Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

791–800 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#791

Users of my (free, open-source) app seem surprised to learn that we've got zero insight into usage patterns. There are situations where a small amount of anonymous telemetry would be extremely helpful but I'm not going to touch it with a barge-pole. Opt-in makes the data useless - not just in terms of the huge drop in quantity but because of the fact it introduces a huge bias in the data selected - the people that wo…

> Opt-in makes the data useless - not just in terms of the huge drop in quantity but because of the fact it introduces a huge bias in the data selected - the people that would opt-in are probably not a good sample of "typical users".

Why? I don't think that's obvious. It may also be related to the way the opt-in is presented. In general, I would expect this to be a workable solution. Even if the opt-in group deviates from the "typical user", it's the best data you can get in an honest and ethically sound way. This should certainly be better than no data at all?

For any website/app that presents an opt-in cookie consent banner this is implicitly already the case.

Re: Apple Photos phones home on iOS 18 and macOS 15

#792

Is this just a smokescreen around slowly sneaking CSAM scanning back in after the pushback last time? The "default on" behavior is suspect. [1] https://www.wired.com/story/apple-photo-scanning-csam-commun...

Yup, this is their way of injecting the "phone home" element via an innocuous rationale, "location matching". The global index will of course also match against other markers they deem worthy of matching, even if they don't return that to the user.

Honestly, why the hell would Apple bother with such a contrived and machiavellian strategy to spy on their users?

They literally own the code to iOS. If they wanted to covertly track their customers, they could just have their devices phone home with whatever data they wanted to collect. Realistically there would be no way to know if this was actually happening, because modern devices emit so much encrypted data anyway, it wouldn’t be hard to hide some nefarious in all the noise.

Time Cook isn’t some Bond villain, sitting in a giant chair, stroking a white cat, plotting to take over the world by lulling everyone into a false sense of privacy (I mean Zuckerburg already did that). Apple is just a large giant corporation that wants to make money, and is pretty damn open about that fact. They clearly think that they can make more money by doubling down on more privacy, but that doesn’t work if you don’t actually provide the privacy, because ultimately, people are really crap at keeping secrets, especially when a media group would happily pay for a story, even at Apple.

Re: Apple Photos phones home on iOS 18 and macOS 15

#793
post #204

Earlier quoted context omitted.

I guess it depends on what you're calling "your data" -- without being able to reconstruct an image from a noised vector, can we say that that vector in any way represents "your data"? The way the process works, Apple makes their own data that leaves your device, but the photo never does.

It's the same as the CSAM initiative. It doesn't matter what they say they send, you cannot trust them to send what they say they send or trust them not to change it in the future. Anything that leaves my devices should do so with my opt-IN permission.

Even if they implemented the feature with opt-in permissions, why would you trust this company to honor your negative response to the opt-in?

Re: Apple Photos phones home on iOS 18 and macOS 15

#794

Earlier quoted context omitted.

The third choice, after opt-in and opt-out is to force the user to choose on upgrade before they can use their device again. "Can we use an encrypted, low-resolution copy of your photos that even we ourselves can't see?"

Okay except "encrypted, low-resolution copy of your photos" is an incredibly bad explanation of how this feature works. If nobody on HN so far has managed to find an explanation that is both accurate and understandable to the average consumer, any "hey can we do this" prompt for this feature is essentially useless anyways. And, IMO, unnecessary since it is theoretically 100% cryptographically secure.

I think it's sufficiently accurate, why don't you think it is? I don't think the vector vs low-res aspect is particularly material to understanding the key fact that "even we ourselves can't see?"

Re: Apple Photos phones home on iOS 18 and macOS 15

#795

Earlier quoted context omitted.

Even with opt-in a vendor will keep harassing the user until they tap "yes" in an inattentive moment. And I've been in situations where I noticed a box was checked that I'm sure I didn't check. I want to turn these things off and throw away the key. But of course the vendor will never allow me to. Therefore I use Linux.

I want to turn these things off and throw away the key. But of course the vendor will never allow me to. Therefore I use Linux. I hate to break it to you, but these things happen in Linux, too. It's not the operating system that's the problem. It's that the tech industry has normalized greed.

Yes, but if it happens at least there is no greedy intent and it will be corrected by the community.

Re: Apple Photos phones home on iOS 18 and macOS 15

#796
post #784

Earlier quoted context omitted.

Even with opt-in a vendor will keep harassing the user until they tap "yes" in an inattentive moment. And I've been in situations where I noticed a box was checked that I'm sure I didn't check. I want to turn these things off and throw away the key. But of course the vendor will never allow me to. Therefore I use Linux.

For what it's worth, I use Linux, too, but as far as phones go, stock phones that run Linux suffer from too many reliability and stability issues for me to daily drive them. I actually did try. So, as far as phones go, I'm stuck with the Android/iOS duopoly like anyone else.

Well, I was speaking in general, not about phones.

Re: Apple Photos phones home on iOS 18 and macOS 15

#797
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

>> Trust in software will continue to erode until software stops treating end users and their data and resources Trust in closed-source proprietary software. In other words: trust in corporate entities. Trust in open-source software is going strong.

Not a given though. Ubuntu phones home a lot by default.

Try disabling the motd stuff - it's quite pernicious by design.

And removing the ubuntu-advantage package disables the desktop. lol.

Re: Apple Photos phones home on iOS 18 and macOS 15

#798

As trivia, on mac os, the photoanalysisd service will run in the background and look through your photos, even if you never open Apple Photos. It can't be disabled unless you disable SIP (system integrity protection) which requires a complicated dance of reboots and warnings. It will reenable if you turn SIP back on. It seems Apple are very passionate about analysing your photos for some reason, regardless if you you…

> for some reason It's directly tied to features they provide in their photo app. This is hardly obscure.

Why make it extremely hard to disable? Photos is hardly a system level app

Re: Apple Photos phones home on iOS 18 and macOS 15

#799

As trivia, on mac os, the photoanalysisd service will run in the background and look through your photos, even if you never open Apple Photos. It can't be disabled unless you disable SIP (system integrity protection) which requires a complicated dance of reboots and warnings. It will reenable if you turn SIP back on. It seems Apple are very passionate about analysing your photos for some reason, regardless if you you…

You may also be shocked to learn that Spotlight looks through every single file on your Mac.

Local search indexing is somewhat more defendable as a system level service, but yeah, it would be nice if that was also up to me as a user.

Re: Apple Photos phones home on iOS 18 and macOS 15

#800
post #789

Earlier quoted context omitted.

I want to turn these things off and throw away the key. But of course the vendor will never allow me to. Therefore I use Linux. I hate to break it to you, but these things happen in Linux, too. It's not the operating system that's the problem. It's that the tech industry has normalized greed.

It is true that there are not absolutely zero instances of telemetry or "phoning home" in Linux, but Desktop Linux is not a similar experience to Windows or macOS in this regard, and it isn't approaching that point, either. You can tcpdump a clean install of Debian or what-have-you and figure out all of what's going on with network traffic. Making it whisper quiet typically isn't a huge endeavor either, usually just…

Are there any tools that enable capturing traffic from outside the OS you’re monitoring, that still allow for process-level monitoring?

Meaning, between the big vendors making the OS, and state-level actors making hardware, I wouldn’t necessarily trust Wireshark on machine A to provide the full picture of traffic from machine A. We might see this already with servers running out-of-band management like iDRAC (which is a perfectly fine, non-malicious use case) but you could imagine the same thing where the NIC firmware is phoning home, completely outside the visibility of the OS.

Of course, it’s not hard to capture traffic externally, but the challenge here would be correlating that external traffic with internal host monitoring data to determine which apps are the culprit.

Post reply on HN