this post was submitted on 17 Aug 2026
608 points (98.1% liked)

deflock.me

502 readers
75 users here now

Automated License Plate Readers (ALPRs) are AI-powered cameras that capture and analyze images of all passing vehicles, storing details like your car’s location, date, and time. They also capture your car’s make, model, color, and identifying features such as dents, roof racks, and bumper stickers, often turning these into searchable data points. These cameras collect data on millions of vehicles—regardless of whether the driver is suspected of a crime. While these systems can be useful for tracking stolen cars or wanted individuals, they are mostly used to track the movements of innocent people.

Learn more at deflock.me

founded 10 months ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] joshcodes@programming.dev -1 points 3 days ago* (last edited 3 days ago) (1 children)

I think they're trying to say that while apple encrypts in transit (upload + download is sftp or some other secure transfer method that can't be eavesdropped on), they don't encrypt at rest, meaning the data is written in decrypted format to disk. Which is a data security no-no for mine and most enterprises out there. They're alleging that if someone got into an apple server, they'd be able to read your data and anyone elses.

~~Now that might not be true but I don't see apple saying otherwise anywhere obvious.~~ It's not true. I'm pretty sure Google do this though. They retain a level of access to train their ai models and other deep learning algorithms on what you write in docs or the photos you upload.

[–] 9tr6gyp3@lemmy.world 2 points 3 days ago (1 children)

Thats not how it works at all. The traffic is encrypted locally on the device before it even gets sent to Apple.

[–] joshcodes@programming.dev 1 points 3 days ago* (last edited 3 days ago)

I'm assuming someone is tired here, and it could well be me, but isn't that quite literally what I said? People were saying E2EE doesn't mean the data is secure when it gets there, I was trying to separate the discussion into at rest (secure storage) vs in transit (E2EE) because they're different applications of encryption. I wasn't really intending to argue about Apple's practice's.

From reading, it is encrypted at rest, which sounds like an Apple thing to do. Decrypted at rest feels very Google. Apple state on their standard plan they store the keys in their data centres which I think is what others were talking about? They say they can help recover them so they're accessible in some capacity between the user and Apple.

On their advanced plan details:

Advanced Data Protection for iCloud is an optional setting that offers our highest level of cloud data security. If you choose to enable Advanced Data Protection, your trusted devices retain sole access to the encryption keys for the majority of your iCloud data, thereby protecting it using end-to-end encryption. Additional data protected includes iCloud Backup, Photos, Notes, and more