Earlier quoted context omitted.
> does the concern still apply? Yes it does and the blogpost specifically explains why. In short, both iOS and macOS are full of bugs, often with the potential of exposing sensitive information. Also, it’s on by default - nobody in their sane mind would have bits of their photos uploaded somewhere, regardless of “we promise we won’t look”. Finally, Photos in iOS 18 is such a bad experience that it seems the breach of…
>regardless of “we promise we won’t look”. AIUI, even if Apple's servers tried to look, they cannot, because of the encryption.
Apple Photos phones home on iOS 18 and macOS 15
391–400 of 1001 posts
Re: Apple Photos phones home on iOS 18 and macOS 15
#392Earlier quoted context omitted.
Just from memory when the scheme came up in earlier discussion. The system is essentially scanning for the signature for some known set of images of abuse so that it aims to capture abusers who would naively keep just these images on their machines. (It can't determine if a new image is abusive, notably). It's conceivable some number of (foolish and abusive) people will be caught this way and those favoring a long dr…
That was the CSAM thing that they have announced they gave up on. This is totally different.
Re: Apple Photos phones home on iOS 18 and macOS 15
#393Is this just a smokescreen around slowly sneaking CSAM scanning back in after the pushback last time? The "default on" behavior is suspect. [1] https://www.wired.com/story/apple-photo-scanning-csam-commun...
That whole incident was so misinformed. CSAM scanning takes place on the cloud with all the major players. It only has hashes for the worst of the worst stuff out there. What Apple (and others do) is allow the file to be scanned unencrypted on the server. What the feature Apple wanted to add was scan the files on the device and flag anything that gets a match. That file in question would be able to be decrypted on th…
Re: Apple Photos phones home on iOS 18 and macOS 15
#394Is this just a smokescreen around slowly sneaking CSAM scanning back in after the pushback last time? The "default on" behavior is suspect. [1] https://www.wired.com/story/apple-photo-scanning-csam-commun...
That whole incident was so misinformed. CSAM scanning takes place on the cloud with all the major players. It only has hashes for the worst of the worst stuff out there. What Apple (and others do) is allow the file to be scanned unencrypted on the server. What the feature Apple wanted to add was scan the files on the device and flag anything that gets a match. That file in question would be able to be decrypted on th…
If they were to add this anti-CSAM feature, it is not unreasonable to think that Apple would be forced to add non-CSAM stuff to the database in these countries, e.g. anything against a local dictatorship/ etc. Adding the feature would only catch the low hanging CSAM fruit, at the cost of great privacy and probably human life. If it was going to stop CSAM once and for all, it could possibly be justified, but that's not the case.
Re: Apple Photos phones home on iOS 18 and macOS 15
#395Earlier quoted context omitted.
> This is what a good privacy story looks like. What a good privacy story looks like is that my photos aren’t sent anywhere in any way shape or form without explicit opt in permission.
Your photos aren't sent anywhere in this system.
Re: Apple Photos phones home on iOS 18 and macOS 15
#396Earlier quoted context omitted.
>regardless of “we promise we won’t look”. AIUI, even if Apple's servers tried to look, they cannot, because of the encryption.
Encryption does not automatically mean secure. Encryptions can and will be broken. Any flaw in their implementation (which nobody can verify) would render encryption useless…
Do you also distrust TLS for example, and therefore refuse to use the internet? What about AES/Chacha for full-disk encryption?
Re: Apple Photos phones home on iOS 18 and macOS 15
#397The referenced Apple blog post[1] is pretty clear on what this feature does, and I wish the author at lapcatsoftware (as well as folks here) would have read it too, instead of taking the blog post as-is. Apple has implemented homomorphic encryption[2], which they can use to compute distance metrics such as cosine similarity without revealing the original query/embedding to the server. In the case of photos, an on-dev…
That's not the point of the outrage though (at least not for me). They enabled by default a feature that analyzes my pictures (which I never upload to iCloud) and sends information about them to their (and others') servers. That is a gross violation of privacy. To be clear, I don't care about any encryption scheme they may be using, the gist is that they feel entitled to reach into their users' most private data (the…
[0] https://www.apple.com/privacy/docs/Differential_Privacy_Over...
Re: Apple Photos phones home on iOS 18 and macOS 15
#398Earlier quoted context omitted.
I think I'm saying: you're not sending "your data" off device. You are sending a homomorphically encrypted locally differentially private vector (through an anonymous proxy). No consumer can really understand what that means, what the risks are, and how it would compare to the risk of sending someone like Facebook/Google raw data. I'm asking: what does an opt in for that really look like? You're not going to be able…
If you can't meaningfully explain what you're doing then you can't obtain informed consent. If you can't obtain informed consent then that's not a sign to go ahead anyway, it's a sign that you shouldn't do it . This isn't rocket surgery.
I mostly agree. I'm just annoyed "this new privacy tech is too hard to explain" leads to "you shouldn't do it". This new privacy tech is a huge net positive for users.
Also: from other comments sounds like it might have been opt-in the whole time. Someone said a fresh install has it off.
Re: Apple Photos phones home on iOS 18 and macOS 15
#399What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…
Re: Apple Photos phones home on iOS 18 and macOS 15
#400Earlier quoted context omitted.
Is this a niche feature? I use this kind of search very often in my photos.
What are some example keywords? I have never searched for landmarks, I only search for location. How many landmarks are there to justify sending your data off? Can't the database be stored on the device?
The usual context is "oh I saw some dolphins forever ago. let me see if I can find the photos..."