Even if I consider Google enemy #1 right now, I also don't really see them as privacy unfriendly. They have a shitton of data, but what have they exactly done with it that warrants the moniker? Microsoft seems to me to be much more privacy unfriendly (e.g., LinkedIn)
Collecting and having that data to begin with is awful & dangerous. The behavior of collecting it is creepy and gross. The existence of the collected data is threatening.
Apple, Facebook, etc. may have (or not have) worse privacy policy, but it is much easier to avoid leaving fingerprints on their servers. Amazon & Microsoft are on the other hand particularly dangerous, though.
I’ve seen scammers find obscure payment portals and run through a bunch of card numbers to see if they approve/deny. Recaptcha prevents that. It’s obviously not the only way, but it’s low dev effort and it works.
Because payment systems that allow for cheap transactions are often leveraged to test stolen credit card data before making a transaction in person.
- iMessage is E2EE (with a big asterisk here of course)
- Maps data stays on device unless you explicitly enable anonymous aggregated crowd sharing data. “Significant locations” never leaves your device
- Apple Photos machine learning recognition all happens on device, not on Apple servers. This is one of my favorite features of my iPhone
- As of the next iOS update, Siri voice command processing happens on device
- The new Apple Private Relay (or whatever it’s called)
No they’re not perfect and they could (and should) do a lot more, but there are objective things that they do better from a privacy standpoint than most other tech companies.
“It is difficult to get a man to understand something, when his salary depends on his not understanding it.”
Upton Sinclair
You'll never get the developers (who are largely fungible) to fully grok the long term consequences of what they are creating because they are blinded by the (entirely natural) fact that the company is keeping them fed.
Technically Google also "promises" practically the same (E2EE in Chats, only sharing map data if you enable it, local photo recognition, local voice assistant on the new Pixel whatever, etc.). But since you have to trust them on this, all of it is not really much better than just having a reasonable "privacy policy" which we all know is meaningless.
E2EE for Messages literally rolled out last month, relies on spotty RCS support and doesn't work with group messages.
Apple Location tracking designed so that even when shared between your devices via Apple's servers it's not visible to Apple.
I have literally never seen Google claim Google Photos is using on device classification, I'd love a source for that since nothing about how it works implies that. Maybe you mean it does some very specific type of classification as a pre-processing step?
> But since you have to trust them on this, all of it is not really much better than just having a reasonable "privacy policy" which we all know is meaningless.
You're free to be wrong? You need to trust someone on a claim vs someone not making the claim at all... those are not the same thing.
Apple hasn't shown a reason to lie, and here's no equivalent financial incentive to Google unless you think Apple is pulling the equivalent of a fake moon landing and somehow running a 147 billion dollar data selling operation no one knows about...
The point is that they make extremely similar promises that you can't verify.
> You need to trust someone on a claim vs someone not making the claim at all... those are not the same thing.
What is the difference between someone saying that your data is not visible to them (oh but you can't verify it!) versus someone saying that they will not touch or store your data after processing it on their privacy policy?
When they control the entire platform, the fact that they claim to be doing something technical to prevent them from accessing the data is absolutely pointless. Even if it were true, they could be able to change it in an instant after a silent update (by themselves, by the government, or even by a third party attack!), and no one would be the wiser.
> Apple hasn't shown a reason to lie, and here's no equivalent financial incentive to Google unless you think Apple
Not sure I understand.
In any case, most companies have already lied multiple times, and _all_ companies share at least one big reason to lie: Come tomorrow, some three letter agency could send them the letter and outright force them to capture your data, and since the only thing that prevents them from capturing your data is empty promises, they could do it in an instant. And would do it. And in fact do it regularly (TFA could in fact be an example of Apple trying to get rid of that).
Btw,
> I have literally never seen Google claim Google Photos is using on device classification,
I have never put a SIM nor network credentials on my only Google Android device that has practically never abandoned my residence and yet it is tagging photos of objects. That's my source. I have not put a SIM either on my iOS devices and they do not tag pictures :)
That's exactly what I just explained, and I don't enjoy these kinds of circular back and forth.
If you feel like an OS where the biggest comfort is you can tear out it's core works best for you, go ahead.
But I will point out starting your comment with "I'm not going to get into the most important aspects of how secure a modern platform" is not a ringing endorsement.
-
I work on embedded Android for a living, so it's not like I'm afraid if what I don't know or something, iOS is a demonstrably privacy-oriented platform.
A mentality of privacy first even if it's just for the sake of marketing differentiation will always come ahead of a mentality of "data collection so we can sell ads", you're not going to change that for me with baseless insistence.
I do not see who is "subverting the most basic tenants of how your systems are designed", and if this is trying to say that the other companies are never claiming those tenants in the first place, then that is objectively false. Google, Microsoft, Apple, etc. have claimed being "privacy first" more times than I count, and, my point is, they are all making similarly dubious promises regarding policy (like, closed-source encryption, no data sent unless you ask for it, etc.).
> If you feel like an OS where the biggest comfort is you can tear out it's core works best for you, go ahead.
This is misleading. Thing is, it is not "tearing out its core" precisely because Google services are actually _not_ at the core of Android, yet. You still cannot do that with iOS (because they do not allow tampering to begin with, least you figure out a way to avoid leaving a fingerprint in their servers).
> "I'm not going to get into the most important aspects of how secure a modern platform" is not a ringing endorsement.
First, none of the topics mentioned are the "most important aspects of how [to?] secure a modern platform".
Second, I distinguish privacy from security. i.e. it doesn't matter if it was the most secure platform in the world if I have to trust all the data to a distrustful entity to begin with.
In fact, I actually prefer privacy over security. E.g. for messaging, I value using servers _I_ control/trust much higher than E2EE encryption, which is definite secondary worry. Metadata is a dangerous thing to leak.
> A mentality of privacy first even if it's just for the sake of marketing differentiation will always come ahead of a mentality of "data collection so we can sell ads",
This is basically trying to answer "to whom I put my blind trust?", so it's subjective. But in my experience it is usually the most "privacy marketing" companies that are usually the worst regarding privacy. See most VPN resellers. Most privacy marketing is just bullshit.
Like
> they are all making similarly dubious promises regarding policy (like, closed-source encryption, no data sent unless you ask for it, etc.).
I just listed multiple of the most common pieces of software where Google and Apple make claims to wildly differing levels of privacy! Does your decision that none of that matters because both companies mention privacy in marketing somehow override reality?
> First, none of the topics mentioned are the "most important aspects of how [to?] secure a modern platform".
You're not sure if "to" is the missing word?
And if you think the number of updated devices is not one of, if not the most important aspect of securing a modern platform, then your opinion on security doesn't matter. And contrary to your implications, privacy and security are not something you prefer over each other, privacy does not exist without security.
> Second, I distinguish privacy from security. i.e. it doesn't matter if it was the most secure platform in the world if I have to trust all the data to a distrustful entity to begin with.
It doesn't matter if you have the most private platform in the world if it's not secure? You can control all the servers you want, if they're not secure your privacy is even worse off than it'd be with a 3rd party at least trying to anonymize it for an ad platform...
> This is basically trying to answer "to whom I put my blind trust?", so it's subjective. But in my experience it is usually the most "privacy marketing" companies that are usually the worst regarding privacy. See most VPN resellers. Most privacy marketing is just bullshit.
Lol so your hunch based on VPNs is supposed to just supersede basic reasoning that if a company can profit off not selling your data wholesale, and is openly designing systems that do benefit your privacy... they're somehow less trustworthy than one that is openly selling your data and requires that they do to exist.
Wildly different? Apple claims E2EE, Google claims E2EE, _Facebook_ of all companies claims E2EE! Did it really change it your opinion of Whatsapp the fact that they claim E2EE? Everyone just laughed and forgot. Whatsapp is going to E2EE your chats right until they moment they don't, and without warning, and you have no way to check! Why take Apple's word differently? They also lied multiple times already! (e.g. Jabber federation)
> And if you think the number of updated devices is not one of, if not the most important aspect of securing a modern platform, then your opinion on security doesn't matter.
I am not sure why my "opinion on security" would be relevant but I for sure think that _ability to verify the security claims_ ranks much higher than anything that has been mentioned so far, including "software updates" of unknown content.
> You can control all the servers you want, if they're not secure your privacy is even worse off than it'd be with a 3rd party
The example is just to show the difference between security and privacy. Your analogy is creating a false association since I can just keep my data offline.
> Lol
And you have the incorrect "hunch" that Apple is not a services company. And that they design systems that "benefit your privacy". They only design systems that tie you to _their_ systems. Wake me up when they design something that doesn't, which would start to look like real privacy.
Like, I spoke about some very specific features, and now you've literally reduced it to "E2EE"... like the entire honking app that it's built around doesn't matter.
If you won't accept that Android's carrier-dependent, 1:1 only RCS app isn't equivalent to iMessage, then there's nothing to talk about.
> The example is just to show the difference between security and privacy. Your analogy is creating a false association since I can just keep my data offline.
How do you keep a messaging app offline.
> And you have the incorrect "hunch" that Apple is not a services company. And that they design systems that "benefit your privacy". They only design systems that tie you to _their_ systems. Wake me up when they design something that doesn't, which would start to look like real privacy.
Do you even knows what you're talking about? Or Apple is 100% a services company that's the whole point. They're a public company, following the money is easy, they make a lot of money off selling people services and hardware.
Meanwhile Google makes most of it's money selling people's data.
It's not rocket science figuring out which is easier to trust, but you just seem hellbent on rationalizing your opinions with more opinions stated as fact and vague paranoia.
That's your right, but don't be surprised if people call you out on it!
Okey, choose any other! What else did you mention? Location services? The same. * Local photo classification? The same. And so on and so forth.
* Both claim "Anonymous and encrypted", for whatever is worth, but we all know how "anonymous" and "encrypted" it must be since they are both using to build their beacon/SSID location database "to be used for augmenting this crowd-sourced database of Wi-Fi hotspot and cell tower locations.", wherever you want it or not (source: Apple's privacy policy).
> How do you keep a messaging app offline.
Or accessible to the relevant parties only.
> Meanwhile Google makes most of it's money selling people's data.
Google, Microsoft, Facebook, etc. also all are oficially _services_ companies....
> It's not rocket science figuring out which is easier to trust
It's not easy because you have practically nothing material to base your trust on, so you have to resort to fluffy marketing.
Claiming that Google is not that much worse than Apple is hardly "paranoia" material. Hitting a nerve there, I guess...
You're asking why someone would trust someone making a claim over someone not even making the claim.
I could ask a toddler "who is more likely not to eat your lollipop, the man who says he will eat it or the man who claims he won't" and they'd understand, yet you've managed to convince yourself that's a tough question.
Have a good one, good luck with your privately owned servers and home-brew OS. I'm sure your privacy is very well protected by giving the world a fingerprint on your identity.
... Since we are dropping the standards now, I will accuse you of being brainwashed. At one point you said:
> I have literally never seen Google claim Google Photos is using on device classification, I'd love a source for that since nothing about how it works implies that. Maybe you mean it does some very specific type of classification as a pre-processing step?
When Apple puts fluffy marketing claiming that now they are doing photo classification on-device, you immediately assume not only that it is true, but that they are _the first_ to do it, and that everyone else is doing photo classification on some fancy remote service. "Why, if Apple markets it, then everyone else would also have marketed it, otherwise it means they are not doing it!"
The thought that perhaps it was actually the opposite - that the majority of vendors were already doing photo classification on-device, and that it was _only Apple_ who was doing the stupid move of sending your photos to the cloud for tagging - never entered your mind.
This is the power of marketing.
And guess which one is rather likely to be true. I just took a couple of pictures of bananas in my 2018ish Android device with no network connectivity of any kind and after one minute they were tagged as "bananas" and "fruit".
This is precisely what I was complaining on my original post. Apple's privacy strategy is mostly marketing fluff at best, and yet it is having an unreasonable effect on people like you.
> I could ask a toddler "who is more likely not to eat your lollipop, the man who says he will eat it or the man who claims he won't" and they'd understand
A more correct analogy would be: who of the men from the shady vans is most likely to kidnap your children. The ones who claim to be "experts in not kidnapping children" or the ones who claim to be "experts in not kidnapping children, those guys at the other van are the real kidnappers".
> Have a good one, good luck with your privately owned servers and home-brew OS. I'm sure your privacy is very well protected by giving the world a fingerprint on your identity.
Again another ridiculous analogy that does not work. You do not need a "home-brew OS", and I have in fact mentioned several alternatives during the above conversation (e.g. de-googling).
“ Messages uses on-device machine learning to analyze image attachments and determine if a photo is sexually explicit. The feature is designed so that Apple does not get access to the messages.”
https://www.apple.com/child-safety/
Still sounds like E2E, no different from messages applying some processing/compression to sent images imo
At least with the right Android device I can flash my own keys to the trust root.
Of course, now they've gone and un-earned the reputation. Too bad.
With respect to this Apple thing, it’s pretty clear that Apple thinks this is more respectful of privacy than what the other providers do. IMO, this is what allows E2E messaging to actually remain E2E.
The EFF and some HN commenters are blending together the parental control aspect from the detection of illegal images aspect. They are two very different things.
And when you talk about the reality of privacy, you can, trivially, turn off the the third party features that trigger the use of cloud services.
This is rarely possible in the apple world for long
Against other tech companies. This whole debacle is a clear example where customers have no control. They can't even not update their device because its already there.
I can actually name a privacy feature that they took a long time to replace: Siri voice recording accountability. Siri voice recordings were saved in the cloud. They were linked to your identity. If you GDPR'd apple they deleted these recordings. They stripped the identifiers. Then you can't GDPR them, and its arguably no more private. LATER they stopped saving them to the cloud (yay more private again!).
To be clear: the voice recordings can identify you even without identifiers. Its your voice. You might say "how do i get too <work address> or <home adddress>. You might say "Hey siri, tell <secret lover> that i love them" and boom now that is out there. Lots of reason people want control there.
Second, starting in IOS 15 with an A12 or newer, the processing is moving on device. Here is an excerpt from https://developer.apple.com/ios/:
"iOS 15 introduces even more privacy controls to help protect user information. With on-device speech recognition, audio of Siri requests is now processed entirely on iPhone by default, and performance improves significantly. Mail Privacy Protection stops senders from learning whether an email has been opened, and hides IP addresses so senders can’t learn a user’s location or use it to build a profile on them. App Privacy Report offers an overview of how apps use the access that has been granted to location, photos, camera, microphone, and contacts in the last seven days, and which other domains are contacted."
Here is another discussion:
https://www.theverge.com/2021/6/7/22522993/apple-siri-on-dev...
I guess that's all about incentives. Since Google is an advertising company, it has most to gain by knowing your deepest personal info, i.e., so that it can "sell" this info to their customers.
Uh... they've aggressively gathered that data? If I take a bunch of photos of you sitting on the toilet, the concern isn't whether I've publicly done anything with those photos, it's that I took them in the first place.
That's how.
Instead of being motivated to use and/or sell user data, it's in Apple's best interest to keep that data secure and play to its competitive advantage as the company who is not trying to pry into its users' lives.
That said, I really don't understand why Apple would do this, and it is very disconcerting. Obviously child pornography is absolutely horrible, but this move seems to throw out everyone's privacy in exchange for catching what I have to imagine is a tiny minority of users who are involved with that.
That, for me too. From my perspective they basically don't have competition. The only viable alternative to Apple is "do everything yourself with open software, and just accept everything being buggier, jankier, and less helpful, while eating way more of your time". Obviously I'm not in love with that option, but what else? MS? Google? Ha.
If Apple stops being Apple it'll be the elimination of a whole category of products and services, essentially. Just won't exist anymore.
This is all less a product of Apple being wonderful than of user-facing computing everywhere else being an embarrassing shit-show.
https://medium.com/seedx-digital-marketing-guru/why-apple-sp...
It is all part of their PR and marketing. And they are very good at it. This happened in Tim Cook's era, not Steve Jobs. May be too good it backfired. If you pay close attention to all the Apple news, ( not some, but ALL ). Pick the top 10 Apple news site and read through it for a few years and it will surely get to most people. And Apple news are the most sort after, highest paid Ads revenue in tech sector. So it is sort of a feedback loop. Worth remembering there are relatively little journalist left, only reporters. No one bother to fact check anything any more. That is why we have so much crap that anyone has some domain knowledge on the subject will immediately smells BS.
And their PR tactics are.... dull or should I say predictable? Controlled Leaks ( I mean come on from the same press again? ) on the same subject or using same allies in testimony ( SnapChat again? )? Unfortunately most people dont do any analysis like this. ( Although I guess that is borderline forensic ).
Marketing and groupthink makes them join and buyers remorse makes them stay
Therefore Apple could focus on privacy in a credible manor, because it didn't threaten their business model and it was an argument they could use, but their competition couldn't.