Live data from Hacker News

Keeping your data from Apple is harder than expected

aalto.fi

161–170 of 244 posts

Re: Keeping your data from Apple is harder than expected

#161
post #2

> ‘Privacy. That's Apple,’ the slogan proclaims. New research from Aalto University begs to differ. > The researchers studied eight apps: Safari, Siri, Family Sharing, iMessage, FaceTime, Location Services, Find My and Touch ID. They collected all publicly available privacy-related information on these apps... > The fragility of the privacy protections surprised even the researchers. Reaction: Either their "surprise"…

Probably more like they were expecting better privacy practices than what Apple provided. One can be very competent but still surprised at just how bad things can be. Otherwise we would be discrediting a lot of climate researchers when they are surprised that things are progressing faster than expected.

I'm thinking there's considerable difference between:

- Predict that a gigacorp, which has been lucratively monetizing user information at gigascale for many years, would prove to be darn good at protecting its sources of user information. In a world where dark patterns, incomprehensible T&C's, "just say yes" user behavior, corporate misdeeds, etc. have been well-known things for many, many years.

and

- Predict the future of the planet's climate years ahead, when state-of-the-art weather forecasting can't yet manage 2 weeks.

(Admitting that I can see a good climate researcher using "surprised" very frequently - both for public consumption, and to summarize "our very-advanced-but-usually-wrong model was wrong yet again".)

Re: Keeping your data from Apple is harder than expected

#162
post #16

What I never understand is how engineers working at Apple think about the product they make. Can they love a device that shares data with their employer and advertisers?

Engineers go to Apple because they want the challenge of building complex features while minimizing the data that Apple and advertisers get. The article itself notes how many features keep data on the device only, or only sync data between devices via end-to-end encryption (in which case Apple does handle the data but cannot read it).

Re: Keeping your data from Apple is harder than expected

#163
post #108

Earlier quoted context omitted.

They are fundamentally different in that two of them derive revenue solely* from exploiting your data, and one of them doesn't. * by-and-large

They became as successful as they are by collecting massive amounts of data to learn to effectively psychologically manipulate people into buying their products, convincing them they are the most secure, fastest, most private option that will make people like them more for using. Apple is above all else a data driven marketing and advertising firm just like Google and Meta. They are profitable because they are effect…

Wild to assert that Steve “I never rely on marketing research” Jobs was successfully only because he did better market research than his competitors.

Re: Keeping your data from Apple is harder than expected

#164

Earlier quoted context omitted.

> It would be much better if I could just uninstall Siri. I don't want a voice assistant, and never have. I just don't turn it on and so never use it.

Car Play will not enable with Siri turned off (at least in my 2019 Subaru).

Same here. I do think it makes some sense in that case.

Re: Keeping your data from Apple is harder than expected

#165
post #153
post #95

Earlier quoted context omitted.

Apple operating systems automatically apply patches to devices for critical security updates so long as those patches are signed by a cryptographic private key held by Apple. That is in fact an RCE system that already exists. There also exist humans that have access to those private keys, and those humans can be controlled by money, court orders, or violence. In China the CCP has control over the software signing key…

You cannot really use that as argument. Everyone does that so it does not make Apple ”worse”. Same applies almost every Linux distribution since their builds are not reproducible. It is just a matter of who you want to trust. Eventually you need to trust someone.

Not everyone does this

My core area of research is supply chain attacks, and I run a company where we regularly train high risk organizations how to remove trust from any single human or system in critical areas of their stack like key management, CI/CD, etc. Many of our clients are fintech companies where trusting a single person, even a system administrator, would seriously endanger them.

Meanwhile Apple sysadmins still manage most of their infra with centrally controlled Puppet nodes last I heard.

Speaking of Linux distros, I created a 100% reproducible and full-source-bootstrapped Linux distro where every package is signed and reproduced by multiple people to avoid having to trust any single human, including me.

https://codeberg.org/stagex/stagex

Guix comes close to this mark too, so we are hardly the only viable option in town.

There are always alternatives to centralizing trust and you do not need to have an Apple-sized budget to afford them.

Re: Keeping your data from Apple is harder than expected

#166
post #76

For privacy-conscious people, the authors certainly picked an outlet with plenty of cookies and trackers - this is what the popup shows me when I pick "customise": 17 necessary cookies 7 functional 34 statistics 49 marketing 10 unclassified This kind of thing makes the article seem... ridiculous, really. Their site is much worse at privacy than Apple.

At least they have a "Reject all" button, easy to access (it should be the norm). Not some dodgy dark pattern that takes a good minute to find.

I think that's just GDPR?

> The requirement to offer a 'Reject All' button next to an 'Accept All' button follows indirectly from the consent requirements in the GDPR; consent must be as easy to revoke as it is to give.

https://www.dataguidance.com/opinion/eu-cookie-banners-and-u...

Re: Keeping your data from Apple is harder than expected

#167

"Lindqvist can’t comment directly on how Google's Android works in similar respects" Of course he can't, because its easier to jump on the Apple bashing bandwagon. I suspect if you did a side-by-side comparison, we all know where Android would fall on the privacy spectrum. Give me Apple over Google any day of the week. I expected better from Lindqvist than take part in a biased article like that.

Someone can be the best at something and still need improvement. Just look at Apple every year working to improve security.

Rather than just assume everything is fine, it's important to call out deficiencies. Especially when someone is seen as the best at something.

Being the best doesn't mean you are good. It just means everyone else is worse.

Re: Keeping your data from Apple is harder than expected

#168
post #50

I remain shocked anyone trusts Meta, Google, or Apple marketing on privacy. These companies are all fundamentally similar in that their proprietary software collects an insane amount of data that will end up in the hands of your enemies either by sale, court order, or security compromise. It is relatively easy to opt out of all of these companies and take some actual control over your privacy.

They are fundamentally different in that two of them derive revenue solely* from exploiting your data, and one of them doesn't. * by-and-large

it seems Apple's hardware revenue have started to plateau, and their services revenue is in jeopardy with the new EU changes to the App Store

it wouldn't surprise me if Apple started ramping up their data revenue in the near future to compensate

Re: Keeping your data from Apple is harder than expected

#169
post #140

Someone much more tech savvy than me should try to use Charles Proxy on an iOS device and see how often your phone is communicating with Apple servers. It’s pretty wild.

> Someone much more tech savvy than me should try to use Charles Proxy on an iOS device and see how often your phone is communicating with Apple servers. It’s pretty wild. You can also see this just by running an iOS simulator with Xcode on a Mac that has Little Snitch installed. The amount of phoning home by iOS (and macOS, for that matter) is shocking.

What is even more shocking is running an Android simulator in the same context. Literally dozens of Little Snitch prompts before the OS even boots to the lock screen. Not defending Apple here, but when I was developing a mobile app in both Xcode and Android Studio I noticed a marked difference in the amounts of phoning home.

Re: Keeping your data from Apple is harder than expected

#170

Earlier quoted context omitted.

> Apple should provide an option to opt-out of Siri "learn from app" for ALL applications. You can. Use the free Apple Configurator tool to generate a profile that has: - "Allow Siri" unchecked - "Allow Siri Suggestions" unchecked Apple Configuratior is great. You can disable all sorts of things, e.g. iCloud access. If your iPhone is on $org MDM, you can do the same on MDM.

The Apple Configurator is only allowed for a Managed Apple ID.

I was able to use Apple Configurator to put a phone into single app mode with a normal, non-developer ID.

Maybe there is a subset of things you can do?

Post reply on HN