7 ms·
As someone with a background in mathematics I appreciate your point about cryptography. That said, there is no guarantee that any particular implementation of
by Gabriel54 2y ago
As someone with a background in mathematics I appreciate your point about cryptography. That said, there is no guarantee that any particular implementation of a secure theoretical algorithm is actually secure.
- threeseed 2y agoThere is also no guarantee that Apple isn't lying about everything. They could just have the OS batch uploads until a later point e.g. when the phone checks for updates. The point is that this is all about risk mitigation not elimination.
- dylan604 2y ago> There is also no guarantee that Apple isn't lying about everything. Other than their entire reputation
- lispm 2y agoA reputation has to be earned again and again.
- echelon 2y agoMaybe your threat model can tolerate an "oopsie woopsie". Politically exposed persons probably cannot.
- parasubvert 2y agoIf you don't personally write the software stack on your devices, at some point you have to trust a third party.
- lispm 2y agoI would trust a company more if their random features sending data are opt-in. A non-advertized feature, which is not independently verified, which about image contents? I would be prefer independent verification of their claims.
- freedomben 2y agoAgreed, but surely you see a difference between an open source implementation that is out for audit by anyone, and a closed source implementation that is kept under lock & key? They could both be compromised intentionally or unintentionally, but IMHO one shows a lot more good faith than the other.
- bolognafairy 2y agoNo. That’s your bias as a nerd. There are countless well-publicised examples of ‘many eyeballs’ not being remotely as effective as nerds make it out to be.
- jrvieira 2y agocan you provide a relevant example for this context?
- dylan604 2y agoHow long did the log4j exist? https://www.csoonline.com/article/571797/the-apache-log4j-vulnerabilities-a-timeline.html https://www.csoonline.com/article/571797/the-apache-log4j-vu... What was the other package that had the mysterious .?
- timschmidt 2y agoAnd yet they were found. How many such exploits lurk unexamined in proprietary codebases?
- dylan604 2y agoyet you say this like Apple or Google or Microsoft has never released an update to address a security vuln
- timschmidt 2y ago
- beeflet 2y agoThe developer-to-user trust required in the context of open-source software is substantially less than in proprietary software. this much is evident.
- fijiaarone 2y agoI’m stealing your information. Hey! That’s wrong. But I promise I won’t do anything wrong with it. Well ok then.
- bolognafairy 2y agoThis is still a very dishonest representation of what’s actually happening.
- kalleboo 2y ago> There is also no guarantee that Apple isn't lying about everything. And at that point all the opt-in dialogs in the world don't matter and you should not be running iOS but building some custom Android ROM from scratch.