Live data from Hacker News

Apple Platform Security (Jan 2026) [pdf]

help.apple.com

151–160 of 205 posts

Re: Apple Platform Security (Jan 2026) [pdf]

#151
post #55

Earlier quoted context omitted.

I still like to encourage people to watch all of https://www.youtube.com/watch?v=BLGFriOKz6U&t=1993s for the details (from Apple’s head of Security Engineering and Architecture) about how iCloud is protected by HSMs, rate limits, etc. but especially the timelinked section. :)

I still recommend Mr. Fart's Favorite Colors as a refutation, describing why all of these precautions cannot protect you in a real-world security model: https://medium.com/@blakeross/mr-fart-s-favorite-colors-3177... Unbreakable phones are coming. We’ll have to decide who controls the cockpit: The captain? Or the cabin?

I don't understand.

That article (written in 2016) says that Apple will build unbreakable phones in the future. Now is the future. So it seems to imply that Apple phones today are unbreakable.

Also, where does the article discuss "all of these protections"? (HSMs, rate limits, etc.)

Re: Apple Platform Security (Jan 2026) [pdf]

#152
post #49

Earlier quoted context omitted.

It's all tempered by them ultimately controlling what you can put on your phone though. As was demonstrated in LA, it's starting to have significant civil rights consequences.

What happened in LA?

https://www.cnn.com/2025/10/03/tech/iceblock-apple-removed-t...

Re: Apple Platform Security (Jan 2026) [pdf]

#153
post #129

Earlier quoted context omitted.

Can someone explain what the real difference is to a consumer user between an iPhone and a Pixel or a Samsung device? Across all services, push notifications, and device backups. Both promise security, Apple promises some degree of privacy. Google stores your encryption keys, and so does Apple unless you opt in for ADP. Is it similar to Facebook Messenger (encrypted in transit and at rest but Meta can read it) and Te…

> Apple promises some degree of privacy. Apple also makes it easier to achieve that privacy: - They put all the privacy controls in one place in Settings so you can audit - App developers are mandated to publish what they collect when publishing apps to the App Store.

> - They put all the privacy controls in one place in Settings so you can audit

That’s true. On Pixel Android, there’s several unrelated places in the various settings for the device and for the Google account to take care of and see that they do not collide. And for every function there’s always some sort of small print like “it’s all private to you unless you choose to share” - but to use any of the features/services you have to “share” like with Google Photos and Calendar and Tasks, you lose track of what you share with whom in the end. So essentially not only the metadata is collected but also the content and nothing’s private as a result, at least that’s what I got to understand. And even if you ask Google to delete your personal information, it will retain it for a while for compliance purposes.

As for

> - App developers are mandated to publish what they collect when publishing apps to the App Store.

I believe that’s still moot and rather a voluntary disclosure that no one vets. I’ve seen apps with no collection stated on App Store but deviating privacy policies, or app functions that contradicted their own privacy policy.

From what I heard and read, I understood that as a well-meant idea but still a misconception on the consumer part due to lack of enforcement by Apple.

Re: Apple Platform Security (Jan 2026) [pdf]

#154

Earlier quoted context omitted.

My understanding though is that the monetization pathways for Samsung and Google are 3rd party—Apple keeps your data to itself.

Apple sends your searches to Google for money. I would call search queries data?

I wonder how exactly Apple Intelligence works with ChatGPT and soon with Gemini. If I remember correctly, there’s no privacy there? If so, where’s the privacy boundary in Apple Intelligence?

Google pushes Gemini everywhere and wants to keep on to your interactions, with human reviews. While I applaud the transparency, having Gemini scrape my screen makes me uneasy. My frog’s not warm enough for that, yet.

And Gemini in Sheets and Docs is just a toy. Microsoft 365 Copilot is a step ahead but is wrong more often than not, at least from my interactions with them. Both very disappointing. No way to justify access to my personal or my company’s or clients’ information.

Apple promises something they call Secure Compute or so, don’t remember the exact name, which appears to be encrypted and randomized in their cloud compute, which is off-device. With iPhone being the most powerful to date (per GeekBench), Tensor Pixels will have to offload most of the edge compute to GCP, and Snapdragon Samsungs while being powerful (I have no idea but would assume) must follow the Pixel Android approach.

So AI features will exfiltrate even more personal information, occasionally, accidentally, or purposefully, and the user would have consented to that and the human reviews just to get access to the smart features.

Re: Apple Platform Security (Jan 2026) [pdf]

#155

Earlier quoted context omitted.

Apple sends your searches to Google for money. I would call search queries data?

> Apple sends your searches to Google for money. I would call search queries data? Yawn. Changing your default search engine takes 5 seconds.

That’s true, though I wish Apple gave me the freedom to define a new search engine, beyond the small provided selection.

Re: Apple Platform Security (Jan 2026) [pdf]

#156

Earlier quoted context omitted.

Apple, Samsung and Google all earn money from ads on your phone, just with different monetization pathways.

My understanding though is that the monetization pathways for Samsung and Google are 3rd party—Apple keeps your data to itself.

I think AdSense is still an Alphabet subsidiary?

Re: Apple Platform Security (Jan 2026) [pdf]

#157
post #49

Earlier quoted context omitted.

It's all tempered by them ultimately controlling what you can put on your phone though. As was demonstrated in LA, it's starting to have significant civil rights consequences.

Security is pointless if platform allows 90% users to be social engineered into running code disabling that security

What's funny is you could read that statement as being an argument for or against walled gardens, depending on what kind of social engineering is being referred to.

Re: Apple Platform Security (Jan 2026) [pdf]

#158
post #129

Earlier quoted context omitted.

Can someone explain what the real difference is to a consumer user between an iPhone and a Pixel or a Samsung device? Across all services, push notifications, and device backups. Both promise security, Apple promises some degree of privacy. Google stores your encryption keys, and so does Apple unless you opt in for ADP. Is it similar to Facebook Messenger (encrypted in transit and at rest but Meta can read it) and Te…

Some of these companies don't make money from you, the end user, but by selling ads and data to more effectively deliver said ads. Differences in capabilities, experience and implementation are all downstream from that. In other words, everyone pays lip service to privacy and security, but it's very difficult to believe that parties like Meta or Google are actually being honest with you. The incentives just aren't th…

I think there’s also a topology chasm at play. Apple controls most of its hardware stack, with Qualcomm modems and Samsung displays, but the SoC is now Apple’s own. Google relies on rotating third parties to assemble the Pixels, hence poor QC. Samsung makes its own Exynos modems which they don’t dog-food and like Apple rely on Qualcomm instead, while Google still depends on Exynos.

Then there’s a big disparity across all Android hardware vendors. Google must cater to that more or less federated topology of Android devices. It’s much harder.

Yet I don’t see any technical blocker for an opt-in for an Apple-grade ADP in Pixels and Galaxies.

It’s all quite weird. Even with Google Passwords, how do I know that it’s E2EE if I can unlock it from a browser with just a device PIN? Lots of loopholes.

Re: Apple Platform Security (Jan 2026) [pdf]

#159

Earlier quoted context omitted.

That chimes roughly with my experience, but to be fair ADP is designed not just for encrypted backups, but to harden the ecosystem for people who may be under the greatest threat. Worth noting that it has been outlawed in the UK and cannot be enabled, which makes me think it's pretty decent

> Worth noting that it has been outlawed in the UK and cannot be enabled For the record, there is an ongoing court battle between Apple and UK government about getting it overturned. Which also says many positive things for Apple that they are willing to put their money where their mouth is and put up a fight.

And that’s a significant PR and marketing posture for Apple.

Re: Apple Platform Security (Jan 2026) [pdf]

#160
post #100

Earlier quoted context omitted.

Or IOW, Googles solution affects only messages. Apple’s solution affects your whole digital life so the consequences are a lot more dire.

Google’s solution also ensures that they know all the metadata of your messages, except the content of the message itself.

Apple too collects unencrypted metadata but now promises to reduce its scope.
Post reply on HN