Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. > Apple maintains that it "takes steps to ensure that personal data is not stored or used by Apple."

> Apple maintains that it "takes steps to ensure that personal data is not stored or used by Apple."

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
34 Indlæg 14 Posters 1 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • cmdrmoto@hachyderm.ioC cmdrmoto@hachyderm.io

    @zzt oh, it’s even SO MUCH WORSE :

    https://cupoftea.social/@Erased_Citizen/117276446682733552

    yeah. “connection assist” is gonna exfiltrate even if you think you have a pi-hole. ios 27 will send your data via cell plan.

    3^3 is Big Brother’s favorite number, apparently

    becomethewaifu@tech.lgbtB This user is from outside of this forum
    becomethewaifu@tech.lgbtB This user is from outside of this forum
    becomethewaifu@tech.lgbt
    wrote sidst redigeret af
    #17

    @cmdrmoto @zzt JFC, doing it that way is completely unreasonable. Android's implementation is somewhat more reasonable, if a bit more "brute-force," switching entirely to cellular when the network quality drops too low, rather than actively working around the network administrator's controls while still using that network... (And AFAIK it goes off radio alone?)

    Though I wonder exactly how pi-hole implements the blocking? Is it dropped requests, bogus nxdomain, or some other response? Because how intentionally malicious that "feature" is depends on how reasonable it is to see those blocks as network-level errors.

    If it's responding with spoofed valid responses like nxdomain, or an empty "no error" response, there is no legitimate reason to query another resolver outside of bypassing dns-level blocking.

    But if it's implementing the blocking by refusing queries for those domains rather than spoofing a 'valid' response, I could see a reasonable device interpreting it that as a broken resolver.

    tsrberry@ravenation.clubT h@is-a.catinsi.deH 2 Replies Last reply
    0
    • becomethewaifu@tech.lgbtB becomethewaifu@tech.lgbt

      @cmdrmoto @zzt JFC, doing it that way is completely unreasonable. Android's implementation is somewhat more reasonable, if a bit more "brute-force," switching entirely to cellular when the network quality drops too low, rather than actively working around the network administrator's controls while still using that network... (And AFAIK it goes off radio alone?)

      Though I wonder exactly how pi-hole implements the blocking? Is it dropped requests, bogus nxdomain, or some other response? Because how intentionally malicious that "feature" is depends on how reasonable it is to see those blocks as network-level errors.

      If it's responding with spoofed valid responses like nxdomain, or an empty "no error" response, there is no legitimate reason to query another resolver outside of bypassing dns-level blocking.

      But if it's implementing the blocking by refusing queries for those domains rather than spoofing a 'valid' response, I could see a reasonable device interpreting it that as a broken resolver.

      tsrberry@ravenation.clubT This user is from outside of this forum
      tsrberry@ravenation.clubT This user is from outside of this forum
      tsrberry@ravenation.club
      wrote sidst redigeret af
      #18

      @becomethewaifu @cmdrmoto @zzt Responses by pihole are configurable. Iirc the default is nxdomain, but it could also reply with 0.0.0.0

      tsrberry@ravenation.clubT becomethewaifu@tech.lgbtB 2 Replies Last reply
      0
      • tsrberry@ravenation.clubT tsrberry@ravenation.club

        @becomethewaifu @cmdrmoto @zzt Responses by pihole are configurable. Iirc the default is nxdomain, but it could also reply with 0.0.0.0

        tsrberry@ravenation.clubT This user is from outside of this forum
        tsrberry@ravenation.clubT This user is from outside of this forum
        tsrberry@ravenation.club
        wrote sidst redigeret af
        #19

        @becomethewaifu @cmdrmoto @zzt Nvm, it answers with 0.0.0.0 by default.

        1 Reply Last reply
        0
        • shnizmuffin@toots.inbutts.lolS shnizmuffin@toots.inbutts.lol

          @zzt "yes" or "yes but later" is the sort of thing that should get someone [ reacted ].

          tael@yiff.lifeT This user is from outside of this forum
          tael@yiff.lifeT This user is from outside of this forum
          tael@yiff.life
          wrote sidst redigeret af
          #20

          @shnizmuffin @zzt this is Mastodon, if you need to redact it, you should move to a new instance lol (and you're the instance owner so I hope you're allowed to say it!)

          it should get you dragged out in the street and shot

          shnizmuffin@toots.inbutts.lolS 1 Reply Last reply
          0
          • tsrberry@ravenation.clubT tsrberry@ravenation.club

            @becomethewaifu @cmdrmoto @zzt Responses by pihole are configurable. Iirc the default is nxdomain, but it could also reply with 0.0.0.0

            becomethewaifu@tech.lgbtB This user is from outside of this forum
            becomethewaifu@tech.lgbtB This user is from outside of this forum
            becomethewaifu@tech.lgbt
            wrote sidst redigeret af
            #21

            @tsrberry @cmdrmoto @zzt Since 0.0.0.0 isn't a valid IP for DNS, I could reasonably see that being interpreted as "this resolver is doing something dumb" rather than "this record was intentionally blocked." I'd try nxdomain or NODATA, and if it's doing this for those? It's either vibecoded to retry-on-cellular for any DNS error, not just plausibly "crap network" ones, or it was written to intentionally subvert network administrator control...

            Though after thinking about it a bit, it could also be looking for dnssec signatures? pi-hole necessarily has to break those to block things after all. I'd have to sniff every DNS request the phone makes to be sure (not particularly difficult with my network, but I don't have an iphone to actually do that with...) but it's entirely plausible for apple's "security focus" to forget that network administrators intentionally break it sometimes.

            1 Reply Last reply
            0
            • tael@yiff.lifeT tael@yiff.life

              @shnizmuffin @zzt this is Mastodon, if you need to redact it, you should move to a new instance lol (and you're the instance owner so I hope you're allowed to say it!)

              it should get you dragged out in the street and shot

              shnizmuffin@toots.inbutts.lolS This user is from outside of this forum
              shnizmuffin@toots.inbutts.lolS This user is from outside of this forum
              shnizmuffin@toots.inbutts.lol
              wrote sidst redigeret af
              #22

              @tael @zzt as an instance owner, it's literally my door they'd kick in. toots.inbutts.lol lives right next to my HVAC.

              tael@yiff.lifeT 1 Reply Last reply
              0
              • shnizmuffin@toots.inbutts.lolS shnizmuffin@toots.inbutts.lol

                @tael @zzt as an instance owner, it's literally my door they'd kick in. toots.inbutts.lol lives right next to my HVAC.

                tael@yiff.lifeT This user is from outside of this forum
                tael@yiff.lifeT This user is from outside of this forum
                tael@yiff.life
                wrote sidst redigeret af
                #23

                @shnizmuffin @zzt we are all on lists anyways you might as well not self-censor short of actually self-incriminating 😛 the blue hellsites do it for advertisers, not the feds.

                shnizmuffin@toots.inbutts.lolS 1 Reply Last reply
                0
                • tael@yiff.lifeT tael@yiff.life

                  @shnizmuffin @zzt we are all on lists anyways you might as well not self-censor short of actually self-incriminating 😛 the blue hellsites do it for advertisers, not the feds.

                  shnizmuffin@toots.inbutts.lolS This user is from outside of this forum
                  shnizmuffin@toots.inbutts.lolS This user is from outside of this forum
                  shnizmuffin@toots.inbutts.lol
                  wrote sidst redigeret af
                  #24

                  Sup feds! @tael takes responsibility for all my drunk toots

                  tael@yiff.lifeT 1 Reply Last reply
                  0
                  • shnizmuffin@toots.inbutts.lolS shnizmuffin@toots.inbutts.lol

                    Sup feds! @tael takes responsibility for all my drunk toots

                    tael@yiff.lifeT This user is from outside of this forum
                    tael@yiff.lifeT This user is from outside of this forum
                    tael@yiff.life
                    wrote sidst redigeret af
                    #25

                    @shnizmuffin I'll also take responsibility for the posts your algorithm shows you

                    shnizmuffin@toots.inbutts.lolS 1 Reply Last reply
                    0
                    • tael@yiff.lifeT tael@yiff.life

                      @shnizmuffin I'll also take responsibility for the posts your algorithm shows you

                      shnizmuffin@toots.inbutts.lolS This user is from outside of this forum
                      shnizmuffin@toots.inbutts.lolS This user is from outside of this forum
                      shnizmuffin@toots.inbutts.lol
                      wrote sidst redigeret af
                      #26

                      @tael the only algorithm I've got going is @fantasyfootballnewswire telling me how absolutely fucked I am.

                      tael@yiff.lifeT 1 Reply Last reply
                      0
                      • shnizmuffin@toots.inbutts.lolS shnizmuffin@toots.inbutts.lol

                        @tael the only algorithm I've got going is @fantasyfootballnewswire telling me how absolutely fucked I am.

                        tael@yiff.lifeT This user is from outside of this forum
                        tael@yiff.lifeT This user is from outside of this forum
                        tael@yiff.life
                        wrote sidst redigeret af
                        #27

                        @shnizmuffin @fantasyfootballnewswire exactly

                        shnizmuffin@toots.inbutts.lolS 1 Reply Last reply
                        0
                        • tael@yiff.lifeT tael@yiff.life

                          @shnizmuffin @fantasyfootballnewswire exactly

                          shnizmuffin@toots.inbutts.lolS This user is from outside of this forum
                          shnizmuffin@toots.inbutts.lolS This user is from outside of this forum
                          shnizmuffin@toots.inbutts.lol
                          wrote sidst redigeret af
                          #28

                          @tael @fantasyfootballnewswire please un-sprain AJ Brown's ankle.

                          1 Reply Last reply
                          0
                          • becomethewaifu@tech.lgbtB becomethewaifu@tech.lgbt

                            @cmdrmoto @zzt JFC, doing it that way is completely unreasonable. Android's implementation is somewhat more reasonable, if a bit more "brute-force," switching entirely to cellular when the network quality drops too low, rather than actively working around the network administrator's controls while still using that network... (And AFAIK it goes off radio alone?)

                            Though I wonder exactly how pi-hole implements the blocking? Is it dropped requests, bogus nxdomain, or some other response? Because how intentionally malicious that "feature" is depends on how reasonable it is to see those blocks as network-level errors.

                            If it's responding with spoofed valid responses like nxdomain, or an empty "no error" response, there is no legitimate reason to query another resolver outside of bypassing dns-level blocking.

                            But if it's implementing the blocking by refusing queries for those domains rather than spoofing a 'valid' response, I could see a reasonable device interpreting it that as a broken resolver.

                            h@is-a.catinsi.deH This user is from outside of this forum
                            h@is-a.catinsi.deH This user is from outside of this forum
                            h@is-a.catinsi.de
                            wrote sidst redigeret af
                            #29

                            @becomethewaifu@tech.lgbt @zzt@mas.to @cmdrmoto@hachyderm.io Not entirely relevant, since it's not the configuration of an end-user system running a corporate OS, but my desktop and other hosts I operate would not do well on a network with local DNS-based filtering, as they tend to be configured with a local recursive DNS resolver and their operator would respond to any non-DNS filtering observed by implementing circumvention tactics.

                            becomethewaifu@tech.lgbtB 1 Reply Last reply
                            0
                            • h@is-a.catinsi.deH h@is-a.catinsi.de

                              @becomethewaifu@tech.lgbt @zzt@mas.to @cmdrmoto@hachyderm.io Not entirely relevant, since it's not the configuration of an end-user system running a corporate OS, but my desktop and other hosts I operate would not do well on a network with local DNS-based filtering, as they tend to be configured with a local recursive DNS resolver and their operator would respond to any non-DNS filtering observed by implementing circumvention tactics.

                              becomethewaifu@tech.lgbtB This user is from outside of this forum
                              becomethewaifu@tech.lgbtB This user is from outside of this forum
                              becomethewaifu@tech.lgbt
                              wrote sidst redigeret af
                              #30

                              @h And since presumably you're a sentient creature that can know (or at least reasonably guess) why that block is in place before you bypass it, that's entirely between you and the network administrator. A mass-market device doing this autonomously is a whole different class of issue.

                              And I say that having mildly annoyed multiple network admins by doing the exact same thing... Thankfully they didn't really care as long as I kept it quiet.

                              1 Reply Last reply
                              0
                              • zzt@mas.toZ zzt@mas.to

                                so the new iOS has data exfiltration in apple intelligence, always-on audio recording, photos that can be permanently correlated with your specific device, and a connection assist feature (which I’m assuming is enabled by default) that breaks all of your attempts to intentionally filter what’s coming in on your connection

                                have I missed any forms of surveillance? who is all this shit for?

                                fivetonsflax@tilde.zoneF This user is from outside of this forum
                                fivetonsflax@tilde.zoneF This user is from outside of this forum
                                fivetonsflax@tilde.zone
                                wrote sidst redigeret af
                                #31

                                @zzt their doc says connectivity assist is on if you had wi-fi assist on, off otherwise, fwiw https://support.apple.com/en-us/127686

                                1 Reply Last reply
                                0
                                • zzt@mas.toZ zzt@mas.to

                                  I’m sure the company that failed to implement anonymous email addresses and a VPN that doesn’t leak your IP is perfectly capable of keeping a constant stream of your personal information, recording of your audio surroundings, and permanent metadata correlating your photos with your device, safe

                                  hipsterelectron@circumstances.runH This user is from outside of this forum
                                  hipsterelectron@circumstances.runH This user is from outside of this forum
                                  hipsterelectron@circumstances.run
                                  wrote sidst redigeret af
                                  #32

                                  @zzt listening to @ashleygjovik is required reading for anyone who has thoughts on apple inc and i mean even if you really like apple you need to be able to incorporate her experience into your mental model

                                  moses_izumi@fe.disroot.orgM 1 Reply Last reply
                                  1
                                  0
                                  • hipsterelectron@circumstances.runH hipsterelectron@circumstances.run

                                    @zzt listening to @ashleygjovik is required reading for anyone who has thoughts on apple inc and i mean even if you really like apple you need to be able to incorporate her experience into your mental model

                                    moses_izumi@fe.disroot.orgM This user is from outside of this forum
                                    moses_izumi@fe.disroot.orgM This user is from outside of this forum
                                    moses_izumi@fe.disroot.org
                                    wrote sidst redigeret af
                                    #33
                                    @hipsterelectron @zzt @ashleygjovik
                                    what is her biggest bombshell about Apple?
                                    1 Reply Last reply
                                    0
                                    • zzt@mas.toZ zzt@mas.to

                                      most AI corps pretend not to train on user data. they’re lying, as has been proven repeatedly (most recently with the mathematicians’ codex data getting exfiltrated behind their backs), but they pretend not to

                                      apple isn’t even pretending, they need your data

                                      it doesn’t matter to them if someone else consented, or if your data or voice are being handled by someone else’s device, and they aren’t particularly subtle about the opt-in being temporary (“not now”)

                                      no, it’s not better that apple isn’t lying about it, they’re trying their hardest to normalize surveillance

                                      bosconet@ioc.exchangeB This user is from outside of this forum
                                      bosconet@ioc.exchangeB This user is from outside of this forum
                                      bosconet@ioc.exchange
                                      wrote sidst redigeret af
                                      #34

                                      @zzt I never believed them...

                                      But bigger risk is do they capture any confidential corp data in raw form for long enough to be part of a data breach

                                      1 Reply Last reply
                                      0
                                      • pelle@veganism.socialP pelle@veganism.social shared this topic
                                      Svar
                                      • Svar som emne
                                      Login for at svare
                                      • Ældste til nyeste
                                      • Nyeste til ældste
                                      • Most Votes


                                      • Log ind

                                      • Har du ikke en konto? Tilmeld

                                      • Login or register to search.
                                      Powered by NodeBB Contributors
                                      Graciously hosted by data.coop
                                      • First post
                                        Last post
                                      0
                                      • Hjem
                                      • Seneste
                                      • Etiketter
                                      • Populære
                                      • Verden
                                      • Bruger
                                      • Grupper