Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

781–790 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#781
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

Even with opt-in a vendor will keep harassing the user until they tap "yes" in an inattentive moment. And I've been in situations where I noticed a box was checked that I'm sure I didn't check. I want to turn these things off and throw away the key. But of course the vendor will never allow me to. Therefore I use Linux.

I want to turn these things off and throw away the key. But of course the vendor will never allow me to. Therefore I use Linux.

I hate to break it to you, but these things happen in Linux, too.

It's not the operating system that's the problem. It's that the tech industry has normalized greed.

Re: Apple Photos phones home on iOS 18 and macOS 15

#782
post #629
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

This mindset is how we got those awful cookie banners. Even more dialogs that most users will blindly tap "Allow" to will not fix the problem. Society has collectively decided (spiritually) that it is ok signing over data access rights to third parties. Adding friction to this punishes 98% of people in service of the 2% who aren't going to use these services anyway. Sure, a more educated populous might tip the scales…

I’m spitballing here but wouldn’t another way to handle it would be to return dummy / null responses by redirecting telemetry calls to something that will do so?

This would have the added benefit of being configurable and work on a bunch of apps instead of just one at a time too

Re: Apple Photos phones home on iOS 18 and macOS 15

#783
post #629

Earlier quoted context omitted.

This mindset is how we got those awful cookie banners. Even more dialogs that most users will blindly tap "Allow" to will not fix the problem. Society has collectively decided (spiritually) that it is ok signing over data access rights to third parties. Adding friction to this punishes 98% of people in service of the 2% who aren't going to use these services anyway. Sure, a more educated populous might tip the scales…

Not really. A mandatory opt-in option at the browser level would be the correct way to do it, but legislation forced instead those cookie banners onto the webpage.

No, legislation (the GDPR) doesn’t say anything about cookie pop ups. It says that private data (or any kind) can only be used with opt in consent, given freely, with no strings attached, with the ability to be withdrawn, that it will be kept secure, deleted when not needed for the original purpose, etc. All very reasonable stuff. Tracking cookies are affected, but the legislation covers all private data (IP, email address, your location, etc) … And if Browsers agreed on a standard to get and withdraw opt-in consent, it would be compatible with what the legislation requires.

Re: Apple Photos phones home on iOS 18 and macOS 15

#784
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

Even with opt-in a vendor will keep harassing the user until they tap "yes" in an inattentive moment. And I've been in situations where I noticed a box was checked that I'm sure I didn't check. I want to turn these things off and throw away the key. But of course the vendor will never allow me to. Therefore I use Linux.

For what it's worth, I use Linux, too, but as far as phones go, stock phones that run Linux suffer from too many reliability and stability issues for me to daily drive them. I actually did try. So, as far as phones go, I'm stuck with the Android/iOS duopoly like anyone else.

Re: Apple Photos phones home on iOS 18 and macOS 15

#785

Earlier quoted context omitted.

And of course you've reported every single crash you've encountered via email or support portal? Normal people don't email support with crash logs, they just grumble about it to their coworkers and don't help fix the problem. You can't fix a problem you don't know about.

> You can't fix a problem you don't know about. And yet we don't have home inspectors coming into our homes unannounced every week just to make sure everything is ok. Why is it that software engineers feel so entitled to do things that no other profession does?

Because software is digital and different than the physical world and someone like you understands that. It's intellectually dishonest to pretend otherwise. How hard is it to make a copy of your house including all the things inside of it? Can you remove all personally identifying features from your house with a computer program? Analogies have their limitations and don't always lead to rational conclusions. Physicists had to contend with a lot of those after Stephen Hawking wrote his book about black holes with crazy theories that don't make sense if you know the math behind them.

Downloading a torrent isn't the same thing as going to the record store and physically stealing a CD, and regular people can also understand that there's a difference between the invasiveness of a human being entering your house and someone not doing that. So either people can understand torrenting isn't the same as going into a store a physically stealing something and anonymized crash logs aren't the same thing as a home inspector coming into your house, or Napster and torrenters actually owe the millions that the RIAA and MPAA want them to.

I'm not saying that all tracking is unequivocally good, or even okay, some of it is downright bad. But let's not treat people as idiots who can't tell the difference between the digital and physical realm.

Re: Apple Photos phones home on iOS 18 and macOS 15

#786

Earlier quoted context omitted.

> The average smartphone is probably doing a hundred things you didn’t knowingly consent to every second. You've succinctly identified a (maybe the ) huge problem in the computing world today. Computers should not do anything without the user's command/consent. This seems like a hopeless and unachievable ideal only because of how far we've already strayed from the light. Even Linux, supposedly the last bastion of use…

"The light" you claim is that users should have the knowledge and discernment to consent to what a computer does. To me, there's never been a case, except maybe in the first decade or so of the hobby/tinkering PC movement, where most users had this ability. Should we just not use computers?

> Should we just not use computers?

I don't think "should we just give up?" is a reasonable question to anything.

Re: Apple Photos phones home on iOS 18 and macOS 15

#787
Going off a tangent, I wonder if the market reveals survival bias: companies and products that did respect privacy practice (e.g. by asking explicit permission) were not able to harness enough user data to compete with other bad players, and as a result, any company would eventually end up like Facebook or go out of business.

Sadly privacy is not a marketable feature, or at least it does not have the ROI as Apple originally believed. I feel the only way to level the play field is to reconsider our regulation framework and treat privacy as a fundamental benefit for consumers.

Re: Apple Photos phones home on iOS 18 and macOS 15

#788

Completely, 100% agreed: > the only way to guarantee computing privacy is to not send data off the device. > It ought to be up to the individual user to decide their own tolerance for the risk of privacy violations. [...] By enabling the "feature" without asking, Apple disrespects users and their preferences. I never wanted my iPhone to phone home to Apple. Regardless of how obfuscated or "secure" or otherwise "priva…

These issues are all addressed in the Apple blog post that talks about how this feature is implemented. Two steps are taken to deal with these risks:

1) iOS creates additional fake queries, and all queries pass through scheduler that ensures you can use time-of-lookup to either discriminate real queries from fake queries, or identify when a photo was taken.

2) All queries are performed anonymously, with the use of a third party relaying service. So there’s no way for Apple to tie a specific query back to a specific device, or even IP address.

Between those two mitigating features. Getting hold of an individuals personal data using this feature requires you to first compromise the targets phone, to disable the fake queries. Then compromise the relaying party to correlate queries back to a specific IP address.

If you can manage all that, then quite frankly you’re a fool for expending all that effort. When you could just use your iOS compromise to have the device send you its location data directly. No need to faff about waiting for your target to take photos, then track multiple landmark lookups, carefully collecting a few bits of additional data per query, until you finally have enough to identify the location of your target or targets.

The whole thing reminds me of XKCD 538.

https://machinelearning.apple.com/research/homomorphic-encry...

Re: Apple Photos phones home on iOS 18 and macOS 15

#789

Earlier quoted context omitted.

Even with opt-in a vendor will keep harassing the user until they tap "yes" in an inattentive moment. And I've been in situations where I noticed a box was checked that I'm sure I didn't check. I want to turn these things off and throw away the key. But of course the vendor will never allow me to. Therefore I use Linux.

I want to turn these things off and throw away the key. But of course the vendor will never allow me to. Therefore I use Linux. I hate to break it to you, but these things happen in Linux, too. It's not the operating system that's the problem. It's that the tech industry has normalized greed.

It is true that there are not absolutely zero instances of telemetry or "phoning home" in Linux, but Desktop Linux is not a similar experience to Windows or macOS in this regard, and it isn't approaching that point, either. You can tcpdump a clean install of Debian or what-have-you and figure out all of what's going on with network traffic. Making it whisper quiet typically isn't a huge endeavor either, usually just need to disable some noisy local networking features. Try Wiresharking a fresh Windows install, after you've unchecked all of the privacy options and ran some settings through Shutup10 or whatever. There's still so much crap going everywhere. It's hard to even stop Windows from sending the text you type into the start menu back to Microsoft, there's no option, you need to mess with Group Policy and hope they don't change the feature enough to need to change a different policy later to disable it again. macOS is probably still better (haven't checked in a while), but there are still some features that basically can't be disabled that leak information about what you're doing to Apple. For example, you can't stop macOS from phoning home to check OCSP status when launching software: there's no option to disable that.

The reason why this is the case is because while the tech industry is rotten, the Linux desktop isn't really directly owned by a tech industry company. There are a few tech companies that work on Linux desktop things, but most of them only work on it as a compliment to other things they do.

Distributions may even take it upon themselves to "fix" applications that have unwanted features. Debian is infamous for disabling the KeepassXC networking features, like fetching favicons and the browser integration, features a lot of users actually did want.

Re: Apple Photos phones home on iOS 18 and macOS 15

#790

Earlier quoted context omitted.

This is just "might makes right" bullshit with slightly prettier framing.

This has absolutely nothing to do with "might makes right". If a fast food store decides to offer a Vietnamese Peanut Burger and Sugar Cane Juice combo, nut allergy suffers are not "morally entitled" to a nut-free option and diabetics are not "morally entitled" to a sugar-free juice option. This applies whether the fast food store is a small family run business, or McDonalds. To suggest that customers are "morally en…

> nut allergy suffers are not "morally entitled" to a nut-free option

Restaurant have a legal obligation to warn the customers. AKA "opt-in" which is NOT what Apple is doing. And it's the whole issue with their behavior.

Post reply on HN