Live data from Hacker News

Apple’s approach to privacy

apple.com

31–40 of 172 posts

Re: Apple’s approach to privacy

#31
post #9

It's a shame the options to disable sending your local spotlight queries to bing and apple are hidden away in a huge list of other apps. I wish they had one giant button for disabling all remote queries instead of 4-5 options spread throughout different settings sub-pages.

I still don't know which setting actually disables that.

Re: Apple’s approach to privacy

#32
post #4
post #3

I'll take them more seriously when they stop voluntarily giving the NSA zero-day vulnerabilities months before they get fixed, essentially giving them "temporary backdoors" to their systems.

Source?

Stuff like gotofail took a while to get patched (weeks?), and things like https://github.com/kpwn/tpwn has been around for a while which is still not patched in any public, non-beta release of OSX.

Re: Apple’s approach to privacy

#33
post #17

> Apple has never worked with any government agency from any country to create a “backdoor” in any of our products or services. We have also never allowed any government access to our servers. And we never will. Did Apple ever provide any insight into what access the Prism program had? They denied knowing about it[1], so either they are lying or it was a mole. Did they ever follow up with an investigation or conclusi…

Prism in general was mischaracterized by the early reports. It was first reported as a persistent backdoor into servers, but it was actually just a way for NSA to automate requests for information through the FBI. This was detailed in later reports.

Edit: for those skeptical about my comment above, here is more detail from a discussion about a year ago:

https://news.ycombinator.com/item?id=8333844

Re: Apple’s approach to privacy

#34
We’re going to make sure you get updates here about privacy at Apple at least once a year and whenever there are significant changes to our policies.

Translation: We set up this page to reference for the inevitable future articles and critcisms of our policies.

Not saying it's a bad idea, but it's very lawerly to me. Like this one:

We don’t build a profile based on your email content or web browsing habits to sell to advertisers. We don’t “monetize” the information you store on your iPhone or in iCloud.

That makes sense, and I figure it's a true statement as written. But, bear with me here, I feel like it could still also be true they build a profile based on X, Y, or Z for internal use by Apple in the name of "making services better" as it were.

What I'd like to see at the bottom of the letter - and don't see even after clicking through a couple of the links - is a link to review all stored content by Apple in a nice, clean two-factor authenticated dashboard, and settings for all devices to be managed in one central location. That would be rather helpful to individuals...a big gesture of that buzzword "transparency" and all that! Yet I highly doubt such a portal / review capability would be implemented by Apple without much metaphorical kicking and screaming.

Re: Apple’s approach to privacy

#36

Earlier quoted context omitted.

Low-level enforcers don't have easy access to such orders.

We don't know that. We do know that the FBI, NSA, and other federal agencies are overly anxious to support local law enforcement - by providing wartime hardware and weapons, as well as support in spying. We know local police patrols use Stingray devices, disrupting cell service and sweeping up private communications without a warrant - that's just a single instance. We have no idea how easy it is for local law enforc…

One could infer how difficult it would be to maintain secrecy as the number of privileged enforcers expands. The longer that secrecy is maintained, the less access probably exists to the privilege.

I'm comfortable assuming that my local beat officer probably can't signal to his superior to pull an NSL on me and start reading every piece of data my devices are streaming over TLS.

Re: Apple’s approach to privacy

#37

We’re going to make sure you get updates here about privacy at Apple at least once a year and whenever there are significant changes to our policies. Translation: We set up this page to reference for the inevitable future articles and critcisms of our policies. Not saying it's a bad idea, but it's very lawerly to me. Like this one: We don’t build a profile based on your email content or web browsing habits to sell to…

[deleted]

Re: Apple’s approach to privacy

#38

Wasn't the Fappening because of a iCloud hole?

No, it was because celebrities are normal people and tended to use the same password for multiple services. One service was compromised, which compromised every other one because the passwords were the same.

Source?

My understanding was that some iCloud account login endpoints (associated with Find My iPhone) didn't have any rate limiting for password failures, and this allowed brute force to work for targetted accounts.

Re: Apple’s approach to privacy

#39
I was reading their guidelines for law enforcement requests: https://www.apple.com/privacy/docs/emeia_le_guidelines_final...

Interesting note: "P. FaceTime FaceTime communications are end-to-end encrypted and Apple has no way to decrypt FaceTime data when it is in transit between devices. Apple cannot intercept FaceTime communications. Apple has FaceTime call invitation logs when a FaceTime call invitation is initiated. These logs do not indicate that any communication between users actually took place. Apple has no information as to whether the FaceTime call was successfully established or duration of a FaceTime call. FaceTime call invitation logs are retained up to 30 days. FaceTime call invitation logs are available only following receipt of a legally valid request"

iMessage is not mentioned. Does this mean they are capable of intercepting iMessage?

edit: in the FAQ it says "Can Apple intercept users’ communications pursuant to a Wiretap Order? Apple can intercept users’ email communications, upon receipt of a valid Wiretap Order. Apple cannot intercept users’ iMessage or FaceTime communications as these communications are end-to-end encrypted."

Re: Apple’s approach to privacy

#40
I use Apple products, including the MBP on which I am typing this post. I paid big bucks and my expectation is Apple should respect my privacy. Services like Google I use them for free, and as such, monetization is fair. Not for Apple, and I hope it won't let me down.
Post reply on HN