Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

641–650 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#641

Earlier quoted context omitted.

Viable alternatives were long gone. I really miss the days of Symbian and Meego, phones that are hackable yet intuitive to use (I.e. Nokia N900, N9). Realistically now we have Tizen and Jolla OS, which had backings from Samsung but nobody gave two damn about it. I bet even if any of these vanilla mobile OS gets big enough they’ll get bought by the 3 giants and suffocated to death just like how Microsoft sniped Nokia.

Samsung is one of the companies I trust the least with regards to security, privacy, and overall competence in software.

Why though? How are they worse than Google for example?

Were there any recent examples where they failed in those?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#642
post #245

Earlier quoted context omitted.

But are these photos that are combined in a row with other CP, and thus indicative that if you have this photo, it’s from a CP collection? Why would I have any content in my phone that would be in that database?

Imagine things like: - A kitchen with nobody in frame. - A couch with nobody in frame. - Outdoor scenery with nobody in frame. - A bathroom with nobody in frame. Is it hard to believe you wouldn't download something like this without knowing where it came from? I'm not talking about borderline stuff. I'm talking about content that has not even a hint of pornography or illegality.

But why am I downloading such things to begin with? Not only do these sound like very boring photos, given their providence I don’t understand this realistic pathway to get onto my phone.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#643
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

Great, so what's the solution? What are you doing to fix it? Do you roll your own silicon? Do you grow your own food (we have no idea what someone could be putting in it)? Are you completely off-grid? Or are you as completely dependent on society writ large as everyone else? Making holier than thou comments about everyone else being sheep isn't helpful or thought provoking. Offer an alternative if it is a bad one (lo…

> Great, so what's the solution? What are you doing to fix it?

Nothing, because my phone is rooted Android.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#644
post #638
post #636

Earlier quoted context omitted.

Respectfully, I think you missed the point of my reply. The person asked: "Would love to hear if anyone is actually using a Linux phone and enjoying it." ...so I responded about what I enjoy about using a "Linux Phone". A "$10 raspberry pi-w" is not a Linux Phone. The question didn't address "security and privacy", so I didn't add it. Though, since you brought it up, I will answer how the Pinephone "helps with having…

Fair enough - I fully agree it would be enjoyable for a Linux enthusiast. I have had one on my shopping list for some time, but I want to use it as a daily driver and since most people say it isn’t ready for that, slightly lower level projects keep winning out.

> I want to use it as a daily driver

What I have encountered is the requirements for it being a daily driver are user specific. I have seen a fair amount of users say "I need $FOO app to work", where $FOO is some an app only developed for Android/iOS (a common one is a banking app, there is almost no way that company will support a Linux phone). So I guess I would ask what your requirements are before I can say if it is daily driver ready or not.

My threshold for it being a "daily driver" is if I can fully replace the "phone" features of my Android phone, which for me, is: Calling, SMS, MMS, Voicemails. MMS is not yet UI functional, but will be sooner than later.

The good news is I am seeing the Linux Phone movement be a positive feedback loop: the more features add, the more users, and the more folks helping to add features.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#645
post #414

Earlier quoted context omitted.

Not an American, but shouldn't you be able to FOIA this?

The NCMEC, who manages the CSAM database, is a private organization.

Wait, so two American companies, Apple and NCMEC, are working together to install spyware on all Apple devices world-wide, with no government involvement?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#646
post #226

It's funny to see anyone here could find this acceptable. I wonder what's comments would be after Apple start to scan phones for anti-censorship or anti-CCP materials in China. Or for some gay porn in Saudi Arabia. Because you know in some countries there are materials that local government find more offensive than mere child abuse. And once surveillance tech is deployed it's certainly gonna be used to oppress people…

> I wonder what's comments would be after Apple start to scan phones for anti-censorship or anti-CCP materials in China.

I'm cynical enough to wonder whether this isn't their actual commercial reason for developing this, with CSAM being a PR fig leaf. Apple is substantially more dependent on China than its major competitors.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#647
post #644
post #638

Earlier quoted context omitted.

Fair enough - I fully agree it would be enjoyable for a Linux enthusiast. I have had one on my shopping list for some time, but I want to use it as a daily driver and since most people say it isn’t ready for that, slightly lower level projects keep winning out.

> I want to use it as a daily driver What I have encountered is the requirements for it being a daily driver are user specific. I have seen a fair amount of users say "I need $FOO app to work", where $FOO is some an app only developed for Android/iOS (a common one is a banking app, there is almost no way that company will support a Linux phone). So I guess I would ask what your requirements are before I can say if it…

Sure - for me (and likely >99.9% of people), from what I have read, it is clearly not ready. I’m a heavy phone user in most respects. For me it would have to start as a hobby project.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#648
post #632
post #528

Earlier quoted context omitted.

This is clearly a good thing to do and supporting those projects is great. So far though, they do nothing to solve the problems we are talking about. The software is not anywhere near audited, and even if it were, you are still interacting with people and services who are using unaudited software.

> The software is not anywhere near audited Many of the projects leverage a well known OS as their base (e.g. pmOS uses Alpine Linux, Mobian uses Debian), and actively ensure that anything that can be upstreamed is upstreamed. So it's not like you're downloading some random ROM off of XDA.

That doesn’t make the system audited. The obvious reason we don’t hear more about the weaknesses is that no high value targets are using these systems, so it’s not worth exploiting them.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#649

That tweet thread is saying it will scan for hashes client side and upload the result, circumventing E2E encryption, but then says theyre just going to do it on your icloud backups because they dont have E2E encryption, so which is it? All?

It doesn't say that. Today Apple servers scan uploaded photos. Tomorrow Apple phones will scan uploaded photos. The next day Apple phones could scan not uploaded photos.

The next day Apple phones could periodically listen to the environment via the internal microphone. The next day Apple phones could take and upload photos of the environment by itself.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#650
post #361

Earlier quoted context omitted.

A report to the cybertips line does not equal a police raid. Unfortunately the scale of the problem and the pace of growth is such that only the worst of the worst content is likely to be prosecuted.

If a phone calls the API "hello, I found some porn here" the phone (and/or it's owner) become a "person of interest" very quickly. (I'll wager) The majority of these calls will be false positives. Now a load of resources get deployed to keep an eye on the device's owner, wasting staff time and compute, wasting (tax funded) government budget that could have gone towards proper investigation.

[deleted]
Post reply on HN