Live data from Hacker News

Apple’s device surveillance plan is a threat to user privacy – and press freedom

freedom.press

81–90 of 145 posts

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#81
post #26

Earlier quoted context omitted.

Presumably, there will be a parallel track to stay on iOS 14 with security updates, at least for some time.

This tech is in iOS since 14.3

The neuralHash part, not the whole CSAM scanning daemon/pipeline, right?

Security updates to iOS 14 will let people (who might not be ready/able to switch from iOS) to actually do what GP said, without unnecessarily exposing themselves to security bugs in outdated OS.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#82
post #24

Earlier quoted context omitted.

Why does anyone even assume that a bad actor would need to apply pressure? These databases are unauditable by design -- all they'd need to do is hand Apple their own database of "CSAM fingerprints collected by our own local law enforcement that are more relevant in this region" (filled with political images of course), and ask Apple to apply their standard CSAM reporting rules. That's it... Tyranny complete.

1) The DB must be updated on both the server and the client. Apple's solution requires the DBs to match, essentially. So you can't update the DB without everyone knowing it was changed. 2) Apple has trillions of dollars to lose by selling out to a shitty change like that. Do those things mean nothing bad can come of it? Hell no. But, right now we have FISA courts and silent warrants sucking in data without anyone kno…

> 2) Apple has trillions of dollars to lose by selling out to a shitty change like that.

Apple has trillions to lose by building this system in the first place. All it takes is one court order to do non-CP scanning with the existing system.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#83
post #68

Earlier quoted context omitted.

Apple does not need to be able to audit the database to discover that it is not a CSAM database. Matches are reviewed by Apple before being reported to the authorities, so they would see that they are getting matches on non-CSAM material. They wouldn't necessarily be able to tell if it was a false positive matching real CSAM material or a true positive matching illegitimate material in the databases put there by a go…

That's even worse - so now apple is deciding whether to report something even if it matches the data provided by the government. It's not their role to judge the contents, only whether the match is correct or not, otherwise even with actual CSAM content, are they going to be making judgement calls? What if the system matches loli content which I imagine is in that database but legal in places? Are they going to then…

> It's not their role to judge the contents, only whether the match is correct or not.

Which is what they would be doing.

Some government gives Apple a purported CSAM hash database, which Apple only accepts because it is a CSAM database. An image gets a match. Apple looks at it and it is not CSAM. Therefore, unless the government lied to them about the database, it must be a false positive and gets rejected as an incorrect match.

The rejection is not because Apple judged the content per se. They just determined that it must be a false positive given the government's claims about the database.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#84

This technology will soon be out of Apple’s control. Higgins correctly highlights the immense pressure Apple will get from governments and other actors to bend the technology and use it for something else than csam. It will happen, people are probably already thinking how to apply such pressure. Sooner or later Apple will cave in and they will have only themselves to blame when freedom supports in Sudan or LGBTQ acti…

> Higgins correctly highlights the immense pressure Apple will get from governments and other actors to bend the technology and use it for something else than csam. It will happen, people are probably already thinking how to apply such pressure. Sooner or later Apple will cave in and they will have only themselves to blame when freedom supports in Sudan or LGBTQ activists in Saudi Arabia will be jailed. I'm having tr…

If Sudan or Saudi Arabia wants to arrest people, there are much easier ways. What “freedom” or “LGBTQ” photos would you even search for?

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#85

I'd love to be a privacy purist on this, but the fact is that there is not going to be any going back on CSAM content scanning of images in iCloud. So either we take this approach, or end up with a worse one, like pure on-cloud scanning with no transparency whatsoever. I read the technical paper today, and this solution is super clever, well considered, and checks just about every box a crypto-solution-phile would wa…

So either we take this approach, or end up with a worse one, like pure on-cloud scanning with no transparency whatsoever. With cloud computing, I can choose my cloud provider and I can upload encrypted files. On device scanning is evil because it's move to create a computing architecture entirely outside the user's control.

This is disabled if you choose to not use iCloud.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#86

While the precedent this sets is indeed concerning, the specific hypotheticals this article give are nonsensical. > an adversary could trick Apple’s algorithm into erroneously matching an existing image In which case the malicious, adversary-controlled images are sent to Apple. After which—the implication is—they can be re-obtained by... the adversary that created them. So what? An adversary could conceivably lower t…

> an adversary could trick Apple’s algorithm into erroneously matching an existing image This is a very real, possible attack. Apple ships its CSAM model on device so any attacker can have a copy of the model. Then the attacker creates an image that triggers CSAM but looks like a panda [1]. Now the attacker sends tons of triggering photos to the unsuspecting victim, who now gets questioned by the FBI. 1: https://medi…

So the attacker creates an image then the user has to download it. Then the FBI digs in and see it was a crafted false positive, then begin to investigate who sent it and why. Then the user takes civil action against the person who sent it for harassment.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#87

Earlier quoted context omitted.

Presumably, there will be a parallel track to stay on iOS 14 with security updates, at least for some time.

If enough people do that, then no reason that they won't just enable it in 14 too.

Assuming that I was not gaslit by other people, I was under impression that would at least require some change to EULA.

Otherwise it sounds like a nuclear option by Apple, with dire effects.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#88
post #51

Earlier quoted context omitted.

For b), I can't see how creating spurious icloud accounts and spoofing it will be hard at it's face. I have made dozens of icloud accounts personally for testing in the past. They may take steps to address this attack vector, it's not an unsolvable problem but it isn't solved by requiring a device or icloud account as far as I can tell. For c), the problem isn't just trusting Apple, for whom the hashes are somewhat o…

I'm not arguing that these aren't real problems, but neither are unique problems of the the client side scanning solution. It's the same or maybe even worse with server side scanning. I'd assume FB, Google & co have some solution to b), so Apple should be able to figure out something. For c), at least Apple takes extra precautions by requiring the photos to be in two separate database provided by different government…

Yeah I agree that B is likely a non issue, at least not an issue that affects the users directly. But C doesn't make me feel any better because the fundamental issue is where the scanning happens. If it happens off my device it cannot happen to photos I don't send off my device. I understand they have policy governing this, but that's not addressing the core conceptual problem of crossing the network boundary onto what I pretend is "my" device.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#89
post #57

Earlier quoted context omitted.

Apple can’t be selling out if they literally have no way of knowing what is in the database of illicit content. That is why they said that the content has to be in two separate nation’s databases. Of course, there is no information that I’ve seen about what other nation’s db they would use. And without another nation, there will be no content in the database? I doubt it. Regardless, it’s a moot issue, since we alread…

Five eyes already does whatever the heck they want, and this isn’t going to change that.

It very well may change it.

Right now they have no ability to scan every photo on every iOS device for “objectionable” content (as defined by them on that day, based on their mood). But soon they will. All they have to do is add photos to the ncemc and an equivalent db in another country.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#90

This technology will soon be out of Apple’s control. Higgins correctly highlights the immense pressure Apple will get from governments and other actors to bend the technology and use it for something else than csam. It will happen, people are probably already thinking how to apply such pressure. Sooner or later Apple will cave in and they will have only themselves to blame when freedom supports in Sudan or LGBTQ acti…

Exactly. Governments tend to accept "we lack the technical capability to comply with your request" (unless said capability is legally mandated, e.g. so-called "lawful intercept"). They do not tend to accept "we possess the technical capability to comply with your request but choose not to do so".

[deleted]
Post reply on HN