Earlier quoted context omitted.
My perception is also that malware ends up in the Google Play Store with much higher frequency than the App Store. Just do a news search for "Google Play Store malware" and "App Store malware" and compare. Also, one can sideload apps, if you have a Mac, onto iOS. Obviously, that's not anywhere as integrated but maybe that's a good thing. Heck, maybe Apple even added that so people in China could sideload VPNs. Maybe…
Add up all the malicious app installs on Google Play Store, and it doesn't even come close to the 500 million[1] (conservative estimate) users affected by XCodeGhost. It looks worse when you consider that the 500 million is on an order of magnitude smaller total iOS userbase vs. Play Store userbase and when you consider that Google allows third party security researchers to investigate and publish research on the Pla…
Our Approach to Privacy
121–130 of 183 posts
Re: Our Approach to Privacy
#122I'm happy Apple is at least trying hard to deal with privacy but honestly I don't think they are doing enough, at least for me. For example, I don't really want to give most apps constant access to my photos, my camera, or my mic but I really don't have a whole lot of choice if I still want to use popular apps and services like Facebook, Instagram, Messenger, Hangouts, Line, WhatsApp etc.. I really wish that every ti…
I think you mis-understand how iOS privacy controls work. An app doesn't get to 'see all your photos' just because you grant photo access, you still have to select which photos to put in the app. Same goes for camera, that just let's the app pull up the camera interface, not be able to access it 24/7 for whatever purpose they want. Same with the mic.
Compared to that workflow, if you open the stock/official photos app and use the share sheet to share one or more photos with a specific app, then it would get only the selected photo(s).
Re: Our Approach to Privacy
#123Earlier quoted context omitted.
I agree with this reasoning (although I'm not particularly privacy minded, and prefer Android and most Google products to iOS and iCloud). The older tech companies like Apple and Microsoft have built business models with a different set of incentives around user data. Google, and particularly Facebook's, business models entirely rely on monetising user data. My personal 'ranking' of a companies incentives to respect…
I'm curious why you would say that Microsoft has the most respect for privacy given Windows 10 telemetry. Is there a MacOS or iOS equivalent?
I would flip MS/Apple personally, but I understand the argument from the perspective of business incentives. Microsoft's incentives don't really care about collection of telemetry, but they have a strong incentive to keep customer data secure from outside entities (e.g., businesses on MS products losing corporate data to outsiders).
Re: Our Approach to Privacy
#124A few things have struck me really strong on Apple's stand and implementation on protecting users' privacy: 1. Though it's understandable that Apple earns money primarily by selling hardware, it's sort of amusing and alarming at the same time that a proprietary almost-closed-source software company is focusing on protecting and preserving privacy whereas partially open source platforms competing with Apple seem to be…
See here for details: https://www.apple.com/business/docs/iOS_Security_Guide.pdf
A lot of the features would be very difficult to implement in Android without cooperating hardware, and hardware is notoriously expensive to get right and scale up. Projects like neo900 and Purism regularly encounter delays, unexpected costs, and pricing issues. It's really tough.
On a broader note, people are spending more and more time in data-hungry apps anyway, which can send almost anything they want to the network. This is sure to chip at any device-level security, pushing it towards irrelevance. I wish I had a log entry every time an app used the location service on my phone along with a database containing a history of Internet-transacted data.
Re: Our Approach to Privacy
#125Earlier quoted context omitted.
Google Photos uses ML to tag photos and this feature released amidst much fanfare at Google I/O a couple of years ago. They don't need location data to geotag photos anymore.
Thanks for explaining one possible method. It could still mean Google is tracking location "without consent". I suppose it depends on whether they use that location data for anything other than Google Photos.
Re: Our Approach to Privacy
#126Privacy is one of those things I can't tangibly describe why I like it, but it just feels good to know that nothing is being saved, even in contrast to just targeting you for ads and nothing else.
We generally speak of organizations, companies, and governments that are seeking the penetrate the veil of individual privacy. And I think that leads people to forget that these entities are made up of people. And people can, and do, do bad things.
A soft example is Snowden stating that NSA operators regularly pass around intercepted nude photo/video from people who had their privacy unjustly compromised: "These are seen as the fringe benefits of surveillance positions.." But the particularly disconcerting issue is that this information can be used against individuals. This article from the EFF highlights the FBI's actions against MLK:
https://www.eff.org/deeplinks/2014/11/fbis-suicide-letter-dr...
That letter was the FBI, posing as a disillusioned black supporter, detailing various embarrassing information that had been collected on MLK and encouraging him to commit suicide -- stating that it would all be published otherwise. And these couple of examples are only stuff that's being done by the "good guys." Information can, and will, be leaked, stolen, traded, and so on. One can only imagine the sort of things the "bad guys" could cook up.
Re: Our Approach to Privacy
#127Earlier quoted context omitted.
Root is not that hard to obtain on most devices. The instructions are straight-forward[1] and easy to follow, especially for anyone reading this thread. But lately Google has decided that rooted phones are a security issue. So if you do choose to install some sort of su utility, some functions like Android Pay may cease to work, not because of technical reasons but because Google deliberately disables them on rooted…
Of course, once you're root you can also prevent those apps (which don't run as root) from finding out that you have root, but it's an ongoing cat-and-mouse game.
Re: Our Approach to Privacy
#128A few things have struck me really strong on Apple's stand and implementation on protecting users' privacy: 1. Though it's understandable that Apple earns money primarily by selling hardware, it's sort of amusing and alarming at the same time that a proprietary almost-closed-source software company is focusing on protecting and preserving privacy whereas partially open source platforms competing with Apple seem to be…
Regarding your first point, it's difficult to implement some security schemes at the operating system level alone. With full vertical control of the product, you can have nice things like secure enclaves and de-facto hardware cryptography acceleration. See here for details: https://www.apple.com/business/docs/iOS_Security_Guide.pdf A lot of the features would be very difficult to implement in Android without cooperat…
> On a broader note, people are spending more and more time in data-hungry apps anyway, which can send almost anything they want to the network. This is sure to chip at any device-level security, pushing it towards irrelevance. I wish I had a log entry every time an app used the location service on my phone along with a database containing a history of Internet-transacted data.
I've long wished for network access permission on iOS, allowing the user to decide which apps can never connect to any networks. To reduce the total attack surface, I'd want to keep many apps (especially games) running only within their sandboxes and having access to only the data they create/generate on-device and no other external resource/server.
AFAIK, Android has had this even in the days of permission requests at app install time. I don't know if granular control is available on this from Android 6 onwards.
Re: Our Approach to Privacy
#129Earlier quoted context omitted.
Add up all the malicious app installs on Google Play Store, and it doesn't even come close to the 500 million[1] (conservative estimate) users affected by XCodeGhost. It looks worse when you consider that the 500 million is on an order of magnitude smaller total iOS userbase vs. Play Store userbase and when you consider that Google allows third party security researchers to investigate and publish research on the Pla…
LOL, let's start with StageFright (1 billion+ pwned with just a text message), move on to StageFright2 (because patching is hard...), and then just keep running down the list of malware in the Play store that is still there months after being discovered. XCodeGhost OTOH, seemed to have hit around 40 apps so that would probably not even get it into the top-100 list of Google Play malware families. Malware families. Th…
Don't conflate unpatched Linux systems with the Play Store. Anybody who uses Android and cares about the security of their device (like anybody who uses a Linux-based router and cares about the security of their network) uses vendors who deploy timely security updates.
Re: Our Approach to Privacy
#130Earlier quoted context omitted.
We know that they lied to customers claiming they couldn't help law enforcement get data off customers' devices. "Unlike our competitors, Apple cannot bypass your passcode and therefore cannot access this data. So it's not technically feasible for us to respond to government warrants for the extraction of this data from devices in their possession running iOS 8."[1] After it became clear that it is technically feasib…
By "technically feasible" are you referring to Apple's ability to build a software update that allows for quicker brute-forcing of the passcode?