Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

381–390 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#381

Earlier quoted context omitted.

Speaking of mobile OS. I am a bit of a newbie myself in this area. I am an Android user but I want to decouple from Google as much as possible. Is there an mobile OS out there that offers a similar experience to, say, Android in terms of functionalities, apps, etc without the drawback of privacy concerns?

Your best bets are GrapheneOS or CalyxOS. In both cases be prepared to sacrifice a lot in terms of convenience (more with GrapheneOS).

thanks!

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#382

Earlier quoted context omitted.

They don't need a warrant. You gave data to someone else. That someone isn't bound to keep it secret. They can demand a warrant if they are motivated by ethical principles but that is optional and potentially overruled by other laws.

But if they're looking for incriminating evidence on your private property (i.e. on-device scanning) then they do need a warrant. It doesn't matter if a copy of it was also given to a third party (i.e. uploaded to iCloud) what matters is where the actual search takes place.

The authorities aren't doing the scanning. You will be made to agree in the fine print to let Apple do it when iCloud sync is enabled. If they run across evidence of a crime then c'est la vie.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#383

Earlier quoted context omitted.

When I use a web service, I expect my data to be collected by the service, especially if it is free of charge. A device I own should not be allowed to collect and scan my data without my permission.

A device I own should not be allowed to collect and scan my data without my permission. It's not scanning; it's creating a cryptographic safety voucher for each photo you upload to iCloud Photos. And unless you reach a threshold of 30 CSAM images, Apple knows nothing about any of your photos.

From the point of view of how image processing works, what is happening can indeed be called “scanning”.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#384

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

In this case I still think there is an engineering problem too: A bad actor only needs to get a bunch of CSAM pictures in your iCloud library to get you into big trouble.

This is not very hard to do. For example, WhatsApp has the "Save pictures to camera roll" option, on by default.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#385
post #81

Earlier quoted context omitted.

> Until a 1-line code change happens that hooks it into UIImage. I really don't understand this view. You are using proprietary software, you are always an N-line change away from someone doing something you don't like. This situation doesn't change this. If you only use open source software and advocate for others to do the same, I would understand it more.

Did you verify all the binaries that you run are from compiled source code that you audited? Your BIOS? What about your CPU and GPU firmware? There is always a chain of trust that you end up depending on. OSS is not a panacea here.

https://news.ycombinator.com/item?id=27897975

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#386

Earlier quoted context omitted.

Now we just need everyone to have that same realization about almost all the software we use on almost all the devices we own. As a practical matter 99.99% of us operate on trust.

Remember that emission cheating scandal? Where we supposedly had a system in place to detect bad actors and yet it was detected by a rare case of some curious student exploring how things work or some such.

Which is why open(-ish[0]) things are good, because people can get curious and see how they work.

[0] I understand the emissions cheating was not supossed to be open, but a relatively open system allowed said student to take a peek and see what was going on.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#388
post #134

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

> there's a legitimate "slippery slope" argument The slippery slope argument is the only useful argument here. The fundamental issue with their PSI/CSAM system is that they already were scanning iCloud content [1] and that they're seemingly not removing the ability to do that. If the PSI/CSAM system had been announced along side E2E encryption for iCloud backups, it would be clear that they were attempting to act in…

> If the PSI/CSAM system had been announced along side E2E encryption for iCloud backups, it would be clear that they were attempting to act in their users best interests.

As I understand it, this was more "leaked" than "announced". That is, it wasn't part of Apple's planned rollout strategy.

My thought was that they'll announce that soon, but then again, I'm shocked soon wasn't last week. I have no idea. Maybe there is some other limitation (legal) on he iCloud E2E backups they needed to solve first?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#390
post #220

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

> For instance, the "it only scans photos uploaded to iCloud" element isn't just an arbitrary limitation that can be flipped with one line of code, as some folks seem to think; as Erik Neuenschwander, head of Privacy Engineering at Apple, explained in an interview on TechCrunch[1]: > > Our system involves both an on-device component where the voucher is created, but nothing is learned, and a server-side component, wh…

>It seems most people are very willing to let their leaders scare them into believing that they must give up liberty in exchange for safety and security.

What Snowden exposed is that these changes are happening in secret, with no democratic support or oversight.

Laws are being circumvented so people aren't being given the choice to support or not.

Post reply on HN