Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

291–300 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#291
post #260
post #118

This matches up with how I view Apples corporate thinking. "we know what's best" "the consumer is not to be trusted". Apple limits access to hardware, system settings, they block apps that don't meet moral standards, are "unsafe", or just might cause apple to not make as much money. They do not significantly care what people say they want after all they know best. A lot of people love not having options and having th…

This isn't exclusive to Apple - Microsoft recently decided that starting from August Windows Defender will have the option for blocking PUAs enabled by default for those users who doesn't have other third-party security software [1]. This also I belive falls under "we know what's best" and "the customer is not to be trusted" or "is too stupid to run things by on its own". This does looks good on paper - caring for cu…

I don’t see why a circumventable default block of random executables is bad. People (even technically adept ones, who are a small minority) are very easy to fool. Depending on how easy it is to allow execution of such a program (which is a UX problem) it can indeed be what prevents a botnet on a significant number of computers.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#292

Earlier quoted context omitted.

> It's interesting how many users in this thread are instinctively siding with the offenders in this, and not the victims. That is infantile. Painting people advocating privacy as siding with offenders is highly insulting.

This is a situation where different people's privacy is in conflict. What's infantile is claiming sole ownership of privacy advocacy while so-whating the worst privacy violation imaginable, from the victims' perspective.

The two sides proposed by your argument are only logically valid opposites if you can logically/mathematically guarantee that this technology will only ever be used for detecting photos depicting blatant and obvious sex abuse. Since you cannot, the entire argument is void. I'm not siding with abusers, I simply want arbitrary spies staying the hell away from my computers.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#293
post #274
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

If it seems like this scanning is working as advertised, this will be a great marketing stunt for Apple. Actual predators will stop using Apple products out of fear of getting caught and they will be forced to use Android. Now any person who owns an Android is a potential predator. Also, if you are trying to jailbreak your iPhone, you are a potential predator.

Some 'predators' are dumb. They'll keep using iPhones, get caught, and have their mugshots posted in the press. Great PR for the policy makers who decided this. Such stories will be shoved in the faces of the privacy advocates who were against it, to the detriment of their credibility.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#294

This will go great with zero-click iMessage exploits like this one: https://9to5mac.com/2021/07/19/zero-click-imessage-exploit/ Edit: Actually, this won't even require an exploit if they also scan media for people who have enabled "iMessage in iCloud". Just send someone an image in the DB (or an image that's been engineered to generate a false positive) and wait for them to get raided.

Yup, there is now a single API call for planting an evidence onto dissident's phone and sending a SWAT team to retrieve him.

Authoritarian regimes love this.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#295
post #99
post #46

Earlier quoted context omitted.

False positives, what if someone can poison the set of hashes, engineered collisions, etc. And what happens when you come up positive - does the local sheriff just get a warrant and SWAT you at that point? Is the detection of a hash prosecutable? Is it enough to get your teeth kicked in, or get you informally labeled a pedo by your local police? On the flip side, since it's running on the client, could actual pedophi…

False positives are clearly astronomically unlikely. Not a real issue. Engineered collisions seem unlikely too. Not impossible. Unless there is a straight up cryptographic defect in the hash algorithm, it seems hard to see how engineered collisions could be made to happen at any scale.

Why do you think that? There are plenty of whitepapers on fooling NNs by changing random pixels by a bit, so that the picture is not meaningfully changed for a person, but the computer will label it very differently. Do note that these are not cryptographic hashes because they have to recognize the picture even when compressed differently, cropped a bit, etc.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#296
post #13

Earlier quoted context omitted.

It's still really, really bad. It always starts with child porn, and in a few years the offline Notes app will be phoning home if you write speech criticising the government in China. This technology inevitably leads to the sueveillance, suppression and murder of activists and journalists. It always starts with protecting the kids or terrorism. Perceptual hashes like what Apple is using are already used in WeChat to…

I agree with you 100% — the only solution I’ve found workable is limiting my use of the technology itself as much as possible.

You could you exclusively free software instead. It respects your freedoms.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#297
post #22

This has worrying privacy implications. I hope Apple makes a public announcement about this but wouldn’t be surprised if they don’t. I also would expect EFF will get on this shortly.

What are the implications?

A country can collect a list of people sharing any content they put on a hash list.

Like gay porn, 'save Khashoggi' meme, or a photo from documentary about missing Uighurs.

It's hard to imagine how this could be misused, right?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#298
post #251

Earlier quoted context omitted.

If you're treating your phone as hostile why would you skip gaming apps but use banking ones? That seems backwards if you're assuming your mobile is the weak point.

In the EU the PSD2 directive obliged banks to provide strong authentication for customers login process and various operations on the account incl. payments ofc. Most of the time mobile applications are being used in the result - for either login confirm or as software OTP generators (biometric verification is also supported); the lists of printed codes are rather obsolete now and some banks may actually charge your…

There still exist banks that provide you with an RSA token. If a bank does not give you the option, how can one (sorry) "of the right segment" have business with it? You look at the service provider, you see all kinds of bad signals, you hire it anyway: this is a big part of what is destroying us!

Restraining myself to write something very strong about phone security and general user expectancy and duly expectancy (low) - let us stress again the legal side: how do you prove to a bank that, in case of theft from the account, your device was safe? People who see their money stolen then have controversies with the bank about responsibility.

BTW: PSD2 has been, in many parts, a huge nightmare. Furthermore, healthy parts of it for some reason have not been implemented.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#299
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

> closed social networks It’s not clear that governments would give the open social networks an easier ride either. It could be argued that distributed FOSS developers are easier to pressurise into adding back doors, unless we officially make EFF our HR/Legal department. The other problem is workers have a right to be paid. The alternatives are FOSS and/or distributed social media. Who in good conscience would ask a…

>Who in good conscience would ask a tech worker to give away their labour for free, in the name of everyone else’s freedom?

Here's the hope: the tech workers doing it for 'free' because they're scratching their own itch. So it would not be an act of onerous charity. The techies make some free open source decentralised clone of Reddit, say, then some folks among knitting communities, origami enthusiasts, parents groups, etc. copy it for free and pay to run it on their own hardware.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#300

Sorry to say that, but stuff like this has to happen at some point when people don't own their devices. Currently, nearly no one owns their phone and at least EU legislation is underway to ensure that it stays this way. The next step will be to reduce popular services (public administration, banking, medicine) to access through such controlled devices. Then we are locked in. And you know what? Most people deserve to…

Let us comb this a bit. When you mention that set of population as deserving the consequences, it does not seem too far to me from "People who want trains instead of cars deserve trains". Is this relevant? The big problem is, people buy controversial services, hence finance them and endorse them, hence strengthen them, and in some cases these services make the acceptable ones extinct: the big problem is that people d…

> If you know the exceptions to the untrustable devices, kindly share brand/model/OS/tweak.

https://puri.sm/products/librem-5

Post reply on HN