Live data from Hacker News

Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

techcrunch.com

181–190 of 348 posts

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#181
"It could be argued that it [(Apple)] doesn’t gather enough, as Google Now, Google on Tap and other holistic offerings have the potential to give users much more lateral movement and ‘delight’ moments on Android specifically due to how much data Google gathers on its users."

Many years ago, thinking about the future, I imagined to have a device that would give me more or less what Google Now can give me. What I didn't imagine is that it would be a central server to collect all of that information (about everybody) and send me only a feed. This is very mainframe-like and that was the time we were starting to use Personal Computers (IBM/Apple/any) so you could forgive my naivety. Still I think that's possible to build a Google Now without a server owned by a single central organization and there are things like this https://news.ycombinator.com/item?id=9204954 to prove it (and also prove how hard it is).

So I'm left with not using Google Now and most Google services (no Gmail) because I feel that letting a company access to all those information is creepy and a transitive distrust for every company in similar markets. Recap: what I want is my data only in my hands and clients that query servers and collect the information I need. No clouds thanks, those are good only for encrypted backups. If I want sync and continuity, that should go through a server I control.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#182

Earlier quoted context omitted.

I added a little bit to my comment above. They are asking people for administrator passwords and put them into forms in their computer system. Rule number one of computing is that you shouldn't ever tell anybody your passwords. Asking for it is ridiculous. Considering how casual they acted, I can only assume that quite a lot of people actually told them. That makes me really worried.

That rule #1 doesn't quite apply in this situation. That you should never need to give out passwords is mostly a safeguard for social engineering and phishing scams for accounts stored on a server over the internet . Only a malicious third party would ever ask for these types of account passwords, because those with legitimate needs to access it (you and the service operator) already have it (hopefully just the hash…

I disagree. Not even someone who's there to help you should know your passwords. Consider that many people use the same password for a lot of accounts. On top of that, they already have your email address. By asking their customers for their passwords, they don't just ask them to hand over all the data on their computers, but they also make them vulnerable with regards to their internet accounts.

If I have a hardware problem with my display, I don't want them to read my hard drive. Apparently they still try to do so, which I think is a severe violation of privacy.

I'd have completely understood if they'd asked me to wipe my hard drive because of some data crawling Apple hardware test with an uplink to HQ. So they do have a choice "Can you make a backup and wipe your hard drive?" But asking me for my encryption password means they fail to understand why people encrypt and they don't care for the integrity of your computing.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#183

Earlier quoted context omitted.

Was this done through an Apple Store? The Apple Store staff have asked me for my password too. I've always asked if a Guest account was enough and it's never been a problem. I've always found the "Geniuses" to be fairly helpful and they always explain what they were going to do to my gear.

It works with a Guest account, if you don't encrypt your hard drive. If you use FileVault, they specifically need your administrator password. So what are they actually doing there?

I don't think you can boot the machine to login as Guest without a password if you have FileVault enabled.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#184

Earlier quoted context omitted.

Can one setup a pseudonymous Apple account, funded via Bitcoins?

That's just moving goal posts. Not sure why you even want an Apple account if you want to maximize privacy.

I'd want an Apple account so that I can buy stuff. Maybe I could get by with open-source apps, but that would be a pain. Even if I take Tim Cook's speech at face value, there's the catch that Apple knows who I am. If Apple really wanted to make a point about being privacy-friendly, they would allow account creation via Tor, and accept Bitcoins.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#185
post #173

Earlier quoted context omitted.

Why do they need the password to boot? Especially why do they need to write it down?

If you have full disk encryption enabled, the system won't boot if you don't give it the password. They write it down because you can't expect a tech to remember 16 digits of alphanumeric password for each client, as it looks bad when they have to phone up the client asking what their password is when they forget it. Writing down passwords is bad because other people can find them. If they're kept safe, there's no is…

How about asking to backup your data (which they ask anyway) and asking that the disk be wiped. There are no problems then.

Handing over your password means that there is practically no barrier for a technician to obtain all your data, all your private keys, etc. It only takes one guy with malicious intend to make your life miserable. Often, people also store their work related keys on their computers. So how about opening your company up for someone else?

The issue is that not all people are careful with that. And the code of conduct of Apple to just trust any technician 100% is completely wrong. Setting up a secure infrastructure means, you should assume that parts of it are already compromised. In that case, assume the technician is trying to obtain as much private data as possible, how can they still keep their customers safe?

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#186

Everyone seems to be Apple-bashing, and ignoring the fact that Apple really don't make money out of your private information. They make cash out of selling devices. So their interests are more aligned with yours. You may have noticed that Google don't make their money out of selling hardware. So they make it through other means. This is really inarguable, regardless of whether you think Apple are using that for marke…

> So their interests are more aligned with yours. Exactly how does a company that makes money through selling you products have its interests more aligned to yours?

Because money brings support and customer care too.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#187
post #156

Making a speech is easy, compared to actually doing the right thing. Just a month ago, I was asked by an employee of an Apple Certified Service Provider to decrypt my hard drive in order for Apple to make a "hardware test". There was an issue with my display, but they insisted that Apple's hardware test needed to have access to the data on my hard drive and send information back to Apple via the Internet. What about…

At an Apple Store, I've been asked this a few times. Then, I just say "I'd prefer not to" and have no problem.

Well, I was arguing with them for 10 Minutes. They tried to get my administrator password (because I use FileVault) and I refused. They wouldn't even look at the display issue (not software or data related) without the password.

In the end I just wiped the hard drive. They should've asked for that immediately.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#188
post #134
post #100

Earlier quoted context omitted.

>It's funny how Google advocates always "bash" apple for being "closed source" when this company ships the most popular Unix in the world... and all of their products, even the watch, are based on it. Android ships far more units than OS X/iOS and their derivatives do.

Android is not UNIX - it's GNU[0]/Linux-based, which is UNIX-like. iOS is also not UNIX, which is based on OS X but not UNIX Certified. OS X is UNIX. [0] G NU's N ot U nix

And while technically unix, the command line tools which ship are so horribly out of date as to be almost unusable.... Try using sftp on a mac sometime, if you enjoy the sensation of bleeding from your eyes.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#189
post #3

“I’m speaking to you from Silicon Valley, where some of the most prominent and successful companies have built their businesses by lulling their customers into complacency about their personal information,” “They’re gobbling up everything they can learn about you and trying to monetize it. We think that’s wrong. And it’s not the kind of company that Apple wants to be.” This is a great strategy to win the hearts and m…

As long as Apple heavily relies on closed source technology I'm fairly skeptical about their commitment. Additionally being a US based company all it takes is a friendly government agent showing up and I'm sure they'll hand over stuff without putting up too much of a fight I'd also guess that they do use cookies for their website and pay for web based advertising (thus being an enabler). Siri also makes me rather uncomfortable.

Don't get me wrong, better privacy is an important issue and if Apple sees it as a potential competitive advantage that's pretty good (as it'll force others to improve there as well). I'll be very interested in seeing how much they push this as a general strategy. [sadly I'd argue it's not really all that great of an idea because if push comes to shove most people will readily give up privacy for convenience (imo)]

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#190

Earlier quoted context omitted.

It works with a Guest account, if you don't encrypt your hard drive. If you use FileVault, they specifically need your administrator password. So what are they actually doing there?

I don't think you can boot the machine to login as Guest without a password if you have FileVault enabled.

I think you can still boot from the network. If that's correct, then this whole thing gets ever more mysterious for me.
Post reply on HN