Live data from Hacker News

Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

crypto.stackexchange.com

41–50 of 86 posts

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#41
post #27

For some reason, after reading the initial reporting on this system, I thought it was running against any photos on your iPhone, but now I read the actual paper, it seems like it only applies to photos destined to be uploaded to iCloud? So users can opt out by not using iCloud?

As far as I know apple plans to put up 2 systems, one focused on phones of people age But I haven't looked to closely into it.

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#42

Why does Apple even bother with encryption? They should just skip all of the warrant requirements etc and use their iCloud keys to unlock our content and store it unencrypted at rest. Maybe they can also build an api so that governments can search easily for dissidents without the delays that the due process of law causes.

They already have that. https://en.wikipedia.org/wiki/PRISM_(surveillance_program) But the 'security' services want access to what's on people's phones too.

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#43
post #27

For some reason, after reading the initial reporting on this system, I thought it was running against any photos on your iPhone, but now I read the actual paper, it seems like it only applies to photos destined to be uploaded to iCloud? So users can opt out by not using iCloud?

As far as I know apple plans to put up 2 systems, one focused on phones of people age But I haven't looked to closely into it.

Yeah this is basically it.

They have a system that checks for hashes of images to try and find specific CSAM from a database when images are uploaded to iCloud, this already happens but is now moving on device. When explaining this I've used the analogy that here they are looking for specific images of a cat, not all images that may contain a cat. When multiple images are detected (some threshold not defined) it triggers an internal check at apple of details about this hash and may then involve law enforcement.

The other one is for children 12 and under, that are inside a family group. The parents are able to set it up to show a pop up when it detects adult content. In this case they are looking for cats in any image, rather than specific cat image. The popup lets them know it may be an image not suitable for kids, that its not their fault and they can choose to ignore it. It also lets them know if they chose to open it anyway their parents will get notified and be able to see what they've seen.

This is a good rundown: https://www.apple.com/child-safety/

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#44
post #10
post #7

Earlier quoted context omitted.

What is the difference between CP and CSAM and why is everyone suddenly using the term CSAM instead of CP?

CSAM is not necessarily pornographic material, but merely material that becomes objectionable within context. For example, parents' photos of kids in the bath isn't CP. However _someone else_ having a _quantity_ of bath photos is CSAM, if they have no reasonable reason for possessing them.

It’s very muddy, though. The number of pictures on one’s hard drive is irrelevant to the fact that a child has been abused or not. In your example, none of the children would have been abused. Also, who gets to define how much “a lot” is? We can’t say that it’s ok if it’s your children (or grand-children’s, or nephews, etc), because most of child abuse cases involve close family members or close friends.

We definitely should punish exploitation of children, including sexual, and we definitely should punish distributing images of this. But conflating exploiting, distributing, and viewing, and then putting a big taboo on this, is really not ideal. These things are different. Otherwise what we end up with is righteous frenzy when someone gets punished for sexting.

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#45

Regardless of whether this attack works or not, you'd assume this scheme produces a wider attack surface against pictures in iCloud and against iCloud users. One attack I could imagine is a hacker uploading child porn to a hacked device to trigger immediate enforcement against a user (and sure, maybe there are more controls involved but would you carry around a very well-protected, well-designed hand grenade in your…

Or even a hash collision with a banned image. Actually, if that could be generated this thing could fall apart pretty quickly if such collisions could be widely distributed.

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#46
post #10

Earlier quoted context omitted.

CSAM is not necessarily pornographic material, but merely material that becomes objectionable within context. For example, parents' photos of kids in the bath isn't CP. However _someone else_ having a _quantity_ of bath photos is CSAM, if they have no reasonable reason for possessing them.

It’s very muddy, though. The number of pictures on one’s hard drive is irrelevant to the fact that a child has been abused or not. In your example, none of the children would have been abused. Also, who gets to define how much “a lot” is? We can’t say that it’s ok if it’s your children (or grand-children’s, or nephews, etc), because most of child abuse cases involve close family members or close friends. We definitel…

That is correct. The children within the images that are classified as CSAM don't necessarily have (though frequently are) to be abused.

For example, the NCMEC database contains hashes for Nirvana's Nevermind cover. Completely innocent to possess within it's original and intended context.

I have not said whether I agree with this, because I do see problems when automating the process.

However, the precedent for it being used as a flag for law enforcement has already happened. Having a collection of similar imagery is considered CSAM - and that is likely correct. A collection is probably not innocent. But having one or two images may happen incidentally without your awareness of it.

As to who decides what constitutes significance? That is where you'll hit the most problems, and reasonable discussion of it will be quickly shut down with the same arguments used for automating a flagging system. The conversation requires nuance, but those currently calling for such systems aren't interested in a good faith discussion.

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#47
post #27

For some reason, after reading the initial reporting on this system, I thought it was running against any photos on your iPhone, but now I read the actual paper, it seems like it only applies to photos destined to be uploaded to iCloud? So users can opt out by not using iCloud?

Much of the discussion is about how trivial it would be for Apple to start scanning any photos on the phone at a later date. Right now they are able to bill this as doing what they currently do server side, but client side. Later, they can say they are simply applying the same "protections" to all photos instead of merely the ones being uploaded to iCloud.

They can do it already. System is full black box, and all we have is their word. So, saying that adding something might enable something else, is not strong argument.

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#48
post #27

For some reason, after reading the initial reporting on this system, I thought it was running against any photos on your iPhone, but now I read the actual paper, it seems like it only applies to photos destined to be uploaded to iCloud? So users can opt out by not using iCloud?

Did you ever experience that you turned some setting off but it was "accidentally" turned on again after some update/reboot?

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#49

(Context: I teach computer security at Princeton and have a paper at this week's Usenix Security Symposium describing and analyzing a protocol that is similar to Apple's: https://www.usenix.org/conference/usenixsecurity21/presentat... .) The proposed attack on Apple's protocol doesn't work. The user's device adds randomness when generating an outer encryption key for the voucher. Even if an adversary obtains both the…

There may be another attack.

Given some CP image, an attacker could perhaps morph it into an innocent looking image while maintaining the hash. Then spread this image on the web, and incriminate everybody.

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#50
post #11

Earlier quoted context omitted.

Good link to explain why "CSAM" is being used in lieu of "CP" https://www.adfsolutions.com/news/what-is-csam > However, the phrase “child pornography” is almost too sterile and generic to properly exemplify the horrors of what is being created. That is why many advocates, including the National Center for Missing and Exploited Children (NCMEC), believe this phrase to be outdated. > NCMEC refers to these kinds of mate…

What terrible reasoning. 'Child pornography' is already too long to say repeatedly in a sentence so it is often shortened to "child porn." CSAM has far too many syllables so it too is shortened to two syllables in the form of the spoken acronym "CSAM" and so we're back to square one. With that said this is a fascinating display someone pressing the reverse button on the euphemism treadmill. I don't think I've ever se…

You ever notice when cops bust a prostitution ring they never call it that? It's been renamed human trafficking. Law enforcement is all in on the marketing game.

Using scarier words will get the public to trade liberty for security every time.

Post reply on HN