Live data from Hacker News

Apple decided not to roll out Siri in EU after denied request for exemption

reuters.com

601–610 of 735 posts

Re: Apple decided not to roll out Siri in EU after denied request for exemption

#601
post #141

I understand Apple's position on this one. This is essentially a backdoor into all of your data. It is also a very useful feature. The EU regulators are disallowing guardrails without which this backdoor will be used to strip-mine people's personal data. The privacy implications are not legible to most people. If I was more cynical I would suggest that this is being used as an end-run around encryption, since the enc…

It would only be a backdoor if it's implemented as a backdoor. The way Apple Health exchanges data with 3rd-party trackers (Fitbit, Garmin, etc.) is very well built and a good model of how other components in iOS could allow data exchange with very granular permissions. Apple touts the "Private Cloud Compute". If they found a way to share your personal context to process on their cloud in a private and anonymized way…

> It would only be a backdoor if it's implemented as a backdoor.

You don't seem to know how backdoors work.

Oppressive regimes mandate that tech companies pre-install apps to protect people from spam calls, or install specific root certificates so they can intercept your traffic and insert a helpful banner into your browsing session to remind you when to pray.

The EU isn't going to ask Apple to add DataCollectionBackdoor(). They are going to demand that in the spirit of freedom and happiness EU companies must have access to Apple users private data.

Re: Apple decided not to roll out Siri in EU after denied request for exemption

#602

Earlier quoted context omitted.

> Functionally the EU is requiring that Apple dramatically RELAX their privacy and security postures. No. Interoperability doesn't require Apple relax their privacy and security postures. It could instead require third parties to improve theirs.

> It could instead require third parties to improve theirs. Apple made it sound like their proposal for that was rejected by the EU. And it would be consistent with previous regulatory decisions by the EU for them to not want Apple to be setting the rules for how third-party interoperability partners/competitors ensure privacy. It seems to me that the EU has a preference for protecting privacy with legal mechanisms,…

I’m sure they love it when Apple says, “Well… they COULD give us their models to put in private compute, but we’re not paying them for that and they’re not getting any more data than we get, ourselves. Which is exactly none.”

Re: Apple decided not to roll out Siri in EU after denied request for exemption

#603
There are two things here:

Allowing Siri competitors. EU is 100% right to demand from Apple to give the same data that Siri has to any other app (competitor) that the user chooses to install, trusts and has granted access. The grant should be the gate keeper, not Apple.

User privacy, data retention, pii, etc - I am not 100% sure here - if you send user data somewhere to a LLM, it gets very complicated, very fast, and probably the rules should be revisited / simplified / relaxed.

Re: Apple decided not to roll out Siri in EU after denied request for exemption

#604
post #599
post #223

Earlier quoted context omitted.

Not privacy, but as an example: NIST, MS, and the security community all recommend against forcing people to change their passwords on fixed intervals. They should only be changed when there is an indication they have been compromised. PCI requirements demand mandatory 30 day rotation intervals on user passwords for users with administrative privileges, IORC. Something like that. They haven’t kept up. So until they c…

Your example completely ignores the temporal dimension. The best practice was to rotate your passwords, but we discovered that this led users to picking less secure and easier to remember passwords and patterns. Once technology offered up solutions to problems like password managers and breach notifications, that recommendation changed. PCI used to mandate password changes for in-scope accounts (meaning they have acc…

They specifically addressed the temporal element:

> They haven’t kept up.

Other standards all used to recommend password rotation. Most have amended it to deprecate or even prohibit password rotation.

> Once technology offered up solutions to problems like password managers and breach notifications, that recommendation changed

It wasn’t just that.

The original recommendation for password expiration failed to take into account the human practices that resulted.

Everyone has worked in an office with passwords on post-it notes, or seen passwords numbered with sequentially incremented integers at the end. Password rotation isn’t merely a baseline level of assurance, it has a negative impact on security because of the effect it has on password hygiene. In practice, passwords that expire can be easily guessed by appending something to the end of the prior password. And they are more likely to be written down in plaintext.

Permanent, non-expiring passwords without MFA are stronger in practice than expiring passwords.

Re: Apple decided not to roll out Siri in EU after denied request for exemption

#605

Earlier quoted context omitted.

> This is essentially a backdoor into all of your data. This is the rhetoric used against right to repair. "What if enemies get access to our citizens' data if we allow anyone but us to repair your car?"

I have never seen this argument against (admittedly I'm not big into such debates) right to repair, did it came up somewhere?

Yes, it's what the opposition literally does. Go read some press pieces from these neoliberal moderates:

https://www.progressivepolicy.org/weighing-the-risks-of-righ...

Re: Apple decided not to roll out Siri in EU after denied request for exemption

#606
post #405

Earlier quoted context omitted.

> Apple claims to protect user privacy all the time. But they can't offer a product in a major jurisdiction that has actually meaningful privacy laws? The DMA and the GDPR are laws that at their core make each other more difficult. the stated outcome of the DMA - allowing any vendor/user full access to your device - is not easily supported when solving for privacy.

A popup that's like "do you want to give app XY access to this data?" is really not that hard to build... It's a lazy excuse, nothing more.

And then most users soon have given permissions to a ton of apps with sketchy records of protecting user data, so what was the point of even trying to protect privacy?

Re: Apple decided not to roll out Siri in EU after denied request for exemption

#607

Earlier quoted context omitted.

Former, you mean?

Yes, indeed, I wasn't paying attention.

I figured, just wanted to verify, because while the former seems like the obvious answer, it could be argued with a straight face that Apple's strategy is in fact the latter. Or something like it.

Re: Apple decided not to roll out Siri in EU after denied request for exemption

#608
post #276

Earlier quoted context omitted.

They've just announced PCC for Google Cloud using Nvidia GPUs and Intel CPUs so it would probably run on just about anything - https://security.apple.com/blog/expanding-pcc/

Of course Google has the capacity to run PCC. This isn't about whitelabel PCC being run by FAANG. This is about Super Private Benoau AI being available for any user to install. How can they know whether it respects their privacy or not? The home page says that they're the best and mostest private ever of course, has animations generated by Claude and everything. But actually it runs on servers bought from Hetzner's s…

> How can they know whether it respects their privacy or not?

How can you know whether Apple would actually respect your privacy or not? If it's on-device you can audit it, but how can you prove their cloud is actually respecting your privacy?

If you have an answer to this then why can't third-parties also do the same?

Re: Apple decided not to roll out Siri in EU after denied request for exemption

#609
post #600

Earlier quoted context omitted.

Who said anything about a direct vote for every action? You're putting words in my mouth. Yes, I think it's a particularly good example of government dysfunction. The issue itself is simple enough to easily make sense of and it's clear that it's a suboptimal outcome. The regulator should obviously not be getting caught up in nonsensical hype. Don't confuse impact of the described action with quality as an example. Th…

> If you don't personally find straws useful that's fine but why should something like that be dictated for everyone else let alone at such a high level of government and without a direct vote by the citizens? That is cleary advocating for something as small straws being worthy of a direct vote. Is there a reasonable expectation for government to be mathematically optimal in any possible way? Why should I not confuse…

>"why should something like that be dictated for everyone else let alone at such a high level of government and without a direct vote by the citizens"

Not the user you were replying to, but they clearly asked why it was done at high-level, and without a vote; you are completely focusing on the latter, and ignoring the former.

I am not sure I agree with that comment, but you shouldn't straw-man it.

Post reply on HN