Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

111–120 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#111

Earlier quoted context omitted.

> This is what a coverup looks like This is a dumb take. They literally own the entire stack Photos runs on. If they really wanted to do a coverup we would never know about it.

Why wouldn't this mistake be addressed in a security hotfix then? Apple has to pick a lane - this is either intended behavior being enabled against user's wishes, or unintended behavior that compromises the security and privacy of iPhone owners.

Or option (c).

This is a useful, harmless feature that does not comprise security or privacy in any way.

Re: Apple Photos phones home on iOS 18 and macOS 15

#112
post #11

"I don't understand most of the technical details of Apple's blog post" I do: - Client side vectorization: the photo is processed locally, preparing a non-reversible vector representation before sending (think semantic hash). - Differential privacy: a decent amount of noise is added the the vector before sending it. Enough to make it impossible to reverse lookup the vector. The noise level here is ε = 0.8, which is q…

[deleted]

Re: Apple Photos phones home on iOS 18 and macOS 15

#113
post #73

Earlier quoted context omitted.

Which is wrong but doesn’t make it a coverup, which by definition assumes trying to hide evidence of wrongdoing.

It is a coverup. Apple is overtly and completely aware of the optics surrounding photo scanning - they know that an opt-in scheme cannot work as they found out previously. Since they cannot convince users to enable this feature in good-faith, they are resorting to subterfuge. We know that Apple is vehement about pushing client-side scanning on users that do not want it, I do not believe for a second that this was a m…

> they are resorting to subterfuge

This is illogical. If Apple wanted to engage in subterfuge they would simply compromise the OS.

When a company controls the entire stack either you trust everything they do. Or nothing.

Re: Apple Photos phones home on iOS 18 and macOS 15

#114

At this point, Mac Mini M4's are cheap enough and capable enough to just purchase two: one for off-line use, another on-. Perhaps this is marketing genius (from an AAPL-shareholder POV)? ---- I'm laughing at the insanity of all this interconnectivity, but an NDA prevents me from typing the greatest source of my ironic chuckles. Described in an obtuse way: a privacy-focused hardware product ships with an undisclosed p…

> letting the feds see every time you use the product This does not happen.

Wrong. Anything that makes any network request is by definition a privacy leak. The network itself is always listening, and the act of making any connection says that you are using the computer, and where, and when.

Re: Apple Photos phones home on iOS 18 and macOS 15

#115

Earlier quoted context omitted.

I appreciate the explanation. However, I think you do not address the main problem, which is that my data is being sent off my device by default and without any (reasonable) notice. Many users may agree to such a feature (as you say, it may be very secure), but to assume that everyone ought to be opted in by default is the issue.

When your phone sends out a ping to search for cellular towers, real estate brokers collect all that information to track everywhere you go and which stores you visit. Owning a phone is a privacy failure by default in the United States.

You are being downvoted because you're so painfully correct. It's not an issue exclusive to the United States, but American intelligence leads the field far-and-away on both legal and extralegal surveillance. The compliance forced by US Government agencies certainly helps make data tracking inescapable for the average American.

Unfortunately, the knee-jerk reaction of many defense industry pundits (and VCs, for that matter) is that US intelligence is an unparalleled moral good, and the virtues of privacy aren't worth hamstringing our government's work. Many of these people will try to suppress comments like yours because it embarrasses Americans and American business by association. And I sympathize completely - I'm dumbfounded by the response from my government now that we know China is hacking our telecom records.

Re: Apple Photos phones home on iOS 18 and macOS 15

#116
post #11

"I don't understand most of the technical details of Apple's blog post" I do: - Client side vectorization: the photo is processed locally, preparing a non-reversible vector representation before sending (think semantic hash). - Differential privacy: a decent amount of noise is added the the vector before sending it. Enough to make it impossible to reverse lookup the vector. The noise level here is ε = 0.8, which is q…

> "It ought to be up to the individual user to decide their own tolerance for the risk of privacy violations." -> The author themselves looks to be an Apple security researcher, and are saying they can't make an informed choice here

I don’t think that that’s what the author is saying at all, I think he’s saying that Apple should let the user decide for themself if they want to send all this shit to Apple, freedom for the individual. They’re not saying “I dunno”

Re: Apple Photos phones home on iOS 18 and macOS 15

#117
post #35

Earlier quoted context omitted.

The right call is to provide the feature and let users opt-in. Apple knows this is bad, they've directly witnessed the backlash to OCSP, lawful intercept and client-side-scanning. There is no world in which they did not realize the problem and decided to enable it by default anyways knowing full-well that users aren't comfortable with this. People won't trust homomorphic encryption, entropy seeding or relaying when n…

> This is what a coverup looks like. That’s starting to veer into unreasonable levels of conspiracy theory. There’s nothing to “cover up”, the feature has an off switch right in the Settings and a public document explaining how it works. It should not be on by default but that’s not a reason to immediately assume bad faith. Even the author of the article is concerned more about bugs than intentions.

Would you feel the same if Microsoft turned on Recall on all Windows PCs everywhere with an update?

They worked very hard on security these past few months, so it should be all good, right?

Re: Apple Photos phones home on iOS 18 and macOS 15

#118

Earlier quoted context omitted.

Why wouldn't this mistake be addressed in a security hotfix then? Apple has to pick a lane - this is either intended behavior being enabled against user's wishes, or unintended behavior that compromises the security and privacy of iPhone owners.

Or option (c). This is a useful, harmless feature that does not comprise security or privacy in any way.

If it's a useful, harmless feature, then let users opt-in. You'd think Apple would have learned their lesson after a decade of people bitching about U2 being secreted-in to their iTunes library, but apparently not.

Users are smart enough to decide for themselves. Let them.

Re: Apple Photos phones home on iOS 18 and macOS 15

#119
post #44

Earlier quoted context omitted.

I think I'm saying: you're not sending "your data" off device. You are sending a homomorphically encrypted locally differentially private vector (through an anonymous proxy). No consumer can really understand what that means, what the risks are, and how it would compare to the risk of sending someone like Facebook/Google raw data. I'm asking: what does an opt in for that really look like? You're not going to be able…

In response your second question, opt in would look exactly like this: don't have the box checked by default, with an option to enable it: "use this to improve local search, we will create an encrypted index of your data to send securely to our servers, etc..." A PhD is not necessary to understand the distinction between storing data locally on a machine vs. on the internet.

Exactly. It's the height of arrogance to insist that normal users just can't understand such complex words and math, and therefore the company should not have to obtain consent from the user. As a normal lay user, I don't want anything to leave my device or computer without my consent. Period. That includes personal information, user data, metadata, private vectors, homomorphic this or locally differential that. I don't care how private Poindexter assures me it is. Ask. For. Consent.

Don't do things without my consent!!! How hard is it for Silicon Valley to understand this very simple concept?

Re: Apple Photos phones home on iOS 18 and macOS 15

#120

Earlier quoted context omitted.

> It's the equivalent of sending an MD5 of your password somewhere; you may still object, but it is not factually correct to say your password was transmitted. Hackers love to have MD5 checksums of passwords. They make it way easier to find the passwords in a brute force attack. https://en.wikipedia.org/wiki/Rainbow_table

>> It's the equivalent of […] > Hackers love to have MD5 checksums of passwords. Hackers love not understanding analogies. :)

Hackers love to make defective analogies (especially redundant recursive ones) and invite sarcastic corrections to them.
Post reply on HN