Unmasking the Privacy Risks of Apple Intelligence
11–20 of 25 posts
Re: Unmasking the Privacy Risks of Apple Intelligence
#12The concerns here are valid but the fact the authors label this being about Apple Intelligence and Private Cloud Compute really devalues their credibility in general. Siri doesn’t have any of the new AI features, the prompts they’re using have been around for years, and private cloud compute has always been about Apple Intelligence generative features.
As a user, you can configure these settings in the UI. You can use the defaults command. They can be configured using a configuration profile/MDM. You could block the domains based on their associated feature, which are publicly documented by Apple. [1]
It's like complaining about Windows telemetry without bothering to configure the registry (or even open the settings menu).
Re: Unmasking the Privacy Risks of Apple Intelligence
#13The concerns here are valid but the fact the authors label this being about Apple Intelligence and Private Cloud Compute really devalues their credibility in general. Siri doesn’t have any of the new AI features, the prompts they’re using have been around for years, and private cloud compute has always been about Apple Intelligence generative features.
They are arguing in bad faith. They clearly know how to disable the relevant subset of these features. They don't do this upfront because they would have nothing to write about otherwise. As a user, you can configure these settings in the UI. You can use the defaults command. They can be configured using a configuration profile/MDM. You could block the domains based on their associated feature, which are publicly doc…
Re: Unmasking the Privacy Risks of Apple Intelligence
#14Apple already slurps everything you do with their "privacy proxy" services, so what more risk do you want? Apple defaults for forwarding all dns and web pages via their proxies, they just can't seem to figure out what to do with it.
Re: Unmasking the Privacy Risks of Apple Intelligence
#15Earlier quoted context omitted.
They are arguing in bad faith. They clearly know how to disable the relevant subset of these features. They don't do this upfront because they would have nothing to write about otherwise. As a user, you can configure these settings in the UI. You can use the defaults command. They can be configured using a configuration profile/MDM. You could block the domains based on their associated feature, which are publicly doc…
Smartphone OS manufactures like Apple and Google do not allow strong secure features to black domain or IP addresses. There are attempts at cheep hacks to use VN or accessibility work a rounds but they can be overwritten by the OS and they prevent use a firewall and VPN at the same time.
No, you sometimes can't use two apps on iOS that attempt to configure DNS and a "VPN" for local filtering purposes at the same time (the latter is often a glorified hosts list).
You absolutely can use encrypted DNS and/or a VPN (or Private Relay). None of these have bearing on using an application firewall or pf on macOS.
Re: Unmasking the Privacy Risks of Apple Intelligence
#16Apple already slurps everything you do with their "privacy proxy" services, so what more risk do you want? Apple defaults for forwarding all dns and web pages via their proxies, they just can't seem to figure out what to do with it.
> they just can't seem to figure out what to do with it. That's the funny thing about Siri. It has since Day 1 insisted on being exclusively online-only, processing on the server - even for commands that the pre-Siri Voice Control could do fully locally on an iPhone 3Gs such as "Call Steve" or "Turn Wi-Fi on" That decision always surprised me, and it's surprising that Siri's never improved given that unlike Apple Int…
I just tested this with Wi-Fi and cellular data disabled. Calling someone works perfectly and asking to turn Wi-Fi on presents the relevant toggle.
Re: Unmasking the Privacy Risks of Apple Intelligence
#17For an iPhone local AI, I wrote an app for myself (although I think there are maybe 10 other people who use it) that chats with Apple's local model (that is fairly good) and switches to a Secure Enclave model on their servers and from the documentation it looks like using the cloud model is private and secure.
Even better now, I signed up for ProtonMail's optional Luma LLM Chat system with integrated private web search tools. It is surprisingly good, and I trust Proton that it is private.
Almost the only thing I frequently use commercial LLMs for now is a few times a week using gemini-cli for coding, and NotebookLM a few times a month, plus occasional Gemini use, but I pay for Luma (powered by Mistral models) so I routinely use it for AI search use cases.
Just because technology is incredibly cool, this doesn't mean that we have to use it if real productivity gains are slim or non-existent.
Re: Unmasking the Privacy Risks of Apple Intelligence
#18The concerns here are valid but the fact the authors label this being about Apple Intelligence and Private Cloud Compute really devalues their credibility in general. Siri doesn’t have any of the new AI features, the prompts they’re using have been around for years, and private cloud compute has always been about Apple Intelligence generative features.
The only privacy screen on macOS and iOS is during oob or after OS updates, and it does not make a distinction. As the OP post highlights, there is no way to avoid said telemetry from being sent or configure it in Settings. So all this is not only shady but quite illegal.
Re: Unmasking the Privacy Risks of Apple Intelligence
#19Frida looks like such a cool tool I wish I had some time to play with it
Re: Unmasking the Privacy Risks of Apple Intelligence
#20I'm somewhat disappointed that the authors did not realize that apple-relay.cloudflare.com is not PCC, but is publicly known to be part of iCloud Private Relay. That made me immediately think that there were other parts of the article which were not properly investigated, and likely a fair bit of sensationalization.