This matches up with how I view Apples corporate thinking. "we know what's best" "the consumer is not to be trusted". Apple limits access to hardware, system settings, they block apps that don't meet moral standards, are "unsafe", or just might cause apple to not make as much money. They do not significantly care what people say they want after all they know best. A lot of people love not having options and having th…
This isn't exclusive to Apple - Microsoft recently decided that starting from August Windows Defender will have the option for blocking PUAs enabled by default for those users who doesn't have other third-party security software [1]. This also I belive falls under "we know what's best" and "the customer is not to be trusted" or "is too stupid to run things by on its own". This does looks good on paper - caring for cu…
Apple enabling client-side CSAM scanning on iPhone tomorrow
291–300 of 757 posts
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#292Earlier quoted context omitted.
> It's interesting how many users in this thread are instinctively siding with the offenders in this, and not the victims. That is infantile. Painting people advocating privacy as siding with offenders is highly insulting.
This is a situation where different people's privacy is in conflict. What's infantile is claiming sole ownership of privacy advocacy while so-whating the worst privacy violation imaginable, from the victims' perspective.
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#293Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…
If it seems like this scanning is working as advertised, this will be a great marketing stunt for Apple. Actual predators will stop using Apple products out of fear of getting caught and they will be forced to use Android. Now any person who owns an Android is a potential predator. Also, if you are trying to jailbreak your iPhone, you are a potential predator.
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#294This will go great with zero-click iMessage exploits like this one: https://9to5mac.com/2021/07/19/zero-click-imessage-exploit/ Edit: Actually, this won't even require an exploit if they also scan media for people who have enabled "iMessage in iCloud". Just send someone an image in the DB (or an image that's been engineered to generate a false positive) and wait for them to get raided.
Authoritarian regimes love this.
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#295Earlier quoted context omitted.
False positives, what if someone can poison the set of hashes, engineered collisions, etc. And what happens when you come up positive - does the local sheriff just get a warrant and SWAT you at that point? Is the detection of a hash prosecutable? Is it enough to get your teeth kicked in, or get you informally labeled a pedo by your local police? On the flip side, since it's running on the client, could actual pedophi…
False positives are clearly astronomically unlikely. Not a real issue. Engineered collisions seem unlikely too. Not impossible. Unless there is a straight up cryptographic defect in the hash algorithm, it seems hard to see how engineered collisions could be made to happen at any scale.
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#296Earlier quoted context omitted.
It's still really, really bad. It always starts with child porn, and in a few years the offline Notes app will be phoning home if you write speech criticising the government in China. This technology inevitably leads to the sueveillance, suppression and murder of activists and journalists. It always starts with protecting the kids or terrorism. Perceptual hashes like what Apple is using are already used in WeChat to…
I agree with you 100% — the only solution I’ve found workable is limiting my use of the technology itself as much as possible.
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#297This has worrying privacy implications. I hope Apple makes a public announcement about this but wouldn’t be surprised if they don’t. I also would expect EFF will get on this shortly.
What are the implications?
Like gay porn, 'save Khashoggi' meme, or a photo from documentary about missing Uighurs.
It's hard to imagine how this could be misused, right?
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#298Earlier quoted context omitted.
If you're treating your phone as hostile why would you skip gaming apps but use banking ones? That seems backwards if you're assuming your mobile is the weak point.
In the EU the PSD2 directive obliged banks to provide strong authentication for customers login process and various operations on the account incl. payments ofc. Most of the time mobile applications are being used in the result - for either login confirm or as software OTP generators (biometric verification is also supported); the lists of printed codes are rather obsolete now and some banks may actually charge your…
Restraining myself to write something very strong about phone security and general user expectancy and duly expectancy (low) - let us stress again the legal side: how do you prove to a bank that, in case of theft from the account, your device was safe? People who see their money stolen then have controversies with the bank about responsibility.
BTW: PSD2 has been, in many parts, a huge nightmare. Furthermore, healthy parts of it for some reason have not been implemented.
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#299Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…
> closed social networks It’s not clear that governments would give the open social networks an easier ride either. It could be argued that distributed FOSS developers are easier to pressurise into adding back doors, unless we officially make EFF our HR/Legal department. The other problem is workers have a right to be paid. The alternatives are FOSS and/or distributed social media. Who in good conscience would ask a…
Here's the hope: the tech workers doing it for 'free' because they're scratching their own itch. So it would not be an act of onerous charity. The techies make some free open source decentralised clone of Reddit, say, then some folks among knitting communities, origami enthusiasts, parents groups, etc. copy it for free and pay to run it on their own hardware.
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#300Sorry to say that, but stuff like this has to happen at some point when people don't own their devices. Currently, nearly no one owns their phone and at least EU legislation is underway to ensure that it stays this way. The next step will be to reduce popular services (public administration, banking, medicine) to access through such controlled devices. Then we are locked in. And you know what? Most people deserve to…
Let us comb this a bit. When you mention that set of population as deserving the consequences, it does not seem too far to me from "People who want trains instead of cars deserve trains". Is this relevant? The big problem is, people buy controversial services, hence finance them and endorse them, hence strengthen them, and in some cases these services make the acceptable ones extinct: the big problem is that people d…