Imagine you're having a remote appointment with your doctor for a very personal health issue.
-
Imagine you're having a remote appointment with your doctor for a very personal health issue.
Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.
You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.
The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.
"What about all the privacy laws protecting me?", you claim in distress.
Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"
The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.
Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.
This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.
Brace yourself.
@Em0nM4stodon
Let's put the Creep Watches with the Pedo Glasses in X Rockets and send them to the sun. -
Imagine you're having a remote appointment with your doctor for a very personal health issue.
Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.
You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.
The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.
"What about all the privacy laws protecting me?", you claim in distress.
Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"
The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.
Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.
This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.
Brace yourself.
@Em0nM4stodon @Npars01 Coming years? It is happening right now! The surest way I’ve found to get a doctor to pay attention to privacy concerns is to ask if the watch/recorder/whatever is on the other side is “HIPAA Compliant”. This is the law to protect the privacy of your health information. If they don’t know, ask for the contact info for their HIPAA Compliance Officer. Every company that touches private health information is required to have one. You might have to call the most senior person to find out. Why should they care? If they don’t give you this info and answer your questions, you can complain to US Health and Human Services (online form) and that can kick off an investigation that can get very serious. In addition to big $$ fines, a company (including universities) can lose ALL access to Federal contracts and grants FOREVER.
Is Apple HIPAA compliant? No.
-
@Em0nM4stodon @Npars01 Coming years? It is happening right now! The surest way I’ve found to get a doctor to pay attention to privacy concerns is to ask if the watch/recorder/whatever is on the other side is “HIPAA Compliant”. This is the law to protect the privacy of your health information. If they don’t know, ask for the contact info for their HIPAA Compliance Officer. Every company that touches private health information is required to have one. You might have to call the most senior person to find out. Why should they care? If they don’t give you this info and answer your questions, you can complain to US Health and Human Services (online form) and that can kick off an investigation that can get very serious. In addition to big $$ fines, a company (including universities) can lose ALL access to Federal contracts and grants FOREVER.
Is Apple HIPAA compliant? No.
@meltedcheese @Npars01 This is good advice for people located in the United States.
-
Imagine you're having a remote appointment with your doctor for a very personal health issue.
Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.
You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.
The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.
"What about all the privacy laws protecting me?", you claim in distress.
Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"
The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.
Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.
This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.
Brace yourself.
@Em0nM4stodon This means you cannot say to a doctor anything you cannot say to a cop and a hostile news reporter without first searching them for hidden recording devices. Check their glasses, check their watch, if either is a known creep device, do not discuss or seek treatment for sensitive matters with that practitioner.
-
@Em0nM4stodon Today a doctor friend posted the reverse: patients happily recording their conversation or feeding it to some AI app. Most patients are probably not thinking through these privacy issues, either. 🫣
@alex @Em0nM4stodon should laws protect patients from themselves?
even if individuals don't care, doctors must not preclude their chance to shoot themselves in the foot. -
@Em0nM4stodon @Npars01 Coming years? It is happening right now! The surest way I’ve found to get a doctor to pay attention to privacy concerns is to ask if the watch/recorder/whatever is on the other side is “HIPAA Compliant”. This is the law to protect the privacy of your health information. If they don’t know, ask for the contact info for their HIPAA Compliance Officer. Every company that touches private health information is required to have one. You might have to call the most senior person to find out. Why should they care? If they don’t give you this info and answer your questions, you can complain to US Health and Human Services (online form) and that can kick off an investigation that can get very serious. In addition to big $$ fines, a company (including universities) can lose ALL access to Federal contracts and grants FOREVER.
Is Apple HIPAA compliant? No.
@meltedcheese @Em0nM4stodon @Npars01 advocate for better but recognize the FTC regulates “consumer devices.”
-
Imagine you're having a remote appointment with your doctor for a very personal health issue.
Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.
You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.
The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.
"What about all the privacy laws protecting me?", you claim in distress.
Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"
The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.
Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.
This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.
Brace yourself.
-
Imagine you're having a remote appointment with your doctor for a very personal health issue.
Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.
You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.
The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.
"What about all the privacy laws protecting me?", you claim in distress.
Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"
The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.
Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.
This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.
Brace yourself.
@Em0nM4stodon Note that this is already happening.
If your doctor or hospital using Windows, between Windows Recall, Copilot or even AcrobatReader (sending files to their servers for OCR, summarizing, etc.) and a million other way to leak files, basically everything ends up on foreign servers.
The state of privacy in medical is almost non-existent and this is terrifying.
Meanwhile the EU is pushing ChatControl and Remote Attestation to destroy Privacy even more instead of protecting us.
-
@gruber From Apple's documentation:
"For Siri Recap, Apple Foundation Models running on Private Cloud Compute (PCC) summarize and format the final output."
"Siri Recap summaries and saved Live Rewind text snippets stored in the Siri app are end-to-end encrypted when synced through iCloud"
"If you use iCloud with two-factor authentication and have a device passcode, any Siri Recap summary or Live Rewind text snippet you choose to save syncs across your devices end-to-end encrypted in the Siri app."
@Em0nM4stodon PCC doesn't store anything, by design. Siri stuff stored with E2EE is ... fine? And any doctor recording anything using any device in the U.S. needs your explicit permission vis-à-vis HIPAA. I've had a few doctors ask me about AI recording in the last few years.
-
Imagine you're having a remote appointment with your doctor for a very personal health issue.
Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.
You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.
The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.
"What about all the privacy laws protecting me?", you claim in distress.
Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"
The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.
Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.
This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.
Brace yourself.
@Em0nM4stodon
My spouse brought this up with his cardiologist, whose office relies on Google for everything & has Google "smart" shit everywhere.The office barred my spouse from returning. Yes, they fired my spouse, their patient, because he brought up privacy concerns, because Google doesn't respect the laws of their own country, let alone ours, let alone anyone else's. This is going to be a massive problem.
-
It's not just LG TVs. Any smart tv with Automatic Content Recognition that has access to any network (wired or wireless) is doing speech-to-text and uploading it whenever they establish a connection on any network.
So (1) don't connect them to the internet
And (2) don't use any streaming features
And (3) regularly look for open internet connections (your neighbours, etc)
And (4) do not accept any terms of use. Use it strictly as a dumb monitor.@barbra @swordgeek @Em0nM4stodon
LG TVs go a bit further than most and record in room audio while they appear to be off. They will store the audio until it finds internet and it will send it to LG for analysis.And their terms of service for their computer monitors tells the owner that wiretap laws require them to inform their guests that they are being monitored, but these terms are never even presented to the user. Windows automatically agrees to them to make things simpler.
-
@barbra @swordgeek @Em0nM4stodon
LG TVs go a bit further than most and record in room audio while they appear to be off. They will store the audio until it finds internet and it will send it to LG for analysis.And their terms of service for their computer monitors tells the owner that wiretap laws require them to inform their guests that they are being monitored, but these terms are never even presented to the user. Windows automatically agrees to them to make things simpler.
@barbra @swordgeek @Em0nM4stodon
So, how many doctors have LG gaming monitors?
-
@barbra @swordgeek @Em0nM4stodon
So, how many doctors have LG gaming monitors?
@RnDanger @swordgeek @Em0nM4stodon
How many reception areas an waiting rooms have any sort of smart tv connected to the network?
-
@Em0nM4stodon PCC doesn't store anything, by design. Siri stuff stored with E2EE is ... fine? And any doctor recording anything using any device in the U.S. needs your explicit permission vis-à-vis HIPAA. I've had a few doctors ask me about AI recording in the last few years.
@gruber Storing on iCloud with end-to-end encryption is still storing on their servers.
-
@Em0nM4stodon PCC doesn't store anything, by design. Siri stuff stored with E2EE is ... fine? And any doctor recording anything using any device in the U.S. needs your explicit permission vis-à-vis HIPAA. I've had a few doctors ask me about AI recording in the last few years.
@gruber “by design” means nothing, when what’s designed today can be redesigned by Apple tomorrow, and it places a lot of trust in Apple, Nvidia, Google, and Intel to ALL not have fucked up their designs somewhere along the way.
None of them have a sterling privacy reputation in the first place, but *especially* not Apple on the server side of things, with Private Relay, Hide My Email, and Siri itself all having very notable slip-ups recently.
Apple also makes a lot of claims about PCC which are misleading at best, like their claims regarding the ability for independent security experts to audit Apple. While you can verify what binary images are running, they don’t have reproducible builds, the binaries contain no symbols; it would be very hard to verify that the binary images match Apple’s published specs, or whether Apple’s introduced any concerning changes or bugs in new images in a timely manner.
When data is not protected by raw mathematical encryption, it is always fundamentally at risk when being handled by a third party regardless of data protection safeguards they’ve put in place.
(This is not to mention the issue of Apple normalizing this behavior, which will lead Google and Samsung et al. to make their own versions way worse than even PCC)
-
@gruber Storing on iCloud with end-to-end encryption is still storing on their servers.
@Em0nM4stodon @gruber the primary reason why privacy advocates care about data on servers is when that data is accessible to third parties. End to end encrypted data is not.
The things to be concerned about here are things like transcription errors or defects allowing access by apps.
-
@Em0nM4stodon
My spouse brought this up with his cardiologist, whose office relies on Google for everything & has Google "smart" shit everywhere.The office barred my spouse from returning. Yes, they fired my spouse, their patient, because he brought up privacy concerns, because Google doesn't respect the laws of their own country, let alone ours, let alone anyone else's. This is going to be a massive problem.
@Katzedecimal @Em0nM4stodon
Sounds like a legal nightmare waiting to happen. (Pipeda/HIPAA/etc) -
@gruber “by design” means nothing, when what’s designed today can be redesigned by Apple tomorrow, and it places a lot of trust in Apple, Nvidia, Google, and Intel to ALL not have fucked up their designs somewhere along the way.
None of them have a sterling privacy reputation in the first place, but *especially* not Apple on the server side of things, with Private Relay, Hide My Email, and Siri itself all having very notable slip-ups recently.
Apple also makes a lot of claims about PCC which are misleading at best, like their claims regarding the ability for independent security experts to audit Apple. While you can verify what binary images are running, they don’t have reproducible builds, the binaries contain no symbols; it would be very hard to verify that the binary images match Apple’s published specs, or whether Apple’s introduced any concerning changes or bugs in new images in a timely manner.
When data is not protected by raw mathematical encryption, it is always fundamentally at risk when being handled by a third party regardless of data protection safeguards they’ve put in place.
(This is not to mention the issue of Apple normalizing this behavior, which will lead Google and Samsung et al. to make their own versions way worse than even PCC)
@jonah @gruber @Em0nM4stodon pick your poison. I mean, the company (previously) led by the gay man who grew up in the absolutely vicious, hate-filled american south, kinda got my vote on "who's gonna care most about privacy" issue in the past.
-
@jonah @gruber @Em0nM4stodon pick your poison. I mean, the company (previously) led by the gay man who grew up in the absolutely vicious, hate-filled american south, kinda got my vote on "who's gonna care most about privacy" issue in the past.
@codinghorror sure, compared to the other big tech companies Apple is pretty great. But compared to not doing this at all, this is a bad move.
And still, I frankly do not trust Apple to secure a server as much as I trust them to secure a local device lol
-
@jonah @gruber @Em0nM4stodon pick your poison. I mean, the company (previously) led by the gay man who grew up in the absolutely vicious, hate-filled american south, kinda got my vote on "who's gonna care most about privacy" issue in the past.
@codinghorror wait... what?! this is such a bizarre take and we have so much evidence against it. look at grindr crashing almost every time there's some republican meetup. almost none of those guys are out of the closet and they certainly don't care about americans' privacy.
i don't know tim cook's backstory but a lot of us can mask pretty well
peter thiel is gay and is behind freaking palantir
we ain't all angels