A lot of Apple's "privacy" features nowadays are marketing. It's privacy theater. What matters is whether they can tell a plausible story to the public, not whether is technically effective.
A lot of Apple's "privacy" features nowadays are marketing. It's privacy theater. What matters is whether they can tell a plausible story to the public, not whether is technically effective.
It doesn't even apply in this instance, since Apple's work on fingerprint resistance still results in real privacy improvements even when later shown to be imperfect. It means Apple has to improve what they've already done, not that what they've done so far is mere "marketing" or "theatre".
Shall I cite my list of CVE? Or perhaps it would be more interesting to cite my list of unfixed 0days.
> It doesn't even apply in this instance, since Apple's work on fingerprint resistance still results in real privacy improvements even when later shown to be imperfect. It means Apple has to improve what they've already done, not that what they've done so far is mere "marketing" or "theatre".
What does it say about Apple engineering that that they keep shipping features with very obvious and/or predictable flaws?
As for your point about the pattern of vulnerabilities: I'd attribute this to being closed source. They keep shipping security features with limited auditing, and only discover flaws in production.
Apple announces powerful new privacy and security features: https://www.apple.com/newsroom/2023/06/apple-announces-power...
WebKit Features in Safari 17.0: https://webkit.org/blog/14445/webkit-features-in-safari-17-0...
In general, Apple is trying to market itself as the privacy company. "What happens on iPhone stays on iPhone", yadda yadda.
> Maybe Hanlon's applies here.
I think my view is in alignment with Hanlon's razor. I don't think it's necessarily malicious deception. Rather, Apple has a habit of shipping the laziest implementations and slapping a "privacy" label on them, but the public doesn't know that these are lazy half-measures.
> As for your point about the pattern of vulnerabilities: I'd attribute this to being closed source.
WebKit is open source.
> They keep shipping security features with limited auditing, and only discover flaws in production.
I don't think this is a closed/open source issue. It's just bad engineering.
In the game of tracking, minor hurdles are great at stymying many actors.
And finally, your citation in response to someone saying they haven’t seen Apple market web audio fingerprinting protections has no references to said feature. Are you saying all the privacy features in that press release are a smokescreen? It’s quite unclear.
I'm not aware of any. But they aren't advertising fingerprinting resistance either.
> In the game of tracking, minor hurdles are great at stymying many actors.
That's questionable.
> And finally, your citation in response to someone saying they haven’t seen Apple market web audio fingerprinting protections has no references to said feature.
There were multiple antifingerprinting methods in Safari 17. The linked articles referred to them collectively.
>
> That's questionable.
It's basically indisputable. Ask any online advertising buyer about the effectiveness of audience targeting for Safari users versus the competition. Or consider the ability of the average website operator to adopt Fingerprint.js instead of whatever half-broken tool their usual audience measurement provider offers them.
https://blog.google/products/chrome/privacy-sandbox-tracking...
> Chrome is testing Tracking Protection, a new feature that limits cross-site tracking.
And I haven't heard any argument suggesting that the marketing is deceptive. Apple implemented numerous fingerprinting protections and nobody has demonstrated any of them to be "theatre" or mere "marketing", only that a security researcher was able to defeat one protection among many (and then published their work so Apple can solve for it in the next release). In reality, ALL such work is an ongoing battle between developers and security researchers.
In each subsequent reply you are shifting your stance in order to deflect away from this original claim, essentially by holding Apple to an impossible standard where anything less than perfection on the first try is equivalent to scamming the public with lies. Do you want to defend your original claim that "a lot of Apple's privacy features nowadays are marketing" and "privacy theater"?
> Shall I cite my list of CVE? Or perhaps it would be more interesting to cite my list of unfixed 0days.
The list of vulnerabilities is not very informative for the same reason a trackers blocked statistic is not. It doesn’t give any baseline for comparison and may just be a reflection of how important and interesting to security researchers the target is.
That's a rather bold claim, unless you're a mind-reader.
> The number of reports is not helpful data without a lot of other context, but you offered it as if it would be convincing or definitive.
I didn't give a number. I only said I have a list. It seems that you're still missing my point, which was simply that my knowledge of and experience with these specific technologies means that my original comment was not a "wild accusation". That's it, that's the whole point.
> How many CVEs and 0-days have you filed against Audacity?
I don't use Audacity, and I have no idea how it's relevant here.
It seems like you have me confused with someone else in the thread who used the phrase "wild accusation" and are responding rudely. I think your original comment was needlessly exaggerated and inflammatory and defending it, instead of clarifying it, is a bad look. Clearly you have an axe to grind with Apple, and my advice to you is you should put a little more effort into hiding it if you want others to take you seriously.
No, I'm not confused. But that comment was the context for my mentioning CVE and 0days, which you decided to discuss yourself.
simondotau: "That's an wild accusation to make without citations."
me: "Shall I cite my list of CVE? Or perhaps it would be more interesting to cite my list of unfixed 0days."
you: "The list of vulnerabilities is not very informative for the same reason a trackers blocked statistic is not."
If you don't want to discuss my previous quoted comment, that's fine, but you have in fact mentioned it and continue to mention it. Thus, the context is very relevant.
> and are responding rudely.
Where exactly was I rude?
> I think your original comment was needlessly exaggerated and inflammatory and defending it, instead of clarifying it, is a bad look.
I would be happy to clarify it, but the first time you asked for clarification was here: https://news.ycombinator.com/item?id=39661492
I'll respond to that comment, though it may take some time.
> Clearly you have an axe to grind with Apple
I've been a Mac user for more than 20 years, a professional Mac developer for more than 15, and I currently sell apps in the Mac App Store and iOS App Store. Do I have critiques of Apple? Yes, of course. However, they are the critiques of an insider who has no intention to leave the ecosystem.
You're throwing around your ego and responding with alleged claims of personal expertise when this discussion has nothing to do with that. You're deflecting with puffery; which is irrelevant with respect to your original claim which I questioned. I don't care that you have a list and I don't care how long it is. You accused Apple of engaging in privacy theatre, and that "many" privacy features where mere "marketing". Defend that claim or move on.
https://fingerprint.com/blog/ios15-icloud-private-relay-vuln...
> 3rd party cookie blocking?
It's very funny that you should ask this question in response to an article about fingerprinting without cookies.
But yes, there are various workaround to use 1st party cookies or other storage to take the place of 3rd party cookies.
Perhaps the worst is the Safari "Privacy Report", which has always been misleading: https://www.simoahava.com/privacy/intelligent-tracking-preve...
I’d say the privacy report is the only real false security feature, but Apple was a laggard in that market. For all we know, they could have been trying to match features with Ghostery or Brave that teach consumers this is a feature you should expect from your browser. Users may also have been needed education about that behavior in order to justify the compatibility regressions cookie blocking incurs. It’s impossible to know from the outside, but your body of evidence to support a really strong accusation is quite weak.
If Safari behaved the same as Chrome, then Apple couldn't market Safari as more private than Chrome.
I don't know what you're talking about. What are X, Y, and Z specifically?
All software has bugs. I think it is more interesting to see how companies respond to reported issues. And how they improve things.
Is OpenSSL "theatre" because it had (bad!) bugs in the past?
https://www.schneier.com/blog/archives/2009/11/beyond_securi...
Public Relay is obviously not accurately described by that term and any rule which classifies it as such would be useless because it would classify all browser security as theater because everyone has had bugs, and everyone has had to adopt more sophisticated defenses to counter more sophisticated attackers.