Live data from Hacker News

Briar Project

briarproject.org

71–80 of 189 posts

Re: Briar Project

#71

Earlier quoted context omitted.

It's right in Apple's privacy policy, see Disclosure to Third Parties section: https://www.apple.com/legal/privacy/en-ww/ They obviously sell user data in aggregate - not at a personal level, but which of the big tech companies sell personal data (maybe FB / Cambridge Analytica?) Also, Apple has Google as the default search engine which Google pays billions for. Is that selling your personal data?

You mean the disclosure to third parties section that explicitly says "Apple does not sell personal information"? I can't see anything in that section that says that they sell information to third parties, personally identifiable or aggregate (I would consider the latter to be "personal" data as well fwiw). Is there a specific sentence you're thinking of? It seems to be talking about the necessary sharing of data tha…

They target ads to your interests, default on:

"Ads that are delivered by Apple’s advertising platform may appear in Apple News and in the App Store. If you do not wish to receive ads targeted to your interests from Apple's advertising platform, you can choose to enable Limit Ad Tracking, which will opt your Apple ID out of receiving such ads regardless of what device you are using. If you enable Limit Ad Tracking on your mobile device, third-party apps cannot use the Advertising Identifier, a non-personal device identifier, to serve you targeted ads. You may still see ads in the App Store or News based on context like your search query or the channel you are reading. In third-party apps, you may see ads based on other information."

Re: Briar Project

#72
post #44

Earlier quoted context omitted.

If spying on you is their business model, why would they build an app to prevent you from being spied?

Spying on you is not Apple's business model.

It is, alongside limiting what you can do with their leased equipment that people think they bought.

Re: Briar Project

#73
post #48

Criminal conspiracy as a service. I don’t think I’d invest my money. Edit: to clarify their marketing is transparently targeting organizers of street violence. I have no problem with encryption and don’t think government forbidding it is a good idea.

One of the core contradictions of liberal democracy is that all of the freedoms we hold up as advantages of it were obtained by people violently protesting it: labor rights, LGBT rights, environmental legislation, and obviously we are still fighting..

So, congratulations, I guess, on being privileged enough that your interests have always aligned with the interests of the state.

Re: Briar Project

#74
Earlier this year, I finally took the time to revisit the state of instant messaging services. My requirements:

- open source

- cross-platform (linux, mac, windows, ios, android)

- group chats

- end-to-end encryption

- well-understood crypto ciphers & protocols

- mature enough for a reasonable expectation of security & privacy

- easy enough for most computer users

- some way to protect metadata (e.g. self-hosting)

- signup without real-world ID

- offline message delivery

I ended up choosing the Matrix network. The reference client is called Element[1] (formerly Riot). There are things I dislike about the client, but they're pretty minor compared to the benefits of the underlying protocol, and lots of alternative clients are in development[2][3].

On top of meeting my requirements, all signs indicate that development is both active and moving in the right directions. Reading the team's weekly reports and issue tracker convinced me that they are making very sound decisions.

[1]: https://element.io/

[2]: https://matrix.org/clients-matrix/

[3]: https://matrix.org/clients/

Here's what I didn't like about the others:

Briar: Lacked cross-platform support and (iirc) offline messaging. Tor brings baggage that not everyone is ready to accept.

Cwtch: Not mature yet.

Jami: Very fragile code base in my experience, which was also true when was called Ring, and when it was called SFLphone. Only about 25% of the builds I've tried over the years actually worked. I was unable to determine whether it had offline messaging.

Keybase: Now owned by Zoom, which is a privacy nightmare.

Ricochet: Same problems as Briar.

RocketChat: Crypto is not mature yet.

Session: Not mature yet. Small limit on number of group chat participants.

Signal: Required phone number for signup. Required Google Play Services (aka spyware) for quite a long time. Weak cross-platform support. Some of that is finally changing, but Moxie will surely make more intolerable design decisions, and refuse to fix them for years, again.

Telegram: Homebrew crypto.

XMPP: Most clients are hard to use (or to teach others to use). Good servers are hard to find. Protocol standards are a mess. I couldn't find a real-world e2ee group chat implementation.

Everything else: Failed to meet my requirements even before I looked closely, mostly due to closed code and/or problematic corporate interests. (For example, I will not use an app from Facebook or any of its subsidiaries.)

Re: Briar Project

#75

Earlier quoted context omitted.

You mean the disclosure to third parties section that explicitly says "Apple does not sell personal information"? I can't see anything in that section that says that they sell information to third parties, personally identifiable or aggregate (I would consider the latter to be "personal" data as well fwiw). Is there a specific sentence you're thinking of? It seems to be talking about the necessary sharing of data tha…

They target ads to your interests, default on: "Ads that are delivered by Apple’s advertising platform may appear in Apple News and in the App Store. If you do not wish to receive ads targeted to your interests from Apple's advertising platform, you can choose to enable Limit Ad Tracking, which will opt your Apple ID out of receiving such ads regardless of what device you are using. If you enable Limit Ad Tracking on…

A third party being able to list ads on apples ad platform that target some collection of desired user data is not the same thing as said third party obtaining user data.

Third parties are buying ad listings, not user data. They have no way to extract user data from the ad platform, unless there's some kind of data leak.

If you think Apple is harvesting data off of bought back phones to improve their ad targeting that would also be a scandal (that I would expect some evidence of - otherwise it's just baseless speculation), but referring to it as "selling user data" is just obscuring what you're actually trying to communicate.

Re: Briar Project

#76

Earlier quoted context omitted.

Spying on you is not Apple's business model.

Oh indeed it is. I spent years reading apple reports and my conclusion was that they want the data for themselves so they can sell it. Devices don't make much profit when you factor in how much is spent buying up almost all old devices that hit the market.

> I spent years reading apple reports

Which ones?

Re: Briar Project

#77
post #70

I don’t have an answer, but a slightly different perspective. Many different segments have a deep interest in using highly secure encrypted communications: politicians working on deals within/between governments (that should be auditable, but many try to avoid that), whistleblowers, organizers operating in adverse governments, dissidents, terrorists, pedophiles with a lot to lose (similar to Epstein’s network), healt…

> It takes one of the egregious bad actors using the system to commit a crime worthy of public attention before the entire system is justifiably unpacked, banned, or considered a signal of bad intentions.

Banning encryption because bad actors use it is not justifiable.

Re: Briar Project

#78
post #57

Earlier quoted context omitted.

I've pondered the merits of someone spreading a virus that just sends (small, but relatively constant and random) amounts of encrypted data (maybe to other infected devices, and various other endpoints). Spread it widely enough and everyone gets to communicate privately with plausible deniability. Of course it doesn't even need to be real data, random gibberish would work too.

Perhaps. Back in the 80's, folks on Usenet would add words like "nuclear", "bomb", "spy", "communist" to their email footers and posting signatures, in hopes of overloading the (suspected/expected) NSA monitoring of traffic. I'm going to guess that sophisticated filters dealt effectively with such things back then, and even more sophisticated filters would deal with your random encrypted bits too.

Curious anecdote, some underground Japanese P2P networks have files with contents filled with references to Tiananmen, Tibet and the Uyghurs etc. probably to attract attention from CCP to deter Chinese users from downloading them.

Re: Briar Project

#80

Earlier quoted context omitted.

Spying on you is not Apple's business model.

It is, alongside limiting what you can do with their leased equipment that people think they bought.

This made me jump. You make one excellent point, with appropriately shocking language:

When I can’t do what I want with my phone, I may as well be leasing it. Hmmm.

But I don’t believe Apple’s business model is to spy on me.

Post reply on HN