Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

261–270 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#261
post #252

Earlier quoted context omitted.

> It’s not a back door in any sense of the word. It is. It's a simple matter for two foreign governments to decide they don't want their people to criticize the head of state with memes, and then insert such images into the database Apple uses for scanning. Apple's previous position on privacy was to make such snooping impossible because they don't have access to the data. Now they are handing over access. What I and…

How does this attack even work? So some government poisons the database with political dissident memes and suddenly Apple starts getting a bunch of new reports which when reviewed are obviously not CSAM. If the government can force Apple to also turn over these reports then they could have just made Apple add their political meme database directly and it's already game over.

More like, the government says Apple can't operate there unless they include what they say is illegal.

Apple is run by humans who are subject to influence and bias. Who knows what policy changes will come in Apple's future. Apple's previous stance was to not hand over data because they don't have access to it. This change completely reverses that.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#262
post #164

Earlier quoted context omitted.

> This is an area we’ve been looking at for some time, including current state of the art techniques which mostly involves scanning through entire contents of users’ libraries on cloud services that — as you point out — isn’t something that we’ve ever done; to look through users’ iCloud Photos. https://techcrunch.com/2021/08/10/interview-apples-head-of-p... > This moment calls for public discussion, and we want our c…

> The voucher generation is actually exactly what enables us not to have to begin processing all users’ content on our servers, which we’ve never done for iCloud Photos. I really dislike this statement. It's likely designed to be "technically true". But it's been reported elsewhere that they do scan iCloud content: https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-... Perhaps they scan as the data is being…

That link doesn’t confirm that they have already been doing it. Just that they changed an EULA.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#263
post #66
post #43

Earlier quoted context omitted.

If your threat model includes pervasive spying by multiple nation states, and being grabbed in the night by black helicopters, it seems unlikely you'll be overly concerned about them precisely inserting at least 30 of your photos into multiple CSAM databases and also co-ercing Apple's manual review to get you reported to NCMEC.

I don't think people are worried about multiple nation states framing them with CSAM photos - they're worried about multiple nation states in an intelligence collaboration poisoning both sets of hash lists with non-CSAM material, so that there is an intersection that makes it onto the device. There is still that Apple human reviewer once the threshold has passed. What I would love to ask Apple is - what happens if/wh…

The document states that incorrectly flagged items are forwarded to engineering for analysis. Given their target false-positive rate (1 in 3 trillion, was it?) it seems likely that engineering would very carefully analyze a rush of false positives.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#264

> The second protection [against mis-inclusion of non CSAM hashes] is human review: there is no automated reporting in Apple’s system. All positive matches must be visually confirmed by Apple as containing CSAM before Apple will disable the account and file a report with the child safety organization. I don't understand this at all. As I understand it, part of the problem is that — in the US — Apple isn't legally all…

Your understanding is incorrect. Apple can, and is in fact required to, verify that they have actual CSAM before forwarding it to the Cyber Tip line. At that point, they must delete the information within 60 days.

> Apple can, and is in fact required to, verify that they have actual CSAM

It's not Apple's job to decide if something is CSAM or not. They're required to report it if they suspect it is, even if they can't confirm it.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#265

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

Lots of people have made policy arguments. No US law requires client side scanning. No US law forbids E2E encryption. US courts don't let law enforcement agencies just demand everything they want from companies. Apple relied on that 5 years ago successfully.[1] And capitulating preemptively is bad strategy usually. What Neuenschwander said doesn't establish it isn't just an arbitrary limitation. [1] https://en.wikipe…

> And capitulating preemptively is bad strategy usually.

Why do you think they are doing it then?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#266

Earlier quoted context omitted.

No. The 4A protections don't apply to third parties. This is part of why the US has nearly nonexistent data protection laws.

If Apple was performing scans on their cloud servers, you'd be absolutely right. But if the scanning is being done on the individual's device, I'm not sure it's that straightforward. The third party doctrine surely cannot apply if the scanning is performed prior to the material being in third party hands. Therefore if the Government forces Apple to change the search parameters contained within private devices, I cann…

This point was made in the economist today.

https://www.economist.com/united-states/2021/08/12/a-38-year...

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#267

I have no doubt the features work exactly the way Apple said they do. Seriously. I very much doubt that they will refuse to scan for whatever China asks. I very much doubt they'll risk the PRC shutting down Foxconn factories. I very much doubt Apple will ultimately be able to resist scanning for whatever the US Government asks in a national security letter attached to a gag order. They will take them to a secret cour…

> Now, will Apple bother to fight this out in court? I think they probably will.

Why would they? Each year they give up customer data on over 150,000 users without a fight when the US government simply asks them for it[1].

[1] https://www.apple.com/legal/transparency/us.html

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#268
post #115
post #78

Earlier quoted context omitted.

I understand the technologies they're proposing deploying at a decent level (I couldn't implement the crypto with my current skills, but what they're doing in the PSI paper makes a reasonable amount of sense). The problem is that this "hard" technological core (the crypto) is subject to an awful lot of "soft" policy issues around the edge - and there's nothing but "Well, we won't do that!" in there. Plus, the whole T…

> Even if this, alone isn't enough to convince you to move off Apple, are you comfortable with the trends now clearly visible? Still much better than all but the most esoteric inconvenient alternatives.

And if those are all that's left that meet your criteria for a non-abusive platform, then... well, that's what you've got to work with. Maybe try to improve those non-abusive platforms.

I'm rapidly heading there. I'm pretty sure I won't run Win11 given the hardware requirements (I prefer keeping older hardware running when it still fits my needs) and the requirement for an online Microsoft account for Win11 Home (NO, and it's pretty well stupid that I have to literally disconnect the network cable to make an offline account on Win10 now, and then disable the damned nag screens).

If Apple is going full in on this whole "Your device is going to work against you" thing they're trying for, well... I'm not OK with that either. That leaves Linux and the BSDs. Unfortunately, Intel isn't really OK in my book either with the fact that they can't reason about their chips anymore (long rant, but L1TF and Plundervolt allowing pillage of the SGX guarantees tells me Intel can't reason about their chips)... well. Hrm. AMD or ARM it is, and probably not with a very good phone either.

At this point, I'm going down that road quite quickly, far sooner than I'd hoped, because I do want to live out what I talk about with regards to computers, and if the whole world goes a direction I'm not OK with, well, OK. I'll find alternatives. I accept that unless things change, I'm probably no more than 5-10 years away from simply abandoning the internet entirely outside work and very basic communications. It'll suck, but if that's what I need to do to live with what I claim I want to live by, that's what I'll do.

"I think this is a terrible idea and I wish Apple wouldn't do it, but I don't care enough about it to stop using Apple products" is a perfectly reasonable stance, but it does mean that Apple now knows they can do more of this sort of thing and get away with it. Good luck with the long term results of allowing this.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#269
If they continue down this road, they will not only have effectively created the smartphone category, but also coincidentally destroyed it.

If our devices are designed to spy on us, we're frankly not even going to use them anymore. I wonder if they forgot that using this thing is optional? You'll see a resurgence of single purpose dumb devices.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#270
post #245

Earlier quoted context omitted.

You may not be able to solve the bias problem altogether, but you can definitely change the threat model and who you have to trust. Apple’s model has always involved trusting them . This model involves trusting other people in narrow ways. The architecture determines what those ways are.

Trusting Apple to not scan my device in the past was easy because as an engineer I know I would speak up if I saw that kind of thing secretly happening, and I know security researchers would speak up if they detected it. Now Apple will scan the device and we must trust that 3rd parties will not abuse the technology by checking for other kinds of imagery such as memes critical of heads of state. The proposed change is…

> checking for other kinds of imagery such as memes critical of heads of state.

Do you live in a country where the head of state wants to check for such memes?

Post reply on HN