Hacker News new | ask | show | jobs
by smoldesu 820 days ago
The parent is right, though. Both Google and Apple send encrypted telemetry that you cannot MITM or decrypt a-la HTTPS or TLS. The average iPhone and average Android phone lights up like a Christmas tree in Wireshark - some of it can be reverse-engineered with TLS or DNS abuse, some of it is RSA encrypted against the hardware root-of-trust.

Apple's mea-culpa is that unlike Android they do not ship an Open Source OS ROM for developers to modify. Google's telemetry can be entirely neutralized by removing Google Play services and using Android without Google software. iPhones don't have that escape hatch, leading to a pretty literal limitation of how you "own" your phone and the software on it. On top of that, iOS has a permissions architecture Apple designed to give the user second-class control over the network. You cannot MITM Apple services - they will go around whatever user-land profile you think you've set. On top of that, there are modem emissions that you're never going to catch with a MDM profile hack and certificate pinning. You have fully drank the kool-aid if you think an empty aircrack-ng screen means "you won" against the multitrillion dollar company and coalition of government regulatory bodies.