Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

721–730 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#722
post #152

Earlier quoted context omitted.

And so in this context. You are saying that every network request is going to a target controlled by the US government.

Or their friends. https://en.wikipedia.org/wiki/Five_Eyes https://en.wikipedia.org/wiki/Room_641A

>https://en.wikipedia.org/wiki/Room_641A

Why yes, I did happen to work in US data centers throughout the 2010's... including during Snowden's [then adamently-denied] revelations.

"If you're taking flak, you're near the target."

Re: Apple Photos phones home on iOS 18 and macOS 15

#723

Is this just a smokescreen around slowly sneaking CSAM scanning back in after the pushback last time? The "default on" behavior is suspect. [1] https://www.wired.com/story/apple-photo-scanning-csam-commun...

That whole incident was so misinformed. CSAM scanning takes place on the cloud with all the major players. It only has hashes for the worst of the worst stuff out there. What Apple (and others do) is allow the file to be scanned unencrypted on the server. What the feature Apple wanted to add was scan the files on the device and flag anything that gets a match. That file in question would be able to be decrypted on th…

I can't believe how uninformed, angry, and still willing to argue about it people were over this. The whole point was a very reasonable compromise between a legal requirement to scan photos and keeping photos end-to-end encrypted for the user. You can say the scanning requirement is wrong, there's plenty of arguments for that. But Apple went so above and beyond to try to keep photo content private and provide E2E encryption while still trying to follow the spirit of the law. No other big tech company even bothers, and somehow Apple is the outrage target.

Re: Apple Photos phones home on iOS 18 and macOS 15

#724
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

Would you mind giving an example of something bad that could happen to somebody as a result of Apple sending this data to itself? Something concrete, where the harm would be realized, for example somebody being hurt physically, emotionally, psychologically, economically, etc

Re: Apple Photos phones home on iOS 18 and macOS 15

#725

Users of my (free, open-source) app seem surprised to learn that we've got zero insight into usage patterns. There are situations where a small amount of anonymous telemetry would be extremely helpful but I'm not going to touch it with a barge-pole. Opt-in makes the data useless - not just in terms of the huge drop in quantity but because of the fact it introduces a huge bias in the data selected - the people that wo…

Yes, this is one of the main reasons people mostly build on web. It's very difficult to make desktop software better, and especially Linux users are hostile to patterns that would make improvements possible

Re: Apple Photos phones home on iOS 18 and macOS 15

#726
post #690

As trivia, on mac os, the photoanalysisd service will run in the background and look through your photos, even if you never open Apple Photos. It can't be disabled unless you disable SIP (system integrity protection) which requires a complicated dance of reboots and warnings. It will reenable if you turn SIP back on. It seems Apple are very passionate about analysing your photos for some reason, regardless if you you…

“It seems Apple are very passionate about analysing your photos for some reason, regardless if you yourself are.” Isn’t this fragile to pollution from end users? What if we all ran A local Image generator trained on our own photos… But slightly broken… And just flooded their photo hash collection with garbage? Now what ? This would be a very good flushing action. Lot would be learned by seeing who got angry about thi…

No. The analysis in question is fully local, used for indexing photos by categories in the Photos app. It is unrelated to any cloud features and not something shared across users.

They are also not using your personal photos to feed the location database, most likely public sources and/or Apple Maps data. If they are relying on GPS-tagged public photos alone, you could probably mess up a system like this by spoofing GPS location en-masse and posting them online for years, but for what purpose?

Re: Apple Photos phones home on iOS 18 and macOS 15

#727
post #665

Earlier quoted context omitted.

The point still stands. That’s how geo-tagged images get in your photos, and the search function still works. For what it’s worth, I’m surprised that you never save photos to your phone that you didn’t take yourself. Do people not send you interesting pictures? Pictures of yourself?

I don't actually use my phone for much. Taking photos, making phone calls. I'm not the kind of person who lives on their phone. I live on my laptop (which has Location Services disabled entirely). I don't even use Photos app on Mac anymore. They've ruined it compared to the old iPhoto. I just keep my photos in folders in Finder.

[flagged]

Re: Apple Photos phones home on iOS 18 and macOS 15

#728
post #105
post #4

I don’t even use iCloud Photos and this was on by default. Very bad move by Apple to ship my photos off my device, without my permission, in any shape or form, I don’t care.

That isn't what is happening. The author of this blog post has absolutely no idea what he is talking about.

> That isn't what is happening

Then why is it happening to me?

Re: Apple Photos phones home on iOS 18 and macOS 15

#729

Earlier quoted context omitted.

You may also be shocked to learn that Spotlight looks through every single file on your Mac.

I was. First by the md_worker processes that mysteriously started pinning all of my CPU cores after a git clone. Then by the realization that MacOS had built a full-text index of millions of lines of source code (it only took a few hours of my Mac being too hot to touch). A lot of Apple's defaults are just plain bizarre. Why the hell is Spotlight seeing source code mimetypes and feeding it to the search index?

I love it that it indexes source code. It allows me to find things easily.

Re: Apple Photos phones home on iOS 18 and macOS 15

#730
post #643
post #629

Earlier quoted context omitted.

This mindset is how we got those awful cookie banners. Even more dialogs that most users will blindly tap "Allow" to will not fix the problem. Society has collectively decided (spiritually) that it is ok signing over data access rights to third parties. Adding friction to this punishes 98% of people in service of the 2% who aren't going to use these services anyway. Sure, a more educated populous might tip the scales…

> This mindset is how we got those awful cookie banners. The only thing I've found awful is the mindset of the people implementing the banners. That you feel frustration over that every company has a cookie banner, is exactly the goal. The companies could decide that it isn't worth frustrating the user over something trivial like website analytics, as they could get that without having to show a cookie banner at all.…

In my experience, most people that have semi or full decision-making control over this kind of thing have absolutely no idea if they even need cookie consent banners. They just fall for the marketing speak of every single SAAS product that sells cookie-consent/GDPR stuff and err on the side of caution. No one wants to be the guy that says: "hey, we're only logging X, Y and not Z. And GDPR says we need consent only if we log Z, so therefore we don't need cookie consent." For starters, they need a lawyer to tell them it's "A OK" to do it this way, and secondly it's plain old cheaper and a lot less political capital to just go with the herd on this. The cost of the banner is off-loaded outside of the company and, for the time being, the users don't seem to mind or care.

This is why half the web has cookie-consent banners. No amount of developers who know the details screaming up the ladder will fix this. The emergent behavior put in place by the legal profession and corporate politics favors the SAAS companies that sell GDPR cookie banner products and libraries. Even if they're in the right, there is a greater-than-zero percent chance that if they do the wrong thing they'll go to court or be forced to defend themselves. And even then if it's successful, the lawyers still need to be paid, and the company will look at "that fucking moron Joe from the website department" which caused all their hassles and countless hours of productivity as a result of being a "smart ass".

Post reply on HN