Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

301–310 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#301
post #293

Earlier quoted context omitted.

NCMEC's database does not only contain CSAM. It has never been audited. It's full of false positives. They are immune from FOIA requests. They are accountable to nobody. They work so closely with the FBI that there are FBI agents working on the database directly. NCMEC is essentially an unaccountable, unauditable department of the FBI that also happens to be incompetent (the amount of non-CSAM in the database is larg…

You don't know what's in it, but you do know it's full of false positives? I wonder, do you know how many of those false positives are flagged as A1?

I know for a fact that it is full of false positives, there's also public sources making the same claim. [1]

[1] https://www.hackerfactor.com/blog/index.php?/archives/929-On...

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#302
post #221

Earlier quoted context omitted.

> without your approval This isn’t true. You can always turn off iCloud Photo Library and just store the photos locally or use a different cloud provider.

I hate this argument. Pressing yes to the T&C once when you setup an Apple account doesn’t exactly constitute my approval imo (even if it does legally). There’s no disable button or even clear indication that it’s going on.

> There’s no disable button or even clear indication that it’s going on.

iCloud Photos is an on-off switch.

In terms of clearly indicating everything that is going on within the service, that is just not possible for most non-tech users. It appears to have been pretty difficult even for those familiar with things like cryptography and E2E systems to understand the nuances and protections in place.

Instead, the expectation should be that using _any_ company's cloud hosting or cloud synchronization features is fundamentally sharing your data with them. It should then be any vendor's responsibility give give customers guarantees on which to evaluate trust.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#303

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

Speaking of mobile OS. I am a bit of a newbie myself in this area. I am an Android user but I want to decouple from Google as much as possible. Is there an mobile OS out there that offers a similar experience to, say, Android in terms of functionalities, apps, etc without the drawback of privacy concerns?

Your best bets are GrapheneOS or CalyxOS. In both cases be prepared to sacrifice a lot in terms of convenience (more with GrapheneOS).

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#304
post #167

Earlier quoted context omitted.

> If the PSI/CSAM system had been announced along side E2E encryption for iCloud backups, it would be clear that they were attempting to act in their users best interests. Absolutely. I don't know whether there's a reason for this timing (that is, if they are planning E2E encryption, why they announced this first), but this is probably the biggest PR bungle Apple has had since "you're holding it wrong," if not ever.…

Right, and in the interview linked [1] above they state: > The voucher generation is actually exactly what enables us not to have to begin processing all users’ content on our servers, which we’ve never done for iCloud Photos. But they do appear to do "something" server-side. It's possible that all data in scanned as it is ingested for example. I dislike this statement, because it's probably technically correct but d…

What I don’t understand is that if they announced they would do that scanning server side, the only eyebrows that would be raised is of people who thought they were doing it already. It’s not like if those pictures were e2e encrypted. I still haven’t seen any convincing argument about why searching client side provide any benefit to end users, while being a massive step in the direction of privacy invasion.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#305
post #268
post #115

Earlier quoted context omitted.

> Even if this, alone isn't enough to convince you to move off Apple, are you comfortable with the trends now clearly visible? Still much better than all but the most esoteric inconvenient alternatives.

And if those are all that's left that meet your criteria for a non-abusive platform, then... well, that's what you've got to work with. Maybe try to improve those non-abusive platforms. I'm rapidly heading there. I'm pretty sure I won't run Win11 given the hardware requirements (I prefer keeping older hardware running when it still fits my needs) and the requirement for an online Microsoft account for Win11 Home (NO,…

> And if those are all that's left that meet your criteria for a non-abusive platform, then... well, that's what you've got to work with. Maybe try to improve those non-abusive platforms.

There's always the potential to work on the underlying laws. Not every problem can be solved by tech alone.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#306

I don’t like the idea of stuff running on my device, consuming my battery and data, when the only point is to see if I am doing something wrong? An analogy I can come up with is: the government hires people to visit your house every day, and while they’re there they need your resources (say, food, water, and electricity). In other words, they use up some of the stuff you would otherwise be able to use only for yourse…

[deleted]

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#307

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

Speaking of mobile OS. I am a bit of a newbie myself in this area. I am an Android user but I want to decouple from Google as much as possible. Is there an mobile OS out there that offers a similar experience to, say, Android in terms of functionalities, apps, etc without the drawback of privacy concerns?

The problem is that many Android apps require Google services to function properly. You can try two Android derivatives: CalyxOS[1] that implements a privacy-conscious subset of Google services allowing many Android apps to work properly, and GrapheneOS[2] that excludes Google services altogether at the cost of lower app compatibility[3]. Both require using Google Pixel hardware.

[1] https://calyxos.org/ [2] https://grapheneos.org/ [3] "GrapheneOS vs CalyxOS ULTIMATE COMPARISON (Battery & Speed Ft. Stock Android & iPhone)", https://www.youtube.com/watch?v=7iS4leau088

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#308
post #260
post #134

Earlier quoted context omitted.

> there's a legitimate "slippery slope" argument The slippery slope argument is the only useful argument here. The fundamental issue with their PSI/CSAM system is that they already were scanning iCloud content [1] and that they're seemingly not removing the ability to do that. If the PSI/CSAM system had been announced along side E2E encryption for iCloud backups, it would be clear that they were attempting to act in…

> The fundamental issue with their PSI/CSAM system is that they already were scanning iCloud content This scanning was of email attachments being sent through an iCloud-hosted account, not of other iCloud hosted data (which is encrypted during operation.)

If it’s encrypted but apple has the key, it’s not encrypted to them.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#309
post #86

Earlier quoted context omitted.

Apple actually gives special devices to Security Researchers that allow them further access into the device than a normal consumer device: https://developer.apple.com/programs/security-research-devic... In this way, third party security researchers can verify their claims. It actually works out pretty well for them since third party security researchers often find pretty severe vulnerabilities through this program.

That program, at least when it was introduced, required participants not to report security vulnerabilities publicly until Apple allowed them to do so, with no limits on how long that can be (see https://news.ycombinator.com/item?id=23920454 for a discussion from that time). That makes this program particularly useless for the purpose of auditing whether Apple is adhering to its promises.

For security issues where the participants basically make their living indirectly by getting credit for security vulnerabilities, this carrot-and-stick potentially motivates them to stay quiet.

Meanwhile, researchers have gotten wise to notary techniques (like publishing document hashes to twitter) which would let them severely and publicly shame Apple should they sit on something that ultimately turns out to be a zero day, with much delight from/participation by the media.

For privacy/societal issues where Apple is a deliberate bad actor, they would presumably either directly be willing to break the terms of the agreement to go public, or would release information indirectly and rely on herd privacy with other researchers.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#310
post #91

> The second protection [against mis-inclusion of non CSAM hashes] is human review: there is no automated reporting in Apple’s system. All positive matches must be visually confirmed by Apple as containing CSAM before Apple will disable the account and file a report with the child safety organization. I don't understand this at all. As I understand it, part of the problem is that — in the US — Apple isn't legally all…

Your phone transmits the images with their security envelope (which was computed on device and contains neural hash and "visual derivative") to the iCloud server. During that process, Apple does not know whether there's any CSAM in it, so they can transmit legally. Then the server determines whether the number of matches exceeds the threshold. Only if that is the case (by crypto magic) can the security envelope of th…

Your understanding seems correct. After a positive evaluation from Apple, the CyberTipline report is filed to NCMEC, which operates as a clearinghouse and notifies law enforcement.

Law enforcement then gets a court order, which will cause Apple to release requested/available information about that account.

If photos later are outside the key escrow system, Apple would not be able to release the photos encryption keys, and would only be able to share 'public' photo share information which the user has opted to share without encryption to make it web-accessible.

Presumably in this case, the visual derivatives would still be used as evidence, but there would be 5th amendment arguments around forcing access to a broader set of photos.

Post reply on HN