Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

361–370 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#361

Earlier quoted context omitted.

Especially for a company which heavily markets about how privacy-focused it is, 1)sending my personal data to them in any way is not a "feature." It's especially not a feature because what it sets out to do is rather unnecessary because every photo has geotagging, time-based grouping, and AI/ML/whatever on-device keyword assignments and OCR. I can open up my phone right now and search for every picture that has grass…

> This was very clearly an "ask for forgiveness because the data we want is absolutely priceless and we'll get lots of it by the time people notice / word gets out. It's very clearly not, since they've gone to huge lengths to make sure they can't actually see the data themselves see the grandparent post.

[flagged]

Re: Apple Photos phones home on iOS 18 and macOS 15

#362

Earlier quoted context omitted.

That's what rallying against Apple in the name of privacy is already...

Are you saying we shouldn't hold Apple accountable for privacy encroachments then?

I don't think this is. I think this is well within the search improvement config that started in like iOS 15.

Re: Apple Photos phones home on iOS 18 and macOS 15

#363
post #154

Earlier quoted context omitted.

I'm not sure I agree -- asking users about every single minor feature is (a) incredibly annoying, and (b) quickly causes request-blindness in even reasonably security-conscious users. So restraining the nagging for only risky or particularly invasive things makes sense to me. Maybe they should lump its default state into something that already exists? E.g. assume that if you already have location access enabled for P…

Especially for a company which heavily markets about how privacy-focused it is, 1)sending my personal data to them in any way is not a "feature." It's especially not a feature because what it sets out to do is rather unnecessary because every photo has geotagging, time-based grouping, and AI/ML/whatever on-device keyword assignments and OCR. I can open up my phone right now and search for every picture that has grass…

> It's especially shitty because they've gated a huge amount of their AI shit behind owning the current iPhone model....but apparently my several generation old iPhone is more than good enough to do some AI analysis on all my photos

Hear hear. As if they can do this but not Visual Intelligence, which is just sending a photo to their servers for analysis. Apple has always had artificial limitations but they've been getting more egregious of late.

Re: Apple Photos phones home on iOS 18 and macOS 15

#364
post #95

Earlier quoted context omitted.

Notice is always good and Apple should implement notice. However, "my data is being sent off my device" is incorrect, as GP explained. Metadata, derived from your data, with noise added to make it irreversible, is being sent off your device. It's the equivalent of sending an MD5 of your password somewhere; you may still object, but it is not factually correct to say your password was transmitted.

> It's the equivalent of sending an MD5 of your password somewhere; you may still object, but it is not factually correct to say your password was transmitted. Hackers love to have MD5 checksums of passwords. They make it way easier to find the passwords in a brute force attack. https://en.wikipedia.org/wiki/Rainbow_table

Hackers don’t know about salts yet?

Re: Apple Photos phones home on iOS 18 and macOS 15

#365

The referenced Apple blog post[1] is pretty clear on what this feature does, and I wish the author at lapcatsoftware (as well as folks here) would have read it too, instead of taking the blog post as-is. Apple has implemented homomorphic encryption[2], which they can use to compute distance metrics such as cosine similarity without revealing the original query/embedding to the server. In the case of photos, an on-dev…

Just from memory when the scheme came up in earlier discussion.

The system is essentially scanning for the signature for some known set of images of abuse so that it aims to capture abusers who would naively keep just these images on their machines. (It can't determine if a new image is abusive, notably).

It's conceivable some number of (foolish and abusive) people will be caught this way and those favoring a long dragnet for this stuff will be happy. But this opens the possibility that a hacker could upload an image to an innocent person's computer and get that person arrested. Those favoring the long dragnet will naturally say the ends justify the means and you can't make an omelet without cracking a few eggs. Oh, "think of the children".

Edit: Also worth adding that once a company is scanning user content to try to decide if the user is bad, it makes it that much easier to scan all kind of content in all kind of ways for all kinds of reasons. "for the good", naturally.

Re: Apple Photos phones home on iOS 18 and macOS 15

#366

Earlier quoted context omitted.

> It's the equivalent of sending an MD5 of your password somewhere; you may still object, but it is not factually correct to say your password was transmitted. Hackers love to have MD5 checksums of passwords. They make it way easier to find the passwords in a brute force attack. https://en.wikipedia.org/wiki/Rainbow_table

Hackers don’t know about salts yet?

Bath salts yes, security salts, not so much.

Re: Apple Photos phones home on iOS 18 and macOS 15

#367

Why does Apple keep insisting that I want anything to do with them after I bought the device? Let go of the freaking tether. And let me choose my own photo editing service provider.

Perhaps it's the legion of kool-aid drinkers that preceded you and influenced their design.

Re: Apple Photos phones home on iOS 18 and macOS 15

#368

The referenced Apple blog post[1] is pretty clear on what this feature does, and I wish the author at lapcatsoftware (as well as folks here) would have read it too, instead of taking the blog post as-is. Apple has implemented homomorphic encryption[2], which they can use to compute distance metrics such as cosine similarity without revealing the original query/embedding to the server. In the case of photos, an on-dev…

That's not the point of the outrage though (at least not for me). They enabled by default a feature that analyzes my pictures (which I never upload to iCloud) and sends information about them to their (and others') servers. That is a gross violation of privacy. To be clear, I don't care about any encryption scheme they may be using, the gist is that they feel entitled to reach into their users' most private data (the…

If the data is encrypted, does the concern still apply?

You bring up the example of Onedrive, but there is no use of e2e encryption or HE techniques there.

Re: Apple Photos phones home on iOS 18 and macOS 15

#369

Earlier quoted context omitted.

The average smartphone is probably doing a hundred things you didn’t knowingly consent to every second. Should Apple insist that every end user consents to the user agent string sent on every HTTP request?

> The average smartphone is probably doing a hundred things you didn’t knowingly consent to every second. You've succinctly identified a (maybe the ) huge problem in the computing world today. Computers should not do anything without the user's command/consent. This seems like a hopeless and unachievable ideal only because of how far we've already strayed from the light. Even Linux, supposedly the last bastion of use…

> I didn't consent to any of this!

Yes you did. You purchased a computer, put this software on it and executed it. If you didn't want it to do whatever it's doing you should have determined what it would do beforehand and chose not to do it.

Re: Apple Photos phones home on iOS 18 and macOS 15

#370

Earlier quoted context omitted.

That's not the point of the outrage though (at least not for me). They enabled by default a feature that analyzes my pictures (which I never upload to iCloud) and sends information about them to their (and others') servers. That is a gross violation of privacy. To be clear, I don't care about any encryption scheme they may be using, the gist is that they feel entitled to reach into their users' most private data (the…

If the data is encrypted, does the concern still apply? You bring up the example of Onedrive, but there is no use of e2e encryption or HE techniques there.

Yes, of course, the concern is the data being exfiltrated to begin with. Like someone else in this thread mentioned, if they upload a single pixel from my image without my consent, that is too much data being uploaded without my consent.
Post reply on HN