HN user

St0n3d

14 karma

h1gh.

Posts1
Comments16
View on HN

“Apple created its own proprietary alternative, NeuralHash, which apparently wasn’t as good. So Apple U-turned on its efforts to scan for CSAM in its cloud storage. Instead, Apple implemented end-to-end encryption for iCloud files.”

Wasn’t Apple’s design to explicitly NOT scan in its cloud storage, but look at the file on-device at the moment you wish to upload it to iCloud? This method would make it compatible with Advanced Data Protection; so ADP could have always been in the pipeline rather than Apple u-turning. In fact, NeuralHash may have been proposed because Apple wanted to introduce ADP and saw a potential problem here/get concerns from government agencies about it and saw this as a means to an end(-to-end).

The system was designed pretty elegantly and offers far better privacy protections - including guardrails - than what Microsoft and Google do, but the communication from Apple about it was absolutely horrible and generated enormous backlash. (Not saying I agreed with implementing it, just saying the design was infinitely better than competitors.)

This will not happen. If Apple complies, it complies. They can’t blame Apple for not following a random EU directive in jurisdictions outside of the EU to begin with. They’re even different legal entities. The EU is not going to do anything about this at all and if they try: it will be blocked. I’ll check back here in 6 months to see how this aged.

That’s also why the EU probably won’t get more strict than this. The climate is very bad for tech companies with increasingly vague and weird laws (that mostly nobody asked for I might add) and this is starting to piss some countries off as they see other continents starting to excel and we can’t catch up due to such insane amounts of red tape.

3.) that’s not exactly true. Currently, you can choose for an open system or a walled garden in which you can’t be de facto blackmailed in to leaving the walled garden. With this so called freedom of choice you mention, I am no longer able to choose for a true walled garden. If I rely on certain apps that are moved to their own store, I am forced to go there and break the walled garden. Ergo: my choice is taken away from me. For completely arbitrary reasons.

As it was you had choices as a consumer; open, closed - whatever you want. But the thing I deliberately want to choose for is now taken away from me through one of the worst and most unfair business laws I’ve ever seen, that only does harm to the majority of consumers whose choice is taken away and whose privacy and safety is being weakened to destroyed. But “they have a choice to stay in their walled garden” (they just can’t use their phone the way they want and were always used to anymore if they do, but we don’t mention that part and we don’t care those millions of people are getting royally screwed over).

You know, true choice could’ve been achieved if the EU had made a fair law. They didn’t and now we as consumers are going to pay a very heavy price.

A part of this really stands out to me. The new privacy policy associated with this states that Apple collects device identifiers, your Apple ID and the current (GPS-)location of your device and shares this: A.) with Apple to “develop new fraud prevention measures” B.) with your “payment network” (read: your bank).

There is no option to opt-out of this, the privacy policy states that if you do not wish for Apple to collect this data and share it with your bank that you “must use another card”. In other words: you need to participate and agree to sharing this data with your bank or you can no longer use Apple Pay.

Am I the only one that thinks this is absolutely insane and goes hard against Apple’s promise for privacy? Why on earth would you give the bank all that information including the device location with no way to opt out? I also wonder if this sudden one-sided change is even legal under the GDPR considering Apple did not solicit any permission but simply gave a push notification stating “enhanced fraud protection” has now been enabled and that for any payment this data is now collected by Apple and subsequently shared with the bank.

Nobody has found it doing that, though. It could be something that will be added in the future of course (let's hope not...), but "could be" is not really interesting for the current situation. It ain't analysing your chats at this time.

Same in the Netherlands, Germany and Spain. I saw an article that in the Netherlands it apparently is installed on 90% of all smartphones. As far as I know, WhatsApp is pretty much the default in the EU with the exception of Scandinavian countries. Norway, Sweden, Finland are more often to be found on Messenger.