27 ms·
Could you elaborate a bit on why you've judged it as privacy theatre? I'm skeptical but uninformed, and I believe Mullvad are taking a similar approach.
by ysnp 9mo ago
Could you elaborate a bit on why you've judged it as privacy theatre? I'm skeptical but uninformed, and I believe Mullvad are taking a similar approach.
- tempodox 9mo agoThe gov’t can force them to reveal any user’s data and slap them with a gag order so no one will ever know this happened.
- MontyCarloHall 9mo agoAll user data is E2E encrypted, so the government literally cannot force this. This has been the source of numerous disputes [0, 1] that either result in the device itself being cracked [0] (due to weak passwords or vulnerabilities in device-level protection) or governments attempting to ban E2E encryption altogether [1]. [0] https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_dispute https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_d... [1] https://en.wikipedia.org/wiki/Crypto_Wars https://en.wikipedia.org/wiki/Crypto_Wars
- greentea23 9mo agoWhat you cited is for data on a device that was turned off. Not daily internet connected usage. No one is saying you have no protection at all with Apple, it is just very limited compared to what it should be by modern security best practices, and much worse than what can be achieved on android and linux.
- nozzlegear 9mo ago> much worse than what can be achieved on android and linux. * Certain types of Android
- mmh0000 9mo agoMaybe E2E, but the data eventually has to be decrypted to read it. Then you learn that every modern CPU has a built-in backdoor, a dedicated processor core, running a closed-source operating system, with direct access to the entire system RAM, and network access. [a][b][c][d]. You can not trust any modern hardware. https://en.wikipedia.org/wiki/Intel_Management_Engine https://en.wikipedia.org/wiki/Intel_Management_Engine https://en.wikipedia.org/wiki/AMD_Platform_Security_Processor https://en.wikipedia.org/wiki/AMD_Platform_Security_Processo... https://en.wikipedia.org/wiki/ARM_architecture_family#Security_extensions https://en.wikipedia.org/wiki/ARM_architecture_family#Securi... https://en.wikipedia.org/wiki/Security_and_privacy_of_iOS https://en.wikipedia.org/wiki/Security_and_privacy_of_iOS
- dmitrygr 9mo agoSome of those things are not like the others. TrustZone is not a dedicated core. It is a mode of the CPU, akin to x86's SMM
- natch 9mo agoE2E encrypted is nothing if key escrow is happening. Why did they change their wording from: Nobody can read your data, not even Apple to: Apple cannot read your data. You know why.
- nozzlegear 9mo agoIf they didn't want you to think key escrow might be possible, why wouldn't they just leave the wording the way it was? Why go through the effort and thereby draw attention to it? The court system doesn't use sovcit rules where playful interpretation of wording can get a trillion dollar corporation out of a lawsuit or whatever.
- ajam1507 9mo agoWhen did they change their wording?
- hbs18 9mo agoIt's a warrant canary, https://en.wikipedia.org/wiki/Warrant_canary https://en.wikipedia.org/wiki/Warrant_canary
- drnick1 9mo agoBecause Apple makes privacy claims all the time, but all their software is closed source and it is very hard or impossible to verify any of their claims. Even if messages sent between iPhones are E2EE encrypted for example, the client apps and the operating system may be backdoored (and likely are). https://en.wikipedia.org/wiki/PRISM https://en.wikipedia.org/wiki/PRISM
- greentea23 9mo agoMullvad is nothing like Apple. For apple devices: - need real email and real phone number to even boot the device - cannot disable telemetry - app store apps only, even though many key privacy preserving apps are not available - /etc/hosts are not your own, DNS control in general is extremely weak - VPN apps on idevices have artificial holes - can't change push notification provider - can only use webkit for browsers, which lacks many important privacy preserving capabilities - need to use an app you don't trust but want to sandbox it from your real information? Too bad, no way to do so. - the source code is closed so Apple can claim X but do Y, you have no proof that you are secure or private - without control of your OS you are subject to Apple complying with the government and pushing updates to serve them not you, which they are happy to do to make a buck Mullvad requires nothing but an envelope with cash in it and a hash code and stores nothing. Apple owns you.
- MrDarcy 9mo agoThis comment confuses privacy with anonymity.
- whilenot-dev 9mo agoAnonymity is an inherent measure to preserve ones individual privacy. What value did you intent to add with your remark?
- greentea23 9mo agoNot for all points. And not being anonymous means your identity is not private...
- asadotzler 9mo agoAnonymity is a critical aspect of privacy. If you cannot prevent your name being associated with your data, you do not have real privacy.
- Melatonic 9mo agoAgreed on most points but you can setup a pretty solid device wide DNS provider using configuration profiles. Similar to how iOS can be enrolled in work corporate MDM - but under your control. Works great for me with NextDNS. Orion browser - while also based on WebKit - is also awesome and has great built in Adblock and supposedly privacy respecting ideals.
- natch 9mo agoThey transitioned from “nobody can read your data, not even Apple” to “Apple cannot read your data.” Think about what that change means. And even that is not always true. They also were deceptive about iCloud encryption where they claimed that nobody but you can read your iCloud data. But then it came out after all their fanfare that if you do iCloud backups Apple CAN read your data. But they aren’t in a hurry to retract the lie they promoted. Also if someone in another country messages you, if that country’s laws require that Apple provide the name, email, phone number, and content of the local users, guess what. Since they messaged you, now not only their name and information, but also your name and private information and message content is shared with that country’s government as well. By Apple. Do they tell you? No. Even if your own country respects privacy. Does Apple have a help article explaining this? No.
- dpoloncsak 9mo ago>Also if someone in another country messages you, if that country’s laws require that Apple provide the name I don't mean to sound like an Apple fanboy, but is this true just for SMS or iMessage as well? It's my understanding that for SMS, Apple is at the mercy of governments and service providers, while iMessage gives them some wiggle room. Ancedotal, but when my messages were subpoenaed, it was only the SMS messages. US citizen fwiw
- threatofrain 9mo agoIf you want to turn on full end-to-end encryption you can, if you want to share your pubkey so that people can't fake your identity on iMessage you can, and there's still a higher tier of security than that presumably for journalists and important people. It's something a smart niece or nephew could handle in terms of managing risk, but the implications could mean getting locked out of your device which you might've been using as the doorway to everything, and Apple cannot help you.
- classicsc 9mo ago[dead]
- richwater 9mo agoYou people will never be happy until the only messaging that exists is in a dusty basement and Richard Stallman is sleeping on a dirty futon.