# Is it worth taking all the effort and struggle with the privacy friendly apps if I am using Apple devices?

**URL:** https://discuss.privacyguides.net/t/is-it-worth-taking-all-the-effort-and-struggle-with-the-privacy-friendly-apps-if-i-am-using-apple-devices/15909
**Category:** Questions
**Tags:** software
**Created:** 2023-12-29T11:10:27Z
**Posts:** 36

## Post 1 by @Tech-Trooper — 2023-12-29T11:10:27Z

Hi, all. I has always been a privacy and security enthusiast who follows and supports the development of open source and privacy friendly software such as the Proton Suite, Firefox, Brave, Bitwarden, Notesnook, ublock origin and etc. I even started blogging in my native language about the importance of these issues. Yet, I think I am experiencing an overwhelming exhaustion which I find very weird and funny to some extent that. I exactly know why I should not turn in myself to apple. Still the struggle comes to me futile nowadays.

Using these apps cost a significant inconvenience. And, most of the time, you experience some problems with these products. For instance, after the release of Proton Drive, I started to switch my backups from Icloud Drive to Proton, and it was very painful. I cannot completely use SimpleLogin, because there are so many sites blocking it during or after registration. These are just simple examples. Even though you pay for the products, you rarely find complete replacements, and you wont have the deeper integration with your OS and devices.

Instead of this hassle, I can use Safari, Icloud mail and drive, hide my email and other apple services. Most of them are E2EE, privacy friendly services, unlike Google or Microsoft products.

So, is it still worth the hassle and time I spend in the future resisting to use the alternatives? Is there anyone with similar feelings?

---

## Post 2 by @pinkandwhite — 2023-12-29T11:16:11Z

It just comes down to your personal threat model: are you okay with trusting Apple with the things you’ve listed? If yes, then there’s nothing wrong with it and you’re going to still have decent privacy from third parties that aren’t Apple. If your threat model is “big tech fuck off” then you should keep trying to use non-Apple services even if you are on Apple devices right now and migrate to non-Apple devices as your current devices get to be replaced.

---

## Post 3 by @anon58739604 — 2023-12-30T03:17:37Z

I know how you feel, this is called a burnout.

I don’t know what your threat model is, but if you trust Apple by all means use it.

But I still think looking into alternatives is a good thing, but you don’t always need to replace what you have if it works.

BTW, have you looked into digital minimalism? I don’t know your needs but this helped me a lot with my personal burnout. For example, for notes you could just use a notebook and for cloud backups use hard drives. It could also benefit your privacy.

---

## Post 4 by @anon21489307 — 2023-12-30T10:26:01Z

> [@Tech-Trooper](#):
>
> Using these apps [privacy-friendly apps] cost a significant inconvenience.

Don’t use all these apps all at once, especially if you’re inside an Apple ecosystem, which is pretty much a lockdown. You are better with trying one alternative at a time. Otherwise, it would be an overwhelming experience.

> [@Tech-Trooper](#):
>
> Most of them [Apple apps] are E2EE

IMO, this would be a misunderstanding, since there’s no source available, just claims. See [WhatsApp “end-to-end encrypted” messages aren’t that private after all - Ars Technica](https://arstechnica.com/gadgets/2021/09/whatsapp-end-to-end-encrypted-messages-arent-that-private-after-all/) for example.

The source should be available, so anyone can verify that their E2EE implementation is working correctly without any hole/backdoor. Otherwise, it’s worthless.

If it’s possible, even the OS should be open source. But it’s still worth using privacy-friendly apps regardless of the OS.

---

## Post 5 by @pinkandwhite — 2023-12-30T10:35:59Z

The misunderstanding would be assuming that you can’t verify things if you have no source. I haven’t read any articles claiming that [Apple’s explanation of how iMessage E2EE works](https://support.apple.com/en-au/guide/security/sec70e68c949/web) is not true; it would not be very hard to get a jailbroken device and hook into iMessage to trace whether it _is_ doing what it says it’s doing (at least for the on-device portion). Obviously open-source implementations like Signal are better because you don’t have to jump through any hoops beyond knowing basic coding and cybersecurity to verify things, but again, you don’t _need_ to see the source to do that verification.

---

## Post 6 by @Reset0609 — 2023-12-30T10:40:10Z

> [@Tech-Trooper](#):
>
> Using these apps cost a significant inconvenience.

In what sense? I suppose it will depend on your usage but by far the biggest inconvenience for me is vendor lock-in. Even if you nowadays use only Apple devices and can thus conveniently access all the data everywhere, you’re curtailing your freedom when it comes to device purchasing choices and setting yourself up for potentially painful forced migrations in the future whether you decide to continue buying Apple or not. Its not just Google that discontinues services or changes the conditions under which they are available

---

## Post 7 by @anon21489307 — 2023-12-30T10:41:04Z

> [@pinkandwhite](#):
>
> The misunderstanding would be assuming that you can’t verify things if you have no source.

No, you can’t verify anything without the source. For example, if the hidden code randomly applies to some devices? To some random period of time? Or to a specific individual? Etc.

> [@pinkandwhite](#):
>
> you don’t _need_ to see the source to do that verification.

For some obvious cases, yes. For any real verification, no.

> [@pinkandwhite](#):
>
> I haven’t read any articles claiming that [Apple’s explanation of how iMessage E2EE works](https://support.apple.com/en-au/guide/security/sec70e68c949/web) is not true

This proves nothing. No one knows. It’s like saying that only the one who got caught for stealing is a thief, so if the person can steal without getting caught, he/she is not a thief.

---

## Post 8 by @pinkandwhite — 2023-12-30T10:45:52Z

I think it’s important to criticise proprietary software with _accurate_ claims, not hypotheticals that lean into conspiracy territory. If your threat model requires being absolutely 110% sure there’s nothing there that’s malicious then yes, you take those hypotheticals into account and use FOSS software and do all the intense checking, but for the average person who isn’t a high-value target, it just ends up being more conspiratorial than anything and personally it makes it hard to support FOSS despite it being better overall.

All the claims of “hidden code that randomly applies” can happen with FOSS software, especially if it’s a large enough project. Someone nearly snuck a backdoor into Linux. It’s not an argument that uniquely applies to proprietary software.

PS: “they” is a wonderful pronoun you can use for people without the clunky “he/she”, it’s been in English for longer than anyone here has been alive

---

## Post 9 by @anon21489307 — 2023-12-30T10:57:37Z

> [@pinkandwhite](#):
>
> I think it’s important to criticise proprietary software with _accurate_ claims, not hypotheticals

It’s just a matter of _fact_ and one of differences between proprietary software and open source/source available software. It’s just that no one can claim for 100% that any proprietary software work the way they told. I didn’t say for 100% like you do that we can verify the apps without seeing the source. I did say that no one can ignore that possibility.

> [@pinkandwhite](#):
>
> All the claims of “hidden code that randomly applies” can happen with FOSS software

This is incorrect. Nothing can be hidden in a public FOSS repo. If it’s not found, yes.

> [@pinkandwhite](#):
>
> PS: “they” is a wonderful pronoun you can use for people without the clunky “he/she”, it’s been in English for longer than anyone here has been alive

Thank you teacher. Sorry, English is not my native language. I believe not all people alive here is a native English speaker. I will try better next time, by the way.

---

## Post 10 by @anon2844160 — 2023-12-30T14:45:41Z

> [@anon21489307](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/pinkandwhite/48/4525_2.png) pinkandwhite:
> 
> > All the claims of “hidden code that randomly applies” can happen with FOSS software
> 
> This is incorrect. Nothing can be hidden in a public FOSS repo. If it’s not found, yes.

Unfortunately much of the FOSS software is not checked by people who have suitable skills to detect malicious code. Also if you use a binary package you don’t know that what you have matches the source code (example the SourceForge disaster). IIRC The Atlantic Council even listed OSS as the 4th most significant threat to software security ( I assume because it is so easy to insert malicious code on collaborative projects). To be 100% safe you would need to have the skills to detect malicious code, then examine the app source code, each of the libraries it uses, and any other code sources it uses, then compile it on a compiler which you have also checked to be sure the compiler is not inserting malicious code. I don’t know anyone who has done this.

Personally I rely more on the reputation of the source of the binary than OSS or proprietary, though given the choice I prefer OSS.

---

## Post 11 by @Tech-Trooper — 2023-12-30T15:15:39Z

My threat model is just about evading mass surveillance, big tech, and supporting open source projects. I don’t see Apple as a threat personally. However, I really dislike the walled garden mentality, and want to support open source projects and community.

> [@anon58739604](#):
>
> I don’t know what your threat model is, but if you trust Apple by all means use it.
> 
> But I still think looking into alternatives is a good thing, but you don’t always need to replace what you have if it works

Do I trust Apple? I think they have a different business model than Google. Still, it can change over time, they can monetise our data, or when faced with legal hurdles, they won’t care so much about users. And it’s not open source, so we don’t really know the extent of their E2EE, or other privacy protections.  
But they add many privacy good features, hide my email, fingerprinting protections. Apple even brought profiles to safari on iOS, which other browsers do not have.

> [@anon58739604](#):
>
> BTW, have you looked into digital minimalism? I don’t know your needs but this helped me a lot with my personal burnout

Yes, I did. I actually remove apps from time to time, and minimise the number of notifications. Still, I need different software for personal and work purposes. So, a complete minimalism is really difficult for me. But thanks for the suggestion.

---

## Post 12 by @Reset0609 — 2023-12-30T15:31:32Z

> [@anon2844160](#):
>
> The Atlantic Council

Does not seem to be a very credible organization, looking at who’s funding them: [https://www.atlanticcouncil.org/about/donate/honor-roll-of-contributors-2019/](https://www.atlanticcouncil.org/about/donate/honor-roll-of-contributors-2019/)

Certainly you’re not expecting a big business lobbying group, one whose backers largely profit from closed-source software, to tell you that open-source is where its at..

Edit: one of the poorest countries in the world, Democratic Republic of Timor-Leste, apparently has made a sizeable donation to this organization. Oh, and ever heard of Ukrainian company Burisma? Theyre seemingly involved in that too ([Atlantic Council - InfluenceWatch - InfluenceWatch](https://www.influencewatch.org/non-profit/atlantic-council/)). Seems to be a platform to exchange political and business favors

---

## Post 13 by @anon58739604 — 2023-12-30T17:06:32Z

> [@Tech-Trooper](#):
>
> My threat model is just about evading mass surveillance, big tech, and supporting open source projects. I don’t see Apple as a threat personally. However, I really dislike the walled garden mentality, and want to support open source projects and community.

If you want to avoid big tech and you dislike the walled garden, I think you should move to something that fits what you like. Maybe like GrapheneOS or DivestOS which are both open source and are not walled gardens. If money is an issue, the best I can say is to check out alternatives if you like them.

> [@Tech-Trooper](#):
>
> Do I trust Apple? I think they have a different business model than Google. Still, it can change over time, they can monetise our data, or when faced with legal hurdles, they won’t care so much about users. And it’s not open source, so we don’t really know the extent of their E2EE, or other privacy protections.  
> But they add many privacy good features, hide my email, fingerprinting protections. Apple even brought profiles to safari on iOS, which other browsers do not have.

That is true, they do a lot more for privacy than things like Google. IMO, for the most sensitive stuff I would avoid iCloud email since they don’t encrypt their emails. The less info you give is better.

> [@Tech-Trooper](#):
>
> Yes, I did. I actually remove apps from time to time, and minimise the number of notifications. Still, I need different software for personal and work purposes. So, a complete minimalism is really difficult for me. But thanks for the suggestion.

That’s fair, digital minimalism isn’t for everyone, but it’s good you took some important steps of removing apps. Your’re welcome :slight_smile:

---

## Post 14 by @JibJab — 2023-12-31T21:50:23Z

When I get burned out trying to balance security, privacy and anonymity against usability, functionality and cost I say “This is good enough for now”.  
Then I submit more data broker opt-out requests☺

---

## Post 15 by @Tech-Trooper — 2024-01-01T10:34:41Z

> [@anon21489307](#):
>
> IMO, this would be a misunderstanding, since there’s no source available, just claims. See [WhatsApp “end-to-end encrypted” messages aren’t that private after all | Ars Technica](https://arstechnica.com/gadgets/2021/09/whatsapp-end-to-end-encrypted-messages-arent-that-private-after-all/) for example.

Even though I dislike Meta and Whatsapp, this is not meaning that E2EE is broken. If a message is reported by users, then it is shared with moderators. It is an issue of privacy, not security. In a rare statement, Signal [supported](https://signal.org/blog/there-is-no-whatsapp-backdoor/) Whatsapp. There is no need for FUD. I did not delve deeper into this subject, but if they break E2EE, we should have seen them appearing in courts.

Moreover, if you are using the OS, all data can be already collected from your keyboard, other means. I wish everything could be open source. I tried GrapheneOS in my hobby phone, but I don’t feel ready for the switch.

> [@Reset0609](#):
>
> In what sense? I suppose it will depend on your usage but by far the biggest inconvenience for me is vendor lock-in.

That’s the problem. Now, apple devices are the best choice for me. If I start to use grapheneOS one day, I can switch many services. In one day, I can move all my files, photos and other stuff, so I am not completely dependent. The only difficult part maybe aliases, still it is not a big deal.

> [@JibJab](#):
>
> Then I submit more data broker opt-out requests

Yeah, but we don’t know to what extent they comply with.

---

## Post 16 by @pinkandwhite — 2024-01-01T12:38:17Z

What the “whatsapp backdoor!!!1!!1” is in this case is actually the fact that users can report messages to Meta and those messages get saved to the user’s device then sent to Meta’s moderators to evaluate. Very scary and backdoor, I know.

---

## Post 17 by @anon21489307 — 2024-01-01T20:52:26Z

> [@Tech-Trooper](#):
>
> this is not meaning that [WhatsApp] E2EE is broken.

It’s literally broken, as there’s also unencrypted metadata AKA PMPs attached to the user’s encrypted message, in which **this metadata is visible to Facebook—and to law enforcement authorities or others that Facebook decides to share it with** , as stated in the article.

> [@Tech-Trooper](#):
>
> if they break E2EE, we should have seen them appearing in courts.

As stated in the article:

> Since the pen orders and their results are frequently sealed [by the court], it’s also difficult to say exactly what metadata the company has turned over… we don’t know exactly what metadata is present in these PMPs, we do know it’s highly valuable to law enforcement.

Basically, no one knows the metadata content that was shared, whether it included even the messages’ encryption key, etc.

My point is that if we can’t possibly _verify_ how their E2EE implementation works, as we don’t see the source of the app, we can’t assume that it’s actual E2EE as it’s supposed to be. Perhaps, there’s a switch to turn off the target’s E2EE, etc. We just don’t know. All we know for sure is WhatsApp’s E2EE is useless and shouldn’t be considered as anything more than one’s peace of mind.

* * *

> [@pinkandwhite](#):
>
> the fact that users can report messages to Meta and those messages get saved to the user’s device then sent to Meta’s moderators to evaluate.

Yes, according to what everyone was told :sweat_smile:

Edit: Oh, I almost forget that this point is stated in the article also:

> Although nothing indicates that Facebook currently collects user messages _without_ manual intervention by the recipient, **it’s worth pointing out that there is no technical reason it could not do so.**

---

## Post 18 by @pinkandwhite — 2024-01-01T22:48:21Z

There is no technical reason why I couldn’t just steal $3 million in cryptocurrency from a random schmuck but that doesn’t mean I’m going to risk doing it. Besides, the metadata is the most important commodity for governments and LE, and that isn’t protected with Wapp so why go through all the trouble of adding automated message sharing when having actual proof of such would be even worse for their reputation than all the FUD for not much gain at all.

---

## Post 19 by @anon21489307 — 2024-01-01T22:57:18Z

> [@pinkandwhite](#):
>
> There is no technical reason why I couldn’t just steal $3 million in cryptocurrency from a random schmuck

Whether they could have done that, or for why they did or didn’t do that to any person, is another point entirely and doesn’t relevant to this conversation regarding WhatsApp’s E2EE.

If you have anything related to the topic to discuss (WhatsApp’s E2EE implementation), please say so. Otherwise, please don’t derail the topic further.

---

## Post 20 by @pinkandwhite — 2024-01-01T23:02:04Z

Just because you don’t like someone challenging your “PROPRIETARY IS THE DEVIL 666” take doesn’t mean I’m derailing the topic. My absurd example is directly related to the matter at hand – why would Meta do something that would hurt their reputation further (and thus their bottom line) when the alternative is to lull people into a false sense of security using an E2EE app that doesn’t protect metadata. Signal seems to think it’s important to argue with the facts, they’ve defended Wapp in the past with regards to prior FUD around the encryption used (someone linked the article further up in the thread)

---

## Post 21 by @anon21489307 — 2024-01-01T23:29:33Z

> [@pinkandwhite](#):
>
> Just because you don’t like someone challenging your “PROPRIETARY IS THE DEVIL 666”

Why would you assume I hate challenges? And why would you assume I think proprietary is the devil?

In fact, I support the use of many proprietary related software if I deem it’s appropriate in my eyes. For example, I would use Chrome over Firefox (if there’s no Brave), or I would use official Snap apps over unofficial Flatpak apps. But that’s not related to the matter of this topic.

I am simply stating the _fact_ regarding the situation of WhatsApp’s E2EE, which you seem to fail to counter reasonably.

> [@pinkandwhite](#):
>
> My absurd example is directly related to the matter at hand

No, it isn’t. Becuase…

> [@pinkandwhite](#):
>
> why would Meta do something that would hurt their reputation

You are not Meta. Therefore, you can’t assume for them.

However, everyone here can think of the possibility of something happening, not saying it will happen for 100%. It’s just nobody knows. But it seems you always assume otherwise. Believing everything they told you? Without any curiosity?

> [@pinkandwhite](#):
>
> Signal seems to think it’s important to argue with the facts,

Did they know all the facts inside out of Meta/WhatsApp operations and government orders?

From my point of view regarding Signal’s article, they just wanted to protect their protocol, which WhatsApp is using. And there’s nothing wrong about it. They just needed to do their things. But the fact as stated in the article is only one part of the whole story. For one, I don’t see they talked about the metadata. Interestingly, the article ended with:

> We believe that WhatsApp remains a great choice for users concerned with the privacy of their message content.

Yes, the great choice for privacy concerned users. Maybe, they should tell that to Natalie Edwards, who somehow got caught because WhatsApp’s E2EE didn’t work as intended, in which all the evidences used in the case, which were leaked by the system, are still unknown to the public.

---

## Post 22 by @JibJab — 2024-01-03T01:05:25Z

I’m just a single data point and anecdotal at that but searching for myself indicates they are honoring my opt-out requests. For how long? Who knows. Friends and relatives have searched for me using various engines and they get no results. Currently, Google Search Services have been rummaging around for two weeks and only finding very obscure posts from a job related site from 2005.

---

## Post 24 by @SYST3M_D3STR0YER — 2026-02-01T20:12:35Z

> [@anon2844160](#):
>
> Unfortunately much of the FOSS software is not checked by people who have suitable skills to detect malicious code. Also if you use a binary package you don’t know that what you have matches the source code (example the SourceForge disaster).

Yes, but since you can compile the source code and check whether that matches the binary (which is 100% impossible with proprietary software), it is much much easier to detect malicious code. Yes, free software isn‘t perfect, but it‘s much much better than proprietary software.

---

## Post 25 by @KathyM — 2026-02-01T21:01:19Z

Correct me if I am wrong but the only thing Apple doesn’t EE encrypt via Advanced Data Protection is contact, calendar, and email.

We can be reasonably certain that Apple isn’t bs with their recent hubbub regarding disabling ADP for the United Kingdom, then the UK gov backing off of that move.

Covering the holes Apple can’t end to end encrypt can be done with proton? For your phones contacts, limit info to just phone numbers. Expanded contact info in proton contacts. Use proton calendar and email.

---

## Post 26 by @SYST3M_D3STR0YER — 2026-02-02T07:36:43Z

I don‘t really think Apple takes the privacy of the users serious. My personal opinion is that they just make it look from the outside as best as they can that they care about the privacy and security of the users.

> **[Spying - Reasons not to use Apple](https://stallman.org/apple.html#spying)**
>
> For current political commentary, see the daily political notes.

One example from that link:

> Apple [left a security hole in iTunes unfixed for 3 years](https://stallman.org/archives/2011-nov-feb.html#28_November_2011_%28Apple_iTunes_Government_Spying%29) after being informed about the problem. During that time, governments used that security hole to invade people’s computers.

---

## Post 27 by @anon80329175 — 2026-02-02T07:42:09Z

The Stallman website linked has info written awhile ago. Do we know if all of what’s in it about Apple is still true today?

---

## Post 28 by @SYST3M_D3STR0YER — 2026-02-02T07:46:06Z

? All sources are linked you can check

---

## Post 29 by @anon80329175 — 2026-02-02T07:50:12Z

I did. And that’s why I replied to you.

Many links are linking to pages that are many years old now. Hence my skepticism of all the claims made. Sure, it does appear to be be true at one point. But I am also trying to figure out if its gotten better or worse and because all info is many years old now, it’s hard to say without diving deep into each claim and piece of info and updating it.

---

## Post 30 by @KathyM — 2026-02-02T12:18:40Z

I’m going to need a more persistent pattern than a security fuckup from more than a decade ago.

Since we don’t know anything, it’s possible that intelligence services pressured :red_apple: to leave the vulnerability open. It’s pre-Snowden when Gov could walk up to companies, say that there’s a terrorist only said company can help stop, and national security letter a few employees. Since then every company knows that it’s every company getting a NSL and now cooperation is a lot more strategic/political.

Or that it was sent to iTunes team to patch, they threw a hissy fit about their deadlines, security was told to fix other pressing bugs, finally the story got noticed by an executive who walked downstairs. And that gap in handling of security bug reports was fixed.

---

## Post 31 by @SYST3M_D3STR0YER — 2026-02-03T13:25:58Z

> [@KathyM](#):
>
> I’m going to need a more persistent pattern than a security fuckup from more than a decade ago.
> 
> Since we don’t know anything, it’s possible that intelligence services pressured :red_apple: to leave the vulnerability open. It’s pre-Snowden when Gov could walk up to companies, say that there’s a terrorist only said company can help stop, and national security letter a few employees. Since then every company knows that it’s every company getting a NSL and now cooperation is a lot more strategic/political.
> 
> Or that it was sent to iTunes team to patch, they threw a hissy fit about their deadlines, security was told to fix other pressing bugs, finally the story got noticed by an executive who walked downstairs. And that gap in handling of security bug reports was fixed.

> [@anon80329175](#):
>
> Many links are linking to pages that are many years old now. Hence my skepticism of all the claims made. Sure, it does appear to be be true at one point. But I am also trying to figure out if its gotten better or worse and because all info is many years old now, it’s hard to say without diving deep into each claim and piece of info and updating it.

I have to admit, that‘s a fair point regarding that argument.

Apple still asks for the address of the person setting up an Apple-ID (_and they don’t need it, they are not going to send you a letter_).

And of course, any privacy promise from Apple is not verifiable because everything is closed-source.

---

## Post 32 by @KathyM — 2026-02-04T16:32:21Z

An address helps them address legal liability. We’re entering a balkanization of privacy rights, where your address determines what a company is liable for.

---

## Post 33 by @SYST3M_D3STR0YER — 2026-02-04T19:39:49Z

I am not 100 % sure on this since I don‘t have a Google account, but Google doesn‘t asks for an address, doesn‘t it?

_ **If** _ that is true, then Apple is asking for more information than necessary which is a privacy problem.

---

## Post 34 by @KathyM — 2026-02-05T02:10:48Z

Being a data broker company, Google would rather not know your address so they can treat you like an American.

I can’t locate a public explanation from Apple but the best guesses I’ve seen is for sales tax or some apps are geo restricted.

---

## Post 35 by @anonymous550 — 2026-02-05T03:26:42Z

Yes, because eventually you’ll switch to Linux where those tools will pay off. :wink: In this spirit, ensure the apps have cross-platform compatibility!

---

## Post 36 by @SYST3M_D3STR0YER — 2026-02-05T07:01:41Z

> [@KathyM](#):
>
> Being a data broker company, Google would rather not know your address so they can treat you like an American.

Come on, you know yourself that this is illegal and that Google _of course does not do this_, right?

> [@KathyM](#):
>
> I can’t locate a public explanation from Apple but the best guesses I’ve seen is for sales tax or some apps are geo restricted.

Then IP address would be a much more reliable source for that :sweat_smile:
