Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

471–480 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#471

Earlier quoted context omitted.

Yes, of course, the concern is the data being exfiltrated to begin with. Like someone else in this thread mentioned, if they upload a single pixel from my image without my consent, that is too much data being uploaded without my consent.

If they sent a completely randomly generated integer from your phone without consent, would that be okay with you? Genuine question.

I'm not who you asked, but no, I wouldn't be.

I'd want an explanation of why they want to send this data. They need to seek informed consent, and the default needs to be no data collection. Opt-in, not opt-out.

If I do opt-in, I can withdraw that consent at any time.

I can also expect them to delete any collected data within a reasonable (to me) time frame, tell me what they do with it, who they share it with, supply me with any personally identifying data they have colllected, and allow me to correct it if it's wrong. And if they use the data to make important decisions automatically, e.g. bank loan yes/no, I have the right to make them use human reasoning to reconsider.

There is no reason to let businesses non-consensually collect any data from you, even if that's their entire business model. Don't let their self-serving lies about "you can trust us" or "it's normal and inevitable" swindle you out of your privacy.

Incidentally,"a completely randomly generated integer" could describe Apple's Advertising Identifier, which allows third parties to track the bejesus out of you.

Re: Apple Photos phones home on iOS 18 and macOS 15

#472
post #436

Earlier quoted context omitted.

> I mean for one, because of people like you that are concerned about it. Apple wants you to have the choice if you are against this feature. It's silly to try to use that as some sort of proof that the feature isn't safe. If they know some people will be against the feature, why not ask instead of enabling it for them? > My iPhone has a button to disable the flash in the camera app. Does that imply that somehow usin…

Honestly I'm a little tired so I'm not gonna completely/perfectly address everything you said here but > If they know some people will be against the feature, why not ask instead of enabling it for them? Honestly I would just say this is because you can only ask so many things. This is a hard to explain feature, and at some point you have to draw a line on what you should and shouldn't ask for consent on. For many pe…

> Honestly I would just say this is because you can only ask so many things. This is a hard to explain feature, and at some point you have to draw a line on what you should and shouldn't ask for consent on. For many people, the default reaction to a cookie popup is to hit "accept" without reading because they see so many of them. Consent fatigue is a privacy risk too. Curious where you'd choose to draw the line?

Cookie consent fatigue is both good and bad. Before cookie consent, you just simply had no idea all of this crap was going on; cookie consent took something invisible and made it visible. I agree it sucks, but learning that basically everything you use collects and wants to continue to collect data that isn't essential has opened a lot of people's eyes to how absurdly wide data collection has become.

> Yes, my point is that your reasoning isn't good faith either. We both know it's silly and a bit conspiratorial to imply that Apple adding a setting for it means they know a feature is secretly bad. If they wanted to hide this from us, neither of us would be talking about it right now because we wouldn't know it existed.

Apple doesn't add options for no reason. It's useful to control whether the camera flash goes off for potentially many reasons. Similarly, if this option was absolutely bullet-proof, it wouldn't need an option. The option exists because having derivatives of private data flowing over to servers you don't control is not ideal practice for privacy, and Apple knows this.

And of course Apple isn't trying to hide it, they're currently trying to sell it to everyone (probably mainly to regulators and shareholders, honestly) that it's the best thing for user privacy since sliced bread.

> That's fair, but there's honestly no perfect answer here. Either you appease the HN crowd on every feature but overwhelm most non-technical users with too many popups to the point they start automatically hitting "yes" without reading them, or you make features that you truly consider to be completely private opt-out but upset a small subset of users who have extremely strict privacy goals.

> How do you choose where that dividing line is? Obviously you can't ask consent for every single feature on your phone, so at some point you have to decide where the line between privacy and consent fatigue is. IMO, if a feature is genuinely cryptographically secure and doesn't reveal any private data, it probably should be opt-out to avoid overwhelming the general public.

> Also, how would you phrase the consent popup for this feature? Remember that it has to be accurate, be understandable to the majority of the US population, and correct state the privacy risks and benefits. That's really hard to do correctly, especially given "21 percent of adults in the United States (about 43 million) fall into the illiterate/functionally illiterate category"[0].

I honestly think the answer is simple: All of this cookie consent bullshit exists because the real answer is relatively simple, but it's inconvenient. If online behavioral tracking is so bad for our privacy, and we can't actually trust companies to handle our data properly, we should full-on ban it under (almost?) any circumstances. There. Cookie consent fixed. You can't track users for "non-essential" purposes anymore. And no, they don't need to. There was a time before this was normal, and if we can help it, there will be a time after it was normal too. Protecting someone's stupid business model is not a precondition for how we define our digital rights.

This is exactly why I worry about Apple's intentions. For what it's worth, I don't believe that the engineers or even managers who worked on this feature had anything but good intentions, and the technology is very cool. Obviously, nobody is denying that Apple is good at making these "privacy" technologies. But Apple as a whole seems to want you to think that the root cause of the privacy problem is just that our technology isn't private enough and it can be fixed by making better technology. Conveniently, they sell products with that technology. (I do not think that it is any shocker that the first uses of this technology are as innocuous as possible, either: this is a great strategy to normalize it so it can eventually be used for lucrative purposes like advertising.)

But that's wrong, and Apple knows it. The privacy problem is mostly just an effect of the loss of agency people have over their computers, and the reason why is because the end user is not the person that software, hardware and services are designed for anymore, it's designed for shareholders. We barely regulate this shit, and users have next to no recourse if they get pushed and coerced to do things they don't want to. You just get what you get and you have to pray to the tech gods that they don't turn the screws even more, which they ultimately will if it means they can bring more value to the shareholders. Yes, I realize how cynical this is, but it's where we're at today.

So yes, it's nice to not inundate the user with a bunch of privacy prompts, but the best way to do that is to remove and replace features that depend on remote services. And hell, Apple already did do a lot of that, it's Google who would have absolute hell if they had to put an individual prompt for every feature that harms your privacy. Apple devices don't have very many privacy prompts at all, and in this case it's to the point of a fault.

(P.S.: I know I used the term and not Apple, but even calling it "privacy" technology feels a bit misleading. It's not actually improving your privacy, it's just making a more minimal impact to your privacy stature than the leading alternative of just sending shit to cloud services raw. It's a bit like how electric vehicles aren't really "green" technology.)

Re: Apple Photos phones home on iOS 18 and macOS 15

#473
post #470

Apple TOS: > To uphold our commitment to privacy while delivering these experiences, we have implemented a combination of technologies to help ensure these server lookups are private, efficient, and scalable. Efficiency and scalability have nothing to do with "upholding one's commitment to privacy". This shows they're insincere. But, is privacy achievable today? I doubt it. People desperately want (or think they want…

> Efficiency and scalability have nothing to do with "upholding one's commitment to privacy". This shows they're insincere.

"private, efficient, and scalable" means "private AND efficient AND scalable". What makes you think they are being insincere about the privacy aspect?

Re: Apple Photos phones home on iOS 18 and macOS 15

#474
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

> Trust in software will continue to erode > there is an increasing discontent growing towards opt-out telemetry Really? That's news to me. What I observed is people giving up more and more privacy every year (or "delegating" their privacy to tech giants).

Apple seems to be the best option here too. They seem to have put in a huge effort to provide features people demand (searching by landmarks in this case) without having to share your private data.

It would have been so much easier for them to just send the whole photo as is to a server and process it remotely like Google does.

Re: Apple Photos phones home on iOS 18 and macOS 15

#475
post #348
post #308

Earlier quoted context omitted.

It's probably a pretty large set of people, perhaps even the majority, since I'd suspect that most people don't pay for additional iCloud storage and can't fit their photo library into 5GB. In fact, I'm willing to bet that if they'd added this feature and gated it behind iCloud Photos being enabled, we'd have different articles complaining about Apple making a cash grab by trying to get people to pay for premium stor…

> It's probably a pretty large set of people, perhaps even the majority, since I'd suspect that most people don't pay for additional iCloud storage and can't fit their photo library into 5GB. Large set? Yes. Majority? No. CIRP says 2/3 of US Apple users pay for iCloud storage[0]. It's this popular for the exact reason you mentioned. Almost no one can fit their photo library into 5GB so they opt in to the cheap 50GB f…

Time Machine does not backup your desktop and other spots that might be essential in case of needing a backup. iCloud does.

I know users who would prefer not to trust Apple for anything, and only pay for and use iCloud to backup the Desktop [and similar locations]. If they were to hear that their opt-in for iCloud means that Apple starts copying random things, they would not be happy.

[OT, I use Arq. But admit that iCloud is simpler, and it is not apples to apples.]

IMO, the fact that Apple backs up your keychain to the Mothership; and that this is a "default" behavior that will re-enable itself when shut off, reflects an attitude that makes me very distrustful of Apple.

Re: Apple Photos phones home on iOS 18 and macOS 15

#476
post #324
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

Developers of software want, and feel entitled to, the data on your computer, both about your usage within the app, as well as things you do outside of the app (such as where you go and what you buy). Software will continue to spy on people so long as it is not technically prohibited or banned.

In the OP article it seems more like users demand to search their photos by text, and Apple has put in a huge effort to enable that without gaining access to your photos.

Re: Apple Photos phones home on iOS 18 and macOS 15

#477
post #428

Earlier quoted context omitted.

That's absurd. We can regulate these problems. If the EU can regulate away the lightning connector they can regulate away this kind of stuff.

You're seriously arguing that it's absurd for customers to have "absolute control" over all software? No EU regulation could regulate away all "moral" concerns over software. More specifically, they EU could regulate, but the overwhelming majority of software companies would either strip significant features out for EU customers, or exit the market altogether.

Lol, they keep threatening that but they still like the money of the europeans.

Re: Apple Photos phones home on iOS 18 and macOS 15

#478
post #314

Earlier quoted context omitted.

Because it turns out that mathematicians and computer scientists have devised schemes that allow for certain computational operations to be performed on encrypted data without revealing the data itself. You can do a+b=c and it doesn’t reveal anything about what a and b are is the intuition here. This has been mostly confined to the realm of theory and mathematics until very recently but Apple has operationalized it f…

And then when the system does the computation to determine your location (wait.what?)

The phone has intelligence to detect things that look like landmarks, and does cropping/normalization and converts to a mathematical form.

Apple has a database trained on multiple photos of each landmark (or part of a landmark), to give a likelihood of a match.

Homomorphic encryption means that the encrypted mathematical form of a potential landmark from the phone can be applied to the encrypted set of landmark data, to get an encrypted result set.

The phone can then decrypt this and see the result of the query. But anyone else sees this as noise being translated to new noise, including Apple's server.

The justification for this approach is storage - the data set of landmarks can only get larger as the data set gets more comprehensive. Imagine trying to match photos for inside castles, cathedrals and museums as examples.

Re: Apple Photos phones home on iOS 18 and macOS 15

#480
post #54
post #40

Earlier quoted context omitted.

I think it does address the main problem. What he is saying is that multiple layers of security is used to ensure (mathematically and theoretically proved) that there is no risk in sending the data, because it is encrypted and sent is such a way that apple or any third party will never be able to read/access it (again, based on theoretically provable math) . If there is no risk there is no harm, and then there is a d…

Your second paragraph is exactly the point made in the article as the reason why it should be an informed choice and not something on by default.

If you don’t trust Apple to do what they say they do, you should throw your phone in the bin because it has total control here and could still be sending your data even if you opt out.
Post reply on HN