Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Imagine you're having a remote appointment with your doctor for a very personal health issue.

Imagine you're having a remote appointment with your doctor for a very personal health issue.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
privacysecurityconsentapple
63 Indlæg 41 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • meltedcheese@c.imM meltedcheese@c.im

    @Em0nM4stodon @Npars01 Coming years? It is happening right now! The surest way I’ve found to get a doctor to pay attention to privacy concerns is to ask if the watch/recorder/whatever is on the other side is “HIPAA Compliant”. This is the law to protect the privacy of your health information. If they don’t know, ask for the contact info for their HIPAA Compliance Officer. Every company that touches private health information is required to have one. You might have to call the most senior person to find out. Why should they care? If they don’t give you this info and answer your questions, you can complain to US Health and Human Services (online form) and that can kick off an investigation that can get very serious. In addition to big $$ fines, a company (including universities) can lose ALL access to Federal contracts and grants FOREVER.

    Is Apple HIPAA compliant? No.

    https://patient-protect.com/post/is-icloud-hipaa-compliant

    j_hearsay@infosec.exchangeJ This user is from outside of this forum
    j_hearsay@infosec.exchangeJ This user is from outside of this forum
    j_hearsay@infosec.exchange
    wrote sidst redigeret af
    #40

    @meltedcheese @Em0nM4stodon @Npars01 advocate for better but recognize the FTC regulates “consumer devices.”

    1 Reply Last reply
    0
    • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange

      Imagine you're having a remote appointment with your doctor for a very personal health issue.

      Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.

      You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.

      The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.

      "What about all the privacy laws protecting me?", you claim in distress.

      Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"

      The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.

      Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.

      This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.

      Brace yourself.

      #Privacy #Security #Consent #Apple

      S This user is from outside of this forum
      S This user is from outside of this forum
      solrize@mathstodon.xyz
      wrote sidst redigeret af
      #41

      @Em0nM4stodon @_elena https://biggaybunny.tumblr.com/post/166787080920/tech-enthusiasts-everything-in-my-house-is-wired

      1 Reply Last reply
      0
      • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange

        Imagine you're having a remote appointment with your doctor for a very personal health issue.

        Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.

        You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.

        The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.

        "What about all the privacy laws protecting me?", you claim in distress.

        Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"

        The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.

        Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.

        This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.

        Brace yourself.

        #Privacy #Security #Consent #Apple

        T This user is from outside of this forum
        T This user is from outside of this forum
        troitregrouloinu@mastodon.social
        wrote sidst redigeret af
        #42

        @Em0nM4stodon Note that this is already happening.

        If your doctor or hospital using Windows, between Windows Recall, Copilot or even AcrobatReader (sending files to their servers for OCR, summarizing, etc.) and a million other way to leak files, basically everything ends up on foreign servers.

        The state of privacy in medical is almost non-existent and this is terrifying.

        Meanwhile the EU is pushing ChatControl and Remote Attestation to destroy Privacy even more instead of protecting us.

        1 Reply Last reply
        0
        • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange

          @gruber From Apple's documentation:

          "For Siri Recap, Apple Foundation Models running on Private Cloud Compute (PCC) summarize and format the final output."

          "Siri Recap summaries and saved Live Rewind text snippets stored in the Siri app are end-to-end encrypted when synced through iCloud"

          "If you use iCloud with two-factor authentication and have a device passcode, any Siri Recap summary or Live Rewind text snippet you choose to save syncs across your devices end-to-end encrypted in the Siri app."

          Source: https://support.apple.com/en-us/148354

          gruber@mastodon.socialG This user is from outside of this forum
          gruber@mastodon.socialG This user is from outside of this forum
          gruber@mastodon.social
          wrote sidst redigeret af
          #43

          @Em0nM4stodon PCC doesn't store anything, by design. Siri stuff stored with E2EE is ... fine? And any doctor recording anything using any device in the U.S. needs your explicit permission vis-à-vis HIPAA. I've had a few doctors ask me about AI recording in the last few years.

          em0nm4stodon@infosec.exchangeE jonah@mastodon.neat.computerJ 2 Replies Last reply
          0
          • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange

            Imagine you're having a remote appointment with your doctor for a very personal health issue.

            Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.

            You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.

            The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.

            "What about all the privacy laws protecting me?", you claim in distress.

            Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"

            The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.

            Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.

            This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.

            Brace yourself.

            #Privacy #Security #Consent #Apple

            katzedecimal@kind.socialK This user is from outside of this forum
            katzedecimal@kind.socialK This user is from outside of this forum
            katzedecimal@kind.social
            wrote sidst redigeret af
            #44

            @Em0nM4stodon
            My spouse brought this up with his cardiologist, whose office relies on Google for everything & has Google "smart" shit everywhere.

            The office barred my spouse from returning. Yes, they fired my spouse, their patient, because he brought up privacy concerns, because Google doesn't respect the laws of their own country, let alone ours, let alone anyone else's. This is going to be a massive problem.

            idlebrain@infosec.exchangeI 1 Reply Last reply
            0
            • B barbra@social.vivaldi.net

              @swordgeek @Em0nM4stodon

              It's not just LG TVs. Any smart tv with Automatic Content Recognition that has access to any network (wired or wireless) is doing speech-to-text and uploading it whenever they establish a connection on any network.

              So (1) don't connect them to the internet
              And (2) don't use any streaming features
              And (3) regularly look for open internet connections (your neighbours, etc)
              And (4) do not accept any terms of use. Use it strictly as a dumb monitor.

              rndanger@infosec.exchangeR This user is from outside of this forum
              rndanger@infosec.exchangeR This user is from outside of this forum
              rndanger@infosec.exchange
              wrote sidst redigeret af
              #45

              @barbra @swordgeek @Em0nM4stodon
              LG TVs go a bit further than most and record in room audio while they appear to be off. They will store the audio until it finds internet and it will send it to LG for analysis.

              And their terms of service for their computer monitors tells the owner that wiretap laws require them to inform their guests that they are being monitored, but these terms are never even presented to the user. Windows automatically agrees to them to make things simpler.

              rndanger@infosec.exchangeR 1 Reply Last reply
              0
              • rndanger@infosec.exchangeR rndanger@infosec.exchange

                @barbra @swordgeek @Em0nM4stodon
                LG TVs go a bit further than most and record in room audio while they appear to be off. They will store the audio until it finds internet and it will send it to LG for analysis.

                And their terms of service for their computer monitors tells the owner that wiretap laws require them to inform their guests that they are being monitored, but these terms are never even presented to the user. Windows automatically agrees to them to make things simpler.

                rndanger@infosec.exchangeR This user is from outside of this forum
                rndanger@infosec.exchangeR This user is from outside of this forum
                rndanger@infosec.exchange
                wrote sidst redigeret af
                #46

                @barbra @swordgeek @Em0nM4stodon
                So, how many doctors have LG gaming monitors? 😅

                B 1 Reply Last reply
                0
                • rndanger@infosec.exchangeR rndanger@infosec.exchange

                  @barbra @swordgeek @Em0nM4stodon
                  So, how many doctors have LG gaming monitors? 😅

                  B This user is from outside of this forum
                  B This user is from outside of this forum
                  barbra@social.vivaldi.net
                  wrote sidst redigeret af
                  #47

                  @RnDanger @swordgeek @Em0nM4stodon

                  How many reception areas an waiting rooms have any sort of smart tv connected to the network?

                  1 Reply Last reply
                  0
                  • gruber@mastodon.socialG gruber@mastodon.social

                    @Em0nM4stodon PCC doesn't store anything, by design. Siri stuff stored with E2EE is ... fine? And any doctor recording anything using any device in the U.S. needs your explicit permission vis-à-vis HIPAA. I've had a few doctors ask me about AI recording in the last few years.

                    em0nm4stodon@infosec.exchangeE This user is from outside of this forum
                    em0nm4stodon@infosec.exchangeE This user is from outside of this forum
                    em0nm4stodon@infosec.exchange
                    wrote sidst redigeret af
                    #48

                    @gruber Storing on iCloud with end-to-end encryption is still storing on their servers.

                    acdha@code4lib.socialA 1 Reply Last reply
                    0
                    • gruber@mastodon.socialG gruber@mastodon.social

                      @Em0nM4stodon PCC doesn't store anything, by design. Siri stuff stored with E2EE is ... fine? And any doctor recording anything using any device in the U.S. needs your explicit permission vis-à-vis HIPAA. I've had a few doctors ask me about AI recording in the last few years.

                      jonah@mastodon.neat.computerJ This user is from outside of this forum
                      jonah@mastodon.neat.computerJ This user is from outside of this forum
                      jonah@mastodon.neat.computer
                      wrote sidst redigeret af
                      #49

                      @gruber “by design” means nothing, when what’s designed today can be redesigned by Apple tomorrow, and it places a lot of trust in Apple, Nvidia, Google, and Intel to ALL not have fucked up their designs somewhere along the way.

                      None of them have a sterling privacy reputation in the first place, but *especially* not Apple on the server side of things, with Private Relay, Hide My Email, and Siri itself all having very notable slip-ups recently.

                      Apple also makes a lot of claims about PCC which are misleading at best, like their claims regarding the ability for independent security experts to audit Apple. While you can verify what binary images are running, they don’t have reproducible builds, the binaries contain no symbols; it would be very hard to verify that the binary images match Apple’s published specs, or whether Apple’s introduced any concerning changes or bugs in new images in a timely manner.

                      When data is not protected by raw mathematical encryption, it is always fundamentally at risk when being handled by a third party regardless of data protection safeguards they’ve put in place.

                      (This is not to mention the issue of Apple normalizing this behavior, which will lead Google and Samsung et al. to make their own versions way worse than even PCC)

                      @Em0nM4stodon

                      codinghorror@infosec.exchangeC 1 Reply Last reply
                      0
                      • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange

                        @gruber Storing on iCloud with end-to-end encryption is still storing on their servers.

                        acdha@code4lib.socialA This user is from outside of this forum
                        acdha@code4lib.socialA This user is from outside of this forum
                        acdha@code4lib.social
                        wrote sidst redigeret af
                        #50

                        @Em0nM4stodon @gruber the primary reason why privacy advocates care about data on servers is when that data is accessible to third parties. End to end encrypted data is not.

                        The things to be concerned about here are things like transcription errors or defects allowing access by apps.

                        extra_special_carbon@mastodon.worldE 1 Reply Last reply
                        0
                        • katzedecimal@kind.socialK katzedecimal@kind.social

                          @Em0nM4stodon
                          My spouse brought this up with his cardiologist, whose office relies on Google for everything & has Google "smart" shit everywhere.

                          The office barred my spouse from returning. Yes, they fired my spouse, their patient, because he brought up privacy concerns, because Google doesn't respect the laws of their own country, let alone ours, let alone anyone else's. This is going to be a massive problem.

                          idlebrain@infosec.exchangeI This user is from outside of this forum
                          idlebrain@infosec.exchangeI This user is from outside of this forum
                          idlebrain@infosec.exchange
                          wrote sidst redigeret af
                          #51

                          @Katzedecimal @Em0nM4stodon
                          Sounds like a legal nightmare waiting to happen. (Pipeda/HIPAA/etc)

                          1 Reply Last reply
                          0
                          • jonah@mastodon.neat.computerJ jonah@mastodon.neat.computer

                            @gruber “by design” means nothing, when what’s designed today can be redesigned by Apple tomorrow, and it places a lot of trust in Apple, Nvidia, Google, and Intel to ALL not have fucked up their designs somewhere along the way.

                            None of them have a sterling privacy reputation in the first place, but *especially* not Apple on the server side of things, with Private Relay, Hide My Email, and Siri itself all having very notable slip-ups recently.

                            Apple also makes a lot of claims about PCC which are misleading at best, like their claims regarding the ability for independent security experts to audit Apple. While you can verify what binary images are running, they don’t have reproducible builds, the binaries contain no symbols; it would be very hard to verify that the binary images match Apple’s published specs, or whether Apple’s introduced any concerning changes or bugs in new images in a timely manner.

                            When data is not protected by raw mathematical encryption, it is always fundamentally at risk when being handled by a third party regardless of data protection safeguards they’ve put in place.

                            (This is not to mention the issue of Apple normalizing this behavior, which will lead Google and Samsung et al. to make their own versions way worse than even PCC)

                            @Em0nM4stodon

                            codinghorror@infosec.exchangeC This user is from outside of this forum
                            codinghorror@infosec.exchangeC This user is from outside of this forum
                            codinghorror@infosec.exchange
                            wrote sidst redigeret af
                            #52

                            @jonah @gruber @Em0nM4stodon pick your poison. I mean, the company (previously) led by the gay man who grew up in the absolutely vicious, hate-filled american south, kinda got my vote on "who's gonna care most about privacy" issue in the past.

                            jonah@mastodon.neat.computerJ tmw@ioc.exchangeT 2 Replies Last reply
                            0
                            • codinghorror@infosec.exchangeC codinghorror@infosec.exchange

                              @jonah @gruber @Em0nM4stodon pick your poison. I mean, the company (previously) led by the gay man who grew up in the absolutely vicious, hate-filled american south, kinda got my vote on "who's gonna care most about privacy" issue in the past.

                              jonah@mastodon.neat.computerJ This user is from outside of this forum
                              jonah@mastodon.neat.computerJ This user is from outside of this forum
                              jonah@mastodon.neat.computer
                              wrote sidst redigeret af
                              #53

                              @codinghorror sure, compared to the other big tech companies Apple is pretty great. But compared to not doing this at all, this is a bad move.

                              And still, I frankly do not trust Apple to secure a server as much as I trust them to secure a local device lol

                              @gruber @Em0nM4stodon

                              1 Reply Last reply
                              0
                              • codinghorror@infosec.exchangeC codinghorror@infosec.exchange

                                @jonah @gruber @Em0nM4stodon pick your poison. I mean, the company (previously) led by the gay man who grew up in the absolutely vicious, hate-filled american south, kinda got my vote on "who's gonna care most about privacy" issue in the past.

                                tmw@ioc.exchangeT This user is from outside of this forum
                                tmw@ioc.exchangeT This user is from outside of this forum
                                tmw@ioc.exchange
                                wrote sidst redigeret af
                                #54

                                @codinghorror wait... what?! this is such a bizarre take and we have so much evidence against it. look at grindr crashing almost every time there's some republican meetup. almost none of those guys are out of the closet and they certainly don't care about americans' privacy.

                                i don't know tim cook's backstory but a lot of us can mask pretty well

                                peter thiel is gay and is behind freaking palantir

                                we ain't all angels

                                codinghorror@infosec.exchangeC 1 Reply Last reply
                                0
                                • tmw@ioc.exchangeT tmw@ioc.exchange

                                  @codinghorror wait... what?! this is such a bizarre take and we have so much evidence against it. look at grindr crashing almost every time there's some republican meetup. almost none of those guys are out of the closet and they certainly don't care about americans' privacy.

                                  i don't know tim cook's backstory but a lot of us can mask pretty well

                                  peter thiel is gay and is behind freaking palantir

                                  we ain't all angels

                                  codinghorror@infosec.exchangeC This user is from outside of this forum
                                  codinghorror@infosec.exchangeC This user is from outside of this forum
                                  codinghorror@infosec.exchange
                                  wrote sidst redigeret af
                                  #55

                                  @tmw look into his backstory. everyone's backstory tells you a lot about who they are and what they become

                                  tmw@ioc.exchangeT 1 Reply Last reply
                                  0
                                  • codinghorror@infosec.exchangeC codinghorror@infosec.exchange

                                    @tmw look into his backstory. everyone's backstory tells you a lot about who they are and what they become

                                    tmw@ioc.exchangeT This user is from outside of this forum
                                    tmw@ioc.exchangeT This user is from outside of this forum
                                    tmw@ioc.exchange
                                    wrote sidst redigeret af
                                    #56

                                    @codinghorror it tells you about who the narrator wants you to believe that the person was in the past. unless you believe that people can't change and that retellings are infallible, it doesn't tell you that much about how they really are

                                    (that much is, well... private!)

                                    codinghorror@infosec.exchangeC 1 Reply Last reply
                                    0
                                    • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange

                                      Imagine you're having a remote appointment with your doctor for a very personal health issue.

                                      Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.

                                      You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.

                                      The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.

                                      "What about all the privacy laws protecting me?", you claim in distress.

                                      Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"

                                      The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.

                                      Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.

                                      This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.

                                      Brace yourself.

                                      #Privacy #Security #Consent #Apple

                                      mydoomfr@mamot.frM This user is from outside of this forum
                                      mydoomfr@mamot.frM This user is from outside of this forum
                                      mydoomfr@mamot.fr
                                      wrote sidst redigeret af
                                      #57

                                      @Em0nM4stodon Imagine your doctor avoids an "overpriced Apple product" and uses a 2y old Huawei phone/watch that no longer gets updates, with apps and access to work email

                                      Imagine there is an LG TV in the room. Given the current controversy around LG TVs allegedly listening or collecting data ; what could go wrong?

                                      Or his laptop still runs Windows 7 because "it works fine", with years of random software installed.

                                      My point: this isn't an Apple problem

                                      1 Reply Last reply
                                      0
                                      • tmw@ioc.exchangeT tmw@ioc.exchange

                                        @codinghorror it tells you about who the narrator wants you to believe that the person was in the past. unless you believe that people can't change and that retellings are infallible, it doesn't tell you that much about how they really are

                                        (that much is, well... private!)

                                        codinghorror@infosec.exchangeC This user is from outside of this forum
                                        codinghorror@infosec.exchangeC This user is from outside of this forum
                                        codinghorror@infosec.exchange
                                        wrote sidst redigeret af
                                        #58

                                        @tmw and if the narrator is the person themselves? This is a massively reductive take.

                                        1 Reply Last reply
                                        0
                                        • acdha@code4lib.socialA acdha@code4lib.social

                                          @Em0nM4stodon @gruber the primary reason why privacy advocates care about data on servers is when that data is accessible to third parties. End to end encrypted data is not.

                                          The things to be concerned about here are things like transcription errors or defects allowing access by apps.

                                          extra_special_carbon@mastodon.worldE This user is from outside of this forum
                                          extra_special_carbon@mastodon.worldE This user is from outside of this forum
                                          extra_special_carbon@mastodon.world
                                          wrote sidst redigeret af
                                          #59

                                          @acdha @Em0nM4stodon @gruber I liken this to the AirTag issue. Everyone was really shocked at the potential harm with AirTag, but Apple put in some pretty strong protections, such as notifying you when one was following you. The notification freaked people out more.

                                          Meanwhile, Tag has been sold for years, and provided zero safety features. So imagine it’s not an Apple watch but something offbrand that nobody is thinking of.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper