Home Privacy Apple WWDC 2022: No Privacy Bombshells, But The Writing’s On The Wall For Fingerprinting

Apple WWDC 2022: No Privacy Bombshells, But The Writing’s On The Wall For Fingerprinting

SHARE:
Apple didn't mention fingerprinting at WWDC on Monday, as many expected – but that doesn’t mean enforcement isn’t coming at some point soon … ish.

There was no mention of fingerprinting (or any allusions to a forthcoming crackdown on the practice) during the kickoff keynote at Apple’s Worldwide Developers Conference on Monday, as many expected – but that doesn’t mean enforcement isn’t coming at some point soon … ish.

Apple has already been crystal clear that, without a user’s permission through ATT, device fingerprinting on iOS is as kosher as pig feet in matzah ball soup.

Although that hasn’t stopped companies from engaging in fingerprinting like it’s going out of style (which it is). And that begs the question: Why hasn’t Apple clamped down yet?

One reason is because enforcement is tricky.

Sticky fingers

As Eric Seufert has pointed out, ad tech and measurement companies fingerprint users and devices based on data collected through their SDKs, which developers integrate directly into their apps.

This means policing fingerprinting could result in serious collateral damage. Apple would have to reject updates from any app partnered with an SDK deemed to be in violation of the policies. (When Apple started rejecting apps with Adjust’s SDK last year for alleged fingerprinting, the result was a confusing mess, to say the least.)

And so the quandary remains: Apple is categorically anti-fingerprinting and yet doesn’t have an elegant enforcement method to actually prevent the practice.

Maybe Google has the answer. There’s nothing stopping Apple from devising (and/or cribbing) a technical solution for an upcoming version of iOS inspired by the SDK Runtime in Google’s Android Privacy Sandbox. This feature could allow third-party SDKs to run in a separate environment, making it impossible for one to access and share data without permission.

A solution like SDK Runtime, which is set for release as part of Android 13, would allow apps to release updates even if their SDK partners are having privacy problems.

It’s a marathon not a (Private) Relay race

Subscribe

AdExchanger Daily

Get our editors’ roundup delivered to your inbox every weekday.

On reflection, it’s hardly surprising that Apple didn’t dwell on third-party data collection and ad tracking at WWDC this year.

At this point, there’s no doubt as to where the company stands, and it wouldn’t be out of character for Apple to begin fingerprinting enforcement at any time. The company doesn’t need a WWDC announcement.

Still, for the past two years, Apple has trained the mobile ad tech community to a Pavlovian response every time Craig Federighi, SVP of software engineering, looks the camera dead in the eye at WWDC and utters the words “Let’s talk about privacy.”

In 2020, those words were a prelude to the AppTrackingTransparency framework and Apple’s announcement that developers would be required to ask for explicit permission before using the IDFA for tracking and ad targeting starting with iOS 14.

The following year, in 2021, Apple announced Private Relay, a beta feature in iOS 15 that masks the IP address of any iCloud+ customers using Safari as their browser. An IP address is one of the main ingredients used to create a device fingerprint.

It’s unclear whether Apple plans to turn on Private Relay by default in iOS 16, as some have predicted. For now, the feature remains disabled by default and available only to people who pay for Apple’s upgraded iCloud subscription service.

In other news, the lack of privacy-related bombshells at WWDC may have been a minor boost to some tech stocks that are still reeling from Apple’s past privacy changes. Meta, Snap and Pinterest were all up a smidge Monday afternoon during and following Apple’s presentation.

Must Read

Readers Are Flocking To Political News, Says WaPo – And Advertisers Are Missing Out

During certain periods this year, advertisers blocked more than 40% of The Washington Post’s inventory over brand safety concerns.

Monopoly Man looks on at the DOJ vs. Google ad tech antitrust trial (comic).

Spicy Quotes You’ll Be Quoting From The Google Ad Tech Antitrust Trial

A lot has already been said and cited during the Google ad tech antitrust trial, with more to come. Here are a few of the most notable quotables from the first two weeks.

The FTC's latest staff report has strong message for social media and streaming video platforms: Stop engaging in the "vast surveillance" of consumers.

FTC Denounces Social Media And Video Streaming Platforms For ‘Privacy-Invasive’ Data Practices

The FTC’s latest staff report has strong message for social media and streaming video platforms: Stop engaging in the “vast surveillance” of consumers.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

Publishers Feel Seen At The Google Ad Tech Antitrust Trial

Publishers were encouraged to see the DOJ highlight Google’s stranglehold on the ad server market and its attempts to weaken header bidding.

Albert Thompson, Managing Director, Digital at Walton Isaacson

To Cure What Ails Digital Advertising, Marketers And Publishers Must Get Back To Basics

Albert Thompson, a buy-side veteran with 20+ years of experience, weighs in on attention metrics, the value of MFA sites, brand safety backlash and how publishers can improve their inventory.

A comic depiction of Google's ad machine sucking money out of a publisher.

DOJ vs. Google, Day Five Rewind: Prebid Reality Check, Unfair Rev Share And Jedi Blue (Sorta)

Someone will eventually need to make a Netflix-style documentary about the Google ad tech antitrust trial happening in Virginia. (And can we call it “You’ve Been Ad Served?”)