> Apple maintains that it "takes steps to ensure that personal data is not stored or used by Apple."
-
I’m sure the company that failed to implement anonymous email addresses and a VPN that doesn’t leak your IP is perfectly capable of keeping a constant stream of your personal information, recording of your audio surroundings, and permanent metadata correlating your photos with your device, safe
@zzt Big Tech is the Governments Big Brother
-
I’m sure the company that failed to implement anonymous email addresses and a VPN that doesn’t leak your IP is perfectly capable of keeping a constant stream of your personal information, recording of your audio surroundings, and permanent metadata correlating your photos with your device, safe
all the infosec boys going “oh apple private cloud is the best, you can’t deny it’s the best way to do this” and the “this” is something that shouldn’t be done
it’s also closed infrastructure you can’t actually evaluate from outside of apple so I’m confused why any of them think the whitepapers are anything other than fantasy
-
all the infosec boys going “oh apple private cloud is the best, you can’t deny it’s the best way to do this” and the “this” is something that shouldn’t be done
it’s also closed infrastructure you can’t actually evaluate from outside of apple so I’m confused why any of them think the whitepapers are anything other than fantasy
@zzt@mas.to "private cloud" sounds like peak oxymoron
-
@zzt Big Tech is the Governments Big Brother
@zzt “look see you don’t gotta give em consent you can lie to em, i do it all the time”
-
@zzt@mas.to "private cloud" sounds like peak oxymoron
@freyalikesgirls it’s ridiculous on the face of it
like, we trust open source end to end encrypted systems because we can verify our end, and we can verify that the system mathematically doesn’t function unless encryption is happening as described, and we can assume that the other end isn’t mishandling data (or more accurately we can factor that into our threat model: the other side can be compromised, and we can’t necessarily solve that risk entirely technically)
we can’t verify any of that for iOS
-
@freyalikesgirls it’s ridiculous on the face of it
like, we trust open source end to end encrypted systems because we can verify our end, and we can verify that the system mathematically doesn’t function unless encryption is happening as described, and we can assume that the other end isn’t mishandling data (or more accurately we can factor that into our threat model: the other side can be compromised, and we can’t necessarily solve that risk entirely technically)
we can’t verify any of that for iOS
@zzt@mas.to i'm so sick of <big asshole tech corpo> and how much they treat everyone like shit
-
@freyalikesgirls it’s ridiculous on the face of it
like, we trust open source end to end encrypted systems because we can verify our end, and we can verify that the system mathematically doesn’t function unless encryption is happening as described, and we can assume that the other end isn’t mishandling data (or more accurately we can factor that into our threat model: the other side can be compromised, and we can’t necessarily solve that risk entirely technically)
we can’t verify any of that for iOS
@freyalikesgirls like, it’s a fair bet that WhatsApp is end to end encrypted and that the features that aren’t Facebook originals are probably as securely encrypted as signal protocol data, because WhatsApp uses a mild variant of the signal protocol
it’s also a fair bet that all ends of a WhatsApp chat are having their data exfiltrated by the WhatsApp client, because that’s what Facebook habitually does. that is how they make money.
a thing can look like it implements perfectly good encryption and still leak all the data that goes into it
-
@freyalikesgirls like, it’s a fair bet that WhatsApp is end to end encrypted and that the features that aren’t Facebook originals are probably as securely encrypted as signal protocol data, because WhatsApp uses a mild variant of the signal protocol
it’s also a fair bet that all ends of a WhatsApp chat are having their data exfiltrated by the WhatsApp client, because that’s what Facebook habitually does. that is how they make money.
a thing can look like it implements perfectly good encryption and still leak all the data that goes into it
@zzt@mas.to tbh whatsapp doesnt look like shit, i cant see any of whats inside
-
@zzt oh, it’s even SO MUCH WORSE :
https://cupoftea.social/@Erased_Citizen/117276446682733552
yeah. “connection assist” is gonna exfiltrate even if you think you have a pi-hole. ios 27 will send your data via cell plan.
3^3 is Big Brother’s favorite number, apparently
@cmdrmoto @zzt That’s not a new feature. It used to be called Wi-Fi Assist. I don’t know what changed in iOS 27 besides the name.
I use NextDNS, and they have a configuration profile that applies their DoH servers at the OS level regardless of which network I’m on. Still, I’m planning on switching to Pi-hole when my subscription expires, so this is good to know.
-
@zzt oh, it’s even SO MUCH WORSE :
https://cupoftea.social/@Erased_Citizen/117276446682733552
yeah. “connection assist” is gonna exfiltrate even if you think you have a pi-hole. ios 27 will send your data via cell plan.
3^3 is Big Brother’s favorite number, apparently
@cmdrmoto @zzt JFC, doing it that way is completely unreasonable. Android's implementation is somewhat more reasonable, if a bit more "brute-force," switching entirely to cellular when the network quality drops too low, rather than actively working around the network administrator's controls while still using that network... (And AFAIK it goes off radio alone?)
Though I wonder exactly how pi-hole implements the blocking? Is it dropped requests, bogus nxdomain, or some other response? Because how intentionally malicious that "feature" is depends on how reasonable it is to see those blocks as network-level errors.
If it's responding with spoofed valid responses like nxdomain, or an empty "no error" response, there is no legitimate reason to query another resolver outside of bypassing dns-level blocking.
But if it's implementing the blocking by refusing queries for those domains rather than spoofing a 'valid' response, I could see a reasonable device interpreting it that as a broken resolver.
-
@cmdrmoto @zzt JFC, doing it that way is completely unreasonable. Android's implementation is somewhat more reasonable, if a bit more "brute-force," switching entirely to cellular when the network quality drops too low, rather than actively working around the network administrator's controls while still using that network... (And AFAIK it goes off radio alone?)
Though I wonder exactly how pi-hole implements the blocking? Is it dropped requests, bogus nxdomain, or some other response? Because how intentionally malicious that "feature" is depends on how reasonable it is to see those blocks as network-level errors.
If it's responding with spoofed valid responses like nxdomain, or an empty "no error" response, there is no legitimate reason to query another resolver outside of bypassing dns-level blocking.
But if it's implementing the blocking by refusing queries for those domains rather than spoofing a 'valid' response, I could see a reasonable device interpreting it that as a broken resolver.
@becomethewaifu @cmdrmoto @zzt Responses by pihole are configurable. Iirc the default is nxdomain, but it could also reply with 0.0.0.0
-
@becomethewaifu @cmdrmoto @zzt Responses by pihole are configurable. Iirc the default is nxdomain, but it could also reply with 0.0.0.0
@becomethewaifu @cmdrmoto @zzt Nvm, it answers with 0.0.0.0 by default.
-
@zzt "yes" or "yes but later" is the sort of thing that should get someone [ reacted ].
@shnizmuffin @zzt this is Mastodon, if you need to redact it, you should move to a new instance lol (and you're the instance owner so I hope you're allowed to say it!)
it should get you dragged out in the street and shot
-
@becomethewaifu @cmdrmoto @zzt Responses by pihole are configurable. Iirc the default is nxdomain, but it could also reply with 0.0.0.0
@tsrberry @cmdrmoto @zzt Since
0.0.0.0isn't a valid IP for DNS, I could reasonably see that being interpreted as "this resolver is doing something dumb" rather than "this record was intentionally blocked." I'd try nxdomain or NODATA, and if it's doing this for those? It's either vibecoded to retry-on-cellular for any DNS error, not just plausibly "crap network" ones, or it was written to intentionally subvert network administrator control...Though after thinking about it a bit, it could also be looking for dnssec signatures? pi-hole necessarily has to break those to block things after all. I'd have to sniff every DNS request the phone makes to be sure (not particularly difficult with my network, but I don't have an iphone to actually do that with...) but it's entirely plausible for apple's "security focus" to forget that network administrators intentionally break it sometimes.
-
@shnizmuffin @zzt this is Mastodon, if you need to redact it, you should move to a new instance lol (and you're the instance owner so I hope you're allowed to say it!)
it should get you dragged out in the street and shot
-
@shnizmuffin @zzt we are all on lists anyways you might as well not self-censor short of actually self-incriminating
the blue hellsites do it for advertisers, not the feds. -
@shnizmuffin @zzt we are all on lists anyways you might as well not self-censor short of actually self-incriminating
the blue hellsites do it for advertisers, not the feds.Sup feds! @tael takes responsibility for all my drunk toots
-
Sup feds! @tael takes responsibility for all my drunk toots
@shnizmuffin I'll also take responsibility for the posts your algorithm shows you
-
@shnizmuffin I'll also take responsibility for the posts your algorithm shows you
@tael the only algorithm I've got going is @fantasyfootballnewswire telling me how absolutely fucked I am.
-
@tael the only algorithm I've got going is @fantasyfootballnewswire telling me how absolutely fucked I am.
@shnizmuffin @fantasyfootballnewswire exactly