• 0 Posts
  • 95 Comments
Joined 4 months ago
cake
Cake day: February 15th, 2024

help-circle












  • No, but they have to disclose all possible avenues of collection. I for one like storing my health data in icloud for processing and retention. They take that data, run it through algorithms, and use it to provide me things like estimated sleep cycle details.

    Yes. Also yes. I find quite a bit of it distasteful, but as a systems administrator I have to be informed of all privacy policies guiding the disclosure and use of company data. It sucks, they’re lengthy and overwhelming, and often you’re right they do ask for too much but at the end of the day it’s less than you’d expect and they never make their money selling it, which is more than you can say about any software company of Apple’s scale.

    If I set the boundaries they’d have none. That’s my preference and why I E2E encrypt everything on my device. I’d give up features and self host if I could, but all of that just isn’t possible for your average user or for them to stay competitive in their business model. Users don’t want to know what E2E is, they don’t want things “losable”, and honestly don’t care about their privacy (check the privacy policy of meta and TikTok vs Apple if you don’t believe me that there’s a difference and the vast majority do not care). That being said Apple provides what I see as the best middle ground. Enough privacy to remain confident my data is secure (E2E icloud backups, E2E messaging, etc) but enough gathering to keep their services competitive with more lucrative competitors with looser policies. Oh. And it would be too far when they started selling it to third party companies. That’s what msde me leave my android phone behind, when Google started migrating all the apis to Google Play Services instead of ASOP apis.

    No offense taken, I understand your rage and I agree with your sentiment. They ask too much. But when you compare the other options, it’s the safest path in my honest opinion.


  • I unfortunately don’t have much to share beyond a decent understanding of compute systems at an enterprise scale (where we utilize these low level subprocessors to do various things such as gather asset data or deploy operating system configurations, see: https://en.m.wikipedia.org/wiki/Intel_Active_Management_Technology). The point I’m trying to make though is that current operating models don’t allow for system trust. If you can’t trust apple with high level data like that needed for llm models on-device (which is how they’ve configured it, requiring a specific user approval and interaction before forwarding minimal data to private process servers) then you shouldn’t trust any device that lacks a complete open boot/firmware/ and OS stack because if these companies were going to exploit your data that egregiously, they already have the lowest level (best) access possible to a system that can transparently (without your knowledge) access encryption enclaves, networking, and storage. Truly open alternatives do exist by the way (see Coreboot, etc) but you’re going to be looking at devices 10-20 years old since almost the entire industry runs proprietary at that level and it takes time for the less heavily funded community players to get up to speed.






  • Apple secures third party audits for their devices and designs, additionally security researchers have methods of verifying certain aspects of device behavior. People dig into stuff and Apple has not only a history of good privacy design, but as far as I’m aware they’ve never been caught doing anything remotely out of scope of their tight knit privacy policies with user data. Your complaint is baseless.