Earlier quoted context omitted.
Completely agree, just one minor point: > I think banking apps requiring SafetyNet passing is the dumbest thing on planet earth. You guys know I can just sign into the website with my mobile browser anyways, right? No, you're not. For logging in, you need a mobile app used as an authentication token. Do not pass go, do not collect $200... (The current state of affairs in Czechia, at least; you still _do_ have the opt…
Right now I don't think there's anything like this in the United States, at the very least. That said, virtually every bank here only seems to support SMS 2FA, which is also very frustrating.
Apple Photos phones home on iOS 18 and macOS 15
671–680 of 1001 posts
Re: Apple Photos phones home on iOS 18 and macOS 15
#672Apple TOS: > To uphold our commitment to privacy while delivering these experiences, we have implemented a combination of technologies to help ensure these server lookups are private, efficient, and scalable. Efficiency and scalability have nothing to do with "upholding one's commitment to privacy". This shows they're insincere. But, is privacy achievable today? I doubt it. People desperately want (or think they want…
> Efficiency and scalability have nothing to do with "upholding one's commitment to privacy". This shows they're insincere. "private, efficient, and scalable" means "private AND efficient AND scalable". What makes you think they are being insincere about the privacy aspect?
When they add that server lookups are also "efficient and scalable", it means that they have had to ponder the privacy aspects with technical concerns regarding efficiency and scalability, and that therefore, privacy is mitigated.
I think a fair reading of this sentence would be: "we provide a version of 'privacy' that we feel is acceptable, within reasonable efficiency and scalability constraints".
They're not going to dedicate a server per customer for example. Would it make sense to do it? No. But it would be honest to say "because of efficiency and scalability limits, the 'privacy' we provide is relative and subject to breaches". (I actually think that's exactly what their wording is trying to say.)
Re: Apple Photos phones home on iOS 18 and macOS 15
#673Is this just a smokescreen around slowly sneaking CSAM scanning back in after the pushback last time? The "default on" behavior is suspect. [1] https://www.wired.com/story/apple-photo-scanning-csam-commun...
My thoughts exactly: "we've got this crafty image fingerprinting, the CSAM detection use proved too controversial to roll out, but let's get the core flows into something that sounds useful for users, so the code atays alive, improving, & ready for future expansion." Whether such fingerprinting can reliably be limited to public "landmarks" is an interesting question, dependent on unclear implementation details. Even…
is it even that?
I don't see the benefit of this whatsoever
Re: Apple Photos phones home on iOS 18 and macOS 15
#674Earlier quoted context omitted.
Use a rooted Android phone with AFWall+ installed, with default block rules. Even just LineageOS allows you to set granular network settings per app, though it's not preemptive like AFWall.
Can't run various banking apps and can't run PagerDuty on a rooted device due to Google Play API Integrity Check. The ecosystem is closing in on any options to not send telemetry, and Google is leading the way in the restrictions on Freedom.
They're the ones allowing you to root your phone or flash a custom ROM in the first place, so that's not a fair characterisation. Banks have a vested interest in reducing fraud, and a rooted Android might allow for easier and additional attack vectors into their apps and thus systems.
Re: Apple Photos phones home on iOS 18 and macOS 15
#675Re: Apple Photos phones home on iOS 18 and macOS 15
#676Earlier quoted context omitted.
Would there be a way to do the stats gathering on device, then once every few months send a popup with statistics? Not sure what bias it adds Like "hey, we make this app, and we care about privacy, here is the information we have gathered over your usage for the past month, can we send this to ourselves, so that we can use it to improve the app?" And then show human readable form of what data was collected.
You'd still have extremely biased data - people who blindly click OK on every pop up are not representative of your typical user; people who get nightmares after hearing the word "telemetry" and will gather the pitchforks if they hear any hint of will always refuse, but depending on your app, might be your typical user (e.g. for self-hosted picture sync and catalogue, who is the target audience - people who don't tru…
It’s very easy to confuse ‘loud protest from a small minority’ and the majority opinion. If a plurality of users chose to participate in an analytics program when asked and don’t care to protest phone-home activities when they’re discovered, then that’s where the majority opinion likely lies.
Re: Apple Photos phones home on iOS 18 and macOS 15
#677Users of my (free, open-source) app seem surprised to learn that we've got zero insight into usage patterns. There are situations where a small amount of anonymous telemetry would be extremely helpful but I'm not going to touch it with a barge-pole. Opt-in makes the data useless - not just in terms of the huge drop in quantity but because of the fact it introduces a huge bias in the data selected - the people that wo…
I provide telemetry data to KDE, because they default to collecting none, and KDE is an open-source and transparent project that I'd like to help if I can. If I used your app, I would be likely to click yes, since it's open-source. Part of the problem I have with projects collecting user data is the dark patterns used or the illegal opt-out mechanism, which will make me decline sending telemetry every time, or even make me ditch it for an alternative. An app that asks:
Can we collect some anonymized data in order to improve the app?
[Yes] [No]
...with equal weight given to both options, is much more likely to have me click Yes if none of the buttons are big and blue whilst the other choice is in a smaller font and "tucked away" underneath the other (or worse, in a corner or hidden behind a sub-menu).Plus, I would think that SOME data would be better than NO data, even if there's an inherent bias leaning towards privacy-minded/power users.
Re: Apple Photos phones home on iOS 18 and macOS 15
#678And this blog post is how I find out the Photos app mysteriously turned iCloud Photos back on. What the fuck? At least "Keep Originals" was still set.
Re: Apple Photos phones home on iOS 18 and macOS 15
#679Earlier quoted context omitted.
Yup, this is their way of injecting the "phone home" element via an innocuous rationale, "location matching". The global index will of course also match against other markers they deem worthy of matching, even if they don't return that to the user.
But wouldn't the homomorphic encryption prevent Apple's servers from knowing if there was a match or not?
in that case it's the source of common key of "the same account" becomes the threat
and now you have to trust... megacorporation with closed-garden ecosystem... to not access its own servers in your place?
Re: Apple Photos phones home on iOS 18 and macOS 15
#680I think I just noticed a similar thing for search that I'm pretty sure was not there before IOS 18. Going into Settings -> Search there's an option now for "Help Apple Improve Search", enabled by default. >Help improve Search by allowing Apple to store the searches you enter into Safari(!!), Siri and Spotlight in a way that is not linked to you. Searches include lookups of general knowledge, and requests to do things…