Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

61–70 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#61

Earlier quoted context omitted.

I hate this type of lukewarm take. "Ah, I see you care about privacy, but you own a phone! How hypocritical of you!"

If you care about your “privacy” and no external service providers having access to your data - that means you can’t use iCloud - at all, any messages service, any back up service, use Plex and your own hosted media, not use a search engine, etc.

Do you use a phone?

Re: Apple Photos phones home on iOS 18 and macOS 15

#62
post #58

Earlier quoted context omitted.

No I am trying to say with a connected device using online services, the service provider is going to have access to your data that you use to interact with them. To a first approximation, everyone in 2024 expects their data and settings to be transferred across devices. People aren’t working as if it is 2010 when you had to backup and restore devices via iTunes. If I’m out of town somewhere and my phone gets lost, d…

And that should rightfully be your informed choice . Just like everyone else should have the right to know what data their devices are sending before it happens and be given the informed choice to refuse. People shouldn’t have to learn that from a random blog post shared on a random website.

In what world is Netflix for instance not going to know your watch history?

How many people are going to say in 2024 that they don’t want continuous cloud backup? You want Windows Vista style pop ups and permissions?

Re: Apple Photos phones home on iOS 18 and macOS 15

#63
post #20
post #11

"I don't understand most of the technical details of Apple's blog post" I do: - Client side vectorization: the photo is processed locally, preparing a non-reversible vector representation before sending (think semantic hash). - Differential privacy: a decent amount of noise is added the the vector before sending it. Enough to make it impossible to reverse lookup the vector. The noise level here is ε = 0.8, which is q…

Quantum makes the homomorphic stuff ineffective in the mid-term. All they have to do is hold on to the data and they can get the results of the lookup table computation, in maybe 10-25 years. Shouldn't be on by default.

What makes you think that this is the biggest problem if things like AES and RSA are suddenly breakable?

If someone wanted to get a hold of your cloud hosted data at that point, they would use their capacity to simply extract enough key material to impersonate a Secure Enclave. That that point, you "are" the device and as such you "are" the user. No need to make it more complicated than that.

In theory, Apple and other manufacturers would already use PQC to prevent such scenarios. Then again, QC has been "coming soon" for so long, it's doubtful that any information that is currently protected by encryption will still be valuable by the time it can be cracked. Most real-world process implementations don't rely on some "infinite insurance", but assume it will be breached at some point and just try to make it difficult or costly enough to run out the clock on confidentiality, which is all that really matters. Nothing that exists really needs to be confidential forever. Things either get lost/destroyed or become irrelevant.

Re: Apple Photos phones home on iOS 18 and macOS 15

#64

Earlier quoted context omitted.

In response to your question in the parent comment, no, I do not use iCloud. And I do not sync any of the things you mentioned here. If someone already consented to using iCloud to store their photos then I would not consider the service mentioned this post to be such a big issue, because Apple would already have the data on their servers with the user's consent. edit: I will just add, even if we accept the argument…

Do you start fresh with an iOS installation after each upgrade or do you back up your iPhone using your computer and iTunes?

I do not have anything backed up on any cloud servers on any provider. If I had to buy a new phone I would start from a fresh installation and move all of my data locally. It's not that I'm a "luddite", I just couldn't keep track of all of the different ways each cloud provider was managing my data, so I disabled all of them.

Re: Apple Photos phones home on iOS 18 and macOS 15

#65

Another setting that surprised me with being turned on by default apparently on macOS 15 is System Settings - Spotlight - "Help Apple Improve Search": "Help improve Search by allowing Apple to store your Safari, Siri, Spotlight, Lookup, and #images search queries. The information collected is stored in a way that does not identify you and is used to improve search results."

No, this is not on by default. After system install at first boot it asks if you want to help improve search and it describes how your data will be handled, anonymized, etc. If you clicked on yes it is on. There is a choice to opt out.

Re: Apple Photos phones home on iOS 18 and macOS 15

#66

Earlier quoted context omitted.

If you care about your “privacy” and no external service providers having access to your data - that means you can’t use iCloud - at all, any messages service, any back up service, use Plex and your own hosted media, not use a search engine, etc.

Do you use a phone?

Yes. I also don’t use Plex, have my own file syncing service running, run my own email server, etc.

I also don’t run a private chat server that people log into - I’m like most of the iPhone and Android using world

Re: Apple Photos phones home on iOS 18 and macOS 15

#67
post #11

"I don't understand most of the technical details of Apple's blog post" I do: - Client side vectorization: the photo is processed locally, preparing a non-reversible vector representation before sending (think semantic hash). - Differential privacy: a decent amount of noise is added the the vector before sending it. Enough to make it impossible to reverse lookup the vector. The noise level here is ε = 0.8, which is q…

You're presenting a false dichotomy between "perfect user understanding" and "no user choice." The issue isn't whether users can fully comprehend homomorphic encryption or differential privacy – it's about basic consent and transparency.

Consider these points:

1. Users don't need a PhD to understand "This feature will send data about your photos to Apple's servers to enable better search."

2. The complexity of the privacy protections doesn't justify removing user choice. By that logic, we should never ask users about any technical feature.

3. Many privacy-conscious users follow a simple principle: they want control over what leaves their device, regardless of how it's protected.

The "it's too complex to explain" argument could justify any privacy-invasive default. Would you apply the same logic to, say, enabling location services by default because explaining GPS technology is too complex?

The real solution is simple: explain the feature in plain language, highlight the benefits, outline the privacy protections, and let users make their own choice. Apple already does this for many other features. "Default off with opt-in" is a core principle of privacy-respecting design, regardless of how robust the underlying protections are.

Re: Apple Photos phones home on iOS 18 and macOS 15

#68

Earlier quoted context omitted.

Do you start fresh with an iOS installation after each upgrade or do you back up your iPhone using your computer and iTunes?

I do not have anything backed up on any cloud servers on any provider. If I had to buy a new phone I would start from a fresh installation and move all of my data locally. It's not that I'm a "luddite", I just couldn't keep track of all of the different ways each cloud provider was managing my data, so I disabled all of them.

If only Apple had a centralized backup service that could store everything automatically at a click of a button so you wouldn’t have to juggle multiple cloud providers…

Re: Apple Photos phones home on iOS 18 and macOS 15

#69
post #40

Earlier quoted context omitted.

I appreciate the explanation. However, I think you do not address the main problem, which is that my data is being sent off my device by default and without any (reasonable) notice. Many users may agree to such a feature (as you say, it may be very secure), but to assume that everyone ought to be opted in by default is the issue.

I think it does address the main problem. What he is saying is that multiple layers of security is used to ensure (mathematically and theoretically proved) that there is no risk in sending the data, because it is encrypted and sent is such a way that apple or any third party will never be able to read/access it (again, based on theoretically provable math) . If there is no risk there is no harm, and then there is a d…

As someone with a background in mathematics I appreciate your point about cryptography. That said, there is no guarantee that any particular implementation of a secure theoretical algorithm is actually secure.

Re: Apple Photos phones home on iOS 18 and macOS 15

#70
post #35

Earlier quoted context omitted.

The right call is to provide the feature and let users opt-in. Apple knows this is bad, they've directly witnessed the backlash to OCSP, lawful intercept and client-side-scanning. There is no world in which they did not realize the problem and decided to enable it by default anyways knowing full-well that users aren't comfortable with this. People won't trust homomorphic encryption, entropy seeding or relaying when n…

> This is what a coverup looks like. That’s starting to veer into unreasonable levels of conspiracy theory. There’s nothing to “cover up”, the feature has an off switch right in the Settings and a public document explaining how it works. It should not be on by default but that’s not a reason to immediately assume bad faith. Even the author of the article is concerned more about bugs than intentions.

Sure it is. This isn't a feature or setting that users check often or ever. Now, their data is being sent without their permission or knowledge.
Post reply on HN