Live data from Hacker News

Apple’s approach to privacy

apple.com

141–150 of 172 posts

Re: Apple’s approach to privacy

#141

https://commons.wikimedia.org/wiki/File:Prism_slide_5.jpg https://commons.wikimedia.org/wiki/File:PRISM_Collection_Det...

Does anyone else have the suspicion that Prism was named prism because instead of getting companies to co-operate with the program they were siphoning off data like they did to google by tapping their fiber lines? That would fit more in line with what we have heard about the tapping stations/rooms at AT&T/Verizon over the years. I mean if they were really involved with back dooring the individual servers of google/ap…

Wouldn't HTTPs prevent that?

Re: Apple’s approach to privacy

#142

Earlier quoted context omitted.

Does anyone else have the suspicion that Prism was named prism because instead of getting companies to co-operate with the program they were siphoning off data like they did to google by tapping their fiber lines? That would fit more in line with what we have heard about the tapping stations/rooms at AT&T/Verizon over the years. I mean if they were really involved with back dooring the individual servers of google/ap…

Wouldn't HTTPs prevent that?

Yes, but according to google they were tapping the "dark fiber" (private lines only carrying google traffic) that were not encrypted between their data centers.

Those lines were for things like data replication so it was a goldmine for the NSA to tap. Those transmissions have since been encrypted.

Re: Apple’s approach to privacy

#143

Earlier quoted context omitted.

“Parallel construction is a law enforcement process of building a parallel - or separate - evidentiary basis for a criminal investigation in order to conceal how the investigation actually began.” https://en.wikipedia.org/wiki/Parallel_construction

Police use parallel construction when they don't want to reveal their methods. I seriously doubt law enforcement would engage in parallel construction if it had access to iMessage but Apple asked it to.

> I seriously doubt law enforcement would engage in parallel construction if it had access to iMessage but Apple asked it to.

Why? They've been using parallel construction to avoid violating NDAs and giving up their capabilities for years. http://www.wired.com/2014/03/harris-stingray-nda/

Re: Apple’s approach to privacy

#144

https://commons.wikimedia.org/wiki/File:Prism_slide_5.jpg https://commons.wikimedia.org/wiki/File:PRISM_Collection_Det...

Does anyone else have the suspicion that Prism was named prism because instead of getting companies to co-operate with the program they were siphoning off data like they did to google by tapping their fiber lines? That would fit more in line with what we have heard about the tapping stations/rooms at AT&T/Verizon over the years. I mean if they were really involved with back dooring the individual servers of google/ap…

I recall that being a common interpretation of the name when the news of PRISM first broke, so you're certainly not alone in that.

Re: Apple’s approach to privacy

#145

Earlier quoted context omitted.

Does anyone else have the suspicion that Prism was named prism because instead of getting companies to co-operate with the program they were siphoning off data like they did to google by tapping their fiber lines? That would fit more in line with what we have heard about the tapping stations/rooms at AT&T/Verizon over the years. I mean if they were really involved with back dooring the individual servers of google/ap…

Wouldn't HTTPs prevent that?

Not entirely, though Google and subsequently Microsoft, Apple et all have upgraded inter-datacentre connectivity to be encrypted - reducing this attack vector.

Re: Apple’s approach to privacy

#146
post #45
post #31

Earlier quoted context omitted.

I still don't know which setting actually disables that.

It's half a google away. https://www.google.com/search?q=disable+spotlight+queries+se...

You know you can Google it but I believe you haven't tried it yourself to do exactly what the goal of the question is, otherwise you would not answer with a plain Google query. I know as I've actually spent the time to experiment. And I'm still not at the point where I can answer it exactly. I don't want "disable everything" I don't want "disable this what's written but I'm not sure if what I type is still transferred" I want the exact information based on the network traffic analysis confirmation. I even know how I could do this but I don't have the time and the motivation and I know the sites that come up on the Google queries didn't do their actual homework, just "generated the content." SEO rules and stuff.

I've hoped somebody would have given an exact link to some competent and exact analysis. Google query it ain't.

I've got by Googling: "turn off 'Spotlight suggestions' and 'Bing Web Results'." Did both. Did that. Still got the web "suggestions" in my search results. I don't know it they are "Spotlight" "bing" or "Safari" but they are there, some server must have been involved as the results can't come from my phone. Clicked around a little more. Now looks better. Or not. I try to avoid the search page. I don't know what turns off what actually. And still don't know who reliably documented it.

It seems that other stuff can send the web queries as the result of what I type. Which stuff is that, what's going on, somebody will still have to find out and explain. Apple still haven't. Or I'm missing something and I'd be glad to learn.

Re: Apple’s approach to privacy

#147
post #115

Earlier quoted context omitted.

> Laws can and have been written that require companies to gather data. Not just that. Laws can (and probably have been) written that require companies to gather data and to explicitly lie about it.

> to explicitly lie about it. Maybe I'm dense or naive, but I don't think there's any precedent for that. A gag order is one thing (and there are certainly places for it), but forcing someone to lie would hopefully violate the First Amendment.

> Maybe I'm dense or naive, but I don't think there's any precedent for that.

It's well know about.

https://en.wikipedia.org/wiki/National_security_letter

https://www.eff.org/deeplinks/2014/04/warrant-canary-faq

Re: Apple’s approach to privacy

#148

I'm just going to leave this here https://www.youbetrayedus.org

This website is about the CISA bill and says:

Apple, Microsoft, Adobe, Symantec, and a handful of other tech companies just began publicly lobbying Congress to pass Cyber Threat Information Sharing legislation, like CISA, a bill that would give corporations total legal immunity when they share private user data with the government and with each other. Many of these companies have previously claimed to fight for their users' privacy rights, but by supporting this type of legislation, they've made it clear that they've abandoned that position, and are willing to endanger their users' security and civil rights in exchange for government handouts and protection.

Re: Apple’s approach to privacy

#149
post #134

I use Apple products, including the MBP on which I am typing this post. I paid big bucks and my expectation is Apple should respect my privacy. Services like Google I use them for free, and as such, monetization is fair. Not for Apple, and I hope it won't let me down.

Or you could use free software, and stop hoping for people around you to be honest.

Free != open source

Re: Apple’s approach to privacy

#150

Earlier quoted context omitted.

> If they haven't cracked your European email provider... The difference is that European email providers are not cooperating, because they aren't obliged by your laws, whereas US companies are not only obliged to comply with requests, but they are also coerced to keep it a secret. > ... then they're not doing what we pay and order them to do That's a good thing to know, plus this is reason enough to pressure our gov…

>European email providers are not cooperating The NSA doesn't need cooperation. It can pwn sysadmins, plant covert operatives, and backdoor equipment in transit (including foreign-made equipment, so long as US intelligence can influence the shipping carrier, for example by recruiting employees or hacking ancient legacy software). If it can't, then it can pwn the other side of the conversation, or watch the SMTP in cl…

> The NSA doesn't need cooperation

But of course it does. Security is not a black and white issue, but rather a matter of cost. And the fact is US companies are much easier and more cost effective to crack because they can be (legally) coerced and nobody has unlimited resources, not even the NSA.

> Disband the NSA and some other agency, some other country, will do the same thing

This is one of those logical fallacies that keeps popping up. So we should bend over and take it like a man, because if it's not the NSA, then it will be somebody else. Even if you're right, bad actors in society should get punished, otherwise they'll never learn. And indeed, it doesn't seem fair to punish US companies, many of whom really want to be good and faithful for their customers, but I've seen many signals that the american public approves and finances this behavior, which includes the above comment and the US government never apologized (to us, foreigners), therefore avoiding US services and products can become a matter of necessity.

> The cat's not going back in the bag because you avoid the US.

Yeah, but you see, I'm not an US citizen so I don't even get to vote on your laws and your government has made it clear that when it comes to foreigners then everything is allowed. And we do have intelligence agencies and they are cooperating even with the NSA and so on and so forth, but here there is no behemoth like the NSA is. And as an EU citizen at least I would have ways to fight it.

> developing and adopting security systems and practices that make doing what the NSA is doing actually difficult

Only a software developer would end up thinking that all political and social issues can be solved with technology. The world doesn't work that way. You want cryptography? It will eventually get outlawed and there is already precedent in the US.

https://xkcd.com/538/

Post reply on HN