Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

351–360 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#351
post #170

Earlier quoted context omitted.

There is no regulatory threat within the US that could require this happen, if this was demanded by the government it would be a blatant violation of the 4th amendment. Apple should have stood their ground if this was in response to perceived government pressure.

There are two gov. issues. One is if the FBI comes knocking and the other is new laws. The government could absolutely write a law banning e2ee so that when the FBI does knock with a warrant they can get access. In the past, Apple has done what they can to stand their ground against the first, but they (like any other company) will have to comply with any laws passed. Whether the 'if a warrant is obtained the gov. sh…

When the FBI does knock with a warrant they already get access to data on iCloud. iCloud is not meaningfully encrypted to prevent this.

The FBI is unable to get a warrant to search data on everyones phones, regardless of what laws are passed. They might be able to get a warrant to search all the data on apple's server (I would consider this unlikely, but I don't know of precedent in either direction), but that data is fundamentally not on everyones phones. This isn't a novel legal question, you cannot search everyones devices without probable cause that "everyone" committed a crime.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#352
post #330
post #186

A key point that needs to be mentioned: we strongly dislike being distrusted. It might well be a genetic heritage. Being trusted in a tribe is crucial to survival, and so is likely wired deep into our social psychology. Apple is making a mistake by ignoring that. This isn’t about people not trusting Apple. It’s about people not feeling trusted by Apple. Because of this, it doesn’t matter how trustworthy the system is…

That's not at all clear. A lot of people like strong border controls for instance, even if it means when they return to their country from abroad they have to go through more checks or present more documents to get in. Or consider large gated communities where you have to be checked by a guard to get in. Many peoples seem fine with being distrusted as long as the distrust is part of a mechanism to weed out those who…

Your examples are not a good analogy. The distrust is transient and then you are cleared. This is a stare of permanently being a suspect.

However, it may certainly be the case that in the end people in general do accept this as a price worth paying to fight pedophiles.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#353
post #270

Earlier quoted context omitted.

> checking for other kinds of imagery such as memes critical of heads of state. Do you live in a country where the head of state wants to check for such memes?

Probably. You underestimate humans if you don't think any of us will try to squash things that make us look bad.

Does your state not have protections against such actions?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#354
post #246

Earlier quoted context omitted.

Nor me. I will not opt out because I think there is no threat to me and I like iCloud photos. That doesn’t mean I like the presence of this mechanism.

> That doesn’t mean I like the presence of this mechanism. I don't think I ever said you did.

No - but you did suggest there was no opting in. I’m pointing out that just because I’m not entirely happy with the choice doesn’t mean it isn’t a choice.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#355
post #106
post #48

Earlier quoted context omitted.

Mostly hysterical may technically be an exaggeration, but mostly misinformed, and often dis-informative is not. This isn’t just about people weighing things they dislike more strongly. It’s also about groupthink, confirmation bias, and a lack of curiosity. HN doesn’t have an immune system against straight up misinformation.

> HN doesn’t have an immune system against straight up misinformation. It certainly doesn't! Misinformation and disinformation are terms du jour, but as far as I can tell they are indistinguishable from old-fashioned people-being-wrong-on-the-internet. If you expect an internet forum to be immune from that...well, that's too much to expect. As far as I can tell (and moderating HN for years has really hammered this ho…

> but as far as I can tell they are indistinguishable from old-fashioned people-being-wrong-on-the-internet. If you expect an internet forum to be immune from that...well, that's too much to expect.

Also, this is a little too glib. I’m not talking about people being wrong or misinformed. I am talking about people actively spreading misinformation. These are distinguishable although I accept that they may be impractical to moderate, hence my claim about no immune system.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#356

Earlier quoted context omitted.

> It was illegal to export "strong encryption" for many years, remember? I've seen multiple reports that European lawmakers are planning to require some kind of scanning for CSAM. If this goes into effect, technology isn't going to block those laws for you. Your Purism phone will either be forced to comply or be illegal. The point is that with a Purism phone or custom ROM on my Android phone, I could disable these "l…

When the governments of the world demand that Apple become an arm of the dystopia, Apple will comply, and its users will have no choice but to go along with it. I would argue that Apple is creating systems so they can't become an arm of the dystopia. For example, even if a government somehow forced Apple to include non-CSAM hashes to the database, the system only uses hashes from multiple child protection agencies in…

>I would argue that Apple is creating systems so they can't become an arm of the dystopia.

For the life of me I can't see how catching child molesters is part of a dystopia.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#357

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

> The more we learn about the way Apple actually implemented this technology, the less likely it seems that it would make it radically easier for those bad actors to do so.

Then why isn’t Apple pushing this angle?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#358
post #257

Earlier quoted context omitted.

> But I sympathize with Apple for making transparent what I assume happens behind closed doors anyway. Using your devices' CPU and battery seems more egregious than doing it on their servers. If they want to help law enforcement, then they should pay for it. Of course they want to help law enforcement by forcing other people to pay the costs. Imagine if Ford came out with a cannabis sensor in their cars that automati…

Let's do a more realistic example. Ford introduces a "driver safety" mechanism where the car requires a clean breathalyzer reading in order to start. If it fails it pops up a message that reminds you that drunk driving is illegal but doesn't actually stop you from starting the engine. It then sends Ford the results in an encrypted payload along with 1/30th of the decryption key. After 30 reports someone at Ford opens…

That's not a realistic analogy because driving is a privilege you must earn, not a human right.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#359
post #266

Earlier quoted context omitted.

This point was made in the economist today. https://www.economist.com/united-states/2021/08/12/a-38-year...

I read the article; I don't think they highlighted this specific point that on-device scanning has a potential, hypothetical constitutional advantage in comparison to Google, Microsoft and Facebook who scan exclusively in the cloud.

They don’t draw out the comparison, but they do mention the protection.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#360

Earlier quoted context omitted.

Apple shipped iCloud Private Relay which is a “1-line code change that hooks into CFNetwork” away from MITMing all your network connections, by this standard.

Any connection worth its salt should be TLS protected.

Also in CFNetwork. Probably a one line change to replace all session keys with an Apple generated symmetric key.
Post reply on HN