Live data from Hacker News

Apple’s device surveillance plan is a threat to user privacy – and press freedom

freedom.press

11–20 of 145 posts

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#11

This article is full of inaccuracies. a) People have extracted a pre-release version from an older iOS phone. It is not the one that will be released and not the same one Apple uses server-side to verify the process. b) Adversaries can not reasonably break this process by flooding it with bad data across a range of compromised phones. The client side version is there to prevent this as is the fact it would require ja…

Putting some extra hashes into a database - especially one tucked away in a corner of the product - is a lot easier than compromising kernel code or a driver. And in this case the database is not exclusively the work of Apple, so third parties have the ability to insert hashes.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#12
I agree with the article that not only are implementation problems a potential threat, but it also sets a dangerous precedent. I also understand that Apple is attempting to compromise with governments that are still pressuring it to create an encryption back door or hand over keys (which it did in China by having another company operate iCloud there). Governments have often used the pursuit and prosecution of child abusers and terrorists as a scapegoat for eroding privacy for all its citizens. Privacy and liberty versus the lawful pursuit of criminals are challenging problems to balance, especially when governments and law enforcement want a free pass searching for whatever content they deem illegal. Governments decide what photos, communications, and even thoughts (if they could) are legal and which one are illegal. Who knows what some (new) governments may decree new obscenity laws? They could legislate that some pictures once considered lawful and innocent are now unlawful and obscene, retroactively, and ask or attempt to force Apple to search for those newly criminal images.

Apple’s new image scanning technology is almost as much of a backdoor to individuals' privacy as handing out their device decryption keys on demand. Except with this new tech, finding criminal activity is even easier for law enforcement, as Apple will attempt to locate criminals for them.

That said, there are better privacy tools available for those that need as much privacy as possible, but they are nowhere near as user-friendly as Apple's devices. For instance, if this new search tool only searches images uploaded to iCloud, as claimed, what stops a pedophile or a journalist from disabling iCloud photo storage and synchronizing photos manually? It is extra work, but not difficult. Keeping average everyday things and activities, such as web browsing history, mostly private requires more effort and expertise than manually copying photos between a phone and a computer.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#13

There is an easy way to cast your vote for saying yes to Privacy. Turn off auto-updates and don't update to iOS 15. Spread the word.

This is not guaranteed to work. At some point Apple might show you an update dialog, and you might click "yes" by mistake.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#14
While the precedent this sets is indeed concerning, the specific hypotheticals this article give are nonsensical.

> an adversary could trick Apple’s algorithm into erroneously matching an existing image

In which case the malicious, adversary-controlled images are sent to Apple. After which—the implication is—they can be re-obtained by... the adversary that created them. So what?

An adversary could conceivably lower the reporting threshold by getting the victim to save a bunch of false-positive images. Again, so what? Surely if the adversary has reason to believe there are some number of CSAM images on a user's phone, there are more direct ways of going after them.

> These kinds of false positives could happen if the matching database has been tampered with or expanded to include images that do not depict child abuse

An adversary would either have to:

A) carry out a supply-chain attack on Apple, B) ship different iOS images in different countries, or C) insert entries into the database on a specific users phone.

Options A and C are irrelevant: if the phone is compromised, the CSAM database being modified is the least of your concerns. And option B is independently verifiable (granted, Apple does not do enough to make third-party auditing of iOS easy, but it is possible).

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#15

This article is full of inaccuracies. a) People have extracted a pre-release version from an older iOS phone. It is not the one that will be released and not the same one Apple uses server-side to verify the process. b) Adversaries can not reasonably break this process by flooding it with bad data across a range of compromised phones. The client side version is there to prevent this as is the fact it would require ja…

For b), I can't see how creating spurious icloud accounts and spoofing it will be hard at it's face. I have made dozens of icloud accounts personally for testing in the past. They may take steps to address this attack vector, it's not an unsolvable problem but it isn't solved by requiring a device or icloud account as far as I can tell. For c), the problem isn't just trusting Apple, for whom the hashes are somewhat o…

For c) you still need to imagine a scenario where Apple is deliberately complicit, because of the human review step. If non-CSAM hashes are inserted into the database, the human reviewers need to know what non-CSAM they're looking for -- otherwise they'll see the e.g. picture of a leaked document, observe that it's not child porn, and flag it as a false positive.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#16
post #7

There business model has always been a threat to user privacy and press freedom, many people were just okay with it cause Apple told them otherwise. Open source is the only model where you can verify though, and so Apple was about blind trust and never about privacy.

Why is this being downvoted? Depressing to see that open source software is not respected here.

People downvote things that make them angry. The things that make people most angry are those things that strike closest to home. An incorrect or unacceptable comment will be downvoted and commented on, even reported. A perfectly valid and true statement, one that is so true that it scares people, will be silently downvoted. It is a form of denial, an attempt to remove a painful truth.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#17

While the precedent this sets is indeed concerning, the specific hypotheticals this article give are nonsensical. > an adversary could trick Apple’s algorithm into erroneously matching an existing image In which case the malicious, adversary-controlled images are sent to Apple. After which—the implication is—they can be re-obtained by... the adversary that created them. So what? An adversary could conceivably lower t…

> An adversary would either have to:

More importantly, they'd need to suborn Apple's human-review process, because the people doing the review would need to know what not-CSAM they're looking for.

Could Apple be coerced into (or willingly) do this? I have no idea. But it's a very different threat-model than the article suggests, that boils down to the "do you trust your OS vendor?" question.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#19
This technology will soon be out of Apple’s control. Higgins correctly highlights the immense pressure Apple will get from governments and other actors to bend the technology and use it for something else than csam. It will happen, people are probably already thinking how to apply such pressure. Sooner or later Apple will cave in and they will have only themselves to blame when freedom supports in Sudan or LGBTQ activists in Saudi Arabia will be jailed. The issue here is not where to draw the line, but who will draw it (spoiler: not Apple).

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#20
I'd love to be a privacy purist on this, but the fact is that there is not going to be any going back on CSAM content scanning of images in iCloud.

So either we take this approach, or end up with a worse one, like pure on-cloud scanning with no transparency whatsoever.

I read the technical paper today, and this solution is super clever, well considered, and checks just about every box a crypto-solution-phile would want. I don't know how it gets better than this. (Technical note: Apple's solution on this requires client and server communication to flag an image, which is part of the reason it's totally off if you turn off iCloud Photo).

If this opens the door to Apple offering E2EE on all photos in iCloud (which it could), then this ends up being a big win over the status quo, in my opinion. And even if not, there are far, far worse alternatives.

[Edited for spelling].

Post reply on HN