Live data from Hacker News

Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

techcrunch.com

301–310 of 348 posts

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#301
post #266

In addition to the comments already here, I think this comes down to trust. Which companies do you trust? Which CEOs do you trust? Eric Schmidt: "If You Have Something You Don't Want Anyone To Know, Maybe You Shouldn't Be Doing It." [1] Mark Zuckerburg: "They trust me — dumb fucks." [2] Tim Cook: "I’m speaking to you from Silicon Valley, where some of the most prominent and successful companies have built their busin…

Schimdt quote is taken out of context and it is not the whole quote.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#302
post #176

Earlier quoted context omitted.

You seem to think that "pro-privacy" is equivalent to "don't collect any private information". It's not. Not at all.

That's exactly what privacy means. When I'm dancing naked in my house, I don't care if the guy holding the IR camera across the road is a government employee or a company's employee. All I care is that he has a camera. If some private data of mine (including, but not limited to pictures of my genitalia) ended up someplace other than on a medium I own, that data is no longer private. I.e. it was a privacy breach.

This is exactly what "Apple-is-better" people on this thread do not get.

They are suggesting that the Apple IR camera is good because it improves the user "experience by syncing with itunes to play a song with the right tempo as you dance" as opposed to the Google IR camera which will result in sun-burn cream ads. What the typical person would want is no IR camera at all.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#303
post #282

Earlier quoted context omitted.

My out-of-warranty MBP needed a new battery because the original battery had started to swell up. I called my local Apple Authorized Service Provider (the only one within 250km) what the procedure was if I wanted to purchase a new battery. They said I would need to drop off the computer with them; they would order a new battery and I could have it back in a week or so. I said I couldn’t do without the computer and I…

Could have cloned the drive yourself and given them a nice clean factory new OSX install to snoop on.

Yep. This is what I've done in the past for our machines.

1) Time Machine it 2) Clean install 3) Drop off computer to be fixed 4) Pick up computer 5) Restore from Time Machine

I've never had a problem.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#304
post #197

Earlier quoted context omitted.

The problem is that Duck Duck go doesn't provide as good results, because it lacks the personalized data. Google knows that when I search for Django I want the web framework. Duck duck go gives me that as well as many links to the film. I think option 1 is more likely for Apple.

Is it really so much harder to search for "django framework" instead of "django unchained" or "django guitar"? When you type in "django", DDG will suggest some searches to autocomplete as well. Is the performance benefit of personalized searches really worth it, compared to refining your search technique in small ways? Personally I prefer DDG simply because the bang codes are so convenient.

yes, but that was just one example, not the only one.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#305

Earlier quoted context omitted.

That rule #1 doesn't quite apply in this situation. That you should never need to give out passwords is mostly a safeguard for social engineering and phishing scams for accounts stored on a server over the internet . Only a malicious third party would ever ask for these types of account passwords, because those with legitimate needs to access it (you and the service operator) already have it (hopefully just the hash…

I disagree. Not even someone who's there to help you should know your passwords. Consider that many people use the same password for a lot of accounts. On top of that, they already have your email address. By asking their customers for their passwords, they don't just ask them to hand over all the data on their computers, but they also make them vulnerable with regards to their internet accounts. If I have a hardware…

Apple techs have access to external drives with multiple versions of OSX installed. If they need to boot your device to test the hardware itself, they will use one of these. If those tests indicate no hardware issue, their only next step is to check out your OS. That would require administrator access to your machine if you're using whole drive encryption.

I mean, I get what you're saying... they should have verified those things up front before asking for access, but I'm pretty sure they work on the concept of getting you the fastest service they can, balanced with the amount of customers they need to help simultaneously. My guess is that the admin password is a default question because they know they _generally_ will need it, so it's best get it up front rather than waiting hours or days for the customer to get back to them.

Personally, when I had to take my Macbook in, I just zero'd out the sensitive data, changed my admin pw to something temporary, and let them have it. I know this will be a TOTAL surprise, but the multibillion dollar corporation didn't use this as a chance to hack my life. What a novel thought.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#306

Making a speech is easy, compared to actually doing the right thing. Just a month ago, I was asked by an employee of an Apple Certified Service Provider to decrypt my hard drive in order for Apple to make a "hardware test". There was an issue with my display, but they insisted that Apple's hardware test needed to have access to the data on my hard drive and send information back to Apple via the Internet. What about…

This is akin to giving your car to a mechanic to repair but refusing to give him the keys in case he might make a copy.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#307
post #200

Earlier quoted context omitted.

If you do work related stuff on your computer, your work should be taking care of the computer. This is why most people get assigned a computer by their places of employment, and are not expected to use their own. The place of work has their own tech team who deal with these types of issues. It's a really bad idea to do work stuff on a home computer because it makes your device much more vulnerable to being snooped o…

>it could be a software issue They can still do some tests. It's not like wiping the hard drive helps solve software issues. >FDE is good for one loss of control; after that you should assume compromise. If the threat model is a malicious actor, yes. If the threat model is accidental plaintext password leaking, there is a huge difference between the scenarios. I could construct a similar argument against password has…

>If the threat model is accidental plaintext password leaking, there is a huge difference between the scenarios.

That's just fear mongering.

Why would you not change your password before taking it in? You should be changing it regularly anyway, and you shouldn't be using that password in more than one place. The idea of it leaking from a technician's database is irrelevant because you would change it as soon as you get the machine back.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#308

Earlier quoted context omitted.

> That isn't a good thing. http://dontbubble.us I don't get the argument being presented there. In either situation, some information is visible, and other information is buried. Presenting the same top results to everyone is just as bad of a bubble.

everyone seeing the same results for the same search terms is inherently not a "bubble"

Sure it is. Everyone's exposed to the "average" person's top 10 or so results. With personalized results, potentially millions of different pages are exposed as the top 10 or so results depending on who's searching.

You get stuff that's a little more relevant to your usual interests, which places you in your own bubble, but IMO that's better than everyone in the world being in the same shared bubble.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#309
post #296

Earlier quoted context omitted.

Thank you for posting a well-balanced summary of the situation. I think the biggest difficulty with balancing privacy concerns against other factors -- or even encouraging debate about and awareness of the issues among non-technical friends and family -- is that an item of data is itself neutral. It is how that data is used or combined with other data that may or may not be in any given party's interests. Sometimes t…

Agreed that data is in and of itself neutral. Similar to a gun it is not its use but how it is used that can be detrimental. In fact, this is true of most anything from a pencil to a car. I think at the core however the issue is not how the data is used but one of ownership and privacy. It is "my" business where I drive. It is "my" business whom I call. It is data about me and my behavior. So to have that information…

It is "my" business where I drive.

True enough. However, it is also the business of the people who are responsible for building and maintaining the roads to know how those roads are being used.

It is "my" business whom I call.

True again. However, it is also the business of the phone company who must provide the service you ordered and to which you will owe money based on the calls you make and, in some cases, who you are calling.

I do understand your concern about data being out there at all. However, the reality is that we interact with the world and the people around us all the time. Sometimes that will result in data that refers to us but also affects other people for legitimate and often unavoidable reasons. So I don't think an extremist position that no-one should ever be able to collect data about you without your explicit consent is ever going to work. As others have noted, that would mean you couldn't interact with almost anyone or anything in the modern world, and unless you're planning to live 100% off-grid as a hermit that's just not a viable possibility. Instead, we should consider issues like the retention and repurposing of data.

Licence plate readers that are automatically tracking cars through a congested area that has variable speed limits are potentially in everyone's interests: smoothing out the traffic flow makes everyone's journey faster and safer, and has basically no downside. However, once a vehicle has left that area, it is no longer necessary to keep any specific details about it for that purpose. The data can be discarded, or completely anonymised simply by turning each plate into a unique but otherwise meaningless number before it's recorded if it's useful to store aggregated data for more general traffic planning purposes. Similarly, if plate recognition is being used for enforcement of that speed limit, there is no need to record the details of anyone except those the system has determined to be exceeding the speed limit, where the evidence will be used for a subsequent prosecution. Once any resulting legal processes have run their course, the data can also then be completely discarded if no conviction resulted.

The risk in either case is not the scanning itself, it is the retention of the data and potentially use for other purposes and correlation with other data sets later. Given robust rules about keeping personal data no longer than necessary for its stated purpose, and probably about declaring its stated purpose in a meaningful and usefully specific way, this is not so much having a tail as having a driver in a car behind who happens to be following you for a while on the same road but then forgets they ever saw you within moments of going your separate ways. I doubt even the most privacy-conscious person would consider that an unreasonable risk in other contexts or expect to be able to prevent it.

Re: Apple’s Tim Cook Delivers Blistering Speech on Encryption, Privacy

#310
post #3

“I’m speaking to you from Silicon Valley, where some of the most prominent and successful companies have built their businesses by lulling their customers into complacency about their personal information,” “They’re gobbling up everything they can learn about you and trying to monetize it. We think that’s wrong. And it’s not the kind of company that Apple wants to be.” This is a great strategy to win the hearts and m…

But it's still mostly bullshit, though, especially coming from a company using closed source software for most of its products. Nobody can really tell what they are collecting, what they do with it and how much of it they share with third parties (including governments). If you google a bit, I bet you will find similar speeches from every single big company CEO these past years: "Privacy is our number one priority, b…

Everyone was happy to believe Google when they used to say their motto was, "Don't be evil," but not willing to believe the CEO of Apple, even though they've done a LOT to show they are working inline with his speech. I'm not saying Apple is a saintly corporation, but just assuming they are bad because they they COULD be bad comes off as paranoid more than insightful.

>Nobody can really tell what they are collecting, what they do with it and how much of it they share with third parties (including governments).

http://www.apple.com/apples-commitment-to-customer-privacy/

Yes, this could all be lies, but so could literally anything anyone says. Either you choose to live as a recluse in the woods with no technology, or you choose to trust at least some corporations. That might mean trusting your search engine, your cell phone company, your car manufacturer. Heck, you're trusting your ISP right now not to do a MITM attack on you. The natural conclusion is that you should use strong encryption in everything you do. At this point, there is one company spearheading this to get it into the hands of consumers who don't know any better.

Again, I realize Apple isn't blameless, but there's an awful lot about their recent actions to show they are making decisions based on what is best for the consumer. I think that's a good thing, and it's hard to imagine why someone would argue against it.

Post reply on HN