Live data from Hacker News

Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

techcrunch.com

191–200 of 348 posts

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#191
If what Tim Cook said could be easily discounted as puffery, it would be largely ignored by the Google fanboys. But the fact that you don't even have to believe what Tim Cook says or even trust him, because Apple's business model doesn't benefit from the perverse incentive that Google's does, is driving them crazy. And no iAd doesn't count, that's a service for third party developers to monetize their own apps. There are no ads in Apple's first party apps. It's also been criticized by advertisers because of Apple's protection of customer privacy. http://adage.com/article/digital/amazon-apple-catch-a-break-...

It's an interesting twist for HN, which is normally ready to take strong pro-privacy positions in the wake of the Snowden leaks under the premise of potential abuse by governments.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#192

Earlier quoted context omitted.

Yes; even if that's not true for Apple stores, plenty of resellers.

Can one setup a pseudonymous Apple account, funded via Bitcoins?

Sure. Make up a name and address and load it with gift cards bought with cash. Done.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#193
post #180

Apple collects tons of user data, and I'm sure they use some of it to provide machine-learning backed services, and I'm sure they'll come out with much nicer products to compete with Google in the future, also enhanced by machine learning techniques. The difference that Tim Cook wants you to believe in is that Apple doesn't directly make money from your data, they just use it to improve their product; alternatively,…

Actually, there's another alternative. Provide all these "insights" with offline, data-on-computers-you-own systems. The intelligence can be carried with you, without internet. This is traditional computing. Apple or Microsoft, or even any other competitor could provide that. They just need to sell you this software (oh and also build it first).

Not possible. The insights come from the combination of everyone's data, not the analysis of any individual in isolation.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#194
post #173

Earlier quoted context omitted.

Why do they need the password to boot? Especially why do they need to write it down?

If you have full disk encryption enabled, the system won't boot if you don't give it the password. They write it down because you can't expect a tech to remember 16 digits of alphanumeric password for each client, as it looks bad when they have to phone up the client asking what their password is when they forget it. Writing down passwords is bad because other people can find them. If they're kept safe, there's no is…

They can't boot it off a flash drive? I can understand asking for a password to do that, but the system should not be designed so that they need access to the current OS install to diagnose hardware problems.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#195
post #174

Earlier quoted context omitted.

Because that company makes its from me, directly. It has to cater its products to ME, and not to advertisers, or enterprises, or anyone else.

Comcast also makes most of its money from users directly. Yet, somehow, the incentives are not aligned. Why is that? How might that apply to Apple?

Comcast has considerable monopoly power: in certain areas there are no good alternatives or your apartment complex might have the cables from Comcast installed but not others. Apple has less monopoly power because of Android competition.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#196
post #180

Earlier quoted context omitted.

Actually, there's another alternative. Provide all these "insights" with offline, data-on-computers-you-own systems. The intelligence can be carried with you, without internet. This is traditional computing. Apple or Microsoft, or even any other competitor could provide that. They just need to sell you this software (oh and also build it first).

Not possible. The insights come from the combination of everyone's data, not the analysis of any individual in isolation.

I am sure there is still value in one users data that could be used that way.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#197

At the moment, this thread seems more like a YouTube comment section than a HN one. Though it's not exactly surprising given that Tim Cook's speech is obviously aimed at Google/FB. Let's start with the facts. Apple makes its major money in hardware. Google makes its major money in search. Obviously, iOS has to be able to compete with Android in order for iPhones to sell well. Google offers services like Google Now an…

The problem is that Duck Duck go doesn't provide as good results, because it lacks the personalized data. Google knows that when I search for Django I want the web framework. Duck duck go gives me that as well as many links to the film. I think option 1 is more likely for Apple.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#198
post #180

Apple collects tons of user data, and I'm sure they use some of it to provide machine-learning backed services, and I'm sure they'll come out with much nicer products to compete with Google in the future, also enhanced by machine learning techniques. The difference that Tim Cook wants you to believe in is that Apple doesn't directly make money from your data, they just use it to improve their product; alternatively,…

Actually, there's another alternative. Provide all these "insights" with offline, data-on-computers-you-own systems. The intelligence can be carried with you, without internet. This is traditional computing. Apple or Microsoft, or even any other competitor could provide that. They just need to sell you this software (oh and also build it first).

On-premise vs. Cloud?

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#199
post #156

Earlier quoted context omitted.

At an Apple Store, I've been asked this a few times. Then, I just say "I'd prefer not to" and have no problem.

Well, I was arguing with them for 10 Minutes. They tried to get my administrator password (because I use FileVault) and I refused. They wouldn't even look at the display issue (not software or data related) without the password. In the end I just wiped the hard drive. They should've asked for that immediately.

>"In the end I just wiped the hard drive. They should've asked for that immediately."

They should have. That said, I'm confident that the significant majority react extremely negatively towards that request, so they have learned to ask for passwords first. Best practice? Definately not.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#200
post #173

Earlier quoted context omitted.

If you have full disk encryption enabled, the system won't boot if you don't give it the password. They write it down because you can't expect a tech to remember 16 digits of alphanumeric password for each client, as it looks bad when they have to phone up the client asking what their password is when they forget it. Writing down passwords is bad because other people can find them. If they're kept safe, there's no is…

How about asking to backup your data (which they ask anyway) and asking that the disk be wiped. There are no problems then. Handing over your password means that there is practically no barrier for a technician to obtain all your data, all your private keys, etc. It only takes one guy with malicious intend to make your life miserable. Often, people also store their work related keys on their computers. So how about o…

If you do work related stuff on your computer, your work should be taking care of the computer. This is why most people get assigned a computer by their places of employment, and are not expected to use their own. The place of work has their own tech team who deal with these types of issues. It's a really bad idea to do work stuff on a home computer because it makes your device much more vulnerable to being snooped on and controlled (for example, your place of employment may gain the ability to remotely wipe your device), and generally if you are in such a pickle then you should just not give them your password.

Again, it could be a software issue. If I complain that my WiFi isn't working, and you take it in to have a look, and your diagnostics say that WiFi works, then without the password you can't do anything at all. If my problem is that Safari runs really slowly and you can't log in, you're not going to be able to fix that.

If your only fix is then to reinstall the operating system and hope for the best, then you've done a terrible job.

In any case, the tech has physical access to your computer, and in the presence of that you should not assume any security from your disk encryption. FDE is good for one loss of control; after that you should assume compromise.

Post reply on HN