HNHacker News
TopNewBestAskShowJobs

scratchyone

307 karma · joined March 22, 2016

submissionscomments
scratchyone··on Apple Photos phones home on iOS 18 and macOS 15
Honestly I'm a little tired so I'm not gonna completely/perfectly address everything you said here but

> If they know some people will be against the feature, why not ask instead of enabling it for them?

Honestly I would just say this is because you can only ask so many things. This is a hard to explain feature, and at some point you have to draw a line on what you should and shouldn't ask for consent on. For many people, the default reaction to a cookie popup is to hit "accept" without reading because they see so many of them. Consent fatigue is a privacy risk too. Curious where you'd choose to draw the line?

> Do you really not see how this is not a good faith comparison? I'm not going to address this.

Yes, my point is that your reasoning isn't good faith either. We both know it's silly and a bit conspiratorial to imply that Apple adding a setting for it means they know a feature is secretly bad. If they wanted to hide this from us, neither of us would be talking about it right now because we wouldn't know it existed.

> We all just learned about today! We don't even need to speculate about whether it is impractical, we know it can't be done, and that's before we consider that loss of privacy and agency over devices is a death-by-a-thousand-cuts situation.

That's fair, but there's honestly no perfect answer here. Either you appease the HN crowd on every feature but overwhelm most non-technical users with too many popups to the point they start automatically hitting "yes" without reading them, or you make features that you truly consider to be completely private opt-out but upset a small subset of users who have extremely strict privacy goals.

How do you choose where that dividing line is? Obviously you can't ask consent for every single feature on your phone, so at some point you have to decide where the line between privacy and consent fatigue is. IMO, if a feature is genuinely cryptographically secure and doesn't reveal any private data, it probably should be opt-out to avoid overwhelming the general public.

Also, how would you phrase the consent popup for this feature? Remember that it has to be accurate, be understandable to the majority of the US population, and correct state the privacy risks and benefits. That's really hard to do correctly, especially given "21 percent of adults in the United States (about 43 million) fall into the illiterate/functionally illiterate category"[0].

[0] https://www.libraryjournal.com/story/How-Serious-Is-Americas...

scratchyone··on Apple Photos phones home on iOS 18 and macOS 15
Yeah this seems to be on by default for me as well, I definitely take issue with that.
scratchyone··on Apple Photos phones home on iOS 18 and macOS 15
If you read the research you'd know that they don't have access to the vector either. They never decrypt the data. All operations on their server are done directly on the encrypted data. They get 0 information about your photos. They cannot even see which landmark your vector was closest to.
scratchyone··on Apple Photos phones home on iOS 18 and macOS 15
Okay except "encrypted, low-resolution copy of your photos" is an incredibly bad explanation of how this feature works. If nobody on HN so far has managed to find an explanation that is both accurate and understandable to the average consumer, any "hey can we do this" prompt for this feature is essentially useless anyways. And, IMO, unnecessary since it is theoretically 100% cryptographically secure.
scratchyone··on Apple Photos phones home on iOS 18 and macOS 15
I'm sure you know that the point of that billboard is to state that your iPhone protects your privacy. That is generally true, Apple is by far the most privacy-focused major phone and software company. Advertising isn't literal, if we're going to be pedantic here the photons emitted by your iPhone's screen technically leave your iPhone and definitely contain private information.
scratchyone··on Apple Photos phones home on iOS 18 and macOS 15
Fundamentally, vector search like this doesn't have a concept of something "matching" or "not matching". It's just a cosine similarity value. To determine if an image "matches", you have to check if that similarity is within some given threshold. If the results of the cosine similarity operation are encrypted (they are with HE), that wouldn't be possible to determine.

The bigger privacy risk would be that the device routes the request to a specific database shard based on whichever has a center-point closest to the image embedding on the device. They take steps to protect this information such as third-party proxying to hide user IP addresses, as well as having devices send fake requests so that the server cannot tell which are real user data and which are fake data.

scratchyone··on Apple Photos phones home on iOS 18 and macOS 15
If they sent a completely randomly generated integer from your phone without consent, would that be okay with you? Genuine question.
scratchyone··on Apple Photos phones home on iOS 18 and macOS 15
> I'd also like to ask a different question: if there's no reason to ever worry about this feature, then why is there even an option to turn it off in the first place?

I mean for one, because of people like you that are concerned about it. Apple wants you to have the choice if you are against this feature. It's silly to try to use that as some sort of proof that the feature isn't safe.

My iPhone has a button to disable the flash in the camera app. Does that imply that somehow using the camera flash is dangerous and Apple is trying to hide the truth from us all? Obviously not, it simply means that sometimes you may not want to use the flash.

They likely chose to make it opt-out because their research shows that this is truly completely private, including being secure against future post-quantum attacks.

> If an adversary is able to intercept encrypted communications, they can store it in hopes of decrypting it in the future in the event that a feasible attack against the cryptosystem emerges. I don't know how likely this is to happen against homomorphic encryption schemes, but the answer is not zero.

Also, if you're going to wildly speculate like this it is at least (IMO) worth reading the research press release since it does answer many of the questions you've posed here[0].

> it's pretty upsetting that it's becoming incredibly hard to the point of being nearly impractical to get modern devices to behave this way and not just fling data around all over the place willy-nilly.

And honestly, is turning off a single option in settings truly impractical? Yes, it's opt-out, but that's because their research shows that this is a safe feature. Not every feature needs to be disabled by default. If most users will want something turned on, it should probably be on by default unless there's a very strong reason not to. Otherwise, every single iPhone update would come with a 30 question quiz where you have to pick and choose which new features you want. Is that a reasonable standard for the majority of non tech-savvy iPhone users?

Additionally, the entire purpose of a phone is to send data places. It has Wi-Fi, Bluetooth, and Cellular for a reason. It's a bit absurd to suggest that phones should never send any data anywhere. It's simply a question of what data should and should not be sent.

[0] https://machinelearning.apple.com/research/homomorphic-encry...

scratchyone··on UK's Online Safety Act comes into force
> Hash-matching tools link known images of CSAM from police databases to encrypted digital fingerprints known as “hashes” for each piece of content to help social media sites’ automated filtering systems recognize and remove them.

I know this is a little bit of a nitpick, but I really feel like it hurts the credibility of a news organization to make a mistake this obvious that also shows they completely misunderstand the entire concept they're explaining.

That's fundamentally a wrong definition and implies that that these social media sites could simply decrypt the hash to access the source material. The entire purpose of hashing as a cryptographic tool is that it isn't encryption.

scratchyone··on Worldtimeapp.com Easy Timezone Converter
yeah i second this, worldtimebuddy is incredible for pretty much all timezone related stuff
scratchyone··on Something weird is happening with LLMs and chess
?? why would openai even want to secretly embed chess function calling into an incredibly old model? if they wanted to trick people into thinking their models are super good at chess why wouldn't they just do that to gpt-4o?
scratchyone··on Show HN: I launched a super cheap and simple to use OCR tool for macOS
This looks wonderful! Just a small heads up, you have a meta tag listing @marc_louvion as the creator (assuming this landing page is built on one of his templates?). I figure you may want to update that so it has your info instead.

  <meta name="twitter:creator" content="@marc_louvion">
scratchyone··on ChatGPT Search
it seems absolutely wonderful for searches that require multiple steps. for example “i want chinese food near me that will be open tomorrow, takes reservations, and has lo mein and will work for my group of two. i want as close as possible if i can but also let me know what reviews say”

my search skills are good but either way that requires 3+ searches and visiting the menu of each restaurant and checking their hours and reservation. remains to be seen if chatgpt search is consistently good at this though

scratchyone··on Show HN: Repaint – a WebGL based website builder
This is incredibly impressive engineering and a wonderful UI! As a dev, I would have to agree with some of the other comments here about access to generated code. I'd definitely suggest this to non-tech friends but I wouldn't see much of a use for it personally without code output.

I was curious what your plans are for code output in the future, have you considered some kind of React integration? If this tool had Storybook-style codebase integration I would 100% pay for a subscription. For example, being able to export the website design as a React project with organized components, allow me to modify the component code to customize behavior, and continue to iterate on the design and apply changes to my codebase?

I think an important thing for me would be to have the ability to continue to modify the design after exporting and be able to apply the design changes without having to lose my code changes.

Obviously just my personal preference so take that with a grain of salt, but I know with that feature this would completely replace Figma in my workflow and would definitely be worth paying for.

Congratulations on your launch!

scratchyone··on ChatGPT can flag comments for review if you ask politely
this is so clearly a model hallucination, this doesn’t really show anything whatsoever
scratchyone··on Ollama is now available on Windows in preview
Out of curiosity, what're you using the fine-tunes for? Do you fine-tune them on your own data or are they just publicly available models you use for different tasks?
scratchyone··on OpenAI Status: Multiple engines are down
Why did you comment this 3 separate times?
scratchyone··on Show HN: I made a webapp to help people create flag designs for fun
Yeah this is def the problem, I’m gonna mess with the web history API and see if I can fix that issue.
scratchyone··on Show HN: I made a webapp to help people create flag designs for fun
Thank you! I’ll try it on firefox and see if I can reproduce the issue
scratchyone··on Show HN: I made a webapp to help people create flag designs for fun
I think you might be missing a word there? Everything is too what? Also thank you for the report!
scratchyone··on Show HN: Browserify CDN that supports bundle and standalone
If this is something people might actually use, I'll buy a shorter domain name.
← PreviousPage 4 of 4