I see a bunch of comments talking about how Apple is being self serving and not at all altruistic when they defend our privacy. And my response is - well duh. And this is supposed to be a problem how? Apple wants my money and nothing else. They aren't motivated to protect my privacy out of the goodness of their hearts. I am happy to pay money for more privacy. The fact that they only do this because they want my mone…
If Apple is the only organisation defending our privacy, it is time to worry
111–120 of 205 posts
Re: If Apple is the only organisation defending our privacy, it is time to worry
#112Earlier quoted context omitted.
>Apple's profile of me, I imagine, is much less detailed than Facebook's Apple certainly is not shy about collecting biometrics. They have the most complete set of biometrics of the FAANGs. I'm not certain what their motive is.
Source? They specifically say they do not collect any of your biometrics. Touch ID and Face ID data is stored in an encrypted form on the Secure Enclave chip and never leaves your device.
Re: If Apple is the only organisation defending our privacy, it is time to worry
#113Earlier quoted context omitted.
Most apps now use certificate pinning, i.e. they have the root certificate included in the app and signed as part of the app, so that method won't work. On Android it's much easier to intercept and modify the behavior of apps and tell the system to disregard signatures and things of the sort.
Maybe you live in an alternate reality, but in this reality most apps aren’t remotely sensitive enough to use cert pinning. Also, since Android 7, even non-cert-pinned apps simply ignore user/admin-installed certificates; you can’t do anything without (1) rooting and injecting cert into root trust store; or (2) binary patching. Neither is easy, whereas installing a certificate as a profile on iOS is a trivial process…
I spent a while reverse-engineering Clubhouse's API and what data they were sending, and even they use cert pinning. Most of the big apps all do.
Re: If Apple is the only organisation defending our privacy, it is time to worry
#114Apple also has a question mark attached to its commitment to privacy in China. Even though the Twitter thread below is by a NYT reporter, it sounds directionally credible given how embedded Apple is in China, both from a manufacturing point of view and also as a growing market. 2021-MAY-18 "NEW: Apple is jeopardizing its Chinese users’ data and augmenting the Chinese government’s censorship to placate authorities and…
Also, Apple needs to comply with local legislation to be able to provide services in other countries. China also happens to be the country source for most of Apple's supply chain - it's not exactly viable to start fighting the local authorities.
Imagine if other big companies with impact in China (like Epic?) choose to align and apply pressure in the name of user privacy (instead of wasting time and money on pointless litigation)... then perhaps, it will be much harder for a local government to get its way.
Re: If Apple is the only organisation defending our privacy, it is time to worry
#115Earlier quoted context omitted.
It’s basically impossible for an American company to defy the American government. They can try in court but ultimately the government has F-22s and nuclear weapons and Apple does not.
Thanks, now I'm imagining a dystopia where large tech companies have their own militaries.
Re: If Apple is the only organisation defending our privacy, it is time to worry
#116As for organisations that cater to personal privacy, I don't see any mention in the article about Purism, Mozilla, LinageOS, F-Droid, QubesOS etc.
Re: If Apple is the only organisation defending our privacy, it is time to worry
#117Earlier quoted context omitted.
That’s a hold out from the Android world, where apps are generally written to expect the user to provide requested permissions. Before Android 6, apps would get all permissions requested for on installation (or the user wouldn’t be able to install the app). From Android 6, when the permission model changed to be similar to iOS to get it at runtime, apps didn’t get written for this new world and would crash or refuse…
I deny functions to apps in Android all the time. I've yet to run into an app that will refuse to run unless that denied function is explicitly needed for that app to do what it was designed to do: eg, location for maps.
Wechat also for a while didn't even allow logging in without location permissions. They may have changed that but there are lots and lots of offending apps.
Re: If Apple is the only organisation defending our privacy, it is time to worry
#118I see a bunch of comments talking about how Apple is being self serving and not at all altruistic when they defend our privacy. And my response is - well duh. And this is supposed to be a problem how? Apple wants my money and nothing else. They aren't motivated to protect my privacy out of the goodness of their hearts. I am happy to pay money for more privacy. The fact that they only do this because they want my mone…
But when apple introduced ads to the App Store, a part of me became quite sad.
Like no amount of money would ever be enough...
Re: If Apple is the only organisation defending our privacy, it is time to worry
#119I see a bunch of comments talking about how Apple is being self serving and not at all altruistic when they defend our privacy. And my response is - well duh. And this is supposed to be a problem how? Apple wants my money and nothing else. They aren't motivated to protect my privacy out of the goodness of their hearts. I am happy to pay money for more privacy. The fact that they only do this because they want my mone…
The relevance of criticism on Apple's privacy stance is in pointing out the limits of Apple's commitment to privacy. Companies like Signal are founded on privacy and encryption, but with Apple, privacy is a nice-to-have, limited to its other business objectives (like how Apple is "committed" to reducing waste to the extent it can sell dongles, chargers, and earbuds separately, but not in terms of repairability). You…
Maybe this is just a shallow read of it, but it feels like sort of a similar dichotomy to that between Apple's rhetoric about objectionable content on app stores and... well, its inclusion of a web browser.
Re: If Apple is the only organisation defending our privacy, it is time to worry
#120Earlier quoted context omitted.
MITM proxies don't work when apps use certificate pinning. Many popular apps do this. > everyone who wants to manually inspect the bytes coming out of their phone == everyone who actually gives a damn about their privacy Do you even know what your phone apps are sending about you? I know what my apps are sending about me. Some of it is pretty scary, honestly.
So you like an OS that sends fake sensor data to apps, but you trust it to send real network data to you? What if it doesn't? What if the hardware sends fake network data to the OS? You clearly don't give a damn about your privacy, because everything you do can be subverted through any of those components. People who give a damn about their privacy write their own OS, apps and install it on their custom built hardwar…
Sure, make your own phone, I'll very much support and admire you if you do.
Until then, since I don't have that hardware engineering prowess, I'm at least a few steps ahead of any iOS user and at least have control over my OS and what my apps do.
iOS users on the other hand just surrender their privacy management to almighty Apple and trust that Apple does no evil, and trust that the signed apps they run on their devices do no evil.
Yeah, if Qualcomm does evil in their Snapdragons I'm screwed, but at least I've reduced my privacy risks by a few notches, better than nothing.