Live data from Hacker News

Our Approach to Privacy

apple.com

31–40 of 183 posts

Re: Our Approach to Privacy

#31

Apple's approach to privacy also includes being a partner in PRISM, a fact which they chose to vigorously deny as false allegations until it was proven to be true. Every story about Apple and privacy chooses to omit thus huge piece of info. Why should anybody trust them now? What has changed to make anybody believe they aren't still lying about privacy?

If their technology is built such that even they themselves cannot peer into the inner workings of your content, what good is their association with PRISM?

But it's not. It says "encrypted when sent and, in most cases, when stored on our servers". Even if encrypted at rest that doesn't mean they can't decrypt it.

The calls and messages should be end-to-end encrypted but they are in control of the PKI so they could probably eavesdrop if they wanted.

Re: Our Approach to Privacy

#32

On Android you can Sideload VPN apps, iOS on the otherhand banned them in China. Apple mounted the most successful attack on General Computing with it's walled garden. The whole Apple is good for privacy is marketing.

Android and its community are sorta schizophrenic towards security. On one hand, users are told that they should never ever, ever install applications from untrusted sources. They should always use the play store because applications are scanned for vulnerabilities and whatnot. On the other hand, we have people telling us that one of the great advantages of Android is that you can sideload apps - bypassing the store…

Yep as someone who is in a cybersecurity job, it's almost trivial to hack Android.

Re: Our Approach to Privacy

#33
post #22

Earlier quoted context omitted.

You don't need to sideload VPN apps on Android. They're right in the store, and there's an API for them to run without root, from what I understand. Here's OpenVPN. https://play.google.com/store/apps/details?id=net.openvpn.op... There's also Tor with Orbot and Orfox. https://play.google.com/store/apps/details?id=org.torproject... https://play.google.com/store/apps/details?id=info.guardianp... But only explicitly conf…

The parent is talking about the lesser-known (for obvious reasons) VPNs, not the well-known ones which are pretty much useless in China for "jumping over the wall".

Do Chinese authorities block OpenVPN based on traffic characteristics? Because you can use this app to connect to any OpenVPN server you choose, including your own.

Same with Tor. You can use an unlisted bridge to get on the network.

Re: Our Approach to Privacy

#34

Apple's approach to privacy also includes being a partner in PRISM, a fact which they chose to vigorously deny as false allegations until it was proven to be true. Every story about Apple and privacy chooses to omit thus huge piece of info. Why should anybody trust them now? What has changed to make anybody believe they aren't still lying about privacy?

PRISM is a system for dispatching FISA 702 directives, which are the documents containing "selectors" (search queries) pursuant to a court-approved FISA 702 certification. It is to search warrants what Stripe is to credit card authorizations.

"Not" being a partner in PRISM doesn't mean much; it just means you're legally obligated to handle that paperwork by hand. Like every other company in the country, you're still required to comply with a valid 702 directive.

Re: Our Approach to Privacy

#35
post #26

Apple does so many things well, actually. I would return to them for some things and even recommend them (versus exclusively GNU/Linux and LineageOS) if they'd only change the stupid iOS terms that prohibit GPL software.

Funny, to me it's not Apple that is stupid, it's your license that is stupid. It's keeping your app out of the App Store, it's keeping ZFS and Dtrace from the Linux kernel, the amount of developer energy and time wasted on GPL enforcement and arguing about what it actually says and means is appalling. Why you would saddle yourself to a license with so much dead weight and so many problems I can't understand.

And yet, the GPL has been absolutely critical in establishing free software as a credible player, so I'd disagree with you on the license being stupid.

Re: Our Approach to Privacy

#36

Apple's approach to privacy also includes being a partner in PRISM, a fact which they chose to vigorously deny as false allegations until it was proven to be true. Every story about Apple and privacy chooses to omit thus huge piece of info. Why should anybody trust them now? What has changed to make anybody believe they aren't still lying about privacy?

If their technology is built such that even they themselves cannot peer into the inner workings of your content, what good is their association with PRISM?

How do you know Apple is telling the truth?

One thing we're certain of, however, is that Apple has the signing keys. They also encrypt their firmware and even other apps to hide how they work.

Re: Our Approach to Privacy

#37
post #26

Apple does so many things well, actually. I would return to them for some things and even recommend them (versus exclusively GNU/Linux and LineageOS) if they'd only change the stupid iOS terms that prohibit GPL software.

Funny, to me it's not Apple that is stupid, it's your license that is stupid. It's keeping your app out of the App Store, it's keeping ZFS and Dtrace from the Linux kernel, the amount of developer energy and time wasted on GPL enforcement and arguing about what it actually says and means is appalling. Why you would saddle yourself to a license with so much dead weight and so many problems I can't understand.

Do they just block the GPLs or any FLOSS license?

Re: Our Approach to Privacy

#38
post #32

Earlier quoted context omitted.

Android and its community are sorta schizophrenic towards security. On one hand, users are told that they should never ever, ever install applications from untrusted sources. They should always use the play store because applications are scanned for vulnerabilities and whatnot. On the other hand, we have people telling us that one of the great advantages of Android is that you can sideload apps - bypassing the store…

Yep as someone who is in a cybersecurity job, it's almost trivial to hack Android.

Most Android devices at least, unless you have the latest Nex... Pixel or Samsung phone.

Re: Our Approach to Privacy

#39
post #31

Earlier quoted context omitted.

If their technology is built such that even they themselves cannot peer into the inner workings of your content, what good is their association with PRISM?

But it's not. It says "encrypted when sent and, in most cases, when stored on our servers". Even if encrypted at rest that doesn't mean they can't decrypt it. The calls and messages should be end-to-end encrypted but they are in control of the PKI so they could probably eavesdrop if they wanted.

Reread Apple's security papers. Much of what's "encrypted on their servers" is encrypted in ways deliberately designed to make it untenable for Apple to decrypt. For instance, material in iCloud is encrypted with a key derived from your device PIN. So concerned is Apple with maintaining their inability to decrypt, even with a brute-force search on the PIN space, that they've contrived an elaborate quorum scheme of HSMs to manage the key space and count failure attempts. Nobody does this and Apple could have stopped here and rightly claimed the most secure large-scale cloud architecture of any mainstream tech company. But they didn't. They used programmable HSMs to implement the system and were concerned that a serious power bent on coercing Apple would target the HSMs. So, once they get the systems deployed, the admins meet and run the programming keys for the HSM through a "physical one way hash function".

On stage at Black Hat, Ivan Krstic claims that hash function to have been a Vitamix blender.

Almost always, when companies claim to encrypt things serverside, they're doing something shady. And it is always preferable that secrets be kept on devices and never touch servers. But Apple is taking the problem seriously.

Re: Our Approach to Privacy

#40
post #14

On Android you can Sideload VPN apps, iOS on the otherhand banned them in China. Apple mounted the most successful attack on General Computing with it's walled garden. The whole Apple is good for privacy is marketing.

Sorry for the silly question. I don't own a mac or an iPhone anymore. My understanding is you can sideload apps on your own iPhone from your own mac running xcode. Are there limitations to what kind of apps you can side load using xcode?

You can (used to be able to?) also sideload without a Mac, that's how some pirate app stores work without jailbreak.
Post reply on HN