Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

41–50 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#42
post #39

Earlier quoted context omitted.

No, the threat model differs entirely. Local scanning introduces a whole host of single points of failure, including the 'independent auditor' & involuntary scans, that risk the privacy & security of all local files on a device. Cloud scanning largely precludes these potential vulnerabilities.

It differs, but iOS already scans images locally and we really don't know what they do with the meta data, and what "hidden" categories there are.

Yes, exactly why Apple breaching user trust matters.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#43

> Apple generates the on-device perceptual CSAM hash database through an intersection of hashes provided by at least two child safety organizations operating in separate sovereign jurisdictions – that is, not under the control of the same government. Any perceptual hashes appearing in only one participating child safety organization’s database, or only in databases from multiple agencies in a single sovereign jurisdi…

If your threat model includes pervasive spying by multiple nation states, and being grabbed in the night by black helicopters, it seems unlikely you'll be overly concerned about them precisely inserting at least 30 of your photos into multiple CSAM databases and also co-ercing Apple's manual review to get you reported to NCMEC.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#45
post #12

Earlier quoted context omitted.

I think the flagging mechanism is rife for abuse. There are clearly more people interested in low information reactions than substantive discussion. If all you act on is reports, you will be biased towards whatever they care about. That is not a good way to moderate for nuance. I’m sure you may have considered this, but I don’t think it’s coming through in the discussion of this important topic which has been mostly…

Reports are not all we act on. We read the threads too. No one can read all of them though. Discussion on this topic has certainly been mixed, but "mostly hysterical" sounds like an exaggeration to me. People's reactions to these things are conditioned by the cognitive bias that causes us to weight the things we dislike much more strongly than the things we agree with ( https://hn.algolia.com/?dateRange=all&page=0&pr…

[deleted]

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#46
post #22

Earlier quoted context omitted.

> And there is no way to audit that the database is what they claim it is, doesn't contain multiple databases that can be activated under certain conditions, etc. Although this is true, the same argument already applies to "your phone might be scanning all your photos and stealthily uploading them" -- Apple having announced this program doesn't seem to have changed the odds of that. At some point you have to trust yo…

Yeah that's true, although to do some sort of mass scanning stealthily they would need a system exactly like what they built with this, if they tried to upload everything for scanning the data use would be enormous and give it away. I guess it comes down to that I don't trust an OS vendor that ships an A.I. based snitch program that they promise will be dormant.

No they wouldn’t need a system like this. They already escrow all your iCloud Backups, and doing the scanning server side allows you to avoid any scrutiny through code or network monitoring.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#47

I keep changing my mind on this. On the one hand I already operate on the assumption that uploading data to a cloud service renders that data non-private, or at least in great risk of becoming non-private in the future. This simply makes my operating assumption explicit. Also this particular implementation and its stated goals aren’t egregious. But then there’s the slippery slope we’ve all been discussing — and the g…

> But I sympathize with Apple for making transparent what I assume happens behind closed doors anyway.

Using your devices' CPU and battery seems more egregious than doing it on their servers. If they want to help law enforcement, then they should pay for it. Of course they want to help law enforcement by forcing other people to pay the costs.

Imagine if Ford came out with a cannabis sensor in their cars that automatically called the cops on you if it detected cannabis inside the car. The sensor is allegedly only active when you're renting a Ford vehicle, not if you purchase it outright. Not a perfect analogy, but how comfortable would you find this situation?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#48
post #12

Earlier quoted context omitted.

I think the flagging mechanism is rife for abuse. There are clearly more people interested in low information reactions than substantive discussion. If all you act on is reports, you will be biased towards whatever they care about. That is not a good way to moderate for nuance. I’m sure you may have considered this, but I don’t think it’s coming through in the discussion of this important topic which has been mostly…

Reports are not all we act on. We read the threads too. No one can read all of them though. Discussion on this topic has certainly been mixed, but "mostly hysterical" sounds like an exaggeration to me. People's reactions to these things are conditioned by the cognitive bias that causes us to weight the things we dislike much more strongly than the things we agree with ( https://hn.algolia.com/?dateRange=all&page=0&pr…

Mostly hysterical may technically be an exaggeration, but mostly misinformed, and often dis-informative is not.

This isn’t just about people weighing things they dislike more strongly.

It’s also about groupthink, confirmation bias, and a lack of curiosity.

HN doesn’t have an immune system against straight up misinformation.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#49
post #2

I think this is the first time they have mentioned that you will be able to compare the hash of the database on your device with a hash published in their KB article. They also detailed that the database is only the intersection of hash lists from two child safety organizations under separate governmental jurisdictions. My immediate thought is that this could still be poisoned by Five Eyes participants, and that it d…

the opportunity being to add general functions in photo viewing apps that add a little entropy to every image (for this specific purpose), to rotate hashes, rendering the dual databases useless

monetization I guess being to hope for subscribers on github, as this could likely just be a nested dependency that many apps import. a convenient app for this specific purpose might not last long in app stores.

Post reply on HN