This article is full of inaccuracies. a) People have extracted a pre-release version from an older iOS phone. It is not the one that will be released and not the same one Apple uses server-side to verify the process. b) Adversaries can not reasonably break this process by flooding it with bad data across a range of compromised phones. The client side version is there to prevent this as is the fact it would require ja…
Apple’s device surveillance plan is a threat to user privacy – and press freedom
11–20 of 145 posts
Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom
#12Apple’s new image scanning technology is almost as much of a backdoor to individuals' privacy as handing out their device decryption keys on demand. Except with this new tech, finding criminal activity is even easier for law enforcement, as Apple will attempt to locate criminals for them.
That said, there are better privacy tools available for those that need as much privacy as possible, but they are nowhere near as user-friendly as Apple's devices. For instance, if this new search tool only searches images uploaded to iCloud, as claimed, what stops a pedophile or a journalist from disabling iCloud photo storage and synchronizing photos manually? It is extra work, but not difficult. Keeping average everyday things and activities, such as web browsing history, mostly private requires more effort and expertise than manually copying photos between a phone and a computer.
Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom
#13There is an easy way to cast your vote for saying yes to Privacy. Turn off auto-updates and don't update to iOS 15. Spread the word.
Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom
#14> an adversary could trick Apple’s algorithm into erroneously matching an existing image
In which case the malicious, adversary-controlled images are sent to Apple. After which—the implication is—they can be re-obtained by... the adversary that created them. So what?
An adversary could conceivably lower the reporting threshold by getting the victim to save a bunch of false-positive images. Again, so what? Surely if the adversary has reason to believe there are some number of CSAM images on a user's phone, there are more direct ways of going after them.
> These kinds of false positives could happen if the matching database has been tampered with or expanded to include images that do not depict child abuse
An adversary would either have to:
A) carry out a supply-chain attack on Apple, B) ship different iOS images in different countries, or C) insert entries into the database on a specific users phone.
Options A and C are irrelevant: if the phone is compromised, the CSAM database being modified is the least of your concerns. And option B is independently verifiable (granted, Apple does not do enough to make third-party auditing of iOS easy, but it is possible).
Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom
#15This article is full of inaccuracies. a) People have extracted a pre-release version from an older iOS phone. It is not the one that will be released and not the same one Apple uses server-side to verify the process. b) Adversaries can not reasonably break this process by flooding it with bad data across a range of compromised phones. The client side version is there to prevent this as is the fact it would require ja…
For b), I can't see how creating spurious icloud accounts and spoofing it will be hard at it's face. I have made dozens of icloud accounts personally for testing in the past. They may take steps to address this attack vector, it's not an unsolvable problem but it isn't solved by requiring a device or icloud account as far as I can tell. For c), the problem isn't just trusting Apple, for whom the hashes are somewhat o…
Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom
#16There business model has always been a threat to user privacy and press freedom, many people were just okay with it cause Apple told them otherwise. Open source is the only model where you can verify though, and so Apple was about blind trust and never about privacy.
Why is this being downvoted? Depressing to see that open source software is not respected here.
Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom
#17While the precedent this sets is indeed concerning, the specific hypotheticals this article give are nonsensical. > an adversary could trick Apple’s algorithm into erroneously matching an existing image In which case the malicious, adversary-controlled images are sent to Apple. After which—the implication is—they can be re-obtained by... the adversary that created them. So what? An adversary could conceivably lower t…
More importantly, they'd need to suborn Apple's human-review process, because the people doing the review would need to know what not-CSAM they're looking for.
Could Apple be coerced into (or willingly) do this? I have no idea. But it's a very different threat-model than the article suggests, that boils down to the "do you trust your OS vendor?" question.
Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom
#18Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom
#19Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom
#20So either we take this approach, or end up with a worse one, like pure on-cloud scanning with no transparency whatsoever.
I read the technical paper today, and this solution is super clever, well considered, and checks just about every box a crypto-solution-phile would want. I don't know how it gets better than this. (Technical note: Apple's solution on this requires client and server communication to flag an image, which is part of the reason it's totally off if you turn off iCloud Photo).
If this opens the door to Apple offering E2EE on all photos in iCloud (which it could), then this ends up being a big win over the status quo, in my opinion. And even if not, there are far, far worse alternatives.
[Edited for spelling].