Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

371–380 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#371

Earlier quoted context omitted.

That's not the point of the outrage though (at least not for me). They enabled by default a feature that analyzes my pictures (which I never upload to iCloud) and sends information about them to their (and others') servers. That is a gross violation of privacy. To be clear, I don't care about any encryption scheme they may be using, the gist is that they feel entitled to reach into their users' most private data (the…

If the data is encrypted, does the concern still apply? You bring up the example of Onedrive, but there is no use of e2e encryption or HE techniques there.

> does the concern still apply?

Yes it does and the blogpost specifically explains why.

In short, both iOS and macOS are full of bugs, often with the potential of exposing sensitive information.

Also, it’s on by default - nobody in their sane mind would have bits of their photos uploaded somewhere, regardless of “we promise we won’t look”.

Finally, Photos in iOS 18 is such a bad experience that it seems the breach of privacy was fundamentally unjustified as no meaningful improvement was introduced at all.

Re: Apple Photos phones home on iOS 18 and macOS 15

#372
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

> Trust in software will continue to erode

> there is an increasing discontent growing towards opt-out telemetry

Really? That's news to me. What I observed is people giving up more and more privacy every year (or "delegating" their privacy to tech giants).

Re: Apple Photos phones home on iOS 18 and macOS 15

#373
post #95

Earlier quoted context omitted.

I appreciate the explanation. However, I think you do not address the main problem, which is that my data is being sent off my device by default and without any (reasonable) notice. Many users may agree to such a feature (as you say, it may be very secure), but to assume that everyone ought to be opted in by default is the issue.

Notice is always good and Apple should implement notice. However, "my data is being sent off my device" is incorrect, as GP explained. Metadata, derived from your data, with noise added to make it irreversible, is being sent off your device. It's the equivalent of sending an MD5 of your password somewhere; you may still object, but it is not factually correct to say your password was transmitted.

If the information being sent from my advice cannot be derived from anything other than my own data then it is my data. I don't care what pretty dress you put on it.

Re: Apple Photos phones home on iOS 18 and macOS 15

#375
post #268

Earlier quoted context omitted.

How much size would it take to store a model of every known location in the world and common things? For ex: I sent a friend a photo of my puppy in the bathtub and her Airpods (via iphone) announced "(name) sent you a photo of a dog in a bathtub". She thought it was really cool and so do I personally. That's a useful feature. IDK how much that requires going off-device though.

> That's a useful feature. I’m really curious how this feature is considered useful. It’s cool, but can’t you just open the photo to view it?

It is a notification summary.

There is a large number of people out there who receive hundreds of notifications (willingly but mostly unwillingly) daily from apps they have installed (not just messengers), and nearly all of them can't cope with the flood of the notifications. Most give up on tending to the notifications altogether, but some resort to the notification summaries which alleviate the cognitive overload («oh, it is a picture of a dog that I will check out when I get a chance to, and not a pic of significant other who got themselves into a car accident»).

The solution is, of course, to not allow all random apps to spam the user with the notifications, but that is not how laypeople use their phones.

Even the more legit apps (e.g. IG) dump complete garbage upon unsuspecting users throughout the day («we thought you would love this piece of trash because somebody paid us»).

Re: Apple Photos phones home on iOS 18 and macOS 15

#376
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

> Trust in software will continue to erode > there is an increasing discontent growing towards opt-out telemetry Really? That's news to me. What I observed is people giving up more and more privacy every year (or "delegating" their privacy to tech giants).

Do you honestly believe people understand what they’re doing?

Nowhere in marketing materials or what passes for documentation on iOS we see an explanation of the risks and what it means for one’s identity to be sold off to data brokers. It’s all “our 950 partners to enhance your experience” bs.

Re: Apple Photos phones home on iOS 18 and macOS 15

#377

Earlier quoted context omitted.

This must be the first consumer or commercial product implementing homomorphic encryption is it not? I would be surprised if doing noisy vector comparisons is actually the most effective way to tell if someone is in front of the Eiffel tower. A small large language model could caption it just as well on device, my spider sense tells me someone saw an opportunity to apply bleeding edge, very cool tech so that they can…

> This must be the first consumer or commercial product implementing homomorphic encryption is it not? Not really, it's been around for a bit now. From 2021: > The other major reason we’re talking about HE and FL now is who is using them. According to a recent repository of PETs, there are 19 publicly announced pilots, products, and proofs of concept for homomorphic encryption and federated analytics (another term fo…

>> I do wonder why we don't hear about it more often though

homomorphobia ?

Re: Apple Photos phones home on iOS 18 and macOS 15

#378
post #213
post #114

Earlier quoted context omitted.

Wrong. Anything that makes any network request is by definition a privacy leak. The network itself is always listening, and the act of making any connection says that you are using the computer, and where, and when.

If every app and system is making network connections by default without the user's knowledge or intervention then it doesn't really prove that you are using the computer at all.

Completely missing the point, but you're right that I should have said “using or in possession” of the computer. The point is that they reveal your physical location to the network, so if they make requests while not directly in use then it's actually even worse.

For context, stationary desktop machines comprise single-digit percentages of Mac sales: https://appleinsider.com/articles/24/03/06/macbook-pro-and-m...

Every other product sold by Apple (Mac notebooks, iPhones, watches, etc) are designed to be carried around with you, happily beaconing your presence to every network and to every other Apple device that will listen. I have seen this with my own eyes where my M3 MBP showed up on my WiFi AP status page as soon as I got home even though it was supposedly “““asleep””” in my bag.

Re: Apple Photos phones home on iOS 18 and macOS 15

#379

The referenced Apple blog post[1] is pretty clear on what this feature does, and I wish the author at lapcatsoftware (as well as folks here) would have read it too, instead of taking the blog post as-is. Apple has implemented homomorphic encryption[2], which they can use to compute distance metrics such as cosine similarity without revealing the original query/embedding to the server. In the case of photos, an on-dev…

Just from memory when the scheme came up in earlier discussion. The system is essentially scanning for the signature for some known set of images of abuse so that it aims to capture abusers who would naively keep just these images on their machines. (It can't determine if a new image is abusive, notably). It's conceivable some number of (foolish and abusive) people will be caught this way and those favoring a long dr…

>The system is essentially scanning for the signature for some known set of images of abuse

Huh? The system is scanning for landmarks, not images of abuse.

>people will be caught this way

Due to the homomorphic encryption, I don't think Apple even knows whether the image matches a landmark in Apple's server database or not. So even if Apple put some images of abuse into its server database (which Apple claims only contains pictures of landmarks), I don't think Apple would know whether there was a match or not.

Re: Apple Photos phones home on iOS 18 and macOS 15

#380
post #11

"I don't understand most of the technical details of Apple's blog post" I do: - Client side vectorization: the photo is processed locally, preparing a non-reversible vector representation before sending (think semantic hash). - Differential privacy: a decent amount of noise is added the the vector before sending it. Enough to make it impossible to reverse lookup the vector. The noise level here is ε = 0.8, which is q…

I am bit bit confused: Data is being sent to Apple, in such a way that it can not be traced back to the user. Apple does some processing on it. Then somehow magically, the pictures on your phone are updated with tags based on Apple's processing....but Apple doesn't know who you are.....

You joked, but you accidentally described what homomorphic encryption does. (if implemented correctly)

> Then somehow magically, the pictures on your phone are updated with tags based on Apple's processing....but Apple doesn't know who you are.....

Yes, this is the whole point.

Post reply on HN