Tim Cook makes blistering attack on the “data industrial complex”
techcrunch.com
techcrunch.com
I started a social data search platform named Datastreamer (http://www.datastreamer.io/) which is basically a petabyte-scale content indexing engine.
We provide API feeds to search engines and social media analytics companies needing bulk data but don't want to have to build a crawler.
For the last 5 years we've had major problems with customers coming to us asking for data which we felt was unethical (at best).
We actually had Saudi Arabia approach us... It was clear that they were intending to something pretty evil with the data.
Their RFP questions were a bit frightening:
- can you track people by religion?
- can you give us their email address?
- can you provide their address?
- can your provide their ethnicity?
- can you provide their social connections?
We're actually losing business to other companies that are performing highly unethical and probably illegal techniques.
We just can't compete with data at that type of fidelity.
If you're a researcher and you want to access bulk data for combating this type of non-sense WE WILL PROVIDE DATA AT COST. We can provide up to 1PB of data but for now we have to charge for the shipping and handling of that data. We're reaching out to some other companies like Google and also the Internet Archive to see if we can provide more cost effective solutions.
I'm working on more tools to give the power back to the users.
Polar (https://getpolarized.io/) is a web browser which allows people to control their own data. The idea is that I can keep a local repository of data and eventually build our own cloud platform based on open systems like IPFS and encrypt the data using group encryption.
There are tons of other shady companies out there doing nefarious things with your data.
We're going to need platforms that support group encryption and better security for apps.
I don't know if there's any way for people/companies like you to defend against unscrupulous companies.
I can only say thank you.
Definitely. Though I also feel we need to give a shock to public awareness of just how evil people can be with this data. My perception is that people are trending towards "vaguely uncomfortable" with the news of foreign interference with targeted ads, election hacking, and so on, but we've a ways to go yet before most will give up supremely-engineered convenience in exchange for security.
As long as the modern world is democratic and the voting populace is subjecting itself to targeted manipulation by data-armed bad actors, we have a problem of not just national security, but international security.
Thanks for being one of the good guys.
It takes years of dedication to be a professional electrician or plumber, but anybody off the street can build an application that aggregates personal information and isn't subject to any sort of regulation or oversight or system of professional ethics.
That doesn't just safeguard the public. It also safeguards the employed individuals when they say, "No, that is not allowed under the ethics of my profession."
This isn't about "let's make the government save us," it's about creating a legal framework to protect the interests of the public and give ethical considerations in data management and software design some legal backing.
I'd add that it would be nice to be able to operate outside of certain fields and certain types of operations without that level of certification.
For instance, freelance web devs, small business software employees, etc who aren't dealing in things like personal or trivial data could continue operation. For example: you don't need to be a doctor to be certified in first aid, or even administer first aid—but you likely wouldn't attempt an invasive, life-threatening surgery.
I'd also like to see—if that kind of regulation were to pass—the inclusion of some kind of grandfather clause that would include the ability to test without formal education.
The reason being there are very many highly capable developers/engineers in the field who don't possess the exact formal background—and in many cases came from other formal backgrounds.
I'd definitely hear arguments for not requiring education at any time, but to keep it on par with the other professions you listed I'll leave it as is.
This might not be the thread for a larger discussion on this—because it seems like it would be a larger discussion. An interesting one, though...
Implementation seems like it would be a challenge, but then again I don't know the stories behind who more modern professions like electricians were regulated. I imagine that field grew much more slowly.
Awesome idea. The same governments who are sending RFPs to burtonator's company will then have the ability to decide who is even allowed to work in the industry.
No they can't. The closest is they can steal(copy/paste) portions of other people's applications, change some text, and attempt to take credit for them.
Also, we do have agency(private) that you suggested. Developer certification programs exist for nearly every language and platform. They aren't very popular. Red Hat will certify you as a java developer for JBoss, Oracle will certify you as a java developer as well. If you can't write code, but still want to feel geeky and have a career as a waiter, you can go get certified as an "ethical hacker" too.
There is no shortage of agency - employers and consumers simply do not care, and by that, I mean they do not want to pay(higher prices) for it.
PS: You can go be an amateur electrician or plumber today, without breaking any laws. However, if you'd like to touch private/public power or water/waste infrastructure, then you need endorsement. It's not illegal for you to hire me(a total amateur at those 2 trades) to both wire and plumb the new house you are building. The awkward moment will be when the water and power company refuse to connect your house, because the work I did was not the work of a licensed electrician or plumber. I understand the spirit of your analogy, but it doesn't translate as well with IT. For that analogy to work, then private/public internet infrastructure would have to refuse to inter-operate with your software if you didn't meet their licensing/certification standard.
Second, I've been fighting for regulations for over three years and I'm getting somewhere, but I'm also starting to think that we need technical solutions to many of these problems. One of the things I see as a problem is that people always want more, but privacy and security often require less.
For example, old charsets only supported Latin characters. With the introduction of Cyrillic characters many assumptions started breaking.
Each time I try to think through how to make the web / internet simpler I realize that it either requires pushing the complexity onto people unprepared to deal with it—an English speaking daughter may want to copy and paste her Russian mother's Cyrillic name, say—or it fails to handle the use cases we need it to handle.
I know this seems kinda abstract, but do you ever think about that interplay? Are there any insights or anecdotes you find useful?
And you always will. Principles and money are often at odds. This is not an easily fixable problem as the well-intended solutions often cause more problems. Enforcement of existing statutes and accepting legal-yet-unethical practices is unfortunately the most rational approach.
> We just can't compete with data at that type of fidelity.
Only in a situation where interminable growth is required in a race to the top. Otherwise, there's room for everyone and that's why there are thousands of software products that "compete" just fine. The key is just making sure there are platforms that allow everyone to build everything.
The key is that they choke you out... They have more engineers, more R&D and a better product because they have more revenue.
I appreciate all your work and contributions to the community in general. Please keep your chin up and keep moving forward.
The first line of defense against this is, and always will be, not publishing so much information about yourself. They can not mine what you do not provide.
We can argue all day about the ethics of the conduct of companies and states looking at these data, but it's a non-issue if the data simply don't exist.
And it will only get worse, as more data will be shared by other people. Soon the streets may be full of people using cameras all day long, just because it allows them to make cooler diaries or blogs, and then the data companies will get universal surveillance.
The only way to keep privacy will be to have your face covered in public (but hey, that will be made illegal, because terrorism or something), or avoid public places completely.
But, I'm baffled by this PR as if they are the privacy messiah. Didn't they just sellout their Chinese users icloud data to the Chinese government?
Yeah. "It's the law, and Apple has to obey the law" is an argument, but here is a company that is willing to compromise their user's privacy in order to be able to sell phones in China. So, if US govt finds a way to say "it's the law" to reveal user data, I'm sure they'll bend over. This grand stand in media is just sickening and theatric.
/rant.
1) His team + Apple Directors that I firmly believe, both in words AND in their action, are strong proponents of privacy of the user
2) The Apple Board + Sharedholders that would revolt if the privacy principles from (1) prevented access to a market of ~1.4 billion people, and potentially gave a competitor like Huawei a further leg up.
In this scenario, I don't see it as "grand-standing," but more of a necessary public act that US should move more in the policy direction of the EU, in spite of steep lobbying from most of the Valley / FANG group that would benefit from less-strict privacy regulations.
That's what Tim Cook is doing here: hoping the US doesn't go in the direction of an authoritarian government, and lobbying as much as he can to prevent that. Imagine if the US adopted a similar law or set of policies that required "backdoors," or data pooling (a la social credit system) - what are his choices?
1) Not operate in the US? Not realistic
2) Ignore them and pay hefty fines up the whazoo? Maybe for a short period of time until Shareholders revolt or the Feds push to start pulling some folks in court.
There is a difference between a company's _incentives_ to do something that is permitted by law - for which I would agree that said company is worthy of criticism to a reasonable extent - and that which a company is _compelled to do so by law._
My point was that Tim Cook's speech was largely to prevent scenarios that would lead to law-makers wanting to create laws like the latter. And Apple _should_ get credit that they have a bunch of incentives to collect user data at will, like many other tech companies, but explicitly avoid that as company policy.
Google and Facebook don't. It really matters when you are being asked to blindly trust a company.
In filings to a court during the FBI legal fight, Apple addressed this topic head on. The reason it was brought up in the first place was because national security establishment water holders were putting out the idea that Apple makes exceptions for China, and the Department of Justice parroted it [1].
From Apple's filing [2]:
>Finally, the government attempts to disclaim the obvious international implications of its demand, asserting that any pressure to hand over the same software to foreign agents “flows from [Apple’s] decision to do business in foreign countries . . . .” Opp. 26. Contrary to the government’s misleading statistics (Opp. 26), which had to do with lawful process and did not compel the creation of software that undermines the security of its users, Apple has never built a back door of any kind into iOS, or otherwise made data stored on the iPhone or in iCloud more technically accessible to any country’s government. See Dkt. 16-28 [Apple Inc., Privacy, Gov’t Info. Requests]; Federighi Decl. ¶¶ 6–7. The government is wrong in asserting that Apple made “special accommodations” for China (Opp. 26), as Apple uses the same security protocols everywhere in the world and follows the same standards for responding to law enforcement requests. See Federighi Decl. ¶ 5.
and a declaration from Craig Federighi personally [3]:
>Apple uses the same security protocols everywhere in the world.
>Apple has never made user data, whether stored on the iPhone or in iCloud, more technologically accessible to any country's government. We believe any such access is too dangerous to allow. Apple has also not provided any government with its proprietary iOS source code. While governmental agencies in various countries, including the United States, perform regulatory reviews of new iPhone releases, all that Apple provides in those circumstances is an unmodified iPhone device.
>It is my understanding that Apple has never worked with any government agency from any country to create a "backdoor" in any of our products and services.
>I declare under penalty of perjury under the laws of the United States of America that the foregoing is true and correct.
That was a few years ago, but Tim Cook basically reaffirmed that a few weeks ago in this interview with Vice [4]. The new law means Apple's Chinese iCloud data needs to be stored in local data centers, but Apple continues to maintain sole control of the keys. Whether you believe them or not, or whether you think that's a meaningful distinction is up to you. But end-to-end encrypted services like iMessage or iPhones itself, remain so and are still unblocked in China.
You might be wondering why Apple seemingly gets an exception when services like WhatsApp are blocked. The answer should be obvious: Apple being an old-world company that still makes products in meat space, (indirectly) employs a lot of people in China. That gives them leverage that other companies don't have.
So they have to comply with certain Chinese laws such as taking down the NYT app, VPN apps, being unable to operate iTunes Books or Movies in China, etc. But that's a small price if it means their core products remain uncompromised.
[1] https://www.lawfareblog.com/deposing-tim-cook
[2] https://assets.documentcloud.org/documents/2762131/C-D-Cal-1...
[3] https://www.documentcloud.org/documents/2762118-Federighi-De...
At that time they were also storing iCloud data on their own servers, correct? To save myself and others from having to watch the Vice video, what did Tim Cook say that reaffirms no blanket Chinese government data access (honest, not sarcasm, I did not watch it)? Why are public statements about privacy always about the US or EU but never China? Surely the lack of consistency/transparency is clear here and causes mistrust.
Be open and honest to your users you claim to care about and there's no problem. Just simple statements like "We have privacy concerns with [insert country here]" or "We aren't allowed to talk about privacy concerns with [insert country here]" or "We do not give blanket data to [insert country here]" or "Although we follow the rules, we disagree with [insert country here]", etc would go a long way. Or continue to be secretive and hidden and anti-user.
>Why are public statements about privacy always about the US or EU but never China?
As much as Apple/Cook may believe privacy is a human right, and have seemingly extracted some important concessions regarding their products, they aren't going to shoot themselves in the head so everyone can feel good about Apple publicly standing up to the CPC. That's a job for governments (the recent efforts by the Trump administration to reset the relationship with China is a good example).
I was having lunch with several lawyers at my company a few weeks ago. One of them was talking strongly about quality devices and Apple’s strong privacy stance. He literally said that we as a society should be grateful for having Apple.
Of course, it's very nice that Apple made the decision to pick this edge, but they did it because they could not compete with Google on web services. So now they're publicly speaking to try and take the sting out of Google's edge. And that's healthy competition, the direct result will be that the consumer benefits, and I can agree we can be grateful to have these powerhouses fighting for our satisfaction.
That's my favorite thing about it: I trust their motives. If Cook were saying this but we knew that the board was getting pissed off about it, I would worry that it was just a matter of time. But Apple is making billions by protecting its users' privacy, investors are raking in cash, and I'd bet the board is thrilled with this. That makes it much, much less likely that they're going to announce one morning that they're abandoning privacy and going all Facebook.
Of course. This is how all companies work. I just really like that this competitive edge exists in the first place. If this competitive edge exists and works, it might actually be stronger as Apple can continue maintaining this stance in the future.
Although I'm not a big Apple user myself (I think/hope I can defend myself enough on other platforms that have a lower cost of entry), it's nice that you can point to iPhones if people are asking for on which they can take reasonable ownership of their privacy without needing to be very tech savvy.
So Apple is the one big technology player whose interests are most closely aligned with the consumer in terms of supporting data privacy.
EDIT: To see the equivalent from the "other side", timagine adtech companies starting a PR war against Apple's closed garden system, arbitrary app store decisions, labor conditions (I'm sure we can find some dirt somewhere in their vast business) to get laws enacted to regulate them on what they can do and not do.
Don't believe for a second that privacy isn't personal to him.
I admit they are better than Google on the privacy issue, but should we be grateful for having an alternative that abuses us in different ways?
PS: I own zero Apple devices (partly because of the reasons you have, not for the way you are misrepresenting those reasons).
Your functionality though, will be severely compromised. So the choices are:
1. Apple - hurts your wallet and your choice of apps (only the walled garden and nothing else). 2. Google - you're the product. not the phone. 3. Something else like the open source solution. You'll spend a lot of time here and will be restricted to the limited choice of apps on the the f-droid store.
So take your pic. I'm mostly in #2, with a billion or so others. I'm fully aware that me and my data are the product here, and whenever I start feeling that I made a deal with the devil, I simply tell myself that they can't know what's happening in my head. I then quickly shift focus and start thinking about something else. :P
To roughly quote another HN user who I don't recall, "Not everybody wants to sysadmin their phone".
Don't assume moral disposition when a CEO is talking his book.
Maybe Tim is really a good person, who knows?
But if Tim were the CEO of Facebook he'd be singing a different tune.
Don't underestimate the ability of CEO's to align their personal views with that of he company.
Apple is sensing blood in the water on Google and Facebook, and this is a smart, basic PR move to go on the offensive against those companies.
Now - I do think it's likely that Cook does actually believe what he is saying - so I'm not fully calling him a hypocrite or anything. But he is a business guy, and were he to be the head of a company for whom this angle would not apply, I suggest strongly he'd have a different story to tell.
When businessmen speak, it's mostly 'just business'. I don't mean that cynically, just pragmatically.
Which is utterly cringeworthy.
iPhone user thinks iPhone is best thing since sliced bread. News at 11.
It doesn't need to be Apple specifically, but I'm glad we have competition. If either of Apple or Google were the only real option, we'd be much worse off than we are now.
It's a shame it's come down to a duopoly, but at least they both have something to compete on.
So someone like Equifax would be on the hook for $1.4T in civil penalties for losing the data on 143 million customers. That would have effectively put them out of business.
If you set up such a system, then it is very easy for engineering in an organization to explain why they need to invest in the security safeguards they need, and it is very hard for product managers to argue for collecting even more detailed information. All because you have created an existential threat to the company if they screw up.
If you think the business community dislikes taxes, just wait until a law is proposed that gives people a private right of action against companies that leak their data. I don't think the term "white hot" would suffice.
Note that with Equifax you never signed any sort of permission or ToS for the data collected, so they'd be hit with a fine regardless.
Many companies collect data on people without a contract. So this would still have teeth even with waived rights.
don't pursue damages?
It's not so much that I think that Apple is more virtuous than Google, that'd be naive. It's more that their business model seems to align better with actually respecting their user's privacy instead of siphoning as much data as they can even if that means using ridiculous defaults, nagging and dark UI patterns.
https://together.jolla.com/question/191235/official-event-sa...
It wasn't too bad, though the swipey interface made it a little to easily to accidentally call people when drunk.
At some point, hardware progress will be so minimal and devices so easy to manufacture that small companies can offer their own high-end phones and can build for them some years without really being much behind the competition.
When that happens, custom ROMs can really lift off and I don't think we're so far away. One or two more generations of smaller chips and better batteries. We're already at the point where the only innovation is adding more cameras.
Do you acknowledge this comes at a huge cost? Apple has a fraction of the marketshare as Android in countries like India. Apple's iPhone prices out billions of people. Android-based phones don't. If Android-based phones adopted Apple's business model, billions of people would not have smartphones.
But I suppose there isn’t a market for that. A majority of users would pick the phone that is only 289 instead of 319 Even if that means selling their data. And the few users that do care are willing to pay the premium for an iPhone. Considering that manufacturing a phone is expensive unless they can mass produce it in quantities such as Samsung and apple, there won’t be a company to make such a phone soon because it would be just as expensive as an iPhone with a lot less features.
And of course the Most important feature of any smartphone are apps and any new platform wouldn’t have any apps. Developer won’t develop for them unless there are enough users and there won’t be enough users unless there are apps. You could probably use googles play services and emulate android but as far as I know there isn’t a way to get around google’s push notifications without compromising the users privacy (which would defeat the purpose). Besides that would be expensive to make and gooogle might not license it at all because there is little in it for them.
If you spread all the revenue of Facebook & Google over every android device it still wouldn’t come close to the difference in price.
Apple could make much cheaper devices, but they’d just end up cannibalising the sales of their high end phones.
But what’s the downside?
I'd like some competition that's actually with Apple (that is others who respect privacy, not Google, Microsoft et al) as I am increasingly disappointed in Apple hardware.
Chinas use of data is definitely not the way to go.
However, I would also caution against the push for almost complete privacy as that IMO leaves out a number of potential advantages from systems having enormous amounts of data about us.
The primary advantage of technology is that it is able to automate and remove a number of things we would otherwise have to do manually, semi-manually etc.
To the extent that we do more and more in the digital space, our digital identity becomes much more important and that creates a new problem that can't be solved through privacy IMO but have to be solved by allowing digital identities to learn how to trust each other (which means exchange data/information).
I don't think there are many ways around that unless you want to get off the grid completely (which is certainly one way to do things).
This is where I think the decentralized part becomes really valuable. How can we own our own data but exchange it with others and build trust over time just like we would in the real world.
Cause in order to take advantage of the technology you will need to feed it with the primary thing that keeps it alive, data.
Siri/iOS/macOS/etc are proof that “smart” services can be done on-device and/or without identifying information and still be useful.
Google does it all server side because it’s the cash cow their entire business is built on, not because it’s the only way to do it.
Before they were public Google did a lot of stuff that was seemingly just "because we can". Give geeks a metric-shit-ton of money and that'sb what you get.
This line sounds like the "businesses aren't allowed to do things that don't maximise profits" myth.
http://fortune.com/2018/09/29/google-apple-safari-search-eng...
You can call it hypocrisy but it doesn't affect the validity of Tim Cook's argument [0].
Each person's idea of where something sits on the spectrum of right and wrong differs.
If someone is being hypocritical, it can lead people to question the motive behind the words.
I think perhaps you should. It would improve the quality of the discussion.
(and like you, a lot of my work-related searches are technical in nature)
I recently built a new laptop and set it as the default, after several failed attempts in the past. I now rarely find myself struggling with tech related searches as I had done previously. Consequently, it has stuck this time. YMMV obvs.
Given that the source on this is one guy at Goldman Sachs, I’d treat that number with some suspicion.
I think the issue is that besides the money they don't really have a competitive advantage so it'd be difficult to catch up given how long Google has been doing this for.
First of all Search is well outside their domain expertise; they aren't really well known for doing either search/MI or even web services well.
Secondly, it takes a long time just to get all the infrastructure set up. There is an unbelievable amount of build/test/deploy infrastructure that Google has been able to set up over the many years of doing search. I certainly think Apple has engineers smart enough to make it happen but in the end building the stuff takes a large amount of time.
And this is all assuming they use AWS/GCP/Azure instead of deploying their own data centers.
It's very much the same difficulty that Google has trying to make hardware to compete with Apple. They have so much experience and expertise in that area already. There's no way Google could make a phone faster than the iPhone: Apple makes their own chips! So instead Google has to compete in the areas where they have a competitive advantage, for example by using AI to make very good cameras.
Apple could do it, but they are a trillion dollar company that hasn't even gotten Maps completely right yet - let them work on one thing at a time...
A search engine is a big enough process—and difficult enough—that you can't just throw money at it and expect it to work in the end. They could try, certainly. And maybe they'd succeed, and maybe they'd fail. And maybe they'd succeed but end up with a successful business unit whose goals are opposed to the rest of the company's.
Apple is never going to give up their premium position.
all told 300+400+300 = 1000 which is STILL lower than the cost of the iPhone x max
To some extent, I sort of blame Apple here. When you boot up an emulator, it's an iPhone X that you see. If it defaulted to the SE, I bet we'd see more apps that render correctly on its screen. But it doesn't, so we don't.
The faster CPU also eliminates a lot of problems. I am sure I am guilty of writing code that is only viable because I'm running it on a 32 core Xeon machine. So are app developers. The faster the CPU you have, the less likely you the user are to suffer because of their sub-optimal algorithm choice.
As devices age, they stop being supported by security updates.
Compared to OnePlus who stopped updated their OnePlus2 past Marshmallow after telling subscribers they would get the Nougat update. This effectively dead ends this model for users. Got rid of my 2 when I found out:
https://gadgets.ndtv.com/mobiles/news/oneplus-2-android-noug...
A 5S will still run the latest iOS, and with a new battery wont be under “performance management” mode, so it should be quite fast to use.
The cheapo androids are more like the Yugo of mobile devices, and the nicer Androids basically cost the same or a little more. iPhone 7 is $1 on many promo deals.
If you go to companies with compliance requirements, iPhone owns the market, and is by far the cheapest solution. One of my "side hustles" in a very large org was managing about 40k iOS devices and 400 android devices... it basically cost about $9/year to manage, including staff. Staffing was basically 40-60% of two IT guys and half of 3 interns. If we broke the cost down further, the Androids would have been significantly more expensive, as additional 3rd party software was required as well as many more man-hours.
The iPhone is magic in that way, with sufficient scale, you deliver almost magical capability to your whole company, including network connectivity, for less than the run cost of a PC. And it costs something like 80% less to manage than a PC. If you look at companies in industries like field service, iPhones are almost a profit center.
If you have a long-duration, pre-negotiated contract with carriers, where you are essentially financing the $500 phone cost every 18-30 months via the service plan, the marginal cost is the metric that matters.
Says about 44%, which is pretty close to "like 50%"
I focus on the US (and UK and Japan), it's a two horse race. You can segment it all sorts of ways. iOS is somewhere between 40-60% in a given segment, and usually around 43-48% overall. Overall share has been declining as the market growth slows and prepaid plans make total device cost more relevant.
Nothing I said means anything ex US, as the solutions, costs and requirements vary.
But it's way less than that worldwide, in India, for example, it's only 1%l
I suppose the best path would be to create a new phone that could either boot Android or your privacy-respecting OS, this way you could still get the mainstream sales with Android and you'd target the niche users who value their privacy with your custom system. Still seems very difficult to achieve, if you want your phone to be cheap you need to target a high sale volume to dilute the cost of your R&D.
I think the big problem is that smartphones never really had an healthy open source ecosystem going because it was all about closed hardware and locked bootloaders. Without a decent open source stack available it's hard to bootstrap a new system. And even if you did manage to do it you'd still need to convince people to port their apps to it (because not having Whatsapp or Instagram is going to be a deal breaker for many).
You can get away with smaller teams if you take the full package that Qualcomm gives (they do most or all of driver work for you). You saw what Essential Products was able to create with around 120 people, but they were heavily using work from other companies to launch it.
Used iOS devices are the Kia version.
Wondering if they could accomplish the same thing many car brands do i.e. Honda <> Acura
People behave as if this is impossible, but the options are all right there in the settings. There are a few places you lose some features but not super significant ones, and mostly those are because the tracking is intrinsically involved in the functions of the app.
I've even had 'Saved Places' not render without search history being enabled.
My next phone will sadly be an IPhone. Not because I love apple(I don't), but just because I'm quitting google.
It would be stupid of them.
We must guard against the acquisition of unwarranted influence, whether sought or unsought, by the military-industrial complex. .... Yet in holding scientific discovery in respect, as we should, we must also be alert to the equal and opposite danger that public policy could itself become the captive of a scientific-technological elite.
[ source : https://en.wikipedia.org/wiki/Eisenhower%27s_farewell_addres... ]
Warning, Google will be tracking that you watch this speech :P
Apple's market strategy was already primed towards a privacy-focused stance, since their profit center is selling physical devices. Thus, when privacy becomes a Big Deal in the world, Tim doesn't have to push hard to get Apple to line up with his beliefs. If Apple had been an advertising-focused company before Snowden, I doubt we'd be seeing as hard a push as they're giving right now.
That being said I can totally believe that he genuinely believes what he says. Actually I'd wager that most tech people, including at Google and Facebook, see that we're having a problem with "big data" and the compulsive profiling of their users. The potential for abuse is tremendous.
Regardless of ulterior motives I think we should rejoice, having a behemoth like Apple taking such a clear stance on this issue could generate enough momentum to have an actual change in mentalities.
I was a BlackBerry die-hard until they switched to Android. A privacy-focused phone using a Google OS, what a joke. Switched to iPhone and it’s pretty good, only thing I miss is the real keyboard.
The $40 should just be a number that would pass the lowest threshold the antitrust regulators will accept. My guess is that $40 doesn't have much to do with lost advertising revenue.
[1]https://www.statista.com/statistics/276306/global-apple-ipho...
There's nothing inherently wrong with agreeing to give a company access to your data. But it's absolutely wrong that once you've handed your data over, that company can do whatever it wants with it, with no restrictions, as if they own it.
Apple has their own speech recognition tech.
- I'm sorry Dave, I don't have a network connection, I cannot respond to you.
"But you just did."
- I'm sorry Dave, I didn't understand you.
However, for the sake of maintaining consistency with the article and staying relevant I have revised this post.
Tim Cook is there to give a speech at a Privacy conference. I thought his comments were consistent with how Apple has been presenting itself over the last years. This gives me some confidence that Cook will continue to lead and push for stronger privacy laws while fighting against politicians who look to weaken encryption
This is transparency - following through and actually giving a damn about things like child labor. They found 2 cases of underage labor in 2017 after auditing 756 facilities and over 1.3M workers. They made it a core violation of their supplier code, meaning that if and when underage labor is found via audit, that supplier loses its business with Apple.
Go read the report - you might find that Apple is a pretty damn thorough company when it comes to responsible labor. Is there more they could do? Yes, there always is - but they're doing quite well so far.
• add VPN on/off to control center
• allow per-app VPN via Apple Configurator, without enterprise MDM
• once the above two are available, we can use Tor, IDS, DPI or pihole on a per-application basis, to reduce data harvesting
• bonus1: allow the open-source iOS MDM community OR the iOS Shortcuts community to make it easy for novice users to have one-click install of "privacy-plus configurations"
• bonus2: provide open-source code for on-device, silicon-enabled voice recognition using Neural Engine. In the meantime, allow anonymous (no iCloud login) use of Siri via Tor on a per-application basis
(Also, political solutions are more likely to incur severe unwanted side-effects, such as, for example, making it almost impossible for any new operating system to enter the smartphone market ever again).
Also, the options Tim Cook has at his disposal go beyond technical solutions: in particular, it would be straightforward for Apple to switch to a pricing strategy that gets iOS devices into the hands of 100s of millions or billions of people who will stick with or choose Android if Apple keeps its current pricing model.
Here is a writer who estimates that Apple could sell the iPhone X at at 40% discount from its current (at the time the web page was written) price without losing money on the sale:
https://www.forbes.com/sites/ewanspence/2017/11/08/apple-iph...
Rather than switching pricing strategies, Mr Cook apparently prefers to lobby the government to help him maintain the iPhone's status as a premium or luxury brand, which in turn preserves the iPhone's very high profit margins.
Also, how does that work with GDPR compliance if the UI clearly doesn’t ask for my consent that all photos are somehow accessed and maybe even uploaded?
I really hoped they'd add this in iOS12.
Second response: Was undermining Google the reason he held the speech in the first place?
'Buy apple products, we care about your data. We will help protect it. Encrypt it. Not share it. And block others form trying to get your data'
But are Apple as benevolent as they say? Do you trust such a gigantic corporation? Are they colluding with governments instead of just advertisers?
Apples' core business is not to violate your privacy left and right, which probably gives them an edge about the likes of Facebook and Google (at least in my book) in this sphere.
Google on the other hand, is an advertising company that also makes software and a smartphone OS among others.
Also Apple's own "repair method" is to tell you that it's broken, without so much as opening the case and just replacing any component that seems to act up, costing you up to the device's original price in repair fees.
I don't blame them for not wanting random third parties doing repairs.
You know what's funny? We reached a point where 100% private conversation between two endpoints is finally possible, without the dependence on any third party (be it the Post Office, GSM operators,, Google, Apple, or anyone else). That's a huge step for communication privacy. And yet, most people choose the other way, they prefer to share their most intimate details with Facebook via Messenger and WhatsApp, with Google via Gmail, with Microsoft via Skype... Mostly because they're unaware of how things work and that other, more secure ways are available. So kudos to Cook for helping that cause just a bit.
Publicly attacking the military industrial complex would be opposed to Apple's economical interests (because it might upset a segment of its customers).
It's difficult to judge the sincerity of moral outrage in an attack that aligns with your own economical interests. You may think of it as "empty posturing" but speaking out against a sociopolitical issue you're not directly part of can help bring about changes and can help shape cultural attitudes.
For example, coming out as gay in 2014 wasn't necessarily in Tim Cook's best economical or even personal interest (though those offended or upset by this are less likely to let that affect doing business with him because after all he's still the CEO of one of the largest corporations) but it may have played a small part in changing overall social attitudes (remember that the Supreme Court decision on equal marriage in 2015 only happened after most states had already passed equivalent legislation and public support had been fairly widespread).
You may not be able to change something by calling out. But you certainly don't change it by remaining silent about it and playing along with the status quo.
https://www.theguardian.com/technology/2015/sep/30/apple-rem...
Ironically and darkly, they allow this game where you conduct drone strikes:
https://itunes.apple.com/us/app/drone-shadow-strike/id824808...
Apple's schtick has long been "technology without the bullshit"- and well, the behavioral data gold rush is basically bullshit for consumers, so sure, they're on the privacy bandwagon in the interests of their own company and it's market strategy.
Regardless, it does not make him any less right.
He's a CEO of a multi-billion publicly traded corporation. Content warning applies for everything he (or any such CEO/PR service) says.
What do you suggest Apple should do instead of comply with the law? Require it's employees to incriminate themselves?
Of the "giant evil megacorporations that will dominate our cyberpunk future", I think Apple has slightly more moral sense and backbone compared to Google and Facebook. Not much, but it's something.
Has Tim Cook ever criticized the Chinese government or does he only ever speak on these issues when it comes to the US?
I'm not the GP but I've seen this exact form of complaint many times. I think the usual response is "stop doing business in China." I don't know how that's supposed to work, though, since Chinese companies make all of Apple's hardware.
I wish that would go away and the Apple EULAs and agreements would get shorter instead of getting longer.
Being able to find out what data is being collected and how it is being used is a prerequisite for any accountable system of balances that could create negative incentivizes for abusive practices.
Obviously preventing all abuse will prove impossible just as preventing all crimes of any other type is impossible — but as with other kind of crime, undesirable outcomes can definitely be reduced when deliberate will is informed by wisdom and fueled by effort ...
1. There is no equivalent for Facebook and apple cannot build a one with privacy 2. There is none from Google-Search and apple has not built one 3. About WhatsApp? (iMessages - yes only within walled garden!) 4. Google groups-? 5. Browser? Safari? 6. Calendar -> Even creating a icloud account needs iDevice 7. Cant create more than 2 Apple account from same iphone!
I disagree, I think technology should solve that pproblem, like Tim Berners-Lee's.
I would imagine a culture's history has a great effect to. Guns in America for example.
I am curious how one would police data privacy when it's incredibly easy to collect data secretly. Do you only go after the big offenders?
[0] http://fortune.com/2018/09/29/google-apple-safari-search-eng...
While the weaponization of data is a legitimate cause for concern, Apple - the company that maintains a score on you - is hardly the one to be believed as a defender of your data or privacy
> Advertisers grew increasingly frustrated with Apple’s unwillingness to grant them access to the wealth of data the company possessed from its customers and Apple’s hundreds of millions of iTunes accounts. Every decision in advertising is born in data — 70 percent of agencies and 73 percent of brands use data to target the desired audience. Strong analytics tools are becoming ever more important as advertisers strive to keep ads relevant.
From: https://techcrunch.com/2016/03/28/the-downfall-of-the-walled...
It's likely that the incumbents, Google & Facebook, were both much further ahead and entrenched for Apple to break through. Apple also tried social networking (ping) and failed. And self diving cars. I don't see any real evidence for Apple not sharing data out of some moral high ground. If they could actually boost their bottom line and not drive away existing customers, they'd do it. They rolled over like a timid puppy when China asked for all, that's ALL of China's iCloud data. They could've walked away from the China business if they had a sliver of moral turpitude, but they obviously don't, which is also evident from their tacit tolerance of child labor and unreasonable working conditions from their suppliers in China
How many investors did Apple lose for not data mining users?
Look at the P/E of Google and Facebook and then look at the P/E of Apple... Apple sweats every dime of their $1T valuation.
https://www.ped30.com/2018/10/24/tim-cook-brussels-data-secu...
I have to call out Apple on something here, and this is something that Tim Cook could personally do something about very actively, however. And it has nothing to do with customer/consumer privacy, which I think Apple does a wonderful job with, typically. It has more to do with the ethos of the corporation.
Apple is just as guilty as anyone else about actually buying and using this data. It may not always be the case that is sourced from wherever, but they use the same tactics in their hiring and keeping tabs on employees that they are so deride in the media. For instance, if any of you are Apple employees, go ahead and check out the HR policy and procedure for publishing your information including your salary. I think you'll find that to be very eye opening. I can't recall the firms name off the top of my head, but they report that information to one of these firms that aggregates this information and in turn sells it in turn.
Oh and use a personal device at work? Apple's own employee contract states that if you connect a personal device to their network, even once, they have the right to demand any contents of that device subject to termination.
I get some of that is for secrecy, don't get me wrong. I understand that i'm highlighting things from a point of view that I don't agree with these policies and that I'm not, and it is quite intentional, discussing why these policies may be in place. For what its worth, I'm okay with secrecy, in the sense of protecting investments, IP, etc. I get business need. What I don't understand is why Apple's own policies don't reflect these values they often tout in public. I personally feel like they have this dual face a lot, where they say things publicly that I agree with but I know `privately`, if you will, the corporation does not reflect these values when its not convenient for doing business
Don't even get me started on Apple not being at the forefront of the Net Neutrality debates, where I think Apple could have real impact (the general population as a whole tends to listen to Apple/Tim Cook more so than any other CEO I can recall in recent memory, as do politicians of all stripes, its quite a trip how must esteem they hold in the public mind, which is why I think its so important they talk about something that should, at least according to their public statements, be right in line with their ethical underpinnings Tim Cook talks about very often).
Rubs me the wrong way, I guess. Am I glad he's at least a CEO of a huge public company that has weight and is talking about this in a way that is agreeable (mostly) and likely far better for the average person? Yes, yes I am, but I think its important we remember the other facts too.
Disclaimer: I did work at Apple, and for what its worth I left on good terms, and I would generally recommend working there, I just want to be honest about the things I saw and felt. There is a lot of good too, believe me.
I thought they might do it when Bud Tribble, Apple's privacy czar, testified in Congress at the hearing about privacy [2]. He was mostly non-committal until about the time when someone asked if California's law should be preempted, and he answered 'yes' but only if the law is strong enough, so I kind of had a feeling that Apple would at least advocate for it in a minor way. Now it makes sense why he was so non-committal, they were saving it for Tim Cook.
This is a full-on endorsement of GDPR in the best possible forum for this, a keynote speech at a conference for data privacy regulators. This is more than I could have hoped for. Crucially, this removes any possibility of a united front as the ad-tech lobbying machine kicks into gear.
I don't know if this was already planned or if it was my email, but I'm ecstatic either way.
[1] https://www.nytimes.com/2018/08/26/technology/tech-industry-...
[2] https://www.c-span.org/video/?451963-1/google-apple-amazon-t...
Prove that localized models built on small datasets work.
Invest in cryptography and user anonymity technologies.
Instead he's just sitting on it like smaug.
> Invest in cryptography and user anonymity technologies.
That’s what they literally do. Much of iOS’s “proactive” features are done on-device, as is things like photos analysis. And most of Apple’s products utilize at least some sort of cryptography and anonymized logging.
At the time of writing, I can only find one top level comment (by 'dvfjsdhgfv') that's making any attempt to discuss or expand upon the content of Cook's comments.
This is one of the most important issues facing mankind, and the ball is very much in our court. We all get plenty of opportunities to criticise our favourite tech companies and their practices, but if every single mention of them becomes an invitation to shoehorn in our gripes and complaints then this entire endeavour is just a massive waste of time.
I'm not even sure it rates in the top 50 outside of paranoid tech workers with nothing more important to worry about.
If personal data has value, and companies are making billions or even trillions of dollars from it, shouldn't these firms be paying the source (us) to use it? Real cash, as opposed to discounts or in-kind exchanges?
All that health data in healthkit would be a treasure trove for insurances, even without using it for adverts (but for determining premiums, for example)
Apple pay could tie into a credit scoring system.
And so on...
Growth may stall, but throwing away one of their primary advantages over nearly every other tech company is a pretty stupid strategy.
While I believe that those who collect such data would make the world a better place if they freely distributed it, I don't think they should be forced to.
I'm sure that whatever hypothetical problem that could result from such collection of data could be solved more efficiently in a different way.
Sure, please paste here your email and other accounts logins.
Maybe you say you can't trust some random stranger on the internet but why would your trust companies, they have no morals, they want only to make money for themselves and on top of that they are incompetent and they can lose your data and random people on the internet will have it.
That is not privacy, it's security. Are you implying that Facebook and Google don't take security seriously?
Because:
> Personal information is extremely valuable.
The main problem isn't making use of personal information, but using it in such a way where it is not clear to the user as to what is being collected by whom, and what is the value they're getting back for that information.
Moreover, is is extremely hard to know about and control leakage of that info to parties you didn't consent to directly.
That said, I do think people should not be surprised that when they reveal pieces of information to a company that that information is used by that company in ways that they don't 100% agree with. If you give up information, you're giving up (some amount) of control over how that information is used.
Stores that have hidden charges and gotchas are reviled, just like we should be outraged by websites that sell your data without your explicit consent.
It's a bait and switch con.
1) No opt-out. Some companies and institutions are decent about this, but the overwhelming majority of companies who are collecting information about me I've never heard of and couldn't name. I'm not asked if tracking, etc. is okay, OR am presented with some dense glacier of legalese when my only interest is to read some article.
2) No transparency. Who has what information about me and how are they using it? I haven't the foggiest clue, if I'm being honest about it, and I'm a relatively technologically sophisticated and aware user.
3) No deletes. Even when a company offers to "delete your data", how can this be verified complete? It is difficult for me to trust a company or institution's word on this having so insidiously collected the data in the first place. Now, before you take issue with "insidiously", consider the information asymmetry present when an average person (non-lawyer/engineer superstar hybrid) signs up for FB or Gmail. There is definitely a sense in which it is clear that you aren't getting something for nothing, but at 16 that didn't occur to me, and now the damage is done.
4) What, precisely, is this data going to be used for? Creepy ads are one thing, and have been pervasive enough long enough that I think many folks see they as normal now. I don't like the advertising economy, and take steps to shield myself and my family from it to the degree that is possible within our inconvenience tolerances, but the scary thing about this data goes beyond shitty frothing-mouth marketing efforts. When the advertisers are done with it (hah!) it is still there, waiting to be exploited in a political, judicial, or military effort of some kind. Google "Sesame Credit" for info on China's bone-chilling weaponization of social media. And yes, I know, China isn't a beacon of human rights, that isn't the point. I suspect that if China can do this out in the open, there are closed doors in DC behind which a more subtle, similar effort is at least an on-again/off-again discussion.
So no, I can't agree with you that "whatever hypothetical problem that could result from such collection of data could be solved more efficiently in a different way". I work at a 2nd tier retailer whose "Customer 360 Experience" is a surveillance program a lesser nation state would be envious of (I was very surprised to learn how much collection efforts have evolved for in brick and mortar stores). Once the data is collected, it's damned near impossible to "uncollect". Genies don't like to go back into their bottles.
5) your data is sold or shared with a third party and they leak it, ex Equifax so you have a lot to lose when your data is leaked (imagine if all our browser history would be collected for years and then somehow leaked, that would suck a lot, probably lives would be destroyed)