suit,” added Mr Warner, a Democrat from Virginia who’s been one of Facebook’s fiercest critics.

The Federal Trade Commission (FTC) warns consumers to be wary when apps ask for information unrelated to the purpose of the app. On its website, the FTC says any information collected by developers can be shared with third parties or used to build databases.

Contact information may not always be directly useful to a developer’s app, unless it has a social or chat component. But it could be sold to data brokers, who combine it with other information to help companies sell goods and services online. And in some cases, it’s a tool to market an app to other people with an endorsement from the person who downloaded it.

Last week, Apple banned apps from contacting people using information collected via a user’s contacts or photos "except at the explicit initiative of that user on an individualised basis". Developers must also provide users with a clear description of how the message will appear to the recipient before sending it.

That type of bulk-texting has been the basis of viral growth for apps like the 2016 sensation Down To Lunch, which let people invite all their friends to lunch at the same time. It’s also been a common tool in political campaigns, supported by companies like CallHub.

In early 2017, some iPhone users began getting texts from an app they’d never heard of before. “A friend added you on ChitChat,” the messages said. “Tap here to get it.”

ChitChat was built by Swipe Labs, a social product design studio that was using contact list access to market its new messaging service to users’ friends. In effect, digital cold-calling on steroids. People complained on Twitter, where venture capitalist Chris Sacca called it "the herpes of contact lists".

Marwan Roushdy, chief executive of Swipe Labs, apologised, calling the tactic a "half baked growth feature".

"We had some issues with too many notifications being sent out," he added. A new version of the app that "throttles down notifications" was sent to Apple for review, Mr Roushdy explained. Swipe Labs was acquired by Uber Technologies a few months later.

In 2013, the FTC sued social-networking app Path over collecting address book information from iPhones and Android phones without user consent. Path settled and committed to not misleading users in the future. Apple CEO Tim Cook met with Path’s CEO to chastise him for the practice, Bloomberg Businessweek reported at the time.

While Apple and Google have taken steps to improve app permissions, when things go awry, regulators tend to put the onus on the apps, not the operating systems. In 2013, the FTC settled with a flashlight app on Android phones for collecting location information and selling it to advertising networks without consumers knowing.

Facebook has stressed that the practice of developers sharing users' friends' data was against its rules. The social-media giant banned the developer who shared this information with Cambridge Analytica. And it made the political consulting firm sign an agreement confirming it had deleted the data back in 2015. This March, the New York Times and other outlets reported the information hadn't been deleted. The episode started a new global discussion about privacy, with European and some US policymakers arguing consumers should dictate where their data flows, not giant tech companies.

On the social network, users make their own profiles, while smartphone address books contain digital dossiers that people make about other people. There may be hundreds of versions of people’s contact information that they have no control over. The same person might be “Dad” on one phone and “Craigslist Couch Guy” on another. The woman who bought his couch years ago may still be inadvertently sharing his address with the game she plays on her iPhone every morning.

TOURNAMENT INFO

Women’s World Twenty20 Qualifier

Jul 3- 14, in the Netherlands
The top two teams will qualify to play at the World T20 in the West Indies in November

UAE squad
Humaira Tasneem (captain), Chamani Seneviratne, Subha Srinivasan, Neha Sharma, Kavisha Kumari, Judit Cleetus, Chaya Mughal, Roopa Nagraj, Heena Hotchandani, Namita D’Souza, Ishani Senevirathne, Esha Oza, Nisha Ali, Udeni Kuruppuarachchi

'Brazen'

Director: Monika Mitchell

Starring: Alyssa Milano, Sam Page, Colleen Wheeler

Rating: 3/5

Company%20Profile
%3Cp%3E%3Cstrong%3ECompany%20name%3A%3C%2Fstrong%3E%20myZoi%3Cbr%3E%3Cstrong%3EStarted%3A%3C%2Fstrong%3E%202021%3Cbr%3E%3Cstrong%3EFounders%3A%3C%2Fstrong%3E%20Syed%20Ali%2C%20Christian%20Buchholz%2C%20Shanawaz%20Rouf%2C%20Arsalan%20Siddiqui%2C%20Nabid%20Hassan%3Cbr%3E%3Cstrong%3EBased%3A%3C%2Fstrong%3E%20UAE%3Cbr%3E%3Cstrong%3ENumber%20of%20staff%3A%3C%2Fstrong%3E%2037%3Cbr%3E%3Cstrong%3EInvestment%3A%3C%2Fstrong%3E%20Initial%20undisclosed%20funding%20from%20SC%20Ventures%3B%20second%20round%20of%20funding%20totalling%20%2414%20million%20from%20a%20consortium%20of%20SBI%2C%20a%20Japanese%20VC%20firm%2C%20and%20SC%20Venture%3C%2Fp%3E%0A
NO OTHER LAND

Director: Basel Adra, Yuval Abraham, Rachel Szor, Hamdan Ballal

Stars: Basel Adra, Yuval Abraham

Rating: 3.5/5

A MINECRAFT MOVIE

Director: Jared Hess

Starring: Jack Black, Jennifer Coolidge, Jason Momoa

Rating: 3/5

Globalization and its Discontents Revisited
Joseph E. Stiglitz
W. W. Norton & Company

Tuesday's fixtures
Group A
Kyrgyzstan v Qatar, 5.45pm
Iran v Uzbekistan, 8pm
N Korea v UAE, 10.15pm
The specs: Lamborghini Aventador SVJ

Price, base: Dh1,731,672

Engine: 6.5-litre V12

Gearbox: Seven-speed automatic

Power: 770hp @ 8,500rpm

Torque: 720Nm @ 6,750rpm

Fuel economy: 19.6L / 100km

THREE
%3Cp%3EDirector%3A%20Nayla%20Al%20Khaja%3C%2Fp%3E%0A%3Cp%3EStarring%3A%20Jefferson%20Hall%2C%20Faten%20Ahmed%2C%20Noura%20Alabed%2C%20Saud%20Alzarooni%3C%2Fp%3E%0A%3Cp%3ERating%3A%203.5%2F5%3C%2Fp%3E%0A
The%20specs
%3Cp%3E%3Cstrong%3EEngine%3A%3C%2Fstrong%3E%201.8-litre%204-cyl%20turbo%0D%3Cbr%3E%3Cstrong%3EPower%3A%20%3C%2Fstrong%3E190hp%20at%205%2C200rpm%0D%3Cbr%3E%3Cstrong%3ETorque%3A%3C%2Fstrong%3E%20320Nm%20from%201%2C800-5%2C000rpm%0D%3Cbr%3E%3Cstrong%3ETransmission%3A%20%3C%2Fstrong%3ESeven-speed%20dual-clutch%20auto%0D%3Cbr%3E%3Cstrong%3EFuel%20consumption%3A%3C%2Fstrong%3E%206.7L%2F100km%0D%3Cbr%3E%3Cstrong%3EPrice%3A%3C%2Fstrong%3E%20From%20Dh111%2C195%0D%3Cbr%3E%3Cstrong%3EOn%20sale%3A%20%3C%2Fstrong%3ENow%3C%2Fp%3E%0A
Living in...

This article is part of a guide on where to live in the UAE. Our reporters will profile some of the country’s most desirable districts, provide an estimate of rental prices and introduce you to some of the residents who call each area home.

The years Ramadan fell in May

1987

1954

1921

1888

Company%20profile
%3Cp%3E%3Cstrong%3EName%3A%3C%2Fstrong%3E%20WallyGPT%3Cbr%3E%3Cstrong%3EStarted%3A%20%3C%2Fstrong%3E2014%3Cbr%3E%3Cstrong%3EFounders%3A%20%3C%2Fstrong%3ESaeid%20and%20Sami%20Hejazi%3Cbr%3E%3Cstrong%3EBased%3A%3C%2Fstrong%3E%20Dubai%3Cbr%3E%3Cstrong%3ESector%3A%20%3C%2Fstrong%3EFinTech%3Cbr%3E%3Cstrong%3EInvestment%20raised%3A%20%3C%2Fstrong%3E%247.1%20million%3Cbr%3E%3Cstrong%3ENumber%20of%20staff%3A%3C%2Fstrong%3E%2020%3Cbr%3E%3Cstrong%3EInvestment%20stage%3A%20%3C%2Fstrong%3EPre-seed%20round%3C%2Fp%3E%0A
Match info

Manchester United 1 (Van de Beek 80') Crystal Palace 3 (Townsend 7', Zaha pen 74' & 85')

Man of the match Wilfried Zaha (Crystal Palace)

if you go

The flights

Air Astana flies direct from Dubai to Almaty from Dh2,440 per person return, and to Astana (via Almaty) from Dh2,930 return, both including taxes. 

The hotels

Rooms at the Ritz-Carlton Almaty cost from Dh1,944 per night including taxes; and in Astana the new Ritz-Carlton Astana (www.marriott) costs from Dh1,325; alternatively, the new St Regis Astana costs from Dh1,458 per night including taxes. 

When to visit

March-May and September-November

Visas

Citizens of many countries, including the UAE do not need a visa to enter Kazakhstan for up to 30 days. Contact the nearest Kazakhstan embassy or consulate.

RESULTS

Bantamweight: Jalal Al Daaja (JOR) beat Hamza Bougamza (MAR)

Catchweight 67kg: Mohamed El Mesbahi (MAR) beat Fouad Mesdari (ALG)

Lightweight: Abdullah Mohammed Ali (UAE) beat Abdelhak Amhidra (MAR)

Catchweight 73kg: Mosatafa Ibrahim Radi (PAL) beat Yazid Chouchane (ALG)

Middleweight: Yousri Belgaroui (TUN) beat Badreddine Diani (MAR)

Catchweight 78KG: Rashed Dawood (UAE) beat Adnan Bushashy (ALG)

Middleweight: Sallah-Eddine Dekhissi (MAR) beat Abdel Enam (EGY)

Catchweight 65kg: Yanis Ghemmouri (ALG) beat Rachid Hazoume (MAR)

Lightweight: Mohammed Yahya (UAE) beat Azouz Anwar (EGY)

Catchweight 79kg: Souhil Tahiri (ALG) beat Omar Hussein (PAL)

Middleweight: Tarek Suleiman (SYR) beat Laid Zerhouni (ALG)

Naga
%3Cp%3E%3Cstrong%3EDirector%3A%C2%A0%3C%2Fstrong%3EMeshal%20Al%20Jaser%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStarring%3A%C2%A0%3C%2Fstrong%3EAdwa%20Bader%2C%20Yazeed%20Almajyul%2C%20Khalid%20Bin%20Shaddad%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ERating%3A%20%3C%2Fstrong%3E4%2F5%3C%2Fp%3E%0A

GOLF’S RAHMBO

- 5 wins in 22 months as pro
- Three wins in past 10 starts
- 45 pro starts worldwide: 5 wins, 17 top 5s
- Ranked 551th in world on debut, now No 4 (was No 2 earlier this year)
- 5th player in last 30 years to win 3 European Tour and 2 PGA Tour titles before age 24 (Woods, Garcia, McIlroy, Spieth)

UAE currency: the story behind the money in your pockets
Electric scooters: some rules to remember
  • Riders must be 14-years-old or over
  • Wear a protective helmet
  • Park the electric scooter in designated parking lots (if any)
  • Do not leave electric scooter in locations that obstruct traffic or pedestrians
  • Solo riders only, no passengers allowed
  • Do not drive outside designated lanes
Election pledges on migration

CDU: "Now is the time to control the German borders and enforce strict border rejections" 

SPD: "Border closures and blanket rejections at internal borders contradict the spirit of a common area of freedom" 

How Beautiful this world is!
Skewed figures

In the village of Mevagissey in southwest England the housing stock has doubled in the last century while the number of residents is half the historic high. The village's Neighbourhood Development Plan states that 26% of homes are holiday retreats. Prices are high, averaging around £300,000, £50,000 more than the Cornish average of £250,000. The local average wage is £15,458. 

2025 Fifa Club World Cup groups

Group A: Palmeiras, Porto, Al Ahly, Inter Miami.

Group B: Paris Saint-Germain, Atletico Madrid, Botafogo, Seattle.

Group C: Bayern Munich, Auckland City, Boca Juniors, Benfica.

Group D: Flamengo, ES Tunis, Chelsea, (Leon banned).

Group E: River Plate, Urawa, Monterrey, Inter Milan.

Group F: Fluminense, Borussia Dortmund, Ulsan, Mamelodi Sundowns.

Group G: Manchester City, Wydad, Al Ain, Juventus.

Group H: Real Madrid, Al Hilal, Pachuca, Salzburg.

Salah in numbers

€39 million: Liverpool agreed a fee, including add-ons, in the region of 39m (nearly Dh176m) to sign Salah from Roma last year. The exchange rate at the time meant that cost the Reds £34.3m - a bargain given his performances since.

13: The 25-year-old player was not a complete stranger to the Premier League when he arrived at Liverpool this summer. However, during his previous stint at Chelsea, he made just 13 Premier League appearances, seven of which were off the bench, and scored only twice.

57: It was in the 57th minute of his Liverpool bow when Salah opened his account for the Reds in the 3-3 draw with Watford back in August. The Egyptian prodded the ball over the line from close range after latching onto Roberto Firmino's attempted lob.

7: Salah's best scoring streak of the season occurred between an FA Cup tie against West Brom on January 27 and a Premier League win over Newcastle on March 3. He scored for seven games running in all competitions and struck twice against Tottenham.

3: This season Salah became the first player in Premier League history to win the player of the month award three times during a term. He was voted as the division's best player in November, February and March.

40: Salah joined Roger Hunt and Ian Rush as the only players in Liverpool's history to have scored 40 times in a single season when he headed home against Bournemouth at Anfield earlier this month.

30: The goal against Bournemouth ensured the Egyptian achieved another milestone in becoming the first African player to score 30 times across one Premier League campaign.

8: As well as his fine form in England, Salah has also scored eight times in the tournament phase of this season's Champions League. Only Real Madrid's Cristiano Ronaldo, with 15 to his credit, has found the net more often in the group stages and knockout rounds of Europe's premier club competition.

Top tips

Create and maintain a strong bond between yourself and your child, through sensitivity, responsiveness, touch, talk and play. “The bond you have with your kids is the blueprint for the relationships they will have later on in life,” says Dr Sarah Rasmi, a psychologist.
Set a good example. Practise what you preach, so if you want to raise kind children, they need to see you being kind and hear you explaining to them what kindness is. So, “narrate your behaviour”.
Praise the positive rather than focusing on the negative. Catch them when they’re being good and acknowledge it.
Show empathy towards your child’s needs as well as your own. Take care of yourself so that you can be calm, loving and respectful, rather than angry and frustrated.
Be open to communication, goal-setting and problem-solving, says Dr Thoraiya Kanafani. “It is important to recognise that there is a fine line between positive parenting and becoming parents who overanalyse their children and provide more emotional context than what is in the child’s emotional development to understand.”