A more sensible way of dealing wirh the issue would be to use an open source Android version like AOSP or LineageOS, not run proprietary gapps, and replace its functionality with F-Droid, MicroG and Yalp-store. Your location will stay out of Apple's/Google's hands and you can still enjoy all convenience of a smartphone. Keeping your freedom in your own hands.
This is true, but it's also potentially worthwhile to consider that Apple has positioned themselves as a hardware company (i.e. the majority of their money is based on selling units of hardware), whereas their main competitor here (Google) is an ad company (i.e. the majority of their money comes from selling their users' data). Apple has chosen to highlight their commitment to privacy partially because they feel it helps their market position, whereas for Google, it would hurt it.
Certainly it doesn't mean that Apple is infallible, just that I think it makes it easier to accept that Apple is more likely to protect privacy more than Google.
I'm pretty biased towards Apple, so obviously this may not work for everyone; if you need source code to feel secure, then by all means, go for it. For people who are looking for less work but some of the benefits, I think that Apple is a decent way to go.
But this is all just marketing, whereas the reality is that Apple could also be hoovering up location data and you may never know.
You may have good reasons to trust Apple more than Google, which is great. Others may reverse that position of trust (perhaps they had their iCloud account hacked into and photographs leaked on the internet).
It isn't just marketing. This is how the alignment of incentives works. A company's incentives are aligned with the people who pay them. Apple's are aligned with those that buy phones. Google and Facebook's are aligned with those that buy ads.
Apple's true incentive is to provide value for their shareholders.
If they can improve the value provided to shareholders by hoovering up information while also maintaining consumer confidence and sales then why would they not?
I think that Apple's incentives are better aligned with my desires for privacy, but it's only an assumption.
Because this sort of thing inevitably leaks? Apple has a formula that demonstrably works, a formula that everyone can directly observe making them an utterly stupid amount of money. It would be the height of stupidity to risk their unparalleled monetary successes to pursue a few dirty little crumbs.
Saiya-jin, your comments all appear to be flagged and dead. You may want to contact a mod about this.
Don't attach these emotions where they are not appropriate. Apple is a for-profit company. If they will be pressed hard by US government behind closed doors, they will bulge and you won't know about it, why should you (maybe in 10 years as part of some leak). If they will decide to change their strategy, they will. They have 0 moral issues hiding gazillions of cash offshore from IRS. Just like any other company out there.
Simple fact is, most people don't care about security. I work in IT, and I have numerous friends with iPhones, but exactly 0 of them cares about extra potential security when choosing phones, most have no clue about these issues. Regular people choose Apple because of Apple and how things look and feel, and how they are perceived among others as a status indicator.
Apple has engineered their products to be unbreakable by Apple. That says a lot about their desire to cooperate!
Apple's billions held internationally aren't hidden, everyone knows where it is. And it was never money destined to be "on-shore" in the first place – it's profits from retail sales which occurred in Europe and elsewhere. Their offices in Ireland have the Apple logo on them and they're one of Ireland's largest taxpayers. Everything they do is on the public record. That money wasn't expatriated from the USA, the IRS isn't owed any of it.
According to their privacy policy[0], they comply with requests by the government for user data and inform the user unless gagged.
> In the second half of 2016, Apple received between 5,750 and 5,999 National Security Orders.
If their products are unbreakable, how can they provide this data to the government?
[0]: https://www.apple.com/privacy/government-information-request...
it's going to be less than 1%
... and where are they going to go?
I’d be pissed for an hour but at the end of the day my phone, laptop, watch, TV and car all syncing my music and crap with no effort is too appealing to scoff at.
Hell if I found out they had a meat locker of dead kittens hidden in the basement of 1 Infinite Loop Id probably stay loyal.
What makes you so confident? How do you know Apple thinks of itself as a hardware company whose incentives are aligned with those that buy phones? Their marketing certainly has made a lot of people think that, but, well that's just marketing.
Apple hasn't exactly always stuck with one identity. In 2007 one could have easily said that Apple is "a computer company" and not "a phone company" like Nokia.
Ultimately though, Google and Apple are incentivize to collect data for a lot more reasons than just selling ads. A lot of software functionality on phones benefits from rich user data. Apple may well be collecting data to drive better software experiences, and how much of that data they'll keep in-house vs sharing with third-parties is anybody's guess.
Even if you only consider advertising and hardware in simple terms, Apple is very directly incentivize to advertise new iPhones to current iPhone users. They want you to crave new models as soon as they come out, and to think your current model is kind of lame and old. Why wouldn't they be tempted to leverage user data to do that?
Finally, the vast majority of iPhone users probably aren't so sensitive to data security (the market of people who are is pretty small). So I doubt Apple cares that much about their perception among security-conscious people.
That sounds great but it can not be further from the truth. So are you saying that Comcast and the telcos of the world incentives are aligned with their users?
You buy a game, do you think that it means that the game producer has your best interest at hearth? Apple is filthy rich not because they have users as top priority, but because the extract as much as they can from them. They have a very clear lock-in policy where they try to avoid their users moving to other platforms if they wish so (iMessage anyone). Is that really in their users interest?
> Apple's are aligned with those that buy phones.
For all we know, that's what they want you to believe. The fact that you are so certain this is how they are incentivized could just mean that they did a fantastic job at marketing and making their users believe this image of themselves they've worked on.
Apple has a very strict internal culture of protecting user privacy.
At the end of the day, they still have a way to break their own encryption; they just don't want to set a legal precedent or create tools to allow a third-party to have unfettered access.
Everything they say in public releases is just, "face". It's better than the Facebook or AT&T models of charging for access as a subscription service, but nonetheless I do not believe them when they claim their hardware is opaque to themselves.
Here is a link to their privacy policy: https://www.apple.com/privacy/government-information-request...
It states that they comply with requests by the government for user data, and informs the user unless gagged.
They received over 5000 NSL's in 6 months last year, which seems kind of dumb if they're not handing over data.
I, for one, do not believe that their "secure enclave" is truly secure, that they have no backdoor.
Or, maybe more relevant, how do I get to know that?
The question the GP was almost certainly asking was "how can the public confirm that security of their data is high on the agenda of Apple (and by extension any company), what systems are in place". Without third-party review of open systems and practices I can't see it being possible.
Aside from Apple’s strong stance and history of protecting the privacy of users, we also have security researchers MITM’ing the traffic sent from iOS devices to Apple, and every jailbreak gives an opportunity to look deeper; if they were acting badly, someone would find that out soon enough.
If some surveillance happy government bans some VPN software then Apple is going to enforce that ban much more thoroughly than Google or Microsoft ever could.
If you paid someone (even multiple people/companies) to do professional audit over OpenSSL, it would be prevented.
Now, with closed software you are lost and the only thing you have is a TRUST the SW developer. Because inspecting blbs is much more difficult. And I don't trust them.
Every time I see a comment about an open source phone I am curious if the poster of the comment is actually going to fine comb the code base.
Edit: I was beat to the punch.
Apple has demonstrated time and time again their commitment to privacy and to protecting user data.
Apple does not see user data as something to be hoarded. They see user data as a liability and work very hard to collect as little as possible in order to provide the services they do.
The idea that Apple is going to discard all of this and add privacy intrusion into iOS, doing a completely 180° on their business model and discarding all of their corporate principles, is extremely unlikely.
That alone is a very strong reason to hoard data if you're Apple.
Really the big outlier here is Siri, I'm sure they could make Siri better if they were willing to hoard data, but Apple has demonstrated that they value user privacy much higher than the incremental improvement they'd make with Siri, and violating user privacy would likely hurt their business a lot more than making Siri a bit better would help.
IMO both Google and Apple aren't saints. Apple had a fairly similar headline in 2011[1]. Now watch people here on HN explain why that was completely different. It's a guarantee.
We really should be focusing coming up with ideas on what we can do. My friend for example (and this isn't a perfect solution) but he bought 2 phones, one of these for calling:
https://images-na.ssl-images-amazon.com/images/I/41AwGb3pKCL...
(extremely thin in real life)
And then he caries a smartphone for encrypted chat apps etc. He removed a bunch of hardware chips from the smartphone so even if you put a simcard it it doesn't connect anywhere. Also the microphone was removed and some other things. It works great. At first he had it with the simcard still in, but he wanted more privacy. Personally, I would have kept a 4g only simcard or something, it's kind of a trade-off because now he can only chat on wifi.
It's far from perfect, but at least he's trying something.
[1]https://www.theguardian.com/technology/2011/apr/20/iphone-tr...
Ok, since you’ve so eloquently asked - a local copy of your location history that colllected when location services are turned on is completely different from remotely collecting location data even when you’ve explicitly disabled location services.
Any attempt to say these are the same thing has gone beyond naive to willfully ignorant at best.
Google's entire business is carefully balanced on user trust. Anyone who posits some naive "they're an ad company" nonsense is just muddying the waters. Google is a user-trust company in a variety of spheres, and without that trust they would be annihilated.
Apple does not see user data as something to be hoarded
I've gotten downvoted elsewhere and will gladly eat it up to warn against this utterly ludicrous kool-aid fueled naivety. Apple says whatever nonsense gets a cheer at their latest product reveal. But if you don't think they're desperately vacuuming up data for their machine learning to stay ahead of the game, you should rethink your positions.
I remember virtually identical claims about Microsoft a decade ago, as an aside. Hell, in conversations about Google versus Microsoft, no less. Then Microsoft, you know, started viciously hoovering up user data like there's no tomorrow.
I'm a (mostly) happy [0] Apple customer. The lack of evidence that they are gathering all my bits makes me comfortable to use their products. I strongly feel we'd hear leaks about how they are saying one thing and doing another if they were. Employees of Apple aren't that loyal.
Yet here we are with Google and their "it's better to ask for forgiveness than permission" attitude.
[0] iOS 11 is bad. Just bad.
https://www.apple.com/newsroom/2011/04/27Apple-Q-A-on-Locati...
It is impossible that a unique device submits data about cell and wifi locations in an "anonymous" way aside from putting another party in between (a party that you'd have to trust), and that caveat is outrageously nonsensical to anyone with a hint of technical capability. But we trust that Apple is then mangling it up. Or do they?
And even if a cell phone does keep the same IP address for a long time, I'm confident that Apple is completely ignoring the IP address for each submission and taking only the encrypted location data. Apple has gone to great lengths to preserve privacy in so many other cases, it's outrageously nonsensical to accuse Apple of trying to match IP addresses with location data to identify individual devices (and besides, even if they did do that, all they'd know is the rough location history of some device, but nothing at all about what that device is or who owns it).
My guess is that they don't given that they have a setting in location services called "Wi-Fi networking". But this should definitely be investigated...
Apple is also much better at privacy now. Maybe they'll also change course and then we might as well stop using smartphones, cause we're being treated like sheep.
The non-Siri Apple machine learning is happening on device. This is something that Google would consider doing for 5s, before all in the meeting would start laughing and they'd go for uploading everything.
Remind me again, which company pulled out of China, Apple or Google?
"In 2014, in response to a series of terrorist attacks, China made all Google services almost unusable by tightening its Internet censorship, often called the "Great Firewall of China"
That would only happen if Google didn't comply with Chinese govt. unlike the other company we are talking about.
Apple, on the other hand, is a consumer brand that is wildly popular worldwide. People save up for these devices, they sell out within minutes and people go to extreme lengths to line up in store for them. There would be much more anger for banning them than Google.
I literally just now created, and then deleted, an Apple Id. It's trivial. Why do you think it isn't?
Being fully compliant with GDPR is a mountain of work even if you thought you were doing all the right things before.
In practice, small companies/ start-ups might not be audited / reported / pursued very much but: a) you'll never know and b) at least all the big tech and e-commerce companies are smack on in the sights of several data protection and competition(!) authorities already. We're all scrambling to be compliant in time.
Source: first hand account from running the GDPR compliance project in e-commerce company.
The same goes for banking apps and all official store membership and coupon apps, just to mention a few categories of apps you will have to do without.
Is called cash :) It's accepted everywhere.
>official store membership and coupon apps
Should all be burned anyway. Plastic cards and bits of paper worked fine for decades, you don't suddenly need to run arbitrary code on my pocket supercomputer.
>banking apps
Safer to use the website. My bank authenticates you by having you enter your PIN into a card reader - although they have created a mobile app, the security is strictly inferior as phones do not come with card readers (and the passcode is different from your PIN, making you more likely to write it down).
The basic pattern is, it's either important enough to be worth being a stickler over, or trivial enough to ditch entirely. Personally, I find "not being on F-Droid" as a very strong signal that I should not want to use an app in the first place. It steers me away from malicious code and proprietary lockin. And I never, ever see an ad on my phone!
A lot of people refuse to carry any significant amount of cash. It is a risk factor, especially when at events and shows or just during busy shopping hours, due to pickpockets. An app with verified identity (using the national 2FA login system in my country) is significantly more secure.
>Should all be burned anyway. Plastic cards and bits of paper worked fine for decades, you don't suddenly need to run arbitrary code on my pocket supercomputer.
It's a bunch of silly plastic cards that I then I have to carry around in my wallet or remember to bring from home when going shopping, as opposed to having the app on my phone, which I carry around with me anyway. The app automatically calculates bonuses and rebate collection marks.
>Safer to use the website. My bank authenticates you by having you enter your PIN into a card reader - although they have created a mobile app, the security is strictly inferior as phones do not come with card readers (and the passcode is different from your PIN, making you more likely to write it down).
My mobile banking app is perfectly secure, it uses the Danish national 2FA login system, used for all public services.
You're willing to sacrifice your privacy for this little convenience?
Surprisingly, it’s not!
A non-Swedish friend studying in Sweden recently told me of a situation (I forget the exact details) where she could not pay with cash. They only accepted payment via Swish[^1] (mobile payment system).
At the time she was with a Swedish friend which was the one to pay for both of them, with my friend paying her friend in cash.
[^1]: https://www.theguardian.com/business/2016/jun/04/sweden-cash...
I went to a festival earlier this year and the door tickets were card-only.
Reverse engineering and analysis techniques gives us enough ways to look into that so called "black box" and see what's going on.
So if Apple one day ships iOS with privacy intrusion built in, they will be caught.
I prefer to trust the motives, i.e. Apple doing reasonable things and staying away from funny business because they want to sell me iPhones.
You have to be pro-active about removing them, it's an opt-in choice.
Don't trust: the company fucking privacy because of economic incentives.
Quite simple.
- "People willing to trade their freedom for temporary security deserve neither and will lose both".
- Apple is screwing over developers AS A BUSINESS MODEL (de-value your complements) - and you want me, a developer, to support them?
Android freedom is purely theoretical for most people, including my family and friends. iOS security and privacy support is real and practical.
P.S: Apple is not screwing developers, they're keeping them under control. Time and time again developers have proven they don't care about security or privacy and they need to be forced to obey the will of the customers through APIs which can't be easily misused.
Their entire business model is predicated on the idea that hardware is important/ worthy, and that software should be $0.99 with free updates forever. It's basically the opposite of Microsoft - what MS did to the OEMs, Apple does to the indie devs.
Also: not sure about your family, but I can choose stuff like "what keyboard to use". For me, that's a kind of freedom too.
The stuff that's really good costs money also on iOS. The Abby OCR is 64 EUR, OmniFocus is about 44 EUR, Korg Gadget cost 45 EUR (now 20, maybe a special offer).
What keyboard to use is a freedom, but not really an important one. It's a convenience.
I recently bought an iPad for my parents and that allows them to have a device which is very unlikely to get infected by spyware or malware and I can count on their private information remaining private. That gives them the freedom to use it as they like and see fot, without having to worry. And without me having to keep up with whatever tracking fuckery Google thought up.
It's also my right to question your view that "security is freedom, freedom is insecurity and danger" (ok, I'm mean/ probably misrepresenting the second part. But not the first one - and that alone should give you a bit of pause)
I considered using Android devices, and had to concede that I have neither the time nor the skill to remove all the spyware added by very motivated and skilled Google engineers. It's a losing battle. So I decided to compromise on my freedom to control "my" device.
This decision is not for everybody. But using plain Android should not be for anybody, people deserve better than a peeping tom like Google.
And google does it with Google Play Services. All we have to go on is the historical record of the manufacturer, and apple’s is vastly better.
Obviously a high-quality open-source smartphone would be preferable, but I’m not aware of such a thing (Although I’m hopeful that purism’s phone will be good).
That’s not a great argument when you’re talking about the single most lucrative consumer product in the history of the world. At that point, the risk to your existing product by making an abrupt 180 like that is far too great.
If only HW and chip manufacturers released Linux sources (or ideally had support in the mainline Linux branch) soon with proper drivers (ideally open)...
Manyfacurers keep releasing lots of closed junk smartphones every year :/ but as long as people will continue buying it, nothing will change.
And this would be swiftly called out by someone soon after release, putting a very ugly stain on Apple's reputation. There is absolutely no advantage they would gain from this which could outweigh the PR nightmare.
Another sensible way (if you are prepared to 'phone' a bit more frugal) is a Sony Xperia X with Sailfish. (But check together first.)
Isn't it likely to be more lucrative now? I imagine that the number of people choosing iOS over Android purely for security/privacy reasons is fairly low. I think the incentive exists for them now and they've ignored it.
Smartphone or not, carrying any phone means providing this information to your carrier at all times.
I don't like the idea of sending this information to anybody, but to be honest, Google is the entity that I'm the last concerned with at the moment. Unlike literally every cell carrier on the market, hey have an excellent track record from a data security perspective, and their entire competitive advantage relies on them not providing that raw data to any third party.
You can't have privacy without security, but security by itself does not equal privacy.
The best security in the world doesn't mean that you have privacy if everything you do online is tracked. And no company arguably tracks you more than Google. The volume of tracking data they collect about users is mind-bogglingly gargantuan in scale.
It's baffling how Google escapes scrutiny on their data collection practices, particularly from the tech community who seem happy to give Google a free pass on matters of privacy and online tracking.
Google has much better security than the phone companies anyway, so letting the phone companies know where you are is bad enough.
I had the idea to "red team" myself and find out if there's a way of finding out my location history from shady online data broker and then take countermeasures.
There is no way to ever completely trust a cellular device.
Hopping out of "airplane mode" can be made arb fast.
So, short answer, customer demand. I bet eventually they will get too creepy with the data and demand will happen.
It is only obvious when one enjoys a wealthy life.
There are lots of countries out where people can barely afford something better than a feature phone, and when they do, their hard worked savings are just enough for an Android device.
So about three times the average monthly wage if the numbers I find are right.
(Sneak edit) Just to write it down another way, that means 25% of the average yearly income. For a phone.
For $300, you could get a competitevly specced Android phone with great support for AOSP custom roms. Get one of these, flash AOSP without play services and you've got a reasonably privacy-focused phone.
This has been the case for many years now. https://youtu.be/hPhkPXVxISY
See the second video, which shows a $300 phone of the previous generation beating an iPhone of the latest generation at the time that cost twice as much. I couldn't find a head to head comparison of the iPhone X against a cheap Android of the previous generation, but I expect the outcome to be the same.
> is really good at opening and closing applications.
The video doesn't show speed of closing applications. Opening communication applications is 90% of what users wait for when using a phone, and Android users wait less.
Your artificial benchmarks that measure gaming performance aren't much use to the 99% of users who use their phones more for productivity than for AAA games.
Except for some people living in the Android world. Why is that?
I think it's a bit like people that are denying climate science. They keep looking for new kinds of benchmarks until they find something that fits their predetermined outcome. Some glacier got longer instead of shorter? and boom see no global warming. Some YouTube dude has a video that makes your phone looks fast? and boom look no further. Benchmarks suck!
In this case, they don't, as you can see with your own eyes. That's because the platforms are different.
> Some YouTube dude has a video that makes your phone looks fast?
Every single video that shows app launching has the same result. Don't believe them? Try it yourself. If you get a different result and post it to YouTube, all of your fanboy friends will love it, and you'll get some revenue. The rest of us are happy to use the more productive and less expensive phones.
You're like a person who says climate change is due to solar flares but doesn't actually measure the effect of solar flares on climate to realize that there is a huge amount of warming that is not accounted for by that simple analysis.
The pisser about it, is Motorola, like so many other companies, abandoned it for major updates. It does ostensibly still get major security updates, but...
(unless you're one of the unlucky people with whatever type of iPhone for whom iOS 11 still is borked for some reason, still having trouble on one iPhone 6S Plus with that).
No. The "obvious" solution here is to regulate companies and give huge fines for doing stuff like this, without explicit user permission. Google went through hell in Germany over its "error" in collecting user data from their Wi-Fi hotspots. Why can't the U.S. do the same in this case?
It's not just an absolute privacy outrage, but also an outrage because Google will drain my phone's battery life without permission, just to serve its own interests.
Dont fool yourself that the problem is the "current" administration and the next administration from the "good guys" will solve everything.
I used iOS and Android phones and I like both. However it makes even me nerveous to use a banking application or similar on an Android. Can’t imagine what kind of shit my dad would have running on an Android device with all the fake fishing apps, bloatware, tracking etc going around.
With a non jailbroken iPhone I have a lot more peace of mind.
Do these people not do banking on Windows machines? The malware situation was infinitely worse on Windows - I see an Android device with some unwanted ads maybe once a year from a friend or family member, but Windows devices are a weekly occurrence and the really nasty stuff - like password sealers and banking trojans do exist, but are extremely hard to come by on Android, compared to Windows where clicking a pop-up and a run button could leave you permanently infested.
They don't.
Almost everyone I know does banking exclusively on their phones. I do that too.
Sorry, legitimate Android app developers! I would like to pay you for the things you create, but your neighborhood is too sketchy for me to visit.
Using a smartphone for banking is really dangerous because banks often use a phone as a second factor and compromising the phone gives full access to your bank account. And many phones do not get security updates.
Even with a regular bank account in most of the world at least, it's tightly regulated and you're only liable for a small portion of the loss - on a credit card, generally nothing at all.
Even without OS security updates, generally browsers and other internet connected software gets security updates regularly, I'd trust a new user on Android far more than Windows because clicking an ad would not have a risk of getting them infected system wide without jumping through some serious hoops and involving a few exploits. On Windows that's one Run button press away.
I would argue it the other way round. On mobile (Android or iOS), apps have much fewer permissions compared to on desktop. e.g., one app can't look into the data of the other app. On desktop, it is possible to write a binary which steals user cookies (e.g., https://github.com/rash2kool/cookie_stealer). For all purposes, the binary would be legitimate, and no antivirus or OS APIs would mark the binary as bad.
However, on mobile, one app can't peek into the private data of the other app. So, the Uber app can't peek into my browser cookies.
- banks often use phone (for example, SMS) as a second factor for authentication, for example to confirm transactions. Compromising a phone thereforer provides full access to your account. Some banks even allow to perform payments by sending SMS without logging in.
- many phones do not receive security updates in time. And those updates close only public vulnerabilities.
- while Android has good permission system, many apps have a very wide set of permissions, including permission to read or send SMS messages, or permission to use accessibility functions, so compromising such an app can also be enough.
Ignorance is bliss.
From my point of view, the sandboxing and authorization model of iOS is way better than what is available on Android right now.
You could argue that newer versions of Android provide a way to ask for permissions, but suffices to target API level 22 on your app and you're off of it. And fon't get me started on full disk encryption and buggy TPM implementations on Android.
So.. what do you know that we don't?
No. The alternative is to install Lineage OS, don't install any Google trash, use F-droid only and a Play Store interface if you have to.
[1] http://news.gallup.com/poll/166211/worldwide-median-househol...
Currently I have a iPhone 6 that i got for 200, no contract. Seems pretty affordable to me. In Liberia, maybe not, but I imagine there are millions of iPhone 4s they would be welcome to take off our hands.
For one it's more expensive, I have to pay a hefty price to get a recent Iphone, compared to being able to get a usuable android phone starting at 100€ or less.
Additionally, I'm a primarly linux user and from what I've gathered, Linux is not supported by Apple at all, rather, you have to buy into the Apple ecosystem to properly use an iphone.
Which is the third point; to use an iPhone I need to become part of the Apple ecosystem while most Android phones interop with any OS and Hardware relatively straightforward most of the time.
There is very much a reality of smartphones existing for over a decade before this type of data collection was done. It is in no way required or critical. If it was beneficial, it still should be a setting that can be turned off.
This isn't applicable just to service companies like Google who value user information, even when purchasing from a product company such as Apple has laptops phoning home at an incredibly unreasonable rate compared to MacOS 1-2 versions prior.
It's like having to run a firewall on your own devices to protect yourself from the manufacturer. Can we imagine if our routers do this, or did?
It's not like Google has a monopoly on tech knowledge.
Living in a walled garden to escape prying eyes is sacrificing freedom for security.
http://blog.chron.com/techblog/2013/10/your-iphone-knows-whe...
This is literally from the article:
> “In January of this year, we began looking into using Cell ID codes as an additional signal to further improve the speed and performance of message delivery,” the Google spokesperson said in an email. “However, we never incorporated Cell ID into our network sync system, so that data was immediately discarded, and we updated it to no longer request Cell ID.”
Despite Apple positioning itself as the privacy minded company righteously protecting your personal information, they still share it with 3rd parties to implement products like Siri. They're very secretive and don't talk about that fact and they only begrudgingly admit it when something like a data leak occurs. Do we have any transparency into those companies that Apple is sharing data with? What standard does Apple hold them to with regards to protecting that data? No one knows because Apple won't say.
Apple's stance on security and privacy is as much theater as it is truth. They're in the business of selling you a product and to make it appealing.
The sad fact is they could tell you the new iPhone 11 allows you to fart rainbows but only if no one is looking and people would believe it.
I absolutely agree. They're exerting power the way Microsoft did in the 90s. The latest "feature" of Gmail on Android, where it opens links in a Gmail Browser instead of your default browser, is Microsoft level shit and has me looking for an alternative.
The only way to regain control over SW and to prevent spying and data leakage is by using free software, where you can read and modify the source code, build the firmware yourself. Because as long as there is source released and some company decides to add a tracking functionality, people will notice and make a fork without it.
This is how it works on GNU/Linux for a decade and I am happy I can use it. Now I only wish people stopped buying these smartphones with proprietary blobs tracking them and demanded free software.
Most people are easy (I don't want to say stupid) and don't see the problem unfortunatelly. :(
Always follow the money.
Well, pricey hardware, at least.
> In the case of google they sell you
No, they aren't in the slave trade; they sell ad placement, not people.
It’s not the placement that’s the value that’s being sold, it’s watching the ads that is. So they definitely use your data to sell your attention, which is the currency you’re paying with.
Yes, it is ad placement that is the actual thing being sold. Advertisers hope to get something else out of it (usually sales), but what is actually sold is placement.
> So they definitely use your data to sell your attention, which is the currency you’re paying with.
No, they are selling the placement. The placement is valuable because, in aggregate, there is an expectation that a certain share of the people to whom it is shown will give some attention to it, but the advertiser generally pays by impression, not by seconds viewed × share of viewers attention devoted to the ad during that time.
But, in any case, either selling placement or attention is different than selling the user, which is a flatly inaccurate description used solely because of its emotional charge.
I noticed several chrome instances running on "Task manager" almost all the time. Used Chrome maybe months ago. So I uninstalled. Who knows what they were doing, collecting. I trust them as much as I (would) trust a hustler on the old 42nd street
It would be even greater if you could upload a zip archive of the plugin.
[1]: https://superuser.com/questions/156913/what-is-the-google-up...
What is your life like to where you think not having a cell is impractical.
In any case a smart phone is fundamentally a weak point in privacy/security no matter which one you get.
In the 90s it was inconvenient to be out and about if you were expecting a call. You might be able to check your messages though, by dialing your answering machine from a payphone.
Payphones barely exist anymore, so it would be even more inconvenient. If you need to be reachable at all (nowadays by email/sms), a cell phone is nearly a requirement. If you do not need to be reachable, you still put yourself at a significant disadvantage by not carrying one.
What is your life like where you would not be inconvenienced by not having a cell phone?
Donald Knuth gave up email in 1990. Too distracting. (I dunno but I wouldn't think he has a cellphone)
When I started grad school in '07 I wanted to forgo a cellphone. I couldn't. My advisor was even annoyed I held out on a smartphone for as long as I did (caved in 2010).
In 2013, sick of my smartphone I went back to a dumbphone. It was great until 2015 when I started working at a place so crappy I have to routinely tether my phone for productive internet access.
My point: it's very possible to live w/out a cell phone. Frankly it's not even hard (I "forget" my phone at home). However, unless you're tenured or are otherwise your own boss, you'll be forced to have one.
Mostly pleasant and stress-free. I haven't owned any phone in ~6 years.
This sounds like advertising. Also, I'm fairly sure that Apple also sells data. Indeed, given current privacy laws, it's basically guaranteed that if a company has proprietary software, it is selling data from that software.
They make it very clear that they are protecting data, to a far greater degree than Google offers if you use their ecosystem.
I don't think it's at all fair to resort to an "Everyone is the same" argument here.
Can you point to a source that shows this? This sounds like a lie to me.
Otherwise, the assumption is that they do.
Logically, apple has no reason to be selling our data in even close to the same way that google does. These arguments have been thoroughly outlined in the threads above. Furthermore, showing us the source code would not prove whether or not apple is selling our data, though it would certainly prove that they are collecting it. And even if they showed people their algorithms for differential privacy, you could always make the argument that they were hiding something.
Essentially it seems that there is no condition that would satisfy the criteria. It's obvious that we have to trust apple's word to some degree and that the relationship is asymmetrical. I've been convinced by the arguments about business model / risk outlined above. What hasn't convinced you?
Companies exist (only) to make money. The only reason Apple has to not sell users' data is because they think the reputational and other costs are more than the profit from selling it.
If at some point in the future, the expected costs and profits change to make it profitable, they will do it without a second thought.
If the code is closed source, the users are less likely to be able to tell whether their data is being sold. This reduces the expected costs of selling the data (in PR expenses, customers who take their business elsewhere on principle and so on).
If the code is open source, it's more likely to be more costly to sell users' data, so it's more likely that it won't be worth it even in the future.
Maybe they're even promoting drug use to kids under 5...I mean it's possible.
If they weren't selling location information, then they could just say it:
https://www.apple.com/legal/privacy/en-ww/
Collection and Use of Non-Personal Information
We also collect data in a form that does not, on its own, permit direct association with any specific individual. We may collect, use, transfer, and disclose non-personal information for any purpose. The following are some examples of non-personal information that we collect and how we may use it:
We may collect information such as occupation, language, zip code, area code, unique device identifier, referrer URL, location, and the time zone where an Apple product is used so that we can better understand customer behavior and improve our products, services, and advertising.
Oh. Well. I'll just be hiding in this corner, then.
The obvious answer is not to get an iphone. Today it’s android, tomorrow it’s apple—you’re willingly using a massive closed stack to handle your location at all times. Trust is simply naive.
If you accept you’re trading privacy, security, and money for a massively convenient liability, you’ll be much happier.