zlacker

[return to "Everyone knows all the apps on your phone"]
1. andsoi+Qg[view] [source] 2025-03-30 00:11:51
>>gnitin+(OP)
> everyone knows all the alls on your phone

On Android phones. iPhone doesn’t have this privacy deficiency.

◧◩
2. wkat42+Cx[view] [source] 2025-03-30 03:14:04
>>andsoi+Qg
On iOS it's kinda worse in some ways. If you enroll into a company MDM they can see all your apps.

On Android if they use the work profile (which is the standard method these days) they can only see the apps inside there.

◧◩◪
3. mgriep+TF[view] [source] 2025-03-30 04:56:06
>>wkat42+Cx
Apple introduced account-driven enrollments in 2021[1], which behaves similar to Android's work profile. Managed apps/data are kept in its own APFS volume, and MDM servers don't have access to anything outside of it. They also disallow system-wide commands like wipe device. The only caveat is you need managed Apple IDs[2] to use this enrollment flow, and I doubt many companies have set it up.

Regardless, MDM installed app visibility is limited to those users who opt-in to an organization managing their personal device, and isn't an effective way to broadly gather what apps a given person has installed. What's described in this post would work on any user/device, and there's no way to deny/opt-out of specific permissions.

[1] https://developer.apple.com/videos/play/wwdc2021/10136/ [2] https://support.apple.com/guide/apple-business-manager/use-m...

◧◩◪◨
4. whs+tY[view] [source] 2025-03-30 09:02:51
>>mgriep+TF
I'm working on implementing this for the company, and the annoying limitations on iOS is that you can't clone apps. If you want Gmail (as an example) as managed app, you can't have another Gmail as unmanaged app. While the company can't see inside the Gmail managed app (without the app itself explicitly providing that feature), the company can remove Gmail (and any local data inside the app) at any time.

Fun fact from the MDM implementation - the most private way (at least to the company policies) to have a company-connected device is to buy a separate phone and install company's MDM on it. On company provided devices, the company may locate company's assets at any time but doing so on a personal device is a privacy breach.

[go to top]