Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

31–40 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#31
I'm not usually the most idealistic when it comes to FOSS, but it's stories like this and Apple's stance of "trust us, we promise we know what we're doing and that nothing is going to go wrong" that makes me think all software should be legally required to be open source.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#33
post #7

I was actually looking to buy the new iPhone should they add back TouchID, but this has been quite the turnoff. Are Pixel phones the only android phones that allow you to do secure boot with non stock images and basically long term cripple phone functionality once its unlocked?

Google does the same with Google Drive. Apple is just late for the party.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#34
At this point we need to be doing more than signing open letters to companies that are completely free to ignore them.

If you work for Apple and don't stand up to this, you should find it extremely hard to find employment or acceptance anywhere. If you're a hiring manager, throw the resumes of anyone that worked at Apple in the trash.

It should be a black mark on you if you continue to work and contribute to Apple after this; If you continue to work for them or support them, you should be ostracized.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#35
post #30
post #28

Earlier quoted context omitted.

You can even sync to $nasty_cloud_provider and don't provide the syncthing password. Problem solved!

What? Syncthing is not a backup program, it, as the name suggests, syncs folders and files. There is no password involved.

Check out: https://docs.syncthing.net/branch/untrusted/html/users/untru...

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#36

I'm not usually the most idealistic when it comes to FOSS, but it's stories like this and Apple's stance of "trust us, we promise we know what we're doing and that nothing is going to go wrong" that makes me think all software should be legally required to be open source.

It would be if y’all slapped the AGPLv3 on your code instead of Apache/MIT/BSD.

If we were to perform a cyber analog of what the founding fathers did for the USA 250 years ago, it would be something along the lines of declaring all software free from the tyranny of corporate control and state oppression. Free in perpetuity so that our digital projections onto hardware shall reside comfortably each in their own pursuit of happiness.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#37
post #29
post #14

Earlier quoted context omitted.

Fairphone allows re-locking the bootloader with the /e/ rom flashed.

The annoying thing about unlocking or relocking the bootloader is that it wipes your phone. Unless you're paranoid that someone can give you a rootkit while you're not looking, as long as you use full device encryption then leaving the bootloader unlocked isn't too bad. Plus, it lets you upgrade your bootloader and OS later. I stupidly relocked the bootloader after installing LineageOS and now I can't upgrade the OS…

I'm in the same boat with my Fairphone and /e/. ;)

For me, re-flashing wouldn't even be that much of a hassle since I have contacts and all in my Nextcloud instance and would only have to make a backup of Signal (I barely use my phone - about 2-3 hours total per month), but I just can't get myself to do it.

Should have sticked with my trusted ol' Nokia 3110c I used for a good 13 years, but alas I sent that in to Fairphone for recycling after I bought my Fairphone 3 last year (which I only bought in the first place because finding CNG gas stations is such a hassle here in Germany).

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#38

I'm not usually the most idealistic when it comes to FOSS, but it's stories like this and Apple's stance of "trust us, we promise we know what we're doing and that nothing is going to go wrong" that makes me think all software should be legally required to be open source.

How would OSS help in this case? Someone can run a hash, find an “offensive” photo and jail you. Shit, if someone is out to get you, they will dig up any photo on your phone, put it in the “bad hashes” database and just wait for Apple to catch you. And then you’re effed, because no court will want to publicly display a photo that may contain child pornography, so you’ll be jailed without a fair trial.

OSS won’t help here. This system must be shut down, and the gov should deal with pedos in a different way.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#39
post #30
post #28

Earlier quoted context omitted.

You can even sync to $nasty_cloud_provider and don't provide the syncthing password. Problem solved!

What? Syncthing is not a backup program, it, as the name suggests, syncs folders and files. There is no password involved.

Syncthing now supports untrusted device sync[0] (i.e. storing an encrypted copy on an untrusted device) in a recent version, though this is still on beta.

[0]: https://docs.syncthing.net/users/untrusted.html

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#40
post #2

I signed this, but I'm very doubtful this will ever achieve something. But this made me wonder: is there an history of people complaining about this sort of things and actually achieving something? I think this might have happened with MSFT's hailstorm/passport, where in the end industry opposition meant the project was abandoned, but I can't recall other instances.

Google cancelled its DoD drone program because of employee protests. https://www.fedscoop.com/google-project-maven-canary-coal-mi...
Post reply on HN