I always question the effectiveness of obfuscating data using "unique identifiers" against a party determined to de-obfuscate the data. Aside from that, however, this is an encouraging read.
Exactly my thought. If they can connect all siri queries made by a user, it doesn't matter much if they don't store the name of that user. Deanonimisation happens easily through correlations, some correlations are really hard to predict. Id't be better if they just didn't store an ID with the data.
How much does Apple know about me? The answer surprised me
31–40 of 74 posts
Re: How much does Apple know about me? The answer surprised me
#32Did we really need a photo of the author holding a prinout of the data? > It kept a copy of every app and song I'd downloaded, every tune I'd added to my iTunes music library, and every time I needed repair on a multitude of Apple devices going back a decade. Is this surprising in any way? If you buy something (or "buy" it for free on the App Store) of course the company you buy it from keeps records of that.
It need not; for example it doesn't need historical data that have been superseded; if it no longer has an app available for download it could purge the fact that you bought it; it could give purchasers an anonymized download key that their phone could store (or cache in icloud someplace).
Re: How much does Apple know about me? The answer surprised me
#33Earlier quoted context omitted.
Exactly my thought. If they can connect all siri queries made by a user, it doesn't matter much if they don't store the name of that user. Deanonimisation happens easily through correlations, some correlations are really hard to predict. Id't be better if they just didn't store an ID with the data.
I think the article is badly phrased, and that they mean that _each_ individual Siri request from a device is from a random identifier, so they can't track it back to you.
Re: How much does Apple know about me? The answer surprised me
#34Earlier quoted context omitted.
Ironically, complying with these asks would require more data to be pushed off the individual devices.
Doesn't that already happen when you upgrade to a new device?
Re: How much does Apple know about me? The answer surprised me
#35I can't find it... I started at icloud.com which sent me to appleid.apple.com which sent me to apple.com/privacy/ and I never found a data download link.
Re: How much does Apple know about me? The answer surprised me
#36The only path left for them was to say they were all about user privacy. If Apple had succeeded wildly in any of those three spaces, I think they'd be caught up like Google, Facebook et al.
I'm not saying this is a bad thing for the tech ecosystem, but I do think it was lucky positioning on their part.
Interested to hear opposing opinion on this.
Re: How much does Apple know about me? The answer surprised me
#37Earlier quoted context omitted.
> always store all the data you have [...] storage is cheap. Here's the flip side: You can't lose data to a breach that you don't store. You can't have a rogue employee crow on social media about how they have access to data you don't store. You can't be liable for GDPR violations about PII you don't store. Data is certainly an asset, but it's also a huge liability - and laws are starting to catch up in order to enfo…
> Here's the flip side: You can't be lose data to a breach that you don't store. That means NO storage, not even "anonymous". (which Apple clearly does) > You can't have a rogue employee crow on social media about how they have access to data you don't store. Requires NO storage, which they clearly do. > You can't be liable for GDPR violations about PII you don't store. If you store it "anonymous" you can, since the…
There's a difference between storing only the data required for conducting your business, and storing all the data you possibly can for some imaginary future use. I'm suggesting the former is a better practice.
> If you store it "anonymous" you can
Anonymity via random-but-unique IDs is a tenuous protection at best when storing everything you possibly can. Take, for example, the fact that with a gender, a zip code, and a birthday, you can be uniquely identified with around 85% accuracy [0]. None of those are traditionally considered to be PII, and it's pretty likely that these are the kinds of things stored "anonymously" by the "store it all for later" kinds of companies.
[0] https://www.eff.org/deeplinks/2009/09/what-information-perso...
Re: How much does Apple know about me? The answer surprised me
#38Earlier quoted context omitted.
Exactly my thought. If they can connect all siri queries made by a user, it doesn't matter much if they don't store the name of that user. Deanonimisation happens easily through correlations, some correlations are really hard to predict. Id't be better if they just didn't store an ID with the data.
I think the article is badly phrased, and that they mean that _each_ individual Siri request from a device is from a random identifier, so they can't track it back to you.
> According to Wired, which reported on the story back in 2013, the data is shipped off to Apple's data farm for analysis, where it generates a random number that represents both the user and voice file. Six months later, Apple "disassociates" the user number from the clip, thereby deleting the number. The files are then stored for an additional 18 months, all for the sake of testing and product improvement.
Re: How much does Apple know about me? The answer surprised me
#39I have a theory that the only reason Apple is today's beacon of user privacy is that they couldn't manage to compete in either the ad (iAd), mail (at least not at G-scale) or social network world (see: Ping). The only path left for them was to say they were all about user privacy. If Apple had succeeded wildly in any of those three spaces, I think they'd be caught up like Google, Facebook et al. I'm not saying this i…
The other big bet is that something might happen to convince users that privacy is good. We'll see how that plays out - users aren't particularly bothered by Facebook revelations as their DAUs attest. Kids are growing up with microphones in their bedrooms (Amazon echo dot for kids) so privacy will be a deeply erodes concept ~15 years from now (if it isn't already).