Earlier quoted context omitted.
Sincere question: why doesn’t this policy apply to the innumerable number of hot takes which are variations on the exact same, often misinformed, reaction? I’m thinking of comments like, “Apple will send me to prison for taking bath tub pics of my infant!” I have seen many on here.
Two answers. First, it does apply. If you see a post that ought to have been moderated but hasn't been, the likeliest explanation is that we didn't see it. We don't come close to reading everything that gets posted here—there is far too much. You can help by flagging it or emailing us at hn@ycombinator.com. Second, there are degrees of these things. It's definitely bad for comments to repeat the same shallow things o…
Security Threat Model Review of the Apple Child Safety Features [pdf]
11–20 of 393 posts
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#12Earlier quoted context omitted.
Two answers. First, it does apply. If you see a post that ought to have been moderated but hasn't been, the likeliest explanation is that we didn't see it. We don't come close to reading everything that gets posted here—there is far too much. You can help by flagging it or emailing us at hn@ycombinator.com. Second, there are degrees of these things. It's definitely bad for comments to repeat the same shallow things o…
I think the flagging mechanism is rife for abuse. There are clearly more people interested in low information reactions than substantive discussion. If all you act on is reports, you will be biased towards whatever they care about. That is not a good way to moderate for nuance. I’m sure you may have considered this, but I don’t think it’s coming through in the discussion of this important topic which has been mostly…
Discussion on this topic has certainly been mixed, but "mostly hysterical" sounds like an exaggeration to me. People's reactions to these things are conditioned by the cognitive bias that causes us to weight the things we dislike much more strongly than the things we agree with (https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...).
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#13Their use of the phrase "This claim is subject to code inspection by security researchers like all other iOS device-side security claims" stood out to me. Could someone tell me how that inspection works? Are there researchers who are given the source code? (I posted this on another thread [0] earlier, but it's more relevant here) [0]: https://news.ycombinator.com/item?id=28175619
It’s not my field, but my understanding is that security researchers often disassemble and/or debug binaries without having access to the source code. For example, as soon as an OS update is released, people will take it apart. Having source might be nice but it’s not necessary.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#14Their use of the phrase "This claim is subject to code inspection by security researchers like all other iOS device-side security claims" stood out to me. Could someone tell me how that inspection works? Are there researchers who are given the source code? (I posted this on another thread [0] earlier, but it's more relevant here) [0]: https://news.ycombinator.com/item?id=28175619
Could someone tell me how that inspection works? Are there researchers who are given the source code?
It doesn't (with the exception of an exclusive program[0]). Not only do they generally make security work on their devices difficult – they have a history of suing companies that facilitate it [1].[0]: https://developer.apple.com/programs/security-research-devic...
[1]: https://www.theverge.com/2021/8/11/22620014/apple-corellium-...
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#15Their use of the phrase "This claim is subject to code inspection by security researchers like all other iOS device-side security claims" stood out to me. Could someone tell me how that inspection works? Are there researchers who are given the source code? (I posted this on another thread [0] earlier, but it's more relevant here) [0]: https://news.ycombinator.com/item?id=28175619
In this way, third party security researchers can verify their claims. It actually works out pretty well for them since third party security researchers often find pretty severe vulnerabilities through this program.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#16What’s not discussed in this Paper is how it won’t be used by third-party actors to falsely accuse someone. Does nobody remember the iCloud hack? What about instead of downloading Jennifer Lawrence’s photos, a hacker uploaded children to get someone falsely accused?
I don’t like the privacy and property rights issues of this but the whole someone will use this to frame someone is quite BS.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#17What’s not discussed in this Paper is how it won’t be used by third-party actors to falsely accuse someone. Does nobody remember the iCloud hack? What about instead of downloading Jennifer Lawrence’s photos, a hacker uploaded children to get someone falsely accused?
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#18Earlier quoted context omitted.
I think the flagging mechanism is rife for abuse. There are clearly more people interested in low information reactions than substantive discussion. If all you act on is reports, you will be biased towards whatever they care about. That is not a good way to moderate for nuance. I’m sure you may have considered this, but I don’t think it’s coming through in the discussion of this important topic which has been mostly…
Reports are not all we act on. We read the threads too. No one can read all of them though. Discussion on this topic has certainly been mixed, but "mostly hysterical" sounds like an exaggeration to me. People's reactions to these things are conditioned by the cognitive bias that causes us to weight the things we dislike much more strongly than the things we agree with ( https://hn.algolia.com/?dateRange=all&page=0&pr…
Similarly, I doubt anyone would be able to reliably match the comments section of any of the dozen articles about this announcement that have reached the front page in the last 8 days with the actual article content.
These are all bad signs about the healthiness of discussion.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#19This is just security theater, they already sign the operating system images where the database reside. And there is no way to audit that the database is what they claim it is, doesn't contain multiple databases that can be activated under certain conditions, etc.
> This feature runs exclusively as part of the cloud storage pipeline for images being up- loaded to iCloud Photos and cannot act on any other image content on the device
Until a 1-line code change happens that hooks it into UIImage.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#20"Anonymous helplines and guidance exist for adults with at-risk thoughts and behavior" - "Learn more and get help."
Now a fake AI on your phone that knows your actions and behaviors can sleep and wait for specific triggers and give you feedback and alert.