4 ms·
"Privacy is a human right" really does seem like it was only an advertising slogan. When Apple says "privacy" they seem to have only meant from advertisers and
by istingray 5y ago
"Privacy is a human right" really does seem like it was only an advertising slogan.
When Apple says "privacy" they seem to have only meant from advertisers and hackers. I'm surprised and disappointed.
- jeroenhd 5y agoI've honestly always interpreted their privacy activism that way. Apple acts as the warden of your data. Backups are encrypted for your privacy, but they hold a copy of the key. Traffic is obfuscated through fake Tor, but they manage the network. iMessage seems safe enough, but the source code is tightly sealed away, only accessible to Apple's eyes. It's still a valid way to advertise the company because I trust Apple more than I trust Google or Microsoft, who are Apple's biggest competitors. I'd much rather use Apple's cloud integration than Google's or Microsoft's within their operating systems as well. But don't think they don't have any data on you. Apple knows about as much about you as Google, but Apple keeps the data to themselves instead of selling access to advertisers. Always consider the possibility that the Apple four years down the line might not have the same ideals as the Apple of today or yesterday. We've seen Microsoft slide from a "you pay money, we give you software" to a "free software if you hand us your data" model and there's no reason why Apple couldn't choose to do the same.
- istingray 5y agoWell said, appreciate the long term perspective and summary of what you see across backups, fake Tor, and closed source iMessage. Good point about changing of Apple leadership. Tim Cook has said that 10 years from now he won't be the Apple CEO. That means someone new is coming in. I purchased a Linux-first System76 laptop and will switch out my other iDevices. It's not just about Apple - any sort of closed source software/hardware just seems unsustainable long term. Having "trust" in organizations seems misplaced.
- JKCalhoun 5y agoMore than "the customer", Apple is, in the end, beholden to government and its laws, whims, etc. Until a company is more powerful than the government I'm not sure how anyone can have an absolute assurance of privacy from a corporation.
- skoskie 5y agoRegarding Apple scanning images, you actually gain more privacy than you have now. Way more. But the near-universal dislike of this initiative leads me to believe people do not understand either a) the current way in which Apple handles images and subpoena requests; or b) some aspect of the (admittedly complex) scanning implementation. But I don't know the precise area that people are getting hung up, so it's tough to address people's fear with the right facts to alleviate that fear. Hence the very one-sided, negative response to the photo scanning. That said, if you clarify where it is that you feel you will lose privacy, I will gladly try to address that for you.
- aeronaute 5y agoCan you elaborate on why you think this gives us way more privacy than we had before? I don't see how adding on-device scanning does that. I think that people generally understand what's going on and where this might lead us in the future.
- skoskie 5y agoIt's less about scanning (they were already doing that on their side) and more about keys. Before, there were two keys. The one on your device, and one for accessing the data on their servers. Apple could be compelled to decrypt that data and hand it over to the government, and the government could ask for literally anything. So all the fear about "what if they decide to scan for images of XYZ" is a fear that already exists. Apple has made it clear that they do not want to aid the government in any way, and stated so directly to congress in 2019. Congress, in turn, made it clear that if they (big tech) didn't come up with a solution, they would legislate some kind of "backdoor" requirement, which would be terrible for everyone. So they had to come up with some kind of solution that: 1. Keeps the government happy enough that they don't pass terrible legislation. 2. Keeps Apple's servers from storing illegal content. 3. Keeps Apple from being involved in the subpoena process. 4. Maintains user privacy – because that's the whole point of this exercise. I genuinely think if people understood how they accomplished this they would see that Apple accomplished two of the objectives (1, 4) and will eventually accomplish #3 as well. But back to keys. Your device has a master key for decrypting the photos, and that's always been the case. What I'm about to talk about Apple's servers only, and not your device: Imagine the two-key system required to launch a nuke, or the big Hollywood bank vault that requires two people to simultaneously get retina scans. "Shared Key Encryption" is the same idea – no one person with a key can decrypt the target. What's cool about this is you can have as many keys as you want, and all of them must be present in order to decrypt the contents. How many keys is Apple using? Well in this particular encryption layer, they are using ~31 keys, and Apple only has ONE. If we stop right there, you can already see how this is way more secure. A government cannot compel Apple to hand over your unencrypted data. Apple has been able to do this in a much simpler way for a long time, but not without causing the government to pass counter-legislation in response. They haven't implemented better security before this for that very reason. So where do the other keys come from? They are generated anytime a match is found in the CSAM database on your phone. Even that database is hashed, so your CSAM database and its hashes are unique from every other iPhone user. If there is no match with the CSAM database for a particular image, the keys for its decryption are never generated. Meanwhile each time CSAM match is made, another of the 31 keys gets generated. So in a (super over-simplified) way, the "bad" images are keys for each other. This is why Apple has set a "threshold" for how many CSAM images must be detected before Apple is notified. They have to meet that threshold in order to have all the keys to be able to decrypt all the offending images. Even then, all other images in your account still remain encrypted and inaccessible. All of this keeps the government happy enough to keep the bad legislation at bay. It's not a perfect solution, but it's better than the alternative, and it results in greater privacy than we have today. Unless/until I see technical documents showing why there is a privacy issue for people who don't have CSAM, I am 100% in favor of this solution.