There is no threat model for an iPhone app to do nefarious things in an App Store distributed app on a non-jailbroken phone. At most, FaceApp grabs the picture you uploaded and some minor meta-data that every app using an analytics tool (read: all of them) collects. This is political grand-standing at best, and would be a non-issue if you replaced the geographic location of the dev team with any other countries I get…
The FBI considers FaceApp to be a potential counterintelligence threat [pdf]
61–70 of 136 posts
Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]
#62The best measure would be for “good actors” (universities, government research agencies, the New York Times) to provide a free FaceApp-type app. It’s like a weekend-hackathon of work and can be prioritized by the app stores.
That works in this particular case but is not a general solution. It's not feasible to have "good actors" rewrite clean versions of software written by "bad actors"
Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]
#63Why don’t we have the ability to restrict at the OS level which domains an app can send information to? Then we can finally host backend software locally on servers of OUR choice.
I would love to see more OPEN SOURCE apps running on servers of our choice, and communication over mesh networks. In fact I’d love for most functionality to be client-side and an option for ALL data sent to servers to be end-to-end encrypted at the OS level. I dont want to have to trust the APP manufacturer to pinky swear it’s all end to end encrypted. The OS should have a little badge saying none of the data sent by the app is being sent in a way the server can decrypt because the OS intercepts and encrypts it with keys the app can’t get. That may still leave side channels such as timing based information to tunnel through. But if we restrict what domains the app can talk to, we can close that loophole too.
That’s what I would love to see ... finally put an end to server side landlords owning your data just cuz they own the infrastructure!
Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]
#64Seems like the word "potential" is conspicuously missing from the title of the submission
Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]
#65There is no threat model for an iPhone app to do nefarious things in an App Store distributed app on a non-jailbroken phone. At most, FaceApp grabs the picture you uploaded and some minor meta-data that every app using an analytics tool (read: all of them) collects. This is political grand-standing at best, and would be a non-issue if you replaced the geographic location of the dev team with any other countries I get…
The threat model is that this photo is shared with the Russian government and then the Russian government can match American citizens (or potentially people working in intelligence), and then using that in facial recognition programs. I.e. they can differentiate Americans (insert x country) from their own citizens and know who to watch more carefully. This is a legitimate threat model. I'm not sure why you think it w…
Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]
#66Forgive me for chuckling at law enforcement in by far the world's largest exporter of consumer malware for treating a single comedy deepfakes app with so much paranoia and suspicion. How did that common saying go that was bandied around in our teenage years? Something like the person in a relationship who fears cheating the most is the one most likely to cheat
Seems like a "pot" should have more knowledge than average on which kettles to call "black".
Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]
#67Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]
#68>"elected officials, candidates, political campaigns, [and] political parties"
not to the general public. The potential threat is for someone at Candidate_1's campaign taking selfies with the app, that then uploads them to Russian servers where the Russian government can see them and can also see what's in the background (sensitive documents?) or see geo-location from the app (like how Strava was leaking the coordinates at military bases [1]) or any number of things a hostile foreign government who has already hacked American elections once and is planning to do it again might want to do with pictures that interns/staffers might think are private.
[1] https://www.theguardian.com/world/2018/jan/28/fitness-tracki...
Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]
#69Earlier quoted context omitted.
It's not better to have your face or other data in a database within reach of your own government. Your government has power over you, other governments do not.
Other governments absolutely have power over you, just not always legally.
Re: The FBI considers FaceApp to be a potential counterintelligence threat [pdf]
#70Earlier quoted context omitted.
It's not better to have your face or other data in a database within reach of your own government. Your government has power over you, other governments do not.
I need a passport and driver license