What Apple’s Tim Cook Overlooked in His Defense of Privacy
nytimes.com
nytimes.com
The difference in the two approaches (Apple/Google) is HOW it uses the data and the amount of data it collects/has access to.
>> "Mr. Cook also failed to fairly explore the substantial benefits that free, ad-supported services have brought to consumers worldwide."
Of course he didn't explore it - he'd be an idiot to explain to everyone the benefits of the very thing he was trying to say wasn't good.
>> "If Apple really didn’t think that its customers should trade their data for free services, you’d guess that it would build its own ad-free web search engine for its devices."
No you wouldn't. A search engine is difficult to build, expensive to build, and hard to do right. Instead they offer users Google as default (which the majority of people would want) and a more private alternative in DDG.
I could continue going through the article explaining how it is utter rubbish but it should be pretty obvious.
Um, Apple replaced Google Maps with their own Map service which is hard to build, expensive to build and they still haven't gotten it right. Despite that, I want Apple to do the same for search so I can remove Google from my iPhone.
>> "I could continue going through the article explaining how it is utter rubbish but it should be pretty obvious."
This is why Apple fanboys have such a bad reputation on the web and spoil perceptions for those of us who own Apple products without subscribing to the fanaticism. Stop the snark. Respond to the actual argument.
Why would you think that demanding that a hardware company should develop a search engine is a better alternative to companies that have chosen to try and invest in search?
I am totally baffled by this mental leap.
Apple hasn't "replaced" Google maps, except in its own apps. Google Maps still is on the iPhone.
Plus, remember the conflict over Google maps was because Google wanted too much personal information about he users and Apple wasn't comfortable with that. Apple spent a lot of effort to replace something for the purpose of protecting users Privacy. I'm not aware of google ever going thru such extensive efforts (despite the cheap website propagandizing the contrary we saw the day of the WWDC keynote.)
>> "This is why Apple fanboys have such a bad reputation on the web and spoil perceptions for those of us who own Apple products without subscribing to the fanaticism"
I'm tired of this smear from people who hate Apple. For the record, you can stop pretending to own Apple products. You're not going to convince us your somehow objective with this lie. When you smear people defening Apple as "fanatics" then you miss the point that Apple is constantly being attacked.
It is the existence of Apple that you cannot tolerate causing you and your kind to constantly attack Apple, and this has been going on for 40 years.
Mac users just want to be left alone, instead of constantly having to defend against dishonest hit pieces like this article in the NYT.
I try to judge a product not based on who/how many people use it or don't use it, but rather by trying the product itself. Because I realized a few years ago that there were a lot of things that I disliked not because of my dislike for the things themselves, but because of my dislike of the people using that product (whether it being a song, and artist, a movie, a book, an app, hardware, the list goes on). A friend once told me that he hates [it/telling people] that he likes Drake. He does like Drake, he just doesn't like to admit it because idk, media, people that listen it him, etc. If you don't like Drake because of who listens/talks about it rather than because of his music, then you're letting everybody else dictate part of what you're listening to. Isn't that weird ? I think it is.
I never use Google Maps on my iPhone, I only use Apple Maps now. Apple Maps works with Siri and my Apple Watch. Apple Maps is the default. I prefer Apple tracking me instead of Google (home, work locations etc) I want Apple to do the same for search.
>> I'm tired of this smear from people who hate Apple. For the record, you can stop pretending to own Apple products. You're not going to convince us your somehow objective with this lie. When you smear people defening Apple as "fanatics" then you miss the point that Apple is constantly being attacked. It is the existence of Apple that you cannot tolerate causing you and your kind to constantly attack Apple, and this has been going on for 40 years. Mac users just want to be left alone, instead of constantly having to defend against dishonest hit pieces like this article in the NYT.
What smear? This paranoia is what I don't like about Apple fan community. I'm not even criticising Apple and you've already jumped to the conclusion that I hate them and don't own any Apple products. I want Apple to succeed, I prefer their products which is why I want a Google search alternative with better privacy protection. But because I disagreed with a snarky comment you accuse me of being dishonest. Wtf
Please tell us more of your insider information about the negotiations between Google and Apple regarding maps apps for iOS.
from a naive standpoint i would call apple's point hypocrit, from a more cynical I'd call it an attack on the business of a competitor (while using the services provided by the same to empower their own products).
Example : Safari on iOS and OSX defaults to Google for the search engine and Apple collects billions of dollars from Google to make it easy for you to sell your data to Google - the very thing Cook is trying to sell you as evil! Same goes for FB, Twitter and Bing.
Also Apple collects a great deal of data just like others and it is not provably different than others unless you insert irrational faith into the equation.
Umm, what? Did you really not know you can search with Bing on Android? You can also not choose to add a Google account and instead use alternative app store on any Android phone by the way. People user Google services because they like them and find value in them. No different than on ios.
i think the article very clearly states some valid arguments and the user in the parent comment fails to provide arguments countering those.
> No you wouldn't. A search engine is difficult to build, expensive to build, and hard to do right.
DuckDuckGo appear to do pretty well for themselves, running on $3m of funding and with a team of 21 people. I'm guessing Apple invests more in their products' packaging design than that. If their users' privacy were a concern to them, searching in Safari would use Apple's (privacy-conscious) search engine, and (until Apple perfected their search index) pipe in results from Bing/Google/whomever, just as DDG does.
The WWDC session on Search API covered its current uses, and some of the privacy controls they've built into it.
https://support.apple.com/en-us/HT204683 https://developer.apple.com/videos/wwdc/2015/?id=709
My argument, thus, goes as follows: If, as a company, you care about something only so little that you are not willing to invest an hours' worth of profit, you probably don't care about it at all. I don't fault Apple for not caring about privacy. Few companies do. I fault them for posing as caring about privacy when their behaviour clearly demonstrates that they care very little.
1: Yes, Apple's hires won't probably have the same skill set as the DDG team. And yes, scaling a search engine from 9M queries a day to what Apple Search would be hit with would take a fair bit of effort. I'm trying to illustrate a point here, so just bear with me ;-)
The article claims that Apple's privacy policy explicitly says that it can use that information for marketing/advertising. From the article:
the company plainly states in its privacy policy that it does use private data in many ways, including... to build its own advertising network.
That's actually pretty evil. Normally if I turn on "tell X about any runtime errors", I expect there to be pretty strong privacy protections in place. After all, I'm doing them a pretty big favour by donating (an admittedly tiny amount of) bandwidth and compute resources to their product improvement. The absolute least I expect is to not be shafted in return.
I'm willing to hold my scorn until they start saying "nmrm2's Mac has never crashed!" without clearing it or compensating you.
1. Equates all advertising with invasive data collection. 2. Suggests that improving individual's control over their data is worse than not improving it, or worse, is hypocritical.
For point one Mr. Cook did not vilify ads nor ad supported services. He spoke against invasive data collection. Now what qualifies as invasive is certainly open for reasonable people to debate but his point is that he feels the industry has gone way too far. I read a physical newspaper this mornin with ads in it. A good portion of that paper's income is from ads and the rest through subscription. They did zero data collection on me. I say this only to demonstrate that you can have ad supported business without bein evil. The nytimes author seems to ignore this.
For point two isn't it better that Apple is improving privacy protections rather than just throwing up its hands and instead joining google in attempting to learn everything about us and the sell access to put data to advertisers who have their own best interests in mind rather than ours? Why is building a more private maps application but still enabling google searches better than not providing a map application?
In short I think it is very possible to run an ethical ad based business. Unfortunately in Silicon Valley we've adopted a default business model of grabbing as much personal information and selling it to the highest bidder rather than offering a great service with non-invasive ads or subscriptions. If Slack can do it why can't others?
- a USB condom is not a solution, it only prevents power sources using data channels. Data devices, which you still might want to use occasionally, are even more likely to be compromised. Plus, it does nothing if the attacker has physical access to the machine.
Of course it is not a perfect solution, but (like a real condom) it is a partial solution to the infection problem that is effective and not very burdensome. Charging is a major mode of vulnerability to USB attacks, quite likely the single biggest. And compared to the big, multi-sided task of redesigning USB and the systems around it, providing a USB condom for charging is cheap and straightforward.
> "apparent" - you don't know what they're doing about this on the inside.
Yes, this is why I used that qualifier. However, for a variety of reasons it does not seem probable that they happen to be preparing a big push on this issue internally.
Actually, Apple has shown foresight in its hardware selection, as they have consistently selected Intel processors with Vt-d/IOMMU support (to this day, it remains difficult to find IOMMU-enabled notebook computers). This has allowed OSX to isolate Thunderbolt and neuter attacks: http://ilostmynotes.blogspot.com/2014/11/thunderbolt-dma-att...
Possibly a similar thing might be done for USB controllers as well...
You're correct in that it's not an Apple-only security issue. I'm not sure if the person you're replying to meant to imply that. However, Apple has never been particularly concerned with pointing out security vulnerabilities. Up until three years ago they were claiming that OSX didn't get viruses and that you could be safe by doing nothing. (http://www.theatlantic.com/technology/archive/2012/06/its-of...) That's why Apple gets a lot of flak from security-oriented folk. They mislead tons of people into thinking that "Macs don't get viruses". And I still hear self-proclaimed geniuses who tell me this, and why it's the reason they'll only use Apple products.
Considering Apple changed their slogan to "built to be safe" after being heavily compromised and criticized by the media, they do deserve a push to take care of hardware security issues by default. After all, security is built in, right? Shouldn't they make some proactive security efforts after advertising to their users repeatedly with the premise that their users shouldn't care about security?
> Actually, Apple has shown foresight in its hardware selection
That link you share came around four years after OSX (and Windows) had the login screen compromised with Firewire hacking devices (http://www.hermann-uwe.de/blog/physical-memory-attacks-via-f...). Of which Apple was the primary vendor involved in pushing the standard. Not only that, it's talking about more modern devices being secure from an exploit that was used to compromise early Thunderbolt-enabled computers roughly two-and-a-half years prior (http://www.breaknenter.org/2012/02/adventures-with-daisy-in-... and http://www.breaknenter.org/projects/inception/). The fact that Apple started utilizing IOMMU to counter DMA attacks and moved away from Firewire isn't foresight - it's reactive. Admitted, a good reaction. That's how a lot of security procedures end up. But let's not pretend that they're ahead of the game on security when they aren't.
> Possibly a similar thing might be done for USB controllers as wel
It's been done for USB, Firewire, Thunderbolt, any hotpluggable PCI/PCI-e expansion port/socket (because you can plug the above in unless it's disabled in the OS). Pretty much anything with DMA in it is an issue.
> Plus, you're talking about a security issue that requires physical access to a machine
You're assuming direct malicious intent. Which might be the case for jealous spouses and high-value targets. But a far more likely consumer scenario is handing your USB stick to a friend with a compromised computer to share a file. After he plugs it in, his malware-infested computer overwrites the USB device's firmware as a new attack vector. When you get it back and use it again, your computer becomes infected.
It's not common now, but it's not really that far fetched.
> It's not common now, but it's not really that far fetched.
And as the average USB device becomes "smarter" (or more like an embedded PC, in any case...) in the future I would assume it will become easier to infect without hardware access. (I am not an expert.) Or think of the many thousands of lab and internet-cafe PCs which are already out there and being used as public or semi-public charging points: those can already certainly be compromised without any hardware access. Even attacks using hardware access to a USB device don't have to be ignorably small-scale. A single compromised public USB charging point could hit hundreds of people: one could consider ATM skimming as an advance warning of what is feasible.
And more generally, access to the hardware on the far side of the USB connection is not (in the general case) the same as access to the hardware on the near side. If in practise one is always as good as the other, well that's exactly the bloody problem! And it's a problem with the USB protocol etc., not the inherently-mostly-insoluble problem of direct access to the internals of the user's local machine.
And that’s not all. When I go to Apple’s App Store,
I’m presented with a bevy of free apps that are
supported either in whole or in part by ads.
There are a lot of weird conclusions that this article tries to make. This is the one that strikes me as the dumbest.Its like bemoaning Microsoft (or any OS maker) that allows people to create apps - apps that may or may not use advertising.
Because of this fundamental difference in security, I think it is fair to say that Apple can make a real and authentic claim to caring about user's privacy. I believe under no circumstances should my phone calls or emails be accessible, searchable, or indexed anywhere other than by myself and the people they are distributed to. SMSs ought to be encrypted and be able to be decrypted by myself or the recipient only. These modes of communication are fundamentally different, and apple has the ability to implement these precautions, and I believe they are truly trying to do so. I don't see how it's even a fair comparison to say Apple is hypocritical compared to the social media giants and Google. They offer fundamentally different services, and should be expected to respect privacy on fundamentally different standards. I don't advocate lower bars, I want high bars for everybody. That is why I applaud Tim Cook for making it a point for Apple to adhere to a high standard of privacy protection. I genuinely hope that what he says reflects the true implementation of that policy.
Perhaps we need privacy principles enshrined in our laws, not a benevolent player in the market.
> [...]
> not a benevolent player in the market.
The reason they have this policy today is not because they want to be a benevolent player in the market, but because it has a negligible impact on their business model and it can't be adopted by the competition (Google). I would also argue that that's what prevents them from changing it in the future. It makes perfect sense from a business perspective.
If he's so righteous, let's see him cut back on the prices or lock-in tactics of his devices. I'm betting his whole salary that he's not doing that.
So why rely on market forces for privacy, because for this fight once lost will be hard to win back.
Apple, on the other hand, was fine with lying to customers about security ("immune to malware!"), building leaky clouds, suing those that put Mac OS on cheaper hardware, locking in users with software toolchain choices, keeping low income users out due to high prices, discriminating against competitors in App Store, and even charging for updates. On top of that, despite tens of billions in profit, they also sold customers out to advertisers. They are one of the least trustworthy companies in existence for privacy-conscious individuals.
So, Tim Cook is full of shit. Apple has enough profit to build inherently private/secure OS's, toolchains, and services. This is obvious given that small to midsized firms with a tiny fraction of the money have outdone Apple in many areas of privacy and security by simply putting in effort. Most likely, Tim Cook is merely doing P.R. work to position Apple's image (not reality) as more trustworthy compared to ad-driven services. Those services can't do this because they'd go bankrupt by not invading privacy.
So, let's rehash. Users have more cool and useful stuff than ever before due to ad-driven model. Users got there by repeatedly choosing to be spied on instead of paying or investing time in a private alternative. Apple's past and current track record on privacy/security are terrible. They also do advertising, although not dependent like competition. Apple's CEO says they believe in privacy/security despite them hardly practicing it. Conclusion: our situation is the from users' demand, their massive use of such services maintains our situation, a niche want private alternatives, and Apple is doing PR to make money off those people (while still selling them out).
Capitalism in action! ;)
That does rather imply that such a thing is possible and the entire history of computer science would indicate that it isn't (yet.)
There's dozens of designs doing similar things in academic literature, on the web (see crash-safe.org or Cambrige's CHERI), in government (see Sandia Secure Processor), and even commercial (see CodeSEAL architecture). Yet, the tiniest modifications (pointer/array/code protection) would give attackers considerable headaches. This must be integrated with other security methods, of course, along with toolchains (esp compilers) modified to use it and any custom software (esp assembler) modified to use it. Those changes are well within Apple's budget. They also bought an ARM license and a fab deal, meaning they can do the hardware mod.
At this point, there's no excuse for our machines to be vulnerable to pointer, buffer, or memory-based attacks given 1960's technology was immune to these by design. And we could adopt such methods relatively inexpensive today. And academic prototypes running FreeBSD and Linux only cost a few mil versus Apple's tens of billions available. Yes, it has been done, can be done, and is simply not done as usual.
But the key there is "simple" - I imagine that's a tiny fraction of the size and complexity of a modern smartphone ecosystem. Scaling it up to a device that can be manufactured at a profit and will sell hundreds of millions is surely more involved than "we could adopt such methods relatively inexpensive today".
There's no need to speculate, though. Several academic projects involving a few amateurs with six to seven digit funding have (a) modified processors for security, (b) modified toolchain to support it, and (c) ported BSD/Linux to it. Others did it for embedded systems. Their schemes are usually much more complex (see Cambrige CHERI processor). Unrealistic to think Apple can't do with 9+ digits less than what academics do with 6-7.