Live data from Hacker News

A Message to Our Customers

apple.com

151–160 of 1001 posts

Re: A Message to Our Customers

#151

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

You are right. What you say about Facebook is true, but Google's Android is open source, so there is no way they can plant a privacy-invading code and get away with that.

No phone on earth runs the open source version of Android that you can download from git. They all run custom versions that include not only closed source personalizations to the system, but they also run lots of closed code as root (play services first and foremost).

The reason why this doesn't happen with Android is much more mundane: most Android phones are not encrypted so the FBI doesn't need help to read all the customer data. They just need to open the phone and dump the flash.

Re: A Message to Our Customers

#152

Earlier quoted context omitted.

> And nobody runs Android on a phone where the entire stack is open source and blob free. > Anyone who does is a rounding error. I'm actually curious if there is literally anyone who uses no proprietary software, including the radios and the SoC, on their Android device. My bet is that there's not even a single device out there for which this is possible. (If there is, I'd love to see it.)

Not quite, but you can come close. I have Cyanogen installed on all my Android devices and I try to use as little proprietary software as possible. However I am patiently waiting for the Neo900, which is a free (libre) hardware design based on the Nokia N900: https://neo900.org/ According to them, there are unfortunately no baseband modems on the market that can legally have their firmware distributed as free softwar…

> According to them, there are unfortunately no baseband modems on the market that can legally have their firmware distributed as free software.

What is the legal restriction here? (It sounds like you're referring to some restriction beyond simple copyright protection on some of their components - are there FCC regulations regarding the firmware?)

EDIT: Ah, of course, the FCC needs to certify devices before they can actually be used.

Re: A Message to Our Customers

#153

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

You are right. What you say about Facebook is true, but Google's Android is open source, so there is no way they can plant a privacy-invading code and get away with that.

Just because it's open source doesn't mean it's safe. You have no control of what happens to that code before it gets installed on a phone. Samsung, whomever can and do modify the code -- those modifications aren't generally open source.

Ruby on Rails is open source but that doesn't mean that all applications on rails are open source.

Re: A Message to Our Customers

#154

Earlier quoted context omitted.

That is hard, we know. But it is not impossible for those with time, resources and willingness to think outside the box. I assume that Apple has a hardware security module for key generation and storage, perhaps even custom-designed and built, to prevent key extraction/copying. Of course, in the end you have to trust Apple that only a limited number of employees have access to such hardware, that they have proper aud…

If there's one thing that we have learned over the last few years from Snowden et al, we have learned that it is safe to assume that these state actors will be trying all the avenues that you or I can think of, and spend years discovering new ones that we have not thought of.

I have trouble understanding your point. What's the alternative to trying to minimize the probability of crypto system compromises?

Re: A Message to Our Customers

#155

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

> Apple is not doing this out of goodwill, or because they believe in protecting privacy.

Personally I think this is ridiculous.

If Tim Cook was born in a range of other countries around the world he would be persecuted and quite likely killed (and not in a pretty way). As such I am sure he is very aware that for many people their privacy is a life and death matter.

Also there would be many people at Apple who would've been dealing with China's aggressive attacks against their users and their own infrastructure and not be too pleased. And to a lesser extent their own government.

I can't imagine the extra few billion that comes from goodwill being a major factor in their efforts to go to all of this trouble.

Re: A Message to Our Customers

#156

Earlier quoted context omitted.

There are basically two groups of large software companies around right now: those which make their business by collecting data, and those which make their business by licensing software[1]. The first group has an overwhelming incentive to not support privacy too strongly. The second group has an overwhelming incentive to not allow too much openness. Until a better business model (or zero-knowledge machine learning)…

Actually, there is a third business model which doesn't exploit its users' privacy, nor does it have to resort to closed-source licensing (but selling add-on services like support and customization). This is the model adopted by companies like Red Hat, Canonical and to some extent Google (in a few products). The future, in fact, belongs to this third business model that helps a business earn profits without hurting i…

The reason I specified large software companies, is that support and customization works well up to a certain scale, but won't give you a "big five" size company. A software Mittelstand which profits from support and customization might indeed be a possible future, but I think is far from a certainty. Also, I wouldn't consider that to be without disadvantages.

Two example disadvantages:

1) As it is, support and customization for specific non-technical paying users are among the things many top engineers least like to do. The reason being that it takes away from time solving the problems of the large mass of non-paying users. Even under the support & customization model versus the proprietary model, the number of paying users is much smaller in the first case in general, which creates a smaller "high priority" class of users.

2) Certain features and applications, such as traffic-aware maps or voice recognition engines are easy to build by huge centralized organizations which hold all the necessary data. They are challenging things to implement for loose collectives of smaller software companies, specially in a privacy-aware way.

Re: A Message to Our Customers

#157

Earlier quoted context omitted.

I know that it is an idiom, I asking why he has no hope

From the link that was posted in reply to you, 'hope against hope' means 'to have hope even when the situation appears to be hopeless'. Which means he does have hope, even though the situation appears to be hopeless.

Why is the situation hopeless? Google, for example, has been undertaking efforts for years to improve security on the Internet, in part for the purpose of protecting privacy. Seven days ago they were featured in an article about how they're going to warn users of Gmail whose incoming emails are not protected by SSL: https://news.ycombinator.com/item?id=11067050 - this is part of their Safer Email initiative. Some time ago they released a Transparency Report as part of that initiative describing which senders to/from Gmail support encryption: https://www.google.com/transparencyreport/saferemail/ - and that's not to mention their efforts promoting HTTPS.

I see these efforts as Google going far out of its way to support privacy and security on the web.

Re: A Message to Our Customers

#158

I can't read it from the letter - are they going to refuse to cooperate? Can they do that?

They're not 'refusing to cooperate' in the sense of just ignoring the court or something. They'll file a motion to have the order lifted, with their reasons. If that's refused, they'll presumably appeal the refusal to a higher court, and so on, to the max extent they can. That's not being obstructionist, it's their legal right.

Re: A Message to Our Customers

#159
post #42

I'm really impressed that Apple is standing up to the government and protecting its users' rights. I've never really considered the iPhone worth the premium price tag, but policies like this have changed my mind. Could someone answer a question I have though? The government wants Apple to create this backdoor and tailor it to the specific device, so presumably it will have a line that goes if (!deviceID.equals("san_b…

Once they build that in for one device then they have opened pandora's box. Then it becomes a precedent in the courts that Apple has this ability so they will issue court orders to make them comply for every single case where a phone is encrypted.

One way around that is for Apple to make it extremely costly for courts to issue many of such orders, because after all Apple are free to charge whatever they like for doing this service.

Re: A Message to Our Customers

#160

I see a lot of people saying they're impressed, admired, etc. at Apple for doing this. It's not about giving props: Apple is not doing this out of goodwill, or because they believe in protecting privacy. Apple has a competitive advantage against Google/Facebook in that its business model does not depend on violating their customer's privacy. They are just exploiting that competitive advantage. Cfr. https://ar.al/note…

You are right. What you say about Facebook is true, but Google's Android is open source, so there is no way they can plant a privacy-invading code and get away with that.

There are parts of Android phones that are closed and proprietary now. Even CyanogenMod.
Post reply on HN