8 ms·
> However, since Apple now proxies Google Safe Browsing traffic, it further safeguards users’ privacy while browsing using Safari. It still shares the same amo
by Camillo 6y ago
> However, since Apple now proxies Google Safe Browsing traffic, it further safeguards users’ privacy while browsing using Safari.
It still shares the same amount of information, it's just being shared with Apple instead of Google. If it was a privacy problem before, it remains so.
- sanxiyn 6y agoThis is a significant improvement if you trust Apple more than Google.
- sschueller 6y agoFor the US Government it's just a different phone number they have to call to get your data...
- deleted 6y ago[deleted]
- stqism 6y agoTypically, people who are trying to defend themselves from nation state threat actors aren’t using iPhones or stock Android phones, and absolutely wouldn’t use safe browsing if they did.
- jlgaddis 6y agoAnd the U.S. Government isn't making a phone call to get the data. They have a "law enforcement portal" they can log in to in order to request the data.
- sneak 6y agoAre we classing the FBI as a "nation state threat actor" now?
- sbuk 6y agoIf you're outside the US, yes.
- sneak 6y agoWhat does that have to do with the threat posed?
- iSnow 6y agoI don't think it's about the FBI as much as the rest of the three-letter soup. NSA, CIA et al. most certainly are a threat to anyone outside the USA holding valuable secrets.
- kergonath 6y agoWell, it is an actor and it is a government agency...
- tempodox 6y agoWhy not? Every system holding PII poses a potential threat, at the very least because every system can get hacked, and at worst because folks with “legitimate” access to that data can still abuse it.
- eriri 6y agoEver heard of Edward Snowden? He exposed how three letter agencies were engaging in mass surveillance, even including American citizens in violation of their very own constitution they've sworn to protect.
- jaegerpicker 6y agoIt always should have been. I'm not sure anyone would not class them as a nation state threat level. It's one of the most powerful government agencies in the most powerful nation in the world. If they don't fit that definition who would?
- emptyparadise 6y agoNo silver bullet. This is a counter against surveillance capitalism but not against surveillance states. In the long run the only sure way to prevent data misuse is to remove the data, but moving existing data to entities without the financial incentives to misuse it is still a step in the right direction.
- lupire 6y agoFor the Chinese government it's a direct feed from Tencent, which Apple devices sent URL data to.
- LeoPanthera 6y agoAnd even if you don't, it still reduces your surface area, because your iPhone is already talking to Apple anyway.
- politelemon 6y agoIt would be better if it didn't talk to their servers, adding more on increases the surface area and impact. In this particular case with Safe Browsing APIs, there wasn't a 'surface area' in the way that you mean, to begin with. The article, and commenters, are incorrectly making it appear that way.
- om2 6y agoThe Safe Browsing protocol does have a theoretical vulnerability whereby a malicious provider could create hash buckets on demand with the intent of guessing user URLs. This change would protect users from this theoretical risk. Also, it prevents Google from getting free info about user IP addresses and other info visible via a direct network connection.
- cromwellian 6y agoI'm guessing this information is next to useless. All they get is an IP address, and all it signals is someone is using a device. It is highly unlikely this is a useful signal for anything given the fact that they're getting much better user IP data from practically dozens of other services people use.
- mvanbaak 6y ago> It would be better if it didn't talk to their servers As long as you have a 'smart' phone, it will talk to servers. Messages, email, contact sync, online backups, tools to give you trace possibilitiies if your phone is stolen ... everything needs some kind of server. And if you use an iPhone, a lot of those will be located at apple. If you use an android phone, those servers will be located at google (and possibly also at the hardware vendor eg samsung etc) Aside from the whole 'company A can be trusted more then company B' thing which is in my opinion a personal matter, this specific item where apple will route the traffic to a 3rd party through apple to hide the ip etc of their customers is a good thing.
- tjpnz 6y agoI don't trust either but knowing how each makes their money one might be less inclined to abuse my data over the other.
- izacus 6y agoWhat are you basing this information on (besides a pinky swear of a corporation which happily forgets their values when it comes to repairability and labor force) ?
- mosselman 6y ago> "knowing how each makes their money" Probably gave it away? > "their values when it comes to repairability and labor force" Apple obviously doesn't have any positive values about labour force and repairability, but both of those have about 0% to do with privacy, so they aren't relevant in this case I'd think.
- 6510 6y agoI get that Apple seems more trust worthy in this setting but if one trusts others depends on everything they do. It would be better if they combined forces to create a separate entity. Safe browsing currently gives both companies the ability to block websites. They could do this when they feel like it but also when ordered to.
- kergonath 6y ago> so they aren't relevant in this case I'd think. It’s just the classic “Apple’s bad, therefore they are absolutely doing anything nefarious I could come up with”.
- tchalla 6y agoYou can look into SEC 10K filings for both firms.
- izacus 6y agoAnd those filings say that Apple is rapidly changing itself into online service firm where most services heavily rely on users data.
- deleted 6y ago[deleted]
- politelemon 6y agoThere is no significant improvement - the data was already hashed/anon to begin with and posed no risk. IP addresses on their own aren't a problem, it's when it's available with additional data that you start to worry. This is purely a move to further lock users in while being touted as being privacy friendly through persistent PR.
- my123 6y agoLock users in? What does it change from that point?
- michaelt 6y ago> IP addresses on their own aren't a problem I'm the only person using my IP address, ergo it's personally identifiable. Seems pretty clear cut to me?
- politelemon 6y agoNot at all. IP addresses are not PII under any definition. Feel free to browse CCPA, GDPR, etc. Even without those regulations, it's still not PII as it takes just a few seconds to enumerable every IP address. If it actually were PII, you would have controls in place to prevent it leaving your device in the first place. IP addresses are only when identifiable metadata is linked with it. I can only guess that you are being deliberately obtuse on this - I had momentarily forgotten that I was on HN so my comments weren't welcome sadly.
- tgragnato 6y agoIf you are an iOS user, then Apple is necessarily in your trust model. Google, not so much. Google’s implementation of k-anonymity in Safe Browsing does not account for their own ability to correlate multiple queries and narrow down which specific website corresponds with the hash.
- lupire 6y agoThe hashes are hashes of a small set of public data, and so reversible via rainbow tables.
- sneak 6y agoBoth are required in the US to turn over user data and logs to the US federal government without a warrant, pursuant to FISA orders. Apple compromised over 30,000 of their customers in such a fashion in 2019, as documented in their own transparency report. The F in FISA stands for foreign, but at least one person who worked on the program has told us that it is used to obtain the data of Americans without warrants as well.
- beermonster 6y agoThis. Would be better to not have to trust anyone!
- madeofpalk 6y agoWhich I guess would be more of a given if you've decided to buy and use an Apple device.
- Manfred 6y agoSoftware update and other features already expose your IP address to Apple. This solution doesn't add another company, so that's a win.
- izacus 6y agoGiving all your information to a single company where it's easily pooled and abused is a win?
- simonh 6y agoNo, it’s segmenting which information goes to which company. Apple already has your IP address so why also give it to Google? Meanwhile the https traffic is only proxied through Apple, so they don’t see the content.
- tchalla 6y agoApple doesn’t collect and use information the same way Google does.
- vntok 6y agoIt is true, Apple handles it way worse. With Google you have access to a whole dashboard where they explain in very simple terms what they know about you (per service) and how they use that information. And of course you can opt-out with a few clicks.
- tchalla 6y agoIt’s interesting that one using data as a selling point is worse than one that doesn’t. In any case, Apple gives you access to all information they have on you and you can opt-out with a click. I’m not sure that’s a differentiator in any case.
- rgovostes 6y agoApple has the same thing[0]. A journalist requested their data from Apple, Google, and Facebook a few years ago[1], > The zip file I eventually received from Apple was tiny, only 9 megabytes, compared to 243 MB from Google and 881 MB from Facebook. And there's not much there, because Apple says the information is primarily kept on your device, not its servers. The one sentence highlight: a list of my downloads, purchases and repairs, but not my search histories through the Siri personal assistant or the Safari browser. Also curious how, if as you say Google is so transparent with this information, they abruptly stopped updating all of their iOS apps on December 8th, the day that Apple required them to publish the data that their apps collect[2,3]. 0: https://privacy.apple.com/ https://privacy.apple.com/ 1: https://www.usatoday.com/story/tech/talkingtech/2018/05/04/asked-apple-everything-had-me-heres-what-got/558362002/ https://www.usatoday.com/story/tech/talkingtech/2018/05/04/a... 2: https://twitter.com/Thomasbcn/status/1356645088697454596 https://twitter.com/Thomasbcn/status/1356645088697454596 3: https://www.macrumors.com/2021/01/05/google-hasnt-updated-ios-apps-since-privacy-labels/ https://www.macrumors.com/2021/01/05/google-hasnt-updated-io...
- relevant_thing 6y agoIf it's a simple proxy tunneling HTTPS traffic to Google, Apple probably doesn't know anything about the content of the queries, and Google doesn't know who sent them. If each kept records, they could get together and combine them to get the hashed URLs, but still a much better situation than directly querying a single endpoint. Signal actually uses a similar approach to anonymize queries to GIPHY from users of its app. https://signal.org/blog/giphy-experiment/ https://signal.org/blog/giphy-experiment/
- deleted 6y ago[deleted]
- sildur 6y agoI think it would have been way more private if they had used tor, defaulting to apple servers if tor wasn't available.
- schmorptron 6y agoThat would probably single handedly bring down the tor network
- goatinaboat 6y agoIt still shares the same amount of information, it's just being shared with Apple instead of Google. If it was a privacy problem before, it remains so. Apple’s business model is not based on exfiltration of personal data, in fact their business of selling hardware is only boosted by adding privacy features.
- Ensorceled 6y ago> If it was a privacy problem before, it remains so. That is a very binary view. Yes, it is still a privacy problem; but now the privacy problem is with a company that is not abusing personal data on a massive scale.
- ViViDboarder 6y agoExcept that if you’re using Safari, you’re already putting some trust in Apple to protect your privacy. Reducing the number of parties to your data is certainly a privacy win.
- kccqzy 6y agoApple doesn't know whatever requests you send. Apple only knows your IP address, whereas Google only knows the request content.