Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

691–700 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#691
post #648

Earlier quoted context omitted.

That doesn’t make the system audited. The obvious reason we don’t hear more about the weaknesses is that no high value targets are using these systems, so it’s not worth exploiting them.

Um, these distros are normally used to run like half the Internet, they are very valuable targets today and I don't think putting them on a phone changes the threat environment so much.

The threat environment is utterly different between an individual person’s phone and an anonymous server behind a firewall on the internet.

It’s not even close.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#692
post #15

Earlier quoted context omitted.

To start scanning my local photos on my local phone and report back?

Apple has been scanning your photos locally for quite some time now. They've been detecting faces, making collections, finding pets, etc. This is just another step in what they have already been doing.

Processing data locally and maintaining information locally is wholly different from reading (supposedly encrypted) information from your device and reporting it back.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#693

Earlier quoted context omitted.

Apple spends a hell of a lot more time and money verifying that my iPhone is secure than say… the developers of any number of the mobile Linux ports. Plus the hardware is nice and actually works. I agree with what you say in principle but here I am using an iPhone to type this while it’s been nearly 2 years since I ordered my Librem 5. Making decent mobile devices that are more secure than an iPhone is not an easy th…

I wondered whether this was sarcasm at first. Yes, making iCloud backups encrypted is not an easy thing I guess.

My comment was directed at the people who would say “don’t use apple” as if Android or any number of FOSS phone alternatives with 5 people maintaining them are more secure than IOS.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#694
post #524

Earlier quoted context omitted.

Signal famously implemented, or at least claimed to implement, a rather similar-sounding feature as a countermeasure against the Cellebrite forensics tool: https://signal.org/blog/cellebrite-vulnerabilities/

What is file that they have installed?

If they told that, people would (try to) remove it. The whole point is that you can't know which (if any) of the hundreds of thousands of files on your device it is. So they aren't telling. Could be they have (or at least claim to have) written their system so it chooses files at random; I think that's what I would do (or claim to have done).

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#695
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

Fuck you.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#696
post #584
post #62

I was under the impression that one of the reasons why these tools aren’t available for public download is because the hashes and system can be used to design defeat mechanisms? Doesn’t this mean that someone who has an image and a jail broken device can just watch the system, identify how the photo is detected, and modify it so that it doesn’t trip the filter? PhotoDNA and systems like it are really interesting, but…

I see it as a huge risk too. If the algorithm and the blocklists leaked, then not only it would be possible to develop tools that reliably modify CSAM to avoid detection, but also generate new innocent-looking images that are caught by the filter. That could be used to overwhelm law enforcement with false positives and also weaponized for SWAT-ing.

Fortunately, it seems that matching is split between client-side and server-side, so extraction of the database from the device will not easily enable generation of matching images.

https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#697

Earlier quoted context omitted.

Unrealistic. My non-tech family and friends don’t care about this, and I can’t make them care. They don’t understand why it’s a problem; they agree with the motive and don’t understand that it’s not actually a solvable problem. It’s not totally dissimilar to the crypto backdoor problem. Normies think it’s great for only the feds to break encryption. Doesn’t work that way, but you can’t explain why to someone who does…

Perhaps as I stated it, yeah it seems unrealistic. However I do think there’s value in gentle, consistent evangelism of privacy in ways that don’t make people feel bad. Most folks actually don’t want their deeply private stuff to be accessible. I’ve found that there are good analogies and ways to think about it that folks can get on board with and start caring to some extent. I absolutely agree that political progres…

A good start would be for the government to stop trying to bully tech companies into compromising on their privacy.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#698

Earlier quoted context omitted.

You should read the rest of the linked Twitter thread, because the issue is that if the hash algorithm has a collision vulnerability, any image could be manipulated to show up as "child porn" to the scanner.

Microsoft created and hosts the PhotoDNA service which all providers use, and PhotoDNA has false positives. All reports are supposed to be manually reviewed before being sent to Cyber Tip.

But, are they? The Swiss federal police weren't too happy about the reports they received from the Cyber Tip.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#699

Earlier quoted context omitted.

Fwiw, Apple's incentive seems to be hardware from the outside more than Software, imo. They tend to sell the hardware by the software for a lot of people, but given that they're so concerned with keeping their software on their hardware i suspect they don't have much reason to push their software over your software. What would concern me is if we see a big revenue stream from their software. Then i'd question them no…

Are you kidding? After getting a taste of the revenue-potential of software in the App Store, it is inevitable that Apple wants more of it. In fact, I predict that Apple will at one point start selling software as a subscription, like SaaS. Other OSes don't fit in that model.

> I predict that Apple will at one point start selling software as a subscription

That’s not a difficult prediction. https://en.wikipedia.org/wiki/Apple_Arcade:

“Apple Arcade is a video game subscription service offered by Apple Inc. It is available through a dedicated tab of the App Store on devices running iOS 13, tvOS 13, iPadOS 13, and macOS Catalina or later. The service launched on September 19, 2019 after being announced in March 2019”

They also have “hardware as a service”. https://www.apple.com/shop/iphone/iphone-upgrade-program:

“The easiest way to upgrade to the latest iPhone. Get a new iPhone every year AppleCare+ coverage included Works with your carrier Starting from $35.33/month”

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#700

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

There have been child abuse victims who have openly condemned this sort of intrusion on privacy, although they obviously don't speak for them all.
Post reply on HN