3 ms·
I don't want my photos to take part in any network; never asked for it, never expected it to happen. I never used iCloud or other commercial cloud providers. Th
by gigel82 2y ago
I don't want my photos to take part in any network; never asked for it, never expected it to happen. I never used iCloud or other commercial cloud providers. This is just forceful data extraction by Apple, absolutely egregious behavior.
- oneplane 2y agoYour photos aren't taken. Did you read the article at all?
- gigel82 2y agoThe "network" mention was in reply to your comment about "participating in a network" which was never the case for one's personal photos (unless explicitly shared on a social network I guess). I did read the article, yes :) Maybe our photos are not sent bit-by-bit but enough data from the photos is being sent to be able to infer a location (and possibly other details) so it is the same thing: my personal data is being sent to Apple's servers (directly or indirectly, partially or fully) without my explicit consent. At least the last time they tried to scan everyone's photos (in the name of the children) they pinky promised they'd only do it before uploading to iCloud, now they're doing it for everyone's photos all the time - it's disgusting.
- oneplane 2y agoNo, your photos aren't sent, also not 'pieces' of it. They are creating vector data which can be used to create searchable vectors which in turn can be used on-device to find visual matches for your search queries (which are local). You can imagine it as hashes (created locally), some characters of that hash from some random positions being used to find out if those can be turned into a query (which is compute intensive so they use PCC for that). So there is no 'data' about what it is, where it is or who it is. There isn't even enough data to create a picture with. Technically, everything could of course be changed, heck, Apple could probably hire someone with binoculars and spy on you 24/7. But this is not that. Just like baseband firmware is not that, and activation is not that, yet using them requires communication with Apple all the same.
- jazzyjackson 2y agoMy understanding as the blog laid it out was that the cloud service is doing the vector similarity search against a finite database of landmark feature vectors, but they are performing that mathematical function under homomorphic encryption such that the result of the vector comparison can only be read with a key that never left your device, so it's just adding a tag "Eiffel tower" that only you see, but the feature vector is sent off device, it's just never able to be read by another party.
- oneplane 2y agoYep. It's essentially an implementation of remote attestation "the other way around". Normally the edge device is untrusted and needs to attest a variety of things before compute is done and the result is accepted, but PCC is the other way where the edge device holds the keys (technically octagon works that out, but it's backed by the on-device SEP). So it does it multiple ways: - Finite sets and added noise, doesn't hurt performance too much but does make it nearly impossible to ID/locate a photo - Encryption at rest and in transit - Transit over hops they don't own - Homomorphic Encryption during remote compute The data it finds was available in two ways: the "result" and the vector embedding. Not sure which one you end up consuming since it also has to work on older models that might not be able to load the embeddings and perform adequately, but it doesn't matter since the data itself will be unique so you can't do parallel reconstruction, but it is also uniquely meaningless to anyone without a key. They are essentially computing on needles that aren't in a haystack, but in a needle stack. The primitives all this is built on have been around for quite a while, including their HBONE implementation, the cryptographically hidden data distribution and the SEP. So far, it has been the only one of its kind outside of disjointed options like buying and operating your own HSM, a large TOR network and a yet to-be-invented self-hosted PCC solution (AMD was supposed to release something but they failed at that, just not as bad as Intel messed up with SGX). Technically, even with everything else removed, just some good TLS 1.2+ and homomorphic encryption would have been more than any other mass market manufacturer has ever done in an effective way. But by adding the additional factors such as degrees of separation so they couldn't get in themselves (without breaking it for everyone in the process) is what makes this so much more robust.
- cortesoft 2y agoThen don't enable this feature?
- layer8 2y agoThe article and this whole thread is about the fact that the feature is enabled by default without notifying the user that the feature even exists.