Transparency Report
apple.com
apple.com
Canada Population: 37M
Australia: 1694 device requests (~70x)
Australia Population: 25M
Why such a big difference between both of these safe countries? The crime rates are pretty similar, Australia definitely doesn't have 70x more crime than Canada, and there aren't simply way more iPhones in Australia. Very different police/prosecuting strategies I guess.
But for some measurement, it seems to work. Drugs are insanely expensive in aus.
I don't have a great definitive answer on why that's the case, but I do have suspicions. One is around the (perceived?) strength of our democracy, driven by mandatory voting and a well designed parliamentary system. Also, we don't have the American history of revolution - distrust for government just is not part of the thinking.
The other is that, for the most part of the last 50 years, our more public institutions have done a good job. The ABC (think the BBC, but Australian) is a trusted news source, Medicare largely "just works" for most people, our public/private education system mostly works, etc.
When it comes to law enforcement, I think the general perception is that while they're far from perfect, they tend to be well governed and as a result given a generous amount of power.
Again, whether this perception is justified or not is a different thing, especially if you're not of Anglo descent.
Culture of war crimes (ADF regularly executed civilians), metadata retention (bipartisan support), anti-encryption (bipartisan support), raiding journalists, letting multiple newborns die because of coronavirus travel restrictions, university censorship kowtowing to China, police brutality, no free speech, no free expression and repeated attacks on the IT industry (many companies incl Microsoft yanked data and compute away from Australia after the bi-partisan laws rammed through parliament allowing the government unfettered access to data).
All of the above has wide bi-partisan responsibility. Most of it has happened in the last 5 years.
In Australia, both parties sell you down a river and tell you they're the best party because of some irrelevant policy minutiae, meanwhile supporting war crimes and the evisceration of the IT industry and our rights.
But the other thing to note about Australia is that the country is a bit of a demographic and cultural misfit in SEA, and reliant on the US umbrella to have unquestioned security against the countries just to the north including two superpowers and any number of countries with the potential to be economic and military powerhouses.
It would be strategically justifiable for Australia to get serious about building up a powerful intelligence system, in a way that it just doesn't for Canada. I imagine if Canada wanted to become the next US State it probably could. Australia is much more isolated and it is foreseeable that the US might withdraw from the Pacific in the next 50 years.
Isn't everything? Also consider that Australia's borders are much easier to patrol due to its "island" nation status.
It’s traditional stereotypical “she’ll be right mate” image is far from reality. Hugely litigious, lots of red tape, if there is a fine for something you will be fined.
The ex prime minister stood in parliament and said “The laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia,” in regards to wanting to back door encryption. That’s what you are dealing with.
> The new law also allows officials to approach specific individuals—such as key employees within a company—with these demands, rather than the institution itself. In practice, they can force the engineer or IT administrator in charge of vetting and pushing out a product's updates to undermine its security. In some situations, the government could even compel the individual or a small group of people to carry this out in secret. Under the Australian law, companies that fail or refuse to comply with these orders will face fines up to about $7.3 million. Individuals who resist could face prison time.
https://www.wired.com/story/australia-encryption-law-global-...
In practice though I don't think anyone actually cares. I certainly haven't been asked about it by any prospective employers and I work in areas of finance where companies are famously protective of their IP.
Maybe this works well for Australia, or they are stuck in 1990 and simply haven't looked back and wondered if anything could be done differently.
Example would be: instead of catching everything you see, you can also collect information until you find a pattern, central driver or societal problem and solve that to solve the underlying problem. The counter-example would then be: instead of always trying to catch the biggest fish you can also make a few examples and disturb something like a criminal network by messing up the actions of their foot soldiers.
I suspect the way you go about it increases or decreases the amount of individual requests you need in order to execute your mandate.
because it is hard to measure the effectiveness. How many terrorist attacks and domestic incidents are there (assuming in good faith those are the only things to be prevented) ?
I would assume in the absence of any of these national security agencies that there were only very few per year if not decade. That makes it hard to adjust the strategy even if you assume that they are totally focused on security only, and not e.g. on the continued presence of their paycheck of suppression of opposition parties.
To give you an example: the (American) security measures at the airport that were introduced in 2001 can be considered a total success, as there has been no incidence since then (success = good, people can get promoted for that[0]), although these measures have been called security theater at times[1].
And with these measures called successful by those promoted people, why change them? Of course some other people opine that they may not be as successful as they claim they are [2], but it is still hard to quantify.
> instead of catching everything you see, you can also collect information until you find a pattern
yeah that seems likely. Though this scares me personally as I may demonstrate a pattern now that will make me a suspect in the future, despite doing nothing wrong.
[0] I worked at big tech once upon a time [1] https://www.theatlantic.com/national/archive/2014/01/tsa-bus... [2] https://www.thelocal.de/20091231/24279
“The ancestors of Australians aren’t prisoners, but rather prison _guards_”
Given the mass protects and how much phone live streaming was involved NEXT years report will be truly revealing.
It's possible it wont jump all that much as when arrested many protestors had their phones at least temporarily siezed, and the Grayshift[2] boxes law enforcement have probably don't need Apple's involvement.
They are perfect for protests. If you are not coordinating or worried about realtime Twitter, but instead documenting, you don't even need a cheapo prepaid SIM.
Wipe them first, and don't leave them anything other than pictures of their own abusive behavior for them to find, unless you'd also like to gift them a copy of the Constitution or perhaps some personal musings on the role of policing in modern culture.
If phones worked like this, people would keep them for many more years, but there would still be more than enough 10+ year old phones available for a close approximation to the shipping cost.
It would also mean that the older phones would go to poor countries that could still use them instead of being slag, because "slow but runs current software" is usable whereas "not even old enough to be slow but can't run current software" means you can't use the thing because websites will throw certificate errors from missing roots, apps won't run on it and it will be full of known vulnerabilities and get malware.
> Based on 110 public records requests to state and local law enforcement agencies across the country, our research documents more than 2,000 agencies that have purchased these tools, in all 50 states and the District of Columbia. We found that state and local law enforcement agencies have performed hundreds of thousands of cellphone extractions since 2015, often without a warrant.
[1] https://www.magnetforensics.com/products/magnet-axiom/cloud/
Comparing US results it seems like Apple has served ~4x fewer requests vs. Google (10197 for Apple and 38042 for Google) in a six month period.
Interestingly, the rate at which both end up turning over data is nearly identical (85% for Apple and 83% for Google).
---
EDIT: nostromo points out that Apple does report the preservation request numbers in a separate section on the detail page. So inclusive of preservation requests, the comparison would be 12,719 for Apple and 38,042 for Google. However, I think Apple is right in not including these in the main number since preservation requests are asking the companies to preserve data that they might otherwise delete in anticipation of a future data request -- which would be counted.
At least for the device part, if you use an open source OS like LineageOS, you can fake all of these things so that it's not even a question. One of the biggest privacy disadvantages of iOS is that Apple maintains total control over the system and therefore they can be compelled by governments to serve these requests, whereas on my "Google" phone I can actually prevent Google from being able to serve them. Sure, the default OS Google supplies may track the hell out of you, but at least you have the option to load your own OS onto the device.
I find it extremely annoying that Apple continues to play the "we're the good guys" card while there is absolutely no data on how Apple themselves track and use your personal data. I would much prefer the system itself were designed such that you have the ability to restrict data collection from even Apple themselves, and that there is clear proof of that fact.
You probably buy food from a restaurant or food ingredients from a grocery store. You don't have to buy food -- you can grow it or hunt it yourself. But there are laws around food labels for a reason.
At the same time you do of course need to have a select group of people that are specialised to deal with this 'for the many', which is where you get government and regulation. But that's just an parallel path to a solution, not something that will 'repair' the lack of understanding from the users.
That's not to say that it used to be better or something; when you needed to know how electronics work to be able to buy, install, operate and maintain a basic radio it wasn't very widely usable. (but at least the users knew enough to 'own' their stuff)
or maybe there are 4x more Androids than iPhones
[1] https://www.forbes.com/sites/toddhixon/2014/04/10/what-kind-...
[2] https://www.newyorker.com/news/news-desk/the-link-between-mo...
In the US I believe Android/iOS is 50/50, but worldwide it's close to 80/20.
Abridging the 4th amendment rights of users wasn't enough: they had to abridge Apple's 1st amendment rights to even say how many times it happened.
These are the people who voted to suspend the constitution and due process in the USA:
The other (potentially more important side) of Apple's 1st amendment rights to speak are the subjects' and everyone else's 1st amendment rights to hear / receive information.
In telling Apple that they cannot reveal the identity of these requests, they are saying that I am not allowed to learn whether I was subjected to ones of these searches. Without being allowed to know, I cannot challenge the search, etc.
The same contra-positive-analysis is helpful with claims of "foreign interference" in elections, where I may have little concern for a foreign adversary's right to speak, but also take serious issue with the idea that I should not be allowed to learn about matters that may be important to and relevant to my vote.
A Transparency Report is still no substitute to Encrypted backup [1] because it made the assumption that every country 's law enforcement system are just.
If Apple cant provide encrypted backup due to pressure from Government, an iOS Time Capsule would surely be a great product. But that would go against the goal of increasing its Services Revenue from iCloud.
[1] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
or just use itunes backup?
2014: ~739 # Requests
2015: ~2,498
2016: ~8,998
2017: ~29,748
2018: ~49,494 # Users, display data changed this year
2019: ~68,994At least on desktop the country cards have a delayed animation and feels super unresponsive.
Also their web design has been accessibility-hostile often enough with the landing pages of Trashcan Mac Pro, iPhone 12 etc all taking over your scroll…
13761 devices?!
* German police put an unusual level of effort into locating stolen devices
* Many mobile devices stolen in other countries end up in Germany
* Germany has a high rate of phone theft despite low crime overall
I'm somewhat surprised, tbh, as I was under the impression that petty theft just isn't actively investigated because it's neither much of a problem, nor economical to do so.
> Device: High number of devices specified in requests predominantly due to return and repair fraud investigations.
> Financial Identifier: High number of financial identifier requests predominantly due to iTunes Gift Card and credit card fraud investigations.
> Account Requests: High number of accounts specified in requests predominantly due to fraud and cyber intrusion investigations and a third party app related investigation.
I wonder what "a third party app related investigation" is about.
0: https://www.apple.com/legal/transparency/us.html#twocolgreyt...
edit: Some data:
US: 15 million iPhones in Q2 2020 [0]
China: ~3 million in 2019 total [1]
[0] https://www.macworld.co.uk/news/sales-us-coronavirus-3794157...
[1] https://www.cnbc.com/2020/01/09/apple-stock-hits-new-all-tim...