Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

611–620 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#611
post #523

Earlier quoted context omitted.

The spirit of the internet won’t generate secure hardware or a transparent software stack. Also, that spirit existed only in an adversary free environment. You may as well say the solution is for everyone to be nice to each other. The solution is to build new technologies that are privacy preserving, transparent, don’t place trust in a central authority but are resistant to attack . This is possible but nobody has bu…

You could run Mobian or similar on a phone from Purism/Pine/etc. Problem is you end up with a vastly inferior hardware device that costs nearly as much as an iPhone. I’m still waiting for my Librem 5 preorder. Would love to hear if anyone is actually using a Linux phone and enjoying it.

> Problem is you end up with a vastly inferior hardware device that costs nearly as much as an iPhone.

The Pinephone is $150/$200.

> Would love to hear if anyone is actually using a Linux phone and enjoying it.

I have one, and I throughly enjoy it! One of the neatest things about it, and I still have to wrap my head around it, is that it can do anything you can do on a desktop. SSH? No problem? Dev environment? "apt install build-essentials". Want to install XFCE? Knock yourself out!

It is still missing MMS, which is why I don't use it daily, but that should be changing much sooner than later.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#612

Earlier quoted context omitted.

> If you avoid Apple, what's the point of M1? - (Potentially) programmable top notch security chip with no overhead encryption - Fanless (Air), cool running, fast processor with very low power consumption - All metal body - Top notch HiDPI screen with color accuracy. - Top notch sensors - Excellent, illuminated keyboard - Big trackpad with pressure sensitivity and taptic engine - Excellent battery life - Excellent ba…

- No dumb LEDs keeping you awake.

Of course this would anger the PC crowd.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#613
post #226

It's funny to see anyone here could find this acceptable. I wonder what's comments would be after Apple start to scan phones for anti-censorship or anti-CCP materials in China. Or for some gay porn in Saudi Arabia. Because you know in some countries there are materials that local government find more offensive than mere child abuse. And once surveillance tech is deployed it's certainly gonna be used to oppress people…

Exactly, now Apple has this tech, shady governments know they can mandate Apple to use it for their own databases and Apple will have to do this if they want to keep operating within a territory.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#614
post #603
post #569

Earlier quoted context omitted.

The alternative is? Google phone? This is not an alternative if you care about privacy. The allegory presented sounds insane (growing your own food) but honestly if you're not rolling your own flashed ROM on a 'droid then your privacy is dead already; I understand throwing all your eggs in one basket is a terrible idea but Apples walled garden and heavy sandboxing was at least somewhat protective.

One option is getting a Phone that has an unlocked bootloader so one can load their own ROM without Goople Play Services. I have a Pixel 3a with LineageOS, no Google Play. I'm pretty happy with it. While the Pinephone isn't perfect yet, I would argue it will be able to replace Android/iOS in a few months.

> so one can load their own ROM without Goople Play Services

Yeah this is the mobile phone equivalent of growing your own vegetables.

I get it, I'm a techy, but until the day is here where rooted phones aren't treated like a special case: for most people if they buy a droid then it's actually significantly worse for their personal privacy than an Apple device.

I don't want that to be the case, but until the pine phone is here and starts being a reasonable alternative; that's how it is.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#615

Earlier quoted context omitted.

Is there some way of verifying that the fingerprints in this database will never match sensitive documents on their way from a whistleblower to journalists, or anything else that isn't strictly illegal? How will this tech be repurposed over time once it's in place?

You seem to be suggesting that the AI will go directly from scanning your photos for incriminating fingerprints to reporting you to journalists. I have to assume humans are involved at some point before journalists are notified. The false-positive will be cleared up and no reputations sullied (except perhaps the reputation of using AI to scan for digital fingerprints).

The other way around. If the database of fingerprints is unauditable, and especially if the database varies from country to country, then it would be very easy to add fingerprints for classified documents, or photos documenting known war crimes, or even just copyrighted stuff to close the so-called analog hole.

Documents could also be engineered to trigger false positives, making it difficult or impossible for a corporate whistleblower to photograph incriminating evidence to deliver to the authorities.

So, if the rumors are true and every iPhone will check every photo against an opaque database of perceptual fingerprints, what safeguards exist (beyond "trust us" from the database keepers) to prevent abuse of the feature to suppress evidence and control the flow of information, and which organizations or governments will have control over the contents of the database? As always, who watches the watchers?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#616

Earlier quoted context omitted.

Nothing is ever perfectly secure. It's a question of whom you should trust for a lesser damage.

Apple spends a hell of a lot more time and money verifying that my iPhone is secure than say… the developers of any number of the mobile Linux ports. Plus the hardware is nice and actually works. I agree with what you say in principle but here I am using an iPhone to type this while it’s been nearly 2 years since I ordered my Librem 5. Making decent mobile devices that are more secure than an iPhone is not an easy th…

I wondered whether this was sarcasm at first. Yes, making iCloud backups encrypted is not an easy thing I guess.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#617
post #614
post #603

Earlier quoted context omitted.

One option is getting a Phone that has an unlocked bootloader so one can load their own ROM without Goople Play Services. I have a Pixel 3a with LineageOS, no Google Play. I'm pretty happy with it. While the Pinephone isn't perfect yet, I would argue it will be able to replace Android/iOS in a few months.

> so one can load their own ROM without Goople Play Services Yeah this is the mobile phone equivalent of growing your own vegetables. I get it, I'm a techy, but until the day is here where rooted phones aren't treated like a special case: for most people if they buy a droid then it's actually significantly worse for their personal privacy than an Apple device. I don't want that to be the case, but until the pine phon…

> Yeah this is the mobile phone equivalent of growing your own vegetables.

Sadly...I know. The unfortunate thing is my recommendation for my family/friends for a phone is an iPhone, because it really is the best for security/privacy today, and they at least support their phones for much longer than an Android.

> I don't want that to be the case, but until the pine phone is here and starts being a reasonable alternative; that's how it is.

Fortunately, I think that time is coming sooner than later.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#618
post #520

Earlier quoted context omitted.

Yeah that’s a fair point. The only reason I was careful was just in case those photos got leaked and taken out of context. Which is a bloody depressing thing to consider when innocently taking pictures of your own family :(

I might have phrased that ambiguously, I mean "an affront to me" as in "to me, that's an affront", not that you have somehow insulted me. I say let children be free, no court is going to indict you because you have baby pictures on your phone.

> no court is going to indict you because you have baby pictures on your phone

Maybe, maybe not. Bad luck is possible with anything involving police, prosecutors, judges, and juries. Need justification for that point of view? Just look at the number of people who were convicted and spent time in jail who truly were innocent. That doesn't even touch on the possible repercussions that can happen from just being questioned/arrested and later let go.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#619

Earlier quoted context omitted.

Then once the manufacturer makes that decision, switch. Honestly this comment is just nonsense.. Apple has always allowed other OSes on Mac. When that changes, buy a new computer.

The iPhone came out 14 years ago, and still doesn't allow switching OS. What more do you need?

The iPhone and the Mac are different platforms, developed at different times, for different purposes and different markets with different design philosophies. I don’t see a logical connection between the iPhone being bootlocked and the Mac necessarily following suite.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#620
post #531

Earlier quoted context omitted.

To quote another tweet from Matthew Green, the author of the Twitter thread ( https://twitter.com/matthew_d_green/status/14231103447303495... ): > Regardless of what Apple’s long term plans are, they’ve sent a very clear signal. In their (very influential) opinion, it is safe to build systems that scan users’ phones for prohibited content. > That’s the message they’re sending to governments, competing services, China…

Is it? That’s just something the tweets have read in. The message could equally well be ‘We won’t become an easy political target by ignoring a problem something most people care about like child porn, but we are going to build a point solution to that problem, so the public doesn’t force us to bow government surveillance requests.’ It’s easy to nod along with an anti-Apple slogan, but we need to consider what would…

If Apple thought this kind of dragnet was a losing political fight that tells me they've become too weak to stand up to unreasonable government demands. Where is the company that won the public opinion battle over unlocking a mass shooter's phone?
Post reply on HN