Live data from Hacker News

Keeping your data from Apple is harder than expected

aalto.fi

181–190 of 244 posts

Re: Keeping your data from Apple is harder than expected

#181

Apple should provide an option to opt-out of Siri "learn from app" for ALL applications. At present, this must be done individually for every app, https://www.imore.com/how-stop-siri-learning-how-you-use-app... . When you later install new apps after setting up the device, you have to remember to go into Settings and opt-out again, for every app, forever. How many people know that iOS devices will default to Siri rea…

Man I am really starting to hate these big tech companies. Everything they do is designed to be as invasive as possible.

Re: Keeping your data from Apple is harder than expected

#182
post #128

Earlier quoted context omitted.

From the article: “The user is given the option to enable or not enable Siri, Apple's virtual assistant. But enabling only refers to whether you use Siri's voice control. Siri collects data in the background from other apps you use, regardless of your choice, unless you understand how to go into the settings and specifically change that”.

A concern with Siri is it sends your voice data to a server to parse. When Siri is disabled, what data is collected via third party apps? I would imagine any time you use voice as a command in an app the iPhone send the data to a server to parse, even in third party apps. Is that the concern, or is it other data?

"Siri" is not just the voice assistant, Apple also uses that designation for other "intelligent" features, like "Siri Suggestions" [0]. The related personal information is shared across devices via Apple servers. Apple states that any analytics shared with Apple are anonymized [1], but users may still prefer to not share analytics in the first place. However, that can't be opted out globally, it can only be disabled per app [0]. Except maybe by turning off Siri in iCloud [2]? It's not clear. That's the criticism, it's difficult for users to understand what settings are enabling or disabling what exactly. It's quite complicated overall, and difficult to tell what you are and aren't sharing.

[0] https://support.apple.com/guide/iphone/about-siri-suggestion...

[1] https://www.apple.com/legal/privacy/data/en/siri-suggestions...

[2] https://support.apple.com/guide/iphone/tell-siri-about-yours...

Re: Keeping your data from Apple is harder than expected

#183
post #150
post #97

Earlier quoted context omitted.

> I live in Silicon Valley, run a b2b tech company ... I have not carried a phone or an Google/Apple controlled device in 3+ years and exclusively use FOSS on a personal basis. Y'know, a regular salt-of-the-earth type guy

My point was if someone about as technically connected as one can be is capable of thriving without a phone, basically anyone can.

It's interesting you think your technical savvy is correlated with necessity.

Re: Keeping your data from Apple is harder than expected

#184
post #67

Apple should provide an option to opt-out of Siri "learn from app" for ALL applications. At present, this must be done individually for every app, https://www.imore.com/how-stop-siri-learning-how-you-use-app... . When you later install new apps after setting up the device, you have to remember to go into Settings and opt-out again, for every app, forever. How many people know that iOS devices will default to Siri rea…

>How many people know that iOS devices will default to Siri reading plaintext for all apps, including E2EE messengers? Is there more on what Siri "learn from app" actually does? Does it scrape entire screen contents? Or just metadata? Or only what the app developer decides to send?

My understanding is that the "learn from app" setting relates to it watching out for NSUserActivity, which is something the app developer has to explicitly send out. The app developer is motivated to do so because NSUserActivity powers a lot of system-integration features.

https://developer.apple.com/documentation/foundation/nsusera...

Re: Keeping your data from Apple is harder than expected

#185
post #76

For privacy-conscious people, the authors certainly picked an outlet with plenty of cookies and trackers - this is what the popup shows me when I pick "customise": 17 necessary cookies 7 functional 34 statistics 49 marketing 10 unclassified This kind of thing makes the article seem... ridiculous, really. Their site is much worse at privacy than Apple.

Sorry, but that's a fallacy:

https://en.wikipedia.org/wiki/Tu_quoque

Re: Keeping your data from Apple is harder than expected

#186
post #149

Earlier quoted context omitted.

Do you have to select car parks based on ones that don't require an app? More and more near me require an app to pay for parking.

Typically you can use a webapp or find a paystation where you can use cash or a prepaid credit card. If there are really no humans at all I would just park further or sometimes just park anyway and risk 1/3 chance I get a $20 ticket once in a while I can then pay online without an app. Sometimes paying occasional tickets instead of using the app can actually save you money.

> risk 1/3 chance I get a $20 ticket

They don't clamp where you are?

Here in Europe you will usually get clamped and have to wait for them to come out to release it and pay a 100 euro fine.

Re: Keeping your data from Apple is harder than expected

#187

"Lindqvist can’t comment directly on how Google's Android works in similar respects" Of course he can't, because its easier to jump on the Apple bashing bandwagon. I suspect if you did a side-by-side comparison, we all know where Android would fall on the privacy spectrum. Give me Apple over Google any day of the week. I expected better from Lindqvist than take part in a biased article like that.

It has already been done[1] and the conclusion is that Apple is not much/no better than Google. When it comes to user data I do believe that Apple is better due to Google’s revenue being from advertisements. Yet Apple has begun exploring this space and at that point I consider them as bad as each other.

[1] https://www.scss.tcd.ie/doug.leith/apple_google.pdf

Re: Keeping your data from Apple is harder than expected

#188
post #125

Earlier quoted context omitted.

Hmm here in Spain it's more difficult. Nobody uses SMS here (nor iMessage), it's all WhatsApp and Telegram. And most banks do force an app here (for 2FA payments for example). Tickets can go on paper yeah, though some restaurants I visit don't do paper menus (especially the asian ones). Also some stuff for work is mobile-only. We have a stupid 2FA system that only works with a mobile app (the company gives us a phone…

> Whatsapp/iMessage Both can be bridged to Matrix, which can be accessed with any OS you like with FOSS software. > Tickets can go on paper yeah, though some restaurants I visit don't do paper menus (especially the asian ones). Many have said this to me initially, until I insist I do not own a cell phone. Then they always find a way to produce a tablet for me, or hastily print a screenshot from a phone, or find an ol…

> Both can be bridged to Matrix, which can be accessed with any OS you like with FOSS software.

Correct, and I do exactly this. But WhatsApp requires a mobile device. It can work without the device turned on, but after a few weeks it will stop working. So you still need to have a phone though you don't need to bring it with you.

iMessage and SMS is totally not a thing at all here. But Telegram is (which doesn't require the mobile app luckily, in fact I really like Telegram despite the lack of end 2 end encryption in regular chats). They allow alternative clients, bots, and their paid plans are cheap enough and offer some features that are genuinely cool and useful. I use it most of the time with local people here instead of whatsapp, I only use that with the few people that don't have telegram.

I'm just mentioning this because in the US telegram appears to have a bad rep somehow. But to me it's one of the services that's the least trying to enshittify. Even Signal I don't use because it's just not terribly useful the way they implemented it.

> Almost nothing is truly mobile only. You can run Android applications on QubesOS in a pinch, but more generally I find most 2FA apps actually use TOTP or FIDO under the hood, and can be replaced with open alternatives with a bit of research.

That won't work. My work requires MDM management of the mobile device for accessing work stuff. And the 2FA app is unfortunately not TOTP or FIDO.

And I agree with you on the cash part yes.

Re: Keeping your data from Apple is harder than expected

#189
post #55

Earlier quoted context omitted.

Apple can remotely execute code on any internet connected device running an proprietary Apple operating system. It is only a matter of time before courts realize this. The CCP controls the Apple software signing HSMs in China for a reason.

But if this is your threat model - that you have no trust of the operating system or the vendor - then all of this is pointless because at any time they can just backdoor themselves. Apple could just never ask or collect this, but still they're one update away from starting to collect it. Of course that's always a threat with any computer, but you must place some amount of trust somewhere .

  you must place some amount of trust somewhere.
Using something and trusting it are different things.

Re: Keeping your data from Apple is harder than expected

#190
post #153
post #95

Earlier quoted context omitted.

Apple operating systems automatically apply patches to devices for critical security updates so long as those patches are signed by a cryptographic private key held by Apple. That is in fact an RCE system that already exists. There also exist humans that have access to those private keys, and those humans can be controlled by money, court orders, or violence. In China the CCP has control over the software signing key…

You cannot really use that as argument. Everyone does that so it does not make Apple ”worse”. Same applies almost every Linux distribution since their builds are not reproducible. It is just a matter of who you want to trust. Eventually you need to trust someone.

  Eventually you need to trust someone.
There are plenty of things I use but don't trust.
Post reply on HN