Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

901–910 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#901
post #268

Earlier quoted context omitted.

How much size would it take to store a model of every known location in the world and common things? For ex: I sent a friend a photo of my puppy in the bathtub and her Airpods (via iphone) announced "(name) sent you a photo of a dog in a bathtub". She thought it was really cool and so do I personally. That's a useful feature. IDK how much that requires going off-device though.

> That's a useful feature. I’m really curious how this feature is considered useful. It’s cool, but can’t you just open the photo to view it?

With an assault of notifications while you are busy, being able to determine without lifting your phone whether the alert is something mundane versus what you've been waiting for, is useful. If I'm working outside, removing gloves to check the phone each time it vibrates becomes endlessly disruptive, but I want the phone with me in case family calls, someone's delivering something, there's an urgent work issue, etc.

Re: Apple Photos phones home on iOS 18 and macOS 15

#902
post #899

Worth noting that you need iCloud active in the first place to opt-out of this feature, so it is still opt-in, since it is only ever defaulted to being on for users who proactively signed into iCloud.

This is not true.

Ah yes, you're right. I spoke to soon. I just checked on the latest Beta simulator and, sure enough, it is checked, with a fresh install and no iCloud account.

At least that proves the service is accessible anonymously (i.e., without an identifying iCloud token)

Re: Apple Photos phones home on iOS 18 and macOS 15

#903
post #643
post #629

Earlier quoted context omitted.

This mindset is how we got those awful cookie banners. Even more dialogs that most users will blindly tap "Allow" to will not fix the problem. Society has collectively decided (spiritually) that it is ok signing over data access rights to third parties. Adding friction to this punishes 98% of people in service of the 2% who aren't going to use these services anyway. Sure, a more educated populous might tip the scales…

> This mindset is how we got those awful cookie banners. The only thing I've found awful is the mindset of the people implementing the banners. That you feel frustration over that every company has a cookie banner, is exactly the goal. The companies could decide that it isn't worth frustrating the user over something trivial like website analytics, as they could get that without having to show a cookie banner at all.…

[flagged]

Re: Apple Photos phones home on iOS 18 and macOS 15

#904
post #895

Earlier quoted context omitted.

> I'd be much more impressed if we could run software like Little Snitch on iOS You can; or, at least, the APIs are available for this, and have been for some time. > or install Firefox https://apps.apple.com/us/app/firefox-private-safe-browser/i... Inb4 "you cannot replace the built-in browser engine" https://developer.apple.com/documentation/browserenginekit > Or even just side load apps without pay $100/year Then…

> You can; or, at least, the APIs are available for this, and have been for some time. Why is there no citation on this one? iOS has a (fairly limited) VPN API but it is woefully insufficient to make an application-level firewall and I don't think any exist. > https://apps.apple.com/us/app/firefox-private-safe-browser/i ... That's Safari in a trenchcoat. > Inb4 "you cannot replace the built-in browser engine" > https…

> Why is there no citation on this one?

Clearly none was needed since you know what I was referring to. I disagree that the APIs are not sufficient, since I've used them in enterprise contexts and found them to be comprehensive. The same APIs are available via consumer means. There are tons of VPN and filtering apps for iOS.

From [0]:

- Change the system’s Wi-Fi configuration

- ...

- Create and manage VPN configurations, using the built-in VPN protocols (Personal VPN) or a custom VPN protocol

- Create and manage network relay configurations

- Implement an on-device content filter

- Create and manage system-wide DNS configurations

- ...

And continues with:

- Configure your VPN to include and exclude some network traffic

- "... built-in proxying for TCP and UDP traffic over HTTP/3 and HTTP/2..."

- Use the Network Extension framework to allow or deny network connections

- ...

> That's Safari in a trenchcoat.

Only if you consider the core of Firefox to be Gecko, and not the entire product experience created around Gecko, which is merely an engine.

The security surface area of a JIT-enabled browser engine is significant and complex (see: Chrome). Apple arguably keeps phones safer by maintaining this restriction. Isn't that what you want in the first place?

> That requires an entitlement that A...

See note about Apple's active hostility toward hobbyists. This is considered a feature from their perspective, and reasonable minds could differ about whether they are right, but it is a choice nonetheless.

> I own both iOS and Android devices for what it's worth

So do I. I don't understand why this is mysterious to you, then.

> Since... it was formed? Really?

Yes, really. "Since it was formed" as in, Apple has always taken a stance (after well documented disagreement between the Steves) to build a "walled garden." Whether that wall is a $100/yr fee, or special screws in a tower case, or what not, they have consistently implemented that opinion with action since their inception.

Apple II aside, macOS is actively hostile toward 3rd party software. See: Notary, signing, and so on.

> This is a frankly insane thing to say to someone who is in middle of criticizing Apple for this exact hostility

Being hostile toward hobbyists is a feature to them, not a bug, and it is orthogonal to privacy at best (at worst, in their view, openness is harmful to privacy). If we are arguing about privacy, then we might agree on this point, but for different reasons.

> [Apple is the same company that ran a tirade]... [Don't like it? Just use something else!]

Yes, that is your right. I don't claim to defend everything Apple produces, but, focusing again on the topic at hand (privacy/security), I personally think they do a better job than most. Their choices to get there can be argued over, of course, which is what we are doing now. I see their choices are part-and-parcel of a larger cohesive strategy; apparently you do not?

> So I can't just pretend Apple doesn't exist

Sure, I never suggested you could, merely that other devices will be naturally better for people who want to use them as enthusiasts or hobbyists outside the Blessed Apple Path(tm).

> I know. I don't think highly of this position, but I am well aware of it.

¯\_(ツ)_/¯ I think highly of your position to argue with it in good faith, so I'm sad to hear that.

[0]: https://developer.apple.com/documentation/networkextension

Re: Apple Photos phones home on iOS 18 and macOS 15

#905
post #895

Earlier quoted context omitted.

> I'd be much more impressed if we could run software like Little Snitch on iOS You can; or, at least, the APIs are available for this, and have been for some time. > or install Firefox https://apps.apple.com/us/app/firefox-private-safe-browser/i... Inb4 "you cannot replace the built-in browser engine" https://developer.apple.com/documentation/browserenginekit > Or even just side load apps without pay $100/year Then…

> You can; or, at least, the APIs are available for this, and have been for some time. Why is there no citation on this one? iOS has a (fairly limited) VPN API but it is woefully insufficient to make an application-level firewall and I don't think any exist. > https://apps.apple.com/us/app/firefox-private-safe-browser/i ... That's Safari in a trenchcoat. > Inb4 "you cannot replace the built-in browser engine" > https…

Also, because it's just worth noting anyway:

> That's Safari in a trenchcoat.

Then so is Chrome, or, where do you draw the line? WebKit bad, Gecko good? Why? Blink is a fork of WebKit. Ultimately who cares which JIT-enabled browser engine runs your JS?

Re: Apple Photos phones home on iOS 18 and macOS 15

#906
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

Opt in doesn't work, it never did. The vast majority (>95%) of users does not understand what those pop-ups say, seems fundamentally incapable of reading them, and either always accepts, always rejects, or always clicks the more visually-appealing button. Try observing a family member who is not in tech and not in the professional managerial class, and ask them what pop-up they just dismissed and why. It's one of the…

[deleted]

Re: Apple Photos phones home on iOS 18 and macOS 15

#907
post #883

Earlier quoted context omitted.

“Ask App Not To Track” would like a word

Not impressed. I'd be much more impressed if we could run software like Little Snitch on iOS, or install Firefox. Or even just side load apps without pay $100/year. (Note: a Safari webview with a Firefox logo on it does not count.)

> Not impressed.

So Apple kneecaps Meta's cross-app advertising, something that literally makes them no direct revenue to implement, and protects users (it famously reduced Facebook cross-app analytics traffic to a significant degree), and you think this is business as usual?

Then you should reconsider my comment at the top of this thread, because it is 100% speaking to this exact phenomenon.

Re: Apple Photos phones home on iOS 18 and macOS 15

#908
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

Opt in doesn't work, it never did. The vast majority (>95%) of users does not understand what those pop-ups say, seems fundamentally incapable of reading them, and either always accepts, always rejects, or always clicks the more visually-appealing button. Try observing a family member who is not in tech and not in the professional managerial class, and ask them what pop-up they just dismissed and why. It's one of the…

Opt in works great, pop-up dialogues do not.

Re: Apple Photos phones home on iOS 18 and macOS 15

#909
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

> So why didn't Apple just simply ask for user permission to enable this feature? That’s an interesting question. Something to consider, iOS photos has allowed you to search for photos using the address the photo was taken at. To do that requires the Photos app to take the lat/long of a photos location, and do a reverse-geo lookup to get a human understandable address. Something that pretty much always involves query…

> To do that requires the Photos app to take the lat/long of a photos location, and do a reverse-geo lookup to get a human understandable address.

It seems trivially possible to do this in a more privacy preserving way: geocode the search query and filter photos locally.

No idea how Apple implements it though.

Re: Apple Photos phones home on iOS 18 and macOS 15

#910
post #883

Earlier quoted context omitted.

Not impressed. I'd be much more impressed if we could run software like Little Snitch on iOS, or install Firefox. Or even just side load apps without pay $100/year. (Note: a Safari webview with a Firefox logo on it does not count.)

> Not impressed. So Apple kneecaps Meta's cross-app advertising, something that literally makes them no direct revenue to implement, and protects users (it famously reduced Facebook cross-app analytics traffic to a significant degree), and you think this is business as usual? Then you should reconsider my comment at the top of this thread, because it is 100% speaking to this exact phenomenon.

I mean I'm unimpressed as far as user agency goes, not as far as privacy goes.
Post reply on HN