Earlier quoted context omitted.
You're presenting a false dichotomy between "perfect user understanding" and "no user choice." The issue isn't whether users can fully comprehend homomorphic encryption or differential privacy – it's about basic consent and transparency. Consider these points: 1. Users don't need a PhD to understand "This feature will send data about your photos to Apple's servers to enable better search." 2. The complexity of the pr…
I don't believe I said or implied that anywhere: 'You're presenting a false dichotomy between "perfect user understanding" and "no user choice."'? Happy to be corrected if wrong. Closest I come to presenting an opinion on the right way UX was "I'm not sure what the right call is here.". The thing I disagreed with was a technical statement "the only way to guarantee computing privacy is to not send data off the device…
Apple Photos phones home on iOS 18 and macOS 15
591–600 of 1001 posts
Re: Apple Photos phones home on iOS 18 and macOS 15
#592What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…
I find that there is a specific niche group of people who care very much about these things. But the rest of the world doesn't. They don't want to care about all these little settings they're just "Oh cool it knows it's the Eiffel tower". The only people who are becoming distrusting of software are a specific niche group of people and I highly suspect they're going to be mad about something.
> So why didn't Apple just simply ask for user permission to enable this feature?
Because most people don't even care to look at the new features for a software update. And let's be serious that includes most of us here otherwise, this feature would have been obvious. So why create a feature that no one will use? It doesn't make sense. So you enable it for everyone and those who don't want it opt-out.
Re: Apple Photos phones home on iOS 18 and macOS 15
#593This discussion got quite long without anyone mentioning the novel technical implementation paper "Scalable Private Search with Wally". Kudos to Apple for researching this, but shame on them for enabling this by default. As a somewhat homomorphic encryption scheme, each query releases some bits of information on what you searching for to avoid using the whole database. Subsequent queries from a given user will genera…
Very curious here as I haven’t seen any papers demonstrating attacks against the differential privacy systems proposed by Apple or Google that successfully deanonymize data. Such an attack in even a test database would be very interesting.
Do you have any papers you can cite about this entropic leakage you’re describing?
Re: Apple Photos phones home on iOS 18 and macOS 15
#594Is this just a smokescreen around slowly sneaking CSAM scanning back in after the pushback last time? The "default on" behavior is suspect. [1] https://www.wired.com/story/apple-photo-scanning-csam-commun...
Very likely yes. Why else would they add a feature that incurs costs for them as an update, at no cost to the users (and not even make a fuss about it)? It is obvious they are monetizing this feature somehow. Could be as innocuous as them training their AI dataset, or feeding into their growing ad business (locations and other things identified in the photos), or collaboration with law enforcement for various purpose…
Erm, you’re aware of the whole Apple intelligence thing right? An entire product that costs Apple money, provided at “no cost” to the user (if you had an iPhone 15). Also every feature in an OS update has a costs associated with it, and iOS updates have cost money for the best part of a decade now.
Has it occurred to you that reason Apple includes new features in their updates is to provide customers with more reasons to buy more iPhones? Just because feature are provided at “no cost” at point of consumption, doesn’t mean Apple won’t make money in the long run, and selling user data isn’t the only way to monetise these features. Companies have been giving out “freebies” for centuries before the internet existed, and the possibility of large scale data collection and trading was even imaginable.
Re: Apple Photos phones home on iOS 18 and macOS 15
#595Earlier quoted context omitted.
That whole incident was so misinformed. CSAM scanning takes place on the cloud with all the major players. It only has hashes for the worst of the worst stuff out there. What Apple (and others do) is allow the file to be scanned unencrypted on the server. What the feature Apple wanted to add was scan the files on the device and flag anything that gets a match. That file in question would be able to be decrypted on th…
Apple sells their products in oppressive regimes which force them to implement region specific features. E.g. China has their own iCloud, presumeably so it can be easily snooped on. If they were to add this anti-CSAM feature, it is not unreasonable to think that Apple would be forced to add non-CSAM stuff to the database in these countries, e.g. anything against a local dictatorship/ etc. Adding the feature would onl…
Re: Apple Photos phones home on iOS 18 and macOS 15
#596Earlier quoted context omitted.
If you accept Android as an option, then GrapheneOS probably check a lot of your boxes on an OS level. GrapheneOS developers sit between you and Google and make sure that shit like this isn't introduced without the user's knowledge. They actively strip out crap that goes against users interests and add features that empower us. I find that the popular apps for basic operation from F-Droid do a very good job of not sc…
Running a custom ROM locks you out of almost all decent phone hardware on the market since most have locked bootloaders, and it locks you out of a ton of apps people rely on such as banking and money transfer apps. You must recognise that it's not a practical solution for most people.
My budget didn't allow me to buy a brand new one but I could buy a second hand pixel 6a for 200€.
Having said that you can also use an older phone with /e/os or lineageos and avoid apps that tracks you by limiting to android apps without telemetry available on f-droid.
Re: Apple Photos phones home on iOS 18 and macOS 15
#597Earlier quoted context omitted.
If you accept Android as an option, then GrapheneOS probably check a lot of your boxes on an OS level. GrapheneOS developers sit between you and Google and make sure that shit like this isn't introduced without the user's knowledge. They actively strip out crap that goes against users interests and add features that empower us. I find that the popular apps for basic operation from F-Droid do a very good job of not sc…
That's great... for the HN reader. However, how is that supposed to work for your significant other, or your mother, or your indifferent-to-technology friend? Don't get me wrong, I also strive to keep my device's information private but, at the same time, I realize this has no practical use for most users.
Having said that it doesn't prevent them to check the "enable network" option when installing apps.
Re: Apple Photos phones home on iOS 18 and macOS 15
#598What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…
Opt in doesn't work, it never did. The vast majority (>95%) of users does not understand what those pop-ups say, seems fundamentally incapable of reading them, and either always accepts, always rejects, or always clicks the more visually-appealing button. Try observing a family member who is not in tech and not in the professional managerial class, and ask them what pop-up they just dismissed and why. It's one of the…
Re: Apple Photos phones home on iOS 18 and macOS 15
#599> I don't understand most of the technical details of Apple's blog post. I did understand the cited bits, and sorry to say but this could have been an optimistic post ("look at this cool new thing!") I dislike Apple's anti-hacker (in the HN sense of the word) practices as much as the next person and don't own any Apple device for that and other reasons, but saying "it doesn't matter how you solved the privacy problem…
How can you trust something you don't understand? That must come from "authority" (some person or org that you trust to know about such matters). That authority isn't Apple for many people. While I have cautious trust in Apple's privacy policies, many people don't, and not without reason. Hence, not understanding Apple's technical explanation of an Apple feature you didn't opt in to sharing personal data, increases t…
But this is the fundamental issue. The author has no idea if personal data is being shared, they’ve made an assumption based on their lack of understanding. It’s entirely possible that all this service does (and arguably likely), is provide a private way for your phone to query a large database of landmark fingerprints, then locally try and match those fingerprints to your photos.
It doesn’t require send up private data. The phone could perform large geographic queries (the size of countries) for batches of fingerprints to be cached locally for photo matching. The homographic encryption just provides an added layer of privacy, allowing the phone to make those queries in a manner that makes it impossible for Apple to know what regions were queried for.
iOS photos already uses databases to convert a photo location into an address, so you can do basic location based searching. That will involve doing lookups in Apple global address database, do you consider that a violation of people’s privacy?
Re: Apple Photos phones home on iOS 18 and macOS 15
#600What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…
Which is kind of ironic in places like HN, where so many advocate for Chromebooks.