Earlier quoted context omitted.
I’m not interested in Apple’s newspeak definition of “E2EE” (where they are between the ends) or “Privacy” (terms and restrictions may apply). I want the real thing.
> I want the real thing. If you used iOS/iMessage, you have always trusted Apple. To be truly 'end to end' you would assume that there's no opportunity for another party to intercept your messages: the only trust would be in the keys you exchanged with your peer. 1. They are a trusted broker for iMessage key exchanges. You didn't do the key exchange, you assumed that when Apple did so on your behalf that you're reall…
Apple urged to drop plans to scan iMessages, images for sex abuse
71–80 of 129 posts
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#72Earlier quoted context omitted.
Let's also not pretend that some of this confusion done is 100% willfully by some of the news organizations reporting on this because it benefits them to conflate the two. We even see it a little from places like EFF who appear to believe their ends justify the means.
The more fear and confusion the EFF can spread, the more donations they get.
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#73Earlier quoted context omitted.
If a copy of your messages (even if it is only low resolution jpgs) get auto forwarded to Apple/FBI under certain circumstances it is not securely E2E encrypted
It’s not forwarded to Apple/FBI though, under any circumstances.
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#74Earlier quoted context omitted.
> I want true end to end enc. People who say things like this rarely also want the hassle that comes with it. Key exchanges, re-keying: all a big PITA. But iMessage (and WhatsApp) do key exchanges facilitated by a trusted broker. If you didn't trust the broker, you would have to do more work when making an initial exchange with a peer and more work if they lost their phone/keys. iMessage has always been a compromise…
Key exchange would be easy in real life, just bump phones when you meet someone. It's only difficult on IRC.
We are over a year into a pandemic which involved wide-scale lockdowns. Physical key exchange is a nonstarter for broad adoption.
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#75Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#76Earlier quoted context omitted.
How is it not still E2EE?
If a copy of your messages (even if it is only low resolution jpgs) get auto forwarded to Apple/FBI under certain circumstances it is not securely E2E encrypted
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#77Earlier quoted context omitted.
Apple can already decrypt your iCloud photos, same with google etc. I don’t get this argument as they can already do that.
iCloud != iMessage
Y'all are starting to make me more sympathetic to Apple. Their biggest misstep was making these announcements simultaneously without foreseeing how many people would (willingly or otherwise) conflate them.
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#78Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#79Earlier quoted context omitted.
I'm not sure we have an understanding of Apple's intentions. Given the massive backlash and the apparent maturity of their plans this must have been in the works for a while. They may have been under pressure from government actors to develop a program. Or they might see writing on the wall. Either way, I doubt they will ever share the total picture behind this move.
The leak of the email describing people with concerns as "screeching" didnt help.
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#80Im not sure if im missing something here, but from what I understand, what Apple is proposing is an enormous privacy boon that seems to be completely misunderstood. All cloud providers are required to, and do, make these scans. The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, excep…
> The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, except in this specific case, secured and controlled by your device. If the CSAM detection were released with encrypted iCloud backups (or generally E2EE iCloud), then I think I'd probably be entirely less outraged. This narrative…