Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

241–250 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#241

Earlier quoted context omitted.

> If Apple has evil intent, or is being coerced by NSLs, they would (be forced to) implement the dangerous mechanism whether this Child Safety feature existed or not. Apple used to fight implementing dangerous mechanisms. And succeeded.[1] [1] https://en.wikipedia.org/wiki/FBI–Apple_encryption_dispute

Their “you can’t compel us to build something” argument was for building a change to the passcode retry logic, which is presumably as simple as a constant change. Certainly building a back door in this system is at least as difficult, so the argument still stands.

In that specific case at least the FBI is asking Apple to produce new firmware that will bypass existing protection on an existing device - basically asking Apple to root a locked down phone which would likely require them breaking their own encryption or finding vulnerabilities in their own firmware. This is not exactly technically trivial since anything of this sort that’s already known would be patched out.

In this case it seems only a matter of policy that Apple submits CSAM hashes to devices for scanning. No new software needs to be written, no new vulnerability found. There’s no difference between a hash database of CSAM, FBI terrorists photos, or Winnie the Pooh memes. All that’s left is Apple’s words that their policy is capable of standing up to the legal and political pressures of countries it operates in. That seems like a far lower bar.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#242
post #228

Earlier quoted context omitted.

> A system which required the collision of multiple governments and Apple and their child abuse agencies simply is not that. Agree to disagree. > I would find it interesting to hear what Federighi would say about this potential abuse case. Personally I would not. That's a political consideration and not something I want to hear a technologist weigh in on while defending their technology. Apple's previous stance, with…

> Personally I would not. That's a political consideration and not something I want to hear a technologist weigh in on while defending their technology. It’s not. The abuse case flows from their architecture. Perhaps it isn’t as ‘easy’ as getting multiple countries to collude with Apple. If the architecture can be abused the way you think it can, that is a technical problem as well as a political one.

You can't solve the human-bias problem with technology. That's the whole reason Apple didn't want to build in a back door in the first place.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#243
post #227

Earlier quoted context omitted.

> creating 1984 in the literal sense I take it you haven’t read 1984. When Craig Federighi straps a cage full of starving rats to my face, I’ll concede this point.

China has tiger chairs. Should we move closer to their big brother systems?

No but this has nothing to do with that.

In case you missed it, I think this is probably a bad move.

I just don’t think these arguments about back doors and creeping totalitarianism are either accurate or likely to persuade everyday users when they weigh them up against the grotesque nature of child exploitation.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#244

Here's what I don't get: who is importing CSAM into their camera roll in the first place? I for one have never felt the urge to import regular, legal porn into my camera roll. Who the hell is going to be doing that with stuff they know will land them in prison? Who the hell co-mingles their deepest darkest dirtiest secret amongst pictures of their family and last night’s dinner? I can believe that some people might b…

Actually it occurs to me that perhaps they're noticing a lot of CSAM is being produced with smartphone cameras and are hoping to snag the phone which produced the originals. If they can get new content into their database before the photographer deletes them, they might find the phone which took the originals—and then find the child victim. Beyond implausible, but then most law enforcement tends to rely on someone ev…

It is only supposed to detect CSAM already known to NCMEC, not identify new images.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#245
post #228

Earlier quoted context omitted.

> Personally I would not. That's a political consideration and not something I want to hear a technologist weigh in on while defending their technology. It’s not. The abuse case flows from their architecture. Perhaps it isn’t as ‘easy’ as getting multiple countries to collude with Apple. If the architecture can be abused the way you think it can, that is a technical problem as well as a political one.

You can't solve the human-bias problem with technology. That's the whole reason Apple didn't want to build in a back door in the first place.

You may not be able to solve the bias problem altogether, but you can definitely change the threat model and who you have to trust.

Apple’s model has always involved trusting them. This model involves trusting other people in narrow ways. The architecture determines what those ways are.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#246
post #229

Earlier quoted context omitted.

Anyone who doesn’t like it can switch off iCloud Photo Library. I can imagine many people doing that in response to this news.

The fact that you can opt out for now does not set me at ease.

Nor me. I will not opt out because I think there is no threat to me and I like iCloud photos. That doesn’t mean I like the presence of this mechanism.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#247
post #108

Earlier quoted context omitted.

I think the fact that no technical document has lasted on the front page but various rumors have is a strong point for my view. An article about internal dissent at Apple has hung on for most of the day, yet almost no comments on it engage with any of the key concepts in the article: what does it mean for an 800 post slack thread to exist? Why does it matter that the security employees don’t seem against the idea on…

https://news.ycombinator.com/item?id=28173134 is #1 on the front page right now. Matthew Green and Alex Stamos both wrote things about this that were on HN's front page for a long time. I'm pretty sure there have been other technical threads as well.

You're doing a bang up job man. It's very kind of you to continue responding to these folks when they've taken your attention rather off topic from your original comment above. Other people's bad behavior doesn't excuse your own, which also happens to be the Chinese version of the golden rule: 己所不欲,勿施於人 (literally: what you don't want, don't apply to others)

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#248
post #243

Earlier quoted context omitted.

China has tiger chairs. Should we move closer to their big brother systems?

No but this has nothing to do with that. In case you missed it, I think this is probably a bad move. I just don’t think these arguments about back doors and creeping totalitarianism are either accurate or likely to persuade everyday users when they weigh them up against the grotesque nature of child exploitation.

> I just don’t think these arguments about back doors and creeping totalitarianism are either accurate or likely to persuade everyday users when they weigh them up against the grotesque nature of child exploitation.

Agree to disagree. This opens the door to something much worse in my opinion.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#249
post #246

Earlier quoted context omitted.

The fact that you can opt out for now does not set me at ease.

Nor me. I will not opt out because I think there is no threat to me and I like iCloud photos. That doesn’t mean I like the presence of this mechanism.

> That doesn’t mean I like the presence of this mechanism.

I don't think I ever said you did.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#250

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

Lots of people have made policy arguments. No US law requires client side scanning. No US law forbids E2E encryption. US courts don't let law enforcement agencies just demand everything they want from companies. Apple relied on that 5 years ago successfully.[1] And capitulating preemptively is bad strategy usually. What Neuenschwander said doesn't establish it isn't just an arbitrary limitation. [1] https://en.wikipe…

Each year, Apple gives up customer data on over 150,000 users based on US government data requests, and NSL and FISA requests[1].

The idea that Apple would fight this is a farce, as they regularly give up customers' data without a fight when the government requests it.

[1] https://www.apple.com/legal/transparency/us.html

Post reply on HN