Live data from Hacker News

Tell Apple: Don’t Scan Our Phones

act.eff.org

11–20 of 32 posts

Re: Tell Apple: Don’t Scan Our Phones

#11

> Under pressure from U.S. law enforcement, Apple has put a backdoor into their encryption system. I'm not on board with what Apple's doing here, but is there any evidence to suggest this statement? From what I know, this is at best misleading and at worst downright false. For example, the scanning is done on user devices so that image data remains encrypted from the time it leaves a users' phone to the time it is re…

It’s both false and unsubstantiated. As described, it is not a back door, and there is no evidence that it was done under pressure.

Either of them could turn out to be true, given some evidence.

Re: Tell Apple: Don’t Scan Our Phones

#12
post #5

Once Apple releases this 'feature', a law would eventually be passed to force Google to add the same to Android.

Oh don't worry, Google is way ahead of Apple when it comes to scanning users' data on devices. I would be surprised if Google weren't doing this but remotely (vs. on-device).

They are doing this remotely, and the thing is its BETTER to do it remotely than on device.

The issue here with Apple is that they want to move this type of scanning on-device. No one has really complained about them scanning for CSAM on iCloud.

The data is NOT e2ee in iCloud, there is literally no reason for them to move this scanning to on-device.

Re: Tell Apple: Don’t Scan Our Phones

#13
post #10

> Under pressure from U.S. law enforcement, Apple has put a backdoor into their encryption system. I'm not on board with what Apple's doing here, but is there any evidence to suggest this statement? From what I know, this is at best misleading and at worst downright false. For example, the scanning is done on user devices so that image data remains encrypted from the time it leaves a users' phone to the time it is re…

Like, what sort of evidence do you want exactly? Apple can search for arbitrary information on user’s property. If you can search ciphertext, it’s not end to end encrypted anymore. End to end means no knowledge of plaintext should be discernible (sometimes even metadata). Further, the dataset is set by them, is opaque and can be anything. That’s obviously a back door in encryption (for government).

> Apple can search for arbitrary information on user’s property.

This is simply false, if you are referring to the CSAM mechanism.

Re: Tell Apple: Don’t Scan Our Phones

#14
post #8

> Under pressure from U.S. law enforcement, Apple has put a backdoor into their encryption system. I'm not on board with what Apple's doing here, but is there any evidence to suggest this statement? From what I know, this is at best misleading and at worst downright false. For example, the scanning is done on user devices so that image data remains encrypted from the time it leaves a users' phone to the time it is re…

Exactly right, from what you know, which is limited to the point of useless on a proprietary, closed source system. It's almost guaranteed to be backdoored being as such.

> It's almost guaranteed to be backdoored being as such.

I.e. it’s a guess.

Re: Tell Apple: Don’t Scan Our Phones

#15
post #13
post #10

Earlier quoted context omitted.

Like, what sort of evidence do you want exactly? Apple can search for arbitrary information on user’s property. If you can search ciphertext, it’s not end to end encrypted anymore. End to end means no knowledge of plaintext should be discernible (sometimes even metadata). Further, the dataset is set by them, is opaque and can be anything. That’s obviously a back door in encryption (for government).

> Apple can search for arbitrary information on user’s property. This is simply false, if you are referring to the CSAM mechanism.

What do you think is stopping Apple from including a hash of Tank Man along with all of the real CSAM hashes?

Re: Tell Apple: Don’t Scan Our Phones

#16
post #13
post #10

Earlier quoted context omitted.

Like, what sort of evidence do you want exactly? Apple can search for arbitrary information on user’s property. If you can search ciphertext, it’s not end to end encrypted anymore. End to end means no knowledge of plaintext should be discernible (sometimes even metadata). Further, the dataset is set by them, is opaque and can be anything. That’s obviously a back door in encryption (for government).

> Apple can search for arbitrary information on user’s property. This is simply false, if you are referring to the CSAM mechanism.

Which part is false?

They state they begin with image data (with a data set they control). In the future, they “can” evolve the scope to anything.

Read the EFF articles. They are well written.

Re: Tell Apple: Don’t Scan Our Phones

#18
This is not a useful petition. Regardless of the outcome, their nature has been shown once again, but this time it is in a more egregious and nefarious manner, and a lot more people are taking notice.

The reason it's not useful is that it temporarily hides away a side, or an image, that users aren't comfortable with. It will not change intentions and facts, it only exists so that people with brand loyalty and a brand identity can feel better about being tied to an ecosystem.

The problem here is the brand identity, in a truly privacy friendly ecosystem, no such thing should exist. I encourage people to not sign it, and instead reflect on what privacy options do exist without a marketing message telling you what it should be.

Re: Tell Apple: Don’t Scan Our Phones

#19
post #13

Earlier quoted context omitted.

> Apple can search for arbitrary information on user’s property. This is simply false, if you are referring to the CSAM mechanism.

What do you think is stopping Apple from including a hash of Tank Man along with all of the real CSAM hashes?

I guess it is a rhetorical question, but this is what will happen next if Apple doesn't halt this scanning initiative.

Too big to listen seems to be what Apple thinks of this matter.

Re: Tell Apple: Don’t Scan Our Phones

#20
post #12

Earlier quoted context omitted.

Oh don't worry, Google is way ahead of Apple when it comes to scanning users' data on devices. I would be surprised if Google weren't doing this but remotely (vs. on-device).

They are doing this remotely, and the thing is its BETTER to do it remotely than on device. The issue here with Apple is that they want to move this type of scanning on-device. No one has really complained about them scanning for CSAM on iCloud. The data is NOT e2ee in iCloud, there is literally no reason for them to move this scanning to on-device.

It does seem overwhelmingly likely to me that Apple intended to clear a path to E2EE of iCloud Photos with this, however, I'm utterly stumped why they haven't made any announcement nor even suggested it as a motivation. It is clearly their best possible rationale for moving the perceptual hashing from cloud to device, and many people would say, "oh, well, I guess I understand that trade off, then." But without that announcement, this looks pointless on top of invasive. And after more than a week of punishing press, it seems even more unbelievable.
Post reply on HN