Hacker News new | past | comments | ask | show | jobs | submit | loteck's comments login

100% false headline. Where's the integrity, Verge?

Where'd you move to?


Connecticut - I've never felt safer walking around at 3 am and I've made more friends in the last 2 months (without trying) than I probably have in the last 6 years of living in the bay area.


Good to hear! Are the comparable areas of similar population density? I'm wondering what incremental steps (non-partisan hopefully) can be brought to the Bay Area to slowly move it towards a similar environment.


I lived in the Bay Area for about 30 years, so here's my (probably biased) opinion. The biggest issue is the lack of community, and in my experience, this is due to the high turnover of residents. From my high school graduating class of 400, fewer than 100 are still in the community; everyone else has moved to Florida, Phoenix, Austin, etc. You can't encourage long-term planning (good public education policies, systematic reductions in the drivers of crime, etc.) if the community changes every two decades. My personal opinion is that the Bay Area won't improve because everyone is out to get 'theirs' and then leave. While I do miss the weather, the lack of humidity, and, honestly, a more educated population, I believe raising children in a strong community is more important. So, I'm more than happy with the trade-offs for a better overall quality of life.


The incidental and systemic benefits of the recordings are exciting to people and celebrated with stories. The hazards of this constant "pollution" of data — how it is slowly changing our society, our economy, our humanity — is harder to quantify or build opposition to.

It's a bit like climate change. Slow, invisible poison.


Law simply needs to internalize encryption. Your cameras are your property and only with consent of owner are they available to authorities.

Public cameras should only be decrypted for evidence to support litigation of crimes, not for police to search for violay, because the current gigantic book of laws has an implicit assumption of a difficulty to enforce.

If suddenly police could use AI to fully prosecute all violations of law then we have all the laws necessary for worse than totalitarian existence.

Every mile you drove in a car will be 10 violations of law. Laugh loud? Violation disturbance of peace. Stand looking at your email too long? Loitering. Cross a park? Dozens of environmental violations.


This is already in the US Constitution. 4th Amendment.


Sure by some interpretations. Unfortunately the current SCOTUS doesn’t see it that way, they think webcams and electronic surveillance should be in the constitution or authorities can do anything. If there isn’t a law or constitutional text to the effect then it doesn’t exist to them. So we have to approach this from actually getting a law passed.


TFA is about camera footage obtained via warrant (thus following due process). Do you think evidence should not be obtainable via warrant?

> Unfortunately the current SCOTUS doesn’t see it that way, they think webcams and electronic surveillance should be in the constitution or authorities can do anything.

Citation needed.


> and celebrated with stories.

Are you sure those are organic?


I've definitely heard organic stories from people who got favorable insurance/legal outcomes after a traffic accident because they were using a dashcam. Generally, if you're not doing anything wrong, it is a good idea to record whatever you're doing, because it's proof that you're not doing anything wrong (police departments use this to great effect; they love bodycams in 99% of cases, and simply turn them off when they're about to do something that they wouldn't want to have a bodycam for). The negatives are second-order effects that only come about when everyone is doing it.


I’m sure the vast majority of them are. Occam’s razor version: fear sells. If you can appeal to the clutching pearls part of the psyche then you can win over people to the idea of constant surveillance as necessary because of the current “wave of crime”. No matter how much crime is down or how many rights have to be taken away for “public safety”. Most reporters are just trying to put food on the table and outside of freedom of the press they couldn’t care less.


s/poison/vitamin/ and you'll be happier.


Double plus good idea, fine chap!


I mean, yes, we'd like to replace poison with vitamins, but that requires some serious changes.


Privacy and security here are being commingled under the banner of AES encryption at rest, which is apparently disabled by default.

I always wonder, if your marketing pitch involves security features, but those features are off by default, aren't you technically pitching your lack of security?


Encryption at rest is disabled by default because many users do not want to keep track of all of their encryption keys, which are not stored by Horizon when that setting is enabled.

There are also other security features, like end-to-end encryption for pastes, but like mentioned before, not everyone wants to lose the ability to preview their content in the dashboard.

By giving the user a choice, I can cater to both crowds: one that prefers convenience, vs the other which prefers the most security.

Edit: To clarify, all files are already encrypted at rest with a key I control. But with Encryption enabled (capital E to distinguish the feature name), it is encrypted again with a key Horizon won't store.


Have you done an Independent security review of these features? What's your CRS score? Do you have CVE fix SLA in place? All these features are good if this was. 2000 website but a single vulnerability in any one of the vendors of your tech stack will compromise your users


Server side encryption is handled using the Go standard library. A more detailed breakdown of the process can be found in the Help Center. TLDR: It's reputable, and best practices are followed through cryptographically secure generation, random IV, high entropy keys, memory hard hashing, etc.

Paste end to end encryption uses the native window crypto subtle API, widely used and reputable.


Coming from cyber security one thing I have learnt is no matter how many layers of security you add nothing is fool proof, I would strongly recommend doing an Independent review getting if not an international certification like ISO or GDPR then something domestic, I like what Mozilla does https://www.mozilla.org/en-US/security/advisories/, this really will enforce trust in your users as today it's really hard to trust websites


Clear and concise. Well done. Impressive for a 17 year old.


And if $company controls the keys.. what happens once funding dries up? Yeah.. nothing personal but we've seen it previously.

In the meantime, OP and Co. could create an open standard for image hosting, and have a lasting impact on the order of S3. Wouldn't that be something?

Here's to hoping.


Congrats on the app! I don't think I've ever clicked into a privacy policy so quickly.


Thank you so much!


This tech has proliferated across cities in the US by claiming to be a "force multiplier". That's supposed to mean it makes police more effective at their mission without actually adding any additional headcount.

But if 70-90% of the time the tech is sending police on goose chases that end with no findings, it seems like "force multiplier" falls into one of those marketing buckets where the truth is the exact opposite. The tech actually divides police from the mission.

Many, many cities are siphoning off public taxpayer dollars and sending them to this company.


Some good comments on this from cryptographer Matt Green here: https://x.com/matthew_d_green/status/1800291897245835616?t=C...

(I wonder if Matt realizes nobody can read his tweets without a X account? Use BlueSky or Masto man)

Edit: here's his thread combined https://threadreaderapp.com/thread/1800291897245835616.html?...


If he really wanted no one to be reading his tweets he’d be using BluSky or Masto…


https://infosec.exchange/ has a ton of infosec people, big names.

https://ioc.exchange/@matthew_d_green - And he's there BTW :)


Is there more to that thread? I can't read it if it exists, not sure if that is what the parent is talking about? But i don't have a Twitter account anymore, so maybe it's locked?


Without being logged into X, you can only see the first post in a thread.


Not even that anymore, all links show is "Something went wrong, but don’t fret — let’s give it another shot."

Impossible to see any content.


That's likely due to tracking prevention or protection by your browser because X really, really wants to track you. If you disable the tracking protection and related settings, you may be able to see the single tweet.


I don't know what you're seeing. It's a very long thread. Exceptionally good take on the whole thing. Apple has gone way out of their way to try and sell this thing. Above and beyond compared to how I imagine Microsoft or Google would have tackled this.


If your AI model sucks, you have to use other gimmicks to lure customers. That's marketing 101.

Create irrational fear about piracy, push privacy focused products and profits as the sheeple promptly fall for this


I've never seen someone use "sheeple" in an anti-privacy argument.


the most successful sheeple operation is the one the sheeple and the entire world is completely oblivious of it.

jokes aside, this is no different from people selling bunker beds, gold, ammunition, crypto, vpns. It is specifically for the set of gullible people who think they and their data is so important. Reality (except for 10,000 people or so) is, most lives and their 'precious' data is worthless. (I'm not talking about SSN, Bank Accounts -- those are well protected by tech cos HN seem to hate on)


Ok that made me spill my coffee.


Or maybe (gasp!) a blog?


These two tweets stand out for me:

> Ok there are probably half a dozen more technical details in the blog post. It’s a very thoughtful design. Indeed, if you gave an excellent team a huge pile of money and told them to build the best “private” cloud in the world, it would probably look like this.

and

> And of course, keep in mind that super-spies aren’t your biggest adversary. For many people your biggest adversary is the company who sold you your device/software. This PCC system represents a real commitment by Apple not to “peek” at your data. That’s a big deal.

I'd prefer things stay on the device but at least this is a big commitment in the right direction - or in the wrong direction but done better than their competitors, I'm not sure which.


Thanks for the link.

> As best I can tell, Apple does not have explicit plans to announce when your data is going off-device for to Private Compute. You won't opt into this, you won't necessarily even be told it's happening. It will just happen. Magically.

Presumably it will be possible to opt out of AI features entirely, i.e. both on-device and off-device?

Why would a device vendor not have an option for on-device AI only? iOS 17 AI features can be used today without iCloud.

Hopefully Apple uses a unique domain (e.g. *.pcc.apple.com) that can be filtered at the network level.


I think the main reason might be the on-device AI is fairly limited features wise. For Apple to actually offer something useful they would need to switch between device/server constantly and they don't want to limit the product by allowing users to disable going to a server.

With OpenAI calls is different because the privacy point is stronger


You would have to activate a clearly LLM-powered software feature and have internet access. I don't know if settings will appear to disable this, but you could imagine it would be the case. This isn't just siphoning off all your data at random.


Would Spotlight be considered a "clearly LLM-powered software feature"? Will there be an option for "non-AI Spotlight"? Disabling dozens of software features, or identifying all apps which might use LLM services, is a daunting proposition. It would be good to have a PCC kill switch, which makes opt-in usage meaningful, rather than forced.


Privacy "consent" is fundamentally broken. We've moved from "we're doing whatever the fuck we want" to "we're doing whatever the fuck we want, but on paper it's whatever the fuck you expressly asked for, whether you wanted to or not."


Almost certainly you will be able to disable it entirely and hide the UI to re-enable it via provisioning profiles via Apple Configurator 2 or MDM.

This is actually what you have to do now if you don’t want Siri and Mail to leak your address book to Apple.


> if you don’t want Siri and Mail to leak your address book to Apple.

By disabling Siri and iCloud, or other policies?


If you have no threat model and want to opt out of random features just because... you probably shouldn't use Apple products at all. Or Google or Microsoft.


For years, Apple has a documented set of security policies to disable off-device processing (e.g iCloud, Siri), via MDM / Apple Configurator. Apple also published details needed for enterprise network filtering to limit Apple telemetry, if all you want from Apple servers are software security updates and notifications.

With a hardened configuration, Apple has world-class device security. In time, remote PCC may prove as robust against real-world threats. Until then, it would be good to retain on-device security policy and choice for remote computation.


Apple does not publish details to limit telemetry. Nowhere in MDM or in their docs do they tell you that you can safely block xp.apple.com (telemetry) but not gs.apple.com (boot ticket signing server for updates).


Thanks, both are listed as required for software updates, https://support.apple.com/en-us/101555

Is there a good non-Apple reference for the functions performed by their servers?


"I wonder if Matt realises nobody can read his tweets without a X account?"

https://nitter.poast.org/matthew_d_green/status/180029189724...


Thanks. I wonder how long that service is going to last.


its been around a loong time


> (I wonder if Matt realizes nobody can read his tweets without a X account? Use BlueSky or Masto man)

He actually has an active Mastodon account, but this particular story is not on there (yet): https://ioc.exchange/@matthew_d_green


Inactive since 2 months


You were right until a couple of hours ago. Then this happened: https://ioc.exchange/@matthew_d_green/112597917470493480



He's not wrong that, given that you want to do this, this is the best way. The alternative would be to not do it at all (though an opt-out would have been good).


Beyond all the hardware complexity, another attack vector is the network infrastructure.


That is covered in the article.


Threads also is popular.

Probably the mainstream Twitter alternative at this point?


Threads is far from mainstream and just filled with spam and OnlyFans spammers at this point.


By every metric Threads is mainstream:

a) Top 10 App Store charts in every country.

b) Heavily promoted through Facebook and Instagram.

c) DAUs are higher than X.


That sounds far more like Twitter than Threads. I get so much spam on Twitter now that I hit rate limits reporting it all.


weird, i get a bunch of music and programming stuff on my Threads feed. it's not very deep, but what's on the surface is quite nice and not a bunch of almost-porn. Twitters become half porn though


There is a lot of that.

But there is far more.

Kara Swisher is on Threads, for instance.


All good ai researchers are on X. They are not switching to bluesky or masto which are frankly, lame.

You build the machine god all day and somehow find in yourself respect for what Jack let Twitter become?

If you dream of Napoleon, an elephant tooting a horn is a signal to sell.


> nobody can read his tweets without a X account

False; works fine for me logged out or incognito..


No, you can't see the thread. You can see the first post, but X took this away [0].

Nitter still works [1]. Also Threadreader (as can be seen linked in Green's tweet).

[0] https://tweetdelete.net/resources/view-twitter-without-accou... [1] https://nitter.poast.org/matthew_d_green


Also can't see the thread.


I’m on iOS. I can’t see the thread. Incognito or normally.


False


Sorry but this is just fatalistic nonsense. A generation ago people did not have anything like the current evolution of surveillance technology. The small number of people who care about ubiquitous surveillance right now are early adopters, not a dying breed.


What makes you think the propaganda won't be pumped in if the US app is sold to a different company?


If it's sold to a US company then it will be our intelligence agencies pumping the propaganda, not theirs. Which is an outcome I'm more amenable to, considering that our intelligence agencies generally have more of an interest in the stability of American society than the intelligence agencies of China.


See also - Facebook is American owned, yet that never stopped assertions that it was used by foreign adversaries to pump their propaganda.


So if it's propaganda either way, then no loss will happen?


Do commenters like this ever stop to consider people who cannot afford to pay higher prices, before encouraging creators to arbitrarily raise prices higher than the creators have already calculated? Do these commenters ever stop to analyze their world view that leads them to believe the litmus test for quality products is whether the product is priced like an Apple product?


I’m all for looking out for the less fortunate, but people running businesses are people too with spouses, children, mortgages, etc. they need to live a sustainable life too. Pricing something to market value is not necessarily a bad thing.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: