Apple clamps down on device fingerprinting that lets sneaky developers track users

After introducing App Tracking Transparency a couple of years ago, Apple wants developers to be even more clear about why they use certain APIs in their apps. On a support page (via AppleInsider) on its developer’s website, the Cupertino firm wants to ensure that a developer’s usage of APIs is consistent with its policy.

Apple explains that some APIs that deliver core functionality to apps have the “potential of being misused to access device signals to try to identify the device or user, also known as device fingerprinting.”

The company clarifies that fingerprinting is not allowed even if a user gives the developer permission to track them. That said, developers will have to describe why their app or third-party SDK on the company’s operating system uses these APIs, and Apple will check if they are being used for the expected reasons.

Apple explains: “From Fall 2023, you’ll receive an email from Apple if you upload an app to App Store Connect that uses the required reason API without describing the reason in its privacy manifest file. From Spring 2024, apps that don’t describe their use of required reason API in their privacy manifest file won’t be accepted by App Store Connect.”

The company follows by saying, “Your app or third-party SDK must declare one or more approved reasons that accurately reflect your use of each of these APIs and the data derived from their use. You may use these APIs and the data derived from their use for declared reasons only. These declared reasons must be consistent with your app’s functionality as presented to users, and you may not use the APIs or derived data for tracking.”

As developers still have time to comply with the new rules, Apple says that if an app uses the required reason API to provide benefits to people for a reason that isn’t already listed, they can submit a request for a new approved reason.

The company also shows what developers need to add to their apps on the documentation page and how to describe data use in privacy manifests.

BGR will let you know once this new policy becomes mandatory and how this could impact your usage of apps.

Stay connected with us on social media platform for instant update click here to join our  Twitter, & Facebook

We are now on Telegram. Click here to join our channel (@TechiUpdate) and stay updated with the latest Technology headlines.

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TechiLive.in is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – admin@techilive.in. The content will be deleted within 24 hours.
Exit mobile version