Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

361–370 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#361

Earlier quoted context omitted.

The goal is not for it to be swept under the rug. The goal is for it to deflect concerns over the coming Privacy Relay service.

Their private relay service appears orthogonal to CSAM… it won’t make criminals and child abusers easier or harder to catch, and it doesn’t affect how people use their iCloud Photos storage.

These people are commonly prosecuted using evidence that includes server logs that showing their static IP address.

Read evidence from past trials it is obvious. See also successful and failed attempts to subpoena this info from VPN services.

Only people with iCloud will be using the relay.

It is true on the surface the photos is disconnected from the use. However, Apple only needs a solid answer that handles the bad optics of what you can do with the Tor-like anonymity of iCloud Privacy Relay.

However, if you look more closely, the CSAM service and its implementation are crafted exactly around the introduction of the relay.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#362
post #169

Earlier quoted context omitted.

My understanding based on piecing together the various poorly cited news stories is that Apple used to scan iCloud Mail for this material, and that’s it.

If you have references to also help me piece this together I'd find that really helpful.

Forbes had the only evidence based reporting where they cited a court case where Apple automatically detected known CSAM in attachments to iCloud Mail: https://www.forbes.com/sites/thomasbrewster/2020/02/11/how-a...

Everyone else is making inferences from a chance to their privacy policy and a statement made by a company lawyer.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#363
post #130

Earlier quoted context omitted.

...because cloud uploads require explicit user consent, practically speaking? Apple's system requires none.

Wouldn't both of those scenarios imply that the "bug" is bypassing any normal user consent? They're only practically different in that the "upload them all for cloud-scanning" one would take longer and use more bandwidth, but I suspect very few people would notice.

[deleted]

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#364
post #106
post #48

Earlier quoted context omitted.

Mostly hysterical may technically be an exaggeration, but mostly misinformed, and often dis-informative is not. This isn’t just about people weighing things they dislike more strongly. It’s also about groupthink, confirmation bias, and a lack of curiosity. HN doesn’t have an immune system against straight up misinformation.

> HN doesn’t have an immune system against straight up misinformation. It certainly doesn't! Misinformation and disinformation are terms du jour, but as far as I can tell they are indistinguishable from old-fashioned people-being-wrong-on-the-internet. If you expect an internet forum to be immune from that...well, that's too much to expect. As far as I can tell (and moderating HN for years has really hammered this ho…

Not only that, but no one (or perhaps we can say for decorum's sake, nearly no one) really cares about the truth. > We care about what we like and we want it to win against what we dislike; all the rest is rationalization.

This is a bleak, valueless and ascientific view of the world. It took a while for me to process it. It is consistent with the postmodern post-truth zeitgeist of tribalism and power being the only thing that matters.

> Moderating HN has really hammered that one into me as well. Such is human nature, and trying to moderate against it would be futile, not to mention a fast track to burnout. I've tried, and have the scars.

I can very clearly see why moderating HN would cause you to adopt this view. It’s interesting because it really doesn’t match the sense of who you are as you come across in your comments.

My own view is that we are not in such a bleak world. Meaning structures are shaped by media and we are only a decade or so into the era where media has become social. This is such a monumental and unprecedented change that it’s bound to appear that there is no up or down for a while.

I think it’s transient, and doesn’t reflect a universal truth about human nature.

For one obvious contradiction - can you think of anyone who actually prefers the idea of a valueless ascientific world? If so, who, and why?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#365
post #130

Earlier quoted context omitted.

...because cloud uploads require explicit user consent, practically speaking? Apple's system requires none.

Wouldn't both of those scenarios imply that the "bug" is bypassing any normal user consent? They're only practically different in that the "upload them all for cloud-scanning" one would take longer and use more bandwidth, but I suspect very few people would notice.

I think the difference lies in the visibility of each system in typical use. Apple's local scanning remains invisible to the user, in contrast to cloud uploading.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#366

Earlier quoted context omitted.

No. The 4A protections don't apply to third parties. This is part of why the US has nearly nonexistent data protection laws.

> The 4A protections don't apply to third parties. The government can't pay someone to break into your house and steal evidence they want without a warrant. I mean, they can, but the evidence wouldn't be admissible in court.

They don't need a warrant. You gave data to someone else. That someone isn't bound to keep it secret. They can demand a warrant if they are motivated by ethical principles but that is optional and potentially overruled by other laws.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#367
post #134

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

> there's a legitimate "slippery slope" argument The slippery slope argument is the only useful argument here. The fundamental issue with their PSI/CSAM system is that they already were scanning iCloud content [1] and that they're seemingly not removing the ability to do that. If the PSI/CSAM system had been announced along side E2E encryption for iCloud backups, it would be clear that they were attempting to act in…

> If the PSI/CSAM system had been announced along side E2E encryption for iCloud backups, it would be clear that they were attempting to act in their users best interests.

Most likely because the only way this announcement makes sense, is that they tried to respond for misleading leaks. We'll see on September probably some E2EE announcements, since iOS 15 beta supports tokens for backup recovery. At least, let's hope so.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#368

My phone is an extension of my brain, it is my most trusted companion. It holds my passwords, my mail, my messages, my photos, my plans and notes, it holds the keys to my bank accounts and my investments. I sleep with it by my bed and I carry it around every day. It is my partner in crime. Now apple are telling me that my trusted companion is scanning my photos as they are uploaded to iCloud, looking for evidence tha…

Technically they could have been scanning the photos already to power some AI algorithms or whatever else. I think this is a nudge for folks to wake up and see the reality of what it means to use the cloud. We are leasing storage space from Apple in this case. Technically, it’s no different than a landlord checking up on their tenants to make sure “everything is okay.” And technically, if you do not like iCloud, don’…

No they really couldn't, because someone investigating, monitoring and reverse engineering the device traffic might have noticed, it would be leaked by a whistleblower, there are plenty of ways this could ruin Apple.

Not so now, they are in the clear either way because Apple themselfes cannot look into the hashes databank. So the backdoor is there, the responsibility of the crime of spying is forwarded to different actors, which even cannot be monitored by Apple.

This is truly a devilish device they thought up. Make misuse possible, exonerate any responsibility to outside actors, act naive as if hands are clean.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#370
post #335

Earlier quoted context omitted.

Technically they could have been scanning the photos already to power some AI algorithms or whatever else. I think this is a nudge for folks to wake up and see the reality of what it means to use the cloud. We are leasing storage space from Apple in this case. Technically, it’s no different than a landlord checking up on their tenants to make sure “everything is okay.” And technically, if you do not like iCloud, don’…

> Technically, it’s no different than a landlord checking up on their tenants to make sure “everything is okay.” By this logic, you don't own your phone but rent it from Apple?

Technically I own my iPhone but the software is licensed to me (not a lawyer but that’s my understanding).

We probably also sign something that allows Apple to do what they will with our images—albeit we retain the copyrights to them.

Just to reiterate: the landlord metaphor is referring to software which we lease from Apple—not the device itself.

This is yet another case where I want to emphasize the importance of OPEN hardware and software designs. If we truly want ownership, we have to take ownership into our hands (which means a lot of hard work). Most commercial software is licensed so no we don’t own anything in whole that runs commercial software.

Post reply on HN