Live data from Hacker News

Apple’s device surveillance plan is a threat to user privacy – and press freedom

freedom.press

41–50 of 145 posts

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#41

I agree with the article that not only are implementation problems a potential threat, but it also sets a dangerous precedent. I also understand that Apple is attempting to compromise with governments that are still pressuring it to create an encryption back door or hand over keys (which it did in China by having another company operate iCloud there). Governments have often used the pursuit and prosecution of child a…

The CSAM scanning solution allows law enforcement to do one thing, assuming they have full control over the image hash database: find people who have multiple photos that are already known to law enforcement that they upload to iCloud.

How would you use this to find criminals in general? I have a hard time to think of a very useful example. Maybe photos of bomb plans downloaded somewhere from the internet that are known to be used by criminal groups?

As to what stops a pedophile or a journalist form disabling iCloud photo storage: Absolutely nothing. This solution is supposed catch people storing CSAM photos in iCloud, that's it. A careful pedophile will not be caught by this.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#42
post #32
post #23

Earlier quoted context omitted.

Since it’s speculation at this point, I’d say we deal with it if and when it happens. I also don’t see how this doesn’t apply even worse to doing cloud side scanning, like companies otherwise do. Is that out of control? Is there any evidence of that?

It's worse because the cloud is someone else's computer. When you're in someone else's house, you go by their rules. Your devices, however, are your own house.

So don't use iCloud Photo. The tech literally can't work without the server component.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#43
Fuck the cloud. Offer 256 and 512GB iPhones and up and give a feature set to entirely and permanently disable cloud function. Save that, and I'll throw my iPhone in the God damn trash. I'll use a raspberry Pi or flip phone if I have to do so.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#44
post #38
post #15

Earlier quoted context omitted.

For c) you still need to imagine a scenario where Apple is deliberately complicit, because of the human review step. If non-CSAM hashes are inserted into the database, the human reviewers need to know what non-CSAM they're looking for -- otherwise they'll see the e.g. picture of a leaked document, observe that it's not child porn, and flag it as a false positive.

> you still need to imagine a scenario where Apple is deliberately complicit Which is very easy to imagine. All I have to do is imagine a national security letter.

Isn't that no greater risk than the status quo, though?

Apple already has all these photos uploaded to their servers and knows the keys as iCloud Photos isn't end-to-end encrypted, so if a government can coerce them into cooperating with running scans like that, this new system doesn't seem to make any difference.

(If the argument is that they can be coerced into changing the new system to scan non-uploaded photos and reporting them outside of the iCloud Photos upload process... that's a threat that applies just as much to every phone. It's an argument for not trusting any OS that you didn't compile from source yourself.)

That is to say, it takes this away from the threat the article is presenting as "governments could sneakily use Apple's system to find dissidents despite Apple's best intentions" and into "governments could use the law to make Apple do things".

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#45
post #43

Fuck the cloud. Offer 256 and 512GB iPhones and up and give a feature set to entirely and permanently disable cloud function. Save that, and I'll throw my iPhone in the God damn trash. I'll use a raspberry Pi or flip phone if I have to do so.

You can use an iPhone without ever logging into iCloud. You can even install MDM profiles to prevent it.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#46
post #43

Fuck the cloud. Offer 256 and 512GB iPhones and up and give a feature set to entirely and permanently disable cloud function. Save that, and I'll throw my iPhone in the God damn trash. I'll use a raspberry Pi or flip phone if I have to do so.

Real talk, a Raspberry Pi phone could be amazing. A $150 (or similarly low cost) hackable phone with a near-guaranteed solid community around it - I’d buy that.

One of my big disappointments is that canonical decided to go super-premium with their attempt at phones. I wish Firefox OS had done better (the f0x phone in particular was incredibly cool) but they never managed to get the sort of community traction they needed.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#47
post #31

There’s been such a debate over this now that I don’t know why Apple are still trying? It’s not even their job to catch child porn. There are many far-reaching cooperations like at Interpol and Europol that successfully bust child porn groups? Even anonymizing networks like Tor are not safe havens. These guys don’t have it easy even today. So why is Apple suddenly extremely adamant about this? Would it even cost them…

One possibility is that they'd like to go E2EE with all iCloud data, including photos, and this lets them do that without the politics (DC level) falling out against them.

I doubt it, considering they give up customers' data when the government requests it for 150,000 users/accounts a year[1]. Not only do they choose to give data when requested, they have to comply with court orders, as well.

Also, governments care about much more than just CSAM. They care about terrorism, drug manufacturing, drug and human trafficking, organized crime, gangs, fraud etc.

This speculation only makes sense if Apple intends to use their CSAM detection and reporting system to detect and report on those other things, as well.

Governments won't like that either, because during investigations and discovery, they'll want all of the customer's data that could be evidence of crimes. These detection and reporting systems, as implemented and by themselves, are only useful for flagging suspicious people. They're no good for complying with warrants or subpeonas.

[1] https://www.apple.com/legal/transparency/us.html

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#48
post #24

Earlier quoted context omitted.

Why does anyone even assume that a bad actor would need to apply pressure? These databases are unauditable by design -- all they'd need to do is hand Apple their own database of "CSAM fingerprints collected by our own local law enforcement that are more relevant in this region" (filled with political images of course), and ask Apple to apply their standard CSAM reporting rules. That's it... Tyranny complete.

1) The DB must be updated on both the server and the client. Apple's solution requires the DBs to match, essentially. So you can't update the DB without everyone knowing it was changed. 2) Apple has trillions of dollars to lose by selling out to a shitty change like that. Do those things mean nothing bad can come of it? Hell no. But, right now we have FISA courts and silent warrants sucking in data without anyone kno…

> Apple's approach creates a possibility of slowing down the politics already trying to move against E2EE data.

This is "appeasement" or "Danegeld", and we all know how that works out in the end

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#49
post #4

Of course. Politicians and officials hate whistleblowers far more than pedophiles, and it's obvious this mechanism will be used to find future Chelsea Mannings and Reality Winners with better opsec to make examples out of them.

How?

I'd love to be convinced that this mechanism could be easily extended to any content at any time without it being totally obvious to the rest of us that it's being used that way.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#50
post #32

Earlier quoted context omitted.

It's worse because the cloud is someone else's computer. When you're in someone else's house, you go by their rules. Your devices, however, are your own house.

> the cloud is someone else's computer. So by your logic, if I use a post office box, that means the postal service has the right to open all my packages?

The USPS is restricted by the Constitution and other legislation on what it can do.

From: https://www.uspis.gov/wp-content/uploads/2019/05/USPIS-FAQs....

> 4. Can Postal Inspectors open mail if they feel it may contain something illegal? First-Class letters and parcels are protected against search and seizure under the Fourth Amendment to the Constitution, and, as such, cannot be opened without a search warrant. If there is probable cause to believe the contents of a First-Class letter or parcel violate federal law, Postal Inspectors can obtain a search warrant to open the mail piece. Other classes of mail do not contain private correspondence and therefore may be opened without a warrant.

Companies hosting your data aren't similarly restricted (though if the US government wants access then they'd be restricted by the Constitution and legislation again). A company's ability to look at whatever you give them is only restricted by your contract with them and the technical limitations created by how you share it (upload encrypted files where they don't have the key? they can't really do much). They may have some legal restrictions on some kinds of data, but it's not going to be uniform across the globe so you'll have to take care with which companies you choose to host your unencrypted data.

Post reply on HN