"I don't understand most of the technical details of Apple's blog post" I do: - Client side vectorization: the photo is processed locally, preparing a non-reversible vector representation before sending (think semantic hash). - Differential privacy: a decent amount of noise is added the the vector before sending it. Enough to make it impossible to reverse lookup the vector. The noise level here is ε = 0.8, which is q…
Apple Photos phones home on iOS 18 and macOS 15
281–290 of 1001 posts
Re: Apple Photos phones home on iOS 18 and macOS 15
#282Earlier quoted context omitted.
Notice is always good and Apple should implement notice. However, "my data is being sent off my device" is incorrect, as GP explained. Metadata, derived from your data, with noise added to make it irreversible, is being sent off your device. It's the equivalent of sending an MD5 of your password somewhere; you may still object, but it is not factually correct to say your password was transmitted.
Well that's what you're told is happening. As it's all proprietary closed source software that you can't inspect or look at or verify in any manner, you have absolutely zero evidence whether that's what's actually happening or not.
Re: Apple Photos phones home on iOS 18 and macOS 15
#283Earlier quoted context omitted.
Do you not sync to iCloud?
You can enable Advanced Data Protection and all your iCloud data will be stored as encrypted blobs.
If only you and three other people have a unique file, Apple knows you are a group.
Re: Apple Photos phones home on iOS 18 and macOS 15
#284Earlier quoted context omitted.
I'm not sure I agree -- asking users about every single minor feature is (a) incredibly annoying, and (b) quickly causes request-blindness in even reasonably security-conscious users. So restraining the nagging for only risky or particularly invasive things makes sense to me. Maybe they should lump its default state into something that already exists? E.g. assume that if you already have location access enabled for P…
> Maybe they should lump its default state into something that already exists? It could be tied to iCloud Photos, perhaps, because then you already know that your photos are getting uploaded to Apple.
(We could argue about it, but personally I think some kind of hash doesn't qualify.)
Re: Apple Photos phones home on iOS 18 and macOS 15
#285Earlier quoted context omitted.
I appreciate the explanation. However, I think you do not address the main problem, which is that my data is being sent off my device by default and without any (reasonable) notice. Many users may agree to such a feature (as you say, it may be very secure), but to assume that everyone ought to be opted in by default is the issue.
I’m a cryptographer and I just learned about this feature today while I’m on a holiday vacation with my family. I would have loved the chance to read about the architecture, think hard about how much leakage there is in this scheme, but I only learned about it in time to see that it had already been activated on my device. Coincidentally on a vacation where I’ve just taken about 400 photos of recognizable locations.…
The choice probably looks to them like:
A - play the game, give everyone a heads up, respond to all feedback, and never ship the feature
B - YOLO it, weather the storm, have people forget about it after the holiday, and go on with their life.
Wether B works is up to debate, but that was probably their only chance to have it ship from their POV.Re: Apple Photos phones home on iOS 18 and macOS 15
#286Earlier quoted context omitted.
I'm not sure I agree -- asking users about every single minor feature is (a) incredibly annoying, and (b) quickly causes request-blindness in even reasonably security-conscious users. So restraining the nagging for only risky or particularly invasive things makes sense to me. Maybe they should lump its default state into something that already exists? E.g. assume that if you already have location access enabled for P…
"asking users about every single minor feature is (a) incredibly annoying" Then why lie and mislead customers that your data stays local?
Re: Apple Photos phones home on iOS 18 and macOS 15
#287Earlier quoted context omitted.
It’s very fair, Apple has historically been very happy to be the sponsor of horrible human rights violations in their supply chain, only marginally paying attention to suicides in their factories when the PR got too bad. Apples version of “human right” includes suicide nets as an alternative to treating people humanely. That’s why their stance is pure marketing - they have blood on their hands. And guess what? You ca…
Oh come on, it’s not like Google is better. 1. Google isn’t available in China not because of some moral reason, and they were in fact available in the past and Google has attempted to go back to China as a search engine, etc. before. They aren’t available because China hacked into their systems and took code and got access to certain accounts, and at the time Google essentially decided it wasn’t worth offering servi…
Now, that happened under a different type of Google (I’m sure they’ll go back now that they torched the culture), but Apple employees who walk around SV like they are better than everybody else - which people on their privacy teams very much do - are pathetically deluded.
All the megacorps are evil, and while Apple likes to put on a holier-than-thou act, it’s just as much bullshit for them to claim they value human rights as it is for Google to say they value privacy.
They value money, that’s it.
Re: Apple Photos phones home on iOS 18 and macOS 15
#288Earlier quoted context omitted.
This must be the first consumer or commercial product implementing homomorphic encryption is it not? I would be surprised if doing noisy vector comparisons is actually the most effective way to tell if someone is in front of the Eiffel tower. A small large language model could caption it just as well on device, my spider sense tells me someone saw an opportunity to apply bleeding edge, very cool tech so that they can…
> This must be the first consumer or commercial product implementing homomorphic encryption is it not? Not really, it's been around for a bit now. From 2021: > The other major reason we’re talking about HE and FL now is who is using them. According to a recent repository of PETs, there are 19 publicly announced pilots, products, and proofs of concept for homomorphic encryption and federated analytics (another term fo…
As far as why it's not more of a buzzword, it's far too in the weeds and ultimately consumers either trust you or they don't. And even if they don't trust you, many of them are still going to use Apple/Google/Facebook system anyway.
Re: Apple Photos phones home on iOS 18 and macOS 15
#289To me it seems like a reasonable feature that was, for the most part, implemented with great consideration for user privacy, though maybe I’m too trusting of the description. I mostly think this article is rage-bait and one should be wary of ‘falling for it’ when it shows up on hacker news in much the same way that one should be wary when rage-bait articles show up in tabloids or on Facebook. It seems likely to me th…
Literally all Apple needed to do was not have it enabled by default. Sending stuff over the network without asking is why trust in Apple is reduced further and further.
I mostly think the reaction to this article is overblown because it appeals popular ideas here about big tech. I think one should be wary of Apple’s claims about privacy: the reason is competition with Google and so they want users to be distrustful of the kinds of features that Google are better at implementing (I don’t want to say Apple isn’t trying to do the right thing either – if you look at accessibility, the competition was very bad for a lot of things for a long time and Apple was good despite the lack of commercial pressure). But I think one should also be wary of articles that make you angry and tell you what you suspected all along. (eg see the commenter elsewhere who doesn’t care about the details and is just angry). It’s much easier to spot this kind of rage-bait piece when it is targeting ‘normal people’ rather than the in-group.