Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

421–430 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#421

Earlier quoted context omitted.

If you can't meaningfully explain what you're doing then you can't obtain informed consent. If you can't obtain informed consent then that's not a sign to go ahead anyway, it's a sign that you shouldn't do it . This isn't rocket surgery.

+100 for "rocket surgery". I mostly agree. I'm just annoyed "this new privacy tech is too hard to explain" leads to "you shouldn't do it". This new privacy tech is a huge net positive for users. Also: from other comments sounds like it might have been opt-in the whole time. Someone said a fresh install has it off.

> This new privacy tech is a huge net positive for users.

It's a positive compared to doing the same "feature" without the privacy tech. It's not necessarily a positive compared to not forcing the "feature" on the user at all.

The privacy tech isn't necessarily a positive as a whole if it leads companies to take more liberties in the name of "hey you don't need to be able to turn it off because we have this magical privacy tech (that nobody understands and may or may not actually work please don't look into it too hard)".

Re: Apple Photos phones home on iOS 18 and macOS 15

#422

If your core concern is privacy, surely you'd be fine with "no bytes ever leave my device". But that's a big-hammer way to ensure no one sees your private data. What about external (iCloud/general cloud) storage? That's pretty useful, and if all your data is encrypted in such a way that only you can read it, would you consider that private? If done properly, I would say that meets the goal. What if, in addition to st…

iCloud is opt in. This should be too. A lot of people are fine with keeping their photos offline-only and syncing with their computers through a cable.

Making it “private” with clever encryption is their job since Apple wants to sell privacy. They aren’t doing it because they are nice or care about us. Plus, code is written by people and people write bugs. How can you tell this is truly bug-free and doesn’t leak anything?

Ultimately, making it opt-in would be painless and could be enabled with a simple banner explaining the feature after the update or on first boot, like all their opt-in features. Making it opt-out is irresponsible to their branding at best and sketchy to their users at worst, no matter how clever they say it is.

Re: Apple Photos phones home on iOS 18 and macOS 15

#423
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

> Trust in software will continue to erode > there is an increasing discontent growing towards opt-out telemetry Really? That's news to me. What I observed is people giving up more and more privacy every year (or "delegating" their privacy to tech giants).

[deleted]

Re: Apple Photos phones home on iOS 18 and macOS 15

#424
post #411

Earlier quoted context omitted.

If the data is encrypted, does the concern still apply? You bring up the example of Onedrive, but there is no use of e2e encryption or HE techniques there.

> If the data is encrypted, does the concern still apply? Yes! For so many reasons! If an adversary is able to intercept encrypted communications, they can store it in hopes of decrypting it in the future in the event that a feasible attack against the cryptosystem emerges. I don't know how likely this is to happen against homomorphic encryption schemes, but the answer is not zero. I'm not suggesting everyone should…

> I'd also like to ask a different question: if there's no reason to ever worry about this feature, then why is there even an option to turn it off in the first place?

I mean for one, because of people like you that are concerned about it. Apple wants you to have the choice if you are against this feature. It's silly to try to use that as some sort of proof that the feature isn't safe.

My iPhone has a button to disable the flash in the camera app. Does that imply that somehow using the camera flash is dangerous and Apple is trying to hide the truth from us all? Obviously not, it simply means that sometimes you may not want to use the flash.

They likely chose to make it opt-out because their research shows that this is truly completely private, including being secure against future post-quantum attacks.

> If an adversary is able to intercept encrypted communications, they can store it in hopes of decrypting it in the future in the event that a feasible attack against the cryptosystem emerges. I don't know how likely this is to happen against homomorphic encryption schemes, but the answer is not zero.

Also, if you're going to wildly speculate like this it is at least (IMO) worth reading the research press release since it does answer many of the questions you've posed here[0].

> it's pretty upsetting that it's becoming incredibly hard to the point of being nearly impractical to get modern devices to behave this way and not just fling data around all over the place willy-nilly.

And honestly, is turning off a single option in settings truly impractical? Yes, it's opt-out, but that's because their research shows that this is a safe feature. Not every feature needs to be disabled by default. If most users will want something turned on, it should probably be on by default unless there's a very strong reason not to. Otherwise, every single iPhone update would come with a 30 question quiz where you have to pick and choose which new features you want. Is that a reasonable standard for the majority of non tech-savvy iPhone users?

Additionally, the entire purpose of a phone is to send data places. It has Wi-Fi, Bluetooth, and Cellular for a reason. It's a bit absurd to suggest that phones should never send any data anywhere. It's simply a question of what data should and should not be sent.

[0] https://machinelearning.apple.com/research/homomorphic-encry...

Re: Apple Photos phones home on iOS 18 and macOS 15

#425

Earlier quoted context omitted.

If the data is encrypted, does the concern still apply? You bring up the example of Onedrive, but there is no use of e2e encryption or HE techniques there.

Yes, of course, the concern is the data being exfiltrated to begin with. Like someone else in this thread mentioned, if they upload a single pixel from my image without my consent, that is too much data being uploaded without my consent.

If they sent a completely randomly generated integer from your phone without consent, would that be okay with you? Genuine question.

Re: Apple Photos phones home on iOS 18 and macOS 15

#426

Earlier quoted context omitted.

> That's a useful feature. I’m really curious how this feature is considered useful. It’s cool, but can’t you just open the photo to view it?

It is a notification summary. There is a large number of people out there who receive hundreds of notifications (willingly but mostly unwillingly) daily from apps they have installed (not just messengers), and nearly all of them can't cope with the flood of the notifications. Most give up on tending to the notifications altogether, but some resort to the notification summaries which alleviate the cognitive overload (…

Hundreds of notifications daily is not unwillingly, nor is it healthy.

You can disable IG trash notifications, for example.

Re: Apple Photos phones home on iOS 18 and macOS 15

#427
> I don't understand most of the technical details of Apple's blog post.

I did understand the cited bits, and sorry to say but this could have been an optimistic post ("look at this cool new thing!")

I dislike Apple's anti-hacker (in the HN sense of the word) practices as much as the next person and don't own any Apple device for that and other reasons, but saying "it doesn't matter how you solved the privacy problem, I feel it's not private" doesn't make it true. Because most other people don't understand the cited words either, if they read that far down anyway, this seems like unfair criticism

Re: Apple Photos phones home on iOS 18 and macOS 15

#428

Earlier quoted context omitted.

I don't care if all they collect is the bottom right pixel of the image and blur it up before sending it, the sending part is the problem. I don't want anything sent from MY device without my consent, whether it's plaintext or quantum proof. You're presenting it as if you have to explain elliptic curve cryptography in order to toggle a "show password" dialogue but that's disingenuous framing, all you have to say is "…

> I don't want anything sent from MY device without my consent Then don’t run someone else’s software on your device. It’s not your software, you are merely a licensee. Don’t delude yourself that you are morally entitled to absolute control over it. The only way to have absolute control over software is with an RMS style obsession with Free software.

That's absurd.

We can regulate these problems.

If the EU can regulate away the lightning connector they can regulate away this kind of stuff.

Re: Apple Photos phones home on iOS 18 and macOS 15

#429

Earlier quoted context omitted.

>The system is essentially scanning for the signature for some known set of images of abuse Huh? The system is scanning for landmarks, not images of abuse. >people will be caught this way Due to the homomorphic encryption, I don't think Apple even knows whether the image matches a landmark in Apple's server database or not. So even if Apple put some images of abuse into its server database (which Apple claims only co…

Does Apple explicitly say that? Or only that they don’t know which landmark it matched?

Fundamentally, vector search like this doesn't have a concept of something "matching" or "not matching". It's just a cosine similarity value. To determine if an image "matches", you have to check if that similarity is within some given threshold. If the results of the cosine similarity operation are encrypted (they are with HE), that wouldn't be possible to determine.

The bigger privacy risk would be that the device routes the request to a specific database shard based on whichever has a center-point closest to the image embedding on the device. They take steps to protect this information such as third-party proxying to hide user IP addresses, as well as having devices send fake requests so that the server cannot tell which are real user data and which are fake data.

Re: Apple Photos phones home on iOS 18 and macOS 15

#430
post #417

Earlier quoted context omitted.

> Trust in software will continue to erode > there is an increasing discontent growing towards opt-out telemetry Really? That's news to me. What I observed is people giving up more and more privacy every year (or "delegating" their privacy to tech giants).

Absolutely! The important bit is that users have no choice in the matter. They're pushed into agreeing to whatever ToS and updating to whatever software version. The backlash against Microsoft's Windows Recall should serve as a good indicator of just how deeply people have grown to distrust tech companies. But Microsoft can keep turning the screws, and don't you know it, a couple years from now everyone will be runni…

fwiw, on Android, you can install a custom certificate and have an app like AdGuard go beyond just DNS filtering, and actually filter traffic down to a request-content level. No root required. (iOS forbids this without jailbreaking though :/)
Post reply on HN