7 ms·
How much does Apple know about me? The answer surprised me
- lumisota 8y agoThe title of this article is click-bait, surely? Apple have made much PR out of their privacy stance. Indeed, the article says: "Apple makes a big deal about its different approach to privacy on the company website". How is this eye opening?
- falcolas 8y agoPerhaps because we've all been conditioned to ignore PR, or to believe the exact opposite of what PR says. Seeing that it's true is an unexpected situation. It's also eye opening in the context of a comparison against the other FAANG companies in question.
- sykh 8y agoThe eye opening part was how little data there was and the hoops needed to verify the recipient. This is in comparison to Google and Facebook. Both have orders of magnitude more data and sent the data with, apparently, little verification.
- ntsplnkv2 8y agoIt's not really eye opening considering Apple products cost money. Their business does not lie upon selling data to advertisers or other entities.
- sykh 8y agoBut they could collect data and presumably profit more. If they did collect more data and profited from this data collection would they really lose enough customers to offset this increase in profit? It seems to me they wouldn’t. I think they are taking a moral stance on the issue at least for the time being. This may change in the future. It is surprising though for the company not to lie about this given the shenanigans that many large companies engage in.
- lern_too_spel 8y agoIt's eye opening that the author doesn't use iCloud? Why? Almost nobody uses iCloud. Each of its components is worst in class.
- sykh 8y agoI use iCloud for storage. It’s worked great for me. I’ve never had a problem with it. It wasn’t eye opening to me that the author doesn’t use iCloud.
- deleted 8y ago[deleted]
- iriNjfk993 8y agoFor you maybe it isn’t But you’re only one of 300 million in the states and 7 billion on the planet And it’s USA Today, mainstream news. Maybe it’s not targeting someone with nothing better to do than memorize Apples policies
- deaps 8y ago<Your Siri requests —"Show me how to get to PF Chang's," or "What year was Steve Jobs born?" go back to Apple — but it uses a random identifier to mask your identity. So a Siri search for the closest Chipotle restaurant will only tell Apple that a user requested the data, but not associate it with me.> I find that comforting. In fact, if I was a large organization and processed a ton of user data, I'd want to store that data anonymously too, due to the sheer risk of having that personal data.
- ajmurmann 8y agoAnd then you have users who always go to the same PF Changs but use navigation in case there is traffic and they should use an alternate route. Your competitor app will learn this and adapt and yours won't. The average customer will have no idea you aren't storing their data and likely doesn't even care while they aren't reading an article about privacy. While I personally wish everyone were to take your approach is also tying one arm behind your back. Edit: I once worked with an ex-googler who told me to always store all the data you have because you never know what you can use it for, you can't get it back if you change your mind and storage is cheap. Hard to argue with this if it's "just" about competitive advantage and monetization.
- mistersquid 8y ago> And then you have users who always go to the same PF Changs but use navigation in case there is traffic and they should use an alternate route. Your competitor app will learn this and adapt and yours won't. Your conclusion doesn't follow from your premise. Once a user navigates to a specific PF Chang's from a specific location, the navigation app can suggest an alternate route that takes into account traffic, regardless of whether that user has a history or not. In your scenario, the history of the user data would not affect the ability of the app to suggest routes that are less trafficked. EDIT: change adverb in last sentence
- soared 8y agoHis point was to store that data because you might want it in the future - not that its necessarily useful now, in this situation. (Ex. 2 years from now, when Apple gets into the restaurant business, they might want to analyze what users (user ids) search for what types/distances of restaurants.
- falcolas 8y agoI always question the effectiveness of obfuscating data using "unique identifiers" against a party determined to de-obfuscate the data. Aside from that, however, this is an encouraging read.
- psergeant 8y agoYou may enjoy learning more about Differential Privacy. https://machinelearning.apple.com/2017/12/06/learning-with-privacy-at-scale.html https://machinelearning.apple.com/2017/12/06/learning-with-p...
- falcolas 8y agoDifferential Privacy and anonymous-but-unique identifiers are disjoint methods of protecting privacy. Per TFA, they appear to be using the latter. And WRT differential privacy, if enough data is captured and associated with a single identifier, then it's sufficient to get a pretty good idea what the user actually does. That's the point of differential privacy in the first place, since it indicates that a statistically meaningful amount of the data is valid. For example, if my user id has five visits out of 1000 DP recorded visits to google.com, it's unlikely that I actually visited google.com. However, if there are 200 recorded visits, it can be safely said that yeah, I intentionally visit google.com.
- ldayley 8y agoSome interesting previous discussion regarding the limitations of Apple's differential privacy can be found here: https://news.ycombinator.com/item?id=15224312 https://news.ycombinator.com/item?id=15224312
- rocqua 8y agoExactly my thought. If they can connect all siri queries made by a user, it doesn't matter much if they don't store the name of that user. Deanonimisation happens easily through correlations, some correlations are really hard to predict. Id't be better if they just didn't store an ID with the data.
- 8y ago
- mgliwka 8y agoJust pointing out the obvious: Absence of evidence is not evidence of absence. The only eyeopening part would be the fact, that Apple doesn't store much about it's users, which isn't verifiable. Also unique identifiers are not the only way to link data. And due to differential privacy the guarantees that the data cannot be linked decays over time (see https://news.ycombinator.com/item?id=15224312 https://news.ycombinator.com/item?id=15224312)
- scarface74 8y agoThe question is motive. Apple's business model isn't predicated on having a lot of data on you. They have to keep a list of your purchase history for instance so you can redownload purchases. Also, why would they risk lying? What's in it for them?
- mgliwka 8y agoI'm by no means implying any malfeasance. I fully agree with your thesis about Apple's business model. Depending on your threat model in regards to your privacy the assurances made by Apple may be enough. To me, it doesn't really matter. As long as I have no proof or control over how my data is being processed, it's better to just assume the worst case and practice data minimisation.
- aeorgnoieang 8y ago> Absence of evidence is not evidence of absence. That's neither obvious nor true. Absence of evidence is more likely if there really is an absence of whatever; thus it is in fact evidence of absence, if only weak evidence.
- Cenk 8y agoDid we really need a photo of the author holding a prinout of the data? > It kept a copy of every app and song I'd downloaded, every tune I'd added to my iTunes music library, and every time I needed repair on a multitude of Apple devices going back a decade. Is this surprising in any way? If you buy something (or "buy" it for free on the App Store) of course the company you buy it from keeps records of that.
- icebraining 8y agoIf you buy something of course the company you buy it from keeps records of that. I don't think it's a problem, but they could not tie it to your identity. After all, when you buy something with cash, the company might keep a record of the purchase, but it's not (or at least not always) tied to you.
- gumby 8y ago> Is this surprising in any way? If you buy something (or "buy" it for free on the App Store) of course the company you buy it from keeps records of that. It need not; for example it doesn't need historical data that have been superseded; if it no longer has an app available for download it could purge the fact that you bought it; it could give purchasers an anonymized download key that their phone could store (or cache in icloud someplace).
- jmelloy 8y agoThat’s pretty rough from a financial audit perspective. For budgeting purposes I’ve tried to find a full list of my iTunes purchase, and couldn’t find it in the store. Didn’t think to look in privacy.
- gumby 8y agoI'm not complaining per se, but quite puzzled why someone would downvote this factual comment. Plenty of companies sell you things without maintaining a record (say, a brick and mortar shoe store) and there's typically little reason to do it online either. Yes, I know plenty of online companies do routinely spy on users but I see no reason to consider this "of course". This is admittedly creeping into meatspace (there's absolutely no legitimate reason for causing things like automatic toll tags or driving licenses to supply privacy-busting data to third parties, but on the other hand plenty of sandwich shops manage to have "frequent diner" programs that are simply a card the customer carries which is punched each time a sandwich is purchased. There is no reason why an online business shouldn't do the same -- and GDPR should drive businesses to do so. It's in the customer's interest.
- bpicolo 8y agoTo be fair, MB of data is kinda a crummy metric because for Facebook that's primarily photos and videos
- jacksmith21006 8y agoApple needs to create a dashboard exactly like the Google one. Their agreement allows them to collect tons of data but there is no transparency on what they have and no ability to remove or download. The Google one also has all your devices in one place with what apps and permissions you have granted. Exactly what I would like for my Apple devices.
- falcolas 8y agoIronically, complying with these asks would require more data to be pushed off the individual devices.
- itsdrewmiller 8y agoClickbait headline - could it get changed to clarify the alleged answer is “very little”?
- misterbowfinger 8y agoAgreed, headline is very clickbait-y, should be changed
- dwighttk 8y agoIt would be nice to have more than "Apple also offers data downloads in the privacy section of its website. It's hard to find..." I can't find it... I started at icloud.com which sent me to appleid.apple.com which sent me to apple.com/privacy/ and I never found a data download link.
- mmastrac 8y agoI have a theory that the only reason Apple is today's beacon of user privacy is that they couldn't manage to compete in either the ad (iAd), mail (at least not at G-scale) or social network world (see: Ping). The only path left for them was to say they were all about user privacy. If Apple had succeeded wildly in any of those three spaces, I think they'd be caught up like Google, Facebook et al. I'm not saying this is a bad thing for the tech ecosystem, but I do think it was lucky positioning on their part. Interested to hear opposing opinion on this.
- nxc18 8y agoIt was becoming plain a few years ago (by 2015 at the latest) that Apple didn't have the aptitude to compete in big Data or machine learning. It was very clever of them to bet on privacy - the one strategy that has little need for big Data and ML. The other big bet is that something might happen to convince users that privacy is good. We'll see how that plays out - users aren't particularly bothered by Facebook revelations as their DAUs attest. Kids are growing up with microphones in their bedrooms (Amazon echo dot for kids) so privacy will be a deeply erodes concept ~15 years from now (if it isn't already).
- Isamu 8y agoI agree, if the success was there they'd follow it. But to be fair I think Steve Jobs was pretty interested in privacy and put some of that philosophy in the company. So they were already pursuing privacy goals but there would be these conflicts of interest that they would eventually have to resolve. Luckily they continued to suck at social networking and many online things. It works better for them to double down on privacy.
- 01001010 8y agoWhat if the causal relationship was reversed? Perhaps the success wasn't there in those areas due to a previously established philosophy concerning privacy. Grasping and purely conjecture obviously, just putting it out there.
- 8y ago
- csomar 8y agoOkay, wait. So tech company can store all that data under “xyz anon user” and then they don’t have any data about you?
- grigjd3 8y agoDepends on the data but yes.
- IloveHN84 8y ago8days= more time to filter user content and claim they have no data about you
- tinus_hn 8y agoThis click baity title didn’t come from the article. You’ll never guess what happens next!
- ghosttie 8y agoHow can it direct you to the nearest Chipotle if it doesn't know where you are? It must know who you are at least at the time of the query