7 ms·
It’s not just marketing fluff though, Apple actually is better from a privacy perspective on many fronts: - iMessage is E2EE (with a big asterisk here of cours
by gpanders 5y ago
It’s not just marketing fluff though, Apple actually is better from a privacy perspective on many fronts:
- iMessage is E2EE (with a big asterisk here of course)
- Maps data stays on device unless you explicitly enable anonymous aggregated crowd sharing data. “Significant locations” never leaves your device
- Apple Photos machine learning recognition all happens on device, not on Apple servers. This is one of my favorite features of my iPhone
- As of the next iOS update, Siri voice command processing happens on device
- The new Apple Private Relay (or whatever it’s called)
No they’re not perfect and they could (and should) do a lot more, but there are objective things that they do better from a privacy standpoint than most other tech companies.
- azinman2 5y agoWorking for Apple, I can say that privacy pervades every discussion of every feature. It’s not just fluff.
- dcow 5y agoDo you have any insight on how other employees feel about this system? I'm sure it's all over the place but anything that stands out?
- ncmncm 5y agoWhat you mean is that privacy policy is above your pay grade. Everything below can be compromised by one choice at the top.
- dev_tty01 5y agoNo it can't. Someone has to implement that choice. It would be visible to the technical staff.
- jrm4 5y agoSure...but: “It is difficult to get a man to understand something, when his salary depends on his not understanding it.” Upton Sinclair
- mLuby 5y agoIt's the opposite: without the developer understanding the thing, there can be no bug fixes nor new features, and therefore no salary.
- jrm4 5y agoYou're focusing on the wrong, and obvious, thing. You'll never get the developers (who are largely fungible) to fully grok the long term consequences of what they are creating because they are blinded by the (entirely natural) fact that the company is keeping them fed.
- azinman2 5y agoI think you’re being unnecessarily cynical and actually incorrect here. It’s not like I’m told to implement some tiny thing where the left hand doesn’t know what the right hand is doing. The entire premise of whatever system is being built is clear, as are all the discussions with the privacy folks, the execs, marketing, designers, etc. Privacy is a constant point of discussion, and often times what engineering wants is made far more difficult by privacy, and they get the final word.
- ncmncm 5y agoA single person can implement a chosen weakening, compromising everything done by lower-level staff. If you don't think this is trivially possible, you know nothing about the fragility of security.
- deleted 5y ago[deleted]
- Teever 5y agoIf you think that you can't be duped by your employer then you've already been duped.
- AshamedCaptain 5y agoBut it IS marketing fluff, because you literally have to trust them on their word. They provide no means to verify what they are claiming and even if you could verify they could still silently update the client apps the next day (since they _exclusively_ control all platforms, all clients and all servers) and you would be none the wiser. Technically Google also "promises" practically the same (E2EE in Chats, only sharing map data if you enable it, local photo recognition, local voice assistant on the new Pixel whatever, etc.). But since you have to trust them on this, all of it is not really much better than just having a reasonable "privacy policy" which we all know is meaningless.
- BoorishBears 5y agoThe local voice assistant model is on a fraction of Android devices. E2EE for Messages literally rolled out last month, relies on spotty RCS support and doesn't work with group messages. Apple Location tracking designed so that even when shared between your devices via Apple's servers it's not visible to Apple. I have literally never seen Google claim Google Photos is using on device classification, I'd love a source for that since nothing about how it works implies that. Maybe you mean it does some very specific type of classification as a pre-processing step? > But since you have to trust them on this, all of it is not really much better than just having a reasonable "privacy policy" which we all know is meaningless. You're free to be wrong? You need to trust someone on a claim vs someone not making the claim at all... those are not the same thing. Apple hasn't shown a reason to lie, and here's no equivalent financial incentive to Google unless you think Apple is pulling the equivalent of a fake moon landing and somehow running a 147 billion dollar data selling operation no one knows about...
- AshamedCaptain 5y agoI am not going to enter a discussion on who rolled whatever first, whose userbase has the most up to date OS, or the like. iOS is not going to win any privacy argument here anyway for the simple reason that at least I can de-googlefy Android. The point is that they make extremely similar promises that you can't verify. > You need to trust someone on a claim vs someone not making the claim at all... those are not the same thing. What is the difference between someone saying that your data is not visible to them (oh but you can't verify it!) versus someone saying that they will not touch or store your data after processing it on their privacy policy? When they control the entire platform, the fact that they claim to be doing something technical to prevent them from accessing the data is absolutely pointless. Even if it were true, they could be able to change it in an instant after a silent update (by themselves, by the government, or even by a third party attack!), and no one would be the wiser. > Apple hasn't shown a reason to lie, and here's no equivalent financial incentive to Google unless you think Apple Not sure I understand. In any case, most companies have already lied multiple times, and _all_ companies share at least one big reason to lie: Come tomorrow, some three letter agency could send them the letter and outright force them to capture your data, and since the only thing that prevents them from capturing your data is empty promises, they could do it in an instant. And would do it. And in fact do it regularly (TFA could in fact be an example of Apple trying to get rid of that). Btw, > I have literally never seen Google claim Google Photos is using on device classification, I have never put a SIM nor network credentials on my only Google Android device that has practically never abandoned my residence and yet it is tagging photos of objects. That's my source. I have not put a SIM either on my iOS devices and they do not tag pictures :)
- systemsignal 5y agoIs there even an asterisk? “ Messages uses on-device machine learning to analyze image attachments and determine if a photo is sexually explicit. The feature is designed so that Apple does not get access to the messages.” https://www.apple.com/child-safety/ https://www.apple.com/child-safety/ Still sounds like E2E, no different from messages applying some processing/compression to sent images imo
- gpanders 5y agoThe asterisk I was referring to is the fact that the E2EE keys are backed up to iCloud Backups along with your messages, and those backups are not E2EE. So the encryption of iMessages is fairly easy to get around if either the sender or the recipient uses iCloud backup.