Apple decided not to roll out Siri in EU after denied request for exemption
301–310 of 735 posts
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#302Earlier quoted context omitted.
Throwing infinite money at engineering problems doesn't move deadlines arbitrarily. But Apple's position here is actually really wild: Apple claims to protect user privacy all the time. But they can't offer a product in a major jurisdiction that has actually meaningful privacy laws? Didn't they consider that while designing the product? This is quite the contradiction.
> Apple claims to protect user privacy all the time. But they can't offer a product in a major jurisdiction that has actually meaningful privacy laws? Didn't they consider that while designing the product? Complying with complex privacy laws is surprisingly orthogonal to making a product with good privacy. In another regulatory area (not privacy, but something more historically regulated) we ran into strange situatio…
Maybe it's more because the privacy is largely marketing and helps with continuously shutting out competitors under the guise of privacy?
If they really cared about privacy, they would end-to-end encrypt iCloud backups [1] by default and not just when ADP is enabled, which only a small subset of users do. In fact, many technical people I know don't even realize that iCloud backups are not end-to-end encrypted. At any rate, this large hole opens a lot of data (including iMesssage) open to Apple, law enforcement, etc.
https://support.apple.com/en-us/102651
[1] And iCloud Drive, and photos, and notes, and voice memos, and wallet passes, and contacts, and reminders, and...
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#303Earlier quoted context omitted.
I think there's a reasonable question of whether the Siri stuff is even a feature that customers want. Additionally, money can not solve all problems, 9 people can't make a baby in a month, and if these sorts of regulations are serious at all like they are for medical regulation then you really do need to do the work of assessing risks, etc., and there's a chain of waterfall development to all that.
[flagged]
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#304They basically make it an existential risk to build your success on anything nicely and neatly tightly vertically integrated. Everything must be dragged down to mediocrity by the unavoidable slippage between mandated abstraction layers and avoidance of features that can’t be easily or safely generalized.
It’s conflicting. Is Apple abusing its role in some cases, such as the App Store, and in need of some reigning in? Sure, but some of this goes too far and essentially requires them to strip their products of a portion of their appeal.
Even more frustrating is that nobody seems to be willing to discuss the issue with any level of nuance. It’s nearly all binary EU good/Apple bad or the reverse.
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#305Apple said "hey, can we not comply with the law", the EU said no, so it didn't launch. Seems pretty straightforward to me. I can see why Apple might want to request an 18 month exemption, there's clearly extra work required to comply with EU regulations. But on the other hand it also feels like a straightforward play for consumer sympathy: let them get used to using it every day for 18 months, then pressure the EU to…
Google eng mgr here. I've worked on a few projects related to compliance with various government policies. This isn't "assign a two-pizza team to it, will be done in a quarter"; these types of compliance efforts can mean completely redoing multiple core systems to handle privacy, wipeout, audit, reporting, per-location policies, etc etc. These efforts can involve hundreds to thousands of people for multiple years. Su…
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#306Earlier quoted context omitted.
I mean, Apple's PCC audits require them to individually vet each auditor before they're allowed to see the PCC nodes. If Apple extended that philosophy to other vendors then yeah, it would be deliberately unfair and anticompetitive.
It sounds like they are whitelisting the hashes of all the Google software and OSes and stuff to ensure nothing is changed out from under them without them knowing. Even if you could make all the other possible vendors run private cloud compute style stuff that would be a lot to manage. And I can’t imagine the EU would like, and as a user I would certainly hate, the “OK you can use Grok but you lose all privacy too b…
Most sysadmins know that hash matching only mitigates a small subset of rare upstream attacks. Apple could still be MITMing the whole thing (SSL added and removed here :)) and no auditor would get the chance to check. The offered audit is so weak that I would not trust any FAANG business to administrate it.
Apple is once again demanding arbitrary centralization to give them an undeserved veto power. None of this is for security.
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#307Apple said "hey, can we not comply with the law", the EU said no, so it didn't launch. Seems pretty straightforward to me. I can see why Apple might want to request an 18 month exemption, there's clearly extra work required to comply with EU regulations. But on the other hand it also feels like a straightforward play for consumer sympathy: let them get used to using it every day for 18 months, then pressure the EU to…
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#308Re: Apple decided not to roll out Siri in EU after denied request for exemption
#309Apple said "hey, can we not comply with the law", the EU said no, so it didn't launch. Seems pretty straightforward to me. I can see why Apple might want to request an 18 month exemption, there's clearly extra work required to comply with EU regulations. But on the other hand it also feels like a straightforward play for consumer sympathy: let them get used to using it every day for 18 months, then pressure the EU to…
Google eng mgr here. I've worked on a few projects related to compliance with various government policies. This isn't "assign a two-pizza team to it, will be done in a quarter"; these types of compliance efforts can mean completely redoing multiple core systems to handle privacy, wipeout, audit, reporting, per-location policies, etc etc. These efforts can involve hundreds to thousands of people for multiple years. Su…
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#310Earlier quoted context omitted.
Why does systems are not designed take into account that compliance work?
I assume you're asking this in good faith, so I'll answer in good faith. Laws vary from country to country, state to state, and they vary tremendously. Laws are also changing all the time. There's literally no way to predict what rules will be in place at any given time. Also, adding code to meet some government regulation takes time and effort that (form the company's perspective) could be better spent building a pr…
It would be good for US companies to know that EU laws are not "guidelines", just as US enforces their laws on companies from outside.