Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

[flagged]


I am, and so is the author of those tweets.


Is your claim that data is being exfiltrated to Apple?


Data exfiltration is not necessary for this to be a privacy concern; data becomes a liability as soon as it's collected even locally.

EDIT: in this case, however, data exfiltration is happening, by means of Apple's closed-source software blindly sending HTTP requests to unknown servers. Apple might not be the recipient of the exfiltrated data, but the exfiltration is happening nonetheless.


[flagged]


> Frankly this is absurd.

What's absurd is Apple's software sending requests to random and entirely-unvetted servers without even so much as notifying the user, let alone obtaining consent.

> Did you know that the file system of your computer contains your personal data, including files you save?

Why yes, and that would just so happen to be the reason why I ain't exactly comfortable with closed-source software silently sifting through it and blindly following anything and everything vaguely resembling a URL or encoding thereof.

> EDIT: No, that’s not what exfiltration means. You are simply misusing the word.

https://www.fortinet.com/resources/cyberglossary/data-exfilt...:

"A common data exfiltration definition is the theft or unauthorized removal or movement of any data from a device. Data exfiltration typically involves a cyber criminal stealing data from personal or corporate devices, such as computers and mobile phones, through various cyberattack methods.

"Another data exfiltration meaning is data exportation and extrusion, data leakage, or data theft, which can pose serious problems for organizations. Failing to control information security can lead to data loss that could cause reputational and financial damage to an organization."

Thanks to this crawler, anyone who sends you even so much as a QR-encoded image of a link will know that it was successfully received, that it was a macOS machine that received it, and quite possibly the public IP address of the machine that received it. That's data that's worth preventing disclosure, for the same reasons email clients often don't load images in emails by default.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: