Live data from Hacker News

Messaging and chat control

patrick-breyer.de

301–310 of 336 posts

Re: Messaging and chat control

#301

I voted Remain in the EU referendum here in the UK but, in 2021, a few things have happened that have caused me to question whether that was the right choice and whether, with Brexit, we have the right outcome (albeit for very much the wrong reasons seen through 2016 eyes): 1. Ursula von der Leyen and the EU Commission bullying companies and non-EU countries about vaccine production and provision. A wider point here…

m8, to me it seemed like all the news I read in the last years, about England and the road to surveillance state, put your country ahead. I'm sure Boris will soon announce they'll do the same.

Maybe. I think it's actually pretty hard to predict. He's so populist... although that could of course punt him in either direction.

Re: Messaging and chat control

#302
post #231

Earlier quoted context omitted.

That experiment shows that whatever is stored on ProtonMail's servers plus your password is sufficient to decrypt your emails. This could be explained by the private key being derived from or encrypted with your password. ProtonMail's documentation says it's the latter ( https://protonmail.com/support/knowledge-base/how-is-the-pri... ): > Your ProtonMail private key is generated in your browser. Before sending the pr…

The most likely attacker against proton mail are various law enforcement or intelligence agencies. Such agency can force PM to modify login process to derive password from submitted form, or to just switch private keys for non-encrypred ones, because the user won't even notice it. Truly secure entity just wouldn't have private keys on a server at all . Users would have to go through an an uncomfortable process of gen…

You make a poor argument overall. Just because convenience will tend to win out doesn’t mean people shouldn’t choose more secure over less secure.

Your argument boils down to “govt can force them to change how they do that”, as opposed to a flaw in their approach.

Re: Messaging and chat control

#303
post #204

Earlier quoted context omitted.

AFIAK, Protonmail private keys are kept client-side. They are decrypted by the password inside the browser UI.

No. I just logged in to that very same account using different browser on a different computer. The email was displayed just fine. Protonmail keeps generated public and private keys on their servers.

It keeps copies that your browser locally encrypted with a symmetric key derived from your password. When you log on your browser downloads them, and decrypts them with your password.

Protonmail do not see your password and without it cannot decrypt the pub/private key pair.

Re: Messaging and chat control

#304
post #15

This report [0] is all I could find. I would have expected this to be more widely reported, and I'm surprised to see it isn't. [0]: https://www.europarl.europa.eu/doceo/document/TA-9-2021-0319...

That link shows the existing legislation, approved in July. Today it doesn't mandate anybody to scan anything but effectively _allows_ service providers to scan for CSAM, if they wish, by defining "combating online child sexual abuse" as a legitimate reason to process personal data within the limitations of the EU's various privacy & data protection directives (GDPR being the obvious one, but there's others too). It'…

Thank you for the great summary.

Re: Messaging and chat control

#305

Earlier quoted context omitted.

"Child porn" is a smokescreen. It's what every privacy advocate saw coming: find the worst, most repugnant thing possible and use it to backdoor encryption. It's not a dream, and it's really happening, right now.

CSAM is still problematic, though. The consensus is that creates a market that incentivizes the abuse of children, because you cannot produce CSAM without CSA. It seems to be the one of the few classes of data that is an exception to the standard of privacy that is applied to almost all other data, to the point that Apple took action against it. Dozens of other countries besides the US also agree, and outlaw that cla…

I was gonna write a whole thing, but mostly I just wanted to say we'll be able to deepfake CSAM inside of 10 years, no question, so this whole thing is moot.

Re: Messaging and chat control

#306
post #138

Earlier quoted context omitted.

For a little more context, see https://www.howtogeek.com/710509/apples-imessage-is-secure..... For those unfamiliar, as I was, it appears iCloud backup is enabled by default. I think the above statement about iMessage not being e2e in practice is very fair.

This option is transparent to the user and easy to change. Also, anyone who has done IT support will appreciate that yeah regular users actually want / need backups enabled by default, it's often a life saver for them.

Apple doesn't need the keys to enable backups.

And the mere fact it's a default makes it a significant problem when discussing it as a popular and widespread E2E messenger. It would be more borderline if it was a required configuration choice with no default that clearly disclaimed the ramifications.

Even then, you have the issue that you are not the only person with a copy of the conversation. Your partner - or partners - has it too. Does Apple require some kind of pre-conversation negotiation to determine how the conversation will be stored in the backups? Or at least provide some kind of warning if a person with backups disabled gets in contact with somebody with backups enabled?

I don't disagree with you about backups, but how useful they are is completely irrelevant in this context for several separate reasons.

Re: Messaging and chat control

#307

Earlier quoted context omitted.

Their point was CSAM means especially bad CP. Your points were different. It's a perceptual hash. Matches don't have to be exact. And people have engineered collisions for other perceptual hash algorithms. What a computer sees and what a person sees can be very different. People have said the human verification just involves the visual derivative of the suspect image. Apple didn't explain what that is really. And hum…

Sorry. Either the posts got updated or I got the thread confused as others were trying to say that (re: hash versus classifier). Re hashing, Apple claims 1:1 trillion likelihood of a collision. These kinds of systems are not rolled out lightly, and even if that number is wrong, it’s feels unlikely to me that it’s too far off. If it is and it has too many false positives, this will get noticed and the system pulled un…

Apple's claim is unverifiable. It counts for nothing. And people with relevant experience have called it bullshit.[1]

Even just arresting someone means separating them from their children. Preventing them from working if their job involves children. Seizing all their electronics for months. Violating the privacy of their files and belongings. Legal costs. Possibly media reports. Putting innocent people through this because a secret algorithm said a secret database matched a secret number of times is unacceptable.

Several people have claimed false positives are in the database. Including someone who verifiably worked with it.[1]

US prosecutors have absolute immunity. Any civil suit would be dismissed swiftly.

People don't collect random subsets of all pornography ever made. Some is much more popular. People have specific tastes. Photo sets exist.

[1] https://www.hackerfactor.com/blog/index.php?/archives/929-On...

Re: Messaging and chat control

#308

Earlier quoted context omitted.

The age of consent goes low as 14 in Europe but that doesn't change the definition of CP. Probably they won't prosecute when both parties are underage and such so heavily but consent age doesn't change the fact that nudity is 18+.

Nudity is 18+ in extremist countries like the Emirates or the USA. Sorry but in France, 30 years ago before american culture started to dictate where money come from, you would see genitals from all genders and ages in movies. Nobody found it offensive, because we didn't have a catholic puritan morality to impose its sick twisted vision of the human body on us. Meanwhile we sold car by showing cars, not hot girls. Bu…

> Nudity is 18+ in extremist countries like the Emirates or the USA

Titanic was PG-13 and it had a titty.

Re: Messaging and chat control

#309

Earlier quoted context omitted.

"Child porn" is a smokescreen. It's what every privacy advocate saw coming: find the worst, most repugnant thing possible and use it to backdoor encryption. It's not a dream, and it's really happening, right now.

CSAM is still problematic, though. The consensus is that creates a market that incentivizes the abuse of children, because you cannot produce CSAM without CSA. It seems to be the one of the few classes of data that is an exception to the standard of privacy that is applied to almost all other data, to the point that Apple took action against it. Dozens of other countries besides the US also agree, and outlaw that cla…

> Finding actual CSAM (and not just any kind of pornography involving minors, hence the shift in terminology) is supposedly directly tied to finding child abusers, thus preventing future child abuse from taking place.

NCMEC and similar groups call all pornography involving minors CSAM.[1] And this system can't detect new CSAM.

> Another thing that nobody seems to talk about is that Apple doesn't want to be held liable for CSAM stored on their servers, either.

Many people said they would prefer server side scanning. Other people argued E2E encryption would shield Apple from liability.

[1] https://www.missingkids.org/theissues/csam

Re: Messaging and chat control

#310
post #296

Earlier quoted context omitted.

I genuinely do not know the answer. But also, what would you define as false positive? It's blurry definitions all the way down, and that's part of the reason politics doesn't like this problem and would rather argue technology and punishment after-the-fact than actual protection / prevention. Nuance is expensive and doesn't play well to the crowd.

If I take a picture of my adorable toddler playing naked in a sprinkler in the backyard and CPS calls that child porn and takes him away from me, that's a false positive. I don't know much about abusers, but my hunch is that they know they are abusers and will more-or-less accept being caught. But what I know about non-abusive parents is if you take their kids away, it's war.

Two things:

1. I thought you were referring to false positives as a result of my favoring funding of existing Child Services working from mandatory reporting from local relevant professions.

2. My commentary about taking children from parents having its own set of risks was more along the lines of trauma to the child, in that even in if the parent/ child relationship is abusive and harmful, it's such a strong bond that severing it, or restricting it can cause psychological issues.

Totally agree with your commentary above regarding any attempt to remove kids from non-abusive parents. Absolutely scorched earth nuclear war. Also, it would actively be a form of child abuse by introducing unnecessary trauma to the child(ren) and possibly instilling a lifelong suspicion (at best) of authority.

As a result of that train of thought, my answer is: no false positives would be acceptable.

Fundamentally, I'm against personal photos being scanned at all; false positives being one reason, and the broad misapplication of bans by 'big tech' in their implementations of automated systems detecting breaches of policy, and the overall "computer says no" brick wall offered as recourse, being another.

Post reply on HN