In a way, nothing changed. Apple could've done on-device scanning forever. In another way, everything changed.
I'm not sure what I'm going to do about it. Problem is that the devices are really really good.
In a way, nothing changed. Apple could've done on-device scanning forever. In another way, everything changed.
I'm not sure what I'm going to do about it. Problem is that the devices are really really good.
EDIT: And they have CCTV and undercover security officers everywhere. More than you can possibly imagine.
Everything else with I agree. The eco-system of all these companies is never-ending (cars, food, cities, etc.). It's like those sci-fi movies where one corporation owns everything. The only difference is it's 5 or 6 companies because they haven't yet started to merge.
For a computer you can buy for the same money that you spend for a MacBook Air a computer with better specs and hardware that you can upgrade. Apple tends not to upgrade the oldest computers, leaving you with an insecure OS where you can't run the latest software. I have my battle Thinkpad that with Linux runs better than most Macbook and we are talking about a PC that has more than 10 years and I bought used on Ebay for 100$.
Really Apple is not that great. I once used to buy their product thinking they were superior, and maybe once they were, nowadays they are just the other crap made in China but sold at (at least) twice the price because they have the Apple logo on it.
If you compare two phones at 200$, sure. But it is not possible to buy a phone with a better CPU than the 500$ iPhone SE 2. Impossible, no CPU can beat it. So no Android phone has better specs.
For a laptop, if the case is considered a spec like it should, then you have a much clearer picture. Apple has perfected its aluminium processes to provide a rigid and shock-resistant casing, and inevitably when people provide legitimate examples of PC laptops to buy, they never mention that the laptop you'll get will have a shitty plastic case with a heavy steel frame. The worst of both worlds, and many friends have come to me saying they need to change their laptop when theirs is fairly recent. The culprit? their case broke or the display hinge did.
> So no Android phone has better specs
Because it's all matter of CPU. To me is more important internal storage, with 200$ you get nowadays a phone with 256Gb of memory plus a micro SD slot. Or it's important RAM, you get 8Gb of RAM (the same amount of my desktop computer), meaning you can have all the apps in background without issues. You get a fingerprint reader, that is more secure and usable than the stupid face ID. You get a USB-C connector that nowadays is everywhere, not the proprietary lightning port. You get a bigger battery that you don't have to charge everyday. You get a bigger screen with an higher resolution. You get an headphone jack. You get a FM radio (a stupid thing, but I don't get why iPhone doesn't put it).
> Apple has perfected its aluminium processes to provide a rigid and shock-resistant casing, and inevitably when people provide legitimate examples of PC laptops to buy, they never mention that the laptop you'll get will have a shitty plastic case with a heavy steel frame.
I don't care about the cool case of the macbook. I care about having a solid case, even if it's ugly plastic. My thinkpad t440p that I bought for 150$ on ebay I can carry around without worrying, I can spill a coffee on the keyboard and it will not break, I can make it fall from a ladder and it will not break.
Also if something breaks on a macbook, the only option is to throw it in the bin and buy a new one. How do you replace the LCD panel on a macbook? You can't, because it's all glued together and you have to replace the entire lid of the computer, that costs more than the computer itself. On my computer? Pop the display frame with hands, 4 screw and you remove the LCD, a 10 minutes job. Want to access the internal components? Two screws on the bottom and you have access to SSD, RAM, Wi-Fi card and CPU.
Want to change the battery? You will have to do so sooner or later, well on the macbook not only you have to disassemble the entire computer, but it's also glued with a strong adhesive, not only it's difficult to remove but also dangerous, since it's easy to damage the battery and since it's a lithium battery it can even explode. On my laptop just unlock the mechanism and the battery comes out, put a new one in and job done, 15 seconds.
Which specs? When I last checked, the latest M1 Airs were dominating the entire laptop market on CPU performance, battery life and not making noise. These are important considerations. I mean, sure, for the same price you can probably find better displays, more RAM, a bigger SSD, a better port selection, and all sorts of other things, but there are always tradeoffs, it's not like any laptop beats an Air wholesale on all specs.
If someone doesn't particularly care about upgradability (most people don't), the Air actually seems a pretty good deal. Perhaps they were overpriced before, but I don't think they are anymore.
Bought the latest SE over a year ago at considerably less than my last comparable Android device. Have spent under $100 in the App Store since.
Phone does everything that I want it to do including some fairly complex multi-app automations 15 minutes before I leave, when I get an SMS, etc...
I've read a lot of stuff by RMS and am certainly aware of his concerns.
I have an iPhone and Mac so I guess you would consider that I "ignored" him. This is a ridiculous conclusion. I considered the risks and trade-offs of non-FOSS software, and regrettably accepted them, because the FOSS alternatives had trade-offs that cumulatively (for me) were much worse. Unlike RMS, I am not a one-dimensional person that only evaluates tech on the single dimension of freedom. Tech is not a religion for me; it's just a tool.
RMS pontificating about FOSS does not magically bring iPhone comparable FOSS software and hardware into existence. If the FOSS community wants consumer adoption, ratio of pontificating about to building consumer products needs to be much lower.
I'm pretty sure that most go with habit and convenience. I mean.... Apple could lock MacOSX down tomorrow and charge you $100 for terminal access and "informed decision" people would still argue how good MacBooks are (they aren't that good)
I literally have to have an app to make my bluetooth mouse scroll in the opposite direction than the trackpad, because there is "Scroll Direction" checkbox in both mouse and trackpad... but it's actually one config option. And with every update I hope that they don't screw up that app... OSX has less and less of "less is more".
It's a mutually-beneficial trade-off, it's just that one party gains individually, and the other gains by quantity. Advertisers wouldn't care a lot what restaurants you like, but they care a lot about what restaurants people in your city like.
Ok, it is a "tool", but it's like an axe controlled by another person, not you. Maybe you trust that person with such a tool; I don't.
Not trusting Apple doesn't magically bring a trustworthy iPhone competitor into existence.
I'm afraid that'll never happen, at least, until most people don't care about their privacy and are willing to accept one-sided tradeoffs with phone vendors. BUT, there are alternatives like LineageOS that do a pretty good job. They only need more acceptance by public to be able to compete at the level of a trillion-dollar company like AAPL.
My beef is just with statements like "people ignore RMS," as I have yet to see any evidence of this. Everything I have observed is that anyone who has heard of RMS is fully aware of his concerns, but most of those people just have different priorities.
But spending your money on Apple products certainly won't either.
Well, purchase a Pixel 5, install CalyxOS or Graphene, lock bootloader again. Job done. Probably you'll lose some convenience, but you know, you may always ask some FOSS dev to bake a feature for you and pay for it.
The amount of money needed to bring CalyxOS to the iPhone level of polish and to get the same sets of popular apps on there is probably in the millions.
For example, say US government. I trust the US government not to kill me (Dutch citizen, not a terrorist, not a criminal, etc etc). Does that mean I trust the US government with my personal data? No, that's a different discussion. And if I were to trust them with my personal data, does that mean I believe the US government has integrity? No. I've been very disappointed with the US government with regards to a recent war (I'll refrain from details as its irrelevant), so they need to earn back credibility. In my language there's a saying 'vertrouwen komt te voet, maar vertrekt per paard' which translates to something akin to 'trust comes on foot and goes on horseback'.
> RMS pontificating [...]
Uh, no. RMS was right all along and you're still not getting it.
You bought devices you can't upgrade, you can't run software on, that oppress indie devs, that tax 30% of the market, that sell out freedom fighters in oppressive regimes, and that now spy on you. And now you realize the problem.
The only way out of this madness is to get the sensible representatives in Congress to move forward with an antitrust case. Breaking up the power monopoly will perhaps get us back to a place where we have rights. The way it is now, Apple is a central point of failure.
Again, everything RMS spoke was truth, and it's here again rearing its ugly head.
Our government isn't one person or one party, and that's a strength.
One of my local reps is leading the big tech breakup movement, and I'm incredibly proud to have her representing me.
Can you help me with a few? Maybe 5? I'm pretty low on the US government at the moment. I can name quite a few things we lead in that are horrible.
>One of my local reps is leading the big tech breakup movement, and I'm incredibly proud to have her representing me.
I think that's great but I doubt that will ever be allowed to happen. Too much money will be thrown at congress and they will either do nothing, or do nothing in a way that makes them look like they did.
I might agree with parts of your list, but I think that people are way too down on the US and its accomplishments. I wouldn't want to live elsewhere.
25th most democratic country ("flawed democracy") [1]
Which metrics? Defense spending? Healthcare cost?
[1] https://en.wikipedia.org/wiki/Democracy_Index#By_country
I have yet to see a phone with the build quality and value add that I need a mobile phone to have from Free Software endeavors. These are the table stakes for the majority of people. Not the list you just rattled off. You aren't even in the running to compete on the other value adds if you can't do the above.
What are you looking for out of this anti-trust case? Apple is not a monopoly. There are numerous privacy-focused phones and Android distros available. I think there just isn't a huge market for a privacy-focused phone (no, 1000 people on a HN and twitter is not a huge market.)
Actually it's not like FOSS community is fighting for your adoption, you know? It's you who should do something in order to make good things happen.
After emancipation, there were plenty of slaves who wouldn't leave the plantation, and became slaves-by-another-name in the sharecropping system. I don't think any of them were so up their own asses that they blamed the slaves who left for not making it easier to leave.
Also, RMS didn't talk about "FOSS." He talked about the inevitable future if we continued our trajectory, and suggested Free Software as the solution.
I'm also not going to make lowering your carbon emissions just as easy and convenient as using all of the carbon you want. Take responsibility for yourself, or at least don't actively denigrate people for being right.
it always some one else that is to blame, the rich, the evil corporation, the right wing, the left wing, china,.... etc etc etc
All I said is if the FOSS community wants consumer adoption, the path forward is making things consumers like, NOT blaming us for "ignoring" RMS, because no one ever did that.
Basically everything your post implies (that I think I am entitled to something, that I think everything should be easy, etc...) is not true.
As I keep pointing out again and again, all I'm saying is that people don't use FOSS, but it's not because they don't value privacy, not because they don't value freedom, and for the love of biscuits not because of anything to do with RMS or ignoring him.
The options are use an iPhone (not freedom), use an Android phone (not freedom), or use something like LineageOS. Using something like LineageOS is major commitment that most people don't have room in their lives for, because they have different priorities, which might also be very good.
EDIT: Here's a metaphor, it'd be like if you asked your friend who owns a car with an ICE why he keeps ignoring Al Gore's warnings about the climate. It's like, Al Gore can be right, your friend can believe in Climate change, and he can still decide he needs an ICE car because he's barely making ends meet and is trying to support a family. You can claim that your friend has made bad choices, but there is no argument that he "ignored" Al Gore.
I think humans - having been nomads for the most part of their existence – just aren't equipped to care for their habitat (say: ecosystems). It's rather recent that became important, <8k years compared to 250k before.
No, it's because FOSS has no economic model.
Well it would mean giving up the phone entirely.
My guess is that this applies to about as many people as the opposite “wants to control their device” stance. Which is to say approximately nobody. Most users probably don’t think about these things much if at all. They want a smartphone that runs the expected smartphone apps and has the expected smartphone features, and do not care whether or not some nerd can install and run some apps they’ve never heard of on his own device.
I imagine, though, that most people would have an opinion one way or the other about phones snitching on their owners.
I wish the android hardware ecosystem had half the longevity you get with the cheapest iphone.
Those are much more fun explanations than just realizing they probably have plants to start the cheering in a room full of fanboys
With current change, they have "partial" E2E encryption and Apple can decrypt them only if CSAM treshold is reached. If we leave all speculation, this is a great improvement for privacy in CSAM context.
You can opt-out from scanning by not using iCloud.
Source?
The distinction still needs to be made between AOSP and whatever ships on your phone or is included in play services. Especially on HN of all places.
That's why I specified "decent smartphone". I wouldn't consider the UX of Android without Play Services to be "decent".
But computers are another story. So far we still maintain some privacy there thanks to Linux.
Open source doesn't guarantee we have any type of control over it if the hardware is locked down. The reason is more that the industry hasn't bothered selling locked-down computers yet by default. The tech is there, Secure Boot + TPM. They just give us the options to override in the BIOS. For now.
It can though. See: GPLv3.
IMO the greatest failure of Linux was not upgrading from GPLv2.
More than half of YC’s hardware startups, not to mention Android and probably Teslas in their current form, probably would have never happened were they not able to embed Linux in a controlled manner without having to invest in catering to the four total users who will want to build a system image and reflash the firmware on their whatever. (Android has some means to do so and an audience much more interested in doing so but the point stands.)
I’m also interested in the legal framework around a software license that’s able to dictate the architecture and design of components around the software, and I suspect it will not survive if challenged, particularly in Europe.
The greatest failure of free software, to me, is thinking in absolutes and not studying how the world actually uses computers as time goes on. The concepts, ideas, and demands are stuck in 1991 and are basically “man shakes fist at capitalism,” while writing capitalist exceptions into the very Tivoization clause in question under pressure.
They have to release that code anyway. All they have to “invest” in is not implementing measures to prevent people using it.
You and I don't seem to share the same definition of Free Software. I personally pay for, and know others who pay for Free Software. Free is about freedom, not price.
> not to mention Android and probably Teslas in their current form, probably would have never happened were they not able to embed Linux in a controlled manner without having to invest in catering to the four total users who will want to build a system image and reflash the firmware on their whatever.
All they have to do is not go out of there way to lock down the ability to flash the firmware. It does not require extra effort to support this. It requires extra effort to block this.
-- Alan Kay, https://www.fastcompany.com/40435064/what-alan-kay-thinks-ab...
I have an iPhone, and pythonista is the only potential thing which fulfils the criteria of "computing", everything else is convenience.
Smartphones have done an incredible amount at bringing the consumption of the internet, audio, video and rich communication via social media.
But they have not brought "real world computing", because "real world computing" is any goal-oriented activity requiring, benefiting from, or creating computing machinery. It includes the study and experimentation of algorithmic processes and development of both hardware and software. It has scientific, engineering, mathematical, technological and social aspects.
You might want to read the wikipedia page.
>"In a general way, we can define computing to mean any goal-oriented activity requiring, benefiting from, or creating computers. Thus, computing includes designing and building hardware and software systems for a wide range of purposes; processing, structuring, and managing various kinds of information; doing scientific studies using computers; making computer systems behave intelligently; creating and using communications and entertainment media; finding and gathering information relevant to any particular purpose, and so on. The list is virtually endless, and the possibilities are vast."
I basically would half agree that iPhone brought more computing. Based on practical applications, iPhone has not brought radically more computing. iPhone replaced some stationary computing with ultra-mobile computing.
Cheap feature phones, that allowed people in Africa to make cashless payments, brought more computing to ordinary people... than expensive iPhone - that is owned by people who have/had other computers.
People who formally require computing - engineers(all kinds, incl software and structural), data collectors, music professionals and so on - still rely on other forms of computing. Some have shifted to iPad, which made computing more fun. But then all of the heavier forms of computing - they are still done on a "computer", not a phone or iPad.
> But computers are another story.
Librem 5 and Pinephone smartphones are computers running GNU/Linux.
With a close garden and close sourced apps, there are basically nothing you can do (to make sure you're not being monitored). Completely at whim, true for regular computers too, but a lot more choices exist for the latter group.
The worst part is that now the dam's broken, it's all bleeding back into "computers".
And the computers that don't have "bad apps" are hacked and encrypted by ransomware. Is that better?
Spyware is older than smartphones.
I'd rather give all of my DNA to an advertising company.
Back in the day, before cellular phones, mainframe and minicomputer vendors tried their best to restrict the software that could be run on “their” hardware. They realised that they could squeeze the most out of their customers that way.
Would it be any different if Dropbox was scanning files before it uploaded them rather than afterwards? It already computes hashes of your files on your device so that it doesn't have to re-upload existing content, so I honestly don't understand the objection to doing image scanning on your device before uploading your content.
But this is not the time to throw our hands up and say there was nothing we could do all along. That the situation was never ideal does not preclude there being something worth fighting for.
The devices are good, but still Apple has a weak value proposition.
Also, handing them your money probably isn't going to make things better in terms of alternatives.
their devices are really good, but they come with so much crippling for the sake of the walled garden that their goodness is wasted in some fronts.
There's a large list of things they are (or can be with minimal effort) perfectly capable for, but are forbidden for reasons, like reverse wireless charge of other iphones / airpods.
In my book that's a step in the direction of privacy, compared to old status quo.
The conversation is around Apple, which is critical, but we need to compare them to the rest of the industry, and discuss the government/citizen tradeoffs in that light. I.e., holistically, not per company.
Then you get to choose whether to push your data to the third party or not, given the risks involved.
The author even notes they were opposed to Facebook's end-to-end encryption previously, I assume because as for defaults it sets a precedent and makes it unsearchable, but I'm not sure the specific tradeoffs they weigh and points they consider since it's behind a paywall (and I'm not sure I agree).
> discuss the government/citizen tradeoffs in that light. I.e., holistically, not per company.
Right now the differences are essentially per-company, since we've let our experiences be controlled almost entirely by a small subset of companies. To abstract the implementation from the primary implementer is to obfuscate some of the cause and effect here. We should discuss this as a societal tradeoff, as you note, but we should not ignore that this was spurred by a company running out in front of what was required of it and implementing this system which many see as at the expense of their users privacy.
You get to choose whether to push your data to Apple and trigger the scanning with their solution too.
The key escrow option is strictly worse.
That's purely an implementation detail, and subject to change at any time. That's why people are upset.
One solution is limited to you actually pushing your data off your private device, the other is limited to a list of items you say you want to push off your device, but actually happens on your device.
That's the difference between someone searching a large warehouse you and many others have stored belongings, and someone coming into your house and searching through your items freely as long as they're on the list.
Beyond the difference in privacy that search entails fundamentally, people are very worried that the list itself is limited only by policy, and truly, the search of items on that list has full access to your private details but for the grace of those performing the search and controlling the list.
The key escrow option is strictly worse than the current implementation, but it is also naturally constrained and the exposure is entirely user controlled. If you do not put data online in that situation, there is no way for them to process it without first exfiltrating it, which we already have laws and systems in place to hamper.
That’s an evergreen complaint. If they want to introduce a general purpose scanning mechanism they can do so at any time. This is not that.
> That's why people are upset.
I don’t think so. I think they are upset because they don’t like the fact that Apple has any power over them and this remind them of that even though it is not in fact an abuse.
I actually agree with this, but I don’t think that claiming Apple’s implementation to be something it is not is helpful.
The key escrow solution is strictly worse in any future. If key escrow becomes established as a norm between cloud providers and law enforcement, then no free alternative will ever be possible.
I don't think that's true. Systems or programs to encrypt locally before pushing up to a shared platform are possible and currently in use. Those that want that additional security have recourse to get it. Alternatively, people could run their own cloud sync instances (also already available in some forms). This puts the control in the users hands (don't sync to cloud, pre-encrypt to shared cloud, or do some personal sync thing), while also setting a clear precedent of what is acceptable on users personal devices.
The problem here is that this implementation really has nothing to do with cloud sync. Apple has currently linked it to whether you're pushing that data to iCloud, but that's an arbitrary distinction. In the world without iCloud, they could make it scan any media that was sent across the network. The iCloud distinction is entirely arbitrary, which is why people are not satisfied with it. There is nothing beyond promises to keep it that way, and promises are less binding than laws and national security letters.
It is built into the photo uploading mechanism and only scans photos in a very narrow way that can’t be twisted into generic scanning.
> they could make it scan any media that was sent across the network.
Definitely false. It cannot match anything except photos in this very narrow way.
> There is nothing beyond promises to keep it that way,
Not true. The mechanism cannot be used as a general purpose media scanner.
What is true is that Apple could add a general purpose scanner in future, but it wouldn’t leverage this mechanism, and their potential to add arbitrary spyware has always been there and is not changed by this.
Why?
What's to prevent them from pushing specific hashes to a specific phone?
There is no technical reason why they could not push individual hashes to individual phones, only policy ones.
I’m going to go further and say that people are doing a very bad job articulating why the incremental privacy risk of the scheme is significant, over the always-existent privacy risk of a proprietary vendor updating software they entirely control to scan data uploaded to a cloud service which guarantees no protection from vendor access. A later software update to include more hashes or whatever could always regress privacy.
The problem with this sentence is that Apple assumes that they can't target specific individuals because every iPhone and iPad user has the exact same database in their iOS device.
But what if they have a hash in the database where they know that only one person has this exact image on their device? This way you could single out one individual with the same database.
However, unlike with Apple's invasive on-device scanning, you can encrypt files before storing them at Dropbox or Google Drive. There are even simple turnkey solutions like Sookasa:
"Sookasa acts as a transparent layer over Google Drive to encrypt your sensitive files on the cloud and across connected devices..." https://www.sookasa.com/GD
"Sookasa protects data both on devices and in the cloud, and decouples the data from the encryption keys, meaning your data stays secure no matter where it goes." https://www.sookasa.com/dropbox-security/
This isn't a step towards privacy and it sounds (to me at least) like quite the logical contortion to argue that it is.
The part I object to having my life disrupted by having my personal accounts unilaterally deleted by a fucking buggy bot. Our phones are too important to us to just have them shut off without notice. That’s bullshit.
I was at Apple for more than a decade and a half. I saw an untold number of Michael Bolton bugs [0]. It's one thing when a bug causes a dropped frame in a video or a menu takes a tenth of a second too long to appear. It's another when it ruins your life and bankrupts you defending yourself.
Scans on a local device feel quite invasive to me. Phones have become an extension of our person, let's not kid ourselves.
In a few places taking pictures of your child naked while swimming is considered child pornography. Other places having children run around naked on the beach is the norm. (I have a few pictures of me, at 3y/o, naked on the beach)
In the world of remote medicine, can a parent take pictures of their naked child to send to a doctor?
How are they going to fit their cultural specifics to the world?
Knowing how Facebook dealt with it - they are going to apply the strictest rules, so no naked child photos are allowed on your iPhone anymore. For no reason.