Apple says it'll remove iMessage and FaceTime in UK rather than break encryption
9to5mac.com
9to5mac.com
And shortsightedness on the side of lawmakers is baffling. Nobody takes responsibility for vision, we just go along with implementing solutions without considering broader impact or history. If the government has all your correspondence and the government falls into the wrong hands, you're toast, assuming you do not align with the leadership. We're writing that possibility off, but someone gets to brag that they've written legislation to stop the bad guys -- and maybe they did, but the cost was our collective freedom.
What is acceptable (even legal) today may not be tomorrow, or in X years (10, 15, or more)..
If we allow all our private conversations and messages to be permanently archived (and you know they will be, disk space is effectively infinite), who is to say that wouldn't be used against us in the future when laws, or even social standards, have drastically changed?
https://duckduckgo.com/?t=ffab&q=facebook+police+abortion
It's the first like 4 links right now
How much do you want to bet states like Texas or Florida will use government surveillance to prosecute folks seeking medical care?
I give it a month before we hear about someone being charged with some form of conspiracy to leave the state before their poor kids are taken. "Exhibit A will show the defendants intent to move their children across state lines..."
I'd like you to back up that claim because from what I had seen about surveillance and terrorism most people supported it(even the patriot act had popular support in the polls). Only people smart enough to know about encryption oppose this. Most people who don't understand tech pretty much assume the government is already looking at messages. Long before snowden, illegal phone tapping was a public secret people were fine with so long as the government doesn't abuse that access. Even before computers, they had secret rooms where they opened to read people's letters without a warrant. Not one major political candidate that I can recall since 9/11 has mentioned expiring the patriot act or investingating the NSA and recommending criminal charges in their campaign, nor does it get brought up in their town halls.
But generally speaking, I dont think you’ve emphasized it strongly enough. People arent just supportive of trading privacy and freedom for the promise of safety. They are literally begging for it.
A big part of the issue is that the nature of the conversations has changed. Mail and Telephones were never at any point perfectly private. The idea of having complete privacy in such conversations is actually rather new.
The difference is that those communication mediums now represent nearly all communication, rather than a small fraction of it, and that the effort to meaningfully break that privacy has dropped significantly over what it would have required to surveil millions of people in the 1950s. It doesn't require an East-German-esque security state anymore.
Had those rights been respected all along instead of exploited by perverted, power-obsessed authorities because of how easy it was, it wouldn’t be such a shock to lose the ability again. At least in the US where a right to privacy is a constitutional guarantee, I would hope that Apple and others would defiantly continue to offer encrypted services despite government threats. It would seem like the Human Rights Act guarantees the same right, though I don’t know if it has any higher precedence than any other act parliament.
In principle they were not private but in practice they were because in most places the police had to realize that there was a conversation of interest, get a warrant, and use scarce resources.
Now the authorities are able to use machines to monitor traffic patterns for almost all communication the cost of interception is much lower.
Point being, one shouldn't assume that government agencies will adhere to the standard we might wish them to when choosing means of investigation or surveillance.
[0] https://www.nbcnews.com/politics/national-security/fbi-warra...
But now resources are less scarce and the task is easier so blanket surveillance and recording is more nearly practical.
The USA is still doing pretty good but the UK and the EU are staunchly anti privacy. They're pretty good on consumer privacy but don't believe that privacy from the government should exist.
I guess my question boils down to what specifically does the US do right that the UK and Europe does worse?
First, the TFA is about Apple, not the US. The US gov. also attempted to get backdoors from Apple (only to give up and go for the standard security vulnerabilities instead of getting a clean entry point)
Then cloud data stored on Apple servers is still open game, and Apple syncs message on iCloud by default. There's very little incitive for the US gov to burn political will on this issue when it won't matter for 99% of people using the devices. Except the UK gov doesn't get that privilege as the data is on US servers, not UK ones.
That said, it has become apparent to me that we need to impose further limitations because apparently the whitelist/blacklist approach we have thus far is insufficient and the Anti-Federalists were much more correct in the long run.
This is also an opinion commonly shared among people living in a country. Otherwise you either have a dictatorial state preventing people from leaving/reacting (keeping them dirt poor being an option for that), or the people rioting in the streets for months until something breaks.
Traditionally, couldn't they with texts? And with all the major social media players?
Isn't stuff like Signal they can't track relatively new and getting outlawed in many places?
For a democracy to function, people need to be able to have free and candid discussions about any topic without the fear of being ostracised, persecuted or whatever. Only that way can ideas be exchanged and people get a hunch of what others think about stuff of relevance. Only that way can people partake in sensible democratic decision-making. Framed opinions pushed onto you by one-way media are no substitute. That's dictatorship in disguise.
"Classic" ways of public communication, like town halls, pubs, marketplaces or whatnot, cannot fill that role any longer. But online, places like Twitter, Reddit and some chat services that closed the gap now get killed off, too. This dystopia cannot be let come to pass.
Tho as I understand it, Signal's security is more robust.
If I provide privately owned physical infrastructure for protecting those strings and facilitating the routing of the strings am I obligated to make that available to the government for eavesdropping?
It shouldn't be murky at all. For all of the history of humanity, privacy has been the default state. I could talk to people face to face (what used to be the only way) and it was by default private. I could keep written notes and records and they were by default private.
There were special-case mechanisms to violate that privacy (e.g. search warrants, targeted spying) but by their nature they target specific people and, at least most of the time, go through a process with some checks and balances. I don't have any objection to this type of spying. If someone is suspected of a serious crime, it's reasonable for society to have a way to approve planting some surveillance bugs on them and them only.
It's only now that nearly all communication is over third party systems that government suddenly feel it's ok to spy on everyone and all the time. It's clearly not ok, nothing murky about that.
I think this is why it’s such a hot issue though. E2E Encryption is a “get out of all surveillance free card.” Even a mildly trained criminal or terrorist can easily guarantee that his communications will never be intercepted. This has never existed before.
I share with people in the pro-Encryption camp the acknowledgments that you can’t un-invent encryption, so you’ll only be catching the most dim-witted criminals by nerfing the mainstream messengers. Anybody can use the ‘OpenSSL” cli to make unbreakable encryption no matter what laws say.
But I also acknowledge how frustrating it is that a truly bad person can simply bypass all the “just” exceptions to privacy, like a search warrant, if they’re even a little savvy.
TL;DR nerfing iMessage (etc) ain’t it, but I can see how non-evil people in law enforcement wish something could be done about the root problem, which is somewhat new.
An experienced and higher public official will get permission for everything. There is neither a check, nor any balance at all. This is true for every country that pretends surveillance would happen with care.
> get out of all surveillance free card.
Because it is the only encryption that works.
That's the misdirection the pro-surveillance agencies use but it's not true at all.
People still ultimately exist in meatspace (as it used to be called). If you get a warrant based on legitimate suspicion to follow someone, you can assign detectives to follow them, plant bugs in their home, wire up collaborators and all the endless techniques that were used before the internet was around. People are still people and they walk around in the real world, they can be spied upon.
Sure, it's not as easy as sitting back in the DA office and spying on everyone all day long with zero effort, but it should not be. When the power is given to remove fundamental rights to privacy from someone, it needs to be based on a legitimate process and it must take effort. If it is zero-effort it will be relentlessly abused.
Ok that’s another fallacy though. Before, authorities could get a warrant to wiretap phones and to check the outsides of your envelopes (a “mail cover.”) Only an idiot criminal would ever make a phone call or mail a letter today for anything even remotely related to crime because e2e encrypted calls and chat apps are a thing now, removing lots of risk (nobody can do anything short of getting in the room with one party and peeking over his shoulder, which is not just hard for “lazy” cops, it would be hard for elite international spies). That’s a whole new thing, and a big deal if your job is say, stopping and apprehending human trafficking rings or organized crime.
Again though I’m not saying “and that’s why we should have a back door for cops.” I’m not and we shouldn’t. Just that people who say things have changed in a very impactful way are not being hyperbolic or dishonest.
So basically, before the invention of phones, no criminal was ever caught?
Clearly that's not true. It is entirely possible to follow and spy on people in person and that's how it was always done before the 20th century.
Just because new technologies exist does not justify using them to inifinitely augment surveillance powers of the state.
> a big deal if your job is say, stopping and apprehending human trafficking rings or organized crime
You don't succeed at human trafficking or organized crime if you never leave the house and spend all your day just chatting on signal. You have to actually go out into the real world and do the crimes. As soon as you step out of the house you can be followed and monitored and caught in the act.
That line is called the Third Party Doctrine:
https://en.wikipedia.org/wiki/Third-party_doctrine
"The third-party doctrine is a United States legal doctrine that holds that people who voluntarily give information to third parties—such as banks, phone companies, internet service providers (ISPs), and e-mail servers—have "no reasonable expectation of privacy" in that information. A lack of privacy protection allows the United States government to obtain information from third parties without a legal warrant and without otherwise complying with the Fourth Amendment prohibition against search and seizure without probable cause and a judicial search warrant"
... but if you really want true privacy:
"If you want to keep a secret, you must also hide it from yourself" -- George Orwell, 1984
Playing devil's advocate: in most US states, the FBI can in fact plant someone with a wire to record a private conversation. They don't have the resources to record all in-person conversations, but maybe they would if they could.
For some reason, they never do, and they usually get rather upset with me.
Government: “Allowing it might be as dangerous as a gun!”
Problem is most people aren't politically involved and just don't think about any implications of a state being able to fish your messages. And for tech affine users this will likely not be true, but certainly for the masses.
They don't even care how it seems. They'll do anything illegal if they will make more money by doing it and being caught than they'd make not doing it at all. Lucky for them they routinely get tiny slaps on the wrist for things that would get any other "person" executed or put away for life. Once you have enough money, crime usually pays pretty well.
Many people believe this is happening with your phone. It's a recording device after all, and usually carried by most people. If not you then someone nearby likely has one. All these conversations can be transcripted automatically and the vast amounts of text can be analyzed by AI for whatever purpose they want. The infrastructure is already available.
In this plan messages are sent to a third party for analysis. Sure the messages sent to the third party are encrypted but your privacy is entirely violated.
"The most common way people give up their power is by thinking they don't have any." -- Alice Walker
Behind every door and every locked place there could be child pornography and illicit materials hidden!! Every house, every hotel safe are suspects!
Criminal oversight, criminal oversight!
(and if they think their reasoning for backdoors into online chat and conversation is mandated by this supid reasoning of theirs then it must be valid for all entrance doors of every home and buidlding and every locked spaces as well! Getting easy access to material without assistance or knowledge of the people involved.)
https://www.reddit.com/r/facepalm/comments/zcvwno/steel_rein...
Opening the door lets a group of them quickly file in at once to swarm the occupants.
- they still have to be physically there
- one team can do only one raid at a time
- people know if they did a raid
- they needs a judge order and because the previous point you can counter sue if reasonable, at least theoretically
- they can't impersonate you all around the globe including in countries outside of the UK just by raiding you
- a raid is time wise also limited
- police being able to raid doesn't prevent you from guarding yourself against random criminals or agents of foreign hostile governments raiding you
- you know when you are raided
- you are still allowed to put steal doors in your home
- I probably missed a bunch of points
I.e. it's not the same, not at all.
A more correct comparison would to state police can raid you, so they should be able to hack your device but only to retrieve information and being required to leaf a message behind (and even that comparison has issues).
I think this is the big change people miss when it comes to police powers in the digital age. There's not been really been a culture shift from the police nor the citizens about police powers, just a increase in quantity of ability that has turned into a difference in quality. For decades agents of the state have had the theoretical ability to surveil people, and the people were generally OK with it because of the assumption that "well they won't bother doing it to a random guy like me", which was true, back when it required actual footwork, and even pulling up someone's file was a physical task
Assuming one does accept targeted surveillance in extreme cases, then I'm not sure how to solve this apart from the frustratingly "stupid" and probably unenforceable solution of requiring the police and intelligence agencies to be stuck on 90s tech. Theoretical legal sanctions against doing this appear to have no teeth, the only way to discourage surveillance abuse is to make each instance have a non-circumventable operational cost
So to use a concrete example: I actually like private CCTV in public spaces. I do feel safer knowing the police can use that footage if I'm a victim of crime. But I only accept it because most systems are just writing to a local device, meaning there's a cost to the police asking for it. Any scheme to automate access to these records over the internet, no matter how well-meaning and theoretically legally restricted they are, would inevitably be used to make those scenes from The Bourne Ultimatum seem quaint
No one is mass-sharing their safe of child-porn worldwide with thousands of other child-porn voyeurs.
The internet and its ubiquitous accessibility combined with digital image file formats has changed the landscape for those that would fight these heinous crimes.
It is indeed a new and special case where a locked safe is not.
I wouldn't call 1 on 1 chats mass sharing
I see no reason the give the gov eyes on everything when they have a perfectly valid route to investigations.
These government agents are people as well, and as people they'll suffer to wade through the dark corners of the web to locate a minuscule part of all the CP data available worldwide. These people will inevitably require mental care to deal with the trauma of looking at GiBs and GiBs of small kids being raped, that's not a cost we can handwave to "we employ government agents", there's not a limitless supply of people willing to do this job, and doing this job doesn't come for free, not for the individuals doing it neither for society (mental trauma care; staffing high enough to allow rotations and avoid burn out, or PTSD, etc.).
Plus even if you did dragnet everything, you'll still need a human in the loop to verify the findings, even if ml classifiers are used to find leads.
Plus what about people that just encrypt their messages locally before sending them across a backdoored platform? The gov can't make encryption illegal. It's just math. Folks will steno it into memes or whatever is hot that gets shared to allow it to live in plain sight.
Security back doors also carry the risk of having the opposite effect. We’ve seen many examples of powerful, nation state developed tools being leaked online.
There may be a rise in scenarios where people (including children) have their personal devices breached and are extorted for the exact thing the security backdoors were created to prevent.
Governments use CP/Abuse to pass legislation, which is immediately used for almost anything other than that. If a government did actually care about child welfare there are many things they could do that would actually help children.
But this law to "protect children" is being passed by a government that is simultaneously cutting services that help children, and also trying to reduce/restrict sex ed that so that it is easier to abuse children, I'm going to say that "protecting children" is not their goal with this law.
As I said elsewhere, any argument for "we need the ability to remotely access the content of a phone" (which is what the law is demanding: silent updates to remove encryption and anything else they "need") equally applies to having a government mandated cameras in every house. That would actually prevent child abuse. It would prevent domestic violence. If such was happening the police could intervene immediately. It would remove he said/she said from courts: you can simply play the video from the home.
By the definition of "no encryption because protect-the-children", mandatory cameras in every room of every house is both acceptable, and also objectively superior to BS anti-encryption laws. You can't abuse or beat your family members in the first place if a camera is watching, but anyone moving CSAM around on the internet isn't going to have a problem getting an actual encrypted channel - all the law does is make your personal communication, banking, finances, etc insecure, criminals are safe. Of course even if someone does use a now insecure communication channel to share their child abuse it's moot: the cameras in their house would have already caught them.
So why screw around with "make everyone (including children) unsafe to 'protect the children'" when there's a much more effective solution that would stop the abuse in the first place?
Also, the UK already passed a bunch of "you don't get privacy" laws in order to "prevent terrorism", and they seem to be used primarily to catch people not picking up dog poop, not paying tv licensing fees, etc which sure as shit doesn't sound like it's terrorism related.
In summary: if a law that would otherwise violate fairly basic rights is being pushed with clearly emotive justifications like "child abuse", "terrorism" you should assume you are being played.
The police do not need more power. They do not need to violate everyone's rights. They need to do their jobs and do actual work with what they already have, and demonstrate basic competence before they get any more invasive tools. Recall the Ariana grande bombing in the UK? Multiple friends and family of the bomber had independently and repeatedly reported them to the UK police. 9/11: multiple US government agencies had all the information needed, but were too busy trying to compete with each other. In addition (tens of, if you look at the US) thousands rape kits that aren't even processed, and weirdly they keep finding serial killers and rapists when. they. just. do. their. job.
Throwing away more of our privacy, when police already have huge amounts of information that they just can't be bothered to look at, is beyond stupid.
Similarly, based on the track record of supporting and aiding child abusers, and cutting support for children, any claims a government makes saying something is to "protect children" is clearly false.
The whole system around children is setup to protect government against children, FIRST. This will not change with surveillance, in fact it will be made a lot worse, and this is a far bigger problem than CP.
So if people claim that all government people are "good people", who are "just trying to help". The problem is the result. The real question is what happens to those children, to the victims, the rest doesn't matter.
To some extent that's actually true. Most teachers that eventually get convicted for ... students aren't pedophiles. They're people with no previous offences, who really did start their job to teach, who at some point lose their self control when dealing with children, because it's so easy. The problem with it being so easy, which leads to the sad observation that they tend to be responsible for a LOT of children, and therefore make a lot of victims before anything is done, because the system is set up to protect them. The current record is a German director of child services, who sexually abused over 30000 children. You might ask how you can even do that, that's almost one child per day, for a decade. The sad answer to that is that he had a large team around him. Teachers, in more normal cases are accused of abusing between 5 and 10 children.
And the outcomes ...
https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8225538/
https://www.jstor.org/stable/30034577
These people know this. They go through the web merely to punish and use violence against society to force what they consider decency standards. The problem is, they do not help these children, they usually only damage them (which leads to constant embarrassments. FBI 2 years ago proudly announced they had done a razzia, and "saved" 43 children from prostitution. Before 2 weeks passed 41 out of 43 of them had run away, with the very large majority very likely going back to prostitution). They just throw them into the child services system which destroys these children's lives far more than even actual abuse does. And, of course, mostly they were not abused but protected by their parents, and were far safer at home. And even that's ignoring that this is government: a significant fraction will get deported if they don't run away.
And this is ignoring the "accidental" studies, which follow this pattern: someone wants to make a career and needs, effectively, to find a large amount of children abused, to get attention. These can't be actually abused because of how humans work: abused children ... abuse others themselves, damage themselves, do drugs, act in criminal ways, ... So nobody in the system wants those, at best they are very problematic children. What these individuals need to do is convince authorities that a large cohort of normal (very young) children are in fact abused, and "need help". Mostly, of course, they don't tire themselves, and do this by simply lying, then ripping the child from their family, but for example there's the "on this anatomically correct doll" scandal.
The "plus" side of this is that we have plenty of evidence of the effect of child services ABSENT earlier abuse or problems in the child's life. And the evidence is damning. These children don't study. They suicide 10x more than normal children. They essentially do not, at all, continue studies after high school, and a high percentage doesn't finish high school
I would like to point these are studies, but this is extremely visible to people working in the field. The help government provides doesn't help children. They know this, yet they keep working in this system. This is, obviously, not moral.
We already have mountains of awful laws that are passed via appeal to csam emotion. I see no reason to pass another one under the appeal of csam reduction when we all know how it will really be used.
They literally are though? Numerous cases of child abusers abusing their children and publishing the footage of it from their homes, not to mention the mass storage and hosting (hosting _may_ be less common now).
People physically abuse their family and children at scale (domestic violence is not rare), a really good way to stop this would be to mandate cameras and microphones in everyone’s houses.
Don’t worry though: to see/hear recordings from inside someone’s house police will need a warrant.
(But Apple is in the right in this case.)
Sure you could limit yourself to known contacts, but that wouldn't make you rich nor would it create self-sustaining network.
This is exactly the opposite of how it works in the real world.
Or, better, do you shit with the door open?
But it feels like to really achieve successful political pushback on something of this magnitude, it really requires going on offense.
Like, why are all the headlines not "Dudes in law enforcement demand access to millions of young women's intimate photos"?
That said, it’s still creepy, I agree.
Have you seen doors in the uk? Most are just there for design.
They can't break most encryption with force.
Their (former) empire is a part of their cultural identity. It's going to take a few more generations to shed the expectations of what was.
The days of two washed-up subjects of the crown taking Kafiristan all on their lonesome are dead and gone.
The UK with Brexit are starting to find out very quickly how insignificant their nation is and how easy it is to route around the oversized egos of their so-called leaders.
The UK isn’t trying to tell anybody what they can do in any other country. It’s just laying down the law for what happens within its own borders which it’s entirely within its rights to do.
Equally why you would think an American company could or should tell the British government what to do is surely itself an example of empiricism is it not?
Further, they aren’t large enough to block the deal so they will only make things worse for their own citizens as it will just deny citizen access to certain products and services or create or otherwise cause companies pull out of the market causing businesses and citizens to look for sun par alternatives.
Apple and Microsoft can’t tell the UK government what to to, but the power dynamic is still what it is and the reality of what blocking the deal will actually accomplish is still the reality.
Does it boast something else to make up for the loss of these things? Trading something for nothing always feels kinda bad. And if the trade is "We stood up for the right thing with respect to Cloud Gaming monopolization", you constituents might be kinda pissed after a while.
You know the old adage "Bread and Circus". Well you gotta make sure the circus is running well.
Meaning is the law good regardless of what Apple decides to do? Or is it only good if it forces Apple to break encryption?
I think the answer is obvious. Its not a principled law. Its just a threat. They wouldn’t rather lose access to facetime and iMessages than have access to them but encrypted. Thats just crippling themselves.
I don't hold any of the British government departments in high regard, so I will assume malicious power-seeking on their part regardless of anything else.
But for the principal of forced decryption?
Most non-criminal organisations don't know how to secure their communications properly, so while organised criminals that hire decent IT can trivially secure their communications, I don't expect criminals to be generally capable of keeping out of sight of the authorities.
Non-professional criminals will probably all get scooped up easily by a surveillance dragnet.
And the only way past the competent criminals is old-fashioned intel gathering.
But the British government can't actually act on dragnet-scale information anyway:
They've been cutting back on police, court buildings, magistrates, public lawyers, prison buildings, prison staff, and parole boards.
Even if they hadn't, surveys of drug use alone suggest they'd be criminalising a double-digit percentage of the population they can't afford to put through the police let alone the courts. Given what the UK counts as "extreme" porn, I'd guess that's also a double-digit percentage of the population.
And for the other, anti-monopolistic market authorities, the "boast" is a level playing field.
It's easy to criticize a government when you know there will be no retaliation. To judge a company's true stance on such issues see how they behave when there's a prospect of real financial loss.
If Apple weakens crypto for the UK, it affects people in other countries as well. iMessage is not exactly popular in the UK, so it is disproportionately used for transatlantic communication compared to WhatsApp. If Apple complies with the law, they are violating the privacy of users in the US as well.
You say they are not comparable, and then compare them in a way that backs up the point you're trying to argue against. It _is_ two-faced of Apple to give China a pass here, undoubtably in large part due to the massive loss of sales were they not to comply and be removed by the Chinese regime.
> China is a totalitarian regime where even an imperfect freedom is preferable to no freedom at all.
If the Chinese gov't has the keys to unlock "private" conversations, how is this "imperfect freedom" in any way different from WeChat or other state-sanctioned messaging systems?
> The UK is a democratic country which should be upholding the right to privacy.
I mean sure, but Chinese people should have the same rights of privacy as anyone else. It's not suddenly less-bad because their government is totalitarian.
> If Apple weakens crypto for the UK, it affects people in other countries as well. iMessage is not exactly popular in the UK, so it is disproportionately used for transatlantic communication compared to WhatsApp. If Apple complies with the law, they are violating the privacy of users in the US as well.
How is this any different than what Apple currently does when an iMessage user outside China messages someone inside China? My understanding is that it acts precisely as you describe, but I could be wrong. And likewise, from what I understand iMessage is likewise unpopular in China so cross-country communications would potentially be a major source of iMessage activity as well? ( I don't see any statistics on this)
The extent to which Chinese people oppose the government being able to read anyone's conversations is quite different vs. the UK. Unfortunately, it's not likely that this or the Chinese government's behaviour will change any time soon. But in the UK it is an active political question that is still undecided.
And as you said, the size of the market -> how much money they get probably has an influence on Apple's decision to operate in China, even with all the caveats. But it's also not the only factor. If it was, Apple wouldn't consider blocking iMessage/etc for UK customers.
nit: they arent. India is.
A massive company in a foreign country affecting the laws of your own is anti-democratic.
Democracy doesn't mean privacy.
Democracy is a bit more than just rule of the majority (or sub-majority due to the peculiarities of the UK voting system).
Why does Apple even care about how bad the government is? Either they care about user privacy over money, or they value money over privacy. It is fine if they value any of those as I frankly believe it's not Apple's job to moral police governments.
> If Apple complies with the law, they are violating the privacy of users in the US as well.
As is the case now with US-China communication?
Ecosystem features like those are huge contributors to platform retention. And if the cynic in you doesn't believe that, just ask yourself why they burn the money to keep staffing development and maintenance teams for iMessage and FaceTime - they aren't doing it out of kindness right?
In the UK, Facetime maybe. But iMessage isn't used to the level as it is in US. I can't imagine Apple's UK share would take a significant hit due to no iMessage when everyone already uses cross-platform Whatsapp.
The calculation is going to be different in each country, but there is no hypocrisy here.
The Chinese government messing with Chinese servers affect the Chinese market, which makes a lot of money so there is a strong incentive to remain in it. The UK backdooring FaceTime compromises it for the rest of the world and would actually put Apple in jeopardy in other jurisdictions with stronger privacy and data protection laws, for a comparatively minor market. It’d be more significant if the issue was with the EU or the US (both scenarios can realistically happen in the next few years, unfortunately). All they are saying is that they will comply if the regulations are put in place. Also, the British government is known for making noises along these lines before quietly dropping the whole project when it turns out that it’s actually not that simple. Different countries will lead to different risk assessments.
So yeah, there is no inconsistency, it’s just a matter of how you stay on the clear side of the law.
> It's easy to criticize a government when you know there will be no retaliation. To judge a company's true stance on such issues see how they behave when there's a prospect of real financial loss.
A company is not sentient, it does not have a stance. Its policies have no value except when they are decided and enforced by people. It’s dangerous to talk of corporations in terms of ideology, because these things can change and often cash trumps good intentions. In the end all that matters is how much the company and our interests align. The best way to have a company behave over the long term is if it makes sense for it to do so from a business point of view.
China: already a lost cause (before iPhones and messaging existed, in fact).
The UK: a leading western nation.
Let's try to have western countries not be like China? The UK could be a domino... if it falls the authoritarians in other western countries may be emboldened to follow.
It's sad that these politicians don't see the problem... Well either don't see or understand, or they full well understand and that's the point, they're just doing a poor job of explaining why.
In practice, I think we'll waver between losing control of the box and gaining it back, as it sinks in that, truly, no backdoor can be reserved for some and not for others. I think the only viable solution is to break the tube: make it illegal to send encrypted messages over the wire. Period. Then we could keep the box inviolable, opaque, and secure. But it can no longer communicate secretly to others. In practice this will mean more "sneaker net" movement of illicit and/or secret data, and probably leaps and bounds in steganography. It would also end the internet as we know it, especially any and all e-commerce. But hey, that's a small price to pay for eliminating CSAM, right?
Signal, Whatsapp, and iMessage threatening to leave the UK over this bill indicates to me that the bill is unreasonable. However, Meredith Whittaker did a very poor job of demonstrating that during this debate.
On top of all of that, who wants to defend child pornographers? I can see why a person wouldn't even try to engage in that back and forth. There's just no way you come out on top, because basically your side of the argument would have to come down to "Everyone has something to hide, and we should recognize and protect that." It just doesn't _sound_ good.
What is "child pornographer" btw? Is it the one who produces? Is it the one who distributes? Sharing CP != child abuse. Viewing CP != child abuse. Storing CP != child abuse. I want to defend CP viewers. Children can suffer during production (but not always: teenagers can film themselves, for example, i.e. make home videos just like adults). But no one suffers directly during the storage, viewing and distribution of files.
Kshama Sawant is a leftist. There are folks left of her.
If you don't see Biden as centrist or even center right, you have a narrow view of the spectrum.
Our major parties are now squashed into the spectrum between the mean US Democrat and the mean US Republican, it's quite depressing.
The UK courts are currently weak because the government threatens their independence. But the same thing is happening in other countries such as Israel, so it’s not something that a written constitution can prevent. Ultimately the only thing that can guarantee judicial independence is for people to believe in it, and for people to take to the streets. Most British people just don’t care, that is the problem.
The Supreme Court exists for this very purpose, although it is subject to Parliamentary Sovereignty[0].
> No "president" to "not sign it".
Bills do not become law until given Royal Assent by the King. The King may refuse to give Royal Assent to any bill, although this has not been done since 1708.[1]
[0] https://en.wikipedia.org/wiki/Supreme_Court_of_the_United_Ki...
[1] https://en.wikipedia.org/wiki/Royal_assent#United_Kingdom
The USA is in a position where it seems to be perpetually stuck in a 50/50 split of the elected government, so it's not possible for major constitutional reform to be passed by one party.
On the other hand, the current government in the UK has a majority of 80 MPs - if there was a written constitution, it's likely they could simply pass a law to re-write it.
Personally I quite like it. Evidence suggests there’s quite a lot of people trying to blow us up and stuff.
I don't think they like the ability of people to share unofficial information and organize themselves in huge numbers.[0]
People were sharing anti-propaganda propaganda stickers on telegram too.[1] (2:40 the bus is covered in them, also saw a vid where an entire police car was covered in them.)
Watch how quickly that turns the conversation around.
This argument lawmakers have here is entirely built upon the straw man. I understand the deep yearning to protect children but all this won't make the criminals stop using the tools that are currently legal. They will continue to use them. Making them "illegal" won't make them stop using them because they can still be acquired.
This is a meaningless threat.
But that's not especially relevant - people still mainly use WhatsApp for video calls despite the bad quality because everyone is already using WhatsApp.
Apple:
> "We have never heard of PRISM", "We do not provide any government agency with direct access to our servers"
https://web.archive.org/web/20130609061546/https://www.culto...
..some things are just not discussed on public forums.
For example, imagine a Login page that said, "Password incorrect," versus "User does not exist." If you have "User does not exist," you could use that to figure out whether a given email address has an account with a service. That could be useful information to PRISM when looking for a target to subpoena or monitor. (This is also why it's now best practice to just say "Login incorrect" or something vague that doesn't say whether the username, or the password, was wrong.)
Though, I could be wrong, I'd love more info.
Direct access to the data was mentioned in the Guardian and other newspapers
It goes further than just the error message. I think the original exploit was based on how quickly Unix would fail to login. (Bad user failed faster than bad password) and that allowed you to enumerate the user names.
They can essentially conscript anybody in the company to work as a spy using (probably bullshit but still intimidating) legal threats to keep them quiet.
Yes, "evidence for a secret program" is a bit tricky to produce, but the one I know of - Doe v. Ashcroft - the president of the company was compelled to produce data. I'd be very surprised if this wasn't the universal approach.
My immediate reaction to such a letter would be to contact the company legal department regardless of whether the letter said not to, simply because I'd assume unless given very good evidence (and originating from a .gov domain isn't good enough) that it was a scam.
Edit: According to the EFF you can talk to an attorney about an NSL.
An email/phone call to a legal department is much less work and provides all the same protections.
So actually Apple was being honest. They had not heard of PRISM, because that term was only used inside the NSA. And they were not allowing direct government access to their servers, they were responding to FISA warrants.
If we are being pedantic, one can claim that all data, can be very well anything because there is always a "one-time pad" transforming all communication into something malicious.
If the law is not precise, then it is on the government to improve it.
I don't really mind it either anymore, a lot of people have this hero worship fetish and they can't help painting everything in black and white, even though they're all just different shades of gray.
Apple is definitively brighter on that scale then Google or Meta, but they're all corrupt multinational corporations that will do everything they can get away with to increase their bottom line.
Or do you live and operate like RMS?
I have always associated that period with the discovery of Prism. I would love to hear if anybody knows what I'm talking about.
In China they are running their own infrastructure on servers owned by party-affiliated businesses. I wonder how strong their encryption is over there?
China blocks many services with strong encryption but it doesn’t block iMessage.
I mean, I hope so. Im not convinced though.
So it is a good question why CCP didn't block iMessage, despite we know that SMS is heavily censored and monitored (see 金盾工程).
iMessage worked, last I went there.
IIRC it's something to do with needing a license for audio-only telecommunications services. But I also might be entirely wrong about that.
As to why the public themselves go for it, the media landscape in the UK is in a pretty bad way at the moment. An enormous amount of power is still wielded by the traditional press - specifically the power to set the national conversation.
It's also anglophone, which to anglophone companies (Apple still is, to a significant degree), means that its 70M are worth a bit more than the absolute number suggests.
The only reason Apple are saying this is because it's good PR and nobody in the UK uses iMessage anyway, so they won't lose any money.
Wake me up when WhatsApp say the same...
https://www.theguardian.com/technology/2023/mar/09/whatsapp-...
PRISM in the US is proof they don't really care. China and Russia also have data collection on iphones.
I read today that the younger generation grew up with and is so used to surveillance they don't care. It's just a thing. But old codgers like me most definitely care.
Though it hardly matters when ~90% of iPhone users likely have iCloud Backup on. In which case their messages will be backed up to the cloud to where the government could get keys.
If you don’t know apple turned over private text messages of congressional officials and NYTimes reporters WITHOUT protest or question to the Trump Administration. And before you say otherwise Google and Microsoft both did not.
They do not care about privacy, it’s all marketing.
EDIT: Also, ~80%-90% of iPhone users in the country likely have iCloud Backup on. iCloud Backup is not E2E-encrypted in China, and is hosted by a Chinese company instead of Apple. If you want full E2E, you need to use iMessage and hope everyone in the party doesn't have iCloud Backup on... and that's a pretty niche threat now.
I could be wrong about the current state, but I need to see evidence first.
That's how my phone should feel.
What if, you know, you're not planning a murder/bombing/atrocity/etc., like, erm, you know, normal people.
I get it ... nothing to hide, nothing to worry about, right?
China is tricky and I'm sure after Hong Kong Apple changed their calculus.
- if there is success in the UK, relevant persons at Apple can make a more compelling argument to push back on China and other governments a lot more
- perhaps apple is still pushing hard on china and using the UK as an example that they're willing to drop a long time strong market over the anti-encryption legislation
I'm not saying either is the case, but there are benign or even positive reads on why apple is more aggressive with the UK
"At least" companies can put up a fight in the UK (or US, see Apple in the San Bernardino case) and they have a reasonable chance they can lobby to block the efforts.
However there is a great chance that if they threaten to pull out of the UK that the law won't pass. Even if it does it is good marketing. Who knows what will actually happen if the law comes into effect. The UK market definitely isn't small, for all we know they may back down. Or maybe their reputation is more valuable.
But... Everyone in China has their iCloud backups stored in China and Apple holds the keys to these backups. While Apple cannot read E2E encrypted Messages content, they do upload an unencrypted (but encrypted with keys they control) backup of all of the phones Messages data.
It seems likely China can ask Apple for a backup of a citizen's phone and Apple will comply with that request. Or they have access to these data centers.
https://techcrunch.com/2018/02/25/apple-moves-icloud-encrypt...
Maybe the difference is that Apple feels they may be able to talk the UK out of this idea.
All reports of this seem to refer back to the same BBC article, which purports to quote from Apple’s submission, but doesn’t link to it.
wew, its just one big firework waiting to blow. glad i've got the spectator seats
If Siri ever improves too significantly I’ll get nervous.
"In 2021, Apple generated 3.7 billion U.S. dollars with its global advertising business." [1]
"Apple’s services business, which includes advertising and subscription revenues, grew 24% year over year last quarter to a record $19.5 billion" "It’s likely that a large share of this category’s growth comes from advertising" [2]
"Apple ad business could reach $6B by 2025, with $4.1B from Search Ads" [3]
For reference, 2023 Q2 revenue from "services" amounted to 20.9B USD, while hardware product sales amounted to 73.9B USD. [4]
We're thus talking about ~4%, not exactly a rounding error.
[1] https://www.statista.com/statistics/1330127/apple-ad-revenue...
[2] https://www.insiderintelligence.com/content/apple-ad-revenue...
[3] https://appleinsider.com/articles/22/06/15/apple-ad-business...
[4] https://www.apple.com/newsroom/pdfs/FY23_Q2_Consolidated_Fin...
I think Apple managed to understand and attract those types of customers. I find a generational disconnect between the 70's computer users and the user in the 00's.
Untainted (without ML-generated content) human communication is becoming more and more scarce. It’s only a matter of time before they take advantage of that.
They'll forbid any app using ML generated content from providing iMessage extensions, or possibly it’ll receive a warning mark in iMessage when sent. Could also work with content pasted from those apps. Some sort of “provenance check”. They’ll pitch it as a consumer privacy thing, I promise.
That’ll also be the same update where E2E encryption falls off the the marketing.
There is very much a motivation to access massive amounts of user data, especially when you control the OS that would be the gate keeper to that data, as well as how the “choice” is presented to the end user.
I agree but think that Apple is the exception that proves the rule. Its origin story is as good as any Shakespeare.
The second act of Apple started small and focused and re-built itself while keeping the Wall Street mind set at a distance. I think your sentiment misses the fact that Apple doesn't really need Wall Street. Their stock can do whatever it wants the lower it goes the more they can buy. Why would Apple lower their standards?
On their conference calls they always talk about reaching cash neutrality as their goal. I never really understand what that looks like
Untainted (without ML-generated content) human communication is becoming more and more scarce. It’s only a matter of time before they take advantage of that.
I'm not sure if I understand this comment. Apple's size relative to other nation's GDP enables them to hire real humans at an amazing scale. This different than a company that doesn't have a culture of support built-in already. They also have the advantage that many countries would partner with them to raise their own GDP.
I think their approach is to grow the AI to help the existing workforce scale. Get more work done using fewer live bodies.
They'll forbid any app using ML generated content from providing iMessage extensions, or possibly it’ll receive a warning mark in iMessage when sent. Could also work with content pasted from those apps. Some sort of “provenance check”. They’ll pitch it as a consumer privacy thing, I promise.
I hope so that is why I'm Apple customer. I also think you are misreading the times. Apple is about to hand over a lot of authority to the customers.
There is very much a motivation to access massive amounts of user data, especially when you control the OS that would be the gate keeper to that data, as well as how the “choice” is presented to the end user.
Don't project your ambitions on others.
I do believe that Apple's ability to maintain their performance is mystifying and wonder how long it will last.
Facebook uses user data to target ads. Apple doesn’t do this, so they don’t need the data.
If Siri gets better, it’s because Apple have switched it to a better LLM, not because Apple started sucking up magic data dust.
I’m pretty sure that Siri can already read your messages, that’s the point, it’s a speech interface that runs in your phone.
The magic data dust is only useful if they can use all of it though. I just see some incentive there that I can’t imagine them ignoring in a couple years.
Preface: I don't have an opinion on one side or the other.
Question: what were the arguments lobbied against apple that caused them to withdraw? Also, is CSAM the motivating factor for UK or do they want backdoor for more general national security surveillance (or whatever you want to call it)?
Baroness Beeban Kidron has been lobbying for stringent anti-CSAM measures in tech for years [0]. She's lead a major pressure campaign in the US, Canada, and the UK for years [1]. Her charity 5Rights and WeProtect both have been able to back Labour and the Tories so she's able to lobby across the aisles.
It doesn't hurt that the publishing company her parents founded (Pluto Press) has a strong niche in the political space.
The Molly Russell suicide also played a role [2], which she leveraged to highlight the need for restrictive anti-CSAM measures, especially as it became a top tabloid story in the UK.
[0] - https://en.m.wikipedia.org/wiki/Beeban_Kidron
[1] - https://www.politico.com/news/2023/06/14/british-baroness-on...
[2] - https://www.nytimes.com/2022/10/01/business/instagram-suicid...
It just doesn’t seem aligned with the principles of a republic or democracy to have unelected lifetime members who are able to draft legislation.
FYI, the House of Lords can't reject the same bill more than three times, and can't reject a bill that calls an election, so its undemocraticness isn't as bad as you might assume.
There are many issues with it but I don't think many of them are much worse than those that already exist with the House of Commons. (Lobbying: exists in both. Unelectedness: the first past the post system is pretty bad here too. Ability of unelected people to introduce bills: private members' bills exist too).
All of these are problems I'd like solved but I wouldn't support removing the House of Lords.
it acts as a brake for controversial legislation, which is generally a good thing
They would rather have maintained the status quo but thought they had hit on something that would work. Since they didn't need to do anything pulling the software was an easy fix to the controversy. The governments are the ones that are pushing this so let them take the heat.
Apple has a working solution and they can just wait and see what happens and react accordingly.
(Personally, I think this was an overblown risk, since the plan was for the images to first be reviewed by Apple before being sent to the authorities. Presumably if an Apple employee/contractor saw a photo of, say, Tank Man, they wouldn't pass it on. But it's reasonable to be concerned.)
I have come to the conclusion that part of corporate combat involves apparent grassroots outrage.
If a system without a wide open backdoor is proven effective it becomes more difficult to argue for a bigger backdoor.
Thus any undesirable material - a campaign poster, a meme, a video leak of classified info - would be yanked from customer devices and trigger this automated reporting flow.
Apple already gives the Chinese government access to iCloud data for Chinese citizens. Being bullied into searching for eg anti-Xi material is a small jump.
The other concern is that the hashes themselves are prone to false positives. This is true of the source hashes and concerns in the algorithm. The National Center for Missing & Exploited Children data has been known to match on pictures of tricycles and monkeys (clearly not CSAM). Do now we are in a world of pushing automated child abuse charges against people because a faulty algorithm.
The whole thing is just prone to abuse.
- Images could be scanned only after a threshold number of illegal images had been flagged
- Law enforcement agencies could not use the system to flag non-CSAM images
Part of the way they achieve the former - and what makes the system unworkable - is that it's client-sided.
To be clear, every service already scans for CSAM. But the naive way of doing this - comparing SHA-2 message digests - can be trivially manipulated into producing false negatives. Just flip a bit in the image and it becomes a new image. Perceptual hash algorithms instead use notions of image similarity to protect against this, but it also introduces the possibility of false positives - i.e. images that look innocuous but match against CSAM and get you flagged. This is not merely a problem to be solved, but a consequence of such systems being differentiable, which is necessary for them to actually work.
For remote scans, you can at least keep the perceptual hash algorithm secret and avoid leaking information about what images do and don't get flagged. This will frustrate attempts at adversarial training. However, when you put the perceptual hash on everyone's phone, it can be extracted, and people who don't like the idea of running a spying dragnet will deliberately break the hash just to tell you to fuck off. So people were making tools that would modify one image to look like another, which could be used to either hide CSAM or, worse, making cat pictures that get your iCloud flagged.
There's also a bit of moral insult involved with having your phone do things that aren't in your benefit, even if this ostensibly were to keep the feds from demanding explicit backdoors[0]. This system is laughably easy to defeat if you're jailbroken - just turn the daemon off. Hence why Apple made no attempt to integrate it into macOS where users have root access[1].
Law enforcement would never firewall their capabilities to "just CSAM." That's not how the law works. You can't sue your drug dealer for not giving you the weed you paid for, and for similar reasons, law enforcement is never going to only wiretap pedophiles and not drug dealers. There's a few exceptions to this[2], but generally, you should assume that if you're about to give the feds the legal capability to spy, it will be used for every crime down to and potentially including routine traffic stops.
Apple's bulwark against that was to have the system only scan for images that were flagged by multiple independent child protection agencies. However, this isn't a guarantee; the western world routinely collaborates in very not independent ways. There's no guarantee that, say, Europe's pedo-fighters wouldn't have had their arms twisted by their countries' intelligence apparatus, operating in concert with the American CIA who was arm-twisting NCMEC. Apple promised they'd be reviewing all reports before forwarding them to law enforcement, but in this situation there's nothing preventing them from having their arms twisted here, too[3].
[0] For the record, there was no evidence that Apple was using this system to enable iCloud end-to-end encryption. They'd already turned that off because of a UX problem: too many people were permanently locking themselves out of their own data and Apple couldn't break into it for them.
[1] Root access on macOS is complicated by the fact that SIP and boot security exists. They could at least theoretically have made the kernel refuse to terminate the CSAM scanner process at all, but that would be a speed bump at best. Users absolutely can turn off SIP or boot modified kernels on Macs that would remove whatever protection Apple added to the CSAM scanner. And Apple currently has no interest in locking owners out of macOS like they did with iOS.
[2] The NSA actually does try to keep their spying tools to themselves, because they have to fight nation-states, not criminals. Even then, they'll still slip hints under the door and tell the FBI they can only use them if they can make up a story that doesn't expose how the NSA's spying apparatus works.
[3] National Security Letters are one hell of a drug.
Apple could also have their arm twisted to add backdoors, but they've already shown that they'll yell loudly if that happens. Furthermore, the existence of software signatures means that such a backdoor would generate irrefutable paper trails, which is the sort of thing that intelligence agencies hate. It's much easier for them to just quietly extend an existing quasi-backdoor than to create an explicit one that loudly screams "DO NOT USE YOUR PHONE TO DO CRIMES"
Their initial plan was to only compare against the database when you upload to iCloud (in the comparison, OneDrive) and notify the authorities, but of course once the infrastructure for local scanning was in place, extending it to other "scenarios" was just a small update away (I'm sure RIAA/MPAA would love to hear about your old mp3 folder you kept moving over from pc to pc over the years).
It often feels like these public back-and-forths could be theatrical performances, designed to shape public perception more than anything else. State-level actors generally operate with a much wider set of tools and resources at their disposal than what is commonly understood. The fact that the UK is a member of the Five Eyes intelligence alliance is also noteworthy here. This alliance allows for expansive information and resource sharing. The reach and depth of these resources can often surpass the need for individual corporate cooperation.
It's essential to look beyond surface narratives and remember the complexity of global surveillance practices and cyber strategies. Yes, a company's commitment to privacy is admirable and crucial, but it's equally important to stay aware of the many other methods that state actors have at their disposal for obtaining information.
Edit: Fixed typo
The tools you mention still generally require either physical access to the device, or are in some way targeted. You’ll likely never be able to stop these, but a blanket communication encryption ban both serves an entirely different purpose and can much more easily be stopped.
The UK government can stick their agenda right up their big fat, corrupt, dystopian ...
It strikes me as odd that people are now suddenly condemning the UK gov for trying to maintain its ability to keep its people safe, particularly when spying is not an unusual or a new power per se.
The UK government has had the means and the right to spy on its citizens for hundreds of years, via phone taps, espionage, bugs, steaming open letters and all sorts.
It’s served us very well as a country and has also saved many lives - just look at the stats on thwarted terror offences using intercepts as evidence. We are a democracy and if enough people didn’t want the government to hold these powers there exists the means to achieve that via electing a new government.
An American company is now threatening to stop selling some of its products in the UK if the government refuses to let it sell products that weaken their ability to police the nation.
In the context of what’s important to the country perhaps we should choose security over the profits of Apple’s shareholders.
Breaking encryption via backdoors is like a gift to organized crime.
Privacy is also crucially important if you want to maintain free societies long term. Same comment for free speech for public discourse.
I wonder what happens when all the Conservative Party MPs discover that this sort of legislation means even more of their internal party conversations — currently on WhatsApp but who knows what they'll use next — get leaked?
The Conservative party is in a nose-dive which will continue to be until the next couple of generations kick the bucket.
Those who are in the their 60's want the UK to be just like it was before EU.
Those who are in their 40's, 50's accept that brexit was a eff'up, many are in denial that it was a bad decision.
The motto is now "we must just get on with it" which is accepted upon them. They have the lifestyle, let the younger suffer.
I'm 34.. no idea what am I suppose to do.
It's not been easy, but it has been worth it.
They still operate in aus. Therefore they can legally be backdoor'ed, and almost certainly have been but are legally required to not notify their users or make note of it internally. Couple with some 5 eyes legislation and you got cross borders no warrant monitoring.
This grandstanding by Apple is nothing more than propaganda for the plebs. Go read country laws. Apple toes the line like everyone else. Your a suckered if you think otherwise.
Take this PC, a fairly new dell, all patched with the bios et al, and certain websites (dailymail, youtube and reddit) with adverts deliver something that disables the dell mouse.
Only option is to reboot the pc but I have to take the mouse out of the usb and plug it back otherwise the dell usb mouse still wont work after a reboot.
So I love their hubris, but I dont think they see some of the hacking that goes on because its at the hw level.
Only phones activated in the UK or with UK set as the activating country have to follow the rule? Only if there's a SIM card? What about iPods or MacBooks? What if you bring a US phone to the UK, does it have to magically detect and suddenly allow backdoors?
If you leave the UK with your UK phone, is it allowed to be encrypted then, or the UK wants the ability no matter where you go?
I suspect the scanning of this content will be handled solely by accredited services, these likely will have close communication with one or more government entities who supply information on what content is or is not illegal. At this point there isn't really end-to-end encryption anymore: every message will be submitted to one (or more) accredited services. Even if it's encrypted, each message now has the government's blessed service as a recipient.
It's important to remember that we're talking about text messages as well as images, a system that compares only hashes will not be sufficient. The bit about terrorism related information is also worrisome as we know the list of what is and isn't terrorism related is a very political debate.
What matters is the outcome, and indeed mass surveillance will lead to the dossier on everyone outcome, whether that was intended or not.
The damage done by apple with their previous plans for CSAM scanning is huge, and apple will be partially responsible for all the upcoming anti privacy / encryption laws.
Whatever services MS want from Activision they can purchase on an ongoing basis without blocking others like Sony just to block the competition.
Who wants Call of Duty to go xbox only like Halo?
Microsoft is a platform provider, the content creators that use their platform should be free to publish to any platform. Otherwise Microsoft bump the prices and say take it or leave it but you can't get it anywhere else.
If they want to see our messages we should be able to see theirs, fair is fair.
Look at the top comment and see how illogical it is:
> I'm happy to pay a premium and be locked into their walled garden for some things if it means supporting a company that has the power to shift policy in favor of human rights (privacy in this case).
Morons like this actually believe taking away human rights and privacy will make them safer. News flash, the danger are people in power that can't be held accountable. Lastly, be skeptical of anything Apple says as they work together with governments to take away your privacy. Psychopaths will say anything to get you to trust them.
https://www.statista.com/forecasts/997945/most-used-messenge... (non-free link)
I prefer iMessage over the other messengers, but I still haven’t met anyone who cares. A lot of people don’t even know why the bubbles are sometimes green.
This is not a thing outside the United States, and I doubt that most British politicians are even aware of 'blue bubbles'.
For example, the recent controversy regarding the release of Covid-related government communications was centred on WhatsApp, with no reference to other platforms like iMessage.
https://news.sky.com/story/politicians-are-drawn-to-whatsapp...
Nowadays it's mostly about convenience and features compared to SMS, and iPhone has a much smaller marker share in Europe so iMessage isn't a thing.
In contrast, in many European countries Whatsapp has 90%+ penetration [1]. Even where it's relatively unused it's more common than iMessage.
[1] https://www.statista.com/statistics/1311229/whatsapp-usage-m...
Not to mention MMS is vastly inferior to WhatsApp and iMessage for sharing media and other information.
Non Apple work machine?
Also outside of programmers, IT, and designers, you rarely get a choice in the company issued laptop. It never makes sense for a company to issue more expensive Apple computers instead of ThinkPads or Dell computers.
The machine is mine and I do work on it. Thanks for the concern but I’m not worried about getting sued. I’m sure it’s happened here previously, but it’s not like the US.
> Also outside of programmers, IT, and designers, you rarely get a choice in the company issued laptop. It never makes sense for a company to issue more expensive Apple computers instead of ThinkPads or Dell computers.
I’m not one of those professionals and I can get my job done quicker on a Mac. My employer doesn’t dictate how I get things done and paid for the machine I want. I think this is a good thing.
Any job that requires a crappy trackpad isn't a job worth having.
Just seeing those laptops is frustrating. What is the point of the trackpad if you have to use a mouse?
> My employer doesn’t dictate how I get things done and paid for the machine I want.
That is very much not your machine. If your employer ever gets sued, or runs into some investigation, or some internal dispute escalates enough, all the data on it is now likely available for them for review.
Given large enough company and enough people, you'll get that "preserve documents for discovery" email one day. It happens outside of the US too.
And then of course the vastly higher fidelity of pictures and video sent via iMessage.
If I send an SMS message to a group of people, they all see a message from me. They don't know who else got it. And if they reply, they reply only to me. Is your experience different?
WhatsApp (and I think iMessage) allow me to create a group with a name/purpose and send messages to the group and receive replies to the whole group.
(P.S. I went from dumb-phones to Android and have limited exposure to iMessage's feature-set).
Does MMS not exist in your country?
That kind of pricing made WhatsApp an infinitely preferable alternative.
Phones automatically switching to MMS would be catastrophic.
Data (WhatsApp) is essentially free in comparison. £10 (13 USD) per month gets you 20GB: which doesn't care how many messages/recipients/photos you send.
Here in the US its common to have at least 1MB MMS max size. Back in the day 300-600KB was often the max size, but that's definitely changed over the years. Maybe its just splitting it up and re-assembling it behind the scenes, I'm not sure.
I can't speak for all history, but from about 2004 or so in the US MMS and SMS were often bundled and billed the same, especially for networks which had rolled out 3G/EV-DO. Having a plan with 500 messages usually meant 500 combined SMS and MMS message.
The other major feature I see for other messengers over SMS/MMS is much larger attachment sizes. It can be challenging sending an MMS with attachments >1MB. Meanwhile, I can send a 100MB file/video or an 8MB photo over Signal. WhatsApp allows for 16MB attachments. Sending a quick video in-line with the chat thread in MMS is miserable and gives an incredibly trash quality video while most other chat apps you can stick a decent quality 30 seconds or so video without any issue. Photos sent over MMS are usually junk while one could get a decent 4x6+ print off an 8MB photo.
Whatsapp works on PC, Mac, Android and iOS
iMessage only works on Apple devices.
So I use 2 or 3 other apps for mostly a few international people I know but basically everyone I know just defaults to SMS/iMessage.
Automative manufactures didn't give a rats ass about fuel economy until customers wanted it.
That’s not true. Apple was position itself as being better at security than Microsoft long before Google was selling devices to people.
For example:
It's debatable whether or not that was true, and even if you believed it it was up for another debate whether that security was by design or because Apple's vanishingly small share of the PC market made it uneconomical to write malware targeting OSX.
This isn't to say that Microsoft was doing security properly back then either, they weren't.
Google is generally excellent at security, but that doesn't change the fact that they're a nightmare for privacy.
[1]https://www.theregister.com/2017/11/28/root_access_bypass_ma....
I don't much care. Companies don't have ethics, they have fiscal goals. If Apples fiscal goals happen to line up with my own goals, so much the better.
I would tend to trust a company who is doing something to selfishly support the bottom line way easier than I would trust a company who claims to be doing it for the common good of all humanity.
Google famously started off trying to not be evil and also be a profitable company simultaneously. It didn't work out great in that one of those goals became slightly more important than the other.
I remember some talk about those getting encrypted, don't k ow if that has happened yet.
That said, I’d be very happy to see that they did threaten a boycott as well.
Meta:
> Some countries have chosen to block it [WhatsApp]: that’s the reality of shipping a secure product. We’ve recently been blocked in Iran, for example. But we’ve never seen a liberal democracy do that.
They said they won't comply. UK would have to simply block WhatsApp.
It’s by far the largest messaging service that is e2e encrypted by default. I think it’s more than fair to call it ahead of the curve for a service of its size.
https://www.wired.com/2014/11/whatsapp-encrypted-messaging/ https://blog.whatsapp.com/end-to-end-encryption
As recent as 2021, there's been questions: https://arstechnica.com/gadgets/2021/09/whatsapp-end-to-end-...
But, let's go to the start - WhatsApp started in 2011.
Encryption arrived in varying degrees until there was some pressures to change the amount of privacy messages had for advertising purposes.
Lots in the news at the time.
2018 "Another point of disagreement was over WhatsApp’s encryption. In 2016, WhatsApp added end-to-end encryption, a security feature that scrambles people’s messages so that outsiders, including WhatsApp’s owners, can’t read them. Facebook executives wanted to make it easier for businesses to use its tools, and WhatsApp executives believed that doing so would require some weakening of its encryption."
https://www.washingtonpost.com/business/economy/whatsapp-fou...
2018 "Acton said he tried to push Facebook towards an alternative, less privacy hostile business model for WhatsApp — suggesting a metered-user model such as by charging a tenth of a penny after a certain large number of free messages were used up." https://techcrunch.com/2018/09/26/whatsapp-founder-brian-act...
2018 "WhatsApp CEO Jan Koum quits over privacy disagreements with Facebook" https://www.theguardian.com/technology/2018/apr/30/jan-koum-...
2018 WhatsApp co-founder: "I sold my users' privacy" to Facebook "https://www.cbsnews.com/news/brian-acton-whatsapp-on-faceboo...
Encrypted in transit is not at rest, let alone the backups of messages on Google Drive / iCloud.
Check Article 12:
https://www.un.org/en/about-us/universal-declaration-of-huma...
> No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.
I'm no fan of Meta or their privacy violations, but saying that voluntarily downloading an app (which by the way does clearly outline their privacy practices) is equivalent to having my humans rights violated just really waters down what "human rights" should mean.
that's all true until an app becomes the only way to interact with certain groups of people. i certainly wouldn't call my usage of Discord voluntary. it doesn't actually matter how often i read their privacy policy and shake my head. either I break off contact with a large part of the internet that's important to me or I begrudgingly agree "voluntarily" to their terms and conditions.
And aside from that, a lot of software communities are on Discord now. People are gating download links behind it, use their threading feature for support and put their knowledge base in channels. And not just small communities and developers. ASUS has made their main communication channel Discord too.
I agree it's difficult. I've had success showing keybase to people because of how barebones simple it is - but it's not a solution for everything of course.
How many non technical people have heard of Discord?
If the number in your name is your birth year I'm not too surprised, but don't assume you can project from your own experience onto others 1:1.
I can't even get my wife to install Element - and she works in tech as a senior python / automation engineer. People want neatness on their phone and low total complexity, and installing a messenger for a single person is over the line for most.
> You are a very ignorant if you think there is no barrier to getting someone to try an app with a substantially less good UX than what someone's currently using, and that that barrier doesn't border impossible in a group of 10.
Yet many people do have multiple messaging apps.
And Discord the one you think is so popular is not even in the top 10…
https://www.statista.com/statistics/258749/most-popular-glob...
They aren’t counting iMessage as a separate app. But do you really think it wouldn’t rank above Discord?
> I can't even get my wife to install Element - and she works in tech as a senior python / automation engineer.
Maybe your enlightened millennial friends and family aren’t as willing to change as you think they are?
> People want neatness on their phone and low total complexity,
Yet the average person has 35 apps on their phone
https://www.thinkwithgoogle.com/marketing-strategies/app-and...
https://www.wired.com/story/facebook-data-leak-contact-impor...
In modern life, people don't discuss politics in townhalls, pubs, or whatever anymore. Online communication is by now far too siloed and supervised to the point of being unusable. Media are one-way streets, pushing the agenda of billionaires.
But you need to be able to have controversial discussions about "heavy" topics without fear of being ostracised. You need to have a back-channel to give feedback to "higher ups". Etc.pp.
A society where the individual is degraded to a mere drone (even if only loosely via framing) controlled by the "hive mind", without any recourse to voice constructive criticism is a lot of things, but certainly no democracy. There looms a dystopia on our doorstep.
> But you need to be able to have controversial discussions about "heavy" topics without fear of being ostracised.
Uh, why? People should have freedom of speech, but it feels like a lot of people want freedom from the consequences of the their speech. If anything, I think a lot of our current social disharmony is a direct result of the extremely recent development of people being able to mouth offline with very little social constraints.
Mike Tyson probably said it best: "Social media made y'all way too comfortable with disrespecting people and not getting punched in the face for it."
It's like exploited workers and people living in quasi-slavery, many of them don't understand their rights and "voluntarily" waive them. My parents didn't really understand the implications of "voluntarily" accepting Meta's privacy statement - once I explained it to them, they were in complete horror.
Yikes, seems like this is built to keep people from saying things about powerful people that they don't like.
If I cannot attack the honor and reputation of a person, and by extension, artificial person like a corporation, what good is freedom of speech? How can I call someone out for being a scammer, or for doing horrible things? How does one seek public redress of a grievance against a company, or an agent of the government? Does arbitrary apply to timing, or the circumstance? Who is the arbiter of arbitrary? This is not a human right. It is a nice tool for a tyrannical government to strip away rights from people. Oh, you've violated Mr. Arresting Officer by accusing him of falsely arresting you. Now you get to deal with the false arrest and a human rights crime. Likewise, Ms. Bought a Mansion with Public Money can no longer be accused because she has a human right to not have to trifle with public accountability.
Threads is not an attempt to push spyware on users, that would be incompliant in the EU. (And what is this spyware you believe is in Threads?) More likely they know exactly how much work it entails to be compliant and they decided to initially skip the EU market to speed up their launch.
The sad thing is that all their details and yours are already known to Meta.
The dozen of us who behave like you will keep trying though.
https://github.com/SubhamTyagi/openinwa (I recommend downloading from f-droid)
Good thing the EU just outlawed that model and forced everyone to support "third party app stores" that are thinly-veiled shells for Facebook/Google/etc to bypass that review process.
the "I wanna sideload" crowd are nothing more than allies of convenience for FB and others. Facebook was already experimenting with getting users to manually sideload the full-telemetry build and now they can just say "oops not supported on safari, install the native app".
https://arstechnica.com/gadgets/2019/01/facebook-and-google-...
I had to look it up.
Meta was also in the biggest mass surveillance & influence scandal of all times for a private not too long ago, please don't forget
If so I missed the memo (that isn't unlikely, I'm not saying you are wrong!). Any references/links for that? A quick search doesn't turn up much, but Google isn't what it used to be…
You cannot actually believe that meta gives a single solitary fuck about privacy?
I think the GP is likely aligned with you anyways.
Has Apple really removed iMessage and FaceTime anywere else ? Are these available with 100% full encryption in China ? If so then they are just blowing wind :(
Talk less, read more.
https://www.reddit.com/r/ios/comments/cskufy/imessage_encryp...
Then they should read the leaked government documents from around the world that contradict what Apple says themselves. Failing that, they should at least be able to read the actual code to corroborate its security, but that's not an option either.
On what specifically?
> they should at least be able to read the actual code to corroborate its security, but that's not an option either.
Why does that matter? You're already trusting Apple hardware. Public access to source code doesn't make security systems safer. I'm not sure what a journalist or even 99% of webshits on this forum would do with trying to audit crypto.
For starters, PRISM and XKeyscore. Both are damning indictments of the state of surveillance a decade ago, and are so damaging that pretty much every FAANG company denies knowledge of their existence. PRISM was about the outreach the US government has with domestic companies, and XKeyscore showed just how far those connections could be abused.
Simply the fact that these leaked documents exist and Apple denying them is a contradiction. Everything else is speculation, but my brain can imagine a lot happening over those past 9 years.
> Why does that matter?
Accountability purposes.
> You're already trusting Apple hardware.
Ideally I don't do that either. I'm not a fan of closed firmware interfaces and if possible, I'd like to audit the code for those as well.
> Public access to source code doesn't make security systems safer.
The majority of networked servers online today beg to differ. Over time the industry actually found that it's much safer to use an open and transparent OS than it is to trust a black-box with UB that may-or-may-not be fixed.
> I'm not sure what a journalist or even 99% of webshits on this forum would do with trying to audit crypto.
This speaks to a lack of either experience or imagination, I can't tell which.
Where's this denial by Apple? Or is your argument that because Apple doesn't admit colluding with the NSA they must be doing it. Well that is not falsifiable and what evidence are you speaking to of Apple specifically colluding with the NSA.
> I'd like to audit the code for those as well.
Firmware is not hardware. That would still not address the hardware issue.
> The majority of networked servers online today beg to differ. Over time the industry actually found that it's much safer to use an open and transparent OS than it is to trust a black-box with UB that may-or-may-not be fixed.
Yes, the neckbeards chant since CatB. There are extremely few people not putting their trust in blackboxes. Slapping linux on a box doesn't magically make it transparent - nor does linux have a security record you want to brag about.
https://www.apple.com/apples-commitment-to-customer-privacy/
> Well that is not falsifiable and what evidence are you speaking to of Apple specifically colluding with the NSA.
Wow. What a conspicuous coincidence that all of the exonerating evidence is behind closed-doors and marked "trust us"!
> That would still not address the hardware issue.
Is there a hardware issue?
> What a conspicuous coincidence that all of the exonerating evidence.
What exonerating evidence? How does one generally exonerate themselves that they don't know something or were never privy to it.
And I'm no fan of Apple (I'm also not a fan of baseless conspiracy theories), and the flip side of this is what benefit would it be to the NSA to disclose a program to a multinational company of >100k employees if they didn't have to.
You're trying to make it sound like there is a smoking gun that Apple has been lying about their NSA involvement, moreover insinuating in ways that don't seem to serve the best interests of the NSA - and I might even believe you - but so far you have put up nothing but innuendo.
> Is there a hardware issue?
Ok, so you audit your firmware. Why do you trust the hardware you're going to run this audited firmware on? You have thus far proven my point about general public access to source code.
The bottom line is that for the threat model faced by most developed nation citizens, Apple's privacy value proposition is pretty good. If you're up against a large nation-state that is willing to spend some resources you're fucked - and auditing your firmware isn't going to change that.
The idiot pmendes is wrong (if he was correct then no one knowledgeable on the subject would classify that system as E2EE - something more to read about). The encryption keys are not managed in iCloud which you can read yourself:
https://support.apple.com/guide/security/how-imessage-sends-...
https://www.apple.com/legal/privacy/data/en/messages/#:~:tex....
iCloud backup is an opt in feature - you use it full well knowing it effectively damages the affordance of E2E regardless of locale if ADP is not available.
“Read more” did not mean social media.
What exactly is pmendes wrong about? Are you referring to this comment:
> In iMessage the message contents are in fact end to end encripted. Each device encripts the message using the recipient keys and then sends the message. The problem is that iCloud manages the keys by itself so you have no way of knowing who is the exact owner of the key. Addionaly, on group chats, they don't even need to be a man in the middle. They can just add their key to the list of encription keys for that chat, and receive a copy of each message.
What's wrong there, aside from spelling? The nit I would pick is that in "iCloud manages the keys", I would change "iCloud" to "Apple" or "Apple's IDS".
How, specifically, does iCloud backup damage the affordance of E2E? This doesn't make any sense.
If you have somebody's GPG public key, you can encrypt a file to that public key and then put up the encrypted file on a public FTP site [0], whence they can download and decrypt it. iMessage does nearly exactly that, except that 1) Apple's identity service effectively solved the key distribution problem, 2) the messages are, even though already encrypted, themselves also transmitted by encrypted channels to Apple's servers during transit.
[0] Well, I wouldn't do this if I were at all concerned about the contents because it doesn't allow for forward secrecy.
If you’re going to classify every critical fact as a “nit” then nothing is ever wrong.
IDS vs iCloud is far more than a nit. They’re completely different services. iCloud is run by a 3rd party in China, this is well publicized, whereas IDS is not. So that’s like not a minor detail.
iMessage does not depend on iCloud. You don't need an iCloud account. These are unrelated.
Contact key verification is a more recent addition, and again not dependent on iCloud.
> How, specifically, does iCloud backup damage the affordance of E2E?
Just saying, you can sync your data to whatever encrypted or unencrypted service you want if you choose to. This may diminish the value to the end user of E2EE but it is unrelated. I'm not the one that brought up iCloud first. Take that up with the original commenter.
[1] https://apnews.com/article/dubai-middle-east-united-arab-emi...
Such statements rarely end up ageing like wine in the long run. Why would you be so happy about being owned by some big corporation just because it's your favorite big corporation?
Self preservation has taught me not to trust any big corporation, regardless of how good their PR is.
So have 100 year old car companies, and I'm old enough to remember many people saying the same things about their favorite car brand in the past ("I'm only buying X brand because they make quality stuff and they never broke my trust") and I also know they changed their opinion recently after a couple of decades.
And changing car brands is way easier than changing smartphone ecosystems, should one of the two players decide to screw you.
My point is people should not be fanboys of any corporation. History has proven they can always turn against their customer, even if Apple so far hasn't done it, but there's time, company management and culture can, and will always change with time, and with constant shareholder pressure for infinite growth there's plenty of opportunities in the future for the tides to turn, mark my words.
In what world ?
I have switched from iOS to Android and vice versa multiple times while still driving the same car.
Did your app purchases form the Google Play Store automatically transfer to your Apple App store, and did your photos off your Google drive transfer to your iCloud, or vice-versa?
Read my comment again, I ware referring to the ecosystems not being interchangeable, not the phones themselves.
The incompatible ecosystems is the tie-in that keeps people tied to their respective walled gardens, not the physical HW phone brick itself which is interchangeable. Once people invested enough money in one ecosystem, they're less likely to switch to the competition as all their data and purchases are trapped.
Fanboys don't like you pointing out the hard to swallow truth pills. They expect comments to validate their lifestyle choice, not contradict them. Any contraction is a direct offense to them.
> I’m in the middle of switching from android to IOS
At least for you it's easy, because all google apps exist for iOS, but switching away from iOS is absolutely impossible as there is no iCloud or iMessage for Android, so all your data remains hostage with Apple if you try to move.
1. Download Google Drive for iOS
2. Go to the Files App
3. Select all in your iCloud Drive
4. Copy
5. Go to your Google Drive in the Files app
6. Paste
Just like you would copy files from one drive to another.
They are not "great" but they are more than enough to download a zip with all your files and all your photos. From there you go where you want.
And apps are available for iOS that let you access all of them. If you install Google Drive on the iPhone, your drive shows up along side iCloud in the Files app and open/save file dialoga
Do just the opposite of this
https://news.ycombinator.com/item?id=36803905
I’m sure there are ways to migrate your email. Thunderbird?
Which apps would those be that you have to buy on iOS and Android separately? Most non game apps are subscription based that work across platforms.
My photos are already sync to Google Photos on my iPhone and if I had an Android device, I would just download the Google Photos app.
Music bought on iTunes has been DRM free since 2008 and Apple Music is available on Android.
Apple, Google, Amazon and a few other platforms and most of the studios participate in MoviesAnywhere where you buy movies from one platform and it shows up as purchased on the other platforms
What data is “trapped”?
Since every app that I pay to use that has an Android version is subscription based, yes.
> and did your photos off your Google drive transfer to your iCloud, or vice-versa?
Since I can download the Google Drive app on my iPhone and it shows up right next to iCloud Drive on the Files app and in File dialogs. Yes.
As far as photos from iCloud to Google, just download Google Photos on your iPhone and sync your photos.
Anything else?
That's not a direct transfer, it's a workaround which requires you to have free storage on your phone greater than the amount of photos you have.
which is really a low bar.
They will probably comply with some backdoor in partnership with Five-Eyes NSA & GCHQ. This is just PR posturing to build consumer trust.
Same with their venture into CSAM in the west. China could ask Apple for the ML be applied to scan for political dissidents.
It's a slippery slope and the frog gets boiled every year.
Basically, it's as usual a financial calculation of what PR can brings vs what you can lose in the market.
And fanboys believe it's because they are the good guys.
It was about getting a slice of hugely lucrative pie of customer market.
Vaguely remember a charity used to have a thing where they'd auction off a dinner with Steve, then later Tim. Given time with a leader who has literally revolutionized supply chain in CN and a CEO who made Apple his own following the most notable CEO ever, going after various gotcha points would feel like a wasted opportunity. But think I'd have to ask why a company designed in California of the 1960s and 1970s doesn't have line in the sand policies when dealing with a genocidal government and perpetual backdoors in software and politics, but will take a move like this. Would hope for something more than a canned answer.
Except for right to repair...
And software freedom...
Plenty of animals use tools [1]. And this isn’t how we define human rights. Bipedalism is quintessentially human, that doesn’t make tunnels a crime against humanity.
To say that right to repair in specific isn't a human right because the actual human right is agency/ownership/modification/whatever, is a bit like saying that encryption isn't a human right because the actual right is privacy and encryption is just a way to maintain privacy.
The end result is still that people aren't able to exercise rights. I would argue very strongly that having a degree of autonomy over the devices/objects that you own is an intrinsic right.
And if you look back at the history of Open Source software, you'll find that conversations about Libre/Free software have been regularly grounded in discussions of human rights from the start; from rights to ownership, to modification, to communication.
Important? To be sure. Just not "rights".
I don't know, I don't want to argue too much, and I don't want to give you a pedantic reply when we seem to be in agreement that privacy, agency, repair are all important and whether you or I would stick them in a specific category probably doesn't change much about that or necessarily mean that we actually disagree on anything practical related to those concepts.
I think it's bad that Apple isn't willing to fight for right to repair or user agency, but it is good that Apple is willing to fight for privacy regardless of its motivations. I don't think Apple is a universal advocate for human rights and I don't like deifying the company and I don't think its positions on privacy excuse its positions on repair or agency. But it's pretty objectively good for Apple to make a statement that it will pull these products out of the UK rather than comply, and it would be silly for anyone to say that the statement is meaningless just because Apple has bad positions on other freedoms. Apple's positions on right to repair do not make it any less good for Apple to have issued that statement about encryption.
Make no mistake: if Apple needed to get someone killed, they would. They're not some miraculous pinnacles of good in a sea of evil. It's just that they merely need to flex the law at you to destroy your life forever. Apple is no different, they'll hire the Pinkertons and break your fingers should they find the need to. Carnegie Steel did it, Apple's not above it either.
Ok, I'll play along. Suppose Tim Cook wakes up tomorrow and decides for some reason he wants me dead. How exactly does he do it?
Sorry for the Zoolander reference. I couldn't help it
There are plenty of unhinged people in this world who do illegal shit for enough money. Do you think some Ex-Wagner mercenary would pass up that offer?
But all playfulness aside:
* Pay professional hitmen. * Pay a hobo enough to go beat you up in your home. * Pay enough people enough money to kill you pretty much anywhere.
What are they going to do, plead in front of a judge that sees 90% of his murder cases unsolved or solved through guilty pleas that Tim Cook gave them a wad of cash when all they saw was a subordinate of a subordinate of a subordinate ? There's nothing fancy about it. Especially with an economy that drives people to drastic measures: a huge wad of cash that you're guaranteed to keep is enough for most people.
You mean, pay an undercover cop who is advertising himself as a professional hitman?
> * Pay a hobo enough to go beat you up in your home.
He'll pay the hobo, and hobo will run off with the money
> all they saw was a subordinate of a subordinate of a subordinate
This is even more crazy than the earlier suggestions. You think there is going to be a chain of subordinates at apple who will all go along with a murder conspiracy? Try arranging a surprise party with five people, see how well people can keep a secret.
You're naïve. Less than 100 years ago the Pinkertons were still murdering workers and nothing happened to them.
Just imagine this: Tim Cook travel expenses amount to an half a million dollar per year.
travel expenses only.
A professional hit man costs between 1/100th and 1/33th of that.
Tim has to simply give up on a pair of new shoes that year.
On the other hand, we know that governments do this sort of thing all the time.
they simply have better tools than hitmen, but, for example
https://www.businessinsider.in/policy/news/former-ceo-of-ama...
https://www.seattletimes.com/seattle-news/clearly-lasik-co-f...
> we know that governments do this sort of thing all the time.
they also have better tools than hiring hitmen
contract killing is a fraction of all the homicides
OP asked how the multi billionaire CEO of a trillion dollars company could kill someone
He could simply hire an hitman, it would cost him peanuts
If the victim is also using one of the products the company makes, they would also be in possession of all the information an hitman would need to complete his task, no investigation would be necessary
Some of the highest-profile hits nowadays happen in Russia, where the rise of wild-west capitalism has led to a boom in contract killings, with victims including politicians, editors and journalists, businessmen, even poets.
How much do you think it would cost to hire a Russian blackop/elite troop fleeing from his country?
I also imagine the post-arrest interview of the $5000 hitman going like this:
"You're charged with Murder 1, which is a capital offense in this state. Are you ready to die for $5000?"
"Tim Cook made me do it."
In what wonder world are you living?
I am simply saying that a man with 2 billion dollars in his bank account can do whatever he wants.
It is also pretty naive to think that Tim Cook expenses can be questioned by an Apple anonymous accountant.
of course this is all hypothetical, men like Tim Cook would never hire an hitman paying cash personally face to face.
> "You're charged with Murder 1, which is a capital offense in this state. Are you ready to die for $5000?"
> "Tim Cook made me do it."
at best that could legally qualify as insanity
But even assuming it costed 200 thousand dollars, would not change that for a Tim Cook it's a day's pay
If you don't take his vacation offer, he will invite you to a party on his dime. If you don't attend, he will use your location data, make it seem like you were in the wrong place at the wrong time. And depending on the severity and nature of your crime, the outcome will be just low ball enough to make it seem like apple needs to do something bigger than focus on human rights, like making better devices for your security.
They are frequently subpoenaed for information, and turn over that data more often than not: https://www.apple.com/legal/transparency/us.html
Let's not pretend this is a privacy-motivated decision. Where Apple doesn't have negotiating power (eg. China) they have been forced to compromise user safety and privacy[0]. We live in a post XKeyscore world, pretending like this doesn't also happen in America or the UK is a bedtime story for helpless capitalists.
[0] https://support.apple.com/en-us/HT208351
edit: s/EU/UK
(Edit: for my next trick, I will read the post more carefully before replying)
Another good example is the Dutch housing all the data in an building that was used to track down and kill the right people.
The data existing is the problem. The ideal situation is that there is no data.
ask Foxconn employees if that's true or not.
Blood for Bananas: United Fruit's Central American Empire [0] The lawyer who took on Chevron – and now marks his 600th day under house arrest [1] (Debatable) Business Plot, aka Wall St Putsch [2]
[0] https://history.wsu.edu/rci/sample-research-project/ [1] https://www.theguardian.com/us-news/2021/mar/28/chevron-lawy... [2] https://en.wikipedia.org/wiki/Business_Plot
The power a government has over you is likely also potentially the same as a company?
And lastly it is wrong, if the apps do E2E right (but I have no clue about that) you don't give them a secret at all?
You also cannot change one company, but you can change companies usually better than governments ;)
And besides, private corporations don’t have a “monopoly on violence”, the government does
Nobody worries about the government giving customer data to Apple, do they? Why do you suppose that might be?
@dang Is there any way I can counter-argument this statement without it getting flagged? If so, please let me know how.
Because so far I have failed and I don't know what rule I broke by countering this statement.
If you have a link to the flagged comment, I can probably help you understand why HN users would have flagged it. This comment is getting downvotes because complaining about downvotes and flags always does.
IMHO people should be allowed to complain otherwise how can we spot deficiencies and injustices and improve?
Which is all well a good for now, but profit directions can change, and i suspect it's easier to change a direction guided by profit than a direction guided by morals. Ie i suspect their current "good direction" is less stable than some would suggest.
It takes a lot of unearned trust to to assume that there isn't classified surveillance occurring.
If it is, public virtue signalling about not breaking encryption is theater. As the surveillance occurs prior to encryption.
Which client side scanning would that be?
I would hope that the grandparent was not referring to this thing that never existed as "the client side scanning ability that is built into the OS."
https://en.wikipedia.org/wiki/Choice-supportive_bias
the tendency to retroactively ascribe positive attributes to an option one has selected and/or to demote the forgone options. It is part of cognitive science, and is a distinct cognitive bias that occurs once a decision is made. For example, if a person chooses option A instead of option B, they are likely to ignore or downplay the faults of option A while amplifying or ascribing new negative faults to option B. Conversely, they are also likely to notice and amplify the advantages of option A and not notice or de-emphasize those of option B
But it seems Google was more political in its relationships than idealistic. And now the entire sector is compromised.
Apple will be one day compromised too. In some crevice of some unknown government office is a person working on a ten-year initiative to get access to inaccessible information in the tech sector. AT&T was compromised this way. Microsoft was compromised this way. Google was compromised.
What is to say Apple won't be compromised??
OP is repeating marketing.
Apple is a participant in the NSA's PRISM mass surveillance program. They've been compromised for a long time. I doubt any decent sized corporation isn't.
PRISM is the result of vulnerabilities found and purchased from hackers. And integrated together in a project codenamed PRISM. Each source has different levels of information sharing. And with Dropbox being a less integrated and more primitive resource for search, I know the entire PRISM program was a gum and shoestring project.
[0] https://9to5mac.com/2021/08/06/apple-internal-memo-icloud-ph...
PRISM for the US, giving personal data to China, and Russia are examples of them not respecting privacy.
1. https://www.nytimes.com/2021/05/17/technology/apple-china-ce...
From now on though any kind of audit in China is going to be almost impossible. They've started arresting researchers who perform due diligence reports for revealing 'state secrets'.
I would say Apple is pointing out the hypocrisy.
Well you're _technically_ right; they do indeed have that power. However, it sounds like you're suggesting they are using that power _to_ shift policy in favor of human rights (emphasis is of importance).
Whilst I can't prove that their intention has nothing to do with human rights, it's only in the same way that I can't prove the last U.S. invasion of Iraq wasn't about protecting the world from weapons of mass destruction.
It is patently obvious to me that this is a business decision fuelled by the drive to keep profits up, that just happens to coincide with happily with a PR friendly action. It's great that they're doing this, but it's just a coincidence that it aligns with what we want.
"Sorry guv, I don't have the keys for that, so I'm not responsible for what went on as I couldn't have known".
Though the biggest money maker is the idea itself. Many believe that Apple is "on their side", and these kinds of plays re-enforce that. The moment it's more profitable to sell you out than "stand up for privacy", they'll do it.
I agree with your comment, but I think it is naïve to assume that Apple does PR by happenstance. Effective marketing/messaging is the bedrock of their business strategy.
So yes they probably did this primarily for raw profit/power reasons, but the positive PR is a close secondary.
These things they throw up is actually smart play from these global police agencies, so sheeps like you feel safe. (Android is the same thing)
I would rather suggest firmly believing whatever company you chose is spying you (be it true or not), and adjusting what you can accordingly (settings, apps, usage, etc.).
I end up living day by day, knowing that nothing is permanent. Right now, I'm with Apple, acutely aware that someday, this will change -- probably when some snake finally manages to slip through similar legislation in the US and it becomes profitably unattractive for Apple to maintain it's privacy stance.
Apple's privacy stance is a marketing thing, after all.
(1) OFCOM may require a provider of a regulated service to pay a fee in respect of a charging year which is a fee-paying year.
(2) Where OFCOM require a provider of a regulated service to pay a fee in respect of a charging year, the fee is to be equal to the amount produced by a computation—
(a) made by reference to—
(i) the provider’s qualifying worldwide revenue for the qualifying period relating to that charging year, and
(ii) any other factors that OFCOM consider appropriate, and
(b) made in the manner that OFCOM consider appropriate.
https://bills.parliament.uk/publications/51870/documents/367...
So, yes?
China never asked them to compromise. They were banned in 2009.
Or is this just speculation (fitting considering the source)?
> In 2018, Facebook attempted to set up a $30 million subsidiary in Hangzhou to incubate startups and give advice to local businesses. Permission to run the startup was quickly withdrawn
Do you really think that Facebook is out of China for any moral reason?
Of course, we don’t know real reasons why they didn’t open there, but end result is that Apple shares data with China and Meta doesn’t.
What could go wrong?
A fanboy without iMessage and FaceTime ...
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Even with the new iCloud e2ee, which is not on by default, if you enable it, Apple and FBI/DHS/et al can still read all your messages (unless each and everyone you iMessage with also enables it), because iCloud still escrows iMessage sync keys in non-e2ee iCloud Backups, breaking the e2ee in iMessage.
For 99.99%+ of iMessages, they ARE NOT E2EE and can be read at any time by Apple and provided to the state without a warrant. This is by design. HT202303 explains this, because for some reason Apple doesn't like to publicly lie.
This article is brand marketing, nothing more. It worked on you.
Apple has the ability to ship private devices. They don't because they choose not to fight city hall.
>For additional privacy and security, 14 data categories — including Health and passwords in iCloud Keychain — are end-to-end encrypted. Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account. The table below includes a list of data categories that are always protected by end-to-end encryption.
The table includes Messages in iCloud with the caveat that the key is stored in iCloud backups if enabled, but the e2e key is still private, no?
That means the iMessages being synced are encrypted to an endpoint key which is held by both the endpoint and the middle transit service (iCloud/iCloud Backup). That's end-to-middle-and-end encrypted, i.e. not end to end encrypted.
Even if you turn on iCloud Backup e2ee (it's an option now) then your iMessages to everyone who hasn't (99.9%+ of people) aren't e2ee because the other end of the conversation is backing up their endpoint sync key.
Can you expand upon how the advancements in western society since (say) WWII have been neccesarily dependant upon privacy?
Alan Turing. Hell, Tim Cook, a gay man who grew up in Alabama. Neither would have survived childhood with their personalities intact had their governments had the access No. 10 Downing demands.
Privacy preserves society’s margins. The margins, by definition, are where change—growth—is nurtured.
However your examples don't demonstrate how the many advances in western society depend upon privacy nor do they prove that it would not have advanced without privacy.
Alan Turing, for example, was open about his sexuality (an issue that bit him when a robbery took place long after his work at Bletchley).
Even had he been somehow taken out of the picture pre WWII it remains true that Marian Rejewski, Jerzy Różycki and Henryk Zygalski would still have cracked the Enigma cipher, built the prototype Bombe's and passed that knowledge to the likes of Tommy Flowers and William Thomas Tutte.
Turing proved a result applicable to the third part of Hilbert's second problem, the Entscheidungsproblem.
He was very nearly beaten to that as a first by Kurt Gödel who provided an answer to the first two parts of Hilbert's second while indicating an approach to the third part.
Turing was beaten to the goal by Alonzo Church who demonstrated the halting problem for lambda calculus is not effectively calculable.
Later, in 1939 J. Barkley Rosser highlighted the essential equivalence of "effective method" defined by Gödel, Church, and Turing.
So, uhh, yes - it would be nice to see some notion of proof come to in to play here.
Fringe elements are analogous to a society's surface. They, by definition, interact with novel elements and ideas at a higher rate than population.
Internal interactions exchange information. That distributes information (physical and intellectual). It also increases entropy and thus homogeneity. Conductivity (the term of art is legibility [1]) and complexity are at odds with one another.
Ceteris paribus, internal homogeneity shouldn't change the surface. But humans have agency. Homogeneity precedes conformity which drives more homogeneity. Furthermore, less diversity means fewer novel opportunities/interactions between the fringe and the unknown.
Privacy preserves a diversity of fringes which drives social complexity. A society without privacy is simpler, and thus less capable of innovation, than one with it. (There is obviously an upper bound to this phenomenon. A perfectly opaque system is static. But humans, as social creatures, resist isolation more naturally than conformity.)
[1] https://publications.aston.ac.uk/id/eprint/27204/1/Linked_da...
2. Privacy is about as personal of a fight to Cook as shareholder obligations are, and only one of them gets him removed if he neglects it.
3. It's pretty fucking stupid to suggest the UK would do the same thing to Turing today if they had the data. You may recall that there are now laws in both the UK and, yes, Alabama since 2009, that render this a hate crime and deter it properly. It's the lamest possible excuse to support corporate power.
Ultimately Tim Cook will say whatever gets investors horny. If you're dumb enough to factor his sexuality in to your trust quotient, you deserve to be XKeyscored.
A series of examples isn't necessarily a comparison and is certainly not an equation.
> stupid to suggest the UK would do the same thing to Turing today
Re-read the comment. Nobody suggested as much.
If we ignore the open society angle and assume surveillance would be one sided:
Competition is needed for healthy capitalist economies. Competition doesn't work well with great power imbalances. To the extent entrenched business could leverage the government, as they do, powers of surveillance could be used to stifle competition. That leads to stagnation.
Democracy, even in a limited form, doesn't work when everyone is under surveillance by a powerful minority. I don't think I need to elaborate since there's been plenty of writing on that.
Also, people don't want to make civic contributions to a society that treats them like cows with a criminal bent. There's not much argument against being a hedonic leech in a society that benefits from your labor but resents your autonomy.
I haven't answered your question exactly, but it's a bit difficult when framed that way. I still think it's pretty clear that the massive power imbalance that comes with dragnet surveillance can catalyze corruption, stagnation, and malaise, thus impeding progress.
I suspect what many forget or were perhaps unaware of is the in practice society with near zero privacy existed for the vast bulk of actual human history.
Before the car and the radical change in individual human movement that came about for those parts of the world privileged enough to have a car for every family the majority of people lived within a small radius surrounded by people who effectivel knew every detail of each others lives .. if not as it happened then almost certainly by the next quarter as word spread.
Again, as I mentioned above, I like privacy .. but it remains true that the greatest expansions of modern western economies; mass production, feeding quantitively more with less land and labour, etc .. all happened without any essential dependance upon privacy to bring these changes about.
It is the upstream grandparent claim that privacy is fundemental and essential for any advancement in a society that doesn't pass the smell test and certainly hasn't yet been well argued for.
I absolutely do agree that it is desirable .. but essential (in a strict sense) for the continuation of human society .. that needs better argument to pass muster.
The lack of privacy in a local town is surely quite different in its effect on society than a centralized and wide reaching dragnet surveillance program. That local lack of privacy was limited in reach, not automatic nor persistent, and mostly symmetric... which doesn't present the same potential harms.
With no privacy there’s no civil disobedience and no advancement.
Without privacy there’s no resistance to Putin’s regime, or to prohibition (of abortion, homosexuality, alcohol, drugs, …).
Privacy is essential.
I'm a bit curious how you arrived at the conclusion that you're "not sure our species has a fundamental right to [privacy]". That seems like the absurd claim requiring actual support here, seeing as how privacy is the norm, not the other way around.
I didn't claim anything, I said I wasn't sure. Our species is much much older than the concept of privacy. Back when we were still sitting in trees there was no privacy. We decided that that was a thing quite a bit later. Now in the year 2023 I would say many of us see privacy as a fundamental human right though obviously and a privilege to defend.
The very concept natural rights is basically divine rights but without explicitly mentioning a god.
As such, it's much more likely that they are universally true rather than a result of human consensus.
Care to elaborate on your thinking? Genuinely interested.
One more example: some societies will require you to disclose any relation to politically exposed persons. Which is beneficial to society, but I can’t withhold even if I wanted.
As the famous saying goes: There are no solutions, only trade-offs.
Privacy is a trade-off.
The only place where privacy has meaning is in the company of other people. Including society as a kind of group of people.
Here lies the paradox.
(Russia was finally kicked out after continuing what they started in 2014, but their pledge was a joke anyway, or wishful thinking at best).
No sane person believes that there aren't really nasty, organized criminals in the world, and no sane person believes that said criminals have a right to absolute privacy, including e.g. (the moral equivalent of) search warrants.
I grew up in a time/place where organized crime was rampant, and if you looked at the wrong person you could be killed. It was time of racism-by-default, thievery-by-default, a lack of investment in R&D, science or infrastructure, and the opposite of a meritocracy. It was an "invasion" of their privacy that ended that era, and now we can comfortably watch Scorcese movies about it over an internet those people would never have invented or invested in.
That's just a strawman.
Plenty of sane people believe that the threat of criminals doesn't outweigh the threat to individual liberty posed by the state. Additionally, plenty of sane people wouldn't support a ban on locks and safes because it makes it harder to search criminals.
I'm pretty sure I have my sanity in check, and I don't think there's any reason for the government to require private enterprise to break encryption to ease prosecution. It should be hard or impossible for governments to spy on their citizens.
https://en.m.wikipedia.org/wiki/Telford_child_sexual_exploit...
https://www.google.com/amp/s/news.sky.com/story/amp/1-000-ch...,
You extend that to the entire UK government.
A gang, composed of minorities, was explicitly ignored by the police because the police were afraid of being seen as racist for cracking down on them.
* https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
1, Court signed order 2, Public Disclosure during prosecution or within X time of the court order being signed (including when no wrongdoing found) 3, Some sort of test to ensure it's not misused (imminent threat to life, serious crime like murder/child kidnap or something)
The idea that a judge can order a cavity search to find information leading to the location of a suspected murdered/dying child but not to read a message between the suspected murders phones seems ludicrous.
It appears at least in some of the US/UK, a judge can order you to give information including your phone password and if you don't, you become a criminal for that.
I'm just suggesting the question should be around where do we draw the line on privacy vs protection and what safeguards do we put in place.
I.E on a scale of speeding ticket to terrorist attack.
It is not mathematically possible to selectively break E2EE. If it’s broken, it’s not E2EE.
I think the important question is should an authority be able to read messages and if so, under what circumstances?
What if it's to prevent a major terrorist attack, should you have an absolute right to privacy so much so that, a means that would never be used against you can't exist even if it means the loss of a lot of life?
As I say, I think the question should be around where we draw the line and what protections we put in place to ensure it's not crossed.