Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

221–230 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#221

Earlier quoted context omitted.

But the catch is: all the incumbents already treated your data as if you were guilty until proven innocent. Apple’s transparency about that change may have led people to internalize that, but it’s been the de facto terms of most cloud relationships. What I personally don’t understand is why Apple didn’t come out with a different message: we’ve made your iPhone so secure that we’ll let it vouch for your behalf when it…

> What I personally don’t understand is why Apple didn’t come out with a different message: we’ve made your iPhone so secure that we’ll let it vouch for your behalf when it sends us data to store. We don’t want to see the data, and we won’t see any of it unless we find that lots of the photos you send us are fishy. That is PR speak that would have landed worse in tech forums. I respect them more for not doing this. T…

> without your approval

This isn’t true. You can always turn off iCloud Photo Library and just store the photos locally or use a different cloud provider.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#222
post #221

Earlier quoted context omitted.

> What I personally don’t understand is why Apple didn’t come out with a different message: we’ve made your iPhone so secure that we’ll let it vouch for your behalf when it sends us data to store. We don’t want to see the data, and we won’t see any of it unless we find that lots of the photos you send us are fishy. That is PR speak that would have landed worse in tech forums. I respect them more for not doing this. T…

> without your approval This isn’t true. You can always turn off iCloud Photo Library and just store the photos locally or use a different cloud provider.

Let's not pretend anyone is really "opting in" on this feature.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#223
post #81

Earlier quoted context omitted.

> Until a 1-line code change happens that hooks it into UIImage. I really don't understand this view. You are using proprietary software, you are always an N-line change away from someone doing something you don't like. This situation doesn't change this. If you only use open source software and advocate for others to do the same, I would understand it more.

> I really don't understand this view. You are using proprietary software, you are always an N-line change away from someone doing something you don't like. This situation doesn't change this. And I don't understand why it has to be black and white, I think the N is very important in this formula and if it is low that is a cause for concern. Like an enemy building a missile silo on an island just off your coast but p…

I’d leave this one out to the lawyers. I’m not one but I don’t think that the court will evaluate the number of lines of code required for help.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#224

If apple can be coerced by governments to scan photos on the serverside then what is the operational purpose of a frontend scan, given what apple is publicly saying they are trying to do? This is the most confusing aspect for me.

Apple will turn it on eventually for non iCloud destined photos (and documents), you don't build a system like this not to use it.

We know Apple concedes to China's demands, and with another Snowden situation, the US would not hesitate to add classified documents to the scan list and identify individuals.

This system will catch no abusers, because they're not Airdropping photos to each other.

And if they're smart enough to use a VPN, they're not storing that on a phone thats logged into the cloud.

And if they're not using a VPN, they can be caught at download time.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#225
post #213

Earlier quoted context omitted.

No. The 4A protections don't apply to third parties. This is part of why the US has nearly nonexistent data protection laws.

The sort of questions about 4A protections here haven't really been tested. Third party doctrine might not apply in this circumstance and the court is slowly evolving with the times.

e.g. https://en.wikipedia.org/wiki/Carpenter_v._United_States

In Carpenter v. United States (2018), the Supreme Court ruled warrants are needed for gathering cell phone tracking information, remarking that cell phones are almost a “feature of human anatomy”, “when the Government tracks the location of a cell phone it achieves near perfect surveillance, as if it had attached an ankle monitor to the phone’s user”.

...[cell-site location information] provides officers with “an all-encompassing record of the holder’s whereabouts” and “provides an intimate window into a person’s life, revealing not only [an individual’s] particular movements, but through them [their] familial, political, professional, religious, and sexual associations.”

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#226
post #200

Earlier quoted context omitted.

I agree this is vastly better than what anyone else is doing, and you know I understand the technology. However, I don’t think any framing would have improved things. I think it was always going to feel wrong. I would prefer they don’t do this because it feels bad to be a suspect even in this abstract and in-practice harmless way. Having said that, having heard from people who have investigated how bad pedophile acti…

I don’t think I agree. If you think this boils down to instinct, do you think a story about coming together to save the next generation will work well on people cynical enough to see TLAs around every corner? At the very least, I feel like Apple should probably make a concession to the conspiracy minded so that they can bleach any offensive bits from their device and use them as offline-first DEFCON map viewing devic…

> do you think a story about coming together to save the next generation will work well on people cynical enough to see TLAs around every corner?

Absolutely not. I don’t think they need to persuade people who are convinced of their iniquity.

What they need is an environment in which those people look like they are arguing over how many dictatorships need to collude to detect anti-government photos and how this constitutes literal 1984, while Apple is announcing a way to deter horrific crimes against American children that they have seen on TV.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#227
post #200

Earlier quoted context omitted.

I agree this is vastly better than what anyone else is doing, and you know I understand the technology. However, I don’t think any framing would have improved things. I think it was always going to feel wrong. I would prefer they don’t do this because it feels bad to be a suspect even in this abstract and in-practice harmless way. Having said that, having heard from people who have investigated how bad pedophile acti…

> Having said that, having heard from people who have investigated how bad pedophile activity actually is, I can imagine being easily persuaded back in the other direction. There are terrible things out there that we should seek to solve. They should not be solved by creating 1984 in the literal sense, and certainly not by the company that became famous for an advertisement based on that book [1]. Apple, take your ow…

> creating 1984 in the literal sense

I take it you haven’t read 1984.

When Craig Federighi straps a cage full of starving rats to my face, I’ll concede this point.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#228
post #215

Earlier quoted context omitted.

Edit: I reconsidered my previous reply. That really doesn’t sound like anything I’d describe as a “back door”. A back door implies general purpose access. A system which required the collision of multiple governments and Apple and their child abuse agencies simply is not that. One of the casualties of this debate is that people are using terms that make things sound worse than they are. If you can’t get at my filesys…

> A system which required the collision of multiple governments and Apple and their child abuse agencies simply is not that. Agree to disagree. > I would find it interesting to hear what Federighi would say about this potential abuse case. Personally I would not. That's a political consideration and not something I want to hear a technologist weigh in on while defending their technology. Apple's previous stance, with…

> Personally I would not. That's a political consideration and not something I want to hear a technologist weigh in on while defending their technology.

It’s not. The abuse case flows from their architecture. Perhaps it isn’t as ‘easy’ as getting multiple countries to collude with Apple. If the architecture can be abused the way you think it can, that is a technical problem as well as a political one.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#229
post #221

Earlier quoted context omitted.

> without your approval This isn’t true. You can always turn off iCloud Photo Library and just store the photos locally or use a different cloud provider.

Let's not pretend anyone is really "opting in" on this feature.

Anyone who doesn’t like it can switch off iCloud Photo Library.

I can imagine many people doing that in response to this news.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#230
post #56

Earlier quoted context omitted.

> Speaking purely personally, whether the scanning happens immediately-before-upload on my phone or immediately-after-upload in the cloud doesn't really make a difference to me. What I find interesting is that so many people find it worse to do it on device, because of the risk that they do it to photos you don't intend to upload. This is clearly where Apple got caught off-guard, because to them, on-device = private.…

Is this really surprising to you? I'm not trying to be rude, but this is an enormous distinction. In today's world, smartphones are basically an appendage of your body. They should not work to potentially incriminate its owner.

They should not work to potentially incriminate its owner.

But that ship has long sailed, right?

Every packet that leaves a device potentially incriminates its owner. Every access point and router is a potential capture point.

Post reply on HN