Live data from Hacker News

Apple urged to drop plans to scan iMessages, images for sex abuse

aljazeera.com

31–40 of 129 posts

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#31

So, what parts of my phone are actually being scanned by this system? It seems like it's rummaging through any images that are touch iCloud, which would include: - iMessage - WhatsApp - Camera - Matrix (?) - Any other application that you give 'photo' permission to?

As far as I know, it’s only iCloud Photos.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#32
post #10

I want to ignore most of this article to complain about an inaccuracy that keeps coming up. > More broadly, they said the change will break end-to-end encryption for iMessage, which Apple has staunchly defended in other contexts. But... it wouldn't. The iMessage feature doesn't expose the contents of your message to anyone else under any circumstance. If you're a child under 13 and your parents have opted in to this…

> But... it wouldn't. The iMessage feature doesn't expose the contents of your message to anyone else under any circumstance. It does if it contains the flagged content. When we say end-to-end, we mean that even Apple cannot know what is on the wire which won't be the case anymore.

No it doesn't. You're thinking about the iCloud Photo Library reporting. The Messages feature literally never sends any of your content to anyone, no matter how much CSAM you're sent.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#33
post #26

Earlier quoted context omitted.

Apple's investigation code executes on the device, which allows them to preserve their definition of end-to-end as long as you plug your ears and ignore where the 'ends' are.

I’m not interested in Apple’s newspeak definition of “E2EE” (where they are between the ends) or “Privacy” (terms and restrictions may apply). I want the real thing.

In this case, they wouldn't be "between" the ends, no? They'd be _at_ the ends, just as sending a message on Signal doesn't prevent someone from stealing your phone and reading your messages.

I'm not in agreement with this being ok, but if it truly is on device, it still technically can be E2EE

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#34
post #9

After seeing all these posts here and not hearing much about it outside of this space I’m starting to think that the cost benefit analysis that Apple did was that the profit from very likely convincing parents to spend a little more to get their children an iPhone as their first phone (and probably lock those children into their ecosystem) because of these features was greater than the amount of users who would switc…

I'm not sure we have an understanding of Apple's intentions. Given the massive backlash and the apparent maturity of their plans this must have been in the works for a while. They may have been under pressure from government actors to develop a program. Or they might see writing on the wall. Either way, I doubt they will ever share the total picture behind this move.

The leak of the email describing people with concerns as "screeching" didnt help.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#35
post #17

Is aljazeera.com the only outlet willing to cover this aspect of Apple's decision? It seems like the US media is effectively ignoring the complaints.

NY Times had an article covering it yesterday - https://www.nytimes.com/2021/08/18/technology/apple-child-ab...

The article seems to cover both sides of the argument fairly and nails the concerns over Apple's on-device scanning:

> If governments had previously asked Apple to analyze people’s photos, the company could have responded that it couldn’t. Now that it has built a system that can, Apple must argue that it won’t.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#36
post #17

Is aljazeera.com the only outlet willing to cover this aspect of Apple's decision? It seems like the US media is effectively ignoring the complaints.

it was on CNN's homepage yesterday...

https://www.cnn.com/2021/08/17/tech/apple-child-safety-tools...

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#37

Im not sure if im missing something here, but from what I understand, what Apple is proposing is an enormous privacy boon that seems to be completely misunderstood. All cloud providers are required to, and do, make these scans. The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, excep…

Cloud providers are not required to scan for this content.

They are, however, required to disclose it if they find it.

That said, many cloud providers do in fact scan for this content. Apple was the odd one out.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#38

Im not sure if im missing something here, but from what I understand, what Apple is proposing is an enormous privacy boon that seems to be completely misunderstood. All cloud providers are required to, and do, make these scans. The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, excep…

They could comply with a nation state's demands to scan a billion iPhones for a politically dangerous photo.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#39
post #26

Earlier quoted context omitted.

Apple's investigation code executes on the device, which allows them to preserve their definition of end-to-end as long as you plug your ears and ignore where the 'ends' are.

I’m not interested in Apple’s newspeak definition of “E2EE” (where they are between the ends) or “Privacy” (terms and restrictions may apply). I want the real thing.

> I want the real thing.

If you used iOS/iMessage, you have always trusted Apple. To be truly 'end to end' you would assume that there's no opportunity for another party to intercept your messages: the only trust would be in the keys you exchanged with your peer.

1. They are a trusted broker for iMessage key exchanges. You didn't do the key exchange, you assumed that when Apple did so on your behalf that you're really communicating with the peer you think you are.

2. They designed the iOS features that you trust keep iMessage data inaccessible to other untrusted software on your device.

3. They designed the secure enclave and make public statements that they won't compromise it for law enforcement. You trust that their deeds in private match their public statements.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#40
Is there a possibility that this could be some kind of Dual_EC type of backdoor they are trying to insert under the guise of something "positive" -- i.e. CSAM? As others have said elsewhere, it seems so out of the blue like they were pressured from somewhere, which I guess I default to assuming government. After reading "The Hacker and the State" by Ben Buchanan, it made me even more aware of how much depth and penetration there is of the private-government partnership in the US.
Post reply on HN