Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So the M1 has turned me off of Apple products because, quite frankly, I don't want to spend (more) of my time fixing shit a trillion dollar company broke and doesn't care to fix.

This though, this will be the nail in the coffin with my 25 year relationship to Apple. I probably wouldn't even have batted an eye at it to be honest, iff, Apple hadn't been selling me on the idea that their platform is "private and secure." But... they have... And this has made it quite clear, they will absolutely destroy that security/privacy the moment they want/need to. So I have been paying, a hefty premium, to be lied to and that makes me fucking cross. I have previously supported Apple because it seems like they typically do "the right thing" but this is so fucking insane to me I have to permanently question the judgement of those in charge.

Do not sell privacy and security if you're going to completely violate that security and privacy.

In 25 years or less this bullshit will be made illegal, because there is ZERO chance nefarious actors won't learn how to create benign images that match the hash of a heinous photo to destroy people. I can almost guarantee, right now, nation-state sponsored hackers and affiliated groups are attempting to get those hashes and do exactly that. It's just too fucking easy to manipulate once you're in and has absolutely zero chance of being detected once you're generating the hashes until too many lives are ruined.

May hell have no mercy for the souls who made this...



I used to downvote people a couple of years ago who were shedding doubt on Apple’s commitment to privacy.

Boy. I was so wrong. I fell for the Marketing and it made sense at the time “Their business is selling hardware and services, not ads. Ofcourse they are privacy advocates”.

Pass laws and legislation. I admit I was wrong and it’s refreshing to see this whole thing unfold before my eyes. It just solidified my opinion about open source hardware.


That's part of downvote culture -- rather than verbally disagreeing, just press a button. It's easy. You don't have to present a counter-argument, you just begin to bury the opposing side. Everyone adds a shoveful of dirt and eventually that thing is just ... gone. Wished into the cornfield.

And it feels good, too. You've done your part, helping to make that sort of thing vanish.

Now you've seen how it works. That's why real engagement is so very important, it allows us to communicate and specify. What would a real commitment to privacy look like? Now we know that it isn't just a press release and a bunch of shiny happy faces (carefully chosen) holding Apple products. Now we can start talking about what a real commitment to privacy looks like in the world.

I know you think laws and legislation are a good idea, but my guess is that this is a big no, or we will get them but with all kinds of loopholes for three-letter agencies, or no penalties specified for infraction.

We know we won't get any kind of legal punishment, that recent ebay case is a fantastic example of the golden parachute you get.

Perhaps commitment looks like a bond held in escrow. If my Apple TV is found to be exfiltrating the filenames of everything in a network share, the five million in that escrow account gets kicked over to the EFF. Stocks could be held out in reserve.

Essentially, commitment looks like the Sword of Damocles, held over the heads of these corporate actors, and scissors are to be held by people who do not like them much.


I'm just surprised they did it for CP and not terrorism.


I think it's terrorism, and CP.

I have a feeling the CIA, or FBI, had a little chat with Tim Cook, and Tim caved into the pressure.

Who knows they might have some very embarrassing info about the man, and used it to get what they wanted.

I guarantee government, including the IRS, Immigration, etc. will be accessing Apples severs.

At least we won't have to listen to Apple privacy commercials anymore.


> I guarantee government, including the IRS, Immigration, etc. will be accessing Apples severs.

Not sure if I'd go that far, but if they're using fingerprinting to identify CP, no reason they can't/wouldn't use ML to classify iMessages client-side as terrorist/not-terrorist.


"It would be a shame if your company had to be split up for antitrust reasons."

The sad thing is that it does need to be split up, but this was probably the stick used by the FBI/CIA to get their way. And as long as Apple does what they want, they'll let it go about its merry way.


Is it not weird to have people argue that Apple should be above the laws of places like Saudi Arabia and China, but this should be dealt with by "pass laws and legislation" and then expect Apple must obey those?

...?


I think people imply Apple should refuse to do business if it means following unjust laws contrary to their core values. Instead, it is a revelation that their core values aren't to protect the individual, but themselves.


I have absolutely no comment on Apple that you or anyone else hasn’t made. Except your comments about hash matching, the whole point is it goes to manual confirmation, they don’t just detect an illegal hash and come arrest you.

But do you seriously think this isn’t going to be the standard for Android, Windows, ChromeOS, OSX, etc coming at degrees of time or implementation?

I know all the Android people are just thinking “I can root” or “I’ll run Lineage” which is well and good but relatively no one else will.

Stomping your feet and saying No More Apple For Me is not a winner here. It needs to be worse than that for them. What that looks like? I’m just as clueless as anyone else.


I've been trying to get more clarity on this point (`it goes to manual confirmation`) but was unable to. Remember, they're saying this is something that happens on your own device, with your personal photos, not in the cloud.

Is this saying they can randomly choose to upload any personal files (photos) on your device to their servers for a person to look at, because they match a "hash"? Is this not absolutely batshit crazy !?


You know these are photos you requested to upload to iCloud, which would already under the existing system be scanned once they get there, right? But if they get scanned first and then uploaded to Apple that's "absolutely batshit crazy"??

Edit reply in here because I'm rate-limited by drive-by downvoters:

Which part isn't clear to you?

- That they already scanned iCloud photos for such material? Here is an article from 18 months ago about it: http://web.archive.org/web/20210728085553/https://www.telegr...

- That this is only for iCloud photos and not everyone's every photo? "CSAM detection will help Apple provide valuable information to law enforcement on collections of CSAM in iCloud Photos" - https://www.apple.com/child-safety/ paragraph 3.

- Why? From the rest of that link, "providing significant privacy benefits over existing techniques since Apple only learns about users’ photos if they have a collection of known CSAM in their iCloud Photos account. Even in these cases, Apple only learns about images that match known CSAM."


No, that part is not clear to me at all. If they would be "scanned anyway", why would this system exist at all?


Because not every photo is uploaded to iCloud.

If you use iCloud, this is already happening today, probably.

If you don’t use iCloud, yes, the idea is local scan, match hash, then upload for manual review. The involuntary upload will have been covered by the EULA.

I’m not endorsing the idea. But this seems to be the only way it could work.


> So the M1 has turned me off of Apple products because, quite frankly, I don't want to spend (more) of my time fixing shit a trillion dollar company broke and doesn't care to fix.

What is broken about the M1?


M1 Macs are basically iPads, with the same iOS-style locked-down boot process. They even have the same DFU mode as iOS devices.

In my case "my" M1 bricked itself, because Apple servers have refused to permit changes to NVRAM in the machine, and it can't boot a reinstalled OS without Apple's approval.


No, M1 isn't locked down at all. You can disable secure boot and there are efforts to port Linux to it. You can block *.apple.com and everything will still work.


Puppies aren't messy at all. You can shave all their hair off and there are efforts to deal with the slobbering. You can put a diaper on the back end of it and everything will still work.


I've used macs since the 90s and the first thing I always do is delete all the Apple apps, install little snitch, and set up the hosts file to block apple, adobe and anything else that's trying to call home. That's not misunderstanding or misusing the device, it's just standard configuration as far as I'm concerned. I don't have an M1 yet, and I'm a little worried about apps sidestepping little snitch, but I'll cross that bridge when I get to it.


That no production server on the planet runs Apple Silicon, so I'm building on, and supporting, a platform I won't ever run my software on. After quite literally fixing an architectural issue in OTP/BEAM caused by Apple Silicon, it dawned on me, it's literally nothing but increasing costs all the way down. If ARM gets widely adopted on Desktops I'll change my tune, but for now, it's pretty garbage in the real world. I spend time fixing bugs and dealing with bullshit on platform I'll make zero money from. This is compounded by the fact, I've quite successfully and happily moved to Linux for my workstation. Like there's nothing in MacOS I miss, not a fucking thing... because Linux in 2021 is all the good things of an x86-64 Mac with the ability to play nearly (any) game.

In MacOS, I've never been able to to play games (relax) and be productive on the same machine. Now, I am on the daily, and it's literally fucking free.

If I hadn't spent a few weeks slogging out a fix for an arch issues on Apple Silicon, followed by a successful move to Linux there's no way I'd have this perspective... but some-fucking-how... I did and so I do.


All the non-Apple software that people needed to spend months fixing. There's a variety of posts on HN about being "M1 ready".


> "has absolutely zero chance of being detected once you're generating the hashes until too many lives are ruined."

... the alerts go to Apple for human review. You think their human review won't notice a garbled nonsense picture triggering a false positive?


> the alerts go to Apple for human review

This should be read as "the alerts go to a barely-trained employee at a third party contractor like Cognizant[1] who has a quota of material to review every hour or they get fired and don't necessarily get points for accuracy for human review". I don't think Tim Cook is going to be double checking these images.

[1] https://www.theverge.com/2019/2/25/18229714/cognizant-facebo...


Have you not been reading about the App Store review discrepancies for the last decade??




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: