Live data from Hacker News

How does Apple privately find offline devices?

blog.cryptographyengineering.com

161–170 of 184 posts

Re: How does Apple privately find offline devices?

#161
post #95

Earlier quoted context omitted.

Because time and time again it is proven that "these companies" (Facebook and Google) will use any signal they can get their hands on to make money? I'm pretty sure they've both been caught with their hands in the cookie jar doing things they swore they never would.

Genuinely curious, could you provide an example of Google "doing things they swore they never would" with consumer data? Because I know they do plenty of things with data that people think are creepy, but I don't recall ever seeing a story about them doing things they swore they wouldn't (besides the nebulous "don't be evil") or even lying about what they were actually doing with consumer data. If it's happened time…

>Google has been accused of breaking promises to patients, after the company announced it would be moving a healthcare-focused subsidiary, DeepMind Health, into the main arm of the organisation. The restructure, critics argue, breaks a pledge DeepMind made when it started working with the NHS that “data will never be connected to Google accounts or services”.

https://www.theguardian.com/technology/2018/nov/14/google-be...

Re: How does Apple privately find offline devices?

#162
post #95

Earlier quoted context omitted.

Because time and time again it is proven that "these companies" (Facebook and Google) will use any signal they can get their hands on to make money? I'm pretty sure they've both been caught with their hands in the cookie jar doing things they swore they never would.

Genuinely curious, could you provide an example of Google "doing things they swore they never would" with consumer data? Because I know they do plenty of things with data that people think are creepy, but I don't recall ever seeing a story about them doing things they swore they wouldn't (besides the nebulous "don't be evil") or even lying about what they were actually doing with consumer data. If it's happened time…

They claimed multiple times publicly that they weren't scanning emails of students of schools that forced students to use Google email and Chromebooks, when in fact they were using them to build ad profiles.

https://www.edweek.org/ew/articles/2014/03/13/26google.h33.h...

"While the allegations by the plaintiffs are explosive, it’s the sworn declarations of Google representatives in response to their claims that have truly raised the eyebrows of observers and privacy experts. Contrary to the company’s earlier public statements, Google representatives acknowledged in a September motion to dismiss the plaintiffs’ request for class certification that the company’s consumer-privacy policy applies to Apps for Education users. Thus, Google argues, it has students’ (and other Apps for Education users’) consent to scan and process their emails."

"In November, Kyle C. Wong, a lawyer representing Google, also argued in a formal declaration submitted to the court in opposition to the plaintiffs’ motion for class certification that the company’s data-mining practices are widely known, and that the plaintiffs’ complaints that the scanning and processing of their emails was done secretly are thus invalid. Mr. Wong cited extensive media coverage about Google’s data mining of Gmail consumer users’

>Mr. Wong’s inclusion of the following reference to the disclosure provided to students at the University of Alaska particularly caught the attention of privacy advocates: The University of Alaska (“UA”) has a “Google Mail FAQs,” which asks, “I hear that Google reads my email. Is this true?” The answer states, “They do not ‘read’ your email per se. For use in targeted advertising on their other sites, if your email is not encrypted, software (not a person) does scan your email and compile keywords for advertising. For example, if the software looks at 100 emails and identifies the word ‘Doritos’ or ‘camping’ 50 times, they will use that data for advertising on their other sites.” “The fact that Google put this in their declaration means we take it as true,” said Ms. Barnes of the privacy watchdog group EPIC. Google’s sworn court statements reveal that the company has violated student trust by using students’ education records for profit.”

https://www.washingtonpost.com/news/grade-point/wp/2016/02/0...

https://www.eff.org/press/releases/google-deceptively-tracks...

Re: How does Apple privately find offline devices?

#163

Earlier quoted context omitted.

On the other hand, if the information is aggregated to a final answer, why is the data then kept? What if the _wrong people_ get ahold of the more sensitive information _because_ the data was kept beyond its useful life?

In their defense: it is perfectly fine with me to keep my location data, so I can download it later and do cool and/or useful things with it as long as - it is opt in, - it can be deleted by me - is not given to anyone else For all my trashing of Google lately (check my comment history) I actually expect and belive them to defend my raw data in a way that few others are able to. It all boils down to incentives: - as…

Describing Google's data collection practices as "opt in" is a bit generous.

>In going through a set of privacy popups put out in May by Facebook, Google, and Microsoft, the researchers found that the first two especially feature “dark patterns, techniques and features of interface design mean to manipulate users…used to nudge users towards privacy intrusive options.”

https://techcrunch.com/2018/06/27/study-calls-out-dark-patte...

Re: How does Apple privately find offline devices?

#164
post #156
post #101

Well...a bit off topic but kind of relevant. My car got broken into and my iPad nicked. I was able to locate that, however, the cops here in NZ were really unhelpful. They said the GPS location wouldn't be sufficient for a search warrant as they have had many cases of false positives. I said I would give the ssid and ip address of their wifi network, even then they wouldn't agree for a raid. It was only when the thie…

I can definitely see the point regarding GPS location, I remember an article about people living at some default coordinates suffering from something like daily or weekly police raids.

Indeed, due to MaxMind's GeoIP location for the middle of the US (when it can't find a more accurate US location) at 38°N 97°W. So unfortunate.

https://splinternews.com/how-an-internet-mapping-glitch-turn...

Re: How does Apple privately find offline devices?

#165

Earlier quoted context omitted.

It's not just NZ. Police in the US are no better. In the Dallas PD, the detective assigned to the case when our house was burgled would not respond to emails sent to him providing evidence. After reaching out through other avenues to reach the detective, he flat out responded with being too busy to read emails. The case went uncleared. However, a few weeks later, there was a random call saying they found an iPad repo…

When I get frustrated with the police, it helps to remember that they make like $25/hr or less. In a wealthy suburb I just moved into a few months ago, I learned that a majority of the children of the police are growing up below the poverty line. The local politicians are apparently very liberal about their views on police (do not support), so they keep the pay as low as possible. All the police have to live outside…

I don't know where you live, but in Seattle even brand new recruits (who aren't even actually working yet) make more than that

https://www.seattle.gov/police/police-jobs/salary-and-benefi...

Re: How does Apple privately find offline devices?

#166

The problem I see with this is that your phone always has to be broadcasting the BLE beacon, regardless of if it is lost or not. Otherwise it could randomly end up lost in a place with poor/no service... and would never be found For phones, how often is this really an issue? Sure, this is useful for the Tile type "dumb" devices... but if my phone has no cell or data service... it's probably because the battery is dea…

Also, couldn't the BLE beacon be used by "smash and grab" thieves to find devices in your car?

Yes, and this is already happening due to the feature that Macbooks have to connect to eg. BL keyboards and mouses. Perhaps also the "Smart Sleep" function (not sure what it's called exactly) that periodically connects to Wifi to fetch emails so they're there when you open your Mac again. This has happened to me and other folks here in NL, by the way.

Re: How does Apple privately find offline devices?

#167
post #101

Well...a bit off topic but kind of relevant. My car got broken into and my iPad nicked. I was able to locate that, however, the cops here in NZ were really unhelpful. They said the GPS location wouldn't be sufficient for a search warrant as they have had many cases of false positives. I said I would give the ssid and ip address of their wifi network, even then they wouldn't agree for a raid. It was only when the thie…

Funnily in the UK I got Oxford police to enter a house based on GPS and ssid and me remotely setting a loud alert on the phone. The robber sadly smashed it though while being apprehended.

Re: How does Apple privately find offline devices?

#168

Earlier quoted context omitted.

In their defense: it is perfectly fine with me to keep my location data, so I can download it later and do cool and/or useful things with it as long as - it is opt in, - it can be deleted by me - is not given to anyone else For all my trashing of Google lately (check my comment history) I actually expect and belive them to defend my raw data in a way that few others are able to. It all boils down to incentives: - as…

Describing Google's data collection practices as "opt in" is a bit generous. >In going through a set of privacy popups put out in May by Facebook, Google, and Microsoft, the researchers found that the first two especially feature “dark patterns, techniques and features of interface design mean to manipulate users…used to nudge users towards privacy intrusive options.” https://techcrunch.com/2018/06/27/study-calls-out…

> Describing Google's data collection practices as "opt in" is a bit generous.

Maybe it is not clear but I was talking about location history.

At least I think I had to opt in to that at some point.

Re: How does Apple privately find offline devices?

#169

Earlier quoted context omitted.

Describing Google's data collection practices as "opt in" is a bit generous. >In going through a set of privacy popups put out in May by Facebook, Google, and Microsoft, the researchers found that the first two especially feature “dark patterns, techniques and features of interface design mean to manipulate users…used to nudge users towards privacy intrusive options.” https://techcrunch.com/2018/06/27/study-calls-out…

> Describing Google's data collection practices as "opt in" is a bit generous. Maybe it is not clear but I was talking about location history. At least I think I had to opt in to that at some point.

Location history is one of the areas where Google has employed dark patterns.

For example:

>Ways that Google tricks users into sharing location

Android users are pushed through a variety of techniques:

Deceptive click-flow: The click-flow when setting up an Android device pushes users into enabling “Location History” without being aware of it.

Hidden default settings: When setting up a Google account, the Web & App activity settings are hidden behind extra clicks and enabled by default..

Misleading and unbalanced information: Users are not given sufficient information when presented with choices, and are misled about what data is collected and how it is used. Information about location data being used for advertising, for example, is hidden away behind extra clicks.

Repeated nudging: Users are repeatedly asked to turn on “Location History” when using different Google services even if they decided against this feature when setting up their phone.

Bundling of services and lack of granular choices: If the user wants features such as Google Assistant and photos sorted by location, Google turns on invasive location tracking.

https://www.forbrukerradet.no/side/google-manipulates-users-...

More alarmingly, when users attempted to turn off location tracking:

>In a wonderfully clear example of “dark patterns” designed to mislead users and retain control over their data, Google continues tracking your location even when you turn off Location History and are told that “the places you go are no longer stored.” Google says it tells users, but its disclosure is the bare minimum and users are discouraged from further interference with data collection.

https://techcrunch.com/2018/08/13/google-keeps-a-history-of-...

Re: How does Apple privately find offline devices?

#170

>can use a single [private] key regardless of which randomized version of her public key was used to encrypt. I have not seen this before. Trying to wrap my brain around how this works. In terms of ECC I thought public and private were a single pair. Can anyone explain what is going on with public key randomization?

You can derive a new public key from someone's ECC public key, and they can derive the corresponding private key by applying the same transformation. It's somewhat magical! I wouldn't be surprised if Apple is using a scheme based on this instead of ElGamal, they already use ECC extensively. https://github.com/bitcoin/bips/blob/master/bip-0032.mediawi...

Interesting, I hadn't thought of using the techniques of deterministic cryptocurrency wallets to solve this problem. I need to read more about exactly how they work.

It is also easy to solve this simply using ECC and ECDH. I just wrote a scheme on the board in the office. It might have slightly larger data payload than the deterministic wallets approach.

Post reply on HN