Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

401–410 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#401
post #32
post #25

Earlier quoted context omitted.

That document you downloaded that is critical of the party will land you and your family in jail. Enjoy your iPhone. Seriously, folks, we shouldn't celebrate Apple's death grip over their platform. It's dangerous for all of us. The more of you that use it, the more it creates a sort of "anti-herd immunity" towards totalitarian control. Apple talks "privacy", but jfc they're nothing of the sort. Apple gives zero shits…

> Stop. Using. Apple. But is there a realistically better alternative? Pinephone with a personally audited Linux distro? A jailbroken Android device with a non-stock firmware that you built yourself? A homebuilt RaspberryPi based device? A paper notepad and a film camera and an out of print street map?

Viable alternatives were long gone. I really miss the days of Symbian and Meego, phones that are hackable yet intuitive to use (I.e. Nokia N900, N9).

Realistically now we have Tizen and Jolla OS, which had backings from Samsung but nobody gave two damn about it.

I bet even if any of these vanilla mobile OS gets big enough they’ll get bought by the 3 giants and suffocated to death just like how Microsoft sniped Nokia.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#402
post #361

A new aspect of this is that because this is self-reported, and the end goal is to involve the criminal justice system, there is now (essentially) an API call that causes law enforcement to raid your home. What would be the result of 'curl'ing back a few random hashes as positives from the database? Do I expect to be handcuffed and searched until it's sorted out? What if my app decides to do this to users? A maliciou…

A report to the cybertips line does not equal a police raid. Unfortunately the scale of the problem and the pace of growth is such that only the worst of the worst content is likely to be prosecuted.

If a phone calls the API "hello, I found some porn here" the phone (and/or it's owner) become a "person of interest" very quickly.

(I'll wager) The majority of these calls will be false positives. Now a load of resources get deployed to keep an eye on the device's owner, wasting staff time and compute, wasting (tax funded) government budget that could have gone towards proper investigation.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#403

Earlier quoted context omitted.

Let us comb this a bit. When you mention that set of population as deserving the consequences, it does not seem too far to me from "People who want trains instead of cars deserve trains". Is this relevant? The big problem is, people buy controversial services, hence finance them and endorse them, hence strengthen them, and in some cases these services make the acceptable ones extinct: the big problem is that people d…

> If you know the exceptions to the untrustable devices, kindly share brand/model/OS/tweak. https://puri.sm/products/librem-5

This is beautiful, and news (to me) that make me re-breathe like around alpine pines. Thank you!

(It makes me dream of a version which also is ruggedized and uses a high resolution OLED display... But this can easily already be the new palm companion.)

I hope that the current difficulties in (global) manufacturing will be soon be over.

Edit: having mentioned "pines" was not meant to be a pun - I just realized the odd potential reference to the PinePhone.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#406
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

I honestly don't like too much these smug takes > 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 99% of the population will delegate the decision of what code is allowed to run to someone, be it the manufacturer, the government, some guy on the Internet or whatever. For that 99% of the population,…

> "Impossible to leave" is not a matter of closed or open, but it's a matter of social networks in general. You could make Facebook free software and its problems wouldn't disappear.

Not true. If you have interoperability between different networks, you can leave. This is how ActivityPub (e.g. Mastodon, PeerTube, PixelFed) works.

> Not to mention that, again, 99% of people will get vendor-locked because in the end nobody wants to run their own instance of a federated social network.

You just switch to any other instance, because Mastodon doesn't prevent you from doing that.

> The main problem with privacy and computer control is a collective one that must be solved through laws. Thinking that individual action and free software will solve it is completely utopic.

We need both. You cannot force Facebook to allow interoperability when there is no other social network.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#407
post #388

Earlier quoted context omitted.

Not too lost 'cause you can run Linux on M1.

The selling point of Macs is the Apple ecosystem and UX. If you avoid Apple, what's the point of M1? Linux on equivalent AMDs is cheaper and more compatible.

> If you avoid Apple, what's the point of M1?

   - (Potentially) programmable top notch security chip with no overhead encryption
   - Fanless (Air), cool running, fast processor with very low power consumption
   - All metal body
   - Top notch HiDPI screen with color accuracy.
   - Top notch sensors
   - Excellent, illuminated keyboard
   - Big trackpad with pressure sensitivity and taptic engine
   - Excellent battery life
   - Excellent battery endurance
   - Very high sound quality, good speakers, good mics.
   - High quality webcam
   - Light for its class
   - WiFi with plenty of antennas, MIMO support and all modern standards, incl. forward facing ones.
Need more?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#408
post #264

Earlier quoted context omitted.

> No genitals are in shot That you even have to consider sexual interpretations of your BABY'S GENITALS is an affront to me. I have pictures of my baby completely naked, because it is, and I stress this, A BABY. They play naked all the time, it's completely normal.

Don't immediately take affront, take the best possible interpretation of the parent comment. This is about automatic scanning of people's photo libraries in the context of searching for child pornography, presumably through some kind of ML. It seems to me that the concern of the commenter is that if there are photos of their child's genitals that they'll be questioned about creating child pornography, not that they'r…

I mean I’m offended on behalf of the parent poster.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#409
post #369
post #278

Earlier quoted context omitted.

The best bet is probably a pixel phone with GrapheneOS. (Do note, that copperhead os is a scam and is not to be used ) Gnu/linux phones have nonexistent security, other than being niche (so security by obscurity at most). And also, they are not yet usable as a daily driver for me personally, at least.

> Do note, that copperhead os is a scam and is not to be used Can you expand on this point a little bit?

While it may be biased, this is a great summary: https://grapheneos.org/history/

Basically Micay is a legitimate security researcher who created the project and it was later hijacked by the company funding some of it. That company since then try to badmouth Micay at any place they find and is doing shady things on top of the still open source code base. Micay was so professional to destroy the verification key at the time of the forking.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#410
post #332

Earlier quoted context omitted.

What do you mean, authorized by whom? The software applications I run have not been greenlit by any third party. Think about a model in which you code, than wait for authorization before deployment... The worst pulp novel. What exactly are you talking about, the OS?

Ah, you were never exposed to RIM's blackberry signing servers... Those were not the days. I'm glad they were slowly snuffed out of existence.

I had them around, but fortunately no need to develop :) Those for me were the times of PalmOS and WindowsCE/Mobile...
Post reply on HN