Live data from Hacker News

Our Approach to Privacy

apple.com

81–90 of 183 posts

Re: Our Approach to Privacy

#81
post #73
post #70

Earlier quoted context omitted.

Well they decrypt it on your behalf when it's on your device. The point is that couldn't do that without your device/account.

They then go on to say: > While we do back up iMessage and SMS messages for your convenience using iCloud Backup, you can turn it off whenever you want. Sure, I can stop backing my data up - but presuming I don't (like the vast majority of people), does that mean if they got a wiretap order they could just read the data straight from their backup servers? I'm not sure if this was just phrased poorly, or if backing up…

Good question. If you backup via iTunes you have the option of encrypting with a password. I've never been prompted to enter a backup password for iCloud...

Re: Our Approach to Privacy

#82
post #72

How much of this can be independently verified? I suppose we just need to take their word for it?

It all boils down to what you see in the public. The FBI was trying to get Apple to create an iOS variant to extract data from a device, to the point where Tim Cook wrote a letter refusing to do so and was willing to fight it in court. In a similar fashion, Apple has given talks and white papers on iOS security. In tandem with these well documented white papers and talks discussing the internal functions of iOS, we h…

We know that they lied to customers claiming they couldn't help law enforcement get data off customers' devices.

"Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data. So it's not technically feasible for us to respond to government warrants for the extraction of this data from devices in their possession running iOS 8."[1]

After it became clear that it is technically feasible for Apple to assist with those data requests, they quietly removed that claim from their website.[2]

[1] https://arstechnica.com/gadgets/2014/09/apple-expands-data-e...

[2] https://www.apple.com/privacy/government-information-request...

Re: Our Approach to Privacy

#83

Privacy is one of those things I can't tangibly describe why I like it, but it just feels good to know that nothing is being saved, even in contrast to just targeting you for ads and nothing else.

There's an analogy with side-effect-free functions: things are easier to reason about when you don't have to worry about peripheral state changes.

Re: Our Approach to Privacy

#84

Earlier quoted context omitted.

I think you mis-understand how iOS privacy controls work. An app doesn't get to 'see all your photos' just because you grant photo access, you still have to select which photos to put in the app. Same goes for camera, that just let's the app pull up the camera interface, not be able to access it 24/7 for whatever purpose they want. Same with the mic.

I don't think this is correct. The Facebook app regularly shows me all the photos I have taken today and asks if I want to post any of them.

Honestly that sounds really creepy.

Re: Our Approach to Privacy

#85
post #48

After reading this, I have two questions: 1. Are there any statistics showing the ratio of security issues between Android and iOS? 2. What's the most common phone among security researchers? To be honest, I'm wary of believing this, but I own a Nexus and if I had to give the benefit of the doubt to either Google or Apple, it would most certainly be Apple because they don't make business out of my data (or, not as mu…

It is very hard to get this information in depth because researches publish on Android much more frequently (more users, more open platform).

You can look at the CVEs reported on each platform though and the number of critical vulns is comparable at this point.

Re: Our Approach to Privacy

#86
post #28
post #9

Earlier quoted context omitted.

You can disable Face ID by pressing the power and volume buttons at the same time. They are on either side of the phone. Faster than the multiple press method and more discrete.

Only on the iPhone X and possibly the 8.

Face ID only exists on the iPhone X, so you don't need a way to turn it off on other devices. :)

Re: Our Approach to Privacy

#87
post #54

Earlier quoted context omitted.

Android and its community are sorta schizophrenic towards security. On one hand, users are told that they should never ever, ever install applications from untrusted sources. They should always use the play store because applications are scanned for vulnerabilities and whatnot. On the other hand, we have people telling us that one of the great advantages of Android is that you can sideload apps - bypassing the store…

My perception is also that malware ends up in the Google Play Store with much higher frequency than the App Store. Just do a news search for "Google Play Store malware" and "App Store malware" and compare. Also, one can sideload apps, if you have a Mac, onto iOS. Obviously, that's not anywhere as integrated but maybe that's a good thing. Heck, maybe Apple even added that so people in China could sideload VPNs. Maybe…

Add up all the malicious app installs on Google Play Store, and it doesn't even come close to the 500 million[1] (conservative estimate) users affected by XCodeGhost. It looks worse when you consider that the 500 million is on an order of magnitude smaller total iOS userbase vs. Play Store userbase and when you consider that Google allows third party security researchers to investigate and publish research on the Play Store while Apple does not, so XCodeGhost is likely to be the tip of the iceberg.[2]

[1] https://www.google.com/amp/s/www.macrumors.com/2015/09/20/xc...

[2] https://www.google.com/amp/s/www.cultofmac.com/128577/apple-...

Re: Our Approach to Privacy

#88
post #48

After reading this, I have two questions: 1. Are there any statistics showing the ratio of security issues between Android and iOS? 2. What's the most common phone among security researchers? To be honest, I'm wary of believing this, but I own a Nexus and if I had to give the benefit of the doubt to either Google or Apple, it would most certainly be Apple because they don't make business out of my data (or, not as mu…

FWIW tptacek and a few others recommend iPhones for journalists:

https://news.ycombinator.com/item?id=13798321

Re: Our Approach to Privacy

#89

I'm happy Apple is at least trying hard to deal with privacy but honestly I don't think they are doing enough, at least for me. For example, I don't really want to give most apps constant access to my photos, my camera, or my mic but I really don't have a whole lot of choice if I still want to use popular apps and services like Facebook, Instagram, Messenger, Hangouts, Line, WhatsApp etc.. I really wish that every ti…

> they require permission to read all my photos when all I want them to be able to do is save the photo I don't think this is true though. From the code I've seen you only get returned the single UIPhoto the user chose. also remember you can revoke permissions at any time via Settings.

The apps are presenting their own UIs showing all the photos. They also have options to upload all the photos in the background. They clearly get permission to access all the photos.

Going to settings doesn't help

1) Giving an app permission to access the photos and then revoke it when I'm done doesn't prevent the app from accessing as many photos as it pleases until I revoke access. In the time it would take for me to give an app access, select a photo, and then revoke the app could easily have looked at 10s or 100s of photos.

Add some ML in there for their ad targeting

2) With the Mic off I can't receive calls in any of the messaging apps. If iOS asked each time then that issue would go away but as it is I need to leave on mic support or miss calls. I suppose I could miss the first call, turn on mic support, return the call, turn off mic support.

Still, I'd argue if Apple wanted to be even more serious about privacy they wouldn't allow apps to have unrestricted access to the mic as they do because it makes the burden of trying to prevent spying pretty cumbersome.

Re: Our Approach to Privacy

#90

I'm happy Apple is at least trying hard to deal with privacy but honestly I don't think they are doing enough, at least for me. For example, I don't really want to give most apps constant access to my photos, my camera, or my mic but I really don't have a whole lot of choice if I still want to use popular apps and services like Facebook, Instagram, Messenger, Hangouts, Line, WhatsApp etc.. I really wish that every ti…

Thinking about it some more. For Camera and Mic they could have the option to "ask the user" every time and revoke that permission if the top is not the front app after a minute or so. That would at least prevent using the camera and mic when the user has not recently given permission. Whether people would use it or not I don't know. I would.
Post reply on HN