Live data from Hacker News

Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

techcrunch.com

211–220 of 348 posts

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#211

This is marketing folks. Apple's behavior towards Google changed dramatically after Android starting getting traction, and this sudden pivot towards pro-privacy is an Apple's attempt to damage the reputation of it's biggest competitor. Apple hasn't been consistently speaking with the same voice on privacy, both before or after Snowden, and Tim Cook's comments IMHO look cynically designed. Apple collects plenty of per…

Note: I think you should have started your post stating that you work for Google. It's relevant information in this context. 3) iCloud Photo Library is not encrypted client side in a way that prevents Apple from decrypting it on the server, so like Google Photos, Apple will have your photos. Having the data is only one part, the other part is what you can do with the data. Google's rights are extremely broad, althoug…

We also use personal information to help us create, develop, operate, deliver, and improve our products, services, content and advertising, and for loss prevention and anti-fraud purposes.

We may also use personal information for internal purposes such as auditing, data analysis, and research to improve Apple’s products, services, and customer communications.

https://www.apple.com/legal/privacy/en-ww/

No time limit specified = No time limit

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#212
post #200

Earlier quoted context omitted.

How about asking to backup your data (which they ask anyway) and asking that the disk be wiped. There are no problems then. Handing over your password means that there is practically no barrier for a technician to obtain all your data, all your private keys, etc. It only takes one guy with malicious intend to make your life miserable. Often, people also store their work related keys on their computers. So how about o…

If you do work related stuff on your computer, your work should be taking care of the computer. This is why most people get assigned a computer by their places of employment, and are not expected to use their own. The place of work has their own tech team who deal with these types of issues. It's a really bad idea to do work stuff on a home computer because it makes your device much more vulnerable to being snooped o…

>it could be a software issue

They can still do some tests. It's not like wiping the hard drive helps solve software issues.

>FDE is good for one loss of control; after that you should assume compromise.

If the threat model is a malicious actor, yes. If the threat model is accidental plaintext password leaking, there is a huge difference between the scenarios. I could construct a similar argument against password hashing on servers...

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#213

Making a speech is easy, compared to actually doing the right thing. Just a month ago, I was asked by an employee of an Apple Certified Service Provider to decrypt my hard drive in order for Apple to make a "hardware test". There was an issue with my display, but they insisted that Apple's hardware test needed to have access to the data on my hard drive and send information back to Apple via the Internet. What about…

My out-of-warranty MBP needed a new battery because the original battery had started to swell up. I called my local Apple Authorized Service Provider (the only one within 250km) what the procedure was if I wanted to purchase a new battery.

They said I would need to drop off the computer with them; they would order a new battery and I could have it back in a week or so. I said I couldn’t do without the computer and I couldn’t let them access the hard drive (not encrypted) as I have proprietary data on it.

They said I could make the full payment and bring it in when the replacement battery arrives, leave it with them and collect it in a few hours. They insisted they could not replace it with me present and the minimum time I would need to leave it was 3 hours. This is easily enough time to clone the hard disk, which I did point out, politely, but they said this was the most they could do for me.

I ended up buying a third-party battery and changing it myself. It took less than 10 minutes. If it doesn’t last long, I’ll just have to buy a new Mac.

So yes, apparently there are no standards in place for data security as far as authorized service centres are concerned.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#214
post #208

Earlier quoted context omitted.

Not possible. The insights come from the combination of everyone's data, not the analysis of any individual in isolation.

I'd like to disagree. When Google Now reads my email to track my delivery package number or flight number, it's my data. When it understands that I like sport team X, it's my data. When it knows where I work and live to ask Google servers the weather or how long it would take to go somewhere, still my data used as the request base. When Google(+) Photos auto-tags my photos, still my data, although I'd admit the IA tr…

Right, It's your data because it's the things you care about, but knowing you isn't what google cares about, they want to know where you intersect with everyone else.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#215
post #211

Earlier quoted context omitted.

Note: I think you should have started your post stating that you work for Google. It's relevant information in this context. 3) iCloud Photo Library is not encrypted client side in a way that prevents Apple from decrypting it on the server, so like Google Photos, Apple will have your photos. Having the data is only one part, the other part is what you can do with the data. Google's rights are extremely broad, althoug…

We also use personal information to help us create, develop, operate, deliver, and improve our products, services, content and advertising, and for loss prevention and anti-fraud purposes. We may also use personal information for internal purposes such as auditing, data analysis, and research to improve Apple’s products, services, and customer communications. https://www.apple.com/legal/privacy/en-ww/ No time limit s…

You have to read the iCloud terms:

Upon termination of your Account you will lose all access to the Service and any portions thereof, including, but not limited to, your Account, Apple ID, email account, and Content. In addition, after a period of time, Apple will delete information and data stored in or as a part of your account(s).

https://www.apple.com/legal/internet-services/icloud/en/term...

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#216

Earlier quoted context omitted.

Can one setup a pseudonymous Apple account, funded via Bitcoins?

Sure. Make up a name and address and load it with gift cards bought with cash. Done.

Buying gift cards for cash is too insecure.

But I do see https://giftoff.com/gift-cards/apple-store for buying Apple Store gift cards with Bitcoins.

I'll give it a go.

Edit: It seems legitimate: https://bitcointalk.org/index.php?topic=970780.0

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#217

Apple collects tons of user data, and I'm sure they use some of it to provide machine-learning backed services, and I'm sure they'll come out with much nicer products to compete with Google in the future, also enhanced by machine learning techniques. The difference that Tim Cook wants you to believe in is that Apple doesn't directly make money from your data, they just use it to improve their product; alternatively,…

This is just a another way of saying "business good, government bad".

The fact that Google abuses the data and Apple doesn't is already a major difference. Just because government can use its monopoly on violence and imprisonment to go one step beyond doesn't make what businesses do harmless.

Yes, the collection is already inherently dangerous, and what Apple does is certainly not harmless. And yes, they will use that data to their advantage.

But the unscrupulous abuse of that data, the blatant disregard for privacy, a business model that depends on abuse of that data, and the obvious hunger for social and economic power by Google and co is not a minor difference.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#218

Apple collects tons of user data, and I'm sure they use some of it to provide machine-learning backed services, and I'm sure they'll come out with much nicer products to compete with Google in the future, also enhanced by machine learning techniques. The difference that Tim Cook wants you to believe in is that Apple doesn't directly make money from your data, they just use it to improve their product; alternatively,…

> "There's only one way to be safe. And that's to collect only minimal amounts of data for minimal apps."

No. The only way to be really safe is to go live in a cave, not to have any friends and never go anywhere near any tech ever again. I'm sure you can tell that I don't consider that to be much of an option.

It's unhelpful to label 'data collection' as the source of the problem as 'collection' happens everywhere in our interactions with the world. There are valid arguments and discussions to be had about who really owns that data. It may well be about me, but that doesn't necessarily mean that it's mine. I'd say the majority of people are only just beginning to understand that a discussion needs to take place even though technical folks have known this for a long time.

One solution to the 'ownership' problem is to make it possible for everyone to run their own infrastructure. i.e. have their own 'backend' that apps/services can be installed into, which their end-devices can then connect to. This is already possible for the technically savvy but a lot of work is needed before I feel we can trust such systems (I'm working on approaches to this [1,2], based on unikernels).

In the meantime, I applaud business models that are not built around profiling (which is the crux of the issue cf. advertising). They're the only ones where the incentives have any hope of aligning.

[1] http://nymote.org/blog/2013/introducing-nymote/

[2] http://amirchaudhry.com/brewing-miso-to-serve-nymote/

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#219

Everyone seems to be Apple-bashing, and ignoring the fact that Apple really don't make money out of your private information. They make cash out of selling devices. So their interests are more aligned with yours. You may have noticed that Google don't make their money out of selling hardware. So they make it through other means. This is really inarguable, regardless of whether you think Apple are using that for marke…

> So their interests are more aligned with yours. Exactly how does a company that makes money through selling you products have its interests more aligned to yours?

Apple is "more aligned" as in more aligned than Google, not "more aligned" as in perfectly aligned.

Stop viewing the world in black and white.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#220
post #208

Earlier quoted context omitted.

Not possible. The insights come from the combination of everyone's data, not the analysis of any individual in isolation.

I'd like to disagree. When Google Now reads my email to track my delivery package number or flight number, it's my data. When it understands that I like sport team X, it's my data. When it knows where I work and live to ask Google servers the weather or how long it would take to go somewhere, still my data used as the request base. When Google(+) Photos auto-tags my photos, still my data, although I'd admit the IA tr…

I think your point is good, and depends on the question of how much can be done on current and future hardware, and what differences might result to product quality in local-only storage and processing.
Post reply on HN