That is exactly it. Apple is not good at privacy, they are good at giving you the sense of it. A closed source OS, on proprietary hardware, where they don't even give you root access to your own device, will never be private. You pay them, but really they own the phone and you have to trust them.
But they are obviously very good at making you /feel/ secure and private.
Total security is not possible, not at least by a long shot.
Although, I understand your concern about why people trust these companies. While I don't know the answer just yet, I think one reason is that most these companies are located in Western countries where "rule of law" is considered extremely crucial. Openness about balance-sheets, government policies, and privacy are - to the best of my knowledge - critical in the US.
Now tell me what serious alternative there is for a modern smartphone? Firefox and Ubuntu have abondoned their phone OS, and they had no good working system that could compete with Android or iOS? Windows Phone? How's that better than Apple's offering?
Apple seems to have the best arguments here.
You could try jolla or fairphone or even a blackphone (or one of the governmental only privacy oriented smartphones not available to the general public).
But this is somewhat irrelevant as having a smartphone with a GSM chip is a severe privacy issue in itself whatever the hardware/OS. Even a simple mobile phone is a privacy liability unless you take some precautionary measures.
To get some privacy one has to accept to have less comfort and ease of use, privacy and security are a tradeoff. something only a few actually do.
You can use a free version of Android? Yeah! You are going to lack some stuff tho. Google Play Services provides geolocation services, the app store, push notifications,...
Android is more open than iOS but it’s not really open enough to make a significant difference, not for 99% of users and not really for the 1% that think it is more secure or private because they run a (heavily modified, very old, probably abandoned by the manufacturer) Linux kernel but ignore the baseband and closed source camera driver.
Even the FLOSS nature of AOSP has been questioned for years, but as a manufacturer it's impossible to offer a phone with AOSP, to be able to use android you have to include the Gapps.
Google has slowly been moving functional parts from AOSP to Gapps, the point being to limit the AOSP part and eventually get rid it of the open source part.
And no: AOSP is Android. It's like saying that Linux is not Linux unless you bundle it with GNU-utils and wrapped by Canonical.
A device can be perfectly respectful of your privacy despite being closed and proprietary.
The only difference (IMO) between open and closed platform is that with the former you can have 3rd parties inspect it.
However, unless you have the resources to fully audit an open platform (either yourself, or by paying someone else) I believe you should assume the worst from both open and proprietary platforms.
Which does not mean that open source is synonymous of privacy either, only that one can go further than blind trust to the manufacturer.
As another example, Telegram claims to be the most secure messaging app out there. They have open-sourced their code, but what really matters is what they do with peoples' data on their servers.
> They're not going to open source their entire web infrastructure.
I think blockchain can actually solve this problem once and for all. When data is stored in decentralized nodes, much of these concerns are gone.
Personally I do not trust them and for this reason I have no data plan and no internet on my phone.
1. Privacy of information
2. Freedom to inspect, modify and change source code.
So Open != automatic privacy of information.
The question then really boils down to do you trust apple to be doing what they say they are doing? Or would you prefer to verify it yourself? (open source)
I think Apple is betting that point 1 is much more important than point 2. More people also care about it. Hence the strategy.
Actually the more I think about it the more i realize this may be apples master stroke strategy. Google, Facebook etc. business models are primarily based around monetizing your personal data. Where as apple is saying you can have the same level of services but with out having to compromise as much of your data.
Apple is actually uniquely positioned for this strategy, since the do not need to sell your data to companies. They make their money of the devices.
It's probably one of the reasons google has been moving to more and more devices. To neutralize the Apple threat.
Nothing in your reply counters Apple being good at privacy. Source availability is related to privacy in your own personal opinion.
If you would like to audit each line of source code your phone will run, that is fine, most do not. Personally I like to have it both ways by regularly cracking open various components of iOS in a disassembled (ARM assembly is just as good as source code to some folks).
BUT, there is no 500 gb plan. So everyone who wants more than 200 gb is paying for 2TB.
They are earning more, just in a smarter way
The difference with other big players such as facebook or google is that google business is selling ads based on giving software for gratis and facebook business is being the parasitic middleman between people and their data / online interactions (also company) and scrambling to make the investor story time lie believable as long as possible. They both indulge in strong vendor lock-in.
My point is that apple is not in this to protect your privacy or to defend humanist values but to get more people to buy their hardware for increased profit and shareholders.
Where there is vendor lock-in there is no possibility for freedom and freedom requires privacy. Apple has a long history of being the king of vendor lock-in.
My understanding is that apple does not protect privacy, it merely does not disregard it as effectively as the other big players because apple is different in the sense that its business is selling hardware.
Just look at what the posted page actually says: it presents touch id as secure despite being repeatedly shown otherwise, it pretends a complex passcode is secure but it will not protect your privacy when someone is asking you the code with a hammer. It phrases things in a way to induce the reader into thinking apple does not gather data about users: "Apple doesn’t gather your personal information to sell to advertisers or other organizations." which actually means Apple gather your personal information to exploit themselves and to give away or trade with third parties. And so on...
Being better than the worst does not mean it's good enough.
Here are a few examples: try making a backup of your iphone without icloud or itunes (or manual update of iOS, or restoration) try sending GPS coordinates to a non iphone try exporting your contacts to a non iphone When apple finally offered DRM-free music on the itunes music store but refused to licensed their ALAC lossless codec preventing the music to be listened on other devices until it was reverse engineered[1] try installing software on an iphone without using the app store and jailbreaking the iphone jailbreaking is actually made to remove the limitations imposed by apple to its customers integration only works with other apple products
the list goes on
[1]: https://en.wikipedia.org/wiki/Criticism_of_Apple_Inc.#Accusa...
There is nothing Apple does that even remotely resembles such practices. I want to buy an Android? It'll take some time to migrate stuff, but I've done that before, it's not that hard, just time-consuming. It won't cost me multiple times the cost of buying another phone, and I won't lose any data.
> try making a backup of your iphone without icloud or itunes
Is offering a way to backup a device lock-in? It's the same as "oh no you have to use pg_dump to export a postgres database". Also, there are 3rd party apps you can use to backup your phone. And if you make local un-encrypted backups with iTunes, there are many tools to extract stuff like your messages history, and if you really need to - you can just find the right file, fire up sqlite and browse/recover them that way.
> try sending GPS coordinates to a non iphone
Whatsapp can do that, Google hangouts too - there's nothing stopping an app from doing that? What's your point? That you can't send an iMessage to a non-iOS device? I suggest you have a good look at all the alternatives, which can be installed without a problem on an iOS device btw.
> try exporting your contacts to a non iphone
I've done this on multiple occasions. I've had a harder time exporting contacts from Google than from iCloud/iOS devices. Apple simply uses the vCard standard.
The App store would be a vendor lock-in if I could only install Apple made software from it, which is not the case. I use many competing services and apps on my Apple devices.
And yes, ALAC was a problem for a while, but they did release the en/decoder source code under apache2 license in 2011. There are other things that smell a lot more like vendor lock-in: Siri and the maps integration in iOS, but again, that's more an inconvenience than a real hard lock-in.
Apple is not a charity and nobody thinks of them as such. For example, the "RED" campaign is an effort to sell THINGS, but it also gives money to charity. Seems win-win to me.
However, to dismiss it as a marketing scheme is somewhat disingenuous. It may achieve that, but there are plenty of people out there who simply think they make the nicest hardware. The tight integration is icing on the cake. I own almost entirely Apple hardware. If I thought something else was nicer, I'd get it. I don't.
It's telling how you describe Google in comparison; Google is "giving software for gratis" and Facebook is "parasitic." Google is no different than Facebook: using the person as the product to sell advertisements.
This happened to me enough times that I do not even bother looking up compatibility and consider lineageOS as not an option to save myself time.
> the device you had plans to buy are not supported
Because of said context, one simply wouldn't have the plan to buy that device.
Checking for support is only a click away:
Simply mentioning a laundry list of the myriad things an app will be permitted to do is NOT giving me control over security and privacy.
http://cdn.makeuseof.com/wp-content/uploads/2014/06/03-Angry...
That's not control, that's bullshit.
Apple got permissions right long before Android did: no third party apps have intrinsic permission to use the microphone, address book, location etc until the OS asks me on behalf of that app. And I can always say no if I want.
https://www.howtogeek.com/wp-content/uploads/2015/10/ximg_56...
It works just the same as iOS, where the first time an app wants to use your location/etc it asks android, which shows a prompt:
https://uit.stanford.edu/sites/default/files/images/2016/08/...
And can be revoked as well:
https://img.gadgethacks.com/img/81/78/63633813117897/0/snapc...
Once you grant e.g. permission to access the microphone to an Android app, it can do so at any time without you noticing. Until you manually go to the settings and revoke the permission, that is.
If you change the permission to ‘always’ the banner won’t show.
Mic recording, on the other hand, is always user-initiated and very explicit.
With the pace of Android adoption, the new permission model isn't even present on half the devices that have been tracked on the Android Dashboard. [1] Versions 6 and 7 combined are at 48% adoption as of this moment, according to this dashboard.
On the iOS side, the granular permissions model has been around since the last seven years or longer, IIRC. And iOS devices have a much higher rate of new OS adoption, which means almost every iOS device currently in use has the same permission model for a lot longer.
[1]: https://developer.android.com/about/dashboards/index.html#Pl...
I like to know if an app has access to the network. If it does, don't install unless I trust the parent company.
Actually some of these permissions need to be requested by the first-party apps as well. You can deny the built-in Maps application location updates.
I am particularly interested in storing my photos somewhere, but the details about the encryption have not led me to believe that Apple can't access my photos, which is a must-have requirement to me.
Source: https://support.apple.com/en-us/HT202303
It says 'encryption-server: yes' for photos, but around this table you have the text:
" For certain sensitive information, Apple uses end-to-end encryption. This means that only you can access your information, and only on devices where you’re signed in to iCloud. No one else, not even Apple, can access end-to-end encrypted information."
and
"These features and their data are transmitted and stored in iCloud using end-to-end encryption: - iCloud Keychain (Includes all of your saved accounts and passwords) - Payment information - Wi-Fi network information - Home data - Siri information"
So alas, no photos.
Erm, so could Android apps? You don't need to request permission for internet access anymore.
It is established knowledge that Apple has been for a very long time (and remains) a partner of the NSA's PRISM mass surveillance program.
Apple appears to be doing as much as it legally can to get around that fact, such as in providing end to end encryption on iMessage.
If you buy tech from one of the US big corps, you simply have no more privacy. That is a simple fact.
Do you appreciate what your asking? You're honestly saying if they do something this radical then they're "not serious about privacy"?
If they did move to a country with privacy protection then privacy protection could be considered possible.
I’m not convinced this is somehow more virtuous than doing it automatically. The warrant was signed, Apples hands are tied either way.
Which is precisely why I stopped syncing my images to Google.
It does take a while for things to arrive at all destinations due to my crappy internet connection but for me it works quite well.
Works extremely well for me. Set it and forget it.
You’re gonna be fine :)
You can set this in the photos setting. You have the option to store all content locally while also backing up everything in th cloud. However, none of my devices have the space for 357GB of photos so I default everything to “optimize local storage”.
"Favourites" seems to -almost- have this priority in that they'll more often than not be on the device regardless of age and whether you've specifically downloaded them but it's not -quite- there.
[1] It has been flakey as a weasel's taint in the past.
Besides syncing 357GB requires some serious internet which is a privilege of a limited few.
(There's a crowdfund going on for an official iPhone app for Syncthing: https://www.bountysource.com/issues/7699463-native-ios-port-... )
Just a story, I took a picture of my car three months ago, someone asked me to show a picture of my car, I just went to google photos, typed "Grey car" and voila ... This is the future.
Also, we know Google is actively engaged in mining this data in order to do something. Today it's to improve the user experience which I believe is an honest motivation, but inevitably this empowers a surveillance apparatus that both governments and powerful corporations want.
I think it's worth pushing back a bit on the sort of standard operating procedure of tech companies today, and question where this is all leading. Apple are definitely not saints, but at least they provide something resembling a dissenting viewpoint on the issue of customer data privacy.
- Apple was part of the prism program;
- they denied it;
- their platform is so closed you can't have remotely any idea what's it doing;
I would put Apple in the same bag as anyone else and assume they give away everything and then make a big PR noise to pretend they don't.
Only fanboys or naive people would believe the contrary.
* looks like Apple is trusted for key discovery. Abuse of this trust could be tested with the Mac iMessage client. That can’t detect a targeted attack, of course, but I don’t think that’s what you’re claiming is happening.
A privacy version of the godwin point is mentioning google instead of the nazis. Mention the worst known offender and you'll look better in comparison.
iAd..
It isn't successful though, so i hope you can read between the lines of Apple caring about privacy ;)
PS. I'd like to see if they limit the knowledge of Siri because they care about your privacy.
For me, Google are very good at giving you security settings and then completely ignoring them or resetting them to defaults when you're not looking. This in addition to, if you want to be able to do anything with an Android phone, even things that don't even seem to relate to this, you have to consent to giving Google more data to mine. You can't just turn on your location to allow your weather app (regardless of its backend location provider) to show you your local forecast, you have to consent to sending your location to Google on a regular basis. Granted, with most of the processing done on the Google cloud, it's probably unavoidable now.
My current gripe with them, though, is that I specifically switch off my GPS. Two reasons for this - 1. is battery life. I have no need for my weather app to refresh and then get my pinpoint location (which it will, it just requests the most accurate location available from the subsystem) when the cell-tower location will suffice. 2. is that I have no desire for every app on my phone to be able to work out where I am at any time.
On several occasions, however, I'll be in a commercial establishment (shop, restaurant etc.) and a notification on my phone will appear, asking me for further information about the exact store I'm currently in. I've been asked to review the restaurant or if I know the website for the fish and chip shop I'm standing in. How does this happen? Why, the Wifi-Scanning-in-Sleep-Mode option gets randomly re-enabled, of course. And because Google decided to log the SSIDs and MAC addresses of every broadcasting wireless network when they drove the Street View cars, this information is as accurate as GPS. Not to mention, I switch my wifi off when I'm not using it for battery reasons, and this totally undermines the point of having a Wifi Off switch.
I keep switching this option off and Google keeps switching it back on. I'm beyond fed up with their total lack of respect for my privacy. There's also the fact that, not only do they go out of their way to figure out where I am, they then expect me to answer questions. It's like a man in a Google uniform suddenly leaps out of the nearest bin with a clipboard as I'm either waiting for dessert or walking out the door.
I've experienced the Apple lock-in before with my iPods and I'm not keen to sign my life over to an iDevice, but I am getting to the point where they seem to be the only way out of this cycle.
Is this satire? If there's one thing the open source movement has proven, it's that without the backing of a business very little will happen. If there were some "free" mobile system out there, the only way it could work is if there was a "red hat mobile" type of company funding its development. Random "users" generally wouldn't fix anything just as they don't fix Linux/Mozilla/etc. bugs now.