📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

AI on your phone - AN ABSOLUTE PRIVACY DISASTER!

The Hated One12:53

Transcription

There is no other way for me to say this. AI on your phone is a catastrophe. Forget the idea of an embarrassingly inaccurate chatbot. That idea has xenomorphed into an all-powerful assistant that scans your every app and every website and completes tasks on your behalf. This exposes all of us to the biggest privacy and security risks that we have ever seen. The content of everything you do on your AI-enabled phone is at risk. If you chat with someone who has an AI-powered phone, you could be equally exposed. No one is safe from this.

I'll explain that and also give you my solutions because I want to inform you about the dangers of trusting the big tech with literally anything at this point, and I also want you to be able to protect yourself from that. Don't worry, there's no sponsored BS here, only true genuine advice to the best of my ability. I can only do this if you support me directly. I'll first tell you what the problem is, and you will see just how great this covered-up threat of AI devices really is. And I'll tie all of this back to how it will affect you personally and realistically, not in some theoretical scenarios, but in real life, and also debunk a fake solution that is often floated out there, but it really is just fraudulently misleading.

Google, Apple, Meta, and Microsoft are racing to put an all-powerful AI agent on all of your devices and inside all of your apps. They do it in slightly different ways, but they all want to reach the same goal: to give you an unconstrained AI super-user that can see everything and do everything on your device. Now, the only way to do this is by giving AI access to every process, every application, and all content on your phone or PC. This AI assistant is granted privileged access to your personal information. And their plan is to gradually expand this AI access to every app across all of your devices, including encrypted messaging apps like WhatsApp or iMessage.

At this point, we are in the "boiling the frog" moment. So, for the time being, you're given an illusion of choice that this is something you could theoretically opt out of. But all the tech for this to become an irrevocable default is already there. And all it takes is for the next OS update to ship with an AI agent you can't uninstall and can't contain, just like you already can't do with other default apps on your phone. But the regular user does not see this.

On the surface, what you see is a promise of new convenience. The big tech is building AI features that can summarize your emails and texts, and that can also respond to them with AI-generated replies. Their AI tools can constantly scan websites or apps used to provide you with summaries of their content. They could eventually book you appointments or schedule holiday plans. These features are usually on by default, and they include a multi-tier approach of either processing your data on-device or letting much more powerful cloud-based models do the job where the local ones fail. But local models are almost always insufficient because they're too small to do anything really useful. So, for the majority of the tasks, whatever the AI on your phone processes will end up in the cloud, including the content of your end-to-end encrypted messages and chats.

I want everybody to really understand what this means. Whenever the cloud model is called up to perform a task, your data is sent to the server of the company running the model for you, and it's up to them to decide what they want to do with your data. And in case you need an example of how that might look, especially in cases of the most powerful AI models like Gemini or ChatGPT, both Google and OpenAI reserve an exclusive right to use your private data to train their AI models and let human reviewers annotate and review your information. They also retain your data alongside identifiers like your location, device info, or even your IP address.

The AI on your phone is effectively acting as a virus, controlling system permissions, accessing other apps, manipulating the information you see, uploading your content, and navigating the web. It can bypass end-to-end encryption of your messages and call logs that only the most sophisticated malware from a nation-state-sponsored hacking group could achieve. And as for the illusion of choice, you may choose to not use this agent for anything at all, but the AI will be there. Siri on your phone or Google Assistant on Android are both being xenomorphed into AIs, and the company's terms of service and privacy policies adjusted accordingly.

Now, you may be thinking that this doesn't concern you, that you aren't doing anything serious on your phone. But it would assume that you wouldn't want to have your passwords or credit card info stolen, would you? Because the AI on your phone is a whole new vulnerability, one that is always exploitable and one that cannot be mitigated. I'm not trying to scare you here. This is the reality of the current stage of AI. Fundamentally, all large models are vulnerable to so-called prompt injection attacks. Prompt injection attack is just fancy wording for a very simple hack: giving an AI a prompt that will convince it to do something malicious, like give you instructions on how to cook meth, or let a hacker install malware on your phone, or tell an attacker your passwords.

The big tech's goal with AI is for it to be all-knowing. All the things that I mentioned like browsing the web for you, summarizing the content, searching for information, etc. Researchers have already shown that it is possible to trick this all-seeing, all-scanning AI. Let me show you. Suppose you tell an AI to summarize a website. The AI will scan all of the content of the website, which may also include things humans can't see, like invisible text or tiny fonts. An attacker could easily plant a malicious prompt into such a tiny font or an invisible text. Once the AI scans it, it will perform a malicious prompt planted in the invisible text, which could say something to the effect of overriding the AI safety settings and going completely rogue. This could tell your AI assistant to install a malicious app or visit a fraudulent website and give it your credit card info or passwords.

This category of indirect prompt injection attacks have already been shown they can scam people. They are extremely easy to implement because they democratize hacking. Anyone can do this, including you, without having any technical skills. If you can talk to ChatGPT, you can hack it. And you can use ChatGPT to hack other people. All you need is some spare time to find a prompt that can break an AI. And there will always be such a prompt. AI developers will only ever play a catch-up game with hackers, but they will always be behind, only reacting once an attack has been discovered.

Yet, the problem is far greater than some rogue trolls somewhere. These prompt injection attacks are scalable and can be automated. Prompt injection attacks can occur anywhere: inside subtitles in a YouTube video, in an invisible frame on a website, in an unskippable ad on a streaming service, inside inaudible frequencies from an audio source as a form of psychoacoustic hacking. And there doesn't exist a way to completely mitigate this threat other than not using AI at all, which is becoming increasingly more difficult to do with AI being built into browsers, apps, operating systems, messengers, and more. It is becoming harder to find a place without an AI than with it. Unless you watch my solution section of this video, this will lead to a catastrophe. Any hacking group can compromise an entire political or media establishment all at once to do anything they want, including recruiting spies, blackmailing assets, gathering intelligence, or just to watch the world burn. They would use that information over time to develop spies, to turn people, to blackmail people, people who a generation from now will be working in the FBI or the CIA or in the State Department.

Now, for all of those Apple users watching this, don't think this doesn't apply to you because you saw Apple making some dubious privacy promises. You are just as exposed. People have this misguided belief that Apple somehow solved all of the privacy and security problems surrounding AI. "At Apple, we believe privacy is a fundamental human right." They think this is the case partly because the rollout of Apple Intelligence has actually been an utter disaster. It led people to assume it's because Apple's stance on privacy prevents them from making a competent AI assistant. Case in point, the notification summaries that were so hilariously wrong; news agencies filed official complaints against Apple. Apple is behind on AI not because of their stance on privacy, which is nothing but a marketing ruse, which I've talked about before in many of my videos, but because they lack the talent and tech to compete with other AI companies. Apple put in charge of the Siri assistant people that did not even believe in AI as a useful tool. Apple's corporate leadership had no clear vision on what to do with AI and machine learning to the point their AI group internally earned a nickname: Aimless. The fact that Apple's AI attempts suck has nothing to do with their supposed privacy guarantees. On the contrary, let me show you how Apple's AI will still leave you exposed.

Apple implemented a three-tier approach where the first two tiers of AI are supposed to be more private, and only the last tier will upload everything to the cloud. But the first two tiers are so bad they're essentially useless. The tier one models that run locally on the iPhone are the most poorly performing of all. They provide no useful utility beyond generating emojis. Then tier two models run Apple's in-house AI based in the cloud, but with supposed privacy guarantees of a so-called trusted execution environment. Apple went about a very complex route to ensure that data sent from users' iPhones to Apple's servers couldn't easily be stolen or accessed. But this design is a much weaker guarantee of your privacy than end-to-end encryption itself. Apple's infrastructure is not impenetrable, and their employees are not uncompromisable. No, that's not a word. But these partially private models still aren't powerful enough for the actually useful and more complex tasks. For those, Apple has a third tier, which is essentially delegating all work to OpenAI's ChatGPT and by extension surrendering your private data to OpenAI's privacy policy. ChatGPT has no privacy infrastructure. All data sent to it will always be accessible to OpenAI for them to do whatever they want to, which in the broader terms of service also includes using your data to train their models. To truly compete with Google's Gemini, Apple Intelligence will have to be just as much of a privacy invasion and a security risk as any other corporate AI implementation. And all of the AI intelligence models will always be equally vulnerable to prompt injection attacks without any possibility of containment.

Before I move on to talking about solutions, I want to highlight something really important here. We had a good thing, you stupid son of a... This relentless cash-hungry push for AI to be in every single thing in existence is setting back decades of progress. I know this may sound kind of new to some of you, but at least for a while, at least some things used to be improving, at least in some aspects. Our privacy and security used to be terrible, but the rollout of encryption and some privacy technologies have made us all more secure and private. There was a trend to keep more and more data processing on-device rather than moving everything to the cloud. Even from an energy and resource efficiency standpoint, data centers used to be improving. It was not ideal, but there was hope. AI has ruined all of this. The explosive hype around AI isn't paid for just by the stock market and investors' money. The cost of AI is also our privacy and security, and also the justice around using our resources where the big tech is draining our power reservoirs and straining our power grid. But God forbid you turn on an AC unless you're actively dying. I don't think you needed it, but this is yet another proof that corporations don't care about anything other than shareholder value.

There are solutions to this, and I want to offer you ways out of this depending on your technical level and motivation. But I believe that anyone can do all of this, even if you have no technical skills. So please hear all of it. The first tier of solutions revolves around not using any of the big tech AI products and only using those that actively repel them. This can be done on an app-by-app basis as well as system-wide. First things first, you must protect your messaging at all costs. The only private messenger that I've seen proactively resist the AI encroachment is Signal. You may also try Threema or Session if you want something that is not based in the United States. Meta has already implemented AI into their apps, including WhatsApp. This is a total disaster because all Meta models run in the cloud with zero privacy protections. I know it's not surprising.

If you don't want your emails to be used for ads or AI training, then these are your two best options: TutaMail and Proton Mail. I like TutaMail better because it has no AI integration whatsoever. Proton Mail unfortunately does offer AI in Proton Scribe, and I hate it. It's hot garbage, but at least it's optional and can run locally. If you, for some reason, want to run AI, then I only recommend you run it locally. The easiest tool I could find is JAN.AI. Using JAN, you can run any model your device is capable of running. If you want something more advanced, you can try Open WebUI or even running your own AI server if you have money to spare on GPUs. I know that Office Workflow is now heavily infested with various AI implementations. The easiest way out of this is just to use LibreOffice. LibreOffice is open-source, has everything you'll ever need, and it's always private.

Now, the trouble is that AI is implemented system-wide, not just in individual apps. If you truly want to escape the AI overlords, you can't use anything from Microsoft Windows, Apple iOS or macOS, or even Android. It's time to finally replace Windows with Linux. If multi-millionaire YouTube noobs can do it, you can do it. I know it sounds scary to install your own operating system, but trust me, this is a lot easier than it looks. And I recommend you start with Linux Mint; it's probably the easiest Linux distro out there. Ditch iOS and ditch Android. You can still have a smartphone, and it's called GrapheneOS. You'd have to install GrapheneOS yourself, but again, even noob YouTubers can do it, so can you. I've been running GrapheneOS exclusively as my only device for many, many years, and I've had no issues with it whatsoever. You will still have access to all Android apps you'll ever want, but GrapheneOS will never infest your phone with the unmitigated Google AI virus or any other privileged apps for that matter.

Now, I promised you none of this would include any sponsorship BS, and I kept my promise. In return, all I ask for you is that you support me on Patreon and access my podcast for much more content from me. Thank you.