Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Imagine you're having a remote appointment with your doctor for a very personal health issue.

Imagine you're having a remote appointment with your doctor for a very personal health issue.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
privacysecurityconsentapple
63 Indlæg 41 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange

    Imagine you're having a remote appointment with your doctor for a very personal health issue.

    Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.

    You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.

    The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.

    "What about all the privacy laws protecting me?", you claim in distress.

    Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"

    The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.

    Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.

    This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.

    Brace yourself.

    #Privacy #Security #Consent #Apple

    S This user is from outside of this forum
    S This user is from outside of this forum
    solrize@mathstodon.xyz
    wrote sidst redigeret af
    #41

    @Em0nM4stodon @_elena https://biggaybunny.tumblr.com/post/166787080920/tech-enthusiasts-everything-in-my-house-is-wired

    1 Reply Last reply
    0
    • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange

      Imagine you're having a remote appointment with your doctor for a very personal health issue.

      Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.

      You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.

      The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.

      "What about all the privacy laws protecting me?", you claim in distress.

      Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"

      The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.

      Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.

      This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.

      Brace yourself.

      #Privacy #Security #Consent #Apple

      T This user is from outside of this forum
      T This user is from outside of this forum
      troitregrouloinu@mastodon.social
      wrote sidst redigeret af
      #42

      @Em0nM4stodon Note that this is already happening.

      If your doctor or hospital using Windows, between Windows Recall, Copilot or even AcrobatReader (sending files to their servers for OCR, summarizing, etc.) and a million other way to leak files, basically everything ends up on foreign servers.

      The state of privacy in medical is almost non-existent and this is terrifying.

      Meanwhile the EU is pushing ChatControl and Remote Attestation to destroy Privacy even more instead of protecting us.

      1 Reply Last reply
      0
      • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange

        @gruber From Apple's documentation:

        "For Siri Recap, Apple Foundation Models running on Private Cloud Compute (PCC) summarize and format the final output."

        "Siri Recap summaries and saved Live Rewind text snippets stored in the Siri app are end-to-end encrypted when synced through iCloud"

        "If you use iCloud with two-factor authentication and have a device passcode, any Siri Recap summary or Live Rewind text snippet you choose to save syncs across your devices end-to-end encrypted in the Siri app."

        Source: https://support.apple.com/en-us/148354

        gruber@mastodon.socialG This user is from outside of this forum
        gruber@mastodon.socialG This user is from outside of this forum
        gruber@mastodon.social
        wrote sidst redigeret af
        #43

        @Em0nM4stodon PCC doesn't store anything, by design. Siri stuff stored with E2EE is ... fine? And any doctor recording anything using any device in the U.S. needs your explicit permission vis-à-vis HIPAA. I've had a few doctors ask me about AI recording in the last few years.

        em0nm4stodon@infosec.exchangeE jonah@mastodon.neat.computerJ 2 Replies Last reply
        0
        • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange

          Imagine you're having a remote appointment with your doctor for a very personal health issue.

          Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.

          You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.

          The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.

          "What about all the privacy laws protecting me?", you claim in distress.

          Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"

          The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.

          Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.

          This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.

          Brace yourself.

          #Privacy #Security #Consent #Apple

          katzedecimal@kind.socialK This user is from outside of this forum
          katzedecimal@kind.socialK This user is from outside of this forum
          katzedecimal@kind.social
          wrote sidst redigeret af
          #44

          @Em0nM4stodon
          My spouse brought this up with his cardiologist, whose office relies on Google for everything & has Google "smart" shit everywhere.

          The office barred my spouse from returning. Yes, they fired my spouse, their patient, because he brought up privacy concerns, because Google doesn't respect the laws of their own country, let alone ours, let alone anyone else's. This is going to be a massive problem.

          idlebrain@infosec.exchangeI 1 Reply Last reply
          0
          • B barbra@social.vivaldi.net

            @swordgeek @Em0nM4stodon

            It's not just LG TVs. Any smart tv with Automatic Content Recognition that has access to any network (wired or wireless) is doing speech-to-text and uploading it whenever they establish a connection on any network.

            So (1) don't connect them to the internet
            And (2) don't use any streaming features
            And (3) regularly look for open internet connections (your neighbours, etc)
            And (4) do not accept any terms of use. Use it strictly as a dumb monitor.

            rndanger@infosec.exchangeR This user is from outside of this forum
            rndanger@infosec.exchangeR This user is from outside of this forum
            rndanger@infosec.exchange
            wrote sidst redigeret af
            #45

            @barbra @swordgeek @Em0nM4stodon
            LG TVs go a bit further than most and record in room audio while they appear to be off. They will store the audio until it finds internet and it will send it to LG for analysis.

            And their terms of service for their computer monitors tells the owner that wiretap laws require them to inform their guests that they are being monitored, but these terms are never even presented to the user. Windows automatically agrees to them to make things simpler.

            rndanger@infosec.exchangeR 1 Reply Last reply
            0
            • rndanger@infosec.exchangeR rndanger@infosec.exchange

              @barbra @swordgeek @Em0nM4stodon
              LG TVs go a bit further than most and record in room audio while they appear to be off. They will store the audio until it finds internet and it will send it to LG for analysis.

              And their terms of service for their computer monitors tells the owner that wiretap laws require them to inform their guests that they are being monitored, but these terms are never even presented to the user. Windows automatically agrees to them to make things simpler.

              rndanger@infosec.exchangeR This user is from outside of this forum
              rndanger@infosec.exchangeR This user is from outside of this forum
              rndanger@infosec.exchange
              wrote sidst redigeret af
              #46

              @barbra @swordgeek @Em0nM4stodon
              So, how many doctors have LG gaming monitors? 😅

              B 1 Reply Last reply
              0
              • rndanger@infosec.exchangeR rndanger@infosec.exchange

                @barbra @swordgeek @Em0nM4stodon
                So, how many doctors have LG gaming monitors? 😅

                B This user is from outside of this forum
                B This user is from outside of this forum
                barbra@social.vivaldi.net
                wrote sidst redigeret af
                #47

                @RnDanger @swordgeek @Em0nM4stodon

                How many reception areas an waiting rooms have any sort of smart tv connected to the network?

                1 Reply Last reply
                0
                • gruber@mastodon.socialG gruber@mastodon.social

                  @Em0nM4stodon PCC doesn't store anything, by design. Siri stuff stored with E2EE is ... fine? And any doctor recording anything using any device in the U.S. needs your explicit permission vis-à-vis HIPAA. I've had a few doctors ask me about AI recording in the last few years.

                  em0nm4stodon@infosec.exchangeE This user is from outside of this forum
                  em0nm4stodon@infosec.exchangeE This user is from outside of this forum
                  em0nm4stodon@infosec.exchange
                  wrote sidst redigeret af
                  #48

                  @gruber Storing on iCloud with end-to-end encryption is still storing on their servers.

                  acdha@code4lib.socialA 1 Reply Last reply
                  0
                  • gruber@mastodon.socialG gruber@mastodon.social

                    @Em0nM4stodon PCC doesn't store anything, by design. Siri stuff stored with E2EE is ... fine? And any doctor recording anything using any device in the U.S. needs your explicit permission vis-à-vis HIPAA. I've had a few doctors ask me about AI recording in the last few years.

                    jonah@mastodon.neat.computerJ This user is from outside of this forum
                    jonah@mastodon.neat.computerJ This user is from outside of this forum
                    jonah@mastodon.neat.computer
                    wrote sidst redigeret af
                    #49

                    @gruber “by design” means nothing, when what’s designed today can be redesigned by Apple tomorrow, and it places a lot of trust in Apple, Nvidia, Google, and Intel to ALL not have fucked up their designs somewhere along the way.

                    None of them have a sterling privacy reputation in the first place, but *especially* not Apple on the server side of things, with Private Relay, Hide My Email, and Siri itself all having very notable slip-ups recently.

                    Apple also makes a lot of claims about PCC which are misleading at best, like their claims regarding the ability for independent security experts to audit Apple. While you can verify what binary images are running, they don’t have reproducible builds, the binaries contain no symbols; it would be very hard to verify that the binary images match Apple’s published specs, or whether Apple’s introduced any concerning changes or bugs in new images in a timely manner.

                    When data is not protected by raw mathematical encryption, it is always fundamentally at risk when being handled by a third party regardless of data protection safeguards they’ve put in place.

                    (This is not to mention the issue of Apple normalizing this behavior, which will lead Google and Samsung et al. to make their own versions way worse than even PCC)

                    @Em0nM4stodon

                    codinghorror@infosec.exchangeC 1 Reply Last reply
                    0
                    • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange

                      @gruber Storing on iCloud with end-to-end encryption is still storing on their servers.

                      acdha@code4lib.socialA This user is from outside of this forum
                      acdha@code4lib.socialA This user is from outside of this forum
                      acdha@code4lib.social
                      wrote sidst redigeret af
                      #50

                      @Em0nM4stodon @gruber the primary reason why privacy advocates care about data on servers is when that data is accessible to third parties. End to end encrypted data is not.

                      The things to be concerned about here are things like transcription errors or defects allowing access by apps.

                      extra_special_carbon@mastodon.worldE 1 Reply Last reply
                      0
                      • katzedecimal@kind.socialK katzedecimal@kind.social

                        @Em0nM4stodon
                        My spouse brought this up with his cardiologist, whose office relies on Google for everything & has Google "smart" shit everywhere.

                        The office barred my spouse from returning. Yes, they fired my spouse, their patient, because he brought up privacy concerns, because Google doesn't respect the laws of their own country, let alone ours, let alone anyone else's. This is going to be a massive problem.

                        idlebrain@infosec.exchangeI This user is from outside of this forum
                        idlebrain@infosec.exchangeI This user is from outside of this forum
                        idlebrain@infosec.exchange
                        wrote sidst redigeret af
                        #51

                        @Katzedecimal @Em0nM4stodon
                        Sounds like a legal nightmare waiting to happen. (Pipeda/HIPAA/etc)

                        1 Reply Last reply
                        0
                        • jonah@mastodon.neat.computerJ jonah@mastodon.neat.computer

                          @gruber “by design” means nothing, when what’s designed today can be redesigned by Apple tomorrow, and it places a lot of trust in Apple, Nvidia, Google, and Intel to ALL not have fucked up their designs somewhere along the way.

                          None of them have a sterling privacy reputation in the first place, but *especially* not Apple on the server side of things, with Private Relay, Hide My Email, and Siri itself all having very notable slip-ups recently.

                          Apple also makes a lot of claims about PCC which are misleading at best, like their claims regarding the ability for independent security experts to audit Apple. While you can verify what binary images are running, they don’t have reproducible builds, the binaries contain no symbols; it would be very hard to verify that the binary images match Apple’s published specs, or whether Apple’s introduced any concerning changes or bugs in new images in a timely manner.

                          When data is not protected by raw mathematical encryption, it is always fundamentally at risk when being handled by a third party regardless of data protection safeguards they’ve put in place.

                          (This is not to mention the issue of Apple normalizing this behavior, which will lead Google and Samsung et al. to make their own versions way worse than even PCC)

                          @Em0nM4stodon

                          codinghorror@infosec.exchangeC This user is from outside of this forum
                          codinghorror@infosec.exchangeC This user is from outside of this forum
                          codinghorror@infosec.exchange
                          wrote sidst redigeret af
                          #52

                          @jonah @gruber @Em0nM4stodon pick your poison. I mean, the company (previously) led by the gay man who grew up in the absolutely vicious, hate-filled american south, kinda got my vote on "who's gonna care most about privacy" issue in the past.

                          jonah@mastodon.neat.computerJ tmw@ioc.exchangeT 2 Replies Last reply
                          0
                          • codinghorror@infosec.exchangeC codinghorror@infosec.exchange

                            @jonah @gruber @Em0nM4stodon pick your poison. I mean, the company (previously) led by the gay man who grew up in the absolutely vicious, hate-filled american south, kinda got my vote on "who's gonna care most about privacy" issue in the past.

                            jonah@mastodon.neat.computerJ This user is from outside of this forum
                            jonah@mastodon.neat.computerJ This user is from outside of this forum
                            jonah@mastodon.neat.computer
                            wrote sidst redigeret af
                            #53

                            @codinghorror sure, compared to the other big tech companies Apple is pretty great. But compared to not doing this at all, this is a bad move.

                            And still, I frankly do not trust Apple to secure a server as much as I trust them to secure a local device lol

                            @gruber @Em0nM4stodon

                            1 Reply Last reply
                            0
                            • codinghorror@infosec.exchangeC codinghorror@infosec.exchange

                              @jonah @gruber @Em0nM4stodon pick your poison. I mean, the company (previously) led by the gay man who grew up in the absolutely vicious, hate-filled american south, kinda got my vote on "who's gonna care most about privacy" issue in the past.

                              tmw@ioc.exchangeT This user is from outside of this forum
                              tmw@ioc.exchangeT This user is from outside of this forum
                              tmw@ioc.exchange
                              wrote sidst redigeret af
                              #54

                              @codinghorror wait... what?! this is such a bizarre take and we have so much evidence against it. look at grindr crashing almost every time there's some republican meetup. almost none of those guys are out of the closet and they certainly don't care about americans' privacy.

                              i don't know tim cook's backstory but a lot of us can mask pretty well

                              peter thiel is gay and is behind freaking palantir

                              we ain't all angels

                              codinghorror@infosec.exchangeC 1 Reply Last reply
                              0
                              • tmw@ioc.exchangeT tmw@ioc.exchange

                                @codinghorror wait... what?! this is such a bizarre take and we have so much evidence against it. look at grindr crashing almost every time there's some republican meetup. almost none of those guys are out of the closet and they certainly don't care about americans' privacy.

                                i don't know tim cook's backstory but a lot of us can mask pretty well

                                peter thiel is gay and is behind freaking palantir

                                we ain't all angels

                                codinghorror@infosec.exchangeC This user is from outside of this forum
                                codinghorror@infosec.exchangeC This user is from outside of this forum
                                codinghorror@infosec.exchange
                                wrote sidst redigeret af
                                #55

                                @tmw look into his backstory. everyone's backstory tells you a lot about who they are and what they become

                                tmw@ioc.exchangeT 1 Reply Last reply
                                0
                                • codinghorror@infosec.exchangeC codinghorror@infosec.exchange

                                  @tmw look into his backstory. everyone's backstory tells you a lot about who they are and what they become

                                  tmw@ioc.exchangeT This user is from outside of this forum
                                  tmw@ioc.exchangeT This user is from outside of this forum
                                  tmw@ioc.exchange
                                  wrote sidst redigeret af
                                  #56

                                  @codinghorror it tells you about who the narrator wants you to believe that the person was in the past. unless you believe that people can't change and that retellings are infallible, it doesn't tell you that much about how they really are

                                  (that much is, well... private!)

                                  codinghorror@infosec.exchangeC 1 Reply Last reply
                                  0
                                  • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange

                                    Imagine you're having a remote appointment with your doctor for a very personal health issue.

                                    Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.

                                    You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.

                                    The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.

                                    "What about all the privacy laws protecting me?", you claim in distress.

                                    Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"

                                    The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.

                                    Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.

                                    This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.

                                    Brace yourself.

                                    #Privacy #Security #Consent #Apple

                                    mydoomfr@mamot.frM This user is from outside of this forum
                                    mydoomfr@mamot.frM This user is from outside of this forum
                                    mydoomfr@mamot.fr
                                    wrote sidst redigeret af
                                    #57

                                    @Em0nM4stodon Imagine your doctor avoids an "overpriced Apple product" and uses a 2y old Huawei phone/watch that no longer gets updates, with apps and access to work email

                                    Imagine there is an LG TV in the room. Given the current controversy around LG TVs allegedly listening or collecting data ; what could go wrong?

                                    Or his laptop still runs Windows 7 because "it works fine", with years of random software installed.

                                    My point: this isn't an Apple problem

                                    1 Reply Last reply
                                    0
                                    • tmw@ioc.exchangeT tmw@ioc.exchange

                                      @codinghorror it tells you about who the narrator wants you to believe that the person was in the past. unless you believe that people can't change and that retellings are infallible, it doesn't tell you that much about how they really are

                                      (that much is, well... private!)

                                      codinghorror@infosec.exchangeC This user is from outside of this forum
                                      codinghorror@infosec.exchangeC This user is from outside of this forum
                                      codinghorror@infosec.exchange
                                      wrote sidst redigeret af
                                      #58

                                      @tmw and if the narrator is the person themselves? This is a massively reductive take.

                                      1 Reply Last reply
                                      0
                                      • acdha@code4lib.socialA acdha@code4lib.social

                                        @Em0nM4stodon @gruber the primary reason why privacy advocates care about data on servers is when that data is accessible to third parties. End to end encrypted data is not.

                                        The things to be concerned about here are things like transcription errors or defects allowing access by apps.

                                        extra_special_carbon@mastodon.worldE This user is from outside of this forum
                                        extra_special_carbon@mastodon.worldE This user is from outside of this forum
                                        extra_special_carbon@mastodon.world
                                        wrote sidst redigeret af
                                        #59

                                        @acdha @Em0nM4stodon @gruber I liken this to the AirTag issue. Everyone was really shocked at the potential harm with AirTag, but Apple put in some pretty strong protections, such as notifying you when one was following you. The notification freaked people out more.

                                        Meanwhile, Tag has been sold for years, and provided zero safety features. So imagine it’s not an Apple watch but something offbrand that nobody is thinking of.

                                        1 Reply Last reply
                                        0
                                        • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange

                                          Imagine you're having a remote appointment with your doctor for a very personal health issue.

                                          Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.

                                          You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.

                                          The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.

                                          "What about all the privacy laws protecting me?", you claim in distress.

                                          Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"

                                          The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.

                                          Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.

                                          This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.

                                          Brace yourself.

                                          #Privacy #Security #Consent #Apple

                                          A This user is from outside of this forum
                                          A This user is from outside of this forum
                                          agreeable_landfall@mastodon.social
                                          wrote sidst redigeret af
                                          #60

                                          @Em0nM4stodon @janeishly Great. Now I have to add "are you wearing an Apple watch?" to my "do not record this session with your AI transcription system."

                                          It's bad enough that the *doctors* get my history wrong ("No, that's my *family* history of heart disease. I'm fine."), add in software which can't correctly transcribe "fallacious".

                                          And how does any of that work on patients with difficulty speaking? Sure, the doctor is supposed to review the transcript, but they get it wrong often.

                                          hrifeu@waag.socialH 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper