Keeping your data from Apple is harder than expected
aalto.fi
aalto.fi
At present, this must be done individually for every app, https://www.imore.com/how-stop-siri-learning-how-you-use-app.... When you later install new apps after setting up the device, you have to remember to go into Settings and opt-out again, for every app, forever.
How many people know that iOS devices will default to Siri reading plaintext for all apps, including E2EE messengers?
Edit: Turns out — you can't! See the reply below.
The user is given the option to enable or not enable Siri, Apple's virtual assistant. But enabling only refers to whether you use Siri's voice control. Siri collects data in the background from other apps you use, regardless of your choice, unless you understand how to go into the settings and specifically change that,’ says Lindqvist.Now imagining a EULA for Helpful Pre-Stalking..
If I enable some personal assistant at some point in time, I absolutely do expect it to start with no memory.
Apple fights you from disabling Siri as much as they can. I've tried to disable Siri multiple times, but it turns off other unrelated features/services, so it's basically impossible.
For example, if you're using CarPlay, it's required that Siri is enabled, even if you don't use the voice controls.
“The user is given the option to enable or not enable Siri, Apple's virtual assistant. But enabling only refers to whether you use Siri's voice control. Siri collects data in the background from other apps you use, regardless of your choice, unless you understand how to go into the settings and specifically change that”.
[0] https://support.apple.com/guide/iphone/about-siri-suggestion...
[1] https://www.apple.com/legal/privacy/data/en/siri-suggestions...
[2] https://support.apple.com/guide/iphone/tell-siri-about-yours...
I just don't turn it on and so never use it.
I drive a 2003 Golf: there is no Car Play.
These days the voice part is just a UI mode. I use it on my watch and occasionally on my phone when I am wearing earbuds and my phone is in my pocket, but have it disabled on my Mac.
Siri is worse than Cortana in this respect…
Thanks, learnt something new! (It stands for Do What I Mean).
Interesting pages:
1: https://en.wikipedia.org/wiki/DWIM 2: https://en.wikipedia.org/wiki/Principle_of_least_astonishmen...
"It's not the customer's job to know what they want" -- Steve Jobs
Is there more on what Siri "learn from app" actually does? Does it scrape entire screen contents? Or just metadata? Or only what the app developer decides to send?
https://developer.apple.com/documentation/foundation/nsusera...
You can.
Use the free Apple Configurator tool to generate a profile that has:
- "Allow Siri" unchecked
- "Allow Siri Suggestions" unchecked
Apple Configuratior is great. You can disable all sorts of things, e.g. iCloud access.If your iPhone is on $org MDM, you can do the same on MDM.
Maybe there is a subset of things you can do?
Isn’t that what “guided access” is for?
Guided access is finicky and the failure modes are extremely bad for preventing random people from accessing things they shouldn’t.
Huh ? Its available freely via the App Store.
No restrictions whatsoever on who may download and use it.
I can only think it must be something specific to your setup.
Looking at the version I presently have installed, there is an Account menu and it says "sign in...", so I'm clearly not signed in.
Managed Apple ID seems to be some sort of MDM-style thing[1] , I've certainly never done that and no idea how it works ! I have always just used Apple Configurator in plain-vanilla mode.
[1] https://support.apple.com/guide/deployment/managed-apple-ids...
These companies are all fundamentally similar in that their proprietary software collects an insane amount of data that will end up in the hands of your enemies either by sale, court order, or security compromise.
It is relatively easy to opt out of all of these companies and take some actual control over your privacy.
YOLO mallocs most operating systems ship allow an application to -feel- faster and more stable at the expense of security.
If you want software to be stable in a strict malloc environment, write it in rust :)
To be fair though, LineageOS security is actually terrible. Do not use it. If you must have an Android device CalyxOS is the least bad option today.
I have not carried a phone in 3+ years. In spite of what some would have you believe, it is actually relatively easy to live an active and socially engaged life in the modern world without a phone.
Major mental health wins from being offline when you are away from your desk too.
Right? This is completely anecdotal, but I've occasionally seen people lament, "You have to bank, as well as manage health and travel stuff on your phone". My follow up is always, "What can I do with those apps on my phone that I can't do via a laptop or desktop?" I am typically met with silence.
Seriously - beyond SMS 2FA, there's nothing I can do on my phone that I can't do on my desktop, and I sure as hell don't need to have constant access to all of that when I'm out and about.
* by-and-large
Apple is above all else a data driven marketing and advertising firm just like Google and Meta. They are profitable because they are effective at using data to change user purchasing behavior.
it wouldn't surprise me if Apple started ramping up their data revenue in the near future to compensate
the services revenue is at an all time high and keeps climbing:
https://www.statista.com/chart/amp/14629/apple-services-reve...
re. app store, the EU market represents just 7% of their worldwide app store revenues, most probably due to the fact the EU market is 65% android:
https://techcrunch.com/2024/02/01/apple-says-eu-represents-7...
https://www.statista.com/statistics/639928/market-share-mobi....
I know the US govt is hitting them with a similar anti-trust lawsuit, so it might happen over there too
If Apple lose their walled garden, and the 30/15% cut with it, both in EU and US, I think that could be a massive problem for them
Whether or not that will actually happen, or if Apple will find a way to compensate for the lost revenue, I don't know. I wouldn't be surprised if it was causing big discussions inside the company though, and I wouldn't be surprised if people become more bearish on Apple until they show they've found a solution
This could be fantasy talking. How does the walled garden around Steam affect their 30% cut? Oh, there is no wall, and it's... 30%.
So wait, if non-walled-garden stores cost 30% in an open market -- are we sure this is going to work out getting to use the world's most valuable app store shelf space for free?
It doesn't work that way at Walmart...
If Apple wants to be Steam, let them play Steam's game and see how far their philosophy takes them.
Steam isn't both the OS manufacturer and the sole vendor of games on PC, unlike Apple and iOS
I can release a game for PC or macOS and never pay Steam or Apple a dime, can't say the same for iOS
I just want the company to keep my data private from other commercial players. Like don’t sell all my data to anyone who asks or use it to create an invasive model to then advertise/manipulate me.
I think it is reasonable to say that Apple is better on that front than Meta or Google.
17 necessary cookies
7 functional
34 statistics
49 marketing
10 unclassified
This kind of thing makes the article seem... ridiculous, really. Their site is much worse at privacy than Apple.I don't know why you would judge the content of the article based on that, rather than its own merits, particularly given that the subject of the article isn't the security of web pages or cookies. If anything, what the article does discuss has far more egregious security implications than website cookies.
And anyway if you want to see tracking cookies with a browse you only have to use Option + ⌘ + J (on macOS), or Shift + CTRL + J (on Windows/Linux). Easy. It is much more difficult to see if you are being tracked and what data is being tracked and how it is being used on your mac or iphone.
As for privacy I don't know any major vendor that is privacy-focused. Not only is it a hard technical problem to solve, it's also leaving money on the table. I don't see things changing any time soon.
Where does it do that? It explicitly doesn’t compare Apple’s products with other products:
“Lindqvist can’t comment directly on how Google's Android works in similar respects, as no one has yet done a similar mapping of its apps.”
Also, IMO the post is flame-bait in saying “Keeping your data from Apple is harder than expected”. AFAICT, the paper (https://acris.aalto.fi/ws/portalfiles/portal/141787684/Priva...) is not about Apple breaking privacy at all; it solely is about the difficulty of the UI for various privacy settings and of user understanding of what settings do.
They don’t claim, for example, that Apple makes these settings so convoluted to confuse or wear down users so that they close down less stuff (they may or may not, but the paper doesn’t discuss it)
> The requirement to offer a 'Reject All' button next to an 'Accept All' button follows indirectly from the consent requirements in the GDPR; consent must be as easy to revoke as it is to give.
https://www.dataguidance.com/opinion/eu-cookie-banners-and-u...
If you're arguing for more privacy but you're participating in removing privacy, why isn't that hypocritical and makes the argument for privacy weaker from that person?
I agree that it's off-topic to the discussion as a whole, for this particular submission, as it doesn't argue against the content of the article but rather talks about how the content is hosted.
If someone writes that it is healthier to stop smoking, but then someone finds out that the author is a heavy smoker, does that make smoking somehow ok?
It is only a matter of time before courts realize this.
The CCP controls the Apple software signing HSMs in China for a reason.
Of course that's always a threat with any computer, but you must place some amount of trust somewhere.
So even then they would have no data before that point!
Personally I only use reproducibly built FOSS software and I isolate most of my hardware and workloads from each other with virtual machines via QubesOS.
Proprietary software is not at all required to be well integrated into modern society.
you must place some amount of trust somewhere.
Using something and trusting it are different things.Since they call it out in the article as well, I really want to understand the "fragility of the privacy protections" on TouchID.
1. Realise the Apple hard- and software I'm using sucks privacy wise
2. Compare open source alternatives, maybe switch (I have an iPhone and a Fairphone 4 with /e/OS, also a MacBook and a homebrew Linux PC) with a file- and photo export through my NAS.
3. Use the FOSS ecosystem for a bit, be annoyed at some jank, slowly realise that while unquestionably better privacy wise, it's not necessarily better security wise.
4. Miss real life document management (I scan files, apply OCR). MacOS/Spotlight makes it possible to treat my collection as a database rather than a file cabinet that way, Continuity makes it easy to scan.
5. Switch back, rinse and repeat.
I'm driving myself insane. It's always either feeling great about my privacy and sacrifice convenience (I mean, FOSS can probably host that same workflow, it's just that it's a lot more work up front and I'm the one responsible if it breaks) or feeling great about how my stuff works but feeling creeped out about being spied on.
Sigh. People who live in glass houses, etc.
Are they're any ROMs that do?
Every app you install with Play Store pops up and asks if you want to grant it networking. It's cool
Otherwise it's not surprising at all.
Of course he can't, because its easier to jump on the Apple bashing bandwagon.
I suspect if you did a side-by-side comparison, we all know where Android would fall on the privacy spectrum.
Give me Apple over Google any day of the week.
I expected better from Lindqvist than take part in a biased article like that.
Rather than just assume everything is fine, it's important to call out deficiencies. Especially when someone is seen as the best at something.
Being the best doesn't mean you are good. It just means everyone else is worse.
I downloaded a shitty freemium mobile game once and now 80% of my Instagram ads have been ads for shitty mobile games for more than a year. Is this really the best the 500k+ a year ad magicians at Meta came up with? Is this what gives Meta its trillion market cap? Just like Amazon serving me ads for washing machines, right after I bought one. And Google Maps promoting shitty restaurants and services I don't want to go to. Is this the cake apple wants a share of?
I can't wrap my head around data collection.
Counterintuitive, but there’s a chance that the one you bought didn’t work out - and that’s high enough to make you much more likely than the general population to buy a washing machine.
Consider: in the past 20 years there have been about two weeks (total) where an ad for a washing machine could be relevant. That’s about 0.2% of the time. If the RMA rate for new appliances is higher than .2%, that’s a useful bit of targeting information.
Amazon knows if the one I bought worked out or not because I RMAd it or didn't; yet, every time I buy something, I'm inundated with suggestions for the same thing until I've searched or bought a sufficient number of other things, to replace them, and the cycle begins again.
Don't get me wrong, they have some fairly decent suggestions based on the things I browse and purchase, or browse and didn't purchase, but showing me dozens of things like the thing I just bought is hilarious.
To imagine that Amazon hasn't data scienced this out, to completion, is absurd.
It's like if you open YouTube in incognito. It will show you whatever clickbait is most likely to catch an "average" YouTube-user from your country. It's wildly different from what you are seeing signed-in.
In other words, the company paying for the ad wants you to see the ad. For some reason they think you might buy the product. Why would Google tell them "no" if they're offering money for that?
To millions of small business they are the only viable way to reach their customers.
As tech focussed people we often ignore this or play it down. Facebook (as it’s the most used example) being blocked in a country or region (EU for example) would be devastating thousands/tens of thousands of businesses.
The usual reply is “those businesses shouldn’t be so reliant Facebook etc” which misses the point that these business only have a viable route to market thanks to these platforms.
Some of the most useful things I have bought have been thanks to “shitty Facebook and Instagram ads” including home gym equipment I use daily, DIY and wood working products, kitchen utensils, etc
You've stated this as a fact but small businesses thrived before Facebook, so I think it's fair to assume they'll thrive after Facebook is long gone, absent other evidence.
The only type of business I genuinely see suffering are those who advertise crap dropshipped from Alibaba that nobody is looking for organically, sold at 2000% markups, and that would be a good riddance.
The unit economics have totally changed though as there are many more businesses that exist now that simply could not have done in the old model.
The previous company I started was a direct to consumer UK heating product. In the old world we would have had to go through big shed retailers and lost 50-60% margin with 90 to 180 day payment terms and would have had to stock all of their stores from day one. The expense would have stopped that business from ever being started.
With digital platform advertising we could specifically reach our target demographic, loose only 20% margin to customer acquisition and postage costs (so afford to start with smaller manufacturing runs), get paid the day we sold the unit so cash flow positive, hold much less stock and order from our suppliers in response to demand and run our own just in time factory.
The business was much smaller that it would have had to be in the previous world, much less risky and, frankly, only viable thanks to very targeted advertising that allowed us to tell our potential customers about our product when they most needed it.
In this kind of discussion people seem to assume the product spectrum is binary. It's either useful and so would thrive regardless of advertising or useless tat that only exists thanks to digital platform marketing.
That just isn't the case, sure - those ends of the spectrum exist but there is a vast array of businesses in the middle that could not have existing in the old world and aren't useless drop shipped tat.
In this day and age this should be read as "To millions of dropship vendors". And no, I don't want to see their scammy ads either.
I find local small businesses through Reddit or google maps. Never have I encountered an ad for one in the wild.
Putting your eggs in one basket is never a good idea.
That aside, in practice the main people who benefit from GAFAM ads are Alibaba/AliExpress dropship sellers in my experience. Just take a generic piece of product, slap your own label on it and that's a new listing. Had to buy a PC keyboard recently and the search results are just littered with that crap. I don't think you'll find many people shed tears for that crap going bankrupt, it just clogs out actual legit small businesses.
You're totally right but that's the reality for many small businesses. One big route to market props up the whole business.
> are Alibaba/AliExpress dropship sellers in my experience
Possibly making an unfair assumption but I suspect your experience is quite limited then. I know many very legit web first businesses with great products, developed in house or a proper license importers of great products who rely extensively on the GAFAM ad complex.
After Microsoft bought Skype, they changed it from p2p to centralized, so all calls were routed through NSA PRISM. This also had the result of making calls laggier and worse quality.
I think there might be a bit of that sort of thing going on in other places too.
Edit: Extraordinary claims require ... 30 seconds of Googling, apparently:
https://en.m.wikipedia.org/wiki/Skype_protocol#Peer-to-peer_...
Whoever compiles these binary blobs, and the OS images themselves, and anyone capable of coercing them, has god access to your device.
I suggest getting to know someone before giving them that much power over your life.
I think everyone knows that a good part of the Apple app ecosystem relies on syncing data. I don't think anyone is surprised that a daemon is syncing your photos between your devices/cloud. Add podcasts, ePubs, etc. and you're going to have a busy network on your device. It's a reason in fact I use the cloud, sign in with my Apple ID. I can lose my machine but not my documents.
Maybe the thing that is more along the lines of what you're suggesting though is the network traffic that is seemingly less useful to the user (but useful to Apple). Various frameworks have appeared on the OS that allow apps to share analytics (pretty sure though these are the analytics that you are asked if you want to opt out of on an install/setup).
But because it has become so easy to do (in part because there is a framework to handle it, but also just the ubiquity of the presence of a network) lots of, I think, dumb data is collected to no doubt satisfy management/design as to whether some feature of an app is being used or is not being discovered.
The ubiquity as I say has made it too darn tempting for all parties (Apple and 3rd) to become lazy about how their apps are being used and to become too data hungry themselves.
I had someone recently ask me how I get feedback from my blog posts since there is no comment section, no analytics .... they wondered why I bother blogging at all.
You can also see this just by running an iOS simulator with Xcode on a Mac that has Little Snitch installed. The amount of phoning home by iOS (and macOS, for that matter) is shocking.
I have not carried a phone or an Google/Apple controlled device in 3+ years and exclusively use FOSS on a personal basis.
I live in Silicon Valley, run a b2b tech company, have a huge group of local friends, and have never been excluded from anything I wanted in my life for not having a phone.
Paper menus are available if you ask, sms can be converted to VoIP, you do not need Genie Plus to navigate Disney, there is always a way to pay with cash (or cash purchases gift card), paper tickets still work fine everywhere, your bank actually cannot force you to use an app, and internet comments and notifications can wait until you are back home at your desk.
Sure, it is a bit like having a dietary restriction, but it is not the life fulfillment blocker everyone makes you think it is.
Also some stuff for work is mobile-only. We have a stupid 2FA system that only works with a mobile app (the company gives us a phone but it does mean being tracked), and the same with the desk booking (I absolutely hate the office since we implemented flexdesks).
Cash is still common here yeah though I don't like dealing with it. I wish there was a mobile payment method that didn't rely on Apple or Google.
Both can be bridged to Matrix, which can be accessed with any OS you like with FOSS software.
> Tickets can go on paper yeah, though some restaurants I visit don't do paper menus (especially the asian ones).
Many have said this to me initially, until I insist I do not own a cell phone. Then they always find a way to produce a tablet for me, or hastily print a screenshot from a phone, or find an old paper menu and cross out some old prices. When I go back to those restaurants later they sometimes have paper menus more readily available, because they were embarrassed the first time for being unable to accommodate a paying customer.
After all, even people who do have phones, end up with dead batteries. People with dead phone batteries need to eat too
> Also some stuff for work is mobile-only. We have a stupid 2FA system that only works with a mobile app (the company gives us a phone but it does mean being tracked), and the same with the desk booking (I absolutely hate the office since we implemented flexdesks).
Almost nothing is truly mobile only. You can run Android applications on QubesOS in a pinch, but more generally I find most 2FA apps actually use TOTP or FIDO under the hood, and can be replaced with open alternatives with a bit of research.
> and the same with the desk booking (I absolutely hate the office since we implemented flexdesks).
I have never seen one of these that does not have a webapp alternative. If they really don't have one, run their app in a VM and sniff the request traffic. Then you can make a simple shell script or webapp to book those desks for you. Open source it to annoy the company into producing their own. Done this sort of thing many times.
> Cash is still common here yeah though I don't like dealing with it. I wish there was a mobile payment method that didn't rely on Apple or Google.
In most countries instead of trying to flag down wait staff to take your card, then wait for them to come back, you can just drop cash on the table and leave at any time. I have not been to Spain specifically though.
Thing is, everything you buy with Google Apple Visa or Mastercard is logged. Everything you buy at the pharmacy is cross referenced from the cash register software and your credit card purchase then sold to insurance companies, etc etc.
Every time you use cash, you are making a small vote against those types of organizations having any more power over the public. Cash can be an annoyance, but it helps take power away from entities who will absolutely use your data to harm people for profit.
I do this. It's great for protecting your location data and select meta-data, but the contents of your conversation are just as vulnerable as ever because the other party might still be using native apps.
Correct, and I do exactly this. But WhatsApp requires a mobile device. It can work without the device turned on, but after a few weeks it will stop working. So you still need to have a phone though you don't need to bring it with you.
iMessage and SMS is totally not a thing at all here. But Telegram is (which doesn't require the mobile app luckily, in fact I really like Telegram despite the lack of end 2 end encryption in regular chats). They allow alternative clients, bots, and their paid plans are cheap enough and offer some features that are genuinely cool and useful. I use it most of the time with local people here instead of whatsapp, I only use that with the few people that don't have telegram.
I'm just mentioning this because in the US telegram appears to have a bad rep somehow. But to me it's one of the services that's the least trying to enshittify. Even Signal I don't use because it's just not terribly useful the way they implemented it.
> Almost nothing is truly mobile only. You can run Android applications on QubesOS in a pinch, but more generally I find most 2FA apps actually use TOTP or FIDO under the hood, and can be replaced with open alternatives with a bit of research.
That won't work. My work requires MDM management of the mobile device for accessing work stuff. And the 2FA app is unfortunately not TOTP or FIDO.
And I agree with you on the cash part yes.
Y'know, a regular salt-of-the-earth type guy
I am accustomed to life without a smartphone because I could not afford one until my mid 20s and only had a laptop because of a $200 Black Friday sale I waited in line 3 days for.
Keep making assumptions about others though.
If there are really no humans at all I would just park further or sometimes just park anyway and risk 1/3 chance I get a $20 ticket once in a while I can then pay online without an app. Sometimes paying occasional tickets instead of using the app can actually save you money.
They don't clamp where you are?
Here in Europe you will usually get clamped and have to wait for them to come out to release it and pay a 100 euro fine.
City parking they clamp, but those have appless payment always.
Also c'mon let's not compare two radically different things now.
They do get to think. Ergo it's only an excuse/defense.
If you don't care then it's all good.
What made you think it is shared with advertisers?
Everything is local only, except:
- when opted in to send diagnostics and performance analytics (to Apple for first party apps and OS, to app developers for third party apps):
> None of the collected information identifies you personally. Personal data is not logged at all, is subject to privacy preserving techniques such as differential privacy, or is removed from any reports before they’re sent to Apple.
> If you agree to send Analytics information to Apple from multiple devices that use the same iCloud account, we may correlate some usage data about Apple apps across those devices by syncing using end-to-end encryption. We do this in a manner that does not identify you to Apple.
- when searching for or suggesting information that's on the web, but none of it is ever linked to the user in any way:
> When you use Siri Suggestions, Look Up and Visual Look Up, when you type in Search, Safari search and #images search in Messages, or when you invoke Spotlight, limited information will be sent to Apple to provide up-to-date suggestions. Any information sent to Apple does not identify you, and is associated with a 15-minute random, rotating, device-generated identifier. This information may include location, topics of interest (for example, cooking or football), your search queries, including visual search queries, contextual information related to your search queries, suggestions you have selected, apps you use, and related device usage data. This information does not include search results that show files or content on your device. If you subscribe to music or video subscription services, the names of these services and the type of subscription may be sent to Apple. Your account name, number and password will not be sent to Apple.
> This information is used to process your request and provide more relevant suggestions and search results, and is not linked to your Apple ID, email address or other data Apple may have from your use of other Apple services.
> Aggregated information may be used to improve other Apple products and services. Common search queries may be shared with a web search engine to improve search results.
(emphasis mine)
One could argue that there's enough bits of data to deanonymise after the fact, but differential privacy should prevent that to a large extent.
There are also toggles to disable all of that, with possible improvements to usability:
- Some onboarding opt-in/out questions could definitely be improved (e.g the "Ask Siri" onboarding question should either cover all of Siri-the-voice-assistant, Siri-but-actually-Spotlight and Siri-the-suggestion-assistant-that-hints-at-actions-based-on-content-and-behaviour, or be split in three).
- Some grand-master "disallow the OS to see ANYTHING" switch seems to be requested by the most ardent "privacy minded" crowd. I'd argue that at this stage it's more about "privacy paranoid" and/or "security minded" (which I can very much be sympathetic to), because it's not a matter of privacy here since none of the above is privacy challenging: Apple itself does not see anyone's data, and the few search queries it can is entirely unlinked to anyone's id. But then again if you don't trust the locally-processing OS made by Apple (which is going to have access to data anyway because it handles the filesystem and app processes) then I have a surprise: the CPU made by Apple is seeing your data as well.
Other than basic information at set-up time, I don't see any indication that the collected info leaves the device
The word "privacy" in modern sense has been twisted to mean anonymous. So any data collection in absolute terms is an invasion of Privacy. Hence the confusion.
The word "privacy" in Apple sense was that only they can collect information about you. But not any other third party without permissions. And those permission are guided by both user interest and obviously their business interest.
The word "privacy" where data collected about you are randomised and profiled you to certain category of interest will be an invasion of privacy depending on which company is doing it. For Google with their replacement of Cookies it is absolutely wrong. For Apple they are protecting their customer.
Is it pseudonymized? No
Is it fully anonymized? No
Is the user given transparent information about which data is collected, how it is used, for which purposes? No
Is the user given the choice to object to the usage of that data? No
You can't have privacy with this pattern of responses.
A device you own is collecting and using data that pertain to your personal sphere, in ways defined by a vendor, and that you do not understand or control.
From that premise, you cannot hop to the conclusion that the data does not leave the device, because the entity deciding how the data is used is not telling you how the data is used.
That doesn't sound like anyone's definition of privacy outside of Apple. Are you positive you think this defintion isn't twisted ?
> The researchers studied eight apps: Safari, Siri, Family Sharing, iMessage, FaceTime, Location Services, Find My and Touch ID. They collected all publicly available privacy-related information on these apps...
> The fragility of the privacy protections surprised even the researchers.
Reaction: Either their "surprise" was purely theatrical (or journalistic gloss), or else Aalto U. needs to replace them with competent researchers. Just like a policeman who doesn't believe that anyone could really be a criminal, or a doctor who finds it unimaginable that autoimmune diseases could actually occur, or ...
Do you view "university researcher" as pretty-prestigious & cool social status tier - which is provided "because they deserve it", for people who spend years grinding their way up an academic XP ladder?
Or do you see "university researcher" as expense which the public pays, because it expects considerable public benefit from the supposedly-highly-skilled work which the researcher does?
Complex dark patterns, default-to-share, users who just keep clinking Yes, and relentless monetization of user information have been routine & well-known things for quite a few years now.
> Complex dark patterns etc.. have been routine & well-known things for quite a few years now.
That doesn't put some kind of ban on experts being surprised.
Otherwise we would be discrediting a lot of climate researchers when they are surprised that things are progressing faster than expected.
- Predict that a gigacorp, which has been lucratively monetizing user information at gigascale for many years, would prove to be darn good at protecting its sources of user information. In a world where dark patterns, incomprehensible T&C's, "just say yes" user behavior, corporate misdeeds, etc. have been well-known things for many, many years.
and
- Predict the future of the planet's climate years ahead, when state-of-the-art weather forecasting can't yet manage 2 weeks.
(Admitting that I can see a good climate researcher using "surprised" very frequently - both for public consumption, and to summarize "our very-advanced-but-usually-wrong model was wrong yet again".)
Being a software engineer / computer researcher / highly technical person (which puts them / us in a technical competent bubble), it might have been an actual surprise that zero participants managed to perform the task successfully. Add to that that they might have sourced participants from the student community in a technical university, and I don't see why their surprise is "theatrical"
Edit: As expected, quoting the original article: "The participants were recruited using the following methods: (1) posts on the university’s official LinkedIn page and (...)
Participants represented a wide variety of educational and professional backgrounds, including Computer Science and IT, Architecture, Business Administration, Art and Design, Industrial Engineering, Economics, Research and Development, and unemployed participants (...)"