My phone is an extension of my brain, it is my most trusted companion. It holds my passwords, my mail, my messages, my photos, my plans and notes, it holds the keys to my bank accounts and my investments. I sleep with it by my bed and I carry it around every day. It is my partner in crime. Now apple are telling me that my trusted companion is scanning my photos as they are uploaded to iCloud, looking for evidence tha…
This is the thing Apple doesn't realize: our phone's OS vendor has one job: not to betray us. They have betrayed us. I have purchased my last iPhone.
Security Threat Model Review of the Apple Child Safety Features [pdf]
371–380 of 393 posts
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#372I don’t like the idea of stuff running on my device, consuming my battery and data, when the only point is to see if I am doing something wrong? An analogy I can come up with is: the government hires people to visit your house every day, and while they’re there they need your resources (say, food, water, and electricity). In other words, they use up some of the stuff you would otherwise be able to use only for yourse…
A better fitting analogy would be you ask FedEx to pick up a package at your house for delivery, and they have a new rule that they won't pick up packages unless they can look inside to make sure that they are packed correctly and do not contain anything that FedEx does not allow. When they open and look into the package while in your house for the pickup, they are using your light to see and your heating/cooling is…
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#373Earlier quoted context omitted.
This is the thing Apple doesn't realize: our phone's OS vendor has one job: not to betray us. They have betrayed us. I have purchased my last iPhone.
good luck finding a replacement, you'll end up using a custom rom if you are serious about tracking and privacy, and that custom rom will be... fully dependent on donations.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#374Earlier quoted context omitted.
When the governments of the world demand that Apple become an arm of the dystopia, Apple will comply, and its users will have no choice but to go along with it. I would argue that Apple is creating systems so they can't become an arm of the dystopia. For example, even if a government somehow forced Apple to include non-CSAM hashes to the database, the system only uses hashes from multiple child protection agencies in…
>I would argue that Apple is creating systems so they can't become an arm of the dystopia. For the life of me I can't see how catching child molesters is part of a dystopia.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#375Earlier quoted context omitted.
> That doesn’t mean I like the presence of this mechanism. I don't think I ever said you did.
No - but you did suggest there was no opting in. I’m pointing out that just because I’m not entirely happy with the choice doesn’t mean it isn’t a choice.
People who haven't heard what Apple is doing are not presented with a choice. Not everyone follows tech news so closely.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#376Earlier quoted context omitted.
Probably. You underestimate humans if you don't think any of us will try to squash things that make us look bad.
Does your state not have protections against such actions?
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#377Earlier quoted context omitted.
I hate this argument. Pressing yes to the T&C once when you setup an Apple account doesn’t exactly constitute my approval imo (even if it does legally). There’s no disable button or even clear indication that it’s going on.
> There’s no disable button or even clear indication that it’s going on. iCloud Photos is an on-off switch. In terms of clearly indicating everything that is going on within the service, that is just not possible for most non-tech users. It appears to have been pretty difficult even for those familiar with things like cryptography and E2E systems to understand the nuances and protections in place. Instead, the expect…
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#378Earlier quoted context omitted.
I read the article; I don't think they highlighted this specific point that on-device scanning has a potential, hypothetical constitutional advantage in comparison to Google, Microsoft and Facebook who scan exclusively in the cloud.
They don’t draw out the comparison, but they do mention the protection.
I did find someone in the media making this point, so it turns out I'm not being completely original: https://9to5mac.com/2021/08/10/misusing-csam-scanning-in-us-...
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#379Earlier quoted context omitted.
> The 4A protections don't apply to third parties. The government can't pay someone to break into your house and steal evidence they want without a warrant. I mean, they can, but the evidence wouldn't be admissible in court.
They don't need a warrant. You gave data to someone else. That someone isn't bound to keep it secret. They can demand a warrant if they are motivated by ethical principles but that is optional and potentially overruled by other laws.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#380Earlier quoted context omitted.
> GrapheneOS[2] that excludes Google services altogether at the cost of lower app compatibility[3]. It now has https://grapheneos.org/usage#sandboxed-play-services providing broader app compatibility. That video is quite misleading and it's not the best source for accurate information about GrapheneOS.
Thank you for pointing this out, I will start linking to the updated material.