A curious outcome of the scrutiny that the system design is receiving is that it will make it less effective at the task of catching actual collections of CSAM. Page eleven promises something I haven’t seen before: that Apple will publish the match threshold for each version. Meaning, even if after all this, there are abusers still using iCloud photos to manage their illegal collection of CSAM, they can check back to…
Security Threat Model Review of the Apple Child Safety Features [pdf]
161–170 of 393 posts
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#162Earlier quoted context omitted.
You might prefer that, but it doesn’t violate your privacy for them to prefer a different strategy.
why even ask the question " What more did you expect from them?" if you didn't care about the answer? I gave a pretty obvious and clear answer to that, and apparently you didn't care about the question in the first place, and have now misdirected to something else. I am also not sure what possible definition of "privacy" that you could be using, that would not include things such as on device photo scanning, for the…
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#163In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…
> For instance, the "it only scans photos uploaded to iCloud" element isn't just an arbitrary limitation that can be flipped with one line of code, as some folks seem to think; as Erik Neuenschwander, head of Privacy Engineering at Apple, explained in an interview on TechCrunch[1]: >> Our system involves both an on-device component where the voucher is created, but nothing is learned, and a server-side component, whi…
I think what you're arguing is that Apple could still change what's being scanned for, and, well, yes: but that doesn't really affect my original point, which is that this is a policy/legal issue. If you assume governments are bad actors, then yes, they could pressure Apple to change this technology to scan for other things -- but if this technology didn't exist, they could just as easily pressure Apple to do it all on the servers. I think a lot of the anger comes from they shouldn't be able to do any part of this work on my device, and emotionally, I get that -- but technologically, it's hard for me not to shake the impression that "what amount happens on device vs. what amount happens on server" is a form of bikeshedding.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#164Earlier quoted context omitted.
> there's a legitimate "slippery slope" argument The slippery slope argument is the only useful argument here. The fundamental issue with their PSI/CSAM system is that they already were scanning iCloud content [1] and that they're seemingly not removing the ability to do that. If the PSI/CSAM system had been announced along side E2E encryption for iCloud backups, it would be clear that they were attempting to act in…
> This is an area we’ve been looking at for some time, including current state of the art techniques which mostly involves scanning through entire contents of users’ libraries on cloud services that — as you point out — isn’t something that we’ve ever done; to look through users’ iCloud Photos. https://techcrunch.com/2021/08/10/interview-apples-head-of-p... > This moment calls for public discussion, and we want our c…
I really dislike this statement. It's likely designed to be "technically true". But it's been reported elsewhere that they do scan iCloud content:
https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-...
Perhaps they scan as the data is being ingested. Perhaps it's scanned on a third party server. But it seems clear that it is being scanned.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#165In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…
What's the contrarion question?
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#166> Apple will publish a Knowledge Base article containing a root hash of the encrypted CSAM hash database included with each version of every Apple operating system that supports the feature. Additionally, users will be able to inspect the root hash of the en- crypted database present on their device, and compare it to the expected root hash in the Knowledge Base article. This is just security theater, they already si…
> And there is no way to audit that the database is what they claim it is, doesn't contain multiple databases that can be activated under certain conditions, etc. Although this is true, the same argument already applies to "your phone might be scanning all your photos and stealthily uploading them" -- Apple having announced this program doesn't seem to have changed the odds of that. At some point you have to trust yo…
If the OS was open source and supported reproducible builds, you would not have to trust them, you could verify what it actually does & make sure the signed binaries they ship you actually correspond to the source code.
Once kinda wonders what they want to hide if they talks so much about user privacy yet don't provide any means for users to verify their claims.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#167Earlier quoted context omitted.
> there's a legitimate "slippery slope" argument The slippery slope argument is the only useful argument here. The fundamental issue with their PSI/CSAM system is that they already were scanning iCloud content [1] and that they're seemingly not removing the ability to do that. If the PSI/CSAM system had been announced along side E2E encryption for iCloud backups, it would be clear that they were attempting to act in…
> If the PSI/CSAM system had been announced along side E2E encryption for iCloud backups, it would be clear that they were attempting to act in their users best interests. Absolutely. I don't know whether there's a reason for this timing (that is, if they are planning E2E encryption, why they announced this first), but this is probably the biggest PR bungle Apple has had since "you're holding it wrong," if not ever.…
> The voucher generation is actually exactly what enables us not to have to begin processing all users’ content on our servers, which we’ve never done for iCloud Photos.
But they do appear to do "something" server-side. It's possible that all data in scanned as it is ingested for example. I dislike this statement, because it's probably technically correct but doesn't help clarify the situation in a helpful way. It makes me trust Apple less.
[1] https://techcrunch.com/2021/08/10/interview-apples-head-of-p...
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#168Earlier quoted context omitted.
> This is an area we’ve been looking at for some time, including current state of the art techniques which mostly involves scanning through entire contents of users’ libraries on cloud services that — as you point out — isn’t something that we’ve ever done; to look through users’ iCloud Photos. https://techcrunch.com/2021/08/10/interview-apples-head-of-p... > This moment calls for public discussion, and we want our c…
> The voucher generation is actually exactly what enables us not to have to begin processing all users’ content on our servers, which we’ve never done for iCloud Photos. I really dislike this statement. It's likely designed to be "technically true". But it's been reported elsewhere that they do scan iCloud content: https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-... Perhaps they scan as the data is being…
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#169Earlier quoted context omitted.
> The voucher generation is actually exactly what enables us not to have to begin processing all users’ content on our servers, which we’ve never done for iCloud Photos. I really dislike this statement. It's likely designed to be "technically true". But it's been reported elsewhere that they do scan iCloud content: https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-... Perhaps they scan as the data is being…
My understanding based on piecing together the various poorly cited news stories is that Apple used to scan iCloud Mail for this material, and that’s it.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#170I don’t like the idea of stuff running on my device, consuming my battery and data, when the only point is to see if I am doing something wrong? An analogy I can come up with is: the government hires people to visit your house every day, and while they’re there they need your resources (say, food, water, and electricity). In other words, they use up some of the stuff you would otherwise be able to use only for yourse…
The point of it is to make sure iCloud Photos remains a viable service in light of real and perceived regulatory threats, and possibly leave the door open to end to end encryption in the future.