Live data from Hacker News

Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

techcrunch.com

161–170 of 348 posts

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#161
post #157

Earlier quoted context omitted.

I added a little bit to my comment above. They are asking people for administrator passwords and put them into forms in their computer system. Rule number one of computing is that you shouldn't ever tell anybody your passwords. Asking for it is ridiculous. Considering how casual they acted, I can only assume that quite a lot of people actually told them. That makes me really worried.

If you have a software problem, how are they supposed to check that they fixed it without being able to boot the computer?

Why do they need the password to boot? Especially why do they need to write it down?

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#162

Everyone seems to be Apple-bashing, and ignoring the fact that Apple really don't make money out of your private information. They make cash out of selling devices. So their interests are more aligned with yours. You may have noticed that Google don't make their money out of selling hardware. So they make it through other means. This is really inarguable, regardless of whether you think Apple are using that for marke…

I think the strong reaction is because the distinction between Apple and Google is much fuzzier and weaker than Tim Cook (and some commenters here) are trying to make it sound.

Apple makes money from device sales. Apple can make more money by using private information (to improve their cloud services, selling the search default to Google, for iAds and so on) - as long as they don't do something with it that makes people reconsider their next device purchase.

Google makes money from advertising. Google can make more money using private information with their advertising - as long as they don't do something with it that makes people reconsider using Google services.

There's a difference here but it's a difference of degree, not kind. At bottom, Apple and Google are both companies with incentives for collecting and using private information and risks that encourage them not to misuse it. You can try to squeeze a moral distinction out of the details, but it is spin, not substance.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#163

Earlier quoted context omitted.

That's not even a little insane. They needed access to something, and asked you for it to complete their work. It would have been insane if the guy had just hit a button, and your data was decrypted. As it stood, you were always in complete control of your data.

I added a little bit to my comment above. They are asking people for administrator passwords and put them into forms in their computer system. Rule number one of computing is that you shouldn't ever tell anybody your passwords. Asking for it is ridiculous. Considering how casual they acted, I can only assume that quite a lot of people actually told them. That makes me really worried.

But they did not use any backdoor. Etchalon is right - if they had to access file system how should they do that if it was encrypted? And you were in control of the situation - next time change the password to temporary one before handing it over. And if you are really paranoid decrypt and encrypt the drive afterwards to have new encryption keys ;-)

EDIT: spelling.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#164
post #131

Earlier quoted context omitted.

As magicalist points out in his response, you are taking Schmidt's quote completely out of context. Don't feel bad, you're not the only one. Schmidt (and Google) are extremely pro-privacy and against sharing information with the government. Google must have like ten lawsuits going on at all times on the entire planet trying to fight intrusive data request from governments. They spend hundreds of millions of dollars e…

Android is becoming less and less open source by the minute. Google used the opensourcedness as a trojan horse to get the OEMs, but now it's pulling it away.

Ignore that: Google had to rein shitty OEMs in because they were trashing the brand as bad as OEMs screwed Windows. Bad OOBE, inconsistent, buggy, etc. Using GApps as a carrot/stick is something they should have had from the beginning.

There may be other reasons, but the QA aspect is enough that Google would have to hit the OEMs, even if Google wanted to promote open source.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#165

Earlier quoted context omitted.

I added a little bit to my comment above. They are asking people for administrator passwords and put them into forms in their computer system. Rule number one of computing is that you shouldn't ever tell anybody your passwords. Asking for it is ridiculous. Considering how casual they acted, I can only assume that quite a lot of people actually told them. That makes me really worried.

Was this done through an Apple Store? The Apple Store staff have asked me for my password too. I've always asked if a Guest account was enough and it's never been a problem. I've always found the "Geniuses" to be fairly helpful and they always explain what they were going to do to my gear.

It works with a Guest account, if you don't encrypt your hard drive. If you use FileVault, they specifically need your administrator password. So what are they actually doing there?

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#166
post #129

I'm repeating myself (from other threads) but Mozilla should use this sales pitch. Very few users can evaluate business' privacy practices; they only can trust the business. Due to their non-profit, public good status, their mission, and their track record, nobody could compete with Mozilla on trust. EDIT: I'll add: Certainly the other two leading browser makers couldn't compete, and in mobile platforms only Apple, i…

Does Mozilla's track record include their suggested advertising tiles on your newtab page, based off your browsing history? Or their defaulting to Yahoo to send your searches because they were the highest bidder? Now yes, they say the tiles are based on your local history and not transmitted anywhere; so it's not as bad (I don't care if other people don't see it, I don't want my data mined even locally for the purpos…

Mozilla's a non-profit - the money it collects goes into supporting additional open-source products. At the moment, it does this on income of $300 million per year (mostly from their search provider). Of this money, $200 million goes on software development, $10 million goes on running their services (downloads, sync etc), and $70 million goes on administration, general costs (buildings etc) and marketing.

So yes, if you're hoping to crowdfund you a browser, then if you can't persuade people to donate millions and millions and millions then you're not going to be successful. A modern browser engine is millions of lines of highly optimised code long (check out Servo), and that corresponds to hundreds of millions of dollars of investment.

At the moment, you're essentially trying to say that being open-source and being actively developed are mutually exclusive, which seems odd (if Mozilla threw away Yahoo, they'd be bankrupt).

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#167

Earlier quoted context omitted.

That's not even a little insane. They needed access to something, and asked you for it to complete their work. It would have been insane if the guy had just hit a button, and your data was decrypted. As it stood, you were always in complete control of your data.

I added a little bit to my comment above. They are asking people for administrator passwords and put them into forms in their computer system. Rule number one of computing is that you shouldn't ever tell anybody your passwords. Asking for it is ridiculous. Considering how casual they acted, I can only assume that quite a lot of people actually told them. That makes me really worried.

That rule #1 doesn't quite apply in this situation.

That you should never need to give out passwords is mostly a safeguard for social engineering and phishing scams for accounts stored on a server over the internet. Only a malicious third party would ever ask for these types of account passwords, because those with legitimate needs to access it (you and the service operator) already have it (hopefully just the hash in the case of the latter).

The password you're referring to here is an encryption key for a local hard drive that nobody else has access to. If they do in fact need access to the encrypted OS partitions stored on your hard drive in order to diagnose your problem, then they have no choice but to ask you for your encryption key. That's cryptography working as intended.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#168

Earlier quoted context omitted.

Re 1 - I agree that is by a mile the most problematic part of Google's business. It's not a problem that Google knows what's in the emails I store on their servers -- of course they do, I put them there -- but it is problematic if they know I go to www.controversialsite.com when they should have no reason to. But the implication there is that Google's most privacy-invasive product, by a mile, is Google Analytics, whi…

Analytics uses first-party cookies for the site's domain, not your google cookie(s). And you'll have to take them at their word, but they don't combine it with some IP address trickiness or whatever (though that would be a pretty bad idea if you want decent profiles anyway): https://support.google.com/analytics/answer/6004245?hl=en

There's also https://tools.google.com/dlpage/gaoptout if you don't want Analytics tracking you.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#169

Earlier quoted context omitted.

I think, sadly, that's not true. The government can force them to change their business, and begin recording personal information that passes through their hands. Its very strange.

There is a lot of tracking Google does that couldn't just be instantly turned on at the request of a government if Google wasn't already doing it. For example Google Analytics: if that product didn't exist the government couldn't just ask Google to install tracking scripts on half the websites in the world without anybody noticing. You could argue that the government could force Google to create and market Google Ana…

By that argument CDNs shouldn't exist, since the government could theoretically compel them to inject code into the sites they serve.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#170
Apple collects tons of user data, and I'm sure they use some of it to provide machine-learning backed services, and I'm sure they'll come out with much nicer products to compete with Google in the future, also enhanced by machine learning techniques.

The difference that Tim Cook wants you to believe in is that Apple doesn't directly make money from your data, they just use it to improve their product; alternatively, Google makes money from your data by providing advertises with guided access to your eyeball.

But the danger isn't in the fact that Google lulls you into complacency with free services. The danger isn't in the fact that Google sells guided access to your attention. The danger is just in the collection of data, and the fact that one day the government or somebody could find a way.

There's only one way to be safe. And that's to collect only minimal amounts of data for minimal apps. That means gimped Siri. No Apple competitor to Google Photos. And I don't think Apple will do that. I think they'll continue to amass all the data they use to improve customer experience. The fact that Apple makes money differently off the data doesn't change the fact that it's collection that's inherently dangerous.

Post reply on HN