10 ms·
I appreciate the explanation. However, I think you do not address the main problem, which is that my data is being sent off my device by default and without an
by Gabriel54 2y ago
I appreciate the explanation. However, I think you do not address the main problem, which is that my data is being sent off my device by default and without any (reasonable) notice. Many users may agree to such a feature (as you say, it may be very secure), but to assume that everyone ought to be opted in by default is the issue.
- sgammon 2y ago"Your data" is not actually being sent off your device, actually, it is being scrambled into completely unusable form for anyone except you. This is a much greater level of security than what you would expect from a bank, for example, who needs to fully decrypt the data you send it. When using your banking apps over HTTPS (TLS), you are trusting the CA infrastructure, you are trusting all sorts of things. You have fewer points of failure when a key for homomorphic encryption resides only on your device. "Opting-in by default" is therefore not unsafe.
- jeffybefffy519 2y agoThe big mistake here is ownership of your apple devices is an illusion...
- JustExAWS 2y agoDo you use iCloud to store your photos?
- latexr 2y agoI’m not the person you asked, but I agree with them. To answer your question: No, I do not use iCloud to store my photos. Even if I did, consent to store data is not the same as consent to scan or run checks on it. For a company whose messaging is all about user consent and privacy, that matters. This would be easily solvable: On first run show a window with: > Hey, we have this new cool feature that does X and is totally private because of Y [link to Learn More] > Do you want to turn it on? You can change your mind later in Settings > [Yes] [No]
- JustExAWS 2y agoWhen iCloud syncs between devices how do you think that happens without storing some type of metadata? You don’t use iCloud for anything? When you change phones do you start fresh or use your computer for backups? Do sync bookmarks? Browsing history? Do you use iMessage?
- Gabriel54 2y agoIn response to your question in the parent comment, no, I do not use iCloud. And I do not sync any of the things you mentioned here. If someone already consented to using iCloud to store their photos then I would not consider the service mentioned this post to be such a big issue, because Apple would already have the data on their servers with the user's consent. edit: I will just add, even if we accept the argument that it's extremely secure and impossible to leak information, then where do we draw the line between "extremely secure" and "somewhat secure" and "not secure at all"? Should we trust Apple to make this decision for us?
- 4ad 2y ago> If someone already consented to using iCloud to store their photos then I would not consider the service mentioned this post to be such a big issue, because Apple would already have the data on their servers with the user's consent. No, if you enable Advanced Data Protection for iCloud[1], the photos stored in Apple Photos are end to end encrypted. [1] https://support.apple.com/en-us/108756 https://support.apple.com/en-us/108756
- JustExAWS 2y agoDo you start fresh with an iOS installation after each upgrade or do you back up your iPhone using your computer and iTunes?
- Gabriel54 2y agoI do not have anything backed up on any cloud servers on any provider. If I had to buy a new phone I would start from a fresh installation and move all of my data locally. It's not that I'm a "luddite", I just couldn't keep track of all of the different ways each cloud provider was managing my data, so I disabled all of them.
- stackghost 2y agoI hate this type of lukewarm take. "Ah, I see you care about privacy, but you own a phone! How hypocritical of you!"
- latexr 2y agoYou’re describing Matt Bors’ Mister Gotcha. https://thenib.com/mister-gotcha/ https://thenib.com/mister-gotcha/
- JustExAWS 2y agoIf you care about your “privacy” and no external service providers having access to your data - that means you can’t use iCloud - at all, any messages service, any back up service, use Plex and your own hosted media, not use a search engine, etc.
- stackghost 2y agoDo you use a phone?
- JustExAWS 2y agoYes. I also don’t use Plex, have my own file syncing service running, run my own email server, etc. I also don’t run a private chat server that people log into - I’m like most of the iPhone and Android using world
- stackghost 2y agoMaybe lay off the sanctimonious attitude then.
- JustExAWS 2y ago[flagged]
- 2y ago
- Msurrow 2y agoI think it does address the main problem. What he is saying is that multiple layers of security is used to ensure (mathematically and theoretically proved) that there is no risk in sending the data, because it is encrypted and sent is such a way that apple or any third party will never be able to read/access it (again, based on theoretically provable math) . If there is no risk there is no harm, and then there is a different need for ‘by default’, opt in/out, notifications etc. The problem with this feature is that we cannot verify that Apple’s implementation of the math is correct and without security flaws. Everyone knows there is security flaws in all software, and this implementation is not open (I.e. we cannot review the code, and even if we could review code we cannot verify that the provided code was the code used in the iOS build). So, we have to trust Apple did not make any mistakes in their implementation.
- latexr 2y agoYour second paragraph is exactly the point made in the article as the reason why it should be an informed choice and not something on by default.
- Gigachad 2y agoIf you don’t trust Apple to do what they say they do, you should throw your phone in the bin because it has total control here and could still be sending your data even if you opt out.
- latexr 2y agoBugs have nothing to do with trust. You can believe completely that someone’s intentions are pure and still get screwed by their mistake.
- chikere232 2y agoOh yeah, the well known "blind trust" model of security. Never verify any claims of any vendor! If you don't trust them, why did you buy from them?!
- Gabriel54 2y ago
- scosman 2y agoI think I'm saying: you're not sending "your data" off device. You are sending a homomorphically encrypted locally differentially private vector (through an anonymous proxy). No consumer can really understand what that means, what the risks are, and how it would compare to the risk of sending someone like Facebook/Google raw data. I'm asking: what does an opt in for that really look like? You're not going to be able to give the user enough info to make an educated decision. There's ton of risk of "privacy washing" ("we use DP" but at very poor epsilon, or "we use E2E encryption" with side channel data gathering). There's no easy answer. "ask the user", when the question requires a phd level understanding of stats to evaluate the risk isn't a great answer. But I don't have another one.
- latexr 2y agoAsking the user is perfectly reasonable. Apple themselves used to understand and champion that approach. https://www.youtube.com/watch?v=39iKLwlUqBo https://www.youtube.com/watch?v=39iKLwlUqBo
- Gabriel54 2y agoIn response your second question, opt in would look exactly like this: don't have the box checked by default, with an option to enable it: "use this to improve local search, we will create an encrypted index of your data to send securely to our servers, etc..." A PhD is not necessary to understand the distinction between storing data locally on a machine vs. on the internet.
- detourdog 2y agoI Think the best response is make it how iCloud storage works. The option is keep my stuff on the local device or use iCloud.
- ryandrake 2y agoExactly. It's the height of arrogance to insist that normal users just can't understand such complex words and math, and therefore the company should not have to obtain consent from the user. As a normal lay user, I don't want anything to leave my device or computer without my consent. Period. That includes personal information, user data, metadata, private vectors, homomorphic this or locally differential that. I don't care how private Poindexter assures me it is. Ask. For. Consent. Don't do things without my consent!!! How hard is it for Silicon Valley to understand this very simple concept?
- brookst 2y agoNotice is always good and Apple should implement notice. However, "my data is being sent off my device" is incorrect, as GP explained. Metadata, derived from your data, with noise added to make it irreversible, is being sent off your device. It's the equivalent of sending an MD5 of your password somewhere; you may still object, but it is not factually correct to say your password was transmitted.
- amelius 2y ago> It's the equivalent of sending an MD5 of your password somewhere; you may still object, but it is not factually correct to say your password was transmitted. Hackers love to have MD5 checksums of passwords. They make it way easier to find the passwords in a brute force attack. https://en.wikipedia.org/wiki/Rainbow_table https://en.wikipedia.org/wiki/Rainbow_table
- throw0101d 2y ago>> It's the equivalent of […] > Hackers love to have MD5 checksums of passwords. Hackers love not understanding analogies. :)
- robocat 2y agoHackers love to make defective analogies (especially redundant recursive ones) and invite sarcastic corrections to them.
- icehawk 2y agoNobody responding seriously to this because you seem to have missed the part where GP said "with noise added to make it irreversible" and the third sentence in that wikipedia article.
- brookst 2y agoHackers don’t know about salts yet?
- 2y ago
- mensetmanusman 2y agoWhen your phone sends out a ping to search for cellular towers, real estate brokers collect all that information to track everywhere you go and which stores you visit. Owning a phone is a privacy failure by default in the United States.
- mike_d 2y ago> When your phone sends out a ping to search for cellular towers, real estate brokers collect all that Care to provide a pointer to what device they are using? I would absolutely get my real estate license for this.
- talldayo 2y agoYou are being downvoted because you're so painfully correct. It's not an issue exclusive to the United States, but American intelligence leads the field far-and-away on both legal and extralegal surveillance. The compliance forced by US Government agencies certainly helps make data tracking inescapable for the average American. Unfortunately, the knee-jerk reaction of many defense industry pundits (and VCs, for that matter) is that US intelligence is an unparalleled moral good, and the virtues of privacy aren't worth hamstringing our government's work. Many of these people will try to suppress comments like yours because it embarrasses Americans and American business by association. And I sympathize completely - I'm dumbfounded by the response from my government now that we know China is hacking our telecom records.
- 0points 2y agoFWIW, SS7 had known flaws very long ago. It's apparent it has been kept in place because of all of the value it provides to the 5 eyes.
- clint 2y agoDo you consider your data to include non-reversible hashes of your data injected with random noise? I'm not sure I consider that my data. Its also not even really meta-data about my data.
- kemayo 2y agoI'm not sure I agree -- asking users about every single minor feature is (a) incredibly annoying, and (b) quickly causes request-blindness in even reasonably security-conscious users. So restraining the nagging for only risky or particularly invasive things makes sense to me. Maybe they should lump its default state into something that already exists? E.g. assume that if you already have location access enabled for Photos (it does ask!), you've already indicated that you're okay with something about this identifying being sent to Apple whenever you take a picture. My understanding is that Location Services will, among other things, send a hash of local WiFi network SSIDs and signal strengths to a database Apple maintains, and use that to triangulate a possible position for you. This seems loosely analogous to what's going on here with the compute-a-vector thing.
- lapcat 2y ago> Maybe they should lump its default state into something that already exists? It could be tied to iCloud Photos, perhaps, because then you already know that your photos are getting uploaded to Apple.
- kemayo 2y agoInsofar as the photos aren't getting uploaded to Apple for this, that seems a bit extreme. (We could argue about it, but personally I think some kind of hash doesn't qualify.)
- lapcat 2y agoWhat's the Venn diagram of people who both (1) deliberately refrain from enabling iCloud Photos but nonetheless (2) want the Photos app to phone home to Apple in order to identify landmarks in locally stored photos?
- kemayo 2y agoIt's probably a pretty large set of people, perhaps even the majority, since I'd suspect that most people don't pay for additional iCloud storage and can't fit their photo library into 5GB. In fact, I'm willing to bet that if they'd added this feature and gated it behind iCloud Photos being enabled, we'd have different articles complaining about Apple making a cash grab by trying to get people to pay for premium storage. :P
- uoaei 2y agoI guess it depends on what you're calling "your data" -- without being able to reconstruct an image from a noised vector, can we say that that vector in any way represents "your data"? The way the process works, Apple makes their own data that leaves your device, but the photo never does.
- nottorp 2y agoIt's the same as the CSAM initiative. It doesn't matter what they say they send, you cannot trust them to send what they say they send or trust them not to change it in the future. Anything that leaves my devices should do so with my opt-IN permission.
- timmytokyo 2y agoEven if they implemented the feature with opt-in permissions, why would you trust this company to honor your negative response to the opt-in?
- matthewdgreen 2y agoI’m a cryptographer and I just learned about this feature today while I’m on a holiday vacation with my family. I would have loved the chance to read about the architecture, think hard about how much leakage there is in this scheme, but I only learned about it in time to see that it had already been activated on my device. Coincidentally on a vacation where I’ve just taken about 400 photos of recognizable locations. This is not how you launch a privacy-preserving product if your intentions are good, this is how you slip something under the radar while everyone is distracted.
- calf 2y agoIn engineering we distinguish the "how" of verification from the "why" of validation; it looks like much comments disagreement in this post is about the premise of whether ANY outgoing data counts as a privacy consent issue. It's not a technical issue, it's a premises disagreement issue and that can be hard to explain to the other side.
- matthewdgreen 2y agoThe premise of my disagreement is that privacy-preserving schemes should get some outside validation by experts before being turned on as a default. Those experts don’t have to be me, there are plenty of people I trust to check Apple’s work. But as far as I can tell, most of the expert community is learning about this the same way that everyone else is. I just think that’s a bad way to approach a deployment like this.
- saagarjha 2y agoApple of course thinks their internal team of experts is enough to validate this.
- makeitdouble 2y agoTo play Apple's advocate, this system will probably never be perfect, and stand up to full scrutinity from everyone on the planet. And they also need the most people possible activated as it's an adverserial feature. The choice probably looks to them like: A - play the game, give everyone a heads up, respond to all feedback, and never ship the feature B - YOLO it, weather the storm, have people forget about it after the holiday, and go on with their life. Wether B works is up to debate, but that was probably their only chance to have it ship from their POV.
- theshrike79 2y agoHow would you explain client side vectorization, differential privacy and homomorphic encryption to a layman in a single privacy popup so that they can make an informed choice? Or is it better to just trust that mathematics works and thus encryption is a viable way to preserve privacy and skip the dialog?