macOS phones home when previewing local image files [video]
1–10 of 26 posts
Re: macOS phones home when previewing local image files [video]
#2Re: macOS phones home when previewing local image files [video]
#3Is there a hosts entry I can add to block this behavior?
Re: macOS phones home when previewing local image files [video]
#4Re: macOS phones home when previewing local image files [video]
#5I've seen these kind of accusations of spying be made a lot based on misinterpretation of very scant evidence, and without something more concrete I think that's almost certainly what's happening here. A far more likely explanation IMO is that the daemon is doing something like checking for regional availability of the Live Text feature (still somewhat problematic but definitely nowhere near the same ballpark), as partially suggested by this commenter: https://infosec.exchange/@yProd/109698545121198396
Re: macOS phones home when previewing local image files [video]
#6The author of the blog post makes a wild leap (from "A daemon connected to Apple's servers when I used QuickLook on a file" [paraphrased] to "Apple Has Begun Scanning Your Local Image Files Without Consent [...] Stock macOS now invades your privacy via the Internet when browing local files [...] macOS now contains network-based spyware"), with the strong implication that information about those files is being sent to…
Re: macOS phones home when previewing local image files [video]
#7The author of the blog post makes a wild leap (from "A daemon connected to Apple's servers when I used QuickLook on a file" [paraphrased] to "Apple Has Begun Scanning Your Local Image Files Without Consent [...] Stock macOS now invades your privacy via the Internet when browing local files [...] macOS now contains network-based spyware"), with the strong implication that information about those files is being sent to…
Regardless, it shouldn't be pinging the Internet whenever the user previews an image file. No good can come of such behavior.
Re: macOS phones home when previewing local image files [video]
#8Now Apple just moved the search to the OS via an API call to its server, and people are noticing the traffic.
When I worked in telecom, if there was a hit on an image it was reported to legal. Legal contacted the feds. Feds contacted the local PD of the user. The PD would send a cop in to pick up a burned cd. The server would zip all the users data and burn onto a dvd. We wouldnt touch the dvd, the cop would walk into the datacenter and hit eject and collect the dvd. No chain of custody issues.
Re: macOS phones home when previewing local image files [video]
#9Photo hosting services been scanning md5 sums of a database of known criminal images for 20 years. They did that on telecom and isp's since 2000'ish. Google/Apple searched your cloud for mp3s or torrented movies also. Now Apple just moved the search to the OS via an API call to its server, and people are noticing the traffic. When I worked in telecom, if there was a hit on an image it was reported to legal. Legal con…
I'm not sure how photo hosting services doing this for the past 2 decades is related to this when the author of the post explicitly mentions he doesn't use Apple cloud services or products that would trigger such behaviour. This was the OS analysing someone's images, stored locally on their personal computer, and calling back to an API for no discernible reason.
Re: macOS phones home when previewing local image files [video]
#10The author of the blog post makes a wild leap (from "A daemon connected to Apple's servers when I used QuickLook on a file" [paraphrased] to "Apple Has Begun Scanning Your Local Image Files Without Consent [...] Stock macOS now invades your privacy via the Internet when browing local files [...] macOS now contains network-based spyware"), with the strong implication that information about those files is being sent to…
Regardless, it shouldn't be pinging the Internet whenever the user previews an image file. No good can come of such behavior.
Incredibly lazy blog post IMO, if you’re going to write an article and video on an infosec site, take the time to MITM the connection so you can avoid purely tinfoil speculative reporting. Apple likely does not make this easy but it is possible to do anything when SIP is disabled.