Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

391–393 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#391
post #144

Earlier quoted context omitted.

> For instance, the "it only scans photos uploaded to iCloud" element isn't just an arbitrary limitation that can be flipped with one line of code, as some folks seem to think; as Erik Neuenschwander, head of Privacy Engineering at Apple, explained in an interview on TechCrunch[1]: >> Our system involves both an on-device component where the voucher is created, but nothing is learned, and a server-side component, whi…

The system isn't entirely on-device, but relies on uploading data to Apple's servers. Hence, why I said that it's not an arbitrary limitation that it only scans photos uploaded to iCloud. The system literally has to upload enough images with triggering "safety vouchers" to Apple to pass the reporting threshold, and critical parts of that calculation are happening on the server side. I think what you're arguing is tha…

>"what amount happens on device vs. what amount happens on server" is a form of bikeshedding

There's a massive difference between a search carried out on a device someone "owns" and carries with them at all times, and a server owned by someone else.

To claim otherwise is absurd. Hence all this backlash.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#392

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

I have no doubt that Apple doesn't really want to implement this, and have tried to find a "non intrusive" way of doing it.

The sad truth is that once lawmakers decide they want access to all data all the time, there's nothing Apple, Google or Microsoft can do to stop that, except going out of business.

That being said, the big players in cloud storage have scanned your files for a decade. Google, Microsoft, Amazon, they all scan files being uploaded. Apple may also be doing this for iCloud Drive.

The only way to circumvent this is to use E2E encryption, either by using a service that has E2E encryption built in, or by "rolling your own", i.e. using Cryptomator. Again, this is just one law away from being outlawed.

The thing that bothers me most is that hashes are somewhat trivial to spoof[1], so if someone was to get a hold of the list of hashes, they could start sending spoof messages on a large scale, causing a false positive.

I remember when Echelon was making the rounds on the internet a couple of decades ago, and lots of people started adding X headers to their emails to cause false positives.

[1] https://towardsdatascience.com/black-box-attacks-on-perceptu...

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#393
post #353

Earlier quoted context omitted.

Does your state not have protections against such actions?

In theory it does. Laws put in place by previous generations do require maintenance to uphold.

They do indeed.
Post reply on HN