Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

681–690 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#681
post #523

Earlier quoted context omitted.

The spirit of the internet won’t generate secure hardware or a transparent software stack. Also, that spirit existed only in an adversary free environment. You may as well say the solution is for everyone to be nice to each other. The solution is to build new technologies that are privacy preserving, transparent, don’t place trust in a central authority but are resistant to attack . This is possible but nobody has bu…

You could run Mobian or similar on a phone from Purism/Pine/etc. Problem is you end up with a vastly inferior hardware device that costs nearly as much as an iPhone. I’m still waiting for my Librem 5 preorder. Would love to hear if anyone is actually using a Linux phone and enjoying it.

I have been using a Linux smartphone since 2010 an I certainly do enjoy it - first Nokia N900 & N9 followed by a series of Sailfish OS[0][1] devices, with Xperia 10 II with Sailfish X[2] being the latest one.

[0] https://en.m.wikipedia.org/wiki/Sailfish_OS

[1] https://sailfishos.org/

[2] https://shop.jolla.com/

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#682
post #412

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

If you truly want to "protect the children" you should have no issue for the police to visit and inspect your, and all of your neighbors houses. Every few days. Unannounced, of course. And if you were to resist, you MUST be a pedophile who is actively abusing children in their basement.

I'm actually more OK with unannounced inspections of my basement (within reason) than with some government agents reading through my files all the time.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#683
post #611

Earlier quoted context omitted.

You could run Mobian or similar on a phone from Purism/Pine/etc. Problem is you end up with a vastly inferior hardware device that costs nearly as much as an iPhone. I’m still waiting for my Librem 5 preorder. Would love to hear if anyone is actually using a Linux phone and enjoying it.

> Problem is you end up with a vastly inferior hardware device that costs nearly as much as an iPhone. The Pinephone is $150/$200. > Would love to hear if anyone is actually using a Linux phone and enjoying it. I have one, and I throughly enjoy it! One of the neatest things about it, and I still have to wrap my head around it, is that it can do anything you can do on a desktop. SSH? No problem? Dev environment? "apt…

Exactly! Speaking from the Sailfish OS perspective but thats essentially also a normal Linux distro. It's just so refreshing that studs behaves in logical and introspective manner - have an issue ? Check journal, there will most likely be some hints! Need to transfer data ? Mount the device via sshfs!

In comparison my Galaxy Tab S6 is just so much more black box and some stuff just does not work with no apparent way to debug! Like, I tried to setup a samba or SSH server on it for easy data transfer, with zero success after trying all the related apps in frdoid and elsewhere. It just does not work at all! Most likely some brain dead "security" option one can't override 2without rooting the device that is impossible to track down in the mess that is Android.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#684
post #614
post #603

Earlier quoted context omitted.

One option is getting a Phone that has an unlocked bootloader so one can load their own ROM without Goople Play Services. I have a Pixel 3a with LineageOS, no Google Play. I'm pretty happy with it. While the Pinephone isn't perfect yet, I would argue it will be able to replace Android/iOS in a few months.

> so one can load their own ROM without Goople Play Services Yeah this is the mobile phone equivalent of growing your own vegetables. I get it, I'm a techy, but until the day is here where rooted phones aren't treated like a special case: for most people if they buy a droid then it's actually significantly worse for their personal privacy than an Apple device. I don't want that to be the case, but until the pine phon…

> I don't want that to be the case, but until the pine phone is here and starts being a reasonable alternative; that's how it is.

Someone will have to buy the pine phone when it is not a reasonable alternative to support the effort and keep the ball rolling.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#685

Will this work differently depending on what country you are in? For instance, back in 2010 there was that thing about Australia ruling that naked cartoon children count as actual child porn. [1] It's perfectly legal elsewhere (if a bit weird) to have some Simpsons/whatever mash-up of sexualised images, but if I flew on a plane to the land down under, would I then be flagged? edit: If this is scanning stuff on your p…

[deleted]

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#686
post #648
post #632

Earlier quoted context omitted.

> The software is not anywhere near audited Many of the projects leverage a well known OS as their base (e.g. pmOS uses Alpine Linux, Mobian uses Debian), and actively ensure that anything that can be upstreamed is upstreamed. So it's not like you're downloading some random ROM off of XDA.

That doesn’t make the system audited. The obvious reason we don’t hear more about the weaknesses is that no high value targets are using these systems, so it’s not worth exploiting them.

Um, these distros are normally used to run like half the Internet, they are very valuable targets today and I don't think putting them on a phone changes the threat environment so much.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#687

Earlier quoted context omitted.

You don't need to verify everything yourself. You can verify any small part and rely on the community to verify the rest. Or pay someone to verify. However, for all that you need verifiability , which Apple lacks.

> You can verify any small part and rely on the community to verify the rest. Or pay someone to verify. The only difference in this is who you trust. Be it Apple, the community or someone you pay, you're still trusting that someone else's interests align with yours and they did things correctly. In other words, this is not a technical problem. It's a problem that needs to be solved through regulation, because 99% of…

That just shifts who controls the monopoly on verification. Not trusting anyone isn't a reasonable goal. Open verifiability allows you to choose which entities to put trust in and how much trust you can afford to eliminate by doing things yourself.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#688
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

Great, so what's the solution? What are you doing to fix it? Do you roll your own silicon? Do you grow your own food (we have no idea what someone could be putting in it)? Are you completely off-grid? Or are you as completely dependent on society writ large as everyone else? Making holier than thou comments about everyone else being sheep isn't helpful or thought provoking. Offer an alternative if it is a bad one (lo…

What am I doing to fix it? Nothing!

I'm dependent, just as you say, and have no illusions about that.

Getting into this situation wasn't my decision (it was a collective "decision" of our society), and getting out of this won't be due to anything I'll personally do either.

The only difference between me and the average joe is having understood that we have a problem earlier than most.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#689
post #611

Earlier quoted context omitted.

> Problem is you end up with a vastly inferior hardware device that costs nearly as much as an iPhone. The Pinephone is $150/$200. > Would love to hear if anyone is actually using a Linux phone and enjoying it. I have one, and I throughly enjoy it! One of the neatest things about it, and I still have to wrap my head around it, is that it can do anything you can do on a desktop. SSH? No problem? Dev environment? "apt…

Exactly! Speaking from the Sailfish OS perspective but thats essentially also a normal Linux distro. It's just so refreshing that studs behaves in logical and introspective manner - have an issue ? Check journal, there will most likely be some hints! Need to transfer data ? Mount the device via sshfs! In comparison my Galaxy Tab S6 is just so much more black box and some stuff just does not work with no apparent way…

Honestly after using Android for so long too, even just AOSP has gotten much more user hostile.

Running root used to be very simple and semi-sanctioned. Now you have to essentially rootkit your phone (Magisk) for it.

Most of the AOSP programs are abandoned (thankfully ROM maintainers update them!), and you have to deal with a lot of things not working with Google Play.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#690
post #525

Earlier quoted context omitted.

Yes - and for most people trusting Apple is still a better option, because the ‘community’ option is literally just wishful thinking at this point.

Linux kernel AFAIK has less security issues than Apple. Qubes even less. Not sure what the reason for your insult is.

No insult. You actually don’t know that the Linux kernel has less security issues than Apple’s kernel.

But the kernel is only a tiny fraction of the system. There simply is no Linux system that even attempts to solve the problems Apple solves. There could be, but there isn’t - this is what we mean by the term ‘wishful thinking’.

Post reply on HN