Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

971–980 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#971
post #951

Earlier quoted context omitted.

> People simply don't want their device's default state to be "silently working against you That was the misconception of what was happening though. Nothing happens on your device. Only when it gets to the cloud. It just puts a flag on the picture in question to have the cloud scan it. Which is exactly what happens before Apple suggested it and happens now. Except it does it for all your files. > One also can't make…

The scanning and matching is performed on your own device, against a copy of the databases which is encrypted to protect apple and their data providers against accountability for its content. The result of that match is itself encrypted, owing to the fact that the database is encrypted. On upload the query is decrypted and if there are above a threshold matches the decryption keys to all your content are revealed to…

> Your phone is your most trusted agent

What makes you think your phone is the most trusted device? Do you know everything that is running on your phone and what it does?

If a government wanted to enforce it then none of what Apple suggested mattered.

In fact they wouldn't even need to release a paper explaining what they planned to do.

This has been the fallacy against the whole argument.

Re: Apple Photos phones home on iOS 18 and macOS 15

#972
post #943

Earlier quoted context omitted.

Citation needed. As the latest news suggests the opposite.

> Citation needed. The best one I remember is this one: https://www.hackerfactor.com/blog/index.php?/archives/929-On... > As the latest news suggests the opposite. What news?

They don't work on the CSAM. They are a cloud provider who makes CSAM reports.

The only thing I see that is wrong in what they claimed is this:

> The problem is that you don't know which pictures will be sent to Apple.

Apple said in their paper that they don't send anything that is flagged. When the cloud sync occurs the files that are flagged get reviewed. All other files remain encrypted.

> What news?

https://www.nytimes.com/2024/12/08/technology/apple-child-se...

Re: Apple Photos phones home on iOS 18 and macOS 15

#973
post #822
post #816

Earlier quoted context omitted.

Your location data, encoded in photo you take with the phone's camera, being extracted by Apple is what this article is about. How many people use a web based camera or web based photo album app?

GeoIP in every Web request, unless a VPN is being used, alongside scrambling Mac addresses.

When it’s done default on, I default opt out until otherwise.

When it’s done default on, I default opt out.

GeoIP is definitely as you say of figuring out the location of an IP.

With photos, geocoding is embedding the gps location in each photo. Those locations are being sent scrubbed but still metadata to Apple.

The more I think of it I’m not sure if it’s useful to me to give that database to Apple for free. If it was presented as it’s being explained in device maybe I’d say cool, yeah.

Re: Apple Photos phones home on iOS 18 and macOS 15

#974
post #910

Earlier quoted context omitted.

> Not impressed. So Apple kneecaps Meta's cross-app advertising, something that literally makes them no direct revenue to implement, and protects users (it famously reduced Facebook cross-app analytics traffic to a significant degree), and you think this is business as usual? Then you should reconsider my comment at the top of this thread, because it is 100% speaking to this exact phenomenon.

I mean I'm unimpressed as far as user agency goes, not as far as privacy goes.

Ask App Not To Track was literally just the ability for the user to choose for themselves whether tracking is allowed. That’s a user agency improvement.

Re: Apple Photos phones home on iOS 18 and macOS 15

#975
post #951

Earlier quoted context omitted.

The scanning and matching is performed on your own device, against a copy of the databases which is encrypted to protect apple and their data providers against accountability for its content. The result of that match is itself encrypted, owing to the fact that the database is encrypted. On upload the query is decrypted and if there are above a threshold matches the decryption keys to all your content are revealed to…

> Your phone is your most trusted agent What makes you think your phone is the most trusted device? Do you know everything that is running on your phone and what it does? If a government wanted to enforce it then none of what Apple suggested mattered. In fact they wouldn't even need to release a paper explaining what they planned to do. This has been the fallacy against the whole argument.

My message was an informal argument. Apple has proposed and (now) applied the same spyware technology to their desktop/laptop operating system as well. But for most people in the US their phone absolute does occupy that most-trusted niche. For better or worse. The fact that this trust may currently be ill-advised is all the more reason people should demand change that makes it possible.

> If a government wanted to enforce it then none of what Apple suggested mattered.

Perhaps you live in a dicatorship. If so, I'm sorry. In the united states the power of the government is limited by the constitution. The kind of automated surveillance performed nominally 'consensually' via corporations would be unambiguously unlawful for the government to perform.

Re: Apple Photos phones home on iOS 18 and macOS 15

#976
post #950

Earlier quoted context omitted.

> The chance of a hash colliding is near 0%. The 'chance' is 100% -- collisions and even arbitrary second preimages have been constructed. > The hashes are for some of the worst content out there, its not trying to detect anything else. You don't know that because apple developed powerful new cryptographic techniques to protect themselves and their data providers from accountability.

> collisions and even arbitrary second preimages have been constructed. The chance of a mismatch is 8.63616855509e-78% If the hash was an atom then you would have to guess which atom in the observable universe it is. That is how likely a collision will happen.

I have posted numerous neuralhash collisions online already[1] and can generate more on demand. The "chance" is 100% because perceptual hashing schemes do not and cannot achieve cryptographic strength.

[1] https://academic.oup.com/cybersecurity/article/10/1/tyad020/... see the girl/dog image on page 12 for one of my examples in the academic literature.

Re: Apple Photos phones home on iOS 18 and macOS 15

#977

Here's a direct link to the paper that describes this as mentioned in the post, https://machinelearning.apple.com/research/homomorphic-encry... The homomorphic code is available in Swift https://www.swift.org/blog/announcing-swift-homomorphic-encr... I have concerns about how women would be affected by law enforcement who might use the location data to target abortions.

> I have concerns about how women would be affected by law enforcement who might use the location data to target abortions. What? How?

police using photos/location to figure out that a woman from Texas went to an address associated with an abortion clinic, and wow Texas has bounties, noooo potential for abuse there.

you've really been shilling apple and even obnoxiously giving multiple replies to the same comment, what's your problem?

Re: Apple Photos phones home on iOS 18 and macOS 15

#978

Is this just a smokescreen around slowly sneaking CSAM scanning back in after the pushback last time? The "default on" behavior is suspect. [1] https://www.wired.com/story/apple-photo-scanning-csam-commun...

Exactly like how Microsoft "backed off" Recall. Uuuuuntil they shoved it back in and made it undeleteable.

Re: Apple Photos phones home on iOS 18 and macOS 15

#979

As trivia, on mac os, the photoanalysisd service will run in the background and look through your photos, even if you never open Apple Photos. It can't be disabled unless you disable SIP (system integrity protection) which requires a complicated dance of reboots and warnings. It will reenable if you turn SIP back on. It seems Apple are very passionate about analysing your photos for some reason, regardless if you you…

Does it phone home? I don't care about scanning my files. I do care about details of my private data leaving my device.

Re: Apple Photos phones home on iOS 18 and macOS 15

#980
post #963

As trivia, on mac os, the photoanalysisd service will run in the background and look through your photos, even if you never open Apple Photos. It can't be disabled unless you disable SIP (system integrity protection) which requires a complicated dance of reboots and warnings. It will reenable if you turn SIP back on. It seems Apple are very passionate about analysing your photos for some reason, regardless if you you…

CSAM could already be part of some local service theoretically. Privacy ended with a requirement to have an account linked to the device (not just icloud). There is no account needed to use a Linux computer.

You don't need to use icloud to use a Mac.
Post reply on HN