Live data from Hacker News

Apple Platform Security (Jan 2026) [pdf]

help.apple.com

181–190 of 205 posts

Re: Apple Platform Security (Jan 2026) [pdf]

#181

Earlier quoted context omitted.

Apple sends your searches to Google for money. I would call search queries data?

> Apple sends your searches to Google for money. I would call search queries data? Yawn. Changing your default search engine takes 5 seconds.

How many people do you think actually do it?

Re: Apple Platform Security (Jan 2026) [pdf]

#182
post #41

Earlier quoted context omitted.

modeless linked to this article earlier today: https://james.darpinian.com/blog/apple-imessage-encryption/ My current understanding of the facts: 1. Google defaults to encrypted backups of messages, as well as e2e encryption of messages. 2. Apple defaults only to e2ee of messages, leaving a massive backdoor. 3. Closing that backdoor is possible for the consumer, by enabling ADP (advanced data protection) on your devi…

ADP isn’t the default, and almost nobody who isn’t a journalist/activist/potential target turns it on, because of the serious (potentially destructive) consequences. How does Google manage this, such every normie on earth isn’t freaking out?

> because of the serious (potentially destructive) consequences

Huh? What are you talking about? I don’t see anything destructive about it.

Re: Apple Platform Security (Jan 2026) [pdf]

#183
post #100

Earlier quoted context omitted.

Nobody expects their text messages to be backed up. They get deleted and people shrug.

Or IOW, Googles solution affects only messages. Apple’s solution affects your whole digital life so the consequences are a lot more dire.

> Apple’s solution affects your whole digital life

I don’t know if that’s generally true. I could lose my apple account and not really give a a damn. Not that I see how such a thing would happen, save for apple burning down all their datacenters. I’m running ADP

Re: Apple Platform Security (Jan 2026) [pdf]

#185
post #153

Earlier quoted context omitted.

> - They put all the privacy controls in one place in Settings so you can audit That’s true. On Pixel Android, there’s several unrelated places in the various settings for the device and for the Google account to take care of and see that they do not collide. And for every function there’s always some sort of small print like “it’s all private to you unless you choose to share” - but to use any of the features/servic…

> From what I heard and read, I understood that as a well-meant idea but still a misconception on the consumer part due to lack of enforcement by Apple. I'm not familiar with the detail so I cannot comment directly on what you are saying. I don't have the time to go read up on it right now. But what I would say is that many aspects will be indirectly enforced by Apple (and can be audited/enforced by the user) through…

Is it different with Google Play?

Re: Apple Platform Security (Jan 2026) [pdf]

#187
post #129

Earlier quoted context omitted.

Can someone explain what the real difference is to a consumer user between an iPhone and a Pixel or a Samsung device? Across all services, push notifications, and device backups. Both promise security, Apple promises some degree of privacy. Google stores your encryption keys, and so does Apple unless you opt in for ADP. Is it similar to Facebook Messenger (encrypted in transit and at rest but Meta can read it) and Te…

> Can someone explain what the real difference is to a consumer user between an iPhone and a Pixel or a Samsung device? Across all services, push notifications, and device backups. By default, Apple offers you at no charge: email aliases, private relay, Ask No Track barrier. These are just the ones I can think of right now. I am sure there are more. A big thing with Apple is not that they offer different privacy serv…

Aren’t they part of iCloud+ only? Ask no-track can arguably compromise your privacy by fingerprinting.

I agree that the privacy controls on Apple systems are well-organized.

Still, it’s more important to have confidence that the privacy services are not smoke and mirrors with carefully carved-out loopholes. It’s one thing to provide something and hold the competitor as the litmus test, the other to sustainably live up to your promises, like the now pejorative “do no evil” slogan, with retroactive ramifications. There’s really little users can effectively validate about Apple’s privacy promises.

Re: Apple Platform Security (Jan 2026) [pdf]

#188

Earlier quoted context omitted.

ADP isn’t the default, and almost nobody who isn’t a journalist/activist/potential target turns it on, because of the serious (potentially destructive) consequences. How does Google manage this, such every normie on earth isn’t freaking out?

> because of the serious (potentially destructive) consequences Huh? What are you talking about? I don’t see anything destructive about it.

People don't always have enough Apple devices to justify confidence that they couldn't lose them all at the same time, which with ADP is a permanent death sentence if you don't have your recovery key.

(Apple says you can also use a device passcode; I'm not sure if this works if the device is lost. Maybe it does?)

Re: Apple Platform Security (Jan 2026) [pdf]

#189
post #41

Earlier quoted context omitted.

modeless linked to this article earlier today: https://james.darpinian.com/blog/apple-imessage-encryption/ My current understanding of the facts: 1. Google defaults to encrypted backups of messages, as well as e2e encryption of messages. 2. Apple defaults only to e2ee of messages, leaving a massive backdoor. 3. Closing that backdoor is possible for the consumer, by enabling ADP (advanced data protection) on your devi…

Apple's other emphasis is customer experience, and there are more "I forgot my code, help me recover my stuff" people than you can imagine. It would be bad PR for Apple if everybody constantly kept losing their messages because they had no way to get back into their account.

You think there are fewer people who forget using Google devices? I don’t it. The article talks about how Google prevents that from happening.

Re: Apple Platform Security (Jan 2026) [pdf]

#190

Earlier quoted context omitted.

> because of the serious (potentially destructive) consequences Huh? What are you talking about? I don’t see anything destructive about it.

People don't always have enough Apple devices to justify confidence that they couldn't lose them all at the same time, which with ADP is a permanent death sentence if you don't have your recovery key. (Apple says you can also use a device passcode; I'm not sure if this works if the device is lost. Maybe it does?)

I have 2 or 3 yubikeys associated with my account. I think apple does a decent job at communicating the importance of having recovery keys to the point where they deter those who can’t be bothered.

Yubikeys are great

Post reply on HN