• 3 Posts
  • 24 Comments
Joined 1 year ago
cake
Cake day: July 3rd, 2023

help-circle





  • I’m surprised and happy that SUSE is still doing well. I have fond memories of using SUSE in the enterprise especially around their “perfect guest” campaign for using it in virtualized environments. I thought they had very well-baked integration with large Windows networks—things just worked out of the box that didn’t with RHEL. I’m sure a lot has changed in the last decade but I appreciated their cooperative stance in the enterprise.





  • panicnow@lemmy.worldtoPrivacy@lemmy.mlWhy don’t you like Apple?
    link
    fedilink
    arrow-up
    4
    arrow-down
    4
    ·
    edit-2
    4 months ago

    I’m not an Apple apologist, but I feel there are some things Apple does that are privacy focused.

    • The ability to E2EE encrypt iCloud is a very simple privacy feature that is accessible to the technical and non-technical alike.
    • Private relay provides a double VPN architecture that doesn’t cause constant captcha hell and again just works for non-technical people.
    • Hide my email, while not being perfect, is a pretty straightforward method to make throwaway email addresses.

    The things I hate about Apple are generally not privacy related.

    • They are a mega-corporation that stifles innovation
    • They don’t allow other browsers
    • They are puritanical about what is allowed in the App store


  • I love that you got it brown and crisp as I abhor soft/chewy quesadillas.

    I like adding cilantro somewhere (either in fillings or in salsa). Sometimes I throw a little cheese in the pan and let it melt and cook onto the outside of the quesadilla which gives it a little different character. I also love getting chipotle flavor somewhere and usually use Cholula Chipotle sauce which I buy in 64oz bottles instead of the little 5oz bottles they sell in stores.

    I make a lot of quesadillas!






  • Surprisingly, I thought the article was a reasonable summary of the actual paper. I think some people might think this was a poke at privacy on Apple, but it really focused on how hard it is to create accessible settings despite the enormous number of options.

    I have found that navigating the menus in Apple iOS is quite a bit easier than on my Android devices. Mac seems more difficult as the settings tend to be inside the individual apps and don’t surface as well through the search.

    The paper hammered home the point that Siri configurations were particularly hard, but they also mention that Siri data is end-to-end encrypted. I thought all those points were fair.

    I do believe settings need to be improved, but I have little faith they will ever be useful for 99% of users who will simply never change anything from the default. At this point I believe any meaningful improvements for the majority of users will come from useful defaults that include E2E encryption on basically all user data. I feel Apple is coming close with iCloud Advanced Data Protection that was introduced last year, but that needs to become a default. Maybe it cannot though—too many users will lose all their data and then the trade off of security to convenience will not be worthwhile.



  • I agree that decrypt/encrypt is bad—it is simply not E2EE. The solution would have to be a better method of public key distribution for ‘federated’ systems.

    While I don’t know anything specific about facebook messenger, E2EE doesn’t necessarily preclude what you suggest. A messaging service could store the entire chat history encrypted without decryption keys. When you get a new client you could restore the entire history in encrypted form onto your device. You would then use a recovery key you would possess to decrypt the message history on your end. At no time would the messaging service have the keys to decrypt. I’m not saying that is what facebook does.



  • If you enable advanced data protection apple cannot recover your account. You need your recovery keys or a designated recovery contact.

    The apple doc implies (to me) that a SIM swap only works after you authenticate on an apple device (e.g. using your password) even without advanced data protection. I have never tested that.

    You can use the long process (many days) to recover an account assuming you haven’t enabled advanced data protection. I’m okay with that as it is perfect for my grandparents (I had an older relative who got their account back through this method).

    I get that you could SIM swap to recover other accounts (not Apple) if they have SMS as a recovery method. That sucks and it really sucks for people who don’t get that an email or SMS recovery can be a giant hole in security.