Apple CEO Tim Cook: 'Privacy Is a Fundamental Human Right'
npr.org
npr.org
It makes sense, sometimes a really stupid comment (not implying this was the case) can sprawl a really interesting discussion. I often look at the bottom of the comments for hidden goodies.
Maybe it's because I can't read legalese very well, but this looks like tech companies asking congress to codify our rights for the digital age, and to provide a well defined legal framework for those rights to exist within. I'm not really seeing support for sweeping powers of spying; it seems like they're asking for the opposite in fact. Again, I may be misreading that.
1: http://www.bsa.org/~/media/Files/Policy/data/09142015CongLea...
If Apple is serious about privacy they should clarify and affirmatively oppose CISA.
They put other legislations around (I did not inspect them, so can't comment) and among them (in the center so person skimming it might miss it) they put: "Cyber Threat Information Sharing Legislation". They don't mention which bills they are referring to and they made sure that acronym doesn't match CISPA. If you search it you will find that there's no legislation with that name, and the only results you get are CISPA.
Why those companies want CISPA? Because it removes all liability from them when they share the data without a warrant. Basically we no longer will be able to sue them for violating our privacy.
Aka, a Letter of Marque[1]. Some companies really want to be the privateers of the surveillance-industrial complex.
Nothing in CISPA allows them to violate their EULA.
If they had EULAs that violated your privacy in the first place, then that's a problem between you and the company, independent of CISPA.
Problem solved.
And we didn't even involve CISPA!
So I'm still not following why EULA has to do with anything in this context.
Users should also be able to install apps on their iPhones without Apple knowing what they're doing. Personal computing devices shouldn't have artificial walled gardens.
But I agree with him on everything else and think he's a hero for what he's doing.
Look at the Google Play store and the Android ecosystem, which is comparatively more open. If you don't know what you're doing and install apps from the app store without examining them closely, you'll get random ads, trackers uploading your geo-location constantly to god-knows-where, etc.
That's completely orthogonal though, because Play Store is Google's walled garden. What Google allow you to do, in addition to downloading things from their walled garden, is also side-load apps completely separately from the walled garden.
There's no evidence that the ability to side-load causes an increase in malware/crapware.
Apple is fallible. If developers can break out of app review constraints by using carefully included bugs[1] then the only solution is actively monitoring what the apps are doing. If that's the case, what value-add is Apple's walled garden? Just keeping out crappy programs? I think there are plenty of solutions for discovering what programs are good or not, as we've been working on that problem for decades now for computers specifically, and centuries in the general case.
1: http://www.imore.com/researchers-sneak-malware-app-store-exp...
Computer security is just far too confusing and difficult for the non-tech-savvy. With walled gardens people can delegate their security to someone that, while not perfect, is much better at it than they are. For most people this is a huge win. This is what happens to most peoples' computers if they are "open":
https://c1.staticflickr.com/1/99/259360546_504c726d0b.jpg
If someone has a better idea I'm all ears, but I don't know of one that could match the Apple Store for ease of use. Since user experience trumps everything, app stores are winning.
I'm going to repeat that last part, because I think it's very important. Apple's best interests and my best interests are not always aligned. Why should they have ultimate control over what can and cannot be run on my phone.
But in actuality users don't have much option right more so in iOS.They would use the defaults.
Seriously, stop giving the media so much credit. You can trust the Play store as well as you can trust the App store.
http://arstechnica.com/security/2015/09/drop-dead-simple-exp...
If you want to treat users like infants, then you should hereby completely forfeit any and all rights to complain about "tech shortages" and technical illiteracy of end users.
The right thing to do is to ignore it, but on the off-chance that you might be somewhat self-aware, I thought I'd give you the opportunity to catch yourself.
Why the scare quotes? Just because it doesn't provide 100% security doesn't mean that it provides no security.
Which isn't to say I don't think there are advantages to Android's model and that of more open package repositories in general, especially for power users. However most of Apple's base is people who don't care about openness or extra repositories, they want their iPhone to work with a minimum of fuss and not have to worry about malware like you do on Android.
The fact that we can only point to a single (XcodeGhost) cromulent exploitation of the Apple App Store stack is a testament to how good Apple is at maintaining the relative security of the iOS ecosystem.
http://gawker.com/feds-seized-chicago-mans-computers-in-cele...
Those accounts were breached because celebs were phished and not because of bruteforcing, as some people were speculating at the time, or some other vulnerability.
'"In total, the [500] unique iCloud accounts were accessed 3,263 times," the document states.' - http://www.businessinsider.com/fbi-investigation-into-the-fa...
This was a massive failure in Apple's part.
Every single release with iOS has been totally broken security-wise, as can seen from the existence of jailbreaks.
Apple doesn't even require seeing the source code, and so there is no way they can stop malicious applications written to evade detection from getting to the App Store.
And thanks to their policy you must browse with Safari WebKit, which is a nice juicy ~40% browser share target.
Of course, both Android and Windows Phone are broken too, since they also expose oversized monolithic kernels written in C to random applications, but at least Android doesn't require you to give up freedom to get non-security.
The jailbreaks for recent versions of iOS only allow jailbreaking unlocked devices, at which point security is already compromised.
> And thanks to their policy you must browse with Safari WebKit, which is a nice juicy ~40% browser share target.
In iOS 8 they allowed other apps to use the same JIT engine Safari does[1]. This makes me inclined to take them on their word when they say it was previously disallowed for security reasons (some early jailbreaks could be done just by visiting a web page, using security holes in Safari's javascript JIT).
[1]: http://9to5mac.com/2014/06/03/ios-8-webkit-changes-finally-a...
What? You must mean something else because unlocked devices aren't (necessarily) compromised.
I mean compromised in the sense that the malicious party now (for example) has access to the user's email, and would be able to reset a whole host of passwords for online services (assuming they don't use 2FA or something similar, which most users don't). If they wanted to install a keylogger, or get saved passwords, then yes they still have to jailbreak my device. This xkcd is relevant: https://xkcd.com/1200/
Here's a recent report from computerworld - Malware infections delivered via mobile networks - Windows 80%, Android 20%, "iOS and other operating systems were at nearly negligible percentages"
Nothing's perfect but iOS isn't that bad.
(Window's numbers seem to be mostly pcs with tethering. "Data generated from scans by Alcatel-Lucent's Motive Security Guardian technology, which is deployed worldwide by both mobile and fixed-line networks, and monitors traffic from more than 100 million devices")
http://www.computerworld.com/article/2984444/mobile-security...
Virus' primary function is to replicate itself and infect other hosts. You can not simply install apps (or viruses) on other mobile devices without user intervention. Also viruses need access to system and/or other apps to be able to propagate itself, which is not the case on mobile platforms.
None of that things is true for demons.
Btw, iOS also has long running processes if you register proper functionality (VoIP, background download..) when submitting the app to App Store. Also iOS and Android apps can be awaken from the server and perform tasks without user noticing it.
I couldn't agree more with this sentiment. Requiring that all software on your device be signed by a single entity (i.e. apple) is horrifying when you think about where that might lead to in the future.
Like he said, any back door for the good guys is a back door for the bad guys as well.
If apple is ever compelled by the government to not allow a certain app (if they lose in the FISA courts) or if the leadership of apple changes? Stories like this could be just the beginning: http://www.theguardian.com/technology/2015/sep/30/apple-remo...
Why can't iPhones do the same (from a security perspective, I understand the business reasons)?
Also, there a lot of not-savvy people who will follow instructions in a well-crafted email or pop up and allow themselves to succumb to spyware and malware.
Next you'll be saying compilers are backdoors, too. That's not what the term "backdoor" means.
A malicious actor with physical access to your phone
Stop. Physical access means all bets are off.
Tricking a user into side-loading malware does not require physical access to the device and is relatively common on the Android side (more so on third-party stores).
It is a very restricted and time consuming method to access a device.
To censorship[1].
[1]: http://www.bbc.co.uk/newsbeat/article/33280133/apple-removes...
Do you want a General Purpose Computer? Or do you want an appliance that is ultimately controlled by someone else, where you have to get permission[1] if you want to use it in any way that wasn't pre-aproved? What are the odds that the things you want to do will continue to be approved when you ask for permission next year? Or ten years from now?
If someone can restrict how you use your device, you then they are de facto the actual owner of the device. Do you want to own the products[2] you buy, or do you want a future where property rights are rare and you have to lease everything?
The War On General Purpose Computing continues, and the people that wish the Turing machine could be stuffed back in its bottle have been wining small but important battles over the last few years. Apple deserves a lot of blame here, as the walled garden was previously limited to stuff like game consoles, but the the big problem has been the many developers that chose shiny tech, promises of easy development, end-user convenience, and short-term profit over the freedom to tinker with products you actually own.
Of course there will be costs and risks. Fighting this trend toward walled gardens, like any war, will probably require certain sacrifices. I suggest paying those costs now, as price of freedom will only increase.
[1] https://www.fourmilab.ch/documents/digital-imprimatur/ (note: this is originally about publication, but the ideas apply similarly to the War On General Purpose Computing. Also, consider when the essay was written; some technology has changed, but the basic idea is still important)
[2] Many products, not just your "phone" (portable computer). Just look at the rush to throw a CPU and 802.11 PHY into absolutely everything. There are many example, but the current attempt by John Deere ( http://ifixit.org/blog/7192/john-deere-mess/ ) to circumvent the "first-sale doctrine" is a perfect example of what is going to happen to most products if we give up ownership.
Also, stop conflating basic computer literacy (which includes common security knowledge) with the knowledge required to "service the entire engine". We expect people to learn how to drive a car safely. This doesn't require learning how to repair the car or other technical knowledge.
This belief that we should keep users ignorant is highly offensive. If there isn't a clean way for someone to learn the basics of how to use use software safely and securely, that is entirely the fault of the software vendors. Unfortunately, instead of addressing these problems (which is probably hard and expensive), it has become fashionable to blame the victim.
The "VCR blinking 12:00" problem is a good one, because it is absolutely not caused from a lack of capability. The clock on the VCR is often a very low priority for most people, and while those of us that understand technology think it's a simple thing to set it and move on to other problems, for a lot of people, they estimate that it would require finding the manual, reading it for a while, some trial and error, etc, and they judge it's not worth their time. They have more important things to do. The much easier solution is to either ignore it because they really don't care, or wait until the local nerd stops by and bug them to do it. I would even suggest it's a very good evaluation of opportunity cost.
Now, computer security is very important, but it suffers from a pandemic problem: most people are ignorant (which is not their fault) of just how common security problems are, the cost of failure, and the novel problems that technology has created (e.g. automated attacks that make questions like "am I a target?" irrelevant.
You will never solve those problems by taking people's capabilities away. All you've done is give them a false sense of security, because they trust devices based on an incorrect threat model. Educate them, and they will adjust their behavior. This is significantly less technical than learning how to set a VCR's clock.
As for UI - consider the example I used in another comment: include a hardware switch that must be flipped to allow "sudo"-style access for things like installing software. People understand this (I knew a LOT of non-technical people that regularly used the write-protect switch on 3.5" floppies when they didn't want to erase their homework. Simple metaphors like this, when applied consistently (they shouldn't have to use the switch very often) can help a lot.
You will never solve everything; if you had a truly foolproof way make a safe OS for everybody, I suspect you would have solved the Halting Problem. So use technology to catch the obvious stuff and provide tools for people, educate them well (this will take a few generations), and most people will be safe enough.
What you absolutely shouldn't do is limit everybody in a futile effort to try to make it safe for everybody. This is an impossible task, so you will inevitably end up in a cycle where you remove more and more features, as clever people find ways to abuse them.
You claim that if we even allow companies to put out products with locked firmware, it will lead to a dystopian future. So when is this slippery slope going to start? The iPhone was released in 2007, and pretty much nothing has become more restrictive since then (especially considering that pretty much all phones were already locked down). The threat of any computers being TPM locked by the manufacturer, let alone all of them died in its cradle. If anything, we're moving in the opposite direction, since Apple now allows sideloading on iOS devices[1].
And what about users who want a phone that is locked down for security purposes? Why shouldn't we be able to choose the phones we want, while those who want sideloading/flashing choose the many options that support that? If either laws or market collusion actually removes this as an option, I'll join the fight. But for right now, it looks like this war on general purpose computing isn't even brewing.
[1]: http://9to5mac.com/2015/06/10/xcode-7-allows-anyone-to-downl...
Windows. Microsoft, as usual, is late to the party, but Win10 is clearly a step towards the walled garden model. It's not there yet, but stuff like their built in app store and removing choice form the user betray the direction MS intends to take Windows.
Intel CPUs. Why do you think there has been a push for SecureBoot and the new SGX instructions? Hardware support is needed if you want to change WinTel boxen form a General Purpose Computer into a locked down appliance. That hardware support now exists in Skylake and later Intel CPUs. Intel even says on their website that the SGX instructions are about creating "trusted" enclaves that software vendors can use that cannot be accessed by someone with physical hardware access.
> So when is this slippery slope going to start?
It started many years ago. Some of us have been warning about these problems for almost twenty years. When we warned that these technologies were coming, we were laughed at because the threat didn't exist yet. When implementations started to show up, we were ignored because nobody was using those tools yet to lock down systems. Now they are slowly starting to turn on, and you've been given yet another warning. Do you intend to wait until the OS is fully locked down? Or do you want to start to fight for your right to run a General Purpose Computer while you s till have the ability to do so?
Today there was even a thread on HN about homebrew having to work around OSX "System Integrity Protection". Sure, you can disable SIP by jumping through a few technical hoops most people won't understand. Are you going to fight back against this trend, or are you going to wait until you cannot disable SIP "for security reasons"?
Just because you've been ignoring these steps doesn't mean they are not happening.
> TPM
The TPM is only key storage and hashing to check the bootstrap chain-of-trust. The TPM never had any "locking" features. Why are you ignoring all the other hardware changes that have happened after the TPM? Active Management Technology (AMT), Software Guard Extensions (SGX), and UEFI SecureBoot have all happened after the TPM.
> And what about users who want a phone that is locked down for security purposes?
You know what would work a lot better? A hardware switch that had to be flipped to install (sudo) software, and had to be flipped back to boot as normal.
> Why shouldn't we be able to choose the phones we want
Of course you have that choice. That doesn't mean it's a smart choice. You're pushing the (incorrect) assumption that security is in conflict with the end user being able to control their own property. Locking your car door does not require giving up your ability to modify the car's engine. There are other ways to provide security. More importantly, the concept of freedom means that some people will do stupid things with that freedom, but we respect their right to make those mistakes. The answer to malware apps isn't removing everybody's right to use the products they buy as they like, but to educate users and write better UIs that help guide novices.
edit: (accidentally clicked submit before I was done)
"Apple has changed its policy regarding permissions required to build and run apps on devices. Until now, Apple required users to pay $99/year to become a member of Apple’s Developer Program in order to run code on physical iPhone and iPads. As part of the new Developer Program, this is no longer required. Apps can be tested on devices, no purchase necessary."
I don't think I even gave them my real address.
I can't see Apple or Google giving up the cash cow that is their respective garden though.
You aren't a hero for doing or saying something convenient that benefits yourself, regardless of whether it's good and/or true.
At least in China, the "exploited" workers you speak of have chosen to work at factories rather than do the kind of farm labor their parents did. Do you think they would be better off if they were not able to make such a choice? If they were paid the same wages a factory worker in Norway might receive, do you think the manufacturer would choose to open a factory in China?
You describe Cook as just another evil businessman, whereas I suspect he has done more, practically speaking, to lift people out of poverty than most.
Many people have decided that working at Foxconn, etc., is better than the alternatives they perceive as being available to them. Do you not feel somewhat strange judging their arrangement as exploitative? At what hourly rate would it stop being exploitative? How much is it permissible for Tim Cook to earn in a year? Do you really feel able to decide these things?
Are you being exploited? Why not? Aren't your employment opportunities limited by the circumstances of your life, your education, your abilities, etc., just like everyone else?
Personally, hearing stories about their ID's being taken from them, working 2 weeks+ non stop, being forced to fill out forms a certain way, workers committing suicide, etc..are all cringe worthy to me.
Not to say there are no benefits...but that does not mean it can't be better. I'd like to read interviews of people who worked there to see if the job was what they were expecting, worse, or better.
No issue, abstractly. But it seems to me that in this case, Apple is providing opportunities that many people are choosing them for themselves, opportunities that they would otherwise not have. And for the crime of not providing even better opportunities, Apple is being characterized as exploitative. That seems unreasonable and unfair.
> I'd like to read interviews of people who worked there to see if the job was what they were expecting, worse, or better.
I would too. From what I know, it's complicated, and contrary to what a lot of people would expect. For example, there really has been massive discontent at Foxconn, etc. -- because they weren't given as much overtime as promised.
Do I wish that people had better opportunities? So, so dearly. This is probably the deepest emotion/feeling I have in my life, the sense of how fortunate I have been compared to how difficult the lives of others have been, when many of them are just as smart, just as hardworking and resourceful as I am, but were simply born in circumstances that did not grant them as much opportunity as I have enjoyed. This is a big part of why I am in China and why I study Mandarin.
But saying Tim Cook earns "too much", or that factory workers are "exploited" because they make choices that we wouldn't, were we to be magically swapped into their bodies, but with our abilities, or some other imaginary situation that has never existed, is not very understanding of the situation, or fair or productive.
The key, I think, is to realize that if you were the "exploited" workers, you would make the same choices. Really. If you were them, you would do the same thing. Then I think it's more clear that Apple is providing avenues toward better lives, which I see as a very good thing.
To me this seems excessively moralistic, like "all closed source is bad". There are concrete advantages and disadvantages to a walled garden and whether a device has one or not should be up to the manufacturer. Customers then can weigh the tradeoffs when they make their decisions.
I also don't find privacy to be among the significant disadvantages of walled gardens. Lack of choice leading to lower quality experience, the chilling effect of disallowing specific content or entire categories and the potential for price gouging seem to be far and away the biggest issues.
Another issue is "walled gardens are bad" is a bit ignorant of real restrictions device makers have historically had to navigate such as carrier contracts saying no tethering apps.
If they're willing to walk the walk, I don't even mind how transparent this "privacy as a competitive advantage" strategy is.
Having a business incentive that's aligned with privacy is the absolute best thing you could ask for if you want privacy. First because it will ensure they remain committed to it, and also because it shows up the competition and forces them to move in that direction as well.
http://www.apple.com/privacy/approach-to-privacy/
This shows pretty clearly that they "walk the walk".
Probably because privacy concerns weren't mainstream until recently, and it would have looked like an excuse because their services weren't up to par. Which, to be frank, is still the case.
The unnamed search engine company simply cannot afford to offer the same level of privacy as Apple is capable of offering. Meanwhile, the only other supermassive company whose business model might have allowed them to focus on privacy has just thrown in the towel and decided to become as privacy-invasive as everyone else, starting with the recent free upgrade to their flagship operating system.
Being a hardware company that also happens to sell some cloud-based tools, rather than the other way around, sure has its perks.
A depressingly large proportion of the population.
Seriously, why do people conveniently ignore this little fact? Why would these filters exist, as revealed in CLASSIFIED documents, if the government were interested in spying on its own citizens?
If the government were interested in spying on you, they would just do it. They wouldn't need to build machines to protect your privacy rights.
That doesn't make sense. How can you tell who is talking on the phone anyway? And what if a US citizen was talking to a non-citizen?
Regardless, the point is that backdoors - even if used 99% of the time correctly - opens up your phone and all its nitty gritty details of your life to adversaries. IDK how the NSA phone logging worked so I can't really comment on how safe it is. None us can. That's sort of the problem.
But, right now, there exists filters to filter out US citizens comms from NSA spying, as revealed in CLASSIFIED documents.
This is something Snowden's friends love to conveniently ignore, because it doesn't fit into their artificially constructed world-vision of the US government as giant evil monsters.
I thought I recalled Obama saying that all meta data was stored. Regardless...
How did they detect when a US citizen was using a phone abroad, or a terrorist using a landline phone in the USA? Identities are not tied to phones.
Furthermore, how secure is the system they used? Can adversaries tap in to the NSA database? Is the filtering "hard wired" or is it something that is programmable and how susceptible is it to bugs, viruses, or hacking? How trustworthy are the people that control this data? Is it possible that anyone that works at the NSA is not trustworthy and might defect? Such as Edward Snowden?
These are important questions. Even with 'filtering' there is a lot of questions to be asked. And I doubt all them have great answers. The point is, there is a system in place to problematically spy on any phone conversation at any time among other things. Even if they use it "for good," that should be very concerning for anyone that knows that programming secure systems is mostly an effort in futility. Especially for the government who can't even code up a CRUD healthcare website without issue - and that the system is completely closed source not allowing others to review it.
Which brings us to another issue - why was this secret? Isn't this the kind of thing that should be approved by USA citizens? And publically verified for safety and security? This alone is so concerning.
I'm happy you think "filtering" makes all of these questions a non-issue though.
But, right now, the NSA does what is legal, which is to spy on foreign nationals.
We decide what matters when its time to write the laws.
So they don't run algorithms over your meta-data, instead they just give your personal info the the government.
I'm aware Google does comply with government requests too, but also attempts to push back and keep the government honest.
"Apple only disclosed content in response to 27% of the total U.S. account requests we received during the period from July 1st, 2014 to June 30th, 2015"
Source: http://www.apple.com/privacy/government-information-requests...
>But what they don't want to do, they don't want your email to be read, and then to pick up on keywords in your email and then to use that information to then market you things on a different application that you're using. ...
They don't have the technology/infrastructure to perform machine learning techniques that google employs. So they will say 'we think it's a feature that none of our services interoperate.'
That's what we're calling online profiling now?
>That's what we're calling online profiling now?
My Google Now cards on Android say "yes it is". They are driven by email, calendar entries and phone sensors all tied to my profile and it's bloody magical. YMMV.
You're right, it wouldn't be hard, but they aren't doing it. Why? Maybe because they wouldn't be able to use this talking point or maybe they plan to be a hardware/OS company forever and never expand their services? IDK
However, they wish to carefully control the advertising on iOS, if you want to uniquely identify a user for retargeting purposes, well, tracking cookies are evil, but iAd is good!
https://developer.apple.com/iad/my-audiences/iad-my-audience...
>In the spring of 2015, iAd plans to provide developers with unique audience insights about the users in your segments, viewable in iAd Workbench—including their distribution by gender, age, geography, and iTunes Preferences. With audience insights, app developers can find new users with similar characteristics to their existing customers, and tailor messages for retargeting campaign
Did they abandoned this or not? Seems contrary to their current "we aren't using your data" mantra
You mean the machine learning techniques Google developed to better market people things?
This is like saying, Sweden doesn't have nuclear capability so it's opportunistic for them to claim they are peaceful. Only states that pour resources into building nuclear weapons can have a legitimate claim to being peaceful.
Look at Apple's approach to privacy for Maps, which uses randomized identifiers and trip segmentation so that Apple cannot reconstruct your trip. Or iMessage, which uses full end-to-end encryption. That's not Apple failing to catch up, that's Apple going out of their way to protect your privacy.
That's a bit of a cheap swipe. Google's machine learning has been applied to things like spam filtering, image search, and speech recognition.
This doesn't have anything to do with the technical capabilities of each company, it has to do with the fact that my and Google's interests are not aligned. Google, like every other company, is going to do what benefits them the most and there's nothing wrong with that. But when what benefits them doesn't benefit me I have reconsider using their services.
Pretty sure Siri is machine learning...?
Even if it wasn't, they could just hire a bunch of PhD students, maybe acqui-hire a couple of tech companies with their ludicrous amounts of available capital and bam, they have their machine learning algorithm
Not that voice recognition products count as machine learning. Google has a growing neural network, Apple is not competing in that market at all.
Nobody that really understands the problem of no privacy between government or another collecting agency knows enough to weight it on purchasing their device or going with their OS for their phone, tablet, or laptop. If more people knew, how it could be for collecting every single thing from a user, i'm sure apple products would sell more, so I do agree with your point, that it is better to now advertise this.
Neither does IBM, HP, Oracle, Cisco, Salesforce, etc.
In fact when it comes to "major US tech companies", either by revenue or by market cap, I can only think of Facebook and Google that make money mainly from advertising income.
Amazon, the consumer-focused exception, makes their money on physical products not produced by them, and on cloud services—both of which are mostly privacy-neutral as far as third parties go. Amazon knows what you tell Amazon (your shopping history; your AWS API calls) but their business model doesn't involve giving that information to anybody else. They could theoretically take a stance on privacy, but they aren't doing much to enable privacy; just coincidentally avoiding doing anything that negates it.
(And while they may not be specifically selling ads, Amazon's business model is absolutely heavily invested in invasive ad tracking, which was my point. Witness how Amazon products that you look at but don't immediately buy follow you around the Web for fucking weeks.)
The messaging was all about how slick and polished and pretty they were, and how expensive.
Unfortunately Apple failed to realise banner ads are tacky no matter how much polish you throw at them.
The HN crowd absolutely loves using "analytics" to try and divine ways to make their products more profitable. Microsoft even uses this as an excuse for Win10's "telemetry" spyware: they say it's to improve the product. Yet when Apple spies on its users, suddenly it's ok because Apple isn't an ad company.
Apple is using this topic to attack their customers, but they are not exactly on moral high ground.
Sounds like they are taking jabs at one of their biggest competitors, Google.
Further, privacy is obviously a hot topic, well at least in tech discourse. None of my friends are really bothered by any privacy concerns and couldn't care less if Google mines their email to provide targeted ads, honestly... But to the extent that privacy is meaningful to people, safeguarding it is obviously a benefit and thereby something one can sell, and seeing as there've been so many different scandals people probably are at least somewhat sensitive to privacy-centric marketing.
In short, they're selling a consumer benefit while taking a jab at the competition. Not a bad deal, there are barely any cons. Apple never really got into the advertising game, doesn't need to and unlikely plans to. They've had some ad products and neglected it for a long time, probably in large part because ads are a shitty consumer experience and Apple tries to offer the best experience even if that requires higher consumer prices. And finally it's completely in line with Apple's business models on content in the past, creating walled gardens to push paid content (music, books, news, apps), advertising doesn't really fit into that context.
Consider also that it's obviously in line with Apple being the 'nice guys', who recycle materials, appreciate diversity, the artists who just want to be free blabla. Businesses or governments tracking users doesn't fit that narrative and protecting users from these parties does.
And finally, I do believe they genuinely care without any ulterior motive and are willing to push for the things they care about if it doesn't hurt them (much).
With Windows 10, MS is now also an advertising company.
The language of rights does not challenge the fundamental structure of the system.
A few pertinent details:
> The government comes to us from time to time, and if they ask in a way that is correct, and has been through the courts as is required, then to the degree that we have information, we give that information.
Pretty standard stuff. They'll basically give up your info if any court orders them to.
> There have been different conversations with the FBI, I think, over time.
> I don't support a back door for any government, ever.
He doesn't support back-doors. Notice he didn't say there isn't a back-door.
As far as I can tell, Apple will 'give up' your information more or less to the same degree Google will.
Google also runs some algorithms over your data to match an ad to you. Not sure why this is so bad, no data has been given to a 3rd source.
This just strikes me as fluff to attack Google.
BTW, both companies' transparency reports (or at least part):
http://www.google.com/transparencyreport/userdatarequests/co...
http://www.apple.com/ca/privacy/government-information-reque...
BTW - if you compare requests to number of total users of each platform, Apple gives up more data. Not that it matters too much, both seem to comply with applicable laws, although Google's transparency report does seem more extensive.
Either way, not sure I can see the practical difference here.
However, there was the issue that cloud backups weren't encrypted with users' local keys/passwords. Has that been fixed? If not, he's blowing smoke.
http://www.engadget.com/2014/01/24/apples-tim-cook-there-is-...
I thought this was the most interesting quote in the article. I would've assumed the all Apple products would be colluding together, but Cook seems to be saying that isn't the case. That's actually a pretty big gift to consumers, but I wonder what it means up top. Does "Apple" get my news and mail info separately, or do the news app and mail app get their content and deal with it independently of mama Apple? It's a great sentiment - and I can't imagine he'd say it in this sort of interview without truth to it - but it's hard to imagine it in play.
But I think just as importantly this stance is about girding for a fight against government-mandated back doors. After some noise about this from parts of the US government, some important people in government have started to come to their senses, but that doesn't mean it's over, whether in the US or with other governments around the world.
It's become an arms race to the bottom, essentially. To coddle ad companies as if they are mom and pop shops that are struggling is not only naive, but dangerous.
Note that he did not say that no Apple product has a back door.
He also didn't say the camera on iPhones stays off when you're not using them. That must mean they're taking pictures of us and uploading them to Tim Cook's personal sex grotto for him to ogle us, right? I mean, he didn't say they DIDN'T do it, so...
That is to say... perhaps we could keep the paranoia and speculation to things that have a basis in reality?
Oh wait, they can't because that is the majority of their income.
It's worth pointing out that while this was obviously propaganda (or wishful thinking), we now have some proof that this isn't true:
https://www.asc.upenn.edu/news-events/publications/tradeoff-...