Live data from Hacker News

Apple: Android is a tracking device [pdf]

justice.gov

81–87 of 87 posts

Re: Apple: Android is a tracking device [pdf]

#81
post #41

Earlier quoted context omitted.

On the flipside e.g. in Germany this has been used to track down creators of illegal graffiti, using a law that is intended for terrorism and other heavy crimes. We can allow search and rescue missions without having to also accept abuse of power.

Can you reference anywhere where that happened because I've never heard of that and would expect huge pushback in Europe in general..

I think I found the talk I got most of the info from [0]. The interesting parts about the law and how it was abused start roughly at 25:03, though unfortunately it's only available in German (Edit: turns out it actually does have an English audio track).

A very short summary: the law is only supposed to be used for very severe crimes and only if the investigation would otherwise be significantly more difficult or impossible. Also the owners of the tracked phones have to be notified of the tracking as it is a violation of the person's rights. In reality (at the date of the talk) it had never been used for terrorism, about 5% of the time for crimes like murder and in over 70% of the time for theft (including a case of stolen empty beer barrels), and nobody was ever notified.

[0] https://media.ccc.de/v/35c3-9972-funkzellenabfrage_die_allta...

Re: Apple: Android is a tracking device [pdf]

#82
post #41

Earlier quoted context omitted.

Can you reference anywhere where that happened because I've never heard of that and would expect huge pushback in Europe in general..

I think I found the talk I got most of the info from [0]. The interesting parts about the law and how it was abused start roughly at 25:03, though unfortunately it's only available in German (Edit: turns out it actually does have an English audio track). A very short summary: the law is only supposed to be used for very severe crimes and only if the investigation would otherwise be significantly more difficult or imp…

Thank you, those stats of the usage seem fine on paper, maybe worse than they should be, I'm still waiting to see what parent was talking about when he inferred abuse..

Europe does need a security authority, that doesn't depend on slow bureaucracy.

Re: Apple: Android is a tracking device [pdf]

#83

Earlier quoted context omitted.

I would guess is because Apple and Google have different business models, Google is an ad company specializing on collecting info while Apple is selling hardware and software.

https://searchads.apple.com/ https://news.ycombinator.com/item?id=34299433

What does this prove? That I was wrong about my assumption because an article about Apple having incorrect default setting?

Re: Apple: Android is a tracking device [pdf]

#84
post #27
post #17

Earlier quoted context omitted.

How do you square that claim with E2EE and the way Find My works?

Not everything is under E2EE and the Find My is probably not the biggest privacy problem of Apple.

Ah, I stand corrected. They do monitor and intercept everything, then.

Re: Apple: Android is a tracking device [pdf]

#85
post #14

Earlier quoted context omitted.

That’s true of everything you haven’t compiled yourself, using a compiler you wrote and bootstrapped yourself. There is no technical proof that any of the software or hardware we use every day is trustworthy. There is, however, incentive alignment that makes it unlikely that companies do wild and crazy things.

> That’s true of everything you haven’t compiled yourself Except if your software is reproducible: https://reproducible-builds.org/

Still not 100% secure. Someone can MITM your connection and forge the info used to verify builds.

It’s a silly example, but the point stands: there is no 100% security for anything that any other person or system has had any access to. It’s not a reasonable standard to demand.

Re: Apple: Android is a tracking device [pdf]

#86
post #85

Earlier quoted context omitted.

> That’s true of everything you haven’t compiled yourself Except if your software is reproducible: https://reproducible-builds.org/

Still not 100% secure. Someone can MITM your connection and forge the info used to verify builds. It’s a silly example, but the point stands: there is no 100% security for anything that any other person or system has had any access to. It’s not a reasonable standard to demand.

There is no 100% of anything, but there is a reasonable security.
Post reply on HN