15 ms·
Keeping your data from Apple is harder than expected
- bdjsiqoocwk 3y agoIt's only harder than expected if youre one of those who believed them when they say that they value privacy. Otherwise it's not surprising at all.
- bell-cot 3y ago> ‘Privacy. That's Apple,’ the slogan proclaims. New research from Aalto University begs to differ. > The researchers studied eight apps: Safari, Siri, Family Sharing, iMessage, FaceTime, Location Services, Find My and Touch ID. They collected all publicly available privacy-related information on these apps... > The fragility of the privacy protections surprised even the researchers. Reaction: Either their "surprise" was purely theatrical (or journalistic gloss), or else Aalto U. needs to replace them with competent researchers. Just like a policeman who doesn't believe that anyone could really be a criminal, or a doctor who finds it unimaginable that autoimmune diseases could actually occur, or ...
- n4r9 3y agoThat's overly harsh, and a disingenuous analogy to draw.
- bell-cot 3y ago(Guessing that you are not referring to my 'Either their "surprise" was purely theatrical (or journalistic gloss)' phrase.) Do you view "university researcher" as pretty-prestigious & cool social status tier - which is provided "because they deserve it", for people who spend years grinding their way up an academic XP ladder? Or do you see "university researcher" as expense which the public pays, because it expects considerable public benefit from the supposedly-highly-skilled work which the researcher does? Complex dark patterns, default-to-share, users who just keep clinking Yes, and relentless monetization of user information have been routine & well-known things for quite a few years now.
- n4r9 3y agoI hope I wouldn't come into this with either of those preconceived notions, as it sounds like a false dichotomy. University researchers are a mixed bag; I was one myself for a brief stint in a former life. Generally speaking the vast majority of them have at least a genuine desire to advance human knowledge. > Complex dark patterns etc.. have been routine & well-known things for quite a few years now. That doesn't put some kind of ban on experts being surprised.
- VelesDude 3y agoProbably more like they were expecting better privacy practices than what Apple provided. One can be very competent but still surprised at just how bad things can be. Otherwise we would be discrediting a lot of climate researchers when they are surprised that things are progressing faster than expected.
- bell-cot 3y agoI'm thinking there's considerable difference between: - Predict that a gigacorp, which has been lucratively monetizing user information at gigascale for many years, would prove to be darn good at protecting its sources of user information. In a world where dark patterns, incomprehensible T&C's, "just say yes" user behavior, corporate misdeeds, etc. have been well-known things for many, many years. and - Predict the future of the planet's climate years ahead, when state-of-the-art weather forecasting can't yet manage 2 weeks. (Admitting that I can see a good climate researcher using "surprised" very frequently - both for public consumption, and to summarize "our very-advanced-but-usually-wrong model was wrong yet again".)
- sergioisidoro 3y agoFrom the news article I understood that this was an experimental setting, where participants were asked to perform actions in order to prevent data sharing with apple. From the news article I also interpreted that it is indeed "possible" (in the technical sense), but zero of the participants managed to get it right. Being a software engineer / computer researcher / highly technical person (which puts them / us in a technical competent bubble), it might have been an actual surprise that zero participants managed to perform the task successfully. Add to that that they might have sourced participants from the student community in a technical university, and I don't see why their surprise is "theatrical" Edit: As expected, quoting the original article: "The participants were recruited using the following methods: (1) posts on the university’s official LinkedIn page and (...) Participants represented a wide variety of educational and professional backgrounds, including Computer Science and IT, Architecture, Business Administration, Art and Design, Industrial Engineering, Economics, Research and Development, and unemployed participants (...)"
- aidos 3y agoI’m confused by the diagram. A and B appear to be early in the process but looking more carefully they’re actually pointing to steps 11 and 12. Seems a little misleading at first glance.
- Traubenfuchs 3y agoIs the whole point of all this data collection nonsense really just to serve me irrelevant ads I never click? What are they doing with all this worthless information? I downloaded a shitty freemium mobile game once and now 80% of my Instagram ads have been ads for shitty mobile games for more than a year. Is this really the best the 500k+ a year ad magicians at Meta came up with? Is this what gives Meta its trillion market cap? Just like Amazon serving me ads for washing machines, right after I bought one. And Google Maps promoting shitty restaurants and services I don't want to go to. Is this the cake apple wants a share of? I can't wrap my head around data collection.
- danielheath 3y ago> Amazon serving me ads for washing machines, right after I bought one Counterintuitive, but there’s a chance that the one you bought didn’t work out - and that’s high enough to make you much more likely than the general population to buy a washing machine. Consider: in the past 20 years there have been about two weeks (total) where an ad for a washing machine could be relevant. That’s about 0.2% of the time. If the RMA rate for new appliances is higher than .2%, that’s a useful bit of targeting information.
- alias_neo 3y agoI don't buy this; because it always happens when I've bought something from them, not from elsewhere. Amazon knows if the one I bought worked out or not because I RMAd it or didn't; yet, every time I buy something, I'm inundated with suggestions for the same thing until I've searched or bought a sufficient number of other things, to replace them, and the cycle begins again. Don't get me wrong, they have some fairly decent suggestions based on the things I browse and purchase, or browse and didn't purchase, but showing me dozens of things like the thing I just bought is hilarious.
- quesera 3y agoPeople often research replacements before they return an item. To imagine that Amazon hasn't data scienced this out, to completion, is absurd.
- threeseed 3y ago[flagged]
- throwaway290 3y agoYou have to make it sound bad or no one would read it and earn you ad revenue (edit: donations?)
- Tijdreiziger 3y agoI doubt Aalto University is hurting for money that badly.
- wasmitnetzen 3y agoAalto is a public university, and there's no ads on that page. So it's rather: You have to make it sound bad or no one would read your press release.
- em500 3y agoThen I wonder why they're setting 49 marketing cookies on that page, from - Meta Platforms, Inc. (3) - Adform (3) - Google (1) - Issuu (1) - Microsoft (16) - Quantcast (1) - Unibuddy (2) - YouTube (22)
- throwaway290 3y agoGood point
- jocaal 3y agoInformation doesn't have to be explicitly linked to a person in order to identify them. Search browser fingerprinting as an example. The best policy is really to not collect this information.
- Terretta 3y ago> The best policy is really to not collect this information. Quoting from the flowchart: "Touch ID or FacelD are stored locally and cannot be accessed by the operating system or applications." Called out as if it's a bad thing??? It's a really weird flow chart. Meanwhile, Apple did more work on differential privacy than anyone, famously sandbagging their Maps directions / routing by refusing to collect your route A to B, instead segmenting the trips and disassociating them.* Across the board, they create incredible hurdles for themselves at great expense. One wonders why, when Apple have to compete head to head with firms that do not sandbag themselves. Perhaps it's because Apple has to get most of its revenue from device sales and user subscriptions, while the others get almost all of their revenue from turning user data into ads, so they actually are fundamentally different in mindsets? * https://www.idownloadblog.com/2019/03/13/apple-maps-navigation-privacy/ https://www.idownloadblog.com/2019/03/13/apple-maps-navigati...
- walterbell 3y agoApple should provide an option to opt-out of Siri "learn from app" for ALL applications. At present, this must be done individually for every app, https://www.imore.com/how-stop-siri-learning-how-you-use-apps-iphone-and-ipad https://www.imore.com/how-stop-siri-learning-how-you-use-app.... When you later install new apps after setting up the device, you have to remember to go into Settings and opt-out again, for every app, forever. How many people know that iOS devices will default to Siri reading plaintext for all apps, including E2EE messengers?
- klausa 3y agoYou can just disable Siri if you're that concerned? Edit: Turns out — you can't! See the reply below.
- walterbell 3y agoFrom the article: The user is given the option to enable or not enable Siri, Apple's virtual assistant. But enabling only refers to whether you use Siri's voice control. Siri collects data in the background from other apps you use, regardless of your choice, unless you understand how to go into the settings and specifically change that,’ says Lindqvist.
- klausa 3y agoYou're right, I somehow missed that paragraph — I swear I read the article before commenting.
- willvarfar 3y agoNot condoning or anything, but perhaps the thinking is that, if the user can re-enabling siri at a later date, they don't want siri to start with no memory?
- walterbell 3y agoIf/when a user actively consents to "learn from app", it's no different than setting up a new device, e.g. mail downloaded from IMAP server, data transferred from old device, or from cloud services. Now imagining a EULA for Helpful Pre-Stalking..
- amelius 3y agoWhat I never understand is how engineers working at Apple think about the product they make. Can they love a device that shares data with their employer and advertisers?
- cjk2 3y agoI reckon about 1 in every 50 people I've ever worked for actually gives a shit past getting paid. That's probably where the problem lies.
- alt227 3y agoNo engineers at FAANG companies get to think, they do what the board members and execs tell them to.
- throwaway290 3y agoThat's called "Nuremberg defense". It didn't work great in the past.
- xandrius 3y agoNot a defense here, just an explanation. Also c'mon let's not compare two radically different things now.
- throwaway290 3y ago"they don't get to think" is not an explanation and can't even be true. This is not an LLM it's a real human. They do get to think. Ergo it's only an excuse/defense.
- xandrius 3y agoIf you care, either you change mind as you might lose your cushy job, or end up losing your cushy job. If you don't care then it's all good.
- throwaway290 3y ago
- raffinagita 3y ago[flagged]
- ksec 3y agoThe word privacy means so many different things to different people it is hard to discuss about it without first defining it. The word "privacy" in modern sense has been twisted to mean anonymous. So any data collection in absolute terms is an invasion of Privacy. Hence the confusion. The word "privacy" in Apple sense was that only they can collect information about you. But not any other third party without permissions. And those permission are guided by both user interest and obviously their business interest. The word "privacy" where data collected about you are randomised and profiled you to certain category of interest will be an invasion of privacy depending on which company is doing it. For Google with their replacement of Cookies it is absolutely wrong. For Apple they are protecting their customer.
- makeitdouble 3y ago> The word "privacy" in Apple sense was that only they can collect information about you That doesn't sound like anyone's definition of privacy outside of Apple. Are you positive you think this defintion isn't twisted ?
- ksec 3y agoIt is definitely twisted. When Apple collect information about you, most response were ( before the current headline ) "Oh I trust Apple so it is totally fine. Because they dont do Ads"
- Rygian 3y agoIs it PII? Yes, because it's linked to your personal Apple account, that identifies you as an individual to the data controller (Apple, as they are the ones deciding which data to collect and how it will be used). Is it pseudonymized? No Is it fully anonymized? No Is the user given transparent information about which data is collected, how it is used, for which purposes? No Is the user given the choice to object to the usage of that data? No You can't have privacy with this pattern of responses.
- arijun 3y agoIf, as another poster claimed, the data never leaves your device, you absolutely can have privacy. Some people might prefer a stricter form, but it’s not nothing.
- 23B1 3y agookay, so where are the steps?
- Am4TIfIsER0ppos 3y agoDon't purchase the surveillance device.
- wkat4242 3y agoAnd get locked out of 80% of modern life :(
- lrvick 3y agoThat is just not true. I have not carried a phone or an Google/Apple controlled device in 3+ years and exclusively use FOSS on a personal basis. I live in Silicon Valley, run a b2b tech company, have a huge group of local friends, and have never been excluded from anything I wanted in my life for not having a phone. Paper menus are available if you ask, sms can be converted to VoIP, you do not need Genie Plus to navigate Disney, there is always a way to pay with cash (or cash purchases gift card), paper tickets still work fine everywhere, your bank actually cannot force you to use an app, and internet comments and notifications can wait until you are back home at your desk. Sure, it is a bit like having a dietary restriction, but it is not the life fulfillment blocker everyone makes you think it is.
- wkat4242 3y agoHmm here in Spain it's more difficult. Nobody uses SMS here (nor iMessage), it's all WhatsApp and Telegram. And most banks do force an app here (for 2FA payments for example). Tickets can go on paper yeah, though some restaurants I visit don't do paper menus (especially the asian ones). Also some stuff for work is mobile-only. We have a stupid 2FA system that only works with a mobile app (the company gives us a phone but it does mean being tracked), and the same with the desk booking (I absolutely hate the office since we implemented flexdesks). Cash is still common here yeah though I don't like dealing with it. I wish there was a mobile payment method that didn't rely on Apple or Google.
- Doctor_Fegg 3y ago> Content blocker prevented frame displaying https://www.aalto.fi/en/news/keeping-your-data-from-apple-is-harder-than-expected https://www.aalto.fi/en/news/keeping-your-data-from-apple-is... from loading a resource from https://www.aalto.fi/modules/contrib/google_tag/js/gtm.js https://www.aalto.fi/modules/contrib/google_tag/js/gtm.js?[...] Sigh. People who live in glass houses, etc.
- devaiops9001 3y agohttps://grapheneos.org/features https://grapheneos.org/features
- lrvick 3y agoRemember that this too ships a huge number of privileged binary blobs and kernel modules from companies like Qualcomm and Google in the vendor partition. Whoever compiles these binary blobs, and the OS images themselves, and anyone capable of coercing them, has god access to your device. I suggest getting to know someone before giving them that much power over your life.
- fh9302 3y agoThis article is highly misleading, making it sound like Siri is collecting data from apps and sending it to Apple. This is not the case, Siri Suggestions are fully on-device, though they can sync accross devices with mandatory E2EE. Apple never gets access to any of this data.
- lrvick 3y agoApple can remotely execute code on any internet connected device running an proprietary Apple operating system. It is only a matter of time before courts realize this. The CCP controls the Apple software signing HSMs in China for a reason.
- madeofpalk 3y agoBut if this is your threat model - that you have no trust of the operating system or the vendor - then all of this is pointless because at any time they can just backdoor themselves. Apple could just never ask or collect this, but still they're one update away from starting to collect it. Of course that's always a threat with any computer, but you must place some amount of trust somewhere.
- eviks 3y ago> from starting to collect it. So even then they would have no data before that point!
- lrvick 3y agoIf Apple did not collect the data today, then a court order in the future will not allow them to collect data that was not stored today. Personally I only use reproducibly built FOSS software and I isolate most of my hardware and workloads from each other with virtual machines via QubesOS. Proprietary software is not at all required to be well integrated into modern society.
- deleted 3y ago[deleted]
- lrvick 3y agoI remain shocked anyone trusts Meta, Google, or Apple marketing on privacy. These companies are all fundamentally similar in that their proprietary software collects an insane amount of data that will end up in the hands of your enemies either by sale, court order, or security compromise. It is relatively easy to opt out of all of these companies and take some actual control over your privacy.
- tremarley 3y agoApple’s PR team is remarkable. They get away with nearly everything
- jzzskijj 3y agoWhat is the easiest way to get comparable smartphone experience with some actual control over your privacy?
- sebtron 3y agoYour choices are very limited, but you can get an android phone supported by LineageOS or other alternative roms.
- jzzskijj 3y agoI have tried, a long time ago, LineageOS on Samsung Galaxy S3 and S4. The both of the ports were so buggy, that by those experiences I could not trust the maintainers to be capable of securing the system. It may have been a false assumption, but I had to think stability/bugs and security must correlate at some levels.
- lrvick 3y agoActually if you link popular software with a hardened memory allocator, apps will just crash a lot instead of allowing buffer overflows that are shockingly common. YOLO mallocs most operating systems ship allow an application to -feel- faster and more stable at the expense of security. If you want software to be stable in a strict malloc environment, write it in rust :) To be fair though, LineageOS security is actually terrible. Do not use it. If you must have an Android device CalyxOS is the least bad option today.
- poochkoishi728 3y agoAlways wanted the option to disable network access for an app. The lack of this made me suspect that Apple had too much to lose (in harvesting data) to allow this.
- geokon 3y agoAndroid has this in the app manifest, but of course Google doesn't expose this to users Are they're any ROMs that do?
- aembleton 3y agoI used to be able to on ArrowOS, LineageOS and I think on MIUI. Its been a few years since I gave up on custom roms though, so it may no longer be the case.
- folmar 3y agoOn Android it is typically done with a firewall app, like AFWall+
- switch007 3y agoGrapheneOS does Every app you install with Play Store pops up and asks if you want to grant it networking. It's cool
- walterbell 3y agoiOS has a "Local Network" Setting for some apps, e.g. VLC, PhotoSync.
- Angostura 3y agoThat's for apps that request the additional ability to poke about in the local network to look for e.g streaming devices or other devices to control
- flemhans 3y agoLittle Snitch is the best I found although not perfect. (Apps can trivially bypass filtering)
- worldwidelies 3y agoSomeone much more tech savvy than me should try to use Charles Proxy on an iOS device and see how often your phone is communicating with Apple servers. It’s pretty wild.
- JKCalhoun 3y agoIt is wild but not entirely for the reasons someone might think. I think everyone knows that a good part of the Apple app ecosystem relies on syncing data. I don't think anyone is surprised that a daemon is syncing your photos between your devices/cloud. Add podcasts, ePubs, etc. and you're going to have a busy network on your device. It's a reason in fact I use the cloud, sign in with my Apple ID. I can lose my machine but not my documents. Maybe the thing that is more along the lines of what you're suggesting though is the network traffic that is seemingly less useful to the user (but useful to Apple). Various frameworks have appeared on the OS that allow apps to share analytics (pretty sure though these are the analytics that you are asked if you want to opt out of on an install/setup). But because it has become so easy to do (in part because there is a framework to handle it, but also just the ubiquity of the presence of a network) lots of, I think, dumb data is collected to no doubt satisfy management/design as to whether some feature of an app is being used or is not being discovered. The ubiquity as I say has made it too darn tempting for all parties (Apple and 3rd) to become lazy about how their apps are being used and to become too data hungry themselves. I had someone recently ask me how I get feedback from my blog posts since there is no comment section, no analytics .... they wondered why I bother blogging at all.
- xandrius 3y agoDoes that include things like communicating with Apple APNS? If so then I'm not surprised at all.
- HnUser12 3y agoYou can actually see the domains being contacted in the app privacy report. I’m not sure if it includes the OS level connections, but it includes for all apps, including Apple apps.
- 3y ago
- rcarmo 3y agoFor privacy-conscious people, the authors certainly picked an outlet with plenty of cookies and trackers - this is what the popup shows me when I pick "customise": 17 necessary cookies 7 functional 34 statistics 49 marketing 10 unclassified This kind of thing makes the article seem... ridiculous, really. Their site is much worse at privacy than Apple.
- nicce 3y agoNot their fault to be fair. Blame management of Aalto University.
- AlecSchueler 3y agoWho is "management?" The author of the article is listed as the university's communications manager so they wouldn't be totally without a voice in these decisions.
- nicce 3y agoIt can get quite high in the chain. This is a financial decision - extract value (money) with the cost of other values (principles) and users' privacy.
- krapp 3y agoThe authors appear to be associated the university which hosts the site. I doubt they are responsible for the engineering decisions behind the site, or that they "picked the outlet" per se. Authors tend not to have carte blanche control over the platforms on which they publish. I don't know why you would judge the content of the article based on that, rather than its own merits, particularly given that the subject of the article isn't the security of web pages or cookies. If anything, what the article does discuss has far more egregious security implications than website cookies.
- rcarmo 3y agoThe article also has a number of incorrect assumptions regarding how Siri works and what kind of data Apple collects. They do not mention Apple's differential privacy approach, for instance, nor do they seem aware of many iOS improvements in that regard over the past few years. So I don't really consider it a thoroughly researched piece...
- traceroute66 3y ago"Lindqvist can’t comment directly on how Google's Android works in similar respects" Of course he can't, because its easier to jump on the Apple bashing bandwagon. I suspect if you did a side-by-side comparison, we all know where Android would fall on the privacy spectrum. Give me Apple over Google any day of the week. I expected better from Lindqvist than take part in a biased article like that.
- rcarmo 3y agoAn article on Android security would both be much longer and have much less media attention.
- sensanaty 3y agoOr how about we stop excusing megacorps altogether and stomp them both down? This isn't a football team type of competition, its 2 megacorporations that don't give a shit about you and they both deserve to be strangled into submission so that their whole business model doesn't hinge on mass surveillance.
- jasonlotito 3y agoSomeone can be the best at something and still need improvement. Just look at Apple every year working to improve security. Rather than just assume everything is fine, it's important to call out deficiencies. Especially when someone is seen as the best at something. Being the best doesn't mean you are good. It just means everyone else is worse.
- Argonaut998 3y agoIt has already been done[1] and the conclusion is that Apple is not much/no better than Google. When it comes to user data I do believe that Apple is better due to Google’s revenue being from advertisements. Yet Apple has begun exploring this space and at that point I consider them as bad as each other. [1] https://www.scss.tcd.ie/doug.leith/apple_google.pdf https://www.scss.tcd.ie/doug.leith/apple_google.pdf
- sebtron 3y ago[flagged]
- Terretta 3y agoThis is a weird flowchart, calling things out weirdly, like “Touch ID or FacelD are stored locally and cannot be accessed by the operating system or applications.” as if that's a negative? Since they call it out in the article as well, I really want to understand the "fragility of the privacy protections" on TouchID.
- rcarmo 3y agoThat's a great callout. TouchID data never leaves the Secure Enclave, so wondering about privacy implications of that is just ridiculous.
- Angostura 3y agoI don't think Apple's UX for enabling privacy is half as confusing as that "diagram" in the article.
- flemhans 3y agoTry and have little snitch running without the default suggestion to whitelist Apple services. It's mind-blowing.
- instagib 3y agoIf I remember correctly, segregating Apple devices from other devices via subnetting or otherwise causes them to incessantly ping Apple servers and cause issues on network/device.
- mixmastamyk 2y agohttps://sneak.berlin/20210202/macos-11.2-network-privacy/ https://sneak.berlin/20210202/macos-11.2-network-privacy/
- nehal3m 3y agoI go through this annoying oscillating struggle every time I read news like this: 1. Realise the Apple hard- and software I'm using sucks privacy wise 2. Compare open source alternatives, maybe switch (I have an iPhone and a Fairphone 4 with /e/OS, also a MacBook and a homebrew Linux PC) with a file- and photo export through my NAS. 3. Use the FOSS ecosystem for a bit, be annoyed at some jank, slowly realise that while unquestionably better privacy wise, it's not necessarily better security wise. 4. Miss real life document management (I scan files, apply OCR). MacOS/Spotlight makes it possible to treat my collection as a database rather than a file cabinet that way, Continuity makes it easy to scan. 5. Switch back, rinse and repeat. I'm driving myself insane. It's always either feeling great about my privacy and sacrifice convenience (I mean, FOSS can probably host that same workflow, it's just that it's a lot more work up front and I'm the one responsible if it breaks) or feeling great about how my stuff works but feeling creeped out about being spied on.
- deleted 3y ago[deleted]