Live data from Hacker News

Ask HN: What Apple alternatives are you switching to?

news.ycombinator.com

361–370 of 493 posts

Re: Ask HN: What Apple alternatives are you switching to?

#361
post #216

Earlier quoted context omitted.

Of the two, which government do I think is more evil? China's. Which government do I, a permanent resident of America, think could more immediately make my life harder by being able to invade my privacy? America's.

Well, as somebody who has travel to China for business, I would not touch any Chinese hardware or OS at all. In the US and EU you have a working legal system.

As I said, I am not such a person. Most of the English-speaking world consists of the same.

As I said - I agree that China's government is worse. In fact my previous employer had a policy that company devices just didn't cross that border, even when traveling for work. But it's still not a factor in which devices I purchase myself.

Re: Ask HN: What Apple alternatives are you switching to?

#362

Earlier quoted context omitted.

Apple hashes all of your photos offline and then pinky promises to only check the hashes against the official on phone database when the user initiated an upload. The problem isn’t about wackos it’s about governments forcing Apple to do things with this new weapon

Every other cloud storage provider has implemented scanning since 2011-2013.

https://en.m.wikipedia.org/wiki/Whataboutism

Re: Ask HN: What Apple alternatives are you switching to?

#363

To be honest... None. It's a choice. You might wholly disagree, but recent events aren't enough to get me to switch yet, because I think the competition has too many tradeoffs. I can get my photos scanned against a CSAM database... or I can have Google tracking my location constantly regardless of what they say (as they've been proven to be misleading in the past)... or I can use a Linux phone and say goodbye to batt…

It's only a matter of time before Google starts doing the same thing. I can't imagine Google wont do it eventually.

Or does it already and didn't feel the need to make a press release.

Re: Ask HN: What Apple alternatives are you switching to?

#365

Earlier quoted context omitted.

Even if we were to call this a "backdoor", it's a backdoor that creaks quite loudly. I mean, what's the attack vector here? The plan, as far as I'm aware, is to upload a list of hashes to each device that have been vetted by multiple child protection agencies. In order to surveil other things, additional hashes would need to be transferred that wouldn't be vetted by these agencies. That would be noticed, and that's t…

>I mean, what's the attack vector here? The plan, as far as I'm aware, is to upload a list of hashes to each device that have been vetted by multiple child protection agencies. I hope not. If hashes are uploaded to devices, they can be extracted and images that clash against it can be created. I think they're going to be creating hashes of images locally that are being uploaded and send it with the image. Then if the…

> If hashes are uploaded to devices, they can be extracted and images that clash against it can be created.

Many organizations have the hashes, so they could leak nonetheless. Either way, I don't think that's a major problem. If the system interprets a picture of a pineapple as CSAM, you only need to produce the picture of a pineapple to defend yourself against any accusations. If clashes are too commonplace, the entire system would become unreliable and would have to be scrapped.

In any case, I have looked it up. The database is indeed on the device, but it's encrypted:

https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

> Instead of scanning images in the cloud, the system performs on-device matching using a database of known CSAM image hashes provided by NCMEC and other child-safety organizations. Apple further transforms this database into an unreadable set of hashes, which is securely stored on users’ devices.

Overall, after reading the PDF, here is my understanding of the process:

1. Apple gathers a set of "bad hashes"

2. They upload to each device a map from a hashed bad hash to an encrypted bad hash

3. The device runs an algorithm that determines whether there are matches with hashed bad hashes

4. For each match, the device uploads a payload encrypted using a secret on-device key, and a second payload that contains a "share" of the secret key, encrypted using the neural hash and encrypted bad hash.

5. The device also periodically uploads fake shares with dummy data to obfuscate the number of matches that actually occurred. Apple can't tell fake shares from real ones unless they have enough real shares.

6. Once Apple has enough real shares, they can figure out the secret key and know which hashes caused a match.

The main concern I have, and as a non-expert, is step 2: it requires Apple to provide their key to an auditor who can cross-check with child protection agencies that everything checks out and no suspect hashes are included in the payload. In theory, that needs to be done every time a new on-device database is uploaded, but if it is done, or if child protection agencies are given the secret so that they can check it themselves, I think this is a fairly solid system (notwithstanding the specifics of the encryption scheme which I don't have the competence to evaluate).

The thresholding is also a reassuring aspect of the system, because (if it works as stated) the device can guarantee that Apple can't see anything at all until a certain number of images match, not even the count of matching images. The threshold could only be changed with an OS update.

There's certainly a lot of things to discuss and criticize about their system, but it's going to be difficult to do so if nearly no one even bothers reading about how it works. It's frustrating.

Re: Ask HN: What Apple alternatives are you switching to?

#366
post #248

Earlier quoted context omitted.

I find it funny how many people pick a random Chinese phone in their bid for privacy (???)

That would be... literally all phones available today, wouldn't it? With the possible exception of the $2000 Librem 5 USA. However, as one who's moved from an iPhone to a Nokia 8110 with KaiOS, which I in no way argue is as secure as iOS: It has less on it. It has far less on it. It has my phone calls, a handful of text messages, and while it has email access right now, I'm experimenting with if I actually need that,…

Japan, Thailand, and Vietnam manufacture a lot of phones.

Re: Ask HN: What Apple alternatives are you switching to?

#367

Earlier quoted context omitted.

The actual problem is not CSAM scanning. The actual problem is that they've created a great surveillance tool which will inevitably get broader capabilities and they are normalising client-side data scanning (we need to eradicate terrorism, now we need to eradicate human trafficking, and now we need to eradicate tax evasion, oh, we forgot about gay russians, hmm, what about Winnie memes?).

But this was already true. There is no reason the governments couldn't have required this tool to be built at anytime all along. Remember EARN IT where Senators said figure something out (like this CSAM tool) or they'll do it for Apple? The EU is similar, with upcoming draft legislation saying they have to do it if they don't figure something (like this) out.

Back during the FBI/Apple fiasco where the government was lobbying Apple to install a backdoor to unlock phones, Apple argued that their 1st Amendment Rights were being violated, that the government could not force them to write software (since software is speech, and the government cannot force you to say something against your will)

One random article of many: https://money.cnn.com/2016/02/25/technology/apple-fbi-respon...

Edit: but through regulations they could probably say 'you're not allowed to sell phones without x backdoor' but maybe the government didn't want to spell out specifically what capabilities are required.

Re: Ask HN: What Apple alternatives are you switching to?

#368
post #352
post #340

Earlier quoted context omitted.

That's not what was being argued, but you made an excellent point.

What was being argued was exactly this.

I know what I was arguing, and it was specifically mentioned, so no it was not what was being argued.

Re: Ask HN: What Apple alternatives are you switching to?

#369

Earlier quoted context omitted.

I use Bitwig Studio. It has that polished feel of Jetbrains products and has very good MIDI production tools among other things. Of course the downside it's not free and rather expensive, but it's linux native. All the VSTs that I need work through wine/yabridge flawlessly - Ample Guitars, Pianoteq. Even the crappy Kontakt works, but I don't use it much. Backend audio server is JACK2 with Pulseaudio sink. Ardour is p…

Great info. Surprised to hear Wine gets the job done for some of that stuff. Thankyou. :)

I was just as surprised. Not only it works, there are no performance issues like audio cracks and stuff like that. It's awesome.
Post reply on HN