Live data from Hacker News

Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

techcrunch.com

151–160 of 348 posts

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#151
post #138
post #112

Earlier quoted context omitted.

You can skip it

It's disingenuous to ask for it in the first place when one touts itself as a privacy advocate. Vast majority of users will do what they are told to do by default and Apple knows and exploits that.

They're not exploiting it. They're asking for it to register your products, to you.

There's a big skip button.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#152

Making a speech is easy, compared to actually doing the right thing. Just a month ago, I was asked by an employee of an Apple Certified Service Provider to decrypt my hard drive in order for Apple to make a "hardware test". There was an issue with my display, but they insisted that Apple's hardware test needed to have access to the data on my hard drive and send information back to Apple via the Internet. What about…

That's not even a little insane. They needed access to something, and asked you for it to complete their work. It would have been insane if the guy had just hit a button, and your data was decrypted. As it stood, you were always in complete control of your data.

I added a little bit to my comment above. They are asking people for administrator passwords and put them into forms in their computer system. Rule number one of computing is that you shouldn't ever tell anybody your passwords. Asking for it is ridiculous. Considering how casual they acted, I can only assume that quite a lot of people actually told them. That makes me really worried.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#153

Making a speech is easy, compared to actually doing the right thing. Just a month ago, I was asked by an employee of an Apple Certified Service Provider to decrypt my hard drive in order for Apple to make a "hardware test". There was an issue with my display, but they insisted that Apple's hardware test needed to have access to the data on my hard drive and send information back to Apple via the Internet. What about…

Yes, this speech is more marketing than anything. At the end of the day, just like with google, apple is sending your data to the cloud. Location data, they even have their own street view now...

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#154

This is marketing folks. Apple's behavior towards Google changed dramatically after Android starting getting traction, and this sudden pivot towards pro-privacy is an Apple's attempt to damage the reputation of it's biggest competitor. Apple hasn't been consistently speaking with the same voice on privacy, both before or after Snowden, and Tim Cook's comments IMHO look cynically designed. Apple collects plenty of per…

Note: I think you should have started your post stating that you work for Google. It's relevant information in this context.

3) iCloud Photo Library is not encrypted client side in a way that prevents Apple from decrypting it on the server, so like Google Photos, Apple will have your photos.

Having the data is only one part, the other part is what you can do with the data. Google's rights are extremely broad, although they conveniently did not put most stuff in the privacy policy:

When you upload, submit, store, send or receive content to or through our Services, you give Google (and those we work with) a worldwide license to use, host, store, reproduce, modify, create derivative works (such as those resulting from translations, adaptations or other changes we make so that your content works better with our Services), communicate, publish, publicly perform, publicly display and distribute such content. The rights you grant in this license are for the limited purpose of operating, promoting, and improving our Services, and to develop new ones. This license continues even if you stop using our Services (for example, for a business listing you have added to Google Maps).

Source: https://www.google.com/intl/en/policies/terms/

tl;dr: Google can keep your data, even if you stop using their services. Google can use your data for promoting their service and in new services.

I don't think most people realize that there is no way back: once you store your data (e.g. photos) in a Google service, it's theirs to keep (how that works with Dashboard, I don't know).

Please show me comparable terms for Apple Photos (Apple can keep your stuff forever and use it to promote services). If they are not there, there is clearly a difference between storing photos in iCloud or Google Photos.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#155

Earlier quoted context omitted.

Re 1 - I agree that is by a mile the most problematic part of Google's business. It's not a problem that Google knows what's in the emails I store on their servers -- of course they do, I put them there -- but it is problematic if they know I go to www.controversialsite.com when they should have no reason to. But the implication there is that Google's most privacy-invasive product, by a mile, is Google Analytics, whi…

Analytics uses first-party cookies for the site's domain, not your google cookie(s). And you'll have to take them at their word, but they don't combine it with some IP address trickiness or whatever (though that would be a pretty bad idea if you want decent profiles anyway): https://support.google.com/analytics/answer/6004245?hl=en

That is just a Terms Of Service change away. Such legal changes aren't even unlikely: Google already changed their Terms of Service in the past to allow them to combine information from separate sites and services, which they didn't explicitly claim to do before[1].

The 'reassurances' provided in Google's Terms of Service don't mean jack shit when they have the power to change the terms in the future to whatever they want.

[1] http://www.cnet.com/news/google-wants-ability-to-combine-you...!

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#156

Making a speech is easy, compared to actually doing the right thing. Just a month ago, I was asked by an employee of an Apple Certified Service Provider to decrypt my hard drive in order for Apple to make a "hardware test". There was an issue with my display, but they insisted that Apple's hardware test needed to have access to the data on my hard drive and send information back to Apple via the Internet. What about…

At an Apple Store, I've been asked this a few times. Then, I just say "I'd prefer not to" and have no problem.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#157

Earlier quoted context omitted.

That's not even a little insane. They needed access to something, and asked you for it to complete their work. It would have been insane if the guy had just hit a button, and your data was decrypted. As it stood, you were always in complete control of your data.

I added a little bit to my comment above. They are asking people for administrator passwords and put them into forms in their computer system. Rule number one of computing is that you shouldn't ever tell anybody your passwords. Asking for it is ridiculous. Considering how casual they acted, I can only assume that quite a lot of people actually told them. That makes me really worried.

If you have a software problem, how are they supposed to check that they fixed it without being able to boot the computer?

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#158
> We believe the customer should be in control of their own information. You might like these so-called free services, but we don’t think they’re worth having your email, your search history and now even your family photos data mined and sold off for god knows what advertising purpose.

That's very sanctimonious of the CEO of the richest corporation in the world. Speeches are great but what would be even better is for them to deign to actually sell something to the poor, the people who cannot afford to buy into Apple's privacy respecting products.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#159
post #91

> For years we’ve offered encryption services like iMessage and FaceTime because we believe the contents of your text messages and your video chats is none of our business. Sounds great, but take note that it's none of their business today and we know they can be compelled to spy on their users by NSLs. They control the key infrastructure with their closed-source software that runs on their closed-source hardware. If…

TBH, the only app that does this correctly is Threema, with a clear indicator that you have verified the contact. Not even TextSecure does it correctly, and TS is supposed to be the gold standard (you can verify fingerprints, though)

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#160

Earlier quoted context omitted.

That's not even a little insane. They needed access to something, and asked you for it to complete their work. It would have been insane if the guy had just hit a button, and your data was decrypted. As it stood, you were always in complete control of your data.

I added a little bit to my comment above. They are asking people for administrator passwords and put them into forms in their computer system. Rule number one of computing is that you shouldn't ever tell anybody your passwords. Asking for it is ridiculous. Considering how casual they acted, I can only assume that quite a lot of people actually told them. That makes me really worried.

Was this done through an Apple Store? The Apple Store staff have asked me for my password too. I've always asked if a Guest account was enough and it's never been a problem.

I've always found the "Geniuses" to be fairly helpful and they always explain what they were going to do to my gear.

Post reply on HN