Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

191–200 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#191
post #186

A key point that needs to be mentioned: we strongly dislike being distrusted. It might well be a genetic heritage. Being trusted in a tribe is crucial to survival, and so is likely wired deep into our social psychology. Apple is making a mistake by ignoring that. This isn’t about people not trusting Apple. It’s about people not feeling trusted by Apple. Because of this, it doesn’t matter how trustworthy the system is…

But the catch is: all the incumbents already treated your data as if you were guilty until proven innocent. Apple’s transparency about that change may have led people to internalize that, but it’s been the de facto terms of most cloud relationships.

What I personally don’t understand is why Apple didn’t come out with a different message: we’ve made your iPhone so secure that we’ll let it vouch for your behalf when it sends us data to store. We don’t want to see the data, and we won’t see any of it unless we find that lots of the photos you send us are fishy. Android could never contemplate this because they can’t trust the OS to send vouchers for the same photos it uploads, so instead they snoop on everything you send them.

It seems like a much more win-win framing that emphasizes their strengths.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#192

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

> Will this stop those bad actors if they're determined? No, of course not, but there are so many ways they can do it already.

This is not a reason to let your guard down on security. Keeping up with securing things against bad actors is a constant battle. Tim Cook put it best [1] and I want to hear how this is not exactly what he described 5 years ago.

[1] https://youtu.be/rQebmygKq7A?t=57

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#193
post #81

Earlier quoted context omitted.

> Until a 1-line code change happens that hooks it into UIImage. I really don't understand this view. You are using proprietary software, you are always an N-line change away from someone doing something you don't like. This situation doesn't change this. If you only use open source software and advocate for others to do the same, I would understand it more.

Did you verify all the binaries that you run are from compiled source code that you audited? Your BIOS? What about your CPU and GPU firmware? There is always a chain of trust that you end up depending on. OSS is not a panacea here.

It's not a panacea but the most implausible the mechanism, the less likely it's going to be used on anyone but the most high value targets.

(And besides, it's far more likely that this nefarious Government agency will just conceal a camera in your room to capture your fingers entering your passwords.)

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#194

Earlier quoted context omitted.

None of the laws do yet. My observation isn't about the laws as they necessarily exist now, just as the worry about how this could be abused isn't about Apple's policy as it exists now. If we trust US courts to stop law enforcement agencies from demanding everything they want from companies, they they can stop law enforcement agencies from demanding Apple add non-CSAM data to the NeuralHash set. If we don't trust the…

I'm not American, but my understanding is that as soon as Government is forcing Apple to search our devices for something, 4th Amendment protections apply. (Unless they hold a search warrant for that specific person, of course.) Is this not correct?

No. The 4A protections don't apply to third parties. This is part of why the US has nearly nonexistent data protection laws.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#195

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

Speaking of mobile OS. I am a bit of a newbie myself in this area. I am an Android user but I want to decouple from Google as much as possible. Is there an mobile OS out there that offers a similar experience to, say, Android in terms of functionalities, apps, etc without the drawback of privacy concerns?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#196

I strongly considered switching away from Apple products last weekend; but this document has convinced me otherwise. The threats people identify have minimal risk. If a total stranger offers you a bottle of water, you may worry about it being spiked, but him having offered the bottle doesn't make it more, or less, likely that he'll stab you after you accept it. They're separate events, no "slippery slope". It's very…

> If Apple has evil intent, or is being coerced by NSLs, they would (be forced to) implement the dangerous mechanism whether this Child Safety feature existed or not. Apple used to fight implementing dangerous mechanisms. And succeeded.[1] [1] https://en.wikipedia.org/wiki/FBI–Apple_encryption_dispute

Their “you can’t compel us to build something” argument was for building a change to the passcode retry logic, which is presumably as simple as a constant change. Certainly building a back door in this system is at least as difficult, so the argument still stands.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#197

Here's what I don't get: who is importing CSAM into their camera roll in the first place? I for one have never felt the urge to import regular, legal porn into my camera roll. Who the hell is going to be doing that with stuff they know will land them in prison? Who the hell co-mingles their deepest darkest dirtiest secret amongst pictures of their family and last night’s dinner? I can believe that some people might b…

Actually it occurs to me that perhaps they're noticing a lot of CSAM is being produced with smartphone cameras and are hoping to snag the phone which produced the originals. If they can get new content into their database before the photographer deletes them, they might find the phone which took the originals—and then find the child victim.

Beyond implausible, but then most law enforcement tends to rely on someone eventually doing something stupid.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#198

> The second protection [against mis-inclusion of non CSAM hashes] is human review: there is no automated reporting in Apple’s system. All positive matches must be visually confirmed by Apple as containing CSAM before Apple will disable the account and file a report with the child safety organization. I don't understand this at all. As I understand it, part of the problem is that — in the US — Apple isn't legally all…

It’s simple, the reviewers will be cops (so viewing CP is legal).

They will pass on/hit report at rates that make a FISA judge blush.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#199
post #169

Earlier quoted context omitted.

My understanding based on piecing together the various poorly cited news stories is that Apple used to scan iCloud Mail for this material, and that’s it.

If you have references to also help me piece this together I'd find that really helpful.

> Last year, for instance, Apple reported 265 cases to the National Center for Missing & Exploited Children, while Facebook reported 20.3 million

According to [1] it does seem like Apple didn't do any wide scale scanning of iCloud Data.

[1] https://www.nytimes.com/2021/08/05/technology/apple-iphones-...

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#200
post #186

A key point that needs to be mentioned: we strongly dislike being distrusted. It might well be a genetic heritage. Being trusted in a tribe is crucial to survival, and so is likely wired deep into our social psychology. Apple is making a mistake by ignoring that. This isn’t about people not trusting Apple. It’s about people not feeling trusted by Apple. Because of this, it doesn’t matter how trustworthy the system is…

But the catch is: all the incumbents already treated your data as if you were guilty until proven innocent. Apple’s transparency about that change may have led people to internalize that, but it’s been the de facto terms of most cloud relationships. What I personally don’t understand is why Apple didn’t come out with a different message: we’ve made your iPhone so secure that we’ll let it vouch for your behalf when it…

I agree this is vastly better than what anyone else is doing, and you know I understand the technology.

However, I don’t think any framing would have improved things. I think it was always going to feel wrong.

I would prefer they don’t do this because it feels bad to be a suspect even in this abstract and in-practice harmless way.

Having said that, having heard from people who have investigated how bad pedophile activity actually is, I can imagine being easily persuaded back in the other direction.

I think thins is about the logic of evolutionary psychology, not the logic of cryptography.

My guess is that between now and the October iPhone release we are going to see more media about the extent of the problem they are trying to solve.

That is how Apple wins this.

Post reply on HN