Examining Apple's Carefree Attitude Towards Employee Privacy

Zoe Schiffer, writing for The Verge, investigates Apple employees and “the blurring of personal and work accounts.”

This is how it starts: a new Apple employee is told during onboarding that collaborating with their colleagues will require them to make extensive use of iCloud storage, and their manager offers a two terabyte upgrade. This will link their personal Apple ID to their work account — in fact, the instructions for accessing this upgrade explicitly say “you must link your personal Apple ID with your AppleConnect work account.”

Private Search Engine 'Xayn' Releases Web Version of its App

An AI company based in Berlin, Germany called Xayn has launched a web version of its private search engine app.

Both versions of Xayn use Masked Federated Learning to protect users’ data privacy while still providing them with an individually tailored web experience. They are created with the same code base in Flutter, a developing framework that’s designed to function both on mobile and web. The team transferred the AI to work directly in the respective browsers with high speed via WebAssembly so that all personal data stays privately within the browsers.

Looks like it doesn’t work yet on Safari.

AdGuard: 'People Should be Worried About Apple CSAM Detection'

Adblocking company AdGuard is the latest to offer commentary on Apple’s controversial decision to detect CSAM in iCloud Photos. The team ponders ways to block it using their AdGuard DNS technology.

We consider preventing uploading the safety voucher to iCloud and blocking CSAM detection within AdGuard DNS. How can it be done? It depends on the way CSAM detection is implemented, and before we understand it in details, we can promise nothing particular.

Who knows what this base can turn into if Apple starts cooperating with some third parties? The base goes in, the voucher goes out. Each of the processes can be obstructed, but right now we are not ready to claim which solution is better and whether it can be easily incorporated into AdGuard DNS. Research and testing are required.

IMF: Credit Scores Should be Based on Browsing History

As if reality couldn’t be more dystopian, researchers for the International Monetary Fund proposed that credit scores should include data from peoples’ browsing, search, and purchase history.

Citing soft-data points like “the type of browser and hardware used to access the internet, the history of online searches and purchases” that could be incorporated into evaluating a borrower, the researchers believe that when a lender has a more intimate relationship with the potential client’s history, they might be more willing to cut them some slack.

What an insane, stupid idea. Too poor to afford a Mac? Sorry! Your credit score won’t be rising above 600.

Secure Chat App ‘Signal’ Announces Default Disappearing Messages

Signal, a messaging app that uses end-to-end encryption, introduced a feature to let you have all of your messages disappear by default.

Until now, disappearing messages had to be enabled on a per-conversation basis, but for those who want to take ephemerality to the fullest, Signal now supports the ability to preconfigure all conversations you initiate with a default timer.

We’ve also added the ability to set custom timer durations on your conversations, so that some content can be gone in 60 seconds and others can exist for 18 minutes or 4 weeks.

EFF Shares Statement on Apple Scanning for Illegal Content

This week we discovered that Apple plans to localize its scanning efforts to detect child sexual abuse material. The move has been widely criticized and the Electronic Frontier Foundation has shared its statement on the matter.

All it would take to widen the narrow backdoor that Apple is building is an expansion of the machine learning parameters to look for additional types of content, or a tweak of the configuration flags to scan, not just children’s, but anyone’s accounts. That’s not a slippery slope; that’s a fully built system just waiting for external pressure to make the slightest change.

The Rise of QR Codes has Privacy Experts Worried

The popularly of QR codes has risen due to the pandemic, since it enables touchless interactions. But they can be used for tracking and advertising.

But the spread of the codes has also let businesses integrate more tools for tracking, targeting and analytics, raising red flags for privacy experts. That’s because QR codes can store digital information such as when, where and how often a scan occurs. They can also open an app or a website that then tracks people’s personal information or requires them to input it.

Catholic Publication Used Location Data Against a Priest

Catholic media publication The Pillar used location data from gay dating app Grindr to track the movements of a priest, then publicly outed him for “improper behavior.”

It wasn’t clear who had collected the information about Burrill. USCCB spokespeople declined to answer questions Tuesday about what it knew about the information-gathering and what its leadership feels about it, except to say the USCCB wasn’t involved. They also declined to comment on whether they knew if Burrill’s alleged actions were tracked on a private or church-owned phone.

This is a good example of how our data can be used against us, and not just by advertisers.

A Glimpse Into the World of Mobile Advertising IDs and Their Use

Motherboard gives us a brief look into mobile advertising IDs (MAIDS) and how they can be used to unmask your identity.

All BIGDBM USA data assets are connected to each other,” Mack added, explaining that MAIDs are linked to full name, physical address, and their phone, email address, and IP address if available. The dataset also includes other information.

DuckDuckGo Launches Free Email Protection Service

Privacy search engine DuckDuckGo has launched an Email Protection Service to protect against email trackers. You can get a free, personalized @duck.com address that will forward emails to your regular inbox.

We remove hidden trackers from incoming emails sent to this address, then forward them to your regular inbox for safer reading. This means if you use an email service like Gmail or Yahoo, it’s no problem! Emails sent to your Personal Duck Address will arrive there as usual so you can read your email like normal, in any app or on the web, worry-free.

Google Adds Tool to Quickly Delete Your Last 15 Minutes of Searches

Google is adding new protections for your search history like quick deletion, requiring verification to access the My Activity section, and more.

You can also try out a new way to quickly delete your last 15 minutes of saved Search history with the single tap of a button. This feature is available in the Google app for iOS, and is coming to the Android Google app later this year.

You could also just turn disable your search history altogether, too.