Tim Cook says Facebook's collection of user data 'shouldn't exist'
businessinsider.com
businessinsider.com
At Facebook the understanding seems to be more Orwellian community like, spearheaded by Mark Zuckerberg. They envision and build a future where everyone is under surveillance at all times - so collecting a bit more doesn't matter, more to the contrary. Last week there was a story that FB internally also does surveillance on employees and they know what employee click and hover over on, and they monitor their messenger conversations. And it's all okay in their world view. Good to see some balancing conversations.
I believe Apple took even a toll and fell a bit behind the last few years in regards to eg. Siri as they take personal data more of a liability rather than an asset. So, much respect from my side to Apple and Tim Cook for this. And I'm really not much of an Apple fan, but reconsidering with statements like this one.
- https://appleinsider.com/articles/18/03/23/apple-supported-c...
https://www.eff.org/deeplinks/2018/02/cloud-act-dangerous-ex...
> They designed iMessage in a way that ensured they could access the conversation
Neither of these sound correct. Can you explain more or link a source on either?
On iMessage, the encryption keys are managed and accessible by Apple. Steve Gibson makes regular references in his podcast, like this episode: https://www.grc.com/sn/sn-574.htm
Actually, the device asks during setup whether you want to enable location services or not. They are also configurable per-app, obviously
For iMessage, I think you are getting something mixed up. Apple does not have your encryption keys, but like Signal it does control the server used to retrieve keys for your interlocutor(s). This is a trade-off based on the fact that most iPhone buyers likely do not have a desire to run their own server nor would they probably be able to get their friends to all use it. However, apps are available in the App Store if you do want to do that.
http://money.cnn.com/2018/02/28/technology/apple-icloud-data...
Apple will hand over all user data in iCloud to any law enforcement agency with a warrant [1]. That doesn't conflict at all with calling for privacy regulation. China has enacted a data localization law, and they aren't the only ones that are doing it [2]. The CLOUD Act is related to this issue.
Apple retains control of the keys for iCloud. The iCloud services that are end-to-end encrypted remain so. Apple also informed all their Chinese customers prior to this change happening.
You could argue that Apple should leave the Chinese market but that isn't realistic because it's a large market to sell to and where all of Apple's production takes place. Shutting down iCloud in China will have no practical benefit to Chinese customers (and likely make them worse off).
The common retort is to point to Google taking a big stand on principle in leaving China. But if that's the case why haven't they also left Russia and Turkey? In fact they've complied with Russia's data localization law [3] and Turkey's censorship [4] to avoid being blocked. And they're attempting to re-enter the Chinese market [5].
Apple is not a state actor and can't do anything about China's laws other than lobby against it, which they did [6]:
>“While we advocated against iCloud being subject to these laws, we were ultimately unsuccessful,” it said.
Fortunately the rule of law prevails in the US, and it is certainly well within Apple's rights to lobby for privacy legislation. And I hope they do.
[1] https://www.apple.com/privacy/government-information-request...
[2] https://www.servers.global/meeting-the-challenge-of-data-loc...
[3] https://www.wsj.com/articles/google-moves-some-servers-to-ru...
[4] https://www.nytimes.com/2015/04/08/world/europe/google-turke...
[5] http://www.scmp.com/news/china/policies-politics/article/207...
[6] https://www.reuters.com/article/us-china-apple-icloud-insigh...
Facebook's business model is unlike Apple's business model in that it does not make money from sending 12-year-olds into cobalt mines.
https://www.amnesty.org/en/latest/news/2017/11/industry-gian...
A recent change in procurement doesn't change the fact that they grew their business on the backs of teenagers who were sent into unreinforced holes in the ground to dig while kindergarten age children crushed the ore without the benefit of any protective gear.
I'm an iPhone user and I understand the world is a messy place. My point is it's rich of Cook, whose sub-contractor had to install nets outside of windows to prevent suicides, to lecture Zuckerberg about morals.
At the end of the day, Facebook has built an incredibly powerful adtech platform. An unpopular person used it to get elected. That's bad. Tim Cook's career has been spent building workplaces that either crushes spirits, leading to suicide, or literally crushes bodies in mine collapses.
This is the kind of response that I am increasingly finding indistinguishable from propaganda intended to sow discord.
I'm calling out the CEO of the largest corporation in the world for moral failings in his business model. I wish higher profile reporters were doing so.
The goal is not to sow discord, it's to highlight hypocrisy.
I’m sure Apple has a long way to go on several fronts, but one sided hyperbole like in the above comment is unproductive.
Like I said in the OP, I know the world isn't perfect. Normally, I wouldn't call out Apple. But when Cook decides to lecture about the dangers of social media and privacy and calls for more regulation, which would also weaken his competitors, he should have his bad practices brought to light.
All that said, I wouldn't highlight Apple's supply chain failings if their CEO wasn't out chastising competitors for the undesirable traits of their business models.
At the end of the day we all checked off Facebook's EULA and Privacy Policy box and uploaded thousands of artifacts from our lives onto the platform. Perhaps it was a bit naive and overly trusting, but it was our decision. This does not dissolve Facebook of its ethical responsibility to not abuse customer data, but we, at the same time, shouldn't think that we're handing off our private data to some benevolent force that's just going to hold onto it without using it for their own gain.
TBH what disturbs me the most is how much data Facebook has on people's children. There's going to be an entire generation of people whose conception to high school graduation has been archived in Facebook servers, without their consent.
I find it unsettling that Facebook has built profiles on kids who can not, legally, _give_ consent, I mean, at all. Facebook probably has a profile on me (although I have never visited them) because I am active in a community of heavy smartphone users; but at least I am an adult and you could argue that people/institutions/organizations that I interact with have kinda given consent on my behalf (without asking me) by agreeing to these websites' Terms & Conditions. So for adults, you could say it is "Indirectly Implied Consent".
But how can you apply this argument to kids' profiles collected/built/scraped without consent?
We have a lot of work to do, as a society. A combination of laws, co-ordinated across countries, and social shaming perhaps?
Yeah, this would line up with privacy laws about photography/videography, at least in the US. Say I'm not a Facebook user, but I go to a party with my Facebook-using friends. My photo is taken spilling food all over my shirt and that gets posted to Facebook. My participation in an event that had no reasonable expectation of privacy means that any photos of me can be legally taken and posted to Facebook.
> But how can you apply this argument to kids' profiles collected/built/scraped without consent?
Well, one of the problems is that as it stands right now, parents/guardians control that consent. And parents are largely the ones posting pics and FB statuses about their kids. I think there would have to some kind of laws that give children rights to a certain degree of privacy outside of their parents' control.
There was a case in 2016 where an 18 year-old sued her parents to remove 500 of her baby photos from Facebook:
https://www.usatoday.com/story/news/nation-now/2016/09/16/18...
It seems unfortunate to me that she had to wait until she was eighteen in order to address the issue. A lot of social damage can be done before eighteen.
I agree and think Apple promoting and implementing it in their products is wonderful. But most of the world can't afford Apple products and therefore are effectively denied this human right.
It would be great if Apple could provide a low-cost line, probably under a different brand name, that implemented the privacy technologies in otherwise basic phones, laptops, etc. Or maybe license the privacy tech to someone else who does that. (I realize it might be much more complicated than what I describe; for example, the security tech could be too tightly integrated with the rest of the product. Would they have to license iOS? A stripped down version?)
I'm not complaining; it's not Apple's job to solve this problem created by other phone and OS makers. But they could make a big impact and I don't think it would take sales from Apple products; an otherwise cheap phone with Apple's boot security subsystem isn't going to compete with an iPhone.
Getting someone's phone number has always felt like a much higher bar than their FB since you could harass them with calls, SMS, etc and it's more difficult to block. Plus there's an implicit sexual connotation if you ask a woman for her phone number that doesn't apply to Facebook or LinkedIn.
I really don't like how WhatsApp piggybacks on phone numbers and phone contacts but clearly I'm in a tiny minority given how successful they've become.
I don't have a Facebook account.
> Getting someone's phone number has always felt like a much higher bar than their FB since you could harass them with calls, SMS, etc and it's more difficult to block.
It's quite easy to block a number. If they'll go as far as to use a different phone to call you, then they could also use someone else's FB account too.
> Plus there's an implicit sexual connotation if you ask a woman for her phone number that doesn't apply to Facebook or LinkedIn.
That's probably something specific to your culture or a misconception on your part. I don't see how the two actions are different when in the same context, except friending someone on FB means you let them not only try communicate you, but observe a certain period of your past and see pictures/videos/posts of yours. I can't see how that's not more demanding in terms of privacy than asking for someone's phone number.
I'd ideally go for an e-mail address instead of both of them, but well...
Apple loves privacy and hates freedom. It sure looks like the only thing they actually care about is their financial interest.
The fact that this privacy protection happens to be in the financial interest of Apple pleases me, because they are unlikely to sell out long-term interests in protecting reputation for short-term gain in abusing my trust. This alignment of interests makes Apple a better guardian of my privacy, not worse.
None of that is true. All they need to do is create an opt-out mechanism to over-ride those security settings that requires authentication. It's trivial to have both, they just choose not to.
How is letting you install your own OS helping with improving privacy?
In today's world can you really decouple hardware and software if you want strict controls over data and hence privacy?
Only in your opinion. A non-free system whose vendor has an incentive to protect privacy may also provide even stronger privacy protection for the masses than a system that meets your version of 'freedom'.
This isn't a "version" of freedom. It is what freedom literally means. You can say you're willing to sacrifice some freedom to gain privacy, sure. But from a technical perspective, that's a totally false choice.
To dive straight towards the third-rail of this conversation, some people think that being able to go out and buy a gun makes them more free while other people think that the ability of other people (of possibly questionable mental state or moral character) to buy a gun increases the probability that they will be killed by someone else with a gun and because of this they are less free. Both are correct.
If only the market would allow us to make a choice as to which version of freedom we wish to engage in and would provide us with multiple competing platforms that represent alternative visions of computing and informational autonomy. If only...
How, exactly? Are you saying that the burden of potentially unlocking your device in error, even if Apple makes that a convoluted, explicit process makes you less free? If i'm misunderstanding your argument, let me know. If i'm not, I think we both know it's totally silly.
Hates freedome how? This statement is overbroad.
In a nutshell, I would rather support Apple as they're primarily a hardware company that has stated their privacy interests align with mine. As opposed to me supporting an advertising company that happens to sell phones and produce a mobile operating system that seems tailored to do the opposite.
The fact that I can't install my own OS is entirely tangential to the overall company goals of Apple versus Google or even Samsung. Focusing on a phone platform to behave as if it was the PC platform of the 80's reminds me of the for want of a nail proverb.
https://en.wikipedia.org/wiki/For_Want_of_a_Nail
Focusing too far down on "freedom" from the gnu perspective will just put us into territory we can't cover at all realistically right now.
Besides which, I just want to use my phone, not spend endless hours fucking around with it to install all manner of stuff.
In the sense that their devices are not free.
> Besides which, I just want to use my phone, not spend endless hours fucking around with it to install all manner of stuff.
The fact that you don't want to use it that way is hardly relevant to the question of freedom.
Listen, i'm not saying they should spend a bunch of time engineering a solution to support this use case. I'm not saying they should aid people in doing it in any way. But that's not all they're doing. They actively expend resources to thwart people controlling their own devices. It is their corporate policy not just not to support this behavior, but to make it technologically impossible. That is the key point.
If Apple had just said "if you modify the OS, you void your warrant and you're on your own - we offer you zero support", i'd be totally fine with that. Personally, i'm not interested in modifying my device at all, i'm happy to leave it as is. But to go out of their way to make it impossible to do that? That's anti-freedom, no matter how you slice it.
I think Apple understands this. The freedom you desire has ecosystem effects which I don't want.
You may quibble about precisely how hard is hard enough. Maybe they could loosen up a little bit, walk some middle path, and satisfy both of our desires. Maybe. Has anyone done it? Apparently people will sign anything you ask them to in order to play farmville. And every jailbreak seems like a security hole I'd rather not have.
In short, you are still free to not buy their hardware.
Plausibly they care for many things and trade them off.
But more importantly: who cares? We’re not judging whether Tim Cook oughta get into heaven.
People seem highly driven by the profit motive, arguably more than by most other motives. If Apple’s goals are aligned with mine and motivated by profit so they’re likely to be careful to keep from damaging their reputation... great!
It's also been brought up by others that Apple discards its privacy morals when it comes to China. Which is another point in the "probably doesn't actually care about privacy" column. Occam's razor says the simplest explanation is most often true. The simplest explanation here is self-interest.
To be absolutely clear, i'm not disparaging them for taking this position. I think it's great. I'm just trying to contextualize it.
And we also know that nothing about writing walled software ecosystems prevents one from syphoning this data.
So it would appear that Apple has purposefully left money on the table.
So please tell me how that fits with your 'self-interest' explanation of Apple's stance here.
Taking a more strategic perspective, you would look around and see that your competitors have to collect this data to survive. But you don't. That makes this a weakness for them, which means that it's a differentiating factor for your product that they can never copy. This strategic advantage is worth much more than the few billion in quick cash they might pick up by monetizing their user data.
Not only that, but having taken this stance so strongly, it makes any future relaxations of their self-imposed rule an even riskier move as it exposes them to hypocrisy. So it's clearly a double edged sword. And while it's certain Google depends on data now, nothing stops them from making excellent phones with excellent hardware with privacy to boot to compete with Apple on their turf.
Microsoft owns LinkedIn, which is an advertising company. I also seem to recall that they make a reasonable chunk of change from search advertising and other online properties.
According to this link they took in a little over 6 billion in advertising revenue last year:
https://www.statista.com/statistics/725388/microsoft-corpora...
According to this link, amazon took in somewhere in the region of 1.7 billion in revenue from mainly advertising last quarter alone:
https://www.statista.com/statistics/725388/microsoft-corpora...
The more consumers support privacy as a selling feature, the more Apple will guard it. I'll gladly pay a premium to a company that has a vested interest in keeping my shit safe, and a straightforward business model of keeping me happy enough to sell me more shiny things.
Apple actively chooses to not pursue these revenue streams even though they have the resources and reach to do so.
I disagree. Apple can't compete in those spaces effectively because they're already owned by Google/FB. Microsoft has similar resources to Apple, and they tried to compete with Google on search - look how that turned out. Even Google can't compete with FB in social, look at Google Plus.
Apple has, intelligently, recognized that they cannot compete in that space. So they aren't trying. They are then using that to their advantage, by focusing on privacy, which is something their competitors cannot focus on. It's a perfectly legitimate strategy, and there's nothing wrong with them doing that. I support it wholeheartedly.
On the contrary however, it is not in Apple's strategic interest to give users's sovereignty over their devices. In both cases, their behavior aligns not with user interests, but with their own. Being financially self-interested better explains the sum total of Apple's behavior than any interest in user well-being.
Not sure people that live in glass houses should throw rocks.
https://www.amnesty.org/en/latest/news/2018/03/apple-privacy... Campaign targets Apple over privacy betrayal for Chinese iCloud ...
What the data is used for is another issue.
Apple Pay:
https://support.apple.com/en-us/HT203027
> "Apple Pay is also designed to protect your personal information. Apple doesn’t store or have access to the original credit, debit, or prepaid card numbers that you use with Apple Pay. And when you use Apple Pay with credit, debit, or prepaid cards, Apple doesn't retain any transaction information that can be tied back to you—your transactions stay between you, the merchant or developer, and your bank."
Also (https://www.apple.com/privacy/):
> "When you use a credit or debit card with Apple Pay we don’t keep transaction information that can be tied back to you, so we can’t create a history of your purchases. And when you use Apple Pay Cash, information is stored only for fraud prevention, troubleshooting, and regulatory purposes."
If you're suspicious, there's plenty of room in "fraud prevention" and "trouble shooting" for you to make whatever case you want. The first sentence is pretty clear that there isn't enough information to create a history. I suppose there's wiggle room to interpret that as they may be keeping some kind of summary of the purchase history rather than a detailed transaction log.
Health data:
https://www.apple.com/privacy/approach-to-privacy/
> "When your phone is locked with a passcode, Touch ID, or Face ID, all your health and fitness data in the Health app is encrypted. And any Health data backed up to iCloud is encrypted both in transit and on our servers."
> "We also require apps that work with HealthKit to provide a privacy policy for you to review. Your data in the Health app and your activity data on Apple Watch are encrypted with keys protected by your passcode."
In today's age, you need a phone number and e-mail. It's ok - they are decentralized. Don't let a centralized platform of Facebook's evil nature become necessary for you to live your life.
Delete and forget it existed. Ignore and move on. Give up the benefits and pay the cost.
iCloud exists but facilitates storing only core data and otherwise is a sync mechanism.
Social aspects of iCloud are what's "missing" so even a large breach wouldn't result is 100x users being exposed.
The most galling part of the FB failure was that the people breached weren't the ones who installed the misbehaving app. And society at large paid for it.
What's the cost again? I'm still experiencing cognitive dissonance over the fact that this is news here on HN. What Facebook was doing was common knowledge (for the last 8 years?). I assumed all those spammy facebook apps, like candy crush, had access to the entire social graph of facebook (not just US) or at least built it up over time. All those stupid "Log in with Facebook" apps almost always asked for your friend information.
https://github.com/fix-macosx/yosemite-phone-home
https://arstechnica.com/information-technology/2014/10/mac-o...
Don't know what came out of these things in later OS X versions.
>"The ability of anyone to know what you've been browsing about for years, who your contacts are, who their contacts are, things you like and dislike and every intimate detail of your life — from my own point of view it shouldn't exist."
He said that the ability to know what they've collected about you shouldn't exist. Very different.