Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

261–270 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#261

Earlier quoted context omitted.

Do you not sync to iCloud?

That sounds like "with opt in permission".

You aren't wrong, but... it's odd coming here to HN and seeing people talk about privacy like we aren't in the nth generation of people trading theirs away for a pittance. I think the market for the sort of privacy envisioned by some here is incredibly small, incredibly niche, and honestly one of the least likely to buy an iPhone in the first place.

Most people broadcast their lives on social media, happily opt in to all sorts of schemes that track them just for minor conveniences. For people like that, the idea that the privacy protection outlined by the OP isn't enough rings really hollow.

Or to put it bluntly, at some point this really stops feeling like a practical debate, and more of an ideological one.

Re: Apple Photos phones home on iOS 18 and macOS 15

#262
post #130

This whole thing is reminding me of the outrage over Apple and Google's privacy preserving 'Exposure Notification System' system from the Covid years. It defies intuition that they can alert you to exposure without also tracking you, but indeed that's what the technology lets you do. Similarly here, it feels like the author is leaning into a knee jerk reaction about invasion of privacy without really trying to evalua…

I would love to evaluate the privacy of these technologies. Someone reply with a link to the source code so I can see exactly what it is doing, without having to take an internet rando's word for it. Better yet, let me compile it myself.

If you have the capability to actually skillfully analyze this type of crypto, disassembling the binaries from your device (or at the very least, an ipsw for your device) should be trivial.

After all, you wouldn’t actually be trusting the source code given to you to match what’s running on your device, would you?

Re: Apple Photos phones home on iOS 18 and macOS 15

#263

Earlier quoted context omitted.

What would be the value to the user in your scenario? In the photos app real scenario, it’s to enable a search feature that requires pairing photos with data not on the phone. (I understand you’re being sarcastic.)

Maybe we can do some analysis and optimize phone battery life based on your cohorts usage patterns. I don't know, I'm sure we'll figure something out once we have your data!

The entire point is that you don't actually have the data, only the client can decrypt any of it.

Re: Apple Photos phones home on iOS 18 and macOS 15

#264

Earlier quoted context omitted.

Maybe we can do some analysis and optimize phone battery life based on your cohorts usage patterns. I don't know, I'm sure we'll figure something out once we have your data!

The entire point is that you don't actually have the data, only the client can decrypt any of it.

[deleted]

Re: Apple Photos phones home on iOS 18 and macOS 15

#265
post #194

Earlier quoted context omitted.

Thank you for this comment. I found the author's ignorance to be fairly discrediting, and was surprised to find so many follow up comments equally railing on Apple. Between the quote you pointed out and: "One thing I do know, however, is that Apple computers are constantly full of privacy and security vulnerabilities, as proved by Apple's own security release notes" which just reeks of survivorship bias. I think the…

> I found the author's ignorance to be fairly discrediting Why in the world am I supposed to be an expert on homomorphic encryption? How many people in the world are experts on homomorphic encryption? > which just reeks of survivorship bias. What does that even mean in this context? > 1: Feature value What is the value of the feature? As the article notes, this new feature is flying so low under the radar that Apple…

> Why in the world am I supposed to be an expert on homomorphic encryption? How many people in the world are experts on homomorphic encryption?

No one, at any point, implied you had to be an expert on homomorphic encryption. But if you're going to evaluate the security risk of a feature, and then end up on the front page of HN for said security risk, I think it's fair to criticize your lack of objectivity (or attempt at objectivity) by way of not even trying to understand the technical details of the blog.

I will say I think my word choice was unnecessarily harsh, I'm sorry. I think I meant more indifference/inattention.

> What does that even mean in this context?

Apple's list of Security releases is long and storied. By comparison, the Solana Saga Web3 phone's list of security releases is short and succinct. Therefore, the Solana Saga must be more secure and has better security than an Apple device!

> What is the value of the feature? As the article notes, this new feature is flying so low under the radar that Apple hasn't bothered to advertise it, and the Apple media haven't bothered to mention it either. You have to wonder how many people even wanted it.

The marketability of a feature is not necessarily correlated with its value. Some features are simply expected and would be silly to advertise, i.e. the ability to check email or text friends. Other features are difficult to evaluate efficacy, so you release and collect feedback instead of advertising and setting false expectations.

> Lockdown mode is basically for famous people and nobody else.

Similar to Feature value, that audience of that statement is your average person (read: does not read/post on hacker news). Based off the your pedigree, I feel as though you probably know better, and given your "no tolerance for risk" for such a feature, it's something worth at least considering, and definitely isn't ridiculous.

I think it's great you started this conversation. I disagree with your opinion, and that's okay!! But I don't think it's particularly beneficial to any discourse to 1. Imply that you are evaluating security risk 2. Be given a well written technical article so that you are able to make an informed decision (and then share that informed decision) 3. Ignore relevant information from said article, make an uninformed decision 4. Be surprised when someone says you made an uninformed decision 5. Imply the only way to make an informed decision would be to be an expert in the relevant fields from the technical article

Anyway - thanks for writing and replying. Creating and putting yourself out there is hard (as evidenced by my empty blog that I promised I'd add to for the past 2 years). And my criticism was too harsh.

Re: Apple Photos phones home on iOS 18 and macOS 15

#266
post #180

Earlier quoted context omitted.

> This is what a good privacy story looks like. A good privacy story actually looks like not sending any info to anyone else anywhere at any time.

Your answer shows how we all have a very different idea of what our own desired privacy level is. Or what privacy even means.

If you think that sending data to a remote server is equally private to not sending it, then you are the one who doesn't know what privacy means.

Of course it's fine to not desire privacy, or to desire a privacy level that is less than private. That's up to you. I liked the privacy of my old Canon digicam that had no internet. A photo app on a phone that sends stuff over the network might bring some useful functionality in return, but it can only be considered a regression in terms of privacy.

Re: Apple Photos phones home on iOS 18 and macOS 15

#267
post #97
post #40

Earlier quoted context omitted.

I think it does address the main problem. What he is saying is that multiple layers of security is used to ensure (mathematically and theoretically proved) that there is no risk in sending the data, because it is encrypted and sent is such a way that apple or any third party will never be able to read/access it (again, based on theoretically provable math) . If there is no risk there is no harm, and then there is a d…

Except for the fact (?) that quantum computers will break this encryption so if you wanted to you could horde the data and just wait a few years and then decrypt?

Quantum computers don't and won't meaningfully exist for a while, and once they do exist, they still won't be able to crack it. Quantum computers aren't this magical "the end is nigh" gotcha to everything and unless you're that deep into the subject, the bigger question you've got to ask yourself is why is a magic future technology so important to you that you just had to post your comment?

Anyway, back to the subject at hand; here's Apple on that subject:

> We use BFV parameters that achieve post-quantum 128-bit security, meaning they provide strong security against both classical and potential future quantum attacks

https://machinelearning.apple.com/research/homomorphic-encry...

https://security.apple.com/blog/imessage-pq3/

Re: Apple Photos phones home on iOS 18 and macOS 15

#268

Completely, 100% agreed: > the only way to guarantee computing privacy is to not send data off the device. > It ought to be up to the individual user to decide their own tolerance for the risk of privacy violations. [...] By enabling the "feature" without asking, Apple disrespects users and their preferences. I never wanted my iPhone to phone home to Apple. Regardless of how obfuscated or "secure" or otherwise "priva…

How much size would it take to store a model of every known location in the world and common things?

For ex: I sent a friend a photo of my puppy in the bathtub and her Airpods (via iphone) announced "(name) sent you a photo of a dog in a bathtub". She thought it was really cool and so do I personally. That's a useful feature. IDK how much that requires going off-device though.

Re: Apple Photos phones home on iOS 18 and macOS 15

#269
post #40

Earlier quoted context omitted.

I appreciate the explanation. However, I think you do not address the main problem, which is that my data is being sent off my device by default and without any (reasonable) notice. Many users may agree to such a feature (as you say, it may be very secure), but to assume that everyone ought to be opted in by default is the issue.

I think it does address the main problem. What he is saying is that multiple layers of security is used to ensure (mathematically and theoretically proved) that there is no risk in sending the data, because it is encrypted and sent is such a way that apple or any third party will never be able to read/access it (again, based on theoretically provable math) . If there is no risk there is no harm, and then there is a d…

You're welcome to check their implementation yourself:

https://github.com/apple/swift-homomorphic-encryption

Re: Apple Photos phones home on iOS 18 and macOS 15

#270
post #11

"I don't understand most of the technical details of Apple's blog post" I do: - Client side vectorization: the photo is processed locally, preparing a non-reversible vector representation before sending (think semantic hash). - Differential privacy: a decent amount of noise is added the the vector before sending it. Enough to make it impossible to reverse lookup the vector. The noise level here is ε = 0.8, which is q…

Can this be verified?
Post reply on HN