Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

201–210 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#201
post #186

A key point that needs to be mentioned: we strongly dislike being distrusted. It might well be a genetic heritage. Being trusted in a tribe is crucial to survival, and so is likely wired deep into our social psychology. Apple is making a mistake by ignoring that. This isn’t about people not trusting Apple. It’s about people not feeling trusted by Apple. Because of this, it doesn’t matter how trustworthy the system is…

The part Federighi's "interview" where he can't understand how people perceive this as a back door [1] seems incredibly out of touch. The back door is what everyone is talking about. Someone at Apple should at least be able to put themselves in their critics' shoes for a moment. I guess we need to wait to hear Tim Cook explain how this is not what he described 5 years ago [2]. [1] https://youtu.be/OQUO1DSwYN0?t=425 […

It’s not a back door in any sense of the word. That’s why he is surprised people see it as one.

It really only does what they say it does, and it really is hard to abuse.

But that doesn’t matter. The point is that even so, it makes everyone into a suspect, and that feels wrong.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#202

Earlier quoted context omitted.

I'm not American, but my understanding is that as soon as Government is forcing Apple to search our devices for something, 4th Amendment protections apply. (Unless they hold a search warrant for that specific person, of course.) Is this not correct?

No. The 4A protections don't apply to third parties. This is part of why the US has nearly nonexistent data protection laws.

If Apple was performing scans on their cloud servers, you'd be absolutely right. But if the scanning is being done on the individual's device, I'm not sure it's that straightforward. The third party doctrine surely cannot apply if the scanning is performed prior to the material being in third party hands.

Therefore if the Government forces Apple to change the search parameters contained within private devices, I cannot see how this would work around the 4th Amendment.

If this is correct, it might be possible to argue that Apple's approach has (for Americans) constitutional safeguards which do not exist for on-cloud scanning performed by Google or Microsoft.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#203
post #201

Earlier quoted context omitted.

The part Federighi's "interview" where he can't understand how people perceive this as a back door [1] seems incredibly out of touch. The back door is what everyone is talking about. Someone at Apple should at least be able to put themselves in their critics' shoes for a moment. I guess we need to wait to hear Tim Cook explain how this is not what he described 5 years ago [2]. [1] https://youtu.be/OQUO1DSwYN0?t=425 […

It’s not a back door in any sense of the word. That’s why he is surprised people see it as one. It really only does what they say it does, and it really is hard to abuse. But that doesn’t matter. The point is that even so, it makes everyone into a suspect, and that feels wrong .

> It’s not a back door in any sense of the word.

It is. It's a simple matter for two foreign governments to decide they don't want their people to criticize the head of state with memes, and then insert such images into the database Apple uses for scanning.

Apple's previous position on privacy was to make such snooping impossible because they don't have access to the data. Now they are handing over access.

What I and thousands of others online are describing ought to be understandable by anyone at Apple. The fact that an Apple exec can sit there in a prepared interview and look perplexed about how people could see this as a back door is something I don't understand at all. This "closing his ears" attitude may indicate he is full of it.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#204

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

[deleted]

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#205

Sounds like it still comes down to trust. Quoting from the paper: "Apple will refuse all requests to add non-CSAM images to the perceptual CSAM hash database; third party auditors can confirm this through the process outlined before. Apple will also refuse all requests to instruct human reviewers to file reports for anything other than CSAM materials for accounts that exceed the match threshold."

To me, the fact that they are making such a strong statement is a big deal. If they had plans or thought that they would be forced to add other content they would not be so direct in this statement. I hope I am not wrong. As you said: trust.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#206

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

>Apple is treating CSAM as an engineering problem.

No they're treating it as a political and legal problem (with the UK and the EU being the furthest along on passing legislation). Their implementation is the compromise that preserves end-to-end encryption, given those political winds.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#207

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

> … the less likely it seems that it would make it radically easier for those bad actors to do so

Depends on implementation. I can easily see a possibility that the check is gated by a server side logic that can be changed at any moment without anybody knowing.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#208
post #201

Earlier quoted context omitted.

It’s not a back door in any sense of the word. That’s why he is surprised people see it as one. It really only does what they say it does, and it really is hard to abuse. But that doesn’t matter. The point is that even so, it makes everyone into a suspect, and that feels wrong .

> It’s not a back door in any sense of the word. It is. It's a simple matter for two foreign governments to decide they don't want their people to criticize the head of state with memes, and then insert such images into the database Apple uses for scanning. Apple's previous position on privacy was to make such snooping impossible because they don't have access to the data. Now they are handing over access. What I and…

[deleted]

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#209

Earlier quoted context omitted.

why even ask the question " What more did you expect from them?" if you didn't care about the answer? I gave a pretty obvious and clear answer to that, and apparently you didn't care about the question in the first place, and have now misdirected to something else. I am also not sure what possible definition of "privacy" that you could be using, that would not include things such as on device photo scanning, for the…

My question was directed at someone who claimed their privacy was violated, and I asked them to explain how they would’ve liked their service provider to handle a difference in opinion about what to build in the future. I don’t think your comment clarifies that.

> how they would’ve liked their service provider to handle a difference in opinion about what to build in the future

And the answer is that they shouldn't implement things that violate people's privacy, such as things that would be illegal for the government to do without a warrant.

That is the answer. If it is something that the government would need a warrant for, then they shouldn't do it, and doing it would violate people's privacy.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#210
post #126

What strikes me about this paper is that there are no names of the people who wrote it on the title page. Why were they afraid to put their name(s) on this?

Seeing HN over the last week, I can think of a few reasons…
Post reply on HN