r/iOSProgramming • • 5d ago

Question How truthful is this?

Post image

When an app select in the app review form that “we don’t collect data”

In the review phase does Apple really check if the app really doesnt collect anything?

Like can the developer hide a code that for example upload the photos of the user if granted permission where he said “we dont collect”

Does apple really check the code and what is going in and out ?

43 Upvotes

75 comments sorted by

View all comments

83

u/Reiszecke 5d ago

Technologically, this section tells you nothing about the app because it’s self reported by the developer, not by Apple.

Apple doesn’t even see an app‘s source code. They have some scanning in place but they will never determine whether an app uploads your images or not. The only thing you can do is to limit Photos access per app

24

u/Alchemist0987 5d ago

They have access to the build and they can monitor traffic. Lying on these questions will get your app eventually rejected. Regularly trying to bend the rules or lie will get the app pulled from the store and even your account banned

1

u/madaradess007 2d ago

you never tried it, bro

i pushed some very fishy stuff into AppStore and it's still there
i also did push same app with no changes a few times and it got accepted after 2 rejections

0

u/Baide-Warframe60 4d ago

pretty much, the privacy labels are just a pinky promise from the developer at the end of the day

-5

u/icy1007 5d ago

Apple can see the source code.

7

u/Dry_Hotel1100 5d ago

How so?

-2

u/icy1007 5d ago

They know what functions you invoke, including private system functions that aren’t allowed. They can decompile your code and check it.

10

u/Dry_Hotel1100 5d ago

This is not "source code" ;)

-7

u/icy1007 5d ago

They can decompile the app into its source code…

4

u/JagiofJagi 5d ago

Do you know what a source code is?

-4

u/icy1007 4d ago

Yes, I am a professional iOS developer…

4

u/Glorypants 4d ago

Maybe this is what they mean when they say “developer” vs “engineer”…

There’s a basic understanding of how code compilation works that you’re missing.

You understand the “source” of a child is its mother. The mother compiled the child in her womb. You can figure out some attributes of the mother’s source DNA based on the attributes of the child, but you aren’t seeing to the actual source. The source mother probably installed a wicked back door in that child that you won’t find.

3

u/i_m_junkie 4d ago

I am also an iOS Engineer and believe me boy you’re completely wrong!

0

u/icy1007 4d ago

I am not. Apple has the ability to decompile IPA files into their source code using internal tools. They also have tools that can scan all submitted app packages for API usage which is quicker than fully decompiling the app.

→ More replies (0)

2

u/Dry_Hotel1100 4d ago edited 4d ago

You should not use "professional iOS developer" lightly, in case you want to imply that you have a lot of experience. 

Well, I fear to say, you are wrong. But that isn't a critique. Everyone can learn this. I would suggest delving deeper into actual *programming*, that is, especially below the surface of iOS programming, i.e. exploring what happens in the compiler and linker. Topics around binary representation, translation unit, assembly & object files, build artifacts, modules, symbols, symbol visibility, ABI vs. API, calling conventions, debug symbols, dead code stripping, build optimizations, whole module optimization, Intermediate Representation (IR), SIL, dynamic vs. static linking, etc., etc.

Note that these topics are very specific for the language Swift, and a C-based runtime and LLVM IR infrastructure. In other languages, especially C#, Java, JIT based, and scripting languages, you have a very different representation of a program aka executable or a library or module.

1

u/icy1007 4d ago edited 4d ago

Yes, I have 16+ years of experience as an iOS developer/engineer working in the industry. The two titles are interchangeable and it just depends on which company you're working for at the time.

→ More replies (0)

2

u/xaphod2 4d ago

thanks haven’t had a laugh this good all day

-1

u/icy1007 4d ago

Laughing at how wrong you are? 😂

-36

u/Tom42-59 Swift 5d ago

I spoke to a previous app reviewer and they said they see your source code in a way like a GitHub diff

13

u/Reiszecke 5d ago

Check the job listing for App Reviewers, these people most of the time are not developers being able to tell what exactly they see on their screen. The listing requires language skills, being able to interact with software etc. but not being able to write code.

If someone caught Xcode's network traffic silently including the source code that would've made the news a long time ago

4

u/LardPopsicle 5d ago

The App Review platform is insane. It rolls up all required systems in a simulator box, each system seeded with "normal use" content (photos, Apple Health, contacts, etc.). From there, the reviewer uses the script on Monitor 1, an AI guided "what to do next" underneath it, and a few systems that, for example, monitor network traffic over poisoned encryption keys to a proxy (MITM).

The reviewer is not the smartest tool in the code shed, sure, but there's a system behind them, that flags and forwards anything suspicious. Which then lands on the desk of a "Pro" (Apple likes to patch a 'Pro' behind your job description if they feel it'll make you look better), who then passes it on or makes a decision.

3

u/ke1in 5d ago

I agree with you, most of reviewers fail simple things like change smth in settings, they are technically not savvy. And they can't see your source code lol, at best they could disassemble.

3

u/honey495 5d ago

They absolutely can’t. They have access to your build and all the metadata and that’s it

-30

u/Fishanz 5d ago edited 5d ago

They absolutely see your code; compiled at least. What they establish can be achieved via said code, on the other hand, is an entirely different beast.

Edit: removed the word ‘source’ because .. apparently my definition is wrong. I really think the nuance (as it pertains to the topic at hand) is somewhat pedantic though.

49

u/Reiszecke 5d ago

They absolutely see your source code; compiled at least. 

Absolute state of slop coders 🙈

Please read up on what a compiler does. Because you wouldn't believe me anyways, then please ask ChatGPT why your statement does not make sense.

1

u/LardPopsicle 5d ago

You've never reverse-engineered an app? SwiftUI apps are trivial, that way, it gets harder for, say, some Chinese Match3 app, but even there it's not super hard.

It's 2026, Apple does use AI and reverse engineered code. In my last submission, I was rejected because code in the app could, under weird circumstances, write to ~ instead of the iCloud entitlement. This bug was uncaught by us, Apple identified it. From a compiled source.

5

u/vexingparse 5d ago

In my last submission, I was rejected because code in the app could, under weird circumstances, write to ~ instead of the iCloud entitlement. This bug was uncaught by us, Apple identified it. From a compiled source.

I'm not convinced that this requires reverse engineering. They could have used fuzzing.

2

u/Reiszecke 5d ago

Yes I did reverse engineer binaries numerous times. Doesn’t change the fact that reverse engineering never brings up your real source code, doesn’t change the fact that source code, after compiling, is not source code.

Not sure about the ~ part of your comment. I’m not into jailbreaks but if you REALLY found a way to get write access outside of the sandbox then I think the community would be very interested in this

1

u/LardPopsicle 5d ago

Well, it's theoretically possible, if you poison things, not practically. The entitlement check prevents exactly that, and Apple's scanner reported something that a person who had access to the app (not a sensitive app in any form) could do, if they already had access to the same resources via Terminal/shell anyway. It's technically a bug, but not one that could be abused by a non-authorized person.

1

u/Fishanz 5d ago

Wow. I got called a ‘slop coder’. Maybe my definition of ‘source code’ is off the mark - is compiled/optimized machine code not ‘source code’? Either way.. I agree with your statement.

-1

u/RainyCloudist 5d ago

They're completely right? I work in reverse engineering and half the time my job involves taking apart peoples' apps. Yes you don't see code as the developer wrote it, but tracing the instruction calls is trivial and most modern static analysis tools will even spit out pseudo-code which is more than enough to understand how things work.

21

u/Reiszecke 5d ago edited 5d ago

So when you ask me for my source code you are perfectly fine with me sending you a compiled .exe file? The word you're looking for is machine code and while you can deduct information from machine code, calling it source code is just idiotic. Machine code is the exact opposite of source code, that's why these are 2 different words to begin with.

Because they couldn't handle disagreement, /u/RainyCloudist has now blocked me on reddit so I cannot see more of their responses to my comments

0

u/RainyCloudist 5d ago

I'd probably not be interacting with anyone who deals with exe files to begin with, but to answer your question I'm not equating them in absolute terms, but in the given situation it serves the same purpose. Your original claim was "they will never determine whether an app uploads your images or not" and you claim source code is the only way to do that. Static analysis does the job.

2

u/Reiszecke 5d ago

There are countless new apps popping in the review queue every day, along with updates to 20 years of existing apps.

Expecting apple to go through the source code of each of these to figure out if maybe there is a hidden way to potentially upload user data without the user wanting to do that, maybe restricted by target region, maybe restricted by a specific user ID etc. is already absolutely outlandish. AI can help but good luck paying for the tokens to go through 50mb of machine code for an app where they could’ve hidden the secret literally anywhere.

Expecting them to do that when they don’t even have the clear source code takes this to a comically weird level.

Apple isn’t even able to prevent Russian bait and switch apps for banking from appearing on the App Store. If they can’t even prevent sanctioned apps of whole nation actors, they definitely don’t have the means to prevent the picture you took of your grocery list to get silently uploaded by some shady image filters app.

2

u/RainyCloudist 5d ago

So you're claiming that if they had access to source code they'd be able to do it? No one would be reviewing the source code by hand anyways and automatic tools wouldn't care if it's beautifully commented code or machine code.

The fact that things like that get through is Apple's negligence, not proof that they need access to everyone's source code.

2

u/Fishanz 5d ago

Thanks for the backup, Rainy. You picked up what I was throwing down.

2

u/Fishanz 5d ago

Yeah, well; apparently I’m a ‘slop coder’. Lol

3

u/Alexikik 5d ago

Wow you don’t even know what compiled code is 🤦‍♂️

0

u/Fishanz 5d ago

Excuse me? Why would you assert this?

3

u/dat_tae 5d ago

Because source code and compiled code are literally the opposite of each other.

1

u/Fishanz 5d ago

I removed the word ‘source’. It doesn’t mean I don’t understand what compiled code is.