Earlier quoted context omitted.
The problem is that many Android apps require Google services to function properly. You can try two Android derivatives: CalyxOS[1] that implements a privacy-conscious subset of Google services allowing many Android apps to work properly, and GrapheneOS[2] that excludes Google services altogether at the cost of lower app compatibility[3]. Both require using Google Pixel hardware. [1] https://calyxos.org/ [2] https://…
> GrapheneOS[2] that excludes Google services altogether at the cost of lower app compatibility[3]. It now has https://grapheneos.org/usage#sandboxed-play-services providing broader app compatibility. That video is quite misleading and it's not the best source for accurate information about GrapheneOS.
Security Threat Model Review of the Apple Child Safety Features [pdf]
331–340 of 393 posts
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#332Now apple are telling me that my trusted companion is scanning my photos as they are uploaded to iCloud, looking for evidence that apple can pass to the authorities? They made my phone a snitch?
This isn't about security or privacy, I don't care about encryption or hashes here, this is about trust. If I can't trust my phone, I can't use it.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#333Earlier quoted context omitted.
Nowhere have I claimed that the NCMEC databases are entirely devoid of miscategorised data. I am merely pushing back at your evidence-free claim that "it's full of false positives." Once again, you continue to assume that the MD5 collision cited was from a NCMEC corpus and not "other law enforcement sources". You're reading far more into your sources than they are saying. And now you are conflating claims of false po…
>Nowhere have I claimed that the NCMEC databases are entirely devoid of miscategorised data If NCMEC's databases have a false positive rate of 1 in 1,000, do you realise that means a false positive rate is substantially more likely than a hash collision? >I am merely pushing back at your evidence-free claim that "it's full of false positives." 1 in 1,000 is "full of false positives" by my own standards, to which I've…
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#334My phone is an extension of my brain, it is my most trusted companion. It holds my passwords, my mail, my messages, my photos, my plans and notes, it holds the keys to my bank accounts and my investments. I sleep with it by my bed and I carry it around every day. It is my partner in crime. Now apple are telling me that my trusted companion is scanning my photos as they are uploaded to iCloud, looking for evidence tha…
I think this is a nudge for folks to wake up and see the reality of what it means to use the cloud. We are leasing storage space from Apple in this case.
Technically, it’s no different than a landlord checking up on their tenants to make sure “everything is okay.”
And technically, if you do not like iCloud, don’t use it and roll your own custom cloud storage! After all, it’s redundancy and access the cloud provides. And Apple provides APIs to build them.
Hell, with the new Files app on iOS i just use a Samba share with my NAS server (just a custom built desktop with RAID 5 and Ubuntu.)
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#335My phone is an extension of my brain, it is my most trusted companion. It holds my passwords, my mail, my messages, my photos, my plans and notes, it holds the keys to my bank accounts and my investments. I sleep with it by my bed and I carry it around every day. It is my partner in crime. Now apple are telling me that my trusted companion is scanning my photos as they are uploaded to iCloud, looking for evidence tha…
Technically they could have been scanning the photos already to power some AI algorithms or whatever else. I think this is a nudge for folks to wake up and see the reality of what it means to use the cloud. We are leasing storage space from Apple in this case. Technically, it’s no different than a landlord checking up on their tenants to make sure “everything is okay.” And technically, if you do not like iCloud, don’…
By this logic, you don't own your phone but rent it from Apple?
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#336My phone is an extension of my brain, it is my most trusted companion. It holds my passwords, my mail, my messages, my photos, my plans and notes, it holds the keys to my bank accounts and my investments. I sleep with it by my bed and I carry it around every day. It is my partner in crime. Now apple are telling me that my trusted companion is scanning my photos as they are uploaded to iCloud, looking for evidence tha…
Technically they could have been scanning the photos already to power some AI algorithms or whatever else. I think this is a nudge for folks to wake up and see the reality of what it means to use the cloud. We are leasing storage space from Apple in this case. Technically, it’s no different than a landlord checking up on their tenants to make sure “everything is okay.” And technically, if you do not like iCloud, don’…
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#337Earlier quoted context omitted.
Apple is a trillion dollar company with a lot of smart people. You could probably get them to design a system of N of M parts for recovery, or an apple branded key holder that you can store in your bank vault and friends houses. If they wanted to they'd do it.
More than that: Apple already designed and partially implemented such a "trust circles" system. Apple legal killed the feature, because of pressure from the US government. https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv... They also run iCloud (mostly not e2e) on CCP-controlled servers for users in China. They can decrypt ~100% of iMessages in real-time due to the way iCloud Backup (on by default, not e2…
“However, a former Apple employee said it was possible the encryption project was dropped for other reasons, such as concern that more customers would find themselves locked out of their data more often.”
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#338In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…
>Apple is treating CSAM as an engineering problem. No they're treating it as a political and legal problem (with the UK and the EU being the furthest along on passing legislation). Their implementation is the compromise that preserves end-to-end encryption, given those political winds.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#339In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…
> For instance, the "it only scans photos uploaded to iCloud" element isn't just an arbitrary limitation that can be flipped with one line of code, as some folks seem to think; as Erik Neuenschwander, head of Privacy Engineering at Apple, explained in an interview on TechCrunch[1]: > > Our system involves both an on-device component where the voucher is created, but nothing is learned, and a server-side component, wh…
The problem is there's no reason Apple couldn't do anything. All the ML face data gathered on device would be way more valuable than these hash vouchers.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#340My phone is an extension of my brain, it is my most trusted companion. It holds my passwords, my mail, my messages, my photos, my plans and notes, it holds the keys to my bank accounts and my investments. I sleep with it by my bed and I carry it around every day. It is my partner in crime. Now apple are telling me that my trusted companion is scanning my photos as they are uploaded to iCloud, looking for evidence tha…
> It is my partner in crime.