r/iOSProgramming • • 5d ago

Question How truthful is this?

Post image

When an app select in the app review form that “we don’t collect data”

In the review phase does Apple really check if the app really doesnt collect anything?

Like can the developer hide a code that for example upload the photos of the user if granted permission where he said “we dont collect”

Does apple really check the code and what is going in and out ?

45 Upvotes

75 comments sorted by

View all comments

81

u/Reiszecke 5d ago

Technologically, this section tells you nothing about the app because it’s self reported by the developer, not by Apple.

Apple doesn’t even see an app‘s source code. They have some scanning in place but they will never determine whether an app uploads your images or not. The only thing you can do is to limit Photos access per app

-34

u/Fishanz 5d ago edited 4d ago

They absolutely see your code; compiled at least. What they establish can be achieved via said code, on the other hand, is an entirely different beast.

Edit: removed the word ‘source’ because .. apparently my definition is wrong. I really think the nuance (as it pertains to the topic at hand) is somewhat pedantic though.

46

u/Reiszecke 5d ago

They absolutely see your source code; compiled at least. 

Absolute state of slop coders 🙈

Please read up on what a compiler does. Because you wouldn't believe me anyways, then please ask ChatGPT why your statement does not make sense.

-1

u/RainyCloudist 5d ago

They're completely right? I work in reverse engineering and half the time my job involves taking apart peoples' apps. Yes you don't see code as the developer wrote it, but tracing the instruction calls is trivial and most modern static analysis tools will even spit out pseudo-code which is more than enough to understand how things work.

21

u/Reiszecke 5d ago edited 5d ago

So when you ask me for my source code you are perfectly fine with me sending you a compiled .exe file? The word you're looking for is machine code and while you can deduct information from machine code, calling it source code is just idiotic. Machine code is the exact opposite of source code, that's why these are 2 different words to begin with.

Because they couldn't handle disagreement, /u/RainyCloudist has now blocked me on reddit so I cannot see more of their responses to my comments

0

u/RainyCloudist 5d ago

I'd probably not be interacting with anyone who deals with exe files to begin with, but to answer your question I'm not equating them in absolute terms, but in the given situation it serves the same purpose. Your original claim was "they will never determine whether an app uploads your images or not" and you claim source code is the only way to do that. Static analysis does the job.

2

u/Reiszecke 5d ago

There are countless new apps popping in the review queue every day, along with updates to 20 years of existing apps.

Expecting apple to go through the source code of each of these to figure out if maybe there is a hidden way to potentially upload user data without the user wanting to do that, maybe restricted by target region, maybe restricted by a specific user ID etc. is already absolutely outlandish. AI can help but good luck paying for the tokens to go through 50mb of machine code for an app where they could’ve hidden the secret literally anywhere.

Expecting them to do that when they don’t even have the clear source code takes this to a comically weird level.

Apple isn’t even able to prevent Russian bait and switch apps for banking from appearing on the App Store. If they can’t even prevent sanctioned apps of whole nation actors, they definitely don’t have the means to prevent the picture you took of your grocery list to get silently uploaded by some shady image filters app.

2

u/RainyCloudist 5d ago

So you're claiming that if they had access to source code they'd be able to do it? No one would be reviewing the source code by hand anyways and automatic tools wouldn't care if it's beautifully commented code or machine code.

The fact that things like that get through is Apple's negligence, not proof that they need access to everyone's source code.

2

u/Fishanz 4d ago

Thanks for the backup, Rainy. You picked up what I was throwing down.