Isn't basically all your data, everything you type being sent to Apple?
Isn't basically all your data, everything you type being sent to Apple?
No. And I have looked.
Apple is very up front about the features that do and don't talk to the mothership. It has been a while, but I recall that as you go through the setup process, there's always info available telling you when they'll see your info, and more info online. But it tends to be pretty obvious - Apple has slurped up sensitive data before[1], but it did look like an accident, they fixed it, and were forthcoming about what happened.
They're very clear that security related stuff (Secure Enclave - the thumbprint/faceprint data) never leaves the device.
Things I know that talk back:
- App store (obviously, and they care about analytics) - News app (ditto, it is basically a thin web browser) - iCloud (ditto, clearly, and pay attention to the various modes for encryption: IIRC, you need 2FA enabled for the encryption key to not be recoverable on their end. But you should double check for yourself, I don't use iCloud, so I haven't paid attention.)
And looking at my phone on my local net with Wireshark, I also see some chatter that looks like things saving config information, similar to what you see on a Mac. I'm guessing this is them just not being careful - they want everyone backing up to iCloud, and even though I don't, various daemons keep nattering. I block all that stuff when on wifi (both Mac and iOS), with zero problems.
On iOS, you mainly need to be concerned with third-party apps. Some of them build in shady libraries for adtech shitheads, do stupid things with analytic/instrumentation libs, etc. The ecosystem seems less bad than Android, at least.
As close to a bottom line as I can come: turn off cloud backup and the syncing crap, use 2FA, don't download sketchy free games that ship your data to some guy in Romania, and you're leaking significantly less than on Android. Take more precautions (a content filter/ad blocker more aggressive than the defaults, disable wifi and bluetooth to avoid snoops along wherever you go, run your own mail/calendaring, etc.) and you're in pretty good shape, relatively speaking, and depending on your threat model.
[1] IIRC, location data was being logged such that it ended up being sent back in crash reports.
Issues with iOS include:
* iCloud not encrypting data securely serverside (i.e. they can potentially get at the data). You can avoid this by not using iCloud. * They have Ads in app, and now in the Appstore directly. Potentially this changes the dynamic, between user/advertiser in a negative way.
There are probably other issues... but I'm not currently aware of them. Overall it still seems like the best option from a privacy perspective.
When I didn't used 2-step, I forgot my password, called them and they reset it for me (I had to confirm my identity providing them a code sent to my mac).
"All iCloud content data stored by Apple is encrypted at the location of the server. When third-party vendors are used to store data, Apple never gives them the keys. Apple retains the encryption keys in its U.S. data centers."
and
"iCloud content may include email, stored photos, documents, contacts, calendars, bookmarks, Safari browsing history and iOS device backups. iOS device backups may include photos and videos in the Camera Roll, device settings, app data, iMessage, SMS, and MMS messages and voicemail. All iCloud content data stored by Apple is encrypted at the location of the server. When third-party vendors are used to store data, Apple never gives them the keys. Apple retains the encryption keys in its U.S. data centres. iCloud content, as it exists in the subscriber’s account, may be provided in response to a search warrant issued upon a showing of probable cause."
So in short, Apple retains encryption keys for much of the data (including iOS backups), and will provide decrypted data to US law enforcement on request.
https://www.apple.com/legal/privacy/law-enforcement-guidelin...
Much of the data listed as encrypted on server is available to US law enforcement under warrant.
It would be nice, to have an option available where data is encrypted on server, with your key. But that would mean you couldn't recover your data if you lost your key of course (and I think Apple consider that a poor user experience, or are under pressure not to do that...).
AFAIK iCloud backups are not end-to-end encrypted. I believe this past February Tim Cook, or someone else at Apple, was indicating that they were working on changing that. (It was coming up because everyone was wishing the San Bernardino shooter's phone had been backing up to iCloud, so they wouldn't need to get in the phone, they could just access the iCloud backups—IIRC.)
https://www.apple.com/legal/privacy/law-enforcement-guidelin...
https://www.macrumors.com/2014/10/20/apple-spotlight-suggest...
see also
http://bgr.com/2015/04/01/iphone-location-tracking-map/
I recommend don't trust Apple. It's not your code, it's not your hardware.
So turn off Spotlight Suggestions? Obviously if you're searching the web there will be traffic to the search engines.
> http://bgr.com/2015/04/01/iphone-location-tracking-map/
Frequent Locations is on-device only.
It may be on-device only but it's not clear to the end-user that it's happening at all. No visible setting to disable it and vulnerable to malware.