Live data from Hacker News

Apple urged to drop plans to scan iMessages, images for sex abuse

aljazeera.com

111–120 of 129 posts

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#111

Im not sure if im missing something here, but from what I understand, what Apple is proposing is an enormous privacy boon that seems to be completely misunderstood. All cloud providers are required to, and do, make these scans. The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, excep…

> All cloud providers are required to, and do, make these scans.

No scanning is required by law. In fact, the law states you don't have to go out of your way to invade privacy to scan. So yes, you and tons of other people are missing a big piece in this.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#112

Earlier quoted context omitted.

I agree, sadly. This prompted me to unsubscribe from them. In some ways it reminds me of the ACLU. Similar fixation on donations above all else, to the point of dark patterns. I still haven't managed to fully extricate myself from their pleas.

I’m in the same boat. Unfortunately, I don’t see myself continuing to donate to them, given the terrible job they’ve done on this topic. I trusted them to bring nuance and clarity —- really liked what they did in response to the cash bail discussion in California —- but this was too much of a miss for me. I’m still a fan of the ACLU, even with their spotty record on gay rights, but it might just be a matter of time.

I generally support the ACLU mission, but they have antagonized me ever since I started a recurring donation a few years ago. For reasons, I decided to stop the recurring donation, but ACLU is just like the NY Times and many other places -- easy to sign up, damn near impossible to get them to stop. E-mails, phone calls, nothing. Ultimately I just declared the card stolen and had it reissued with a new number.

On top of that, at some point they must have asked if it was okay to contact me, and I must have inadvertently said yes, and now I get regular text messages from random people across the country asking if I will help out. About half the time it's for something in a state (like Georgia during the election) which is several thousand miles from where I live. No amount of begging has gotten this flow of unsolicited text messages to stop.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#113

Pretty clear cut for me: iMessage either offers robust end-to-end encryption , or it doesn’t. (Intentional backdoors place it in the latter ofcourse). I want true end to end enc.

> I want true end to end enc. People who say things like this rarely also want the hassle that comes with it. Key exchanges, re-keying: all a big PITA. But iMessage (and WhatsApp) do key exchanges facilitated by a trusted broker. If you didn't trust the broker, you would have to do more work when making an initial exchange with a peer and more work if they lost their phone/keys. iMessage has always been a compromise…

The thinking that key exchange need to be robust and P2P makes alternative secure solutions harder: most of the times big companies don't want to be caught doin a man-in-the middle attack, so iMessage or even Facebook is practical enough for it, as long as the key exchange can be verified on any other comunications channel easily.

We would be in a much better position right now with email privacy if the version of PGP that doesn't defend from an active attack would have been deployed worldwide.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#114
post #75

Earlier quoted context omitted.

I don't think it reports those links back to big brother though. Keen difference.

I doesn't do that with sexually explicit images on iMessage either.

The rest of the csam monitoring does. And nice that you abuse your karma to downvote people who don't agree with you.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#115

Earlier quoted context omitted.

iMessage already analyzes your messages to preview urls, show YouTube videos, highlight dates, etc. Are those also backdoors?

How do they manage the previews? Skype, for one, uses their servers to get the preview. Vastly different from a client-side preview (which some people wouldn't want either).

iMessage link preview images are generated by the sender.

https://developer.apple.com/library/archive/technotes/tn2444...

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#116

Earlier quoted context omitted.

> If I'm a teen and I sext with a partner, does that mean that in the near future, our messages/photos will be flagged and reviewed for "child porn" and forwarded to police enforcement? No. The system looks for files that are similar to known illegal content. It is not a general purpose underage nude photograph detector.

That's the other feature. Feature 1: CSAM detection. Only on upload of images to iCloud Photos. Feature 2: nudity detection for minor children controlled via the parents' iCloud account. It is not an “underage” nude photograph detector, but a nude photograph detector. All done on-device. The only person(s) notified are THE PARENTS. This is all opt-in and age-restricted. I do not know whether it will affect teens sext…

> The only person(s) notified are THE PARENTS.

Notifying the parents is optional (controlled by parents), and only for accounts below a certain age afaik. It primarily notifies the phone's user.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#117
post #33

Earlier quoted context omitted.

In this case, they wouldn't be "between" the ends, no? They'd be _at_ the ends, just as sending a message on Signal doesn't prevent someone from stealing your phone and reading your messages. I'm not in agreement with this being ok, but if it truly is on device, it still technically can be E2EE

> but if it truly is on device, it still technically can be E2EE What do you think this software does when it finds a matching hash entry? Toss a notification to ask you nicely to pop round your nearest FBI office? What meaning does 'end-to-end' have anymore if this applies? If Apple wrote software on-device to forward a copy of all messages prior to encryption to iCloud for 'backup', would it still be end-to-end? Wh…

E2EE implies it's encrypted between the two parties exchanging messages, which it still is. I'm not suggesting that this isn't an immoral circumvention of the system, but it's still certainly end to end encrypted between the two clients, given that the scanning is performed on device, and not in transit.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#118
post #47

Earlier quoted context omitted.

The concern is that Apple is handing governments a new tool to go “give me a list of all users that have this photo”. It could track down dissidents based on this and combined with metadata is probably sufficient to pinpoint who took a particular picture. Think you shared that picture of police brutality anonymously? Think again.

Unless they change the system, no notification would happen without multiple matches. Also, dissidents can just turn off iCloud sync and no scanning will happen.

What would prevent governments from requiring Apple to scan regardless of iCloud state in order to do business within their borders?

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#119
post #75

Earlier quoted context omitted.

I doesn't do that with sexually explicit images on iMessage either.

The rest of the csam monitoring does. And nice that you abuse your karma to downvote people who don't agree with you.

There is no 'rest of CSAM monitoring'. The CSAM stuff is totally separate from the iMessage stuff we're discussing here.

> And nice that you abuse your karma to downvote people who don't agree with you.

I did not downvote you; not that you be able to tell if I did, anyway.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#120
post #119

Earlier quoted context omitted.

The rest of the csam monitoring does. And nice that you abuse your karma to downvote people who don't agree with you.

There is no 'rest of CSAM monitoring'. The CSAM stuff is totally separate from the iMessage stuff we're discussing here. > And nice that you abuse your karma to downvote people who don't agree with you. I did not downvote you; not that you be able to tell if I did, anyway.

Literally the first sentence under the article headline

"More than 90 policy and rights groups ask company to abandon plans for scanning phones of adults for images of child sex abuse.". Maybe YOU weren't talking about csam, but everyone else was including the article author, if you even read it.

Post reply on HN