Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

771–780 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#771
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

Would you mind giving an example of something bad that could happen to somebody as a result of Apple sending this data to itself? Something concrete, where the harm would be realized, for example somebody being hurt physically, emotionally, psychologically, economically, etc

Easy, consider a parent taking pictures of their kid's genitals to send to their doctor to investigate a medical condition, the pictures getting flagged and reported to the authorities as being child pornography by an automated enforcement algorithm, leading to a 10-month criminal investigation of the parent. This exact thing happened with Google's algorithm using AI to hunt for CP[1], so it isn't hard to imagine that it could happen with Apple software, too.

[1] https://www.koffellaw.com/blog/google-ai-technology-flags-da...

Re: Apple Photos phones home on iOS 18 and macOS 15

#772

Earlier quoted context omitted.

> So why didn't Apple just simply ask for user permission to enable this feature? That’s an interesting question. Something to consider, iOS photos has allowed you to search for photos using the address the photo was taken at. To do that requires the Photos app to take the lat/long of a photos location, and do a reverse-geo lookup to get a human understandable address. Something that pretty much always involves query…

You’re right. But: Anyone in IT or tech, thinking deeply about the raw facts. They know it always boils down to trust, not technology. The interesting thing is that Apple has created a cathedral of seemingly objective sexy technical details that feel like security. But since it’s all trust, feelings matter! So my answer is, if it feels like a privacy violation, it is. Your technical comparison will be more persuasive…

Apple chose to implement things like OHTTP and homomorphic encryption when they could easily have done without it. Doesn't that count for something?

Re: Apple Photos phones home on iOS 18 and macOS 15

#773
post #439

Completely, 100% agreed: > the only way to guarantee computing privacy is to not send data off the device. > It ought to be up to the individual user to decide their own tolerance for the risk of privacy violations. [...] By enabling the "feature" without asking, Apple disrespects users and their preferences. I never wanted my iPhone to phone home to Apple. Regardless of how obfuscated or "secure" or otherwise "priva…

So Signal messages aren't secure because they're transmitted and so their "obfuscation" isn't enough to protect your data? Have you read what the author cited (and then admitted to not understanding) what Apple says they actually do to the data before transmission? I could see an argument in the metadata (though there are multiple assumptions involved there, not least that they don't truly do OHTTP but instead conspi…

The difference being that the signal message is sent with consent: You literally press a button to send it there is a clear causal relationship between clicking the button and the message being sent.

Re: Apple Photos phones home on iOS 18 and macOS 15

#774

Earlier quoted context omitted.

If you don't feel a responsibility for inflicting pain on other people, that's on you. I'm not a sociopath.

The pain of a possible future panopticon dwarfs the "pain" of some software crashing. Considering long-term outcomes does not make you a sociopath - quite the opposite.

Ah, the slippery slope fallacy!

Re: Apple Photos phones home on iOS 18 and macOS 15

#775
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

Even with opt-in a vendor will keep harassing the user until they tap "yes" in an inattentive moment.

And I've been in situations where I noticed a box was checked that I'm sure I didn't check. I want to turn these things off and throw away the key. But of course the vendor will never allow me to. Therefore I use Linux.

Re: Apple Photos phones home on iOS 18 and macOS 15

#776
post #771

Earlier quoted context omitted.

Would you mind giving an example of something bad that could happen to somebody as a result of Apple sending this data to itself? Something concrete, where the harm would be realized, for example somebody being hurt physically, emotionally, psychologically, economically, etc

Easy, consider a parent taking pictures of their kid's genitals to send to their doctor to investigate a medical condition, the pictures getting flagged and reported to the authorities as being child pornography by an automated enforcement algorithm, leading to a 10-month criminal investigation of the parent. This exact thing happened with Google's algorithm using AI to hunt for CP[1], so it isn't hard to imagine tha…

Good example. I think this is worth the tradeoff

Re: Apple Photos phones home on iOS 18 and macOS 15

#778

Earlier quoted context omitted.

> So why didn't Apple just simply ask for user permission to enable this feature? That’s an interesting question. Something to consider, iOS photos has allowed you to search for photos using the address the photo was taken at. To do that requires the Photos app to take the lat/long of a photos location, and do a reverse-geo lookup to get a human understandable address. Something that pretty much always involves query…

You’re right. But: Anyone in IT or tech, thinking deeply about the raw facts. They know it always boils down to trust, not technology. The interesting thing is that Apple has created a cathedral of seemingly objective sexy technical details that feel like security. But since it’s all trust, feelings matter! So my answer is, if it feels like a privacy violation, it is. Your technical comparison will be more persuasive…

> So my answer is, if it feels like a privacy violation, it is. Your technical comparison will be more persuasive if you presented it in Computer Modern in a white paper, or if you are an important Substack author or reply guy, or maybe take a cue from the shawarma guy on Valencia Street and do a hunger strike while comparing two ways to get location info.

They’re broadly similar services, both provided by the same entity. Either you trust that entity or you don’t. You can’t simultaneously be happy with an older, less private feature, that can’t be disabled. While simultaneously criticising the same entity for creating a new feature (that carries all the same privacy risks) that’s technically more private, and can be completely disabled.

> The interesting thing is that Apple has created a cathedral of seemingly objective sexy technical details that feel like security. But since it’s all trust, feelings matter!

This is utterly irrelevant, you’re basically making my point for me. As above, either you do or do not trust Apple to provide these services. The implementation is kinda irrelevant. I’m simply asking people to be a little more introspective, and take a little more time to consider their position, before they start yelling from the rooftops that this new feature represents some great privacy deception.

Re: Apple Photos phones home on iOS 18 and macOS 15

#779
post #11

"I don't understand most of the technical details of Apple's blog post" I do: - Client side vectorization: the photo is processed locally, preparing a non-reversible vector representation before sending (think semantic hash). - Differential privacy: a decent amount of noise is added the the vector before sending it. Enough to make it impossible to reverse lookup the vector. The noise level here is ε = 0.8, which is q…

This answer should be much higher. Thank you

Re: Apple Photos phones home on iOS 18 and macOS 15

#780
post #690

Earlier quoted context omitted.

“It seems Apple are very passionate about analysing your photos for some reason, regardless if you yourself are.” Isn’t this fragile to pollution from end users? What if we all ran A local Image generator trained on our own photos… But slightly broken… And just flooded their photo hash collection with garbage? Now what ? This would be a very good flushing action. Lot would be learned by seeing who got angry about thi…

No. The analysis in question is fully local, used for indexing photos by categories in the Photos app. It is unrelated to any cloud features and not something shared across users. They are also not using your personal photos to feed the location database, most likely public sources and/or Apple Maps data. If they are relying on GPS-tagged public photos alone, you could probably mess up a system like this by spoofing…

Like I said, a good candidate for a "flushing action":

https://kozubik.com/items/FlushingAction/

Flood that system with garbage and let's see who gets upset and how they communicate their upset.

If the system is architected as advertised it shouldn't be a problem ...

Post reply on HN