Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

661–670 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#661
post #489

Earlier quoted context omitted.

>windows TPM aren’t snitching on you? The TPM FUD has really gone out of hand. 1. there's no such thing as "windows TPMs", whatever that means. 2. TPMs basically has zero access to the rest of the system. It's connected via a LPC bus, so there's no fancy DMA attacks to pull off. Over that bus the system firmware sends various hashes of the system state (eg. hash of your bootloader), but that's about it.

> 2. TPMs basically has zero access to the rest of the system. It's connected via a LPC bus, so there's no fancy DMA attacks to pull off. Over that bus the system firmware sends various hashes of the system state (eg. hash of your bootloader), but that's about it. That's the specification. Have you actually monitored the bus using probes? Did you check that the TPM is only connected to LPC?

>Have you actually monitored the bus using probes

Isn't this the definition of FUD?

>Did you check that the TPM is only connected to LPC?

Dunno, you tell me. https://en.wikipedia.org/wiki/File:TPM_Asus.jpg

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#662

Earlier quoted context omitted.

Most other manufacturers aren't in the business of pushing their own OS.

Fwiw, Apple's incentive seems to be hardware from the outside more than Software, imo. They tend to sell the hardware by the software for a lot of people, but given that they're so concerned with keeping their software on their hardware i suspect they don't have much reason to push their software over your software. What would concern me is if we see a big revenue stream from their software. Then i'd question them no…

This is a 2017 article[1] about how Tim Cook pushed Apple to get more revenue from software services. Recent articles this year add to say that Apple has been successful in this area. So perhaps the image of Apple being mainly a hardware company is outdated.

[1] https://www.applemust.com/apples-50b-services-target-just-is...

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#663
post #586

Earlier quoted context omitted.

A country can collect a list of people sharing any content they put on a hash list. Like gay porn, 'save Khashoggi' meme, or a photo from documentary about missing Uighurs. It's hard to imagine how this could be misused, right?

That seems like a real problem, and of course it could be misused, however nothing so far revealed actually tells us whether it is possible. E.g. how the hashes are computed, where they come from, and what happens when a positive match is detected. Until we have a clear understanding of these things, the rest is just speculation.

The hashes will of course be provided by local governments, who have the ultimate authority (because they can forbid Apple to sell there, and Tim Cook never says no to money).

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#664
post #525

Earlier quoted context omitted.

Nothing is ever perfectly secure. It's a question of whom you should trust for a lesser damage.

Yes - and for most people trusting Apple is still a better option, because the ‘community’ option is literally just wishful thinking at this point.

Linux kernel AFAIK has less security issues than Apple. Qubes even less. Not sure what the reason for your insult is.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#665
post #511

Earlier quoted context omitted.

> >99% of the population will delegate the decision of what code is allowed to run to someone, be it the manufacturer, the government, some guy on the Internet or whatever. For that 99% of the population, by the way, it's actually more beneficial to have restrictions on what software can be installed to avoid malware > I do not agree with this. You are saying people are too stupid to make decisions and that is amoral…

> How much of the code running on your data do you personally inspect? https://news.ycombinator.com/item?id=28072201

So you've reversed your earlier position and now admit that it is normal and reasonable for most people to delegate this work? You can call it “the community” but it's still delegation.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#666

Earlier quoted context omitted.

> And then take what actions, exactly? Don’t buy or use their products.

Unrealistic. My non-tech family and friends don’t care about this, and I can’t make them care. They don’t understand why it’s a problem; they agree with the motive and don’t understand that it’s not actually a solvable problem. It’s not totally dissimilar to the crypto backdoor problem. Normies think it’s great for only the feds to break encryption. Doesn’t work that way, but you can’t explain why to someone who does…

[deleted]

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#667

Earlier quoted context omitted.

Nothing is ever perfectly secure. It's a question of whom you should trust for a lesser damage.

Apple spends a hell of a lot more time and money verifying that my iPhone is secure than say… the developers of any number of the mobile Linux ports. Plus the hardware is nice and actually works. I agree with what you say in principle but here I am using an iPhone to type this while it’s been nearly 2 years since I ordered my Librem 5. Making decent mobile devices that are more secure than an iPhone is not an easy th…

> Apple spends a hell of a lot more time and money verifying that my iPhone is secure than say… the developers of any number of the mobile Linux ports.

Secure against entities they don't like. But intentionally insecure against entities they do like.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#668
post #333

Earlier quoted context omitted.

This sort of scanning has existed for well over a decade, and was originally developed by Microsoft (search PhotoDNA). The only thing that's changed here is that there is more encryption around, and so legal guidelines are being written to facilitate this, which has been happening for a long, long time. (I don't disagree with your overall point, and child porn is definitely the thin edge of the wedge, but this isn't…

That's a very strong frog slowly boiling attitude. "It's been happening for a long time already, the only difference now is a 0.1 degree increase", says the frog while being boiled alive.

First they came for kiddie porn, and I did not speak out -because I had no kiddie porn. Then they came for Pepe the frog memes. I did not speak out -because I was held in solitary confinement pending trial and successful completion of the re-education camp.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#669
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

Great, so what's the solution? What are you doing to fix it? Do you roll your own silicon? Do you grow your own food (we have no idea what someone could be putting in it)? Are you completely off-grid? Or are you as completely dependent on society writ large as everyone else? Making holier than thou comments about everyone else being sheep isn't helpful or thought provoking. Offer an alternative if it is a bad one (lo…

How about not supporting it as a start? Approximately half the country, and a majority of tech workers, were happy with #4 and in fact encouraging it.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#670
post #53

It's quite easy to extrapolate this and in a few steps end up in a boring dystopia. First it's iPhone photos, then it's all iCloud files, that spills into Macs using iCloud, then it's client side reporting of local Mac files, and somewhere along all other Apple hardware I've filled my home with have received equivalent updates and are phoning home to verify that I don't have files or whatever data they can see or hea…

> What is the utopian perspective of this which counterbalances the risks for this to be a path worth taking? Apple takes care of everything for you, and they have your best interests at heart. You will be safe, secure, private and seamlessly integrated with your beautiful devices, so you can more efficiently consume. What's not to like about a world where child crime, terrorism, abuse, radical/harmful content and mi…

Who will be accountable for the creeps at apple? Or their overlords in the government?
Post reply on HN