5 ms·
That's not the point of the outrage though (at least not for me). They enabled by default a feature that analyzes my pictures (which I never upload to iCloud) a
by gigel82 2y ago
That's not the point of the outrage though (at least not for me). They enabled by default a feature that analyzes my pictures (which I never upload to iCloud) and sends information about them to their (and others') servers. That is a gross violation of privacy.
To be clear, I don't care about any encryption scheme they may be using, the gist is that they feel entitled to reach into their users' most private data (the photos they explicitly said they don't want to upload to iCloud) and "analyze" them.
This is the same as that time Microsoft enabled OneDrive "by mistake" and started slurping people's private documents and photos saved in default locations (arguably worse since no one takes pictures with their PC's webcams).
- supriyo-biswas 2y agoIf the data is encrypted, does the concern still apply? You bring up the example of Onedrive, but there is no use of e2e encryption or HE techniques there.
- gigel82 2y agoYes, of course, the concern is the data being exfiltrated to begin with. Like someone else in this thread mentioned, if they upload a single pixel from my image without my consent, that is too much data being uploaded without my consent.
- scratchyone 2y agoIf they sent a completely randomly generated integer from your phone without consent, would that be okay with you? Genuine question.
- JTyQZSnP3cQGa8B 2y ago> If they sent [...] without consent, would that be okay with you? No. That would never be acceptable to me.
- amiga386 2y agoI'm not who you asked, but no, I wouldn't be. I'd want an explanation of why they want to send this data. They need to seek informed consent, and the default needs to be no data collection. Opt-in, not opt-out. If I do opt-in, I can withdraw that consent at any time. I can also expect them to delete any collected data within a reasonable (to me) time frame, tell me what they do with it, who they share it with, supply me with any personally identifying data they have colllected, and allow me to correct it if it's wrong. And if they use the data to make important decisions automatically, e.g. bank loan yes/no, I have the right to make them use human reasoning to reconsider. There is no reason to let businesses non-consensually collect any data from you, even if that's their entire business model. Don't let their self-serving lies about "you can trust us" or "it's normal and inevitable" swindle you out of your privacy. Incidentally,"a completely randomly generated integer" could describe Apple's Advertising Identifier, which allows third parties to track the bejesus out of you.
- isodev 2y ago> does the concern still apply? Yes it does and the blogpost specifically explains why. In short, both iOS and macOS are full of bugs, often with the potential of exposing sensitive information. Also, it’s on by default - nobody in their sane mind would have bits of their photos uploaded somewhere, regardless of “we promise we won’t look”. Finally, Photos in iOS 18 is such a bad experience that it seems the breach of privacy was fundamentally unjustified as no meaningful improvement was introduced at all.
- Thorrez 2y ago>regardless of “we promise we won’t look”. AIUI, even if Apple's servers tried to look, they cannot, because of the encryption.
- isodev 2y agoEncryption does not automatically mean secure. Encryptions can and will be broken. Any flaw in their implementation (which nobody can verify) would render encryption useless…
- supriyo-biswas 2y agoI wonder where you'd draw the line. Do you also distrust TLS for example, and therefore refuse to use the internet? What about AES/Chacha for full-disk encryption?
- isodev 2y agoThe line is very simple - my content stays on device, secured (locally) with the current modern and practical tools.
- Thorrez 2y agoSure, but it's more than a promise that they won't look. Apple currently believes it's impossible to look.
- jchw 2y ago> If the data is encrypted, does the concern still apply? Yes! For so many reasons! If an adversary is able to intercept encrypted communications, they can store it in hopes of decrypting it in the future in the event that a feasible attack against the cryptosystem emerges. I don't know how likely this is to happen against homomorphic encryption schemes, but the answer is not zero. I'm not suggesting everyone should spend time worrying about cryptosystems being cracked all day long, and I'm not saying Apple's encryption scheme here will prove insecure. Even if this particular scheme is cracked, it's very possible it won't reveal much of great interest anyways, and again, that is simply not the point. The point is that the correct way to guarantee that your data is private is to simply never transmit it or any metadata related to it over a network in any form. This definitely limits what you can do, but it's a completely achievable goal: before smartphones, and on early smartphones, this was the default behavior of taking pictures with any digital camera, and it's pretty upsetting that it's becoming incredibly hard to the point of being nearly impractical to get modern devices to behave this way and not just fling data around all over the place willy-nilly. And I know people would like Apple to get credit for at least attempting to make their features plausibly-private, but I feel like it's just the wrong thing right now. What we need today is software that gives agency back to the user, and the first part of that is not sending data off to the network without some form of user intent, without dark patterns to coerce said intent. At best, I can say that I hope Apple's approach to cloud services becomes the new baseline for cloud services, but in my opinion, it's not the future of privacy. The future of privacy is turning the fucking radio off. Why the fuck should we all buy mobile devices with $1000 worth of cutting edge hardware just to offload all of the hard compute problems to a cloud server? I'd also like to ask a different question: if there's no reason to ever worry about this feature, then why is there even an option to turn it off in the first place? I worry that what Apple is really doing with pushing out all these fancy features, including their maligned CSAM scanning initiative, is trying to get ahead of regulations and position themselves as the baseline standard. In that future, there's a possibility that options to turn off features like these will disappear.
- sgammon 2y ago> And I know people would like Apple to get credit for at least attempting to make their features plausibly-private, but I feel like it's just the wrong thing right now. Appeal to bandwagon; opinion discarded
- s3p 2y agoIf you really didn't want your photos to be analyzed, would you be using an iPhone? Or any modern smartphone? Google photos doesn't have nearly the privacy focus and no HE whatsoever but I rarely see that mentioned here. It almost seems like Apple gets held to a higher standard just because they have privacy preserving initiatives. Do you use a keyboard on your iphone? You may not have heard but apple is tracking which emojis you type most often [0] and they get sent to apple servers. [0] https://www.apple.com/privacy/docs/Differential_Privacy_Overview.pdf https://www.apple.com/privacy/docs/Differential_Privacy_Over...
- ctxc 2y agoLike parent mentioned - I don't upload photos to Google photos, assume parent doesn't upload photos to iCloud. Should photo info be sent to Apple/Google in this case?
- WA 2y ago> Google photos doesn't have nearly the privacy focus and no HE whatsoever but I rarely see that mentioned here. It almost seems like Apple gets held to a higher standard just because they have privacy preserving initiatives. What is so surprising about this? If you make big claims about anything, you are held to your own standards.
- dwaite 2y ago> It almost seems like Apple gets held to a higher standard just because they have privacy preserving initiatives It doesnt' seem this way at all. It is rare to see someone talking about current behavior, they are always talking about the slippery slope - such as landmark detection obviously being the first step in detecting propaganda on a political dissident's phone. This isn't driven by trying to hold them to a higher standard; it is an emotional desire of wanting to see them caught in a lie.