Live data from Hacker News

iOS 15

apple.com

201–210 of 431 posts

Re: iOS 15

#201

Earlier quoted context omitted.

> Run an on-device scan against a hash database. Using a technology shown to have very frequent collisions. Google and Microsoft have been scanning everything in your account against a hash database for the past decade. Also, unlike Apple's system which doesn't even notify Apple of the first 30 positive results (to protect you from the inevitable false positives) Google and Microsoft offer users no such protection. >…

Scanning content on a gmail account is not even remotely anything like scanning my device.

the photos are only scanned just before being uploaded to iCloud. If you have CSAM on your phone, just turn off iCloud sync

Re: iOS 15

#203

Earlier quoted context omitted.

How do they review the data if your iCloud photos are E2E encrypted?

Let the reader understand. (i.e. They're encrypted in transfer and while stored, but Apple holds the keys: https://qr.ae/pGSHY8 , https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app... [search for 'iCloud'])

For the lazy:

> Each file is broken into chunks and encrypted by iCloud using AES128 and a key derived from each chunk’s contents, with the keys using SHA256. The keys and the file’s metadata are stored by Apple in the user’s iCloud account. The encrypted chunks of the file are stored, without any user-identifying information or the keys, using both Apple and third party storage services—such as Amazon Web Services or Google Cloud Platform—but these partners don’t have the keys to decrypt the user’s data stored on their servers.

As far as I can tell, they don't say anything specific about where or how Apple stores the keys and metadata, so it should be assumed that Apple could decrypt your photos if they wanted to.

Re: iOS 15

#204

For anyone wondering, this was supposed to be the release where Apple could scan your photos for child abuse. This was delayed for this release: https://www.techradar.com/news/apple-delays-child-abuse-phot...

I wonder if upgrading to iOS 15 will increase the chance of receiving this spyware when they do roll it out? I mean 15.X - 15.Y will likely occur automatically while the phone is connected to WiFi and charging.. but 14 to 15 should require user approval, meaning we should be safe as long as we never upgrade >14..?

Turn off uploading photos to iCloud, and then if they start rolling it out, disable automatic updates.

Re: iOS 15

#205

My i-thing says it's up to date at 12.5.4. Wonder what that means securitywise.

It means it's old and doesn't support iOS 13. My iPad says the same thing. And according to Wikipedia, iOS 12 isn't receiving security updates anymore :(

However, the 12.5.4 is still quite a recent update (from June). I think there could still be some security fixes in the future, but probably only for very serious vulnerabilities.

Re: iOS 15

#206

Earlier quoted context omitted.

Leaving updates up to carriers makes it super hard to test mobile apps. You get a bug where it only happens on Samsung Whatever on Android 11, but the phone you bought for QA hasn't yet gotten that update. So you test on an emulators which, of course, don't reproduce the bug.

We had an issue at my previous company where our mobile game was crashing for like, one user. He had this whatever model of Samsung phone, but we had hundreds of people using that phone and no one else had issues. Turns out that, despite the model numbers and identifiers being identical, this one phone in this one country in SE Asia had a slightly different GPU setup and there was a bug in the drivers it shipped with…

That... that is nightmare fuel right there.

Re: iOS 15

#207

Earlier quoted context omitted.

> Run an on-device scan against a hash database. Using a technology shown to have very frequent collisions. Google and Microsoft have been scanning everything in your account against a hash database for the past decade. Also, unlike Apple's system which doesn't even notify Apple of the first 30 positive results (to protect you from the inevitable false positives) Google and Microsoft offer users no such protection. >…

Scanning content on a gmail account is not even remotely anything like scanning my device.

Scanning content on-server means that a single false positive is sitting there, ready to be maliciously misused by any prosecutor who cares to issue a dragnet warrant.

These sorts of dragnet warrants have become increasingly common.

>Google says geofence warrants make up one-quarter of all US demands

https://techcrunch.com/2021/08/19/google-geofence-warrants/

It's not like we haven't seen Google's on-server data hordes misused to falsely accuse users before.

>Innocent man, 23, sues Arizona police for $1.5million after being arrested for MURDER and jailed for six days when Google's GPS tracker wrongly placed him at the scene of the 2018 crime

https://www.dailymail.co.uk/news/article-7897319/Police-arre...

Apple's system is designed to protect you from being associated with false positives, until that threshold of 30 matches is reached. Even then, the next step is to have a human review the data.

Google has never been willing to hire human beings to supervise the decisions an algorithm makes.

Re: iOS 15

#209

Apple continues to support OS updates on the iPhone 6s, a device released almost 6 years ago. Nor is it reserved for their flagship models - the 2016 iPhone SE also gets the latest and greatest. Meanwhile, my flagship android phone from 2018, the Samsung Galaxy S9, is stuck on the last version of Android. At least it still gets security updates, some manufacturers don't even go that far.

> Apple continues to support OS updates on the iPhone 6s, a device released almost 6 years ago. Nor is it reserved for their flagship models - the 2016 iPhone SE also gets the latest and greatest.

I'm not sure whether this is a good thing though. After each major update, older devices become less and less usable. I would appreciate security updates, but I'd gladly skip all these new features that make my phone crawl.

Re: iOS 15

#210
I stayed away from the beta but hopped on as soon as this was released. Loving the bottom tab bars in safari, I don’t know what all the fuss was about.

Interesting that this “add comment” button on hacker news has some weird default style with a bright blue background.

Post reply on HN