Live data from Hacker News

Apple’s approach to privacy

apple.com

61–70 of 172 posts

Re: Apple’s approach to privacy

#61

So how will we ever know until it happens if the encryption on Apple devices is weakened by government demands? I understand they have a posted stance on privacy and such but the US government has shown it will threaten even those who divulge requests. It is to the point I don't upgrade i devices until weeks after just to be sure.

Isn't that problem solved by the 'canary in the coal mine' ? A company can have strong privacy language in their documentation. If any or part of that language disappears suddenly one day, you can know that a government forced the company to go against this language?

Re: Apple’s approach to privacy

#62
post #52

Nice but recently I was asked to enter the admin password of my MBP into a webform at an Apple reseller, it was a requirement for getting the GPU repaired (as part of a recall.) Isn't that very strange?

You don't have to. It just lets them better test and repair your device. If something is gorked up in your system files they can fix it using an admin account. I just dropped two laptops for repairs and didn't know an admin password on one. It wasn't a problem, though I suppose it might be more likely to come back with a wiped disk.

Re: Apple’s approach to privacy

#63
post #60

Earlier quoted context omitted.

> Changes in laws cannot provide access to data that was never gathered and stored in the first place. Laws can and have been written that require companies to gather data. > Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys. Laws can and have been written that require companies to use weaker or broken encryption.

True, of course. But we would presumably know about these laws, in advance, and we would have the ability to make choices based on this knowledge. Apple has thus far been steadfast in resisting this sort of activity and in advocating against any such laws. So for me at least, this is behavior that is worthy of trust.

> But we would presumably know about these laws, in advance

Court rulings and legal authorisations to conduct surveilance can and have ... you guessed it ... been kept secret

Re: Apple’s approach to privacy

#64
post #62
post #52

Nice but recently I was asked to enter the admin password of my MBP into a webform at an Apple reseller, it was a requirement for getting the GPU repaired (as part of a recall.) Isn't that very strange?

You don't have to. It just lets them better test and repair your device. If something is gorked up in your system files they can fix it using an admin account. I just dropped two laptops for repairs and didn't know an admin password on one. It wasn't a problem, though I suppose it might be more likely to come back with a wiped disk.

Why can't they just boot of an USB disk for testing?

Re: Apple’s approach to privacy

#65
post #52

Nice but recently I was asked to enter the admin password of my MBP into a webform at an Apple reseller, it was a requirement for getting the GPU repaired (as part of a recall.) Isn't that very strange?

No it's not strange. It's the only way to make sure everything is working correctly before giving your computer back. If you tell them you aren't comfortable with that they do have workarounds. If they DIDN'T need your password that would be a bigger red flag because it would mean they had backdoors.

Re: Apple’s approach to privacy

#66

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

Genuine curiosity: which country would a company need to be in to be able to trust them?

Switzerland, Netherlands and Norway are a good starting point. I believe that now that privacy became a major concern, we will see countries with some legislative background and experience in other sectors that require secrecy above everything else (e.g. private banking), evolve in secure havens for servers.

Re: Apple’s approach to privacy

#67
post #46

Earlier quoted context omitted.

Doesn't really address iOS 9 which changed things around a bit, and to even find anything about iOS at all you have to start looking at the 4th or 5th result on some random domain. And - even then - there are multiple odd places in the settings you need to check and verify, some of which are hidden in a long list of other apps.

It's detailed in the help page, the link to which is on the same settings screen that contains the switches to turn off. Likewise on MacOS, there's a 'About Spotlight Suggestions & Privacy' button on the Spotlight settings page. Again, it's on the same screen that contains the switches to turn off the feature. You don't need internet access to find these options, and I can't think of a better place to put the help. K…

In iOS9, there's at least "Siri Suggestions" at the top, then intermixed with all your apps there's "Bing Suggestions" and "Spotlight Suggestions", then there's a "Suggested Apps" in the separate "Handoff & Suggested Apps" settings screen, then there is "Suggested Apps" in the "App and iTunes Store" settings screen, then there is "Safari Suggestions" and "Search Engine Suggestions" in the "Safari" settings screen. I have no idea what half of these actually do though. Very confusing.

Re: Apple’s approach to privacy

#68
post #43

Earlier quoted context omitted.

>Does this mean they are capable of intercepting iMessage? You know what the best way is to see who cooperates with law enforcement and to what level? Court documents! I've been trawling court documents for the past few months (I'm writing a blog article on this) and I'm yet to find iMessage being used in court (unless the access to the conversation was given by one of the parties). iMessage really does seem secure f…

“Parallel construction is a law enforcement process of building a parallel - or separate - evidentiary basis for a criminal investigation in order to conceal how the investigation actually began.” https://en.wikipedia.org/wiki/Parallel_construction

Police use parallel construction when they don't want to reveal their methods. I seriously doubt law enforcement would engage in parallel construction if it had access to iMessage but Apple asked it to.

Re: Apple’s approach to privacy

#69

Apple is in a good position in the market to do this, but it is just really hard to trust any US company. They say they will never give anyone access to their servers but how can they make that promise when they don't make the laws? As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.

Locating data outside the US is in no way a defense against US intelligence agencies. There are theoretically controls on domestic spying, and some possibility that Congress could make it illegal. They have a mandate to spy on foreign networks.

If they haven't cracked your European email provider, then they're not doing what we pay and order them to do.

Re: Apple’s approach to privacy

#70
post #5

Apple says "Less than 0.00673% of customers have been affected by government information requests." That's approximately 1 out of every 14,000 -- seems like a lot to me!

How many customers does Apple have? How many people total is that? It's 6730 per 100,000,000 (hundred million). I think Apple has sold like 700 million iphones. But actual customers is less. So there have been maybe 20,000 or so government information requests?

Here is some detail I think you'll appreciate: http://www.apple.com/privacy/transparency-reports/
Post reply on HN