Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

171–180 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#171

Earlier quoted context omitted.

the opportunity being to add general functions in photo viewing apps that add a little entropy to every image (for this specific purpose), to rotate hashes, rendering the dual databases useless monetization I guess being to hope for subscribers on github, as this could likely just be a nested dependency that many apps import. a convenient app for this specific purpose might not last long in app stores.

Perceptual hashes are specifically designed to be resistant to minor visual alterations.

Let the cat and mouse race begin

Any perceptual hash apps to test that theory on?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#174

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

> Our system involves both an on-device component where the voucher is created, but nothing is learned, and a server-side component, which is where that voucher is sent along with data coming to Apple service and processed across the account to learn if there are collections of illegal CSAM. That means that it is a service feature.

Neuenschwander seems to, maybe deliberately, be conflating : "Apple's servers have to be in the loop" and "the code can only look at photos on iCloud".

You are right, the problem is a "slippery slope," but Apple just built roller skates and there are governments trying to push us down it. Apple is in a far better position to resist those efforts if they say " we don't have this code, we will not build it, and there's no way for it to be safe for our users."

I'd say that's a little different than the slippery slope. Something more like (in)defense in depth.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#176

I don’t like the idea of stuff running on my device, consuming my battery and data, when the only point is to see if I am doing something wrong? An analogy I can come up with is: the government hires people to visit your house every day, and while they’re there they need your resources (say, food, water, and electricity). In other words, they use up some of the stuff you would otherwise be able to use only for yourse…

The point of it is to make sure iCloud Photos remains a viable service in light of real and perceived regulatory threats, and possibly leave the door open to end to end encryption in the future.

So they open a huge back door instead of waiting for a threat and fighting that?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#177
post #106
post #48

Earlier quoted context omitted.

Mostly hysterical may technically be an exaggeration, but mostly misinformed, and often dis-informative is not. This isn’t just about people weighing things they dislike more strongly. It’s also about groupthink, confirmation bias, and a lack of curiosity. HN doesn’t have an immune system against straight up misinformation.

> HN doesn’t have an immune system against straight up misinformation. It certainly doesn't! Misinformation and disinformation are terms du jour, but as far as I can tell they are indistinguishable from old-fashioned people-being-wrong-on-the-internet. If you expect an internet forum to be immune from that...well, that's too much to expect. As far as I can tell (and moderating HN for years has really hammered this ho…

I may be the person you are thinking of. I don’t think I ever ‘frequently’ broke the site guidelines, but I definitely don’t do it much these days, and it’s always a mistake when I do.

With regard to the conflict dynamics - I agree, although the amplification isn’t necessarily bad.

Also I think with regard to the ‘deeper truth’, often it’s not so much ‘deeper’ as simpler.

In this case for example, people strongly dislike being distrusted - it might well be a genetic disposition since it is a crucial part of our social psychology, and Apple is making a mistake by ignoring that. This isn’t about people not trusting Apple. It’s about people not feeling trusted by Apple.

Perhaps that counts as deeper, but there isn’t much to say about it - it’s not a loud sounding insight, and so all of the other arguments get built up as a way of amplifying that signal.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#178

Earlier quoted context omitted.

Lots of people have made policy arguments. No US law requires client side scanning. No US law forbids E2E encryption. US courts don't let law enforcement agencies just demand everything they want from companies. Apple relied on that 5 years ago successfully.[1] And capitulating preemptively is bad strategy usually. What Neuenschwander said doesn't establish it isn't just an arbitrary limitation. [1] https://en.wikipe…

None of the laws do yet. My observation isn't about the laws as they necessarily exist now, just as the worry about how this could be abused isn't about Apple's policy as it exists now. If we trust US courts to stop law enforcement agencies from demanding everything they want from companies, they they can stop law enforcement agencies from demanding Apple add non-CSAM data to the NeuralHash set. If we don't trust the…

I'm not American, but my understanding is that as soon as Government is forcing Apple to search our devices for something, 4th Amendment protections apply. (Unless they hold a search warrant for that specific person, of course.) Is this not correct?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#179

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

> It's a policy problem. It's a governance problem. In the long run, we solve this, at least in liberal democracies, by voting people into office who understand technology, understand the value of personal encryption

Yes, it is ultimately policy problem. But the way we get people in office who understand technology is to get technological capabilities in the hands of people before they get into office, as well as the hands of those who will vote for them. Just like "bad facts make bad law", bad engineering makes bad law.

Twenty years ago we forcefully scoffed at the Clipper Chip proposal and the export ban on crypto, because they were so at odds with the actual reality of the digital environment. These days, most people's communications are mediated by large corporations operating on plaintext, and are thus are straightforward to monitor and censor. And especially when companies lead the charge, governments expect to have the same ability.

If I could hole up and rely on Free software to preserve my rights indefinitely, I wouldn't particularly care what the Surveillance Valley crowd was doing with their MITM scheme. But I can't, because Surveillance Valley is teaching governments that communications can be controlled while also fanning the flames and creating glaring examples of why they need to be controlled (cf social media "engagement" dumpster fire). And once governments expect that technology can be generally controlled, they will rule any software that does not do their bidding as some exceptional circumvention device rather than a natural capability that has always existed. This entire "trust us" cloud culture has been one big vaccination for governments versus the liberating power of technology that we were excited for two decades ago. This end result has been foreseeable since the rise of webapps, but it's hard to get software developers to understand something when their salary relies upon not understanding it.

Apart from my ][gs (and later my secondhand NeXT), I've never been a huge Apple fan. But I had hoped that by taking this recent privacy tack, they would put workable digital rights into the hands of the masses. Design their system to be solidly secure against everyone but Apple, control the app store to prevent trojans, but then stay out of users' business as software developers should. But brazenly modifying their OS, which should be working for the interests of the user, to do scanning against the interests of the user is a disappointing repudiation of the entire concept of digital rights. And so once again we're back to Free software or bust. At least the Free mobile ecosystem seems to be progressing.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#180

I don’t like the idea of stuff running on my device, consuming my battery and data, when the only point is to see if I am doing something wrong? An analogy I can come up with is: the government hires people to visit your house every day, and while they’re there they need your resources (say, food, water, and electricity). In other words, they use up some of the stuff you would otherwise be able to use only for yourse…

The point of it is to make sure iCloud Photos remains a viable service in light of real and perceived regulatory threats, and possibly leave the door open to end to end encryption in the future.

This is a false dichotomy that is being pushed constantly online. E2EE is possible without this tech and in fact is only useful without tech like this to act as a MITM.
Post reply on HN