Is the connectivity layer considered: Is the 3rd party "proxy" handler uploading the information using an Apple ID? Does Apple record, store IP information? It seems to me that by using this system you volunteer to send data to Apple constantly which may not reveal your GPS location but will reveal your network location.
I'm happy to see someone trying to innovate in this space. I still wonder if it is okay for journalists and risk affected users to use this or if they should be advised to avoid it.
Buying max RAM from start is a $200 extra which may validate saved space. Not justified is soldered SSD. Ive doubled SSD size once a year to extend laptop life by 6 or 7 years.
Note that these models are created in an era of great inequality. You can expect that if at any point a correction is made to this disparity these numbers will also be effected.
also if in the future we actually make cellular standards where encryption isn't demarcated at the tower and instead setup e2e between consumer devices, some risks are mitigated
it's really a shame that with both 4g and 5g standards bodies did not already work on this.
most abuse mitigated by their limits on the number of downloads allowed and how many days it can stay online. Currently at 7 days max and 100 downloads. If they see abuse they could reduce this further.
about revenue, there are so many valuable directions this can go. It could undercut competitors in ways they cannot sufficiently respond to. (google responding in kind would leave them less reason to not add encrypted storage for drive) By stabilizing this platform they can start to build new privacy-enhancing apps on top. Calendar, contacts, etc. With more dependency on the platform, they will find areas where more storage, longer retention, will be income generating.
privacy may be the only frontier that can displace google,apple,microsoft.
There are many use cases where compromise through code-interdiction after warrant is a perfectly acceptable risk. Also considering what it replaces may further increase the weight of privacy gain. Absolutism is definitely not the way to go, and looking at the state of the tech community (eg. npm, apt, pip, pacman, check that sha256 sum) we left the design-it-right-first a long time ago. A valid argument, though I wouldn't defend it to the death, is that we need to work slowly back toward more secure behaviors rather than chasing absolutely secure technologies. I think send.firefox is a step back from dropbox for some.
Could someone explain why this is on HN? I ask because this comes up often on other non-tech topics. Personally I'm happy these topics can be discussed here.
Overlooked: the apathy required to become techno-mercenaries started with the agents convincing themselves that spying on nationals was different than foreign nationals while working in the NSA. To resist this apathy cyber intelligence agents working for any government/corporation should deploy a moral compass that assumes they are working for the UAE.
This also begs for international conventions. New international conventions would provide a psychological back-stop against the infosec industry's unchecked nationalism. When an agent asks themselves "is what I am doing okay" international convention and law would give them an alternative to compare with other than the militarist default of "yes".
most comments are thoughts and opinions and only few provide new critique. The OP comment here, though presented in an obnoxious way, is new critique because no one else has discussed the civil liberty bias deployed by agents. Though the OP presents this in an offensive way, which is maybe breaking a different rule than just "new critique"
Taking the sources of the article on their word...
They said the tools use faded in late 2017 due to apple patches and that compromise required only sending a text message. Examining CVE's up until late 2017 may give more of an idea of how this tool worked. Judging from a cursory review, there are many remote code exploits so it would be hard to narrow down. But this is what I chose to look at when considering CVE's between Jun 2017 and Dec 2017 that could effect iMessage. Many of these are classified as Denial of Service bugs but often those can be extended to code execution with extensive research.
I can't see how autonomous cars and Musky holes will be good for common people and not just turn into another form of exclusive transport for the rich.
until recently i tried using firefox to quarantine social media and google but the persona extensions would break all the time, leaving me to reconfigure things over and over. Is there another way to quarantine now?
Not about BAT,cryptocurrency. It's all about usable privacy. Makes it easy for me to quarantine Google services, social media, from each other. Privacy as the killer feature is what makes it killer
eventually this (e2e encryption everywhere) will happen once governments realize their security and secrecy depends on the security of consumer technology and to protect the public is to protect themselves.