Live data from Hacker News

Apple’s device surveillance plan is a threat to user privacy – and press freedom

freedom.press

31–40 of 145 posts

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#31
There’s been such a debate over this now that I don’t know why Apple are still trying? It’s not even their job to catch child porn. There are many far-reaching cooperations like at Interpol and Europol that successfully bust child porn groups? Even anonymizing networks like Tor are not safe havens. These guys don’t have it easy even today.

So why is Apple suddenly extremely adamant about this? Would it even cost them anything to not go here?

They’re a hardware and services company making mobile and computing devices mostly geared towards entertainment and creative work. How did they end up here?

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#32
post #23

This technology will soon be out of Apple’s control. Higgins correctly highlights the immense pressure Apple will get from governments and other actors to bend the technology and use it for something else than csam. It will happen, people are probably already thinking how to apply such pressure. Sooner or later Apple will cave in and they will have only themselves to blame when freedom supports in Sudan or LGBTQ acti…

Since it’s speculation at this point, I’d say we deal with it if and when it happens. I also don’t see how this doesn’t apply even worse to doing cloud side scanning, like companies otherwise do. Is that out of control? Is there any evidence of that?

It's worse because the cloud is someone else's computer. When you're in someone else's house, you go by their rules.

Your devices, however, are your own house.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#33

This technology will soon be out of Apple’s control. Higgins correctly highlights the immense pressure Apple will get from governments and other actors to bend the technology and use it for something else than csam. It will happen, people are probably already thinking how to apply such pressure. Sooner or later Apple will cave in and they will have only themselves to blame when freedom supports in Sudan or LGBTQ acti…

> Higgins correctly highlights the immense pressure Apple will get from governments and other actors to bend the technology and use it for something else than csam. It will happen, people are probably already thinking how to apply such pressure. Sooner or later Apple will cave in and they will have only themselves to blame when freedom supports in Sudan or LGBTQ activists in Saudi Arabia will be jailed.

I'm having trouble seeing how Apple's actions make this any more or less likely. It's not like matching photos is some esoteric concept that no repressive government has ever thought of before. It's not even like it's particularly hard. Apple's implementation is the most privacy sensitive way of doing it, but if the rules were going to come down they were going to come down, and they'd be implemented in less privacy sensitive ways.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#34
post #15

Earlier quoted context omitted.

For b), I can't see how creating spurious icloud accounts and spoofing it will be hard at it's face. I have made dozens of icloud accounts personally for testing in the past. They may take steps to address this attack vector, it's not an unsolvable problem but it isn't solved by requiring a device or icloud account as far as I can tell. For c), the problem isn't just trusting Apple, for whom the hashes are somewhat o…

For c) you still need to imagine a scenario where Apple is deliberately complicit, because of the human review step. If non-CSAM hashes are inserted into the database, the human reviewers need to know what non-CSAM they're looking for -- otherwise they'll see the e.g. picture of a leaked document, observe that it's not child porn, and flag it as a false positive.

Constantly flagging my account to Apple is an attack of its own. I don't need Apple to be complicit, just make a mistake by erring on the side of caution when reporting.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#35
post #24

This technology will soon be out of Apple’s control. Higgins correctly highlights the immense pressure Apple will get from governments and other actors to bend the technology and use it for something else than csam. It will happen, people are probably already thinking how to apply such pressure. Sooner or later Apple will cave in and they will have only themselves to blame when freedom supports in Sudan or LGBTQ acti…

Why does anyone even assume that a bad actor would need to apply pressure? These databases are unauditable by design -- all they'd need to do is hand Apple their own database of "CSAM fingerprints collected by our own local law enforcement that are more relevant in this region" (filled with political images of course), and ask Apple to apply their standard CSAM reporting rules. That's it... Tyranny complete.

1) The DB must be updated on both the server and the client. Apple's solution requires the DBs to match, essentially. So you can't update the DB without everyone knowing it was changed.

2) Apple has trillions of dollars to lose by selling out to a shitty change like that.

Do those things mean nothing bad can come of it? Hell no. But, right now we have FISA courts and silent warrants sucking in data without anyone knowing or being able to talk about it. It's not like we're a panacea at the moment.

Apple's approach creates a possibility of slowing down the politics already trying to move against E2EE data.

This is a political fight, and if we all act like ideologues we're going to lose it all in the end.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#36

I'd love to be a privacy purist on this, but the fact is that there is not going to be any going back on CSAM content scanning of images in iCloud. So either we take this approach, or end up with a worse one, like pure on-cloud scanning with no transparency whatsoever. I read the technical paper today, and this solution is super clever, well considered, and checks just about every box a crypto-solution-phile would wa…

> Apple's solution on this requires client and server communication to flag an image

Well of course it does, would be a very pointless surveillance system if it scanned for stuff and then threw away the result.

I've also read the technical papers and all other info put out by Apple so far and my takeaway is that the system is generic, it's not designed specifically for images but can be used with any old fingerprint and arbitrary data can be uploaded in the "security vouchers".

It does not take much imagination to see how it could be used to mass-surveil E2EE communications, hook it into Siri's intent system, add a bunch of banned intents and throw the message into the voucher. If a threshold of bad intents is reached a reviewer will check your messages to verify that you actually had some bad intent before dispatching a patrol to your location.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#37
post #31

There’s been such a debate over this now that I don’t know why Apple are still trying? It’s not even their job to catch child porn. There are many far-reaching cooperations like at Interpol and Europol that successfully bust child porn groups? Even anonymizing networks like Tor are not safe havens. These guys don’t have it easy even today. So why is Apple suddenly extremely adamant about this? Would it even cost them…

One possibility is that they'd like to go E2EE with all iCloud data, including photos, and this lets them do that without the politics (DC level) falling out against them.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#38
post #15

Earlier quoted context omitted.

For b), I can't see how creating spurious icloud accounts and spoofing it will be hard at it's face. I have made dozens of icloud accounts personally for testing in the past. They may take steps to address this attack vector, it's not an unsolvable problem but it isn't solved by requiring a device or icloud account as far as I can tell. For c), the problem isn't just trusting Apple, for whom the hashes are somewhat o…

For c) you still need to imagine a scenario where Apple is deliberately complicit, because of the human review step. If non-CSAM hashes are inserted into the database, the human reviewers need to know what non-CSAM they're looking for -- otherwise they'll see the e.g. picture of a leaked document, observe that it's not child porn, and flag it as a false positive.

> you still need to imagine a scenario where Apple is deliberately complicit

Which is very easy to imagine. All I have to do is imagine a national security letter.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#39

I'd love to be a privacy purist on this, but the fact is that there is not going to be any going back on CSAM content scanning of images in iCloud. So either we take this approach, or end up with a worse one, like pure on-cloud scanning with no transparency whatsoever. I read the technical paper today, and this solution is super clever, well considered, and checks just about every box a crypto-solution-phile would wa…

> Apple's solution on this requires client and server communication to flag an image Well of course it does, would be a very pointless surveillance system if it scanned for stuff and then threw away the result. I've also read the technical papers and all other info put out by Apple so far and my takeaway is that the system is generic, it's not designed specifically for images but can be used with any old fingerprint…

Sure, you're totally right.

But right now all that data is available to Apple.

If they wanted to they could just generate a set of keys, replicate one of your iCloud devices, and send all your iMessages to a 3rd party, etc.

If CSAM scanning is coming, show me a better solution. I don't think there's a world ahead of us that doesn't include it for all platform-hosted photos.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#40
post #32
post #23

Earlier quoted context omitted.

Since it’s speculation at this point, I’d say we deal with it if and when it happens. I also don’t see how this doesn’t apply even worse to doing cloud side scanning, like companies otherwise do. Is that out of control? Is there any evidence of that?

It's worse because the cloud is someone else's computer. When you're in someone else's house, you go by their rules. Your devices, however, are your own house.

> the cloud is someone else's computer.

So by your logic, if I use a post office box, that means the postal service has the right to open all my packages?

Post reply on HN