Forget iPhone X–Apple's Best Product Is Its Privacy Stance
time.com
time.com
I believed everything in this until something that happened in late July this past summer.
In China, their fastest-growing market, China demanded all secure messaging and VPN apps be removed from the App Store and Apple complied.[1]
So privacy matters, unless it's in your fastest-growing market.
I intend to discuss with Tim next time I see him.
1: https://techcrunch.com/2017/07/29/apple-removes-vpn-apps-fro...
How about when Apple removed apps from developers based in Iran because of US sanctions?
https://www.nytimes.com/2017/08/24/technology/apple-iran.htm...
Your tone of voice seems to indicate you don't think that's actually an option.
Cook would immediately be fired by the board. They’d put someone new in, and that someone new would comply with China’s demand.
And no one would be better off. As Cook says at least Apple does the best they can and holds the line on other things like encrypting iMessage.
Somehow, that didn't happen when Google effectively withdrew from China.
If Apple were to pull out, even if the board didn’t fire Cook for that... would they be able to make phones? Is ANYWHERE on Earth capable of that other than China? I suppose you could buy all the parts from China and have them shipped somewhere else to be assembled but what would that do to the cost of the devices?
Would anyone buy an iPhone that starts at $1500 or $2000?
Probably, yeah. It doesn't seem like people mind paying $1000. It would just make it even more of a status symbol.
Are iPhones a Veblen good?
That would indeed take courage and principles on Cook's part. If the board had courage & principles they wouldn't fire him. And if they did — they'd demonstrate what sort of men they are.
> And no one would be better off.
Tim Cook would have his self-respect.
> Tim Cook would have his self-respect.
I agree. And I hope he’d hold the line.
But I think the people of China would be worse off. Stockholders would be worse off. Apple would be worse off, which means as an American buying heir products it might make them slightly worse for me.
Which is what Google pretty much did:
https://en.wikipedia.org/wiki/Google_China#Ending_of_self-ce...
So in the end, Chinese people wouldn't just lose 3rd party VPNs (the first party ones are AFAIK still present in iOS), they would lose all the security features.
Is that still worth the moral stance?
That's exactly what Google did:
https://googleblog.blogspot.com/2010/01/new-approach-to-chin...
As far as I’m aware, from a privacy perspective, Google never had moral problems doing business in China. They’re just using it as a convenient excuse that makes them look good.
In other words, government censorship and attempts by the government to undermine user privacy were ultimately what led to the move out of China. The straw does appear to have been the hack, but the ultimate goal of the hack appeared to be to steal user data.
>Second, we have evidence to suggest that a primary goal of the attackers was accessing the Gmail accounts of Chinese human rights activists.
It's one of those things we choose not to talk about because it's very uncomfortable to see where our loyalties actually lie.
We have stay continuously aware that this is probably a temporary situation and laying all your eggs in one basket is a bad idea. When governments of larger economies start forcing their hands with bans, etc., they will follow the money.
In hindsight, I think the popularity of macOS among UNIX fans has been detrimental to the development of open source software and open ecosystems that can provide more long-term privacy, by sucking a lot of manpower/energy out of the Linux/BSD ecosystem. (I am also guilty as charged.)
Thanks to the rise of macOS windows has become a second class citizen for many development tools.
The non-gui layer of macOS and Linux can for the most part easily be shared. It means open source developers of non-gui tools have a much bigger usergroup and potential contributors.
I am not bombarded with ads when I use iMessage on my Mac like I am when I use Skype on my Windows PC.
Apple has built in support for third party ad blockers. Google would never develop a system to allow ad blockers in Chrome for Android.
* iMessage still uses end-to-end encryption for messages in China.
* iPhones sold in China still utilize Secure Enclave for privacy/encryption.
* Aggregate data still uses differential privacy in China.
The government made a request of them which did not compromise their user's security, and they obliged.
Compare that to when the US government requested backdoor access pass Secure Enclave and they absolutely denied that request.
I agree that it's unfortunate for Chinese users that their government is placing additional limits on the available software in that ecosystem (as well as other ecosystems, I'm sure). But so long as the government is not asking Apple to compromise its users privacy I don't see any strong relation to corroborate the idea: "privacy matters, unless it's in your fastest-growing market".
Do you think Apple would refuse to swap out the public keys if ordered to by the government? Have you ever wondered why iMessage doesn't allow out-of-band key verification?
The Verge's recent technology survey showed that at least its audience believes that Google and Amazon are better protectors of personal privacy than Apple, so their strong stance on encryption and privacy is not yet completely effective in differentiating them from competitors. Hopefully articles like this will enhance the perceived value of privacy, because we need both private and public entities to agree on privacy for it to be effective.
That is true, but in the US a big problem is that part of the government is breaking the law with its surveillance. In that situation technology can help quite a bit. The constitution states that the government needs a warrant to search ones private papers. Encryption works great against illegal government snooping. When the intelligence agencies and Congress starts talking about requiring back doors, like the Clipper Chip or the Apple request, society can hear about it and push to keep the back doors out. Worked with the Clipper Chip at least.
For now. I argue that there will be a technology corporation more powerful than the reach of any nation-state within 50 years.
I’m not wishing for any particular outcome, but considering past convergences and future potential, I’m simply saying it’s likely that some kind of smart contracts operating on distributed computing platforms will eventually become standard processes for law enforcement once computation is more ubiquitous.
I still think there is a market driver (China TAM) that motivates the behavior as much as anything here. I guess we'll see if the slope is slippery or not.
let’s not forget, in China the government controls the entire internet. If Apple didn’t want to take down the listing, they could easily pull down the entire AppStore (if not all Apple services) with one phone call, just as they did with facebook.
It might stop a really egregious violation (spying on political rivals for example), but for general public the protection is pretty weak.
Until a large chunk of congress, and probably the R chunk due to their privacy law stance, gets a TON of embarrassing stuff leaked to the public or better yet ‘shared’ when they weren’t expecting it... I don’t think anything will change. We won’t get real laws to protect people.
And a decent sized part of me says not even incidents like that would do it. It would just be blame-the-victim and you-accepted-that-policy and the laws wouldn’t really change.
Mass surveillance is too enticing to give up so easily.
If by "deployed" they mean "interviewed about their work". I don't understand Time crediting Wired with the research[0], which does a disservice to their actual sources of funding.
Apple's stance on privacy is making a virtue out of necessity.
[1] Yes, yes, I know: iAd. But how well did that work?
There are reports that Apple has an internal committee, including a high level executive, dubbed their "privacy czars" which are required to unanimously sign off on any instance of user data collection, and this committee has actively limited products like Siri over concerns [1]
There's also the San Bernadino customer letter, which has become a defining point in their privacy history [2]. They didn't have to publish that letter; they could have fought it privately or not fought it.
There's really no fundamental reason why iAd couldn't have become a more powerful revenue generating part of their platform. They sell enough iPhones to reach a broad market. But, per [1], reports say that the team ran into internal privacy concerns which constantly forced limiting its capabilities.
Apple is fundamentally different, in ways that can't solely be explained by their product history and revenue sources. Companies like HP and Samsung make consumer hardware, but also generate revenue by selling their customers' data to third parties. Its clear to me that Apple does consider Privacy a revenue-generating product that they sell.
Of course, you can argue that maybe they wouldn't take that stance if they weren't so successful in hardware; that Privacy is a privilege afforded to them because of their success, and less successful companies need that advertising revenue. But now we're arguing hypotheticals, and I'm not going to partake in that.
[1] https://www.reuters.com/article/us-apple-encryption-privacy-...
May you please elaborate on this > Apple is fundamentally different.
What you said is just a little confusing considering that they all (the companies you mentioned) manufacturer hardware in some capacity.
>advertisers became increasingly perturbed that Apple refused to give them access to the wealth of data iAd had on its consumers from Apple's hundreds of millions of iTunes accounts. And it moved slowly to keep up with the latest ad-tech developments, such as cross-device retargeting.
Stefan Bardega, media agency ZenithOptimedia's chief digital officer, told us: "iAd has long been a story of unfulfilled potential. Apple has unique customer-level data that is hugely interesting to advertisers but has struggled (despite talented sales teams) to access that data in a way that doesn't conflict with the core business."
Another media-agency director who asked not to be named told us iAd got little support from the wider Apple organization
He said: "For me, they never understood that they needed to behave like a media owner, rather they could go it alone charging what they wanted, not sharing data, no third-party tracking
http://www.businessinsider.com/why-apple-is-pulling-direct-s...
Maybe iAd could have performed slightly better if certain policies had been different. But iAd still had to compete with Google and Facebook whom by virtue of reaching effectively everybody, offer a much more attractive value proposition to most advertisers. Apple simply can't compete with that. And every decision Apple would have to make in order to be more competitive would be at cost of harming the user experience of their products, ie. the very thing that makes them able to charge a premium in the first place.
Of course, you can argue that maybe they wouldn't take that stance if they weren't so successful in hardware
That's not the argument I'm making. At all. My argument is that advertising as a business model is fundamentally incompatible with selling premium hardware products. To be succesful at one means making strategy choices that prevents you from succesful at the other.
For instance:
>Apple doesn’t like to hand over information about its users, not even to benefit its own business. When the iAd team wanted to use information about users’ iTunes purchases to target ads, Apple execs said no way.
https://www.macworld.com/article/3046539/privacy/how-iads-cl...
Ads in apps themselves I'm reasonably ok with (just avoid those apps). But having an unavoidable advert in the Appstore is annoying.
Overall however, I find it to be a minor annoyance.
Make sure it's known that you're buying their product because they support your interests. They will hopefully see that it's good business to continue doing so.
That's a much more robust way to get the products (and ecosystem) that you want than by praising them.
That's commonly known as praising a company. "Thanks, Apple, for supporting privacy!"
But that doesn't make clear why you're buying their product, or which of their attitudes you want to reinforce.
I have a corp Macbook, but no Apple products bought out of my money.
Facebook, Microsoft and Google collect all your private information and share it with themselves, the government and some with the advertisement industry.
Apple collects some of your private information and is forced to share it with themselves, Nuance and the government (subvertly see snowden and interpolate).
Amazon is in a special position.
I'm always interested when people say this. Say I want to buy some person's data. Is there a way I can do that with Facebook, Microsoft, or Google?
They do it ‘the other way’. You say “I want to buy some eyeballs like X” and they sell you access to the eyeballs.
But they don’t give you the person’s information.
External companies? Perhaps if they partner with Facebook but not normal ad buyers.
At least my friends that work there claim otherwise, but obviously they are biased. But so are you, I suspect.
But that’s good to hear. That’s what I would hope.
[1] https://www.popsci.com/apple-cares-about-your-privacy-unless...
The only reason I would consider getting an iPhone too is Apple's privacy stance. They seem like the only company in the big five (Alphabet, Amazon, Apple, Facebook, Microsoft) that don't seem to be that interested in my data. They just want to sell me the product, and that product is, in essence, a piece of hardware.
http://www.businessinsider.com/uber-iphone-app-secret-access...
Apple always refuses to comment on bugs, security holes and basically anything they can not use for marketing. You WANT to believe that Apple is better.
They signed on to PRISM https://en.wikipedia.org/wiki/PRISM_(surveillance_program) , they happily work with the government over user privacy in articles all the time, and those are just the things we know about. I'm sure there are more PRISM-like back room government deals that we haven't heard of out there, and I haven't seen anything that would make me believe that Apple wouldn't sign on to them.
It is completely unrelated.
Intel ME is about a remote servicing interface that exists on all current Intel processors. While it has some usages for managing computers in a corporate setting or managing servers (keyword to look for: Intel Active Management Technology (Intel AMT), which needs Intel vPro), it exists on nearly all current Intel processors (except, I think, Intel, Quark; but this processor is built for completely different purposes). Thus there are rumors that it is a backdoor for, say, 3-letter agencies. I don't want to spread any rumors here, but just say: Because Intel ME is very large and complicated (according to https://www.youtube.com/watch?v=iffTJ1vPCSo 5 MB in size) it is a real concern that lots of security gaps will be found (and some have been found in the past), which, because of Intel ME's structure (according to https://schd.ws/hosted_files/osseu17/84/Replace%20UEFI%20wit... it runs on ring -3) can easily lead to really dangerous security holes. Just for this reason alone any responsible admin should try to disable Intel ME so that this security liability does not have to stay open.
PRISM is a surveillance program by the NSA.
And yet, making the actual switch is a tremendously difficult task. On the software side alone, it requires recompiling every application you want to run on your platform. That doesn't even touch the cost of rolling the actual hardware. There are more than a few examples of this: Intel's Itanium, Oracle's SPARC, Berkeley's MIPS, Transmeta's Crusoe, etc. Sure, these all had niches (embedded systems, research hardware, a few high-end servers) -- but breaking out into the mainstream (a.k.a. like x86-64 and ARM/ARM64) is damn near impossible.
- Less bugs
- Potentially better applications since the lower layers are stable and don't require you to fight it (as an example, pre vulkan drivers were hell, linux software has to circle around that)
Nobody expects RISC-V to beat i7 or Ryzen in any benchmarks.
IMO its purpose is to be the in hardware what GNU/Linux was in software.
edit: GNU/Linux, not just Linux :)
Crusoe and ARM were not about the promise of better performance, but of being much more energy-efficient for the intended purpose (though since a few years ARM tries to get into a (more) high-performance field).
What I wanted to say is that the major selling point of RISC-V would be its open-ness rather than anything performance (or power) related. In that respect it has already captured the attention of interested parties, regardless of that the actual performance will be.
That's definitely a great reason to get one. A nice bonus you'll find, once you do, is that they're nowhere near as fragile as you fear.
NSA likely exploited the SSL vulnerability in iOS 6.0 (released Sept 2012, NSA added Apple Oct 2012) and got access to snoop on Apple's data.
After pulling the phrase "participate knowingly" out of thin air, Washington Post was forced to walk back that statement:
"Hours after the news broke, and every company bar PalTalk and AOL denied any knowledge of the program and allegations of their involvement, the Post has changed its stance. The phrase “participate knowingly” has been removed from the article, a new passage suggests the firms were unaware of PRISM"
https://thenextweb.com/us/2013/06/07/wapost-backtracks-on-cl...
Are you really suggesting that prior to Sept 2012 there were no critical zero-day vulnerabilities to which the NSA had access? Surely by your reasoning, Apple should have been included in PRISM years prior. And yet, it wasn't until after Steve Jobs died that Apple began to participate.
As someone who uses free software and worked closely with some mobile privacy-related projects, it's headscrambling to see iPhone users talking about privacy. I won't use it; you're free to do so, but when it comes to your privacy, it's just a delusion. At least be aware of what you've got - no security and privacy is way better than a false sense of it.
Android is far from perfect, and I still hate it, but at least I can still control most of it.
and not just you :P
>Jailbreaking permits root access to iOS, allowing the downloading and installation of additional applications, extensions, and themes that are unavailable through the official Apple App Store.
I'd say I _mostly_ disagree.
Many times over the years there have been "major" problems (i.e. antenna-gate and bendgate to name a couple). I've never experienced those issues, and I'm sure neither have many others. The iPhones through the years have been mostly solid for me in terms of hardware without significant design flaws.
Now, I don't try to claim iPhones are perfect, but I think this is an over-reaction.
It took two years for Apple to acknowledge[1] that #staingate was a real issue.
I do think their hardware is generally high quality, but there are holes, and they are magnified by their positioning as a premium brand and certain high-profile denials of said holes. Which for a brand that lives and dies on its reputation seems less than smart. Adding to the weirdness is that I've alternately received excellent support in cases of hardware issues, and next to none. My guess is that the frontline has a whitelist of issues that they can okay, and have no little latitude beyond that.
[1]: https://www.macrumors.com/2017/02/24/apple-extended-anti-ref...
Only data I could find, but very, very old (only covers to iphone 4(!!)
https://www.squaretrade.com/cell-phone-comparison-study-nov-...
> Anecdotally (but with n = many), I see many more scratched/broken iPhone screens than premium Android. Similar prices, same peer group. There are probably other sources of selection bias I'm not seeing, but it's a large enough effect that I'm cautiously positive of my determination absent an actual survey.
This is such a handwavy statement.
Fragile, compared to the competition? Can you point out any objective measure that supports "Unbelievably" fragile?
All modern phones are fragile. Some slightly more than others.
> Anecdotally (but with n = many), I see many more scratched/broken iPhone screens than premium Android. Similar prices, same peer group. There are probably other sources of selection bias I'm not seeing, but it's a large enough effect that I'm cautiously positive of my determination absent an actual survey.
I don't much like Android as a system but at least I can strip it of Google services and install a firewall and feel reasonably private. It's not an ideal option but it works.
You might be thinking about not being able to have an antivirus? In which case, that is certainly a feature - not a bug. Allowing the privileges required to enable an AV to operate on iOS would severely degrade the security of your device. The losses would massively outweigh any potential benefits of having an AV.
Many apps connects back frequently -- sometimes every action I take. Enough!
iOS does not allow fine-grained control over outgoing network access. The assumption is that the user trusts the application to not do anything untoward, after all it was vetted by Apple before it appeared in the store. There are ways to get this type of control on iOS but since the first step you need to take is to 'jailbreak' the device this is not a real solution.
Android does allow this type of control through a multitude of firewall (i.e. Linux iptables) configuration applications. Android devices running version 3.x or earlier need to be 'rooted' to gain access to the firewall configuration, later versions (from 4.0) don't require rooting. The 'no-root' firewall works by routing all traffic through an on-device VPN (which can be instantiated without root access as of Android 4.0). This does mean the firewall application gets access to all network traffic, making that type of application a good target for those who wish to subvert Android network security.
Interesting location identification for the request origination - https://www.dropbox.com/s/v9rtg1igl73gf67/where.png?dl=0
Now, I've seen 2FA requests a couple hundred miles off, but this is _way_ off. I'm in the suburbs of metropolitan Detroit.
For a lark, I googled 'NSA Texas' - https://goo.gl/maps/rb1AhG3EiE62
Hello NSA! You might want to review the process on that one.