Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

851–860 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#851

Is this just a smokescreen around slowly sneaking CSAM scanning back in after the pushback last time? The "default on" behavior is suspect. [1] https://www.wired.com/story/apple-photo-scanning-csam-commun...

That whole incident was so misinformed. CSAM scanning takes place on the cloud with all the major players. It only has hashes for the worst of the worst stuff out there. What Apple (and others do) is allow the file to be scanned unencrypted on the server. What the feature Apple wanted to add was scan the files on the device and flag anything that gets a match. That file in question would be able to be decrypted on th…

> What the feature Apple wanted to add was scan the files on the device and flag anything that gets a match.

This is not the revelation you think it is. Critics understood this perfectly.

People simply did not want their devices scanning their content against some opaque uninspectable government-controlled list that might send you to jail in the case of a match.

More generally, people usually want their devices working for their personal interests only, and not some opaque government purpose.

Re: Apple Photos phones home on iOS 18 and macOS 15

#852

Earlier quoted context omitted.

I can't believe how uninformed, angry, and still willing to argue about it people were over this. The whole point was a very reasonable compromise between a legal requirement to scan photos and keeping photos end-to-end encrypted for the user. You can say the scanning requirement is wrong, there's plenty of arguments for that. But Apple went so above and beyond to try to keep photo content private and provide E2E enc…

There isn’t a law that requires them to proactively scan photos. That is why they could turn the feature back off.

A law by the government requiring proactive scanning of photos would in fact make the whole situation worse in the US because there would need to be a warrant if the government is requiring the scan. As long as it's voluntary by the company and not coerced by the government, they can proactively scan.

Re: Apple Photos phones home on iOS 18 and macOS 15

#853

Earlier quoted context omitted.

That whole incident was so misinformed. CSAM scanning takes place on the cloud with all the major players. It only has hashes for the worst of the worst stuff out there. What Apple (and others do) is allow the file to be scanned unencrypted on the server. What the feature Apple wanted to add was scan the files on the device and flag anything that gets a match. That file in question would be able to be decrypted on th…

I can't believe how uninformed, angry, and still willing to argue about it people were over this. The whole point was a very reasonable compromise between a legal requirement to scan photos and keeping photos end-to-end encrypted for the user. You can say the scanning requirement is wrong, there's plenty of arguments for that. But Apple went so above and beyond to try to keep photo content private and provide E2E enc…

> a legal requirement to scan photos

Can you provide documentation demonstrating this requirement in the United States? It is widely understood that no such requirement exists.

There's no need to compromise with any requirement, this was entirely voluntary on Apple's part. That's why people were upset.

> I can't believe how uninformed

Oh the irony.

Re: Apple Photos phones home on iOS 18 and macOS 15

#854

Earlier quoted context omitted.

That whole incident was so misinformed. CSAM scanning takes place on the cloud with all the major players. It only has hashes for the worst of the worst stuff out there. What Apple (and others do) is allow the file to be scanned unencrypted on the server. What the feature Apple wanted to add was scan the files on the device and flag anything that gets a match. That file in question would be able to be decrypted on th…

> What the feature Apple wanted to add was scan the files on the device and flag anything that gets a match. This is not the revelation you think it is. Critics understood this perfectly. People simply did not want their devices scanning their content against some opaque uninspectable government-controlled list that might send you to jail in the case of a match. More generally, people usually want their devices worki…

From my understanding, it didn't scan all of the files on the device, just the files that were getting uploaded to Apple's iCloud. It was set up to scan the photos on the device because the files were encrypted before they were sent to the cloud and Apple couldn't access the contents but still wanted to try to make sure that their cloud wasn't storing anything that matched various hashes for bad content.

If you never uploaded those files to the cloud, the scanning wouldn't catch any files that are only local.

Re: Apple Photos phones home on iOS 18 and macOS 15

#855
post #629
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

This mindset is how we got those awful cookie banners. Even more dialogs that most users will blindly tap "Allow" to will not fix the problem. Society has collectively decided (spiritually) that it is ok signing over data access rights to third parties. Adding friction to this punishes 98% of people in service of the 2% who aren't going to use these services anyway. Sure, a more educated populous might tip the scales…

Why does it have to be more friction?

Users had a global way to signal “do not track me” in their browser. I don’t know why regulators didn’t mandate respecting that instead of cookie consent popups.

Apple IDs could easily have global settings about what you are comfortable with, and then have their apps respect them.

Re: Apple Photos phones home on iOS 18 and macOS 15

#856

Earlier quoted context omitted.

I’m deeply familiar with all of these techniques, the core issue here is informed consent which they have not obtained. Furthermore, Apples privacy stance is generally a sham as their definition of “human rights” doesn’t extend to China. Which either means Apple doesn’t respect human rights, or they don’t view Chinese people as human.

Apple follows the law. First you need to get the Chinese government to respect those rights. The only other choice is to stop doing business entirely in the country.

A choice many companies have made. Apple is in China to make money, which is what a corporation is set up to do. My point is them claiming the moral high ground of a human rights defender is utterly laughable bullshit.

Re: Apple Photos phones home on iOS 18 and macOS 15

#857
post #758
post #378

Earlier quoted context omitted.

Completely missing the point, but you're right that I should have said “using or in possession” of the computer. The point is that they reveal your physical location to the network, so if they make requests while not directly in use then it's actually even worse. For context, stationary desktop machines comprise single-digit percentages of Mac sales: https://appleinsider.com/articles/24/03/06/macbook-pro-and-m... Eve…

Your Mac connected to your trusted home network when it want turned off? Wow, scandalous. You can randomize your MAC address. Built in OS feature.

“wasn’t turned off” is what I meant to say.

What I mean is, an M3 MacBook has essentially the same processor as a cell phone. Of course it’s able to perform activities when the system is “asleep.” It even has specific online behavior labeled as a feature that can be turned on/off (Power Nap).

https://support.apple.com/guide/mac-help/turn-power-nap-on-o...

This is behavior that is desired by Apple’s users.

I sometimes wish that more Apple users who aren’t satisfied would stop complaining while continuing to throw money at Apple and buy themselves a Linux laptop. If you want a laptop with special features like a WiFi kill switch you should buy one of those, not buy a consumer appliance device that is marketed toward convenience-oriented home users.

Re: Apple Photos phones home on iOS 18 and macOS 15

#858
post #651

Earlier quoted context omitted.

I don't do that. My Photos library contains camera snapshots and screenshots, nothing else.

you started out suggesting it wasn't possible and when presented with a common case showing it was not only possible but likely, you moved the goal posts and now say "well, I don't do that." Weak sauce.

I admit that I hadn't considered the possibility of importing outside geotagged photos into your own Photos library, because I don't do that. But I also said already, "To be clear, I meant that it was a nonissue for me, because I don't geotag my photos (except in that one test). Whether it's an issue for other people, I don't know."

I don't personally have a strong feeling for or against this particular feature, since I don't use geotagging at all, so it doesn't affect me. I'm neither endorsing nor condemining it offhand. I'll leave it to other people to argue over whether it's a privacy problem. It could be! I just lack the proper perspective on this specific issue.

Re: Apple Photos phones home on iOS 18 and macOS 15

#859
post #176

I am on the latest iOS, just discovered this setting, it wasn’t turned on by default.

Maybe the new setting checks a certain combination of other settings first, like: if (setting_1 && setting_2 && !setting_3) { new_setting = true } Mine was also enabled by default.

I have Photos shared library set up, one of the members of the library is a child account — I wonder if that’s got anything to do with it.

Re: Apple Photos phones home on iOS 18 and macOS 15

#860

Earlier quoted context omitted.

> What the feature Apple wanted to add was scan the files on the device and flag anything that gets a match. This is not the revelation you think it is. Critics understood this perfectly. People simply did not want their devices scanning their content against some opaque uninspectable government-controlled list that might send you to jail in the case of a match. More generally, people usually want their devices worki…

From my understanding, it didn't scan all of the files on the device, just the files that were getting uploaded to Apple's iCloud. It was set up to scan the photos on the device because the files were encrypted before they were sent to the cloud and Apple couldn't access the contents but still wanted to try to make sure that their cloud wasn't storing anything that matched various hashes for bad content. If you never…

Your understanding is correct, as was/is the understanding of people critical of the feature.

People simply don't want their device's default state to be "silently working against you, unless you are hyperaware of everything that needs to be disabled". Attacks on this desire were felt particularly strongly due to Apple having no legal requirement to implement that functionality.

One also can't make the moral argument that the "bad content" list only included CSAM material, as that list was deliberately made opaque. It was a "just trust me bro" situation.

Post reply on HN