Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

291–300 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#291

Sounds like it still comes down to trust. Quoting from the paper: "Apple will refuse all requests to add non-CSAM images to the perceptual CSAM hash database; third party auditors can confirm this through the process outlined before. Apple will also refuse all requests to instruct human reviewers to file reports for anything other than CSAM materials for accounts that exceed the match threshold."

It's already a lie, considering NCMEC's database already has non-CSAM images. It won't ever be true, since the hundreds and possibly thousands of entities with direct and indirect access to the database can upload SunnyMeadow.jpg labeled as CSAM content, and it's blindly accepted.

If Apple is receiving a hash labeled as "CSAM", how can they possibly make this guarantee? They do not know it's CSAM. It's unverifiable and comes down to "trust us".

Remember, NCMEC is an unaccountable organisation inextricably linked with the FBI and the U.S. government. It is not subject to FOIA requests. Its database has never been audited, and it is known to be a mess already.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#292
post #170

Earlier quoted context omitted.

The point of it is to make sure iCloud Photos remains a viable service in light of real and perceived regulatory threats, and possibly leave the door open to end to end encryption in the future.

There is no regulatory threat within the US that could require this happen, if this was demanded by the government it would be a blatant violation of the 4th amendment. Apple should have stood their ground if this was in response to perceived government pressure.

IMHO, the relevant regulations are pretty carefully worded to make 4th amendment defenses harder. In this case, Apple has some liability for criminal activity on their platform whether it is was E2E encrypted or not.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#293

Earlier quoted context omitted.

Actually it occurs to me that perhaps they're noticing a lot of CSAM is being produced with smartphone cameras and are hoping to snag the phone which produced the originals. If they can get new content into their database before the photographer deletes them, they might find the phone which took the originals—and then find the child victim. Beyond implausible, but then most law enforcement tends to rely on someone ev…

It is only supposed to detect CSAM already known to NCMEC, not identify new images.

NCMEC's database does not only contain CSAM. It has never been audited. It's full of false positives. They are immune from FOIA requests. They are accountable to nobody. They work so closely with the FBI that there are FBI agents working on the database directly.

NCMEC is essentially an unaccountable, unauditable department of the FBI that also happens to be incompetent (the amount of non-CSAM in the database is large).

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#294
post #147

> Apple generates the on-device perceptual CSAM hash database through an intersection of hashes provided by at least two child safety organizations operating in separate sovereign jurisdictions – that is, not under the control of the same government. Any perceptual hashes appearing in only one participating child safety organization’s database, or only in databases from multiple agencies in a single sovereign jurisdi…

China: here’s our database and here is one for Hong Kong. They’re totally separate we promise.

Separate but identical, indeed.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#295
post #159

Earlier quoted context omitted.

That’s different. The FBI can legally require Apple or any other US company to search for specific files it has access to on it’s own servers because nothing currently shields backup providers. They could and did force Apple to aid in unlocking iPhones when Apple had that capacity. What they couldn’t do was “These orders would compel Apple to write new software that would let the government bypass these devices' secu…

Apple is a trillion dollar company with a lot of smart people. You could probably get them to design a system of N of M parts for recovery, or an apple branded key holder that you can store in your bank vault and friends houses. If they wanted to they'd do it.

More than that: Apple already designed and partially implemented such a "trust circles" system.

Apple legal killed the feature, because of pressure from the US government.

https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

They also run iCloud (mostly not e2e) on CCP-controlled servers for users in China.

They can decrypt ~100% of iMessages in real-time due to the way iCloud Backup (on by default, not e2e) escrows iMessage sync keys.

Apple does not protect your mprivacy from Apple, or, by extension, the governments that ultimately exert control over Apple: China and the USA.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#296
post #293

Earlier quoted context omitted.

It is only supposed to detect CSAM already known to NCMEC, not identify new images.

NCMEC's database does not only contain CSAM. It has never been audited. It's full of false positives. They are immune from FOIA requests. They are accountable to nobody. They work so closely with the FBI that there are FBI agents working on the database directly. NCMEC is essentially an unaccountable, unauditable department of the FBI that also happens to be incompetent (the amount of non-CSAM in the database is larg…

You don't know what's in it, but you do know it's full of false positives? I wonder, do you know how many of those false positives are flagged as A1?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#297
post #201

Earlier quoted context omitted.

It’s not a back door in any sense of the word. That’s why he is surprised people see it as one. It really only does what they say it does, and it really is hard to abuse. But that doesn’t matter. The point is that even so, it makes everyone into a suspect, and that feels wrong .

I would say that it is a back door, because it would work even if iCloud Photos were E2E encrypted. It may not be a generic one, but one that is specific to a purpose Apple decided is rightful. And there is no guarantee that Apple (or authorities) won't decide that there are other rightful purposes.

> I would say that it is a back door, because it would work even if iCloud Photos were E2E encrypted.

Backdoor is defined by the Oxford Dictionary as "a feature or defect of a computer system that allows surreptitious unauthorized access to data."

The system in question requires you to upload the data to iCloud Photos for the tickets to be meaningful and actionable. Both your phone and iCloud services have EULA which call out and allow for such scanning to take place, and Apple has publicly described how the system works as far as its capabilities and limitations. In the sense that people see this as a change in policy (IIRC the actual license agreement language changed over a year ago) , Apple has also described how to no longer use the iCloud Photos service.

One less standard usage is not about unauthorized access but specifically to private surveillance (e.g. "Clipper chip") - but I would argue that the Clipper chip was a case where the surveillance features were specifically not being talked about, hence it still counting as "unauthorized access".

But with a definition that covers broad surveillance instead of unauthorized access, it would still be difficult to classify this as a back door. Such surveillance arguments would only pertain to the person's phone and not to information the user chose to release to external services like iCloud Photos.

To your original point, it would still work with iCloud Photos did not have the key escrow, albeit with less data being capable of being able to be turned over to law enforcement. However iCloud Photos being an external system would still mean this is an intentional and desired feature (presumably) by the actual system owners (Apple).

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#298

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

What apple is doing is fucked up. Full stop. Mental gymnastics are required to go beyond this premise.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#299

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

>The entire point of having a liberal democracy is that we are the government, and we can pull it back from authoritarianism.

We technically can. We also can technically elect people that understand technology. But practically its 100x more likely that I, a person that works with technology for a living, magically finds a way to provide my family with a decent lifestyle doing somethign that doesn't use computers at all. And I view the chances of that happening to be almost non-existent.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#300
post #182

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

I agree that this is a policy issue. The EU passed a new law just a last month regarding this [0]. I thought this was the implementation for the EU. If it was - it was fast? [0] https://news.ycombinator.com/item?id=27753727

I still see a lot of people thinking the EU law demands the scanning of images for CSAM, but really it permits the scanning of images again. Apparently no one noticed that EU privacy laws actually prohibited the scanning of user images until last year, when companies like Facebook stopped scanning images to avoid fines.

So Apple's move can hardly have been for the EU, but had the European Parliament not passed it, Apple would have had to disable it in the EU.

Post reply on HN