Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

161–170 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#161
post #11

"I don't understand most of the technical details of Apple's blog post" I do: - Client side vectorization: the photo is processed locally, preparing a non-reversible vector representation before sending (think semantic hash). - Differential privacy: a decent amount of noise is added the the vector before sending it. Enough to make it impossible to reverse lookup the vector. The noise level here is ε = 0.8, which is q…

> This is what a good privacy story looks like.

A good privacy story actually looks like not sending any info to anyone else anywhere at any time.

Re: Apple Photos phones home on iOS 18 and macOS 15

#162

Earlier quoted context omitted.

I’m deeply familiar with all of these techniques, the core issue here is informed consent which they have not obtained. Furthermore, Apples privacy stance is generally a sham as their definition of “human rights” doesn’t extend to China. Which either means Apple doesn’t respect human rights, or they don’t view Chinese people as human.

That's not really fair; Apple's in a sticky wicket when it comes to the Chinese government, and they're not the only ones. The Chinese government are debatably inhuman. They've literally censored the word "censorship." (Then they censored what people used euphemistically for censorship--"harmonious.") It's funny from the outside but also a miserable state of affairs in 2024.

It’s very fair, Apple has historically been very happy to be the sponsor of horrible human rights violations in their supply chain, only marginally paying attention to suicides in their factories when the PR got too bad.

Apples version of “human right” includes suicide nets as an alternative to treating people humanely. That’s why their stance is pure marketing - they have blood on their hands.

And guess what? You can’t use Google in China, and while Google isn’t by any means perfect, they aren’t Apple.

Re: Apple Photos phones home on iOS 18 and macOS 15

#163

Another setting that surprised me with being turned on by default apparently on macOS 15 is System Settings - Spotlight - "Help Apple Improve Search": "Help improve Search by allowing Apple to store your Safari, Siri, Spotlight, Lookup, and #images search queries. The information collected is stored in a way that does not identify you and is used to improve search results."

No, this is not on by default. After system install at first boot it asks if you want to help improve search and it describes how your data will be handled, anonymized, etc. If you clicked on yes it is on. There is a choice to opt out.

I was on by default for me, both after the macOS 14 -> 15 upgrade and after installing macOS 15 cleanly. I wonder if they ask for consent in some regions only.

Re: Apple Photos phones home on iOS 18 and macOS 15

#164

Earlier quoted context omitted.

When your phone sends out a ping to search for cellular towers, real estate brokers collect all that information to track everywhere you go and which stores you visit. Owning a phone is a privacy failure by default in the United States.

You are being downvoted because you're so painfully correct. It's not an issue exclusive to the United States, but American intelligence leads the field far-and-away on both legal and extralegal surveillance. The compliance forced by US Government agencies certainly helps make data tracking inescapable for the average American. Unfortunately, the knee-jerk reaction of many defense industry pundits (and VCs, for that…

FWIW, SS7 had known flaws very long ago.

It's apparent it has been kept in place because of all of the value it provides to the 5 eyes.

Re: Apple Photos phones home on iOS 18 and macOS 15

#165
post #154

Earlier quoted context omitted.

I appreciate the explanation. However, I think you do not address the main problem, which is that my data is being sent off my device by default and without any (reasonable) notice. Many users may agree to such a feature (as you say, it may be very secure), but to assume that everyone ought to be opted in by default is the issue.

I'm not sure I agree -- asking users about every single minor feature is (a) incredibly annoying, and (b) quickly causes request-blindness in even reasonably security-conscious users. So restraining the nagging for only risky or particularly invasive things makes sense to me. Maybe they should lump its default state into something that already exists? E.g. assume that if you already have location access enabled for P…

> Maybe they should lump its default state into something that already exists?

It could be tied to iCloud Photos, perhaps, because then you already know that your photos are getting uploaded to Apple.

Re: Apple Photos phones home on iOS 18 and macOS 15

#166
post #11

"I don't understand most of the technical details of Apple's blog post" I do: - Client side vectorization: the photo is processed locally, preparing a non-reversible vector representation before sending (think semantic hash). - Differential privacy: a decent amount of noise is added the the vector before sending it. Enough to make it impossible to reverse lookup the vector. The noise level here is ε = 0.8, which is q…

> This is what a good privacy story looks like. A good privacy story actually looks like not sending any info to anyone else anywhere at any time.

Sure, but if we follow that line of thinking to its logical conclusion, we must move to a cabin in the woods, 100 miles from the nearest civilization, growing our own food and never connecting our computing devices to anything resembling a network.

Re: Apple Photos phones home on iOS 18 and macOS 15

#167

Earlier quoted context omitted.

As someone with a background in mathematics I appreciate your point about cryptography. That said, there is no guarantee that any particular implementation of a secure theoretical algorithm is actually secure.

There is also no guarantee that Apple isn't lying about everything. They could just have the OS batch uploads until a later point e.g. when the phone checks for updates. The point is that this is all about risk mitigation not elimination.

I’m stealing your information.

Hey! That’s wrong.

But I promise I won’t do anything wrong with it.

Well ok then.

Re: Apple Photos phones home on iOS 18 and macOS 15

#169
post #11

"I don't understand most of the technical details of Apple's blog post" I do: - Client side vectorization: the photo is processed locally, preparing a non-reversible vector representation before sending (think semantic hash). - Differential privacy: a decent amount of noise is added the the vector before sending it. Enough to make it impossible to reverse lookup the vector. The noise level here is ε = 0.8, which is q…

Thank you for this comment. I found the author's ignorance to be fairly discrediting, and was surprised to find so many follow up comments equally railing on Apple.

Between the quote you pointed out and:

"One thing I do know, however, is that Apple computers are constantly full of privacy and security vulnerabilities, as proved by Apple's own security release notes" which just reeks of survivorship bias.

I think the final call of what is right here _shouldn't_ be informed by the linked article.

IMO, enabled by default without opt-in is absolutely the right call when judging between 1: Feature value 2: Security risk 3: Consent Fatigue.

If you're data-conscious enough to disagree with my prior statement, you should consider having lockdown mode enabled.

If you disagree with my prior statement because of how Apple locks you into Photos, :shake_hands:.

If Enhanced Visual Search is still enabled by default in lockdown mode, then I think that's worth a conversation.

Re: Apple Photos phones home on iOS 18 and macOS 15

#170

Earlier quoted context omitted.

The average smartphone is probably doing a hundred things you didn’t knowingly consent to every second. Should Apple insist that every end user consents to the user agent string sent on every HTTP request?

> The average smartphone is probably doing a hundred things you didn’t knowingly consent to every second. You've succinctly identified a (maybe the ) huge problem in the computing world today. Computers should not do anything without the user's command/consent. This seems like a hopeless and unachievable ideal only because of how far we've already strayed from the light. Even Linux, supposedly the last bastion of use…

"The light" you claim is that users should have the knowledge and discernment to consent to what a computer does.

To me, there's never been a case, except maybe in the first decade or so of the hobby/tinkering PC movement, where most users had this ability.

Should we just not use computers?

Post reply on HN