6 ms·
What makes you think that internal access control at Apple is any better than Google's, Microsoft's or OpenAI's? Google employees have long reported that you ca
by chem83 2y ago
What makes you think that internal access control at Apple is any better than Google's, Microsoft's or OpenAI's? Google employees have long reported that you can't access user data with standard credentials, for example.
Also, what makes you think that Apple's investments on chip design and OS is superior to Google's? Google is known for OpenTitan and other in-house silicon projects. It's also been working in secure enclave tech (https://news.ycombinator.com/item?id=20265625 https://news.ycombinator.com/item?id=20265625), which has been open-source for years.
You're making unverifiable claims about Apple's actual implementation of the technical systems and policies it is marketing. Apple also sells ads (App Store, but other surfaces as well) and you don't have evidence that your AI data is not being used to target you. Conversely, not all user data is used by Google for ad targeting.
- theshrike79 2y ago> What makes you think that internal access control at Apple is any better There are multiple verified stories on the lengths Apple goes internally to keep things secret. I saw a talk years ago about (I think) booting up some bits of the iCloud infrastructure, which needed two different USB keys with different keys to boot up. Then both keys were destroyed so that nobody knows the encryption keys and can't decrypt the contents.
- padolsey 2y agoWhat's funny is that, in all these orgs, it ends up being the low-tech vulns that compromise you in the end. Physical access, social engineering, etc. However, I'm really impressed by the technical lengths Apples goes to though. The key-burning thing reminds me of ICANN' Root KSK Ceremonies.
- p_l 2y agoThe stories about Apple keeping things secret usually go about protecting their business secrets from normal people, up to doing probably illegal actions. Using deniable, one-time keys etc. are... not that unusual. In fact I'd say I'm more worried about the use of random USB keys there instead of proper KMS system. (There are similar stories with how doing a cold start can be difficult when you end up with a loop in your access controls, from Google, where a fortunately simulated cold-start showed that they couldn't access necessary KMS physically to bootstrap the system... because access controls depended, after many layers, on the system to be cold-started).
- milkshakes 2y agothey used smartcards, not usb keys
- p_l 2y agoWhich probably were just key transport devices from offline secured KMSes
- treprinum 2y agoDestroyed? Where? In all places where they were stored? Or just in some of them? How can you tell? You still need to trust them they didn't copy them somewhere.
- theshrike79 2y agoIt's impossible to use any technology if you don't trust anyone. Any piece of technology MAY have a backdoor or secondary function you don't know of and can't find out without breaking said device.
- treprinum 2y agoThat was the point of my response. Somewhere in the chain one must trust something without any proof.
- Spooky23 2y agoIt’s not about technology. It’s about their business. Apple generally engineers their business so that there isn’t an incentive to violate those access controls or principles. Thats not where the money is for them. Behavior is always shaped by rewards and punishments. Positive reinforcement is always stronger.
- whynotminot 2y agoOne hundred percent this. All these conversations always end up boiling down to someone thinking they’re being clever for pointing out you have to trust a company at the end of the day when it comes to security and privacy. Yes. Valid. So if you have to trust someone, doesn’t it make sense for it to be someone who has built protecting privacy into their core value proposition, versus a company that has baked violating your privacy into their value prop?
- TremendousJudge 2y agoThat's a false dichotomy. You may have to trust someone but that someone could be something else than an opaque for-profit company.
- whynotminot 2y agoGive me some examples of benevolent non profits that provide anywhere near the level of consumer services as a company like Apple.
- talldayo 2y agoI'll do better, here's a benevolent nonprofit that goes beyond what Apple provides to ensure top-notch consumer service: https://grapheneos.org/ https://grapheneos.org/
- talldayo 2y agoIt's not about being clever, it's about being perceptive. Apple's cloud commitment has a history of being sketchy, whether it's their government alliance in China, the FIVE-EYES/PRISM membership in America, or their obsession with creating "private" experiences that rely on the benefit of the doubt. Apple doesn't care about you, the individual. Your value as a singular customer is worthless. They do care about the whole; a whole that governments can threaten to exclude them from if they don't cooperate with domestic surveillance demands. How far off do you really think American iCloud is from China? If Apple is willing to backdoor one server, what's stopping them from backdooring them all? If they're willing to lie about notification security, what's stopping them from lying about server integrity too? And worst off, Apple markets security. That's it; you can't go verify their veracity outside the dinky little whitepapers they publish. You can't know for sure if they have privacy violation baked-in to their system because you can't actually verify anything. You simply have to guess, and the best guess you can make gets based off whatever Apple markets as "true" to you. In reality, we can do better with security and should probably expect more from one of the largest consumer technology brands in the world. Simply assuming that they aren't violating user privacy is an absurd thing to gamble your security on.
- cdata 2y agoThat's not even getting to the fact that Apple is also running a display ads business: https://searchads.apple.com/ https://searchads.apple.com/
- woadwarrior01 2y agoIndeed. Apropos to this: new features[1] to insert ads into videos in native apps. [1]: https://developer.apple.com/videos/play/wwdc2024/10114/ https://developer.apple.com/videos/play/wwdc2024/10114/
- musictubes 2y agoSuch a lazy take. Yes, they show ads based on what you search for in the App Store. They will also show apps based on location if the customer opts in to that feature. No other data is used. No browsing history, no purchase history, nothing like what other companies are collecting. https://searchads.apple.com/privacy https://searchads.apple.com/privacy
- cdata 2y agoEventually the addressable market for iPhones will saturate, but the growth imperative will remain. If I were king of Apple and I truly valued user privacy, I would be careful not to tie any revenue streams to products that entail the progressive violation of user privacy.
- deleted 2y ago[deleted]
- mbs159 2y agoGlancing at your comment history I can't help but notice that most of your comments are related to defending Apple, even at points where the consensus on HN is that Apple is obviously in the wrong. I applaud you, sir.