11 ms·
Our Approach to Privacy
- phoe-krk 9y agoSo a cop can put your phone in front of your face while you're tied up and unable to do a thing. Boom, phone unlocked. Marvelous.
- laken 9y agoCouldn't the same be said for a fingerprint too?
- intopieces 9y agoiOS 11 allows you to disable touch or face ID by pressing the power button 5 times.
- jobvandervoort 9y agoThey changed this for the iPhone X: you press the lock and one of the volume buttons at the same time.
- schrodinger 9y agoThat's awesome. I wonder if cops could construe that into an "obstruction of justice" (or similar) offense?
- intopieces 9y agoOnly if they have a warrant for the search at the time you do it. Else, the device is not part of an active investigation.
- R4nger 9y agoAFAIK if you keep your eyes closed, it doesn't unlock. Also, its still an improvement from when cops borrow your thumb. At least this way, you have less chance of getting hurt.
- megous 9y agoI'd rather lose my finger than my head, thank you.
- marter 9y agoYou are the first person to ever think of this! Congratulations. This place is becoming reddit.
- mamp 9y agoYou can disable Face ID by pressing the power and volume buttons at the same time. They are on either side of the phone. Faster than the multiple press method and more discrete.
- jwilcoxson 9y agoYou always have a choice to not buy an iPhone X, or if you do, not use Face ID.
- jafingi 9y agoAnd they would also have access to your fingerprint then. What difference would it make??
- GeekyBear 9y agoIn either case, they would have to get a warrant first. Once they have that warrant, it doesn't matter what biometric locking method you use.
- have_faith 9y agoIf you think it's a security risk, then don't enable. It's pretty simple. It's very transparent about how it works.
- mtgx 9y ago> While we do back up iMessage and SMS messages for your convenience using iCloud Backup, you can turn it off whenever you want. Wouldn't they be able to hold that privacy promise much better if they actually allowed people to keep iCloud backup on let's say for pictures, but still be able to disable iMessage messages? I think many people would like to use iCloud but without it backing up personal conversations, too. Also, iMessage's end-to-end encryption was rather flawed last Matthew Green checked, compared to other end-to-end messaging apps. https://blog.cryptographyengineering.com/2016/03/21/attack-of-week-apple-imessage/ https://blog.cryptographyengineering.com/2016/03/21/attack-o... As for their use of differential privacy, when they introduced that it was essentially a hidden way of gather more of your data than before, not less, but while still being able to say "hey, we may gather more data than ever on you starting with the new iOS, but it's pretty private, so it's cool, don't worry about it". All of that said, I know Apple is still miles ahead of Google on privacy. If anything, over the last 1-2 years, Google has become increasingly bolder and more shameless about tracking users without them realizing (except in the EU, where they are forced to make it a little easier for users to understand how they are being tracked, and even that happened because of the anti-trust lawsuit). Here's just one example of Google's increasingly privacy-hostile behavior: https://www.extremetech.com/internet/238093-google-quietly-changed-its-privacy-policy-no-longer-promises-to-anonymize-your-personal-information-when-selling-ads https://www.extremetech.com/internet/238093-google-quietly-c...
- dangsdad 9y agotldr. Apple:securly sharing your most intimate secrets with the worlds 7.5billion people. Suppose its better than M$ or Google insecurely sharing them. But not as good as just not handing them out in the first place.
- matt4077 9y agoDifferential privacy is obviously worse for privacy than absolute privacy. But the latter is simply to restrictive and would preclude Apple from applying the benefits of machine learning to their users' benefit. I think, for example, what Apple is doing in health has some awesome potential. Also animated shit emojis! But "differential privacy" has a specific meaning that isn't just "sharing less data". It's trying to find provable methods to get the aggregate data needed for ML without exposing any single user's data. Kinda like the big data version of having one random soldier with a blank in his rifle in any firing squad.
- aub3bhat 9y agoOn Android you can Sideload VPN apps, iOS on the otherhand banned them in China. Apple mounted the most successful attack on General Computing with it's walled garden. The whole Apple is good for privacy is marketing.
- 3825 9y agoSorry for the silly question. I don't own a mac or an iPhone anymore. My understanding is you can sideload apps on your own iPhone from your own mac running xcode. Are there limitations to what kind of apps you can side load using xcode?
- ikawe 9y agoNothing installed that way can receive push notifications, though not all apps need or use then.
- nnutter 9y agoI'm not certain but I think push notifications can also be used "invisibly" to trigger data sync so this could mean limited functionality beyond just receiving "pop-ups".
- mhovan 9y agoNot strictly true. I regularly test push notifications on sideloaded builds at client sites. Getting provisioning profiles and certificates setup correctly (especially on all extensions) is a bit cumbersome. To get those certificates may require an Apple enterprise developer account. And the builds signed this way are not debuggable.
- dpkonofa 9y agoThat's not true. You can receive push notifications on side loaded apps.
- ReverseCold 9y agoYou can (used to be able to?) also sideload without a Mac, that's how some pirate app stores work without jailbreak.
- titanomachy 9y agoHow much of this can be independently verified? I suppose we just need to take their word for it?
- Shank 9y agoIt all boils down to what you see in the public. The FBI was trying to get Apple to create an iOS variant to extract data from a device, to the point where Tim Cook wrote a letter refusing to do so and was willing to fight it in court. In a similar fashion, Apple has given talks and white papers on iOS security. In tandem with these well documented white papers and talks discussing the internal functions of iOS, we haven't seen any well known or trivial exploits appear to surface that demonstrate flaws in them. In the case of the FBI fiasco, for example, we know that the FBI later paid Cellebrite for an exploit that allowed them to unlock the device. We don't know the details of how that happened, but the FBI had to reach out to an independent company and exploit an older device to do it. To be clear: if they were lying about the lengths they go to with encryption, on device security, and user trust, this story would have been different. The FBI would have already had a backdoor or been able to trivially break the device, or they would have complied and created an iOS variant to break in. All we know is what they stood their ground on, and the effort that was required for the FBI to get in. iOS 10 security white paper: https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf Talk about iOS security at Black Hat: https://www.youtube.com/watch?v=BLGFriOKz6U https://www.youtube.com/watch?v=BLGFriOKz6U
- lern_too_spel 9y agoWe know that they lied to customers claiming they couldn't help law enforcement get data off customers' devices. "Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data. So it's not technically feasible for us to respond to government warrants for the extraction of this data from devices in their possession running iOS 8."[1] After it became clear that it is technically feasible for Apple to assist with those data requests, they quietly removed that claim from their website.[2] [1] https://arstechnica.com/gadgets/2014/09/apple-expands-data-encryption-under-ios-8-making-handover-to-cops-moot/ https://arstechnica.com/gadgets/2014/09/apple-expands-data-e... [2] https://www.apple.com/privacy/government-information-requests/ https://www.apple.com/privacy/government-information-request...
- maxpert 9y agoAt least one company is "trying" keep my photos private. The other day Google Photo told my wife it had prepared an album for our trip to SFO. We were surprised because she already disabled Geo-tagging but whataya know... Google still figured it out!
- petepete 9y agoIf you have location enabled on your phone, Google appears to cross reference your location with your photo timestamps to work out where you were. I know this because when I import my DSLR images to Google Photos it estimates the location, usually very accurately.
- ben1040 9y agoI've also seen it geotag things based upon the content of the image alone. I went to the photo store not long ago and had dozens of rolls of negatives scanned, from a vacation to Europe 20 years ago. I uploaded them into Google Photos and it geotagged many of them automatically. They have a public API that does the same, it detects landmarks in images and can give you a lat/long position for it as well as a confidence score. https://cloud.google.com/vision/docs/detecting-landmarks https://cloud.google.com/vision/docs/detecting-landmarks
- amonavis 9y agoI discovered the same last week. I made a trip to Amsterdam some 11 years ago, and since then uploaded my entire photo library to Google Photos. Last week I was playing around and searched "Amsterdam" in Google Photos, whaddaya know, (most of my) photos from Amsterdam showed up, at least those with discernible features/buildings/landmarks.
- quadrangle 9y agoApple does so many things well, actually. I would return to them for some things and even recommend them (versus exclusively GNU/Linux and LineageOS) if they'd only change the stupid iOS terms that prohibit GPL software.
- X86BSD 9y agoFunny, to me it's not Apple that is stupid, it's your license that is stupid. It's keeping your app out of the App Store, it's keeping ZFS and Dtrace from the Linux kernel, the amount of developer energy and time wasted on GPL enforcement and arguing about what it actually says and means is appalling. Why you would saddle yourself to a license with so much dead weight and so many problems I can't understand.
- AsyncAwait 9y agoAnd yet, the GPL has been absolutely critical in establishing free software as a credible player, so I'd disagree with you on the license being stupid.
- X86BSD 9y agoNo more so than the BSD/MIT/Apache licenses. The BSD license predates the GPL. And has none of the dead weight or baggage.
- AsyncAwait 9y ago> The BSD license predates the GPL And the BSDs predate Linux. Yet Linux distros are the most popular free software OSes out there. I did not say the GPL invented open-source, but I don't think you can deny that it was the force to move it from obscurity, at least at the beginning.
- craftyguy 9y agoDo they just block the GPLs or any FLOSS license?
- whathaschanged 9y agoApple's approach to privacy also includes being a partner in PRISM, a fact which they chose to vigorously deny as false allegations until it was proven to be true. Every story about Apple and privacy chooses to omit thus huge piece of info. Why should anybody trust them now? What has changed to make anybody believe they aren't still lying about privacy?
- dclowd9901 9y agoIf their technology is built such that even they themselves cannot peer into the inner workings of your content, what good is their association with PRISM?
- rnhmjoj 9y agoBut it's not. It says "encrypted when sent and, in most cases, when stored on our servers". Even if encrypted at rest that doesn't mean they can't decrypt it. The calls and messages should be end-to-end encrypted but they are in control of the PKI so they could probably eavesdrop if they wanted.
- tptacek 9y agoReread Apple's security papers. Much of what's "encrypted on their servers" is encrypted in ways deliberately designed to make it untenable for Apple to decrypt. For instance, material in iCloud is encrypted with a key derived from your device PIN. So concerned is Apple with maintaining their inability to decrypt, even with a brute-force search on the PIN space, that they've contrived an elaborate quorum scheme of HSMs to manage the key space and count failure attempts. Nobody does this and Apple could have stopped here and rightly claimed the most secure large-scale cloud architecture of any mainstream tech company. But they didn't. They used programmable HSMs to implement the system and were concerned that a serious power bent on coercing Apple would target the HSMs. So, once they get the systems deployed, the admins meet and run the programming keys for the HSM through a "physical one way hash function". On stage at Black Hat, Ivan Krstic claims that hash function to have been a Vitamix blender. Almost always, when companies claim to encrypt things serverside, they're doing something shady. And it is always preferable that secrets be kept on devices and never touch servers. But Apple is taking the problem seriously.
- jvican 9y agoAfter reading this, I have two questions: 1. Are there any statistics showing the ratio of security issues between Android and iOS? 2. What's the most common phone among security researchers? To be honest, I'm wary of believing this, but I own a Nexus and if I had to give the benefit of the doubt to either Google or Apple, it would most certainly be Apple because they don't make business out of my data (or, not as much as Google, at least).
- pcurve 9y agoI'm an Android user, but I feel the same way. I sometimes wonder what would happen if I were to create a new Google identity and start fresh. Would they try to re-establish my old email's profile and data to the new one without my consent?
- bsenftner 9y agoYes, definitely.
- arunmib 9y agoI tried this as an exercise when they were pushing Google+. Created a new account, was very cognizant to read through all settings and ensured that nothing from my old account can be traced back to this new one. I'm not joking when I say nothing from my old account and tracking: 1. I timed my move (to different city inside bayarea) 2. Changing ISP to wave from comcast 3. Bought new computer 4. Closed my old phone account and only started using work phone. Never used hotspot in my work phone 5. Even changed my coffee drinking habit + free wifi access locations from Starbucks to Peets. Only thing I couldn't change was my name + SSN. Serious paranoid level of things for my online life, but they still populated my digital life with same info and recommendations. After about 10-15 days of doing all this, I enabled Google+ (because at that time to use youtube account, I had to enable it). You know who the first contact recommendation that was there for me under my family - my brother who is living in a different country. I just gave up at that point. Probably I did something wrong during the setup (or) slipped and used the accounts for some period of time on same computer or browser (or) the data companies which sell my offline data have really rich data about me. Whatever the goof-up was, it was just disheartening to learn that after all that work my online privacy just lasted at the max 15days. I really wish there were better ways. Considering the number of security/data breaches (e.g. recent equifax one) I feel like, I have little to no control on things.
- gallerdude 9y agoPrivacy is one of those things I can't tangibly describe why I like it, but it just feels good to know that nothing is being saved, even in contrast to just targeting you for ads and nothing else.
- JumpCrisscross 9y agoWe have a track record of things going south, fast, for societies that sacrifice privacy. It makes sense to tread warily with it.
- zachlatta 9y agoCan you give a few examples?
- JumpCrisscross 9y agoPretty much every authoritarian overthrow that became genocidal relied on a previous bureaucracy's meticulous record keeping.
- zachlatta 9y agoCan you please give a few examples?
- JumpCrisscross 9y agoThe classic ones are Pol Pot and Hitler. With the latter, the Danish example is useful.
- zachlatta 9y agoIn your original comment, you were implying that societies that lose privacy go south very quickly. As in that loss of privacy is causal. I can't speak for Pol Pot, since I'm not very familiar with his regime, but with Hitler and the Danish, my understanding is that record keeping aided in the German occupation. Not that the Denmark went downhill after it started doing meticulous data gathering. Can you give causal examples?
- shmerl 9y agoI wouldn't trust on issues of privacy to the likes of Apple. Who can audit their software? It's not FOSS.
- drdaeman 9y agoYou only need less than a half of Freedom 2 ("freedom to study how the program works") to audit the software. Not even the source code - because you can't trust the source to match the binary (unless Apple has reproducible builds, of course, but I'm not sure they care about this). But, yes, it's mostly based on a trust rather than knowledge obtained during some audit. (I'd even say that trusting is sorta the opposite of knowing) Disclaimer: never owned any Apple device, ever. But they're doing quite well (or, should I say, others are doing so damn terrible in regards to user security and privacy, Apple starts to look not so bad) so I may consider them as an option.
- achamayou 9y agoYou can still contemplate their incentives, their business model, and their reputation/track record. It's not as good as auditing the code (and making sure the code you see is what actually runs), but it's a lot less effort, and depending on the extent to which you are ready to dedicate resources to improving your privacy, may be an acceptable tradeoff.
- imron 9y ago> Apple has no way to decrypt iMessage and FaceTime data when it’s in transit between devices What about when it's not in transit between devices?
- alex_g 9y agoWell they decrypt it on your behalf when it's on your device. The point is that couldn't do that without your device/account.
- jw1224 9y agoThey then go on to say: > While we do back up iMessage and SMS messages for your convenience using iCloud Backup, you can turn it off whenever you want. Sure, I can stop backing my data up - but presuming I don't (like the vast majority of people), does that mean if they got a wiretap order they could just read the data straight from their backup servers? I'm not sure if this was just phrased poorly, or if backing up your iMessages effectively undoes any protection your messages once had.
- deagle50 9y agoGood question. If you backup via iTunes you have the option of encrypting with a password. I've never been prompted to enter a backup password for iCloud...
- DavideNL 9y ago"The iCloud Loophole" (article from March-2016): https://www.macrumors.com/2016/03/02/icloud-backups-less-secure-for-restoring-data/ https://www.macrumors.com/2016/03/02/icloud-backups-less-sec... Although in a link in this HN article Apple says backups _are_ encrypted: https://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303 So, a little confusing... EDIT bah, found this: "Right now, although iCloud backups are encrypted, the keys for the encryption are also stored with Apple. " https://9to5mac.com/2016/02/25/apple-working-on-stronger-icloud-backup-encryption-and-iphone-security-to-counter-fbi-unlock-requests/ https://9to5mac.com/2016/02/25/apple-working-on-stronger-icl...
- greggman 9y agoI'm happy Apple is at least trying hard to deal with privacy but honestly I don't think they are doing enough, at least for me. For example, I don't really want to give most apps constant access to my photos, my camera, or my mic but I really don't have a whole lot of choice if I still want to use popular apps and services like Facebook, Instagram, Messenger, Hangouts, Line, WhatsApp etc.. I really wish that every time they wanted a photo they had to get it through some OS level UX and they only got to see the photos I selected. As it is they get to see all my photos the moment I want to give them a single photo. Similarly if I take a photo in one of them they require permission to read all my photos when all I want them to be able to do is save the photo. As for the Camera I don't give any of those apps access to the camera because I don't trust them not to spy on me in some way (I assume camera = mic access so they could be doing the subsonic listening for ads things etc...). Instead I take the picture with the built in app then access that picture from the app I want to use the picture in. Of course that leads to the problem above. Mic access is more problematic. I don't want any of them to have mic access when I'm not using the mic function directly but I can't talk to my friends who use all those services to call me if I don't give the apps mic access. I feel like if Apple was more serious about privacy they'd handle these issues in some way. The photo one seems mostly straight forward for most use cases. Don't let the app access them at all, only the OS. The camera one is less straight forward. I get that there are innovative things apps can do with the cameras by using them directly. On the other hand most of the current use cases could be handled by letting the OS access the camera only, not the app, and then just giving the result to the app.
- guyfawkes303 9y agoI think you mis-understand how iOS privacy controls work. An app doesn't get to 'see all your photos' just because you grant photo access, you still have to select which photos to put in the app. Same goes for camera, that just let's the app pull up the camera interface, not be able to access it 24/7 for whatever purpose they want. Same with the mic.
- LeoPanthera 9y agoI don't think this is correct. The Facebook app regularly shows me all the photos I have taken today and asks if I want to post any of them.
- jacksmith21006 9y agoApple chose to let the China government into their China data center and Google chose to leave the country instead. So not so simple on who you trust. Personally I trust Google more as they are just a lot better at keeping things secure, imo. Plus governments getting into data is a bigger deal to me than a targeted ad. But it is a personal decision. "A Local Chinese Government Will Oversee Apple’s New iCloud Data Center" http://fortune.com/2017/08/14/apple-china-icloud-data-center/ http://fortune.com/2017/08/14/apple-china-icloud-data-center...
- et-al 9y agoWhy was this downvoted? It's a relevant point to the discussion.
- wyc 9y agoApple sells hardware differentiated by integrated software for premium pricing. They want to build better and more expensive products through superior design and quality control. Collecting and analyzing personal data isn't the most important thing for their business. They might see more benefit by eschewing personal data collection and marketing a privacy-focused message, which they seem to be doing. In contrast, Google and Facebook are companies that sell advertising. The value they can offer to publishers and advertisers completely relies on how well they know their users. Their competitive moat involves collection of proprietary data to continuously improve their products. These are clear incentives to be sticky and greedy with your information, but also to keep it private and proprietary for their own sake. With these incentives in mind, I more readily trust Apple when it says that it will not collect my data compared to data conglomerates, and Apple hasn't done anything to aggressively betray that idea in its history (to my knowledge). Combined with the technical security advantages of iOS, I'm inclined to believe Apple products to be the least-bad option for the security-minded today.
- yaseer 9y agoI agree with this reasoning (although I'm not particularly privacy minded, and prefer Android and most Google products to iOS and iCloud). The older tech companies like Apple and Microsoft have built business models with a different set of incentives around user data. Google, and particularly Facebook's, business models entirely rely on monetising user data. My personal 'ranking' of a companies incentives to respect privacy is something like: 1. Microsoft 2. Apple 3. Amazon 4. Google 5. Facebook Obviously this ranking is very debatable, but I agree business model incentives are a pretty good heuristic.
- chickenfries 9y agoI'm curious why you would say that Microsoft has the most respect for privacy given Windows 10 telemetry. Is there a MacOS or iOS equivalent?
- spsful 9y agoNope, Apple even goes to great lengths to preserve user privacy in the data they collect (See Apple's use of differential privacy)
- spsful 9y agoI wish the EFF still made those "Who has your back" infographics, they were really helpful if you wanted to find out which companies respected your data both online and in the courts. But IMO Apple is the only large multinational corporation that is actually taking steps to protect my privacy so I'm way more inclined to trust them with my personal information. Can't say the same for Google or others.
- newscracker 9y agoA few things have struck me really strong on Apple's stand and implementation on protecting users' privacy: 1. Though it's understandable that Apple earns money primarily by selling hardware, it's sort of amusing and alarming at the same time that a proprietary almost-closed-source software company is focusing on protecting and preserving privacy whereas partially open source platforms competing with Apple seem to be nowhere close on this aspect. Do any of the Android forks try to do as much as Apple does for privacy right out of the box (something a non-technical lay person could get)? 2. It's abundantly clear that a lot of thought has gone into the foundations of a design focused on protecting privacy and in creating silos of information in/with different SDKs and features. 3. It's a bit unclear to me as to why Health data is stored encrypted in iCloud whereas messages aren't. Is there a distinction here between iCloud sync and iCloud backups? The documentation on messages suggests turning off iCloud backup as a protective measure. 4. To me, the weakest link in the ecosystem seems to be third party apps, where Apple relies more on them adhering to the developer guidelines and on publishing a privacy policy.
- wyc 9y agoRegarding your first point, it's difficult to implement some security schemes at the operating system level alone. With full vertical control of the product, you can have nice things like secure enclaves and de-facto hardware cryptography acceleration. See here for details: https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf A lot of the features would be very difficult to implement in Android without cooperating hardware, and hardware is notoriously expensive to get right and scale up. Projects like neo900 and Purism regularly encounter delays, unexpected costs, and pricing issues. It's really tough. On a broader note, people are spending more and more time in data-hungry apps anyway, which can send almost anything they want to the network. This is sure to chip at any device-level security, pushing it towards irrelevance. I wish I had a log entry every time an app used the location service on my phone along with a database containing a history of Internet-transacted data.
- newscracker 9y agoThanks for the explanation on the Android side. It still seems weird that nobody wants to take this up as a USP for their devices (referring to non-Google entities). > On a broader note, people are spending more and more time in data-hungry apps anyway, which can send almost anything they want to the network. This is sure to chip at any device-level security, pushing it towards irrelevance. I wish I had a log entry every time an app used the location service on my phone along with a database containing a history of Internet-transacted data. I've long wished for network access permission on iOS, allowing the user to decide which apps can never connect to any networks. To reduce the total attack surface, I'd want to keep many apps (especially games) running only within their sandboxes and having access to only the data they create/generate on-device and no other external resource/server. AFAIK, Android has had this even in the days of permission requests at app install time. I don't know if granular control is available on this from Android 6 onwards.
- williamle8300 9y agoAll the anti-constitutionalist people at the NSA are getting heartburn as we speak.
- icomefromreddit 9y agoI don't trust Apple. It's a matter of trust, so I have nothing else to say, just I can't trust Apple.
- bgrohman 9y agoOn the subject of privacy, I'm interested in migrating away from Google services, but I have years' worth of data tied up there (email, photos, music, movies, etc). I know Google offers ways to download your data, so it's technically possible to migrate, but it would be tedious and time consuming, to say the least. Does anyone have suggestions for making that process easier?
- cyphunk 9y agoWake me up when they let one sync contacts without giving icloud cleartext access in the process
- mercutio2 9y agoCan you say more about why this is important to you? I mean, more stuff encrypted without provider escrow keys is a generally good thing, but are your contacts specifically more important than, say, you calendar events? What threat model are you worried about with your personal, curated contacts?
- cyphunk 9y agoall data is important, indeed. contacts are just an easy to access example. I'm worried about countries creating laws, secret and public, that force Apple to hand over my data. Specifically those governments that I spend time in and that I also spend time criticising or protesting within as an activist. I'm worried about regime changes. I'm worried about 3rd party data breaches. I'm not worried about how my data exposure would effect me now but how it would effect me in the future when mining and correlating data to use against activists will be much easier.