Sihai network

Update of Apple privacy webpage: practical action to protect user data security

Apple's official speech on privacy security in wwdc19 this year also took a long time. With the growing importance of privacy security, today Apple officially updates the official privacy page, which includes sign in with apple, access to app, background tracking notice and other important content. The details are as follows:

Safari browser, map, IMessage, apple pay further improve privacy security

For the first privacy security project proposed by apple, Safari browser, map, IMessage and apple pay have all obtained the latest privacy security improvement in the environment of IOS 13. Safari browser intelligent anti tracking function uses device-side machine learning technology to intercept the tracker. Advertisers can also generate "fingerprint information" of the device to determine the target according to the browser configuration, installed fonts, plug-ins and other features. In order to prevent this from happening, Safari browser has built-in fingerprint tracking function to prevent web browsing, which only provides simplified system information to the websites you browse, so that data companies are more difficult to identify yourself.

The map app doesn't need to let Apple know which stores, blocks or clinics users have been to, so it can give users a smooth experience. In addition, you don't need to log in to use the map app, so your destination won't be associated with the user's apple ID.

When sending IMessage between devices, each blue bubble information, picture, mobile expression and video are encrypted; and intelligent suggestions in information app, such as recommending photos to be sent according to your chat object, are all completed on the user's device.

Apple pay is sensitive information about the content, occasions, and amount paid by users. Apple will not store, sell or use such information. Apple will not store the user's credit card, debit card number, or share this information with the merchant, but will create a unique "device account number" every time the user adds a card to Apple pay.

Sign in through apple

Users can quickly and easily log in to various apps and websites through existing Apple IDs. Just tap log in via apple and log in with your face ID or touch ID. When you log in through apple, Apple will never track users or collect their personal information. The log in through apple feature requires dual authentication protection on the user's apple ID. If users don't want to share an email address with an app, they can choose to hide their email address, or let Apple create a unique email address for them, where they can forward the received email to their real address. The log in via Apple feature supports all Apple devices as well as web pages and apps on Android or windows devices.

App location access and background tracking notification

Users can use new options to determine whether they are allowed to get the location every time they use the app, so as to control the access to the app location. This further enhances the existing control capabilities, allowing the app to access this information only during use, at any time, or never. When an app uses the user's location information in the background, the user will be notified to decide whether to change the permission.

Provide location information control when sharing photos

When sharing photos, users can control whether to share the location information of photos.

Wireless network and Bluetooth location privacy enhancement

There are changes in the API, which can more strictly limit the wireless network data shared with the app; through the new user control options, users can license or deny the app access to Bluetooth devices. These changes help to prevent app from obtaining location information without user's consent when users use wireless network and Bluetooth.

Address book and search

Some users use the notes section of the address book to store sensitive information. With IOS 13, by default, these notes are not shared with third-party applications when you authorize them to access the address book.

When the lost device is not connected to Wi Fi or cellular network, you can also use the location information from the crowd to locate. When you mark a device as missing and there is another apple user's device nearby, its device can report the device location to you. The whole communication process adopts end-to-end encryption technology. Apple will not know the location of the lost device or the location of the reported discoverer's device, nor the identity information of the discoverer.

Noise and menstrual tracking of female users

The new noise app in watchos 6 uses the microphone on Apple watch series 4 and the updated table to quickly capture the decibel value of the user's ambient noise. The whole operation is completely completed on the device side, and will never record or save any environment audio, to ensure the privacy and security of users.

Users can use the health app on iPhone or the dedicated menstrual tracking app in watchos to record their menstrual cycle information and view the forecast results of next menstruation or pregnancy. These data and all data in the health app are encrypted on the device side. If icloud backup is enabled, relevant data will also be encrypted in icloud. If the user is running IOS 12 or newer system, and dual authentication is enabled, icloud will be protected with end-to-end encryption, which means that Apple cannot get the data.

Private federal learning

Federated learning is a kind of privacy centered machine learning scheme which has been developed in recent years. Private federated learning combines federated learning with differential privacy technology advocated by apple, which can hide the user's identity information when sharing data. When training the machine learning model, private federated learning does not collect user data and analyze it in the cloud, but trains the model locally on each device, and then only updates the model instead of user data back to apple. The apple server will then aggregate these model updates into a new enhanced model and send it back to the user's device. Apple uses differential privacy technology in both device and server to protect user privacy. In IOS 13, we began to use this technology in many fields, including fast input keyboard and personalized "Hey Siri" instructions in some languages.

Author: Chen Gong