So this new Apple stuff has made me decide not to buy an M1. I'm leaning Framework laptop. For my phone though... no idea. My iPhone is honestly such a solid piece of tech. I don't _want_ to go Google either... so what else do i have? I know lots of people run de-googled Androids, which i guess works, but i'd prefer to avoid them entirely. Is there anything that works? edit : I know of the Purism phone ( https://puri…
Apple’s new abuse prevention system: an antritust/competition point of view
221–230 of 318 posts
Re: Apple’s new abuse prevention system: an antritust/competition point of view
#222Re: Apple’s new abuse prevention system: an antritust/competition point of view
#223There is no such thing as a trustworthy third party and even trusting yourself is questionable at the best of times. We are constantly balancing a bunch of different considerations with regards to the way that we compute, purchase devices, and utilize services. Security and privacy are of course important, and Apple to date has had a fairly good (if shallow) track record in this regard, at least in the United States.…
> "As mentioned in the article, this does absolutely nothing towards protecting children other than directing all but the biggest idiots towards platforms that can't be linked to them, which I'd imagine, they already are." I suspect you're more wrong than you think about this. People share large volumes of CSAM through lots of different services - I knew someone who worked on the problem at Linked In (!). HN likes to…
Re: Apple’s new abuse prevention system: an antritust/competition point of view
#224> But when a backdoor is installed, the backdoor exists and history teaches that it’s only a matter of time before it’s also used by the bad guys and authoritarian regimes. Problem is that this scanning is necessarily fuzzy and there is going to be a false positive rate to it. And the way that you'll find out that you've tripped a false positive is that the SWAT team will knock your door down and kill your dog (at a…
> Problem is that this scanning is necessarily fuzzy and there is going to be a false positive rate to it. And the way that you'll find out that you've tripped a false positive is that the SWAT team will knock your door down and kill your dog (at a minimum). Not true. Hash matches are to be human reviewed. So no, people won't get "swatted" accidentally as you allege. The other concerns people have been voicing are ce…
Re: Apple’s new abuse prevention system: an antritust/competition point of view
#225This is optional. You don’t HAVE to use iCloud for your photos. This is no different that YouTube searching videos you upload for copyrighted music. If you don’t want your photos scanned, don’t upload your images to their servers.
Re: Apple’s new abuse prevention system: an antritust/competition point of view
#226Earlier quoted context omitted.
No. A registered charity called The National Center for Missing and Exploited Children controls the hash list. Yes, they are partly government funded, but I highly doubt they'd let their mission be compromised by allowing the government to inject non-CP hashes. Doing so would compromise all the work they've performed over the last four decades. These people are (rightfully) very passionate about their work and can't…
> by allowing the government to inject non-CP hashes I don't think "allowing" is the concern here, because I highly doubt they get to generate the hashes themselves.
Re: Apple’s new abuse prevention system: an antritust/competition point of view
#227Earlier quoted context omitted.
Yes but my understanding is that the hashes are perceptual, as opposed to cryptographic. If the system was matching against known cryptographic hashes the collision / false positive rate would be small, but the fuzzy matching involved with perceptual hashing necessarily has a greater false positive rate. And that doesn’t even begin to address the detection of sent and received “explicit images” which are detected on…
I suspect that's why they have some threshold that moves the false positive rate to one in one trillion. The iMessage bit is different - it's only on device, only on child accounts, and only alerts parents. It's more akin to a parental control feature than anything else.
Bugs in the application of the code, combined with human complacency and mistakes can certainly lead to errors, even if the cryptographic algorithm itself was perfect.
We really need to bring back comp.risks
Re: Apple’s new abuse prevention system: an antritust/competition point of view
#228Earlier quoted context omitted.
It only scans images in your iCloud Photo Library. Not paying for iCloud? No scanning. Not in your photo library? No scanning. And even then, only for known content, not new content.
So the attacker only needs to get access to your iCloud. Your iPhone will happily sync down photos uploaded elsewhere. You don't have to be paying for iCloud, either. There's a free tier, so I'd imagine almost all iPhones are using some tier of it. iCloud account break-ins aren't exactly rare. An accusation, even if false, could ruin an innocent person's life.
i was quite surprised to see this was the default or at least was setup unknowingly to me.
Re: Apple’s new abuse prevention system: an antritust/competition point of view
#229Earlier quoted context omitted.
If you actually think there is going to be a fully automated system dispatching police SWAT teams throughout the US without a manual (or judicial) review then.... I really don't know what to tell you.
Guess its hard to believe that their is a world outside of the United States. Already do whatever it takes to pin some BS on someone that opposes them and has them executed. This would be no different.
Especially since anything flagged by this system is manually reviewed by Apple. So, there would exist counter-evidence for the govt claim.
Don’t misunderstand, I see how this system is ripe for abuse. I was just commenting on the specific claim that there will be automated SWAT call outs (presumably in the US).
Re: Apple’s new abuse prevention system: an antritust/competition point of view
#230Earlier quoted context omitted.
Yes, but then there's a way to upload it in plaintext. That's the backdoor. That can, and will, eventually be used to exfiltrate any file, anytime, whether it would be going to the cloud or not.
It does set a terrible precedent, but it's possible this is a step towards E2E encryption on iCloud data; a way to comply with the law while preventing law enforcement from being able to subpoena other data. Apple is being its usual cryptic self about this, which is once again breeding uncertainty, but I still have hope in the end this will work out.