Check Article 12:
https://www.un.org/en/about-us/universal-declaration-of-huma...
> No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.
I'm no fan of Meta or their privacy violations, but saying that voluntarily downloading an app (which by the way does clearly outline their privacy practices) is equivalent to having my humans rights violated just really waters down what "human rights" should mean.
that's all true until an app becomes the only way to interact with certain groups of people. i certainly wouldn't call my usage of Discord voluntary. it doesn't actually matter how often i read their privacy policy and shake my head. either I break off contact with a large part of the internet that's important to me or I begrudgingly agree "voluntarily" to their terms and conditions.
In modern life, people don't discuss politics in townhalls, pubs, or whatever anymore. Online communication is by now far too siloed and supervised to the point of being unusable. Media are one-way streets, pushing the agenda of billionaires.
But you need to be able to have controversial discussions about "heavy" topics without fear of being ostracised. You need to have a back-channel to give feedback to "higher ups". Etc.pp.
A society where the individual is degraded to a mere drone (even if only loosely via framing) controlled by the "hive mind", without any recourse to voice constructive criticism is a lot of things, but certainly no democracy. There looms a dystopia on our doorstep.
> But you need to be able to have controversial discussions about "heavy" topics without fear of being ostracised.
Uh, why? People should have freedom of speech, but it feels like a lot of people want freedom from the consequences of the their speech. If anything, I think a lot of our current social disharmony is a direct result of the extremely recent development of people being able to mouth offline with very little social constraints.
Mike Tyson probably said it best: "Social media made y'all way too comfortable with disrespecting people and not getting punched in the face for it."
https://www.wired.com/story/facebook-data-leak-contact-impor...
And aside from that, a lot of software communities are on Discord now. People are gating download links behind it, use their threading feature for support and put their knowledge base in channels. And not just small communities and developers. ASUS has made their main communication channel Discord too.
I agree it's difficult. I've had success showing keybase to people because of how barebones simple it is - but it's not a solution for everything of course.
How many non technical people have heard of Discord?
If the number in your name is your birth year I'm not too surprised, but don't assume you can project from your own experience onto others 1:1.
I can't even get my wife to install Element - and she works in tech as a senior python / automation engineer. People want neatness on their phone and low total complexity, and installing a messenger for a single person is over the line for most.
> You are a very ignorant if you think there is no barrier to getting someone to try an app with a substantially less good UX than what someone's currently using, and that that barrier doesn't border impossible in a group of 10.
Yet many people do have multiple messaging apps.
And Discord the one you think is so popular is not even in the top 10…
https://www.statista.com/statistics/258749/most-popular-glob...
They aren’t counting iMessage as a separate app. But do you really think it wouldn’t rank above Discord?
> I can't even get my wife to install Element - and she works in tech as a senior python / automation engineer.
Maybe your enlightened millennial friends and family aren’t as willing to change as you think they are?
> People want neatness on their phone and low total complexity,
Yet the average person has 35 apps on their phone
https://www.thinkwithgoogle.com/marketing-strategies/app-and...
Yikes, seems like this is built to keep people from saying things about powerful people that they don't like.
If I cannot attack the honor and reputation of a person, and by extension, artificial person like a corporation, what good is freedom of speech? How can I call someone out for being a scammer, or for doing horrible things? How does one seek public redress of a grievance against a company, or an agent of the government? Does arbitrary apply to timing, or the circumstance? Who is the arbiter of arbitrary? This is not a human right. It is a nice tool for a tyrannical government to strip away rights from people. Oh, you've violated Mr. Arresting Officer by accusing him of falsely arresting you. Now you get to deal with the false arrest and a human rights crime. Likewise, Ms. Bought a Mansion with Public Money can no longer be accused because she has a human right to not have to trifle with public accountability.
It's like exploited workers and people living in quasi-slavery, many of them don't understand their rights and "voluntarily" waive them. My parents didn't really understand the implications of "voluntarily" accepting Meta's privacy statement - once I explained it to them, they were in complete horror.
Threads is not an attempt to push spyware on users, that would be incompliant in the EU. (And what is this spyware you believe is in Threads?) More likely they know exactly how much work it entails to be compliant and they decided to initially skip the EU market to speed up their launch.
The sad thing is that all their details and yours are already known to Meta.
The dozen of us who behave like you will keep trying though.
https://github.com/SubhamTyagi/openinwa (I recommend downloading from f-droid)
Good thing the EU just outlawed that model and forced everyone to support "third party app stores" that are thinly-veiled shells for Facebook/Google/etc to bypass that review process.
the "I wanna sideload" crowd are nothing more than allies of convenience for FB and others. Facebook was already experimenting with getting users to manually sideload the full-telemetry build and now they can just say "oops not supported on safari, install the native app".
https://arstechnica.com/gadgets/2019/01/facebook-and-google-...
That’s not true. Apple was position itself as being better at security than Microsoft long before Google was selling devices to people.
For example:
It's debatable whether or not that was true, and even if you believed it it was up for another debate whether that security was by design or because Apple's vanishingly small share of the PC market made it uneconomical to write malware targeting OSX.
This isn't to say that Microsoft was doing security properly back then either, they weren't.
Google is generally excellent at security, but that doesn't change the fact that they're a nightmare for privacy.
[1]https://www.theregister.com/2017/11/28/root_access_bypass_ma....
I don't much care. Companies don't have ethics, they have fiscal goals. If Apples fiscal goals happen to line up with my own goals, so much the better.
I would tend to trust a company who is doing something to selfishly support the bottom line way easier than I would trust a company who claims to be doing it for the common good of all humanity.
Google famously started off trying to not be evil and also be a profitable company simultaneously. It didn't work out great in that one of those goals became slightly more important than the other.
Automative manufactures didn't give a rats ass about fuel economy until customers wanted it.
I remember some talk about those getting encrypted, don't k ow if that has happened yet.
https://www.statista.com/forecasts/997945/most-used-messenge... (non-free link)
This is not a thing outside the United States, and I doubt that most British politicians are even aware of 'blue bubbles'.
For example, the recent controversy regarding the release of Covid-related government communications was centred on WhatsApp, with no reference to other platforms like iMessage.
https://news.sky.com/story/politicians-are-drawn-to-whatsapp...
I prefer iMessage over the other messengers, but I still haven’t met anyone who cares. A lot of people don’t even know why the bubbles are sometimes green.
Non Apple work machine?
Also outside of programmers, IT, and designers, you rarely get a choice in the company issued laptop. It never makes sense for a company to issue more expensive Apple computers instead of ThinkPads or Dell computers.
The machine is mine and I do work on it. Thanks for the concern but I’m not worried about getting sued. I’m sure it’s happened here previously, but it’s not like the US.
> Also outside of programmers, IT, and designers, you rarely get a choice in the company issued laptop. It never makes sense for a company to issue more expensive Apple computers instead of ThinkPads or Dell computers.
I’m not one of those professionals and I can get my job done quicker on a Mac. My employer doesn’t dictate how I get things done and paid for the machine I want. I think this is a good thing.
Any job that requires a crappy trackpad isn't a job worth having.
> My employer doesn’t dictate how I get things done and paid for the machine I want.
That is very much not your machine. If your employer ever gets sued, or runs into some investigation, or some internal dispute escalates enough, all the data on it is now likely available for them for review.
Given large enough company and enough people, you'll get that "preserve documents for discovery" email one day. It happens outside of the US too.
Just seeing those laptops is frustrating. What is the point of the trackpad if you have to use a mouse?
The other major feature I see for other messengers over SMS/MMS is much larger attachment sizes. It can be challenging sending an MMS with attachments >1MB. Meanwhile, I can send a 100MB file/video or an 8MB photo over Signal. WhatsApp allows for 16MB attachments. Sending a quick video in-line with the chat thread in MMS is miserable and gives an incredibly trash quality video while most other chat apps you can stick a decent quality 30 seconds or so video without any issue. Photos sent over MMS are usually junk while one could get a decent 4x6+ print off an 8MB photo.
If I send an SMS message to a group of people, they all see a message from me. They don't know who else got it. And if they reply, they reply only to me. Is your experience different?
WhatsApp (and I think iMessage) allow me to create a group with a name/purpose and send messages to the group and receive replies to the whole group.
(P.S. I went from dumb-phones to Android and have limited exposure to iMessage's feature-set).
That kind of pricing made WhatsApp an infinitely preferable alternative.
Phones automatically switching to MMS would be catastrophic.
Data (WhatsApp) is essentially free in comparison. £10 (13 USD) per month gets you 20GB: which doesn't care how many messages/recipients/photos you send.
Here in the US its common to have at least 1MB MMS max size. Back in the day 300-600KB was often the max size, but that's definitely changed over the years. Maybe its just splitting it up and re-assembling it behind the scenes, I'm not sure.
I can't speak for all history, but from about 2004 or so in the US MMS and SMS were often bundled and billed the same, especially for networks which had rolled out 3G/EV-DO. Having a plan with 500 messages usually meant 500 combined SMS and MMS message.
Does MMS not exist in your country?
And then of course the vastly higher fidelity of pictures and video sent via iMessage.
Not to mention MMS is vastly inferior to WhatsApp and iMessage for sharing media and other information.
So I use 2 or 3 other apps for mostly a few international people I know but basically everyone I know just defaults to SMS/iMessage.
Whatsapp works on PC, Mac, Android and iOS
iMessage only works on Apple devices.
Nowadays it's mostly about convenience and features compared to SMS, and iPhone has a much smaller marker share in Europe so iMessage isn't a thing.
In contrast, in many European countries Whatsapp has 90%+ penetration [1]. Even where it's relatively unused it's more common than iMessage.
[1] https://www.statista.com/statistics/1311229/whatsapp-usage-m...
That said, I’d be very happy to see that they did threaten a boycott as well.
Meta:
> Some countries have chosen to block it [WhatsApp]: that’s the reality of shipping a secure product. We’ve recently been blocked in Iran, for example. But we’ve never seen a liberal democracy do that.
They said they won't comply. UK would have to simply block WhatsApp.
You cannot actually believe that meta gives a single solitary fuck about privacy?
I think the GP is likely aligned with you anyways.
Meta was also in the biggest mass surveillance & influence scandal of all times for a private not too long ago, please don't forget
If so I missed the memo (that isn't unlikely, I'm not saying you are wrong!). Any references/links for that? A quick search doesn't turn up much, but Google isn't what it used to be…
I had to look it up.
It’s by far the largest messaging service that is e2e encrypted by default. I think it’s more than fair to call it ahead of the curve for a service of its size.
https://www.wired.com/2014/11/whatsapp-encrypted-messaging/ https://blog.whatsapp.com/end-to-end-encryption
As recent as 2021, there's been questions: https://arstechnica.com/gadgets/2021/09/whatsapp-end-to-end-...
But, let's go to the start - WhatsApp started in 2011.
Encryption arrived in varying degrees until there was some pressures to change the amount of privacy messages had for advertising purposes.
Lots in the news at the time.
2018 "Another point of disagreement was over WhatsApp’s encryption. In 2016, WhatsApp added end-to-end encryption, a security feature that scrambles people’s messages so that outsiders, including WhatsApp’s owners, can’t read them. Facebook executives wanted to make it easier for businesses to use its tools, and WhatsApp executives believed that doing so would require some weakening of its encryption."
https://www.washingtonpost.com/business/economy/whatsapp-fou...
2018 "Acton said he tried to push Facebook towards an alternative, less privacy hostile business model for WhatsApp — suggesting a metered-user model such as by charging a tenth of a penny after a certain large number of free messages were used up." https://techcrunch.com/2018/09/26/whatsapp-founder-brian-act...
2018 "WhatsApp CEO Jan Koum quits over privacy disagreements with Facebook" https://www.theguardian.com/technology/2018/apr/30/jan-koum-...
2018 WhatsApp co-founder: "I sold my users' privacy" to Facebook "https://www.cbsnews.com/news/brian-acton-whatsapp-on-faceboo...
Encrypted in transit is not at rest, let alone the backups of messages on Google Drive / iCloud.
Well you're _technically_ right; they do indeed have that power. However, it sounds like you're suggesting they are using that power _to_ shift policy in favor of human rights (emphasis is of importance).
Whilst I can't prove that their intention has nothing to do with human rights, it's only in the same way that I can't prove the last U.S. invasion of Iraq wasn't about protecting the world from weapons of mass destruction.
It is patently obvious to me that this is a business decision fuelled by the drive to keep profits up, that just happens to coincide with happily with a PR friendly action. It's great that they're doing this, but it's just a coincidence that it aligns with what we want.
I agree with your comment, but I think it is naïve to assume that Apple does PR by happenstance. Effective marketing/messaging is the bedrock of their business strategy.
So yes they probably did this primarily for raw profit/power reasons, but the positive PR is a close secondary.
"Sorry guv, I don't have the keys for that, so I'm not responsible for what went on as I couldn't have known".
Though the biggest money maker is the idea itself. Many believe that Apple is "on their side", and these kinds of plays re-enforce that. The moment it's more profitable to sell you out than "stand up for privacy", they'll do it.
Such statements rarely end up ageing like wine in the long run. Why would you be so happy about being owned by some big corporation just because it's your favorite big corporation?
Self preservation has taught me not to trust any big corporation, regardless of how good their PR is.
So have 100 year old car companies, and I'm old enough to remember many people saying the same things about their favorite car brand in the past ("I'm only buying X brand because they make quality stuff and they never broke my trust") and I also know they changed their opinion recently after a couple of decades.
And changing car brands is way easier than changing smartphone ecosystems, should one of the two players decide to screw you.
My point is people should not be fanboys of any corporation. History has proven they can always turn against their customer, even if Apple so far hasn't done it, but there's time, company management and culture can, and will always change with time, and with constant shareholder pressure for infinite growth there's plenty of opportunities in the future for the tides to turn, mark my words.
In what world ?
I have switched from iOS to Android and vice versa multiple times while still driving the same car.
Did your app purchases form the Google Play Store automatically transfer to your Apple App store, and did your photos off your Google drive transfer to your iCloud, or vice-versa?
Read my comment again, I ware referring to the ecosystems not being interchangeable, not the phones themselves.
The incompatible ecosystems is the tie-in that keeps people tied to their respective walled gardens, not the physical HW phone brick itself which is interchangeable. Once people invested enough money in one ecosystem, they're less likely to switch to the competition as all their data and purchases are trapped.
And apps are available for iOS that let you access all of them. If you install Google Drive on the iPhone, your drive shows up along side iCloud in the Files app and open/save file dialoga
Do just the opposite of this
https://news.ycombinator.com/item?id=36803905
I’m sure there are ways to migrate your email. Thunderbird?
Fanboys don't like you pointing out the hard to swallow truth pills. They expect comments to validate their lifestyle choice, not contradict them. Any contraction is a direct offense to them.
> I’m in the middle of switching from android to IOS
At least for you it's easy, because all google apps exist for iOS, but switching away from iOS is absolutely impossible as there is no iCloud or iMessage for Android, so all your data remains hostage with Apple if you try to move.
1. Download Google Drive for iOS
2. Go to the Files App
3. Select all in your iCloud Drive
4. Copy
5. Go to your Google Drive in the Files app
6. Paste
Just like you would copy files from one drive to another.
They are not "great" but they are more than enough to download a zip with all your files and all your photos. From there you go where you want.
Which apps would those be that you have to buy on iOS and Android separately? Most non game apps are subscription based that work across platforms.
My photos are already sync to Google Photos on my iPhone and if I had an Android device, I would just download the Google Photos app.
Music bought on iTunes has been DRM free since 2008 and Apple Music is available on Android.
Apple, Google, Amazon and a few other platforms and most of the studios participate in MoviesAnywhere where you buy movies from one platform and it shows up as purchased on the other platforms
What data is “trapped”?
Since every app that I pay to use that has an Android version is subscription based, yes.
> and did your photos off your Google drive transfer to your iCloud, or vice-versa?
Since I can download the Google Drive app on my iPhone and it shows up right next to iCloud Drive on the Files app and in File dialogs. Yes.
As far as photos from iCloud to Google, just download Google Photos on your iPhone and sync your photos.
Anything else?
That's not a direct transfer, it's a workaround which requires you to have free storage on your phone greater than the amount of photos you have.
which is really a low bar.
Basically, it's as usual a financial calculation of what PR can brings vs what you can lose in the market.
And fanboys believe it's because they are the good guys.
They will probably comply with some backdoor in partnership with Five-Eyes NSA & GCHQ. This is just PR posturing to build consumer trust.
Same with their venture into CSAM in the west. China could ask Apple for the ML be applied to scan for political dissidents.
It's a slippery slope and the frog gets boiled every year.
It was about getting a slice of hugely lucrative pie of customer market.
Vaguely remember a charity used to have a thing where they'd auction off a dinner with Steve, then later Tim. Given time with a leader who has literally revolutionized supply chain in CN and a CEO who made Apple his own following the most notable CEO ever, going after various gotcha points would feel like a wasted opportunity. But think I'd have to ask why a company designed in California of the 1960s and 1970s doesn't have line in the sand policies when dealing with a genocidal government and perpetual backdoors in software and politics, but will take a move like this. Would hope for something more than a canned answer.
Of course, we don’t know real reasons why they didn’t open there, but end result is that Apple shares data with China and Meta doesn’t.
So, yes?
China never asked them to compromise. They were banned in 2009.
Or is this just speculation (fitting considering the source)?
> In 2018, Facebook attempted to set up a $30 million subsidiary in Hangzhou to incubate startups and give advice to local businesses. Permission to run the startup was quickly withdrawn
Do you really think that Facebook is out of China for any moral reason?
Which is all well a good for now, but profit directions can change, and i suspect it's easier to change a direction guided by profit than a direction guided by morals. Ie i suspect their current "good direction" is less stable than some would suggest.
Make no mistake: if Apple needed to get someone killed, they would. They're not some miraculous pinnacles of good in a sea of evil. It's just that they merely need to flex the law at you to destroy your life forever. Apple is no different, they'll hire the Pinkertons and break your fingers should they find the need to. Carnegie Steel did it, Apple's not above it either.
Ok, I'll play along. Suppose Tim Cook wakes up tomorrow and decides for some reason he wants me dead. How exactly does he do it?
Sorry for the Zoolander reference. I couldn't help it
But all playfulness aside:
* Pay professional hitmen. * Pay a hobo enough to go beat you up in your home. * Pay enough people enough money to kill you pretty much anywhere.
What are they going to do, plead in front of a judge that sees 90% of his murder cases unsolved or solved through guilty pleas that Tim Cook gave them a wad of cash when all they saw was a subordinate of a subordinate of a subordinate ? There's nothing fancy about it. Especially with an economy that drives people to drastic measures: a huge wad of cash that you're guaranteed to keep is enough for most people.
You mean, pay an undercover cop who is advertising himself as a professional hitman?
> * Pay a hobo enough to go beat you up in your home.
He'll pay the hobo, and hobo will run off with the money
> all they saw was a subordinate of a subordinate of a subordinate
This is even more crazy than the earlier suggestions. You think there is going to be a chain of subordinates at apple who will all go along with a murder conspiracy? Try arranging a surprise party with five people, see how well people can keep a secret.
You're naïve. Less than 100 years ago the Pinkertons were still murdering workers and nothing happened to them.
If you don't take his vacation offer, he will invite you to a party on his dime. If you don't attend, he will use your location data, make it seem like you were in the wrong place at the wrong time. And depending on the severity and nature of your crime, the outcome will be just low ball enough to make it seem like apple needs to do something bigger than focus on human rights, like making better devices for your security.
Just imagine this: Tim Cook travel expenses amount to an half a million dollar per year.
travel expenses only.
A professional hit man costs between 1/100th and 1/33th of that.
Tim has to simply give up on a pair of new shoes that year.
I also imagine the post-arrest interview of the $5000 hitman going like this:
"You're charged with Murder 1, which is a capital offense in this state. Are you ready to die for $5000?"
"Tim Cook made me do it."
I am simply saying that a man with 2 billion dollars in his bank account can do whatever he wants.
It is also pretty naive to think that Tim Cook expenses can be questioned by an Apple anonymous accountant.
of course this is all hypothetical, men like Tim Cook would never hire an hitman paying cash personally face to face.
> "You're charged with Murder 1, which is a capital offense in this state. Are you ready to die for $5000?"
> "Tim Cook made me do it."
at best that could legally qualify as insanity
But even assuming it costed 200 thousand dollars, would not change that for a Tim Cook it's a day's pay
In what wonder world are you living?
On the other hand, we know that governments do this sort of thing all the time.
they simply have better tools than hitmen, but, for example
https://www.businessinsider.in/policy/news/former-ceo-of-ama...
https://www.seattletimes.com/seattle-news/clearly-lasik-co-f...
> we know that governments do this sort of thing all the time.
they also have better tools than hiring hitmen
contract killing is a fraction of all the homicides
OP asked how the multi billionaire CEO of a trillion dollars company could kill someone
He could simply hire an hitman, it would cost him peanuts
If the victim is also using one of the products the company makes, they would also be in possession of all the information an hitman would need to complete his task, no investigation would be necessary
Some of the highest-profile hits nowadays happen in Russia, where the rise of wild-west capitalism has led to a boom in contract killings, with victims including politicians, editors and journalists, businessmen, even poets.
How much do you think it would cost to hire a Russian blackop/elite troop fleeing from his country?
There are plenty of unhinged people in this world who do illegal shit for enough money. Do you think some Ex-Wagner mercenary would pass up that offer?
They are frequently subpoenaed for information, and turn over that data more often than not: https://www.apple.com/legal/transparency/us.html
Let's not pretend this is a privacy-motivated decision. Where Apple doesn't have negotiating power (eg. China) they have been forced to compromise user safety and privacy[0]. We live in a post XKeyscore world, pretending like this doesn't also happen in America or the UK is a bedtime story for helpless capitalists.
[0] https://support.apple.com/en-us/HT208351
edit: s/EU/UK
(Edit: for my next trick, I will read the post more carefully before replying)
Another good example is the Dutch housing all the data in an building that was used to track down and kill the right people.
The data existing is the problem. The ideal situation is that there is no data.
ask Foxconn employees if that's true or not.
And besides, private corporations don’t have a “monopoly on violence”, the government does
Blood for Bananas: United Fruit's Central American Empire [0] The lawyer who took on Chevron – and now marks his 600th day under house arrest [1] (Debatable) Business Plot, aka Wall St Putsch [2]
[0] https://history.wsu.edu/rci/sample-research-project/ [1] https://www.theguardian.com/us-news/2021/mar/28/chevron-lawy... [2] https://en.wikipedia.org/wiki/Business_Plot
The power a government has over you is likely also potentially the same as a company?
And lastly it is wrong, if the apps do E2E right (but I have no clue about that) you don't give them a secret at all?
You also cannot change one company, but you can change companies usually better than governments ;)
Nobody worries about the government giving customer data to Apple, do they? Why do you suppose that might be?
https://en.wikipedia.org/wiki/Choice-supportive_bias
the tendency to retroactively ascribe positive attributes to an option one has selected and/or to demote the forgone options. It is part of cognitive science, and is a distinct cognitive bias that occurs once a decision is made. For example, if a person chooses option A instead of option B, they are likely to ignore or downplay the faults of option A while amplifying or ascribing new negative faults to option B. Conversely, they are also likely to notice and amplify the advantages of option A and not notice or de-emphasize those of option B
It takes a lot of unearned trust to to assume that there isn't classified surveillance occurring.
If it is, public virtue signalling about not breaking encryption is theater. As the surveillance occurs prior to encryption.
Which client side scanning would that be?
I would hope that the grandparent was not referring to this thing that never existed as "the client side scanning ability that is built into the OS."
But it seems Google was more political in its relationships than idealistic. And now the entire sector is compromised.
Apple will be one day compromised too. In some crevice of some unknown government office is a person working on a ten-year initiative to get access to inaccessible information in the tech sector. AT&T was compromised this way. Microsoft was compromised this way. Google was compromised.
What is to say Apple won't be compromised??
Apple is a participant in the NSA's PRISM mass surveillance program. They've been compromised for a long time. I doubt any decent sized corporation isn't.
PRISM is the result of vulnerabilities found and purchased from hackers. And integrated together in a project codenamed PRISM. Each source has different levels of information sharing. And with Dropbox being a less integrated and more primitive resource for search, I know the entire PRISM program was a gum and shoestring project.
[0] https://9to5mac.com/2021/08/06/apple-internal-memo-icloud-ph...
OP is repeating marketing.
Except for right to repair...
And software freedom...
Plenty of animals use tools [1]. And this isn’t how we define human rights. Bipedalism is quintessentially human, that doesn’t make tunnels a crime against humanity.
To say that right to repair in specific isn't a human right because the actual human right is agency/ownership/modification/whatever, is a bit like saying that encryption isn't a human right because the actual right is privacy and encryption is just a way to maintain privacy.
The end result is still that people aren't able to exercise rights. I would argue very strongly that having a degree of autonomy over the devices/objects that you own is an intrinsic right.
And if you look back at the history of Open Source software, you'll find that conversations about Libre/Free software have been regularly grounded in discussions of human rights from the start; from rights to ownership, to modification, to communication.
Important? To be sure. Just not "rights".
I don't know, I don't want to argue too much, and I don't want to give you a pedantic reply when we seem to be in agreement that privacy, agency, repair are all important and whether you or I would stick them in a specific category probably doesn't change much about that or necessarily mean that we actually disagree on anything practical related to those concepts.
I think it's bad that Apple isn't willing to fight for right to repair or user agency, but it is good that Apple is willing to fight for privacy regardless of its motivations. I don't think Apple is a universal advocate for human rights and I don't like deifying the company and I don't think its positions on privacy excuse its positions on repair or agency. But it's pretty objectively good for Apple to make a statement that it will pull these products out of the UK rather than comply, and it would be silly for anyone to say that the statement is meaningless just because Apple has bad positions on other freedoms. Apple's positions on right to repair do not make it any less good for Apple to have issued that statement about encryption.
I would rather suggest firmly believing whatever company you chose is spying you (be it true or not), and adjusting what you can accordingly (settings, apps, usage, etc.).
I end up living day by day, knowing that nothing is permanent. Right now, I'm with Apple, acutely aware that someday, this will change -- probably when some snake finally manages to slip through similar legislation in the US and it becomes profitably unattractive for Apple to maintain it's privacy stance.
Apple's privacy stance is a marketing thing, after all.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Even with the new iCloud e2ee, which is not on by default, if you enable it, Apple and FBI/DHS/et al can still read all your messages (unless each and everyone you iMessage with also enables it), because iCloud still escrows iMessage sync keys in non-e2ee iCloud Backups, breaking the e2ee in iMessage.
For 99.99%+ of iMessages, they ARE NOT E2EE and can be read at any time by Apple and provided to the state without a warrant. This is by design. HT202303 explains this, because for some reason Apple doesn't like to publicly lie.
This article is brand marketing, nothing more. It worked on you.
Apple has the ability to ship private devices. They don't because they choose not to fight city hall.
>For additional privacy and security, 14 data categories — including Health and passwords in iCloud Keychain — are end-to-end encrypted. Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account. The table below includes a list of data categories that are always protected by end-to-end encryption.
The table includes Messages in iCloud with the caveat that the key is stored in iCloud backups if enabled, but the e2e key is still private, no?
That means the iMessages being synced are encrypted to an endpoint key which is held by both the endpoint and the middle transit service (iCloud/iCloud Backup). That's end-to-middle-and-end encrypted, i.e. not end to end encrypted.
Even if you turn on iCloud Backup e2ee (it's an option now) then your iMessages to everyone who hasn't (99.9%+ of people) aren't e2ee because the other end of the conversation is backing up their endpoint sync key.
(1) OFCOM may require a provider of a regulated service to pay a fee in respect of a charging year which is a fee-paying year.
(2) Where OFCOM require a provider of a regulated service to pay a fee in respect of a charging year, the fee is to be equal to the amount produced by a computation—
(a) made by reference to—
(i) the provider’s qualifying worldwide revenue for the qualifying period relating to that charging year, and
(ii) any other factors that OFCOM consider appropriate, and
(b) made in the manner that OFCOM consider appropriate.
https://bills.parliament.uk/publications/51870/documents/367...
1. https://www.nytimes.com/2021/05/17/technology/apple-china-ce...
From now on though any kind of audit in China is going to be almost impossible. They've started arresting researchers who perform due diligence reports for revealing 'state secrets'.
I would say Apple is pointing out the hypocrisy.
Has Apple really removed iMessage and FaceTime anywere else ? Are these available with 100% full encryption in China ? If so then they are just blowing wind :(
[1] https://apnews.com/article/dubai-middle-east-united-arab-emi...
Talk less, read more.
https://www.reddit.com/r/ios/comments/cskufy/imessage_encryp...
The idiot pmendes is wrong (if he was correct then no one knowledgeable on the subject would classify that system as E2EE - something more to read about). The encryption keys are not managed in iCloud which you can read yourself:
https://support.apple.com/guide/security/how-imessage-sends-...
https://www.apple.com/legal/privacy/data/en/messages/#:~:tex....
iCloud backup is an opt in feature - you use it full well knowing it effectively damages the affordance of E2E regardless of locale if ADP is not available.
“Read more” did not mean social media.
What exactly is pmendes wrong about? Are you referring to this comment:
> In iMessage the message contents are in fact end to end encripted. Each device encripts the message using the recipient keys and then sends the message. The problem is that iCloud manages the keys by itself so you have no way of knowing who is the exact owner of the key. Addionaly, on group chats, they don't even need to be a man in the middle. They can just add their key to the list of encription keys for that chat, and receive a copy of each message.
What's wrong there, aside from spelling? The nit I would pick is that in "iCloud manages the keys", I would change "iCloud" to "Apple" or "Apple's IDS".
How, specifically, does iCloud backup damage the affordance of E2E? This doesn't make any sense.
If you have somebody's GPG public key, you can encrypt a file to that public key and then put up the encrypted file on a public FTP site [0], whence they can download and decrypt it. iMessage does nearly exactly that, except that 1) Apple's identity service effectively solved the key distribution problem, 2) the messages are, even though already encrypted, themselves also transmitted by encrypted channels to Apple's servers during transit.
[0] Well, I wouldn't do this if I were at all concerned about the contents because it doesn't allow for forward secrecy.
If you’re going to classify every critical fact as a “nit” then nothing is ever wrong.
IDS vs iCloud is far more than a nit. They’re completely different services. iCloud is run by a 3rd party in China, this is well publicized, whereas IDS is not. So that’s like not a minor detail.
iMessage does not depend on iCloud. You don't need an iCloud account. These are unrelated.
Contact key verification is a more recent addition, and again not dependent on iCloud.
> How, specifically, does iCloud backup damage the affordance of E2E?
Just saying, you can sync your data to whatever encrypted or unencrypted service you want if you choose to. This may diminish the value to the end user of E2EE but it is unrelated. I'm not the one that brought up iCloud first. Take that up with the original commenter.
Then they should read the leaked government documents from around the world that contradict what Apple says themselves. Failing that, they should at least be able to read the actual code to corroborate its security, but that's not an option either.
On what specifically?
> they should at least be able to read the actual code to corroborate its security, but that's not an option either.
Why does that matter? You're already trusting Apple hardware. Public access to source code doesn't make security systems safer. I'm not sure what a journalist or even 99% of webshits on this forum would do with trying to audit crypto.
For starters, PRISM and XKeyscore. Both are damning indictments of the state of surveillance a decade ago, and are so damaging that pretty much every FAANG company denies knowledge of their existence. PRISM was about the outreach the US government has with domestic companies, and XKeyscore showed just how far those connections could be abused.
Simply the fact that these leaked documents exist and Apple denying them is a contradiction. Everything else is speculation, but my brain can imagine a lot happening over those past 9 years.
> Why does that matter?
Accountability purposes.
> You're already trusting Apple hardware.
Ideally I don't do that either. I'm not a fan of closed firmware interfaces and if possible, I'd like to audit the code for those as well.
> Public access to source code doesn't make security systems safer.
The majority of networked servers online today beg to differ. Over time the industry actually found that it's much safer to use an open and transparent OS than it is to trust a black-box with UB that may-or-may-not be fixed.
> I'm not sure what a journalist or even 99% of webshits on this forum would do with trying to audit crypto.
This speaks to a lack of either experience or imagination, I can't tell which.
Where's this denial by Apple? Or is your argument that because Apple doesn't admit colluding with the NSA they must be doing it. Well that is not falsifiable and what evidence are you speaking to of Apple specifically colluding with the NSA.
> I'd like to audit the code for those as well.
Firmware is not hardware. That would still not address the hardware issue.
> The majority of networked servers online today beg to differ. Over time the industry actually found that it's much safer to use an open and transparent OS than it is to trust a black-box with UB that may-or-may-not be fixed.
Yes, the neckbeards chant since CatB. There are extremely few people not putting their trust in blackboxes. Slapping linux on a box doesn't magically make it transparent - nor does linux have a security record you want to brag about.
A fanboy without iMessage and FaceTime ...
PRISM for the US, giving personal data to China, and Russia are examples of them not respecting privacy.
What could go wrong?
@dang Is there any way I can counter-argument this statement without it getting flagged? If so, please let me know how.
Because so far I have failed and I don't know what rule I broke by countering this statement.
If you have a link to the flagged comment, I can probably help you understand why HN users would have flagged it. This comment is getting downvotes because complaining about downvotes and flags always does.
IMHO people should be allowed to complain otherwise how can we spot deficiencies and injustices and improve?
These things they throw up is actually smart play from these global police agencies, so sheeps like you feel safe. (Android is the same thing)