Live data from Hacker News

EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

eff.org

71–80 of 215 posts

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#71

Earlier quoted context omitted.

Sure, but I don't expect it from third party cloud platforms - in the same way I wouldn't expect accountability from a garbage man who reports to the police after finding evidence of crime in my garbage. Apple is, for some insane reason, trying to establish the precedent that the contents of your Apple product are now part of the public space - where expectation of privacy isn't a thing.

But that isn’t true. This is only photos uploaded to iCloud.

Why would you lie about something so easily disproven?

"Instead of scanning images in the cloud, the system performs on-device matching..."

https://www.apple.com/child-safety/

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#72
post #48
post #18

> [...] and the parental notification system is a shift away from strong end-to-end encryption. That particular statement doesn't make much sense to me. The parental notification system is just a frontend action (one of many, like link previews and such). What does that have to do with iMessage's encryption? I can see an argument about a shift away from privacy (though it only pertains to minors under 13 receiving se…

It is not about the encryption, it is about what an "end" is. Generally, we consider the "end" to be the end user. If someone else can see the message along the way, it is not end to end anymore from a user perspective, even if it is from a network perspective. And Apple has complete control over your device through software updates. So that the leak is from your device or from the network is a mostly meaningless tec…

> And Apple has complete control over your device through software updates.

This has been true of all operating systems with integrated software updates since the advent of software updates. In this respect, nothing has changed for over a decade.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#73

Earlier quoted context omitted.

The difference here is, that apple would have to develop a new feature for them, test it, and waste millions in lawers to protect themselves from accusations of tampering with the evidence (which a software update definitely is, and who knows what FBI wanted in that software update, maybe even to insert a fake sms to the sms database, or many other things a good defense lawyer could bring to the jury). Here, it's dif…

But the FBI can’t just add the hashes to the db. That’s why it’s the intersection of two dbs in two jurisdictions… to prevent exactly that kind of attack. Then they need to pass a human reviewer as well.

Five Eyes

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#74
post #36

Does Tim Cook have a choice here? I would be surprised to hear that the genesis of this idea was inside of Apple vs. one or more govts pressuring Apple to add this functionality for them. It is also likely they even suggested that Apple should market this as anti-pedo tech to receive the least pushback from users.

If Apple is performing the searching of user private data due to pressure or incentive from the government it would make apple an agent of the government from the perspective of the fourth amendment. As such, these warrantless searches would be unlawful. If what you suggest were true, we should be even more angry with Apple: it would mean that rather than just lawfully invading their users privacy, that they were a p…

The time to be angry with apple was years ago when they launched their false marketing campaign claiming privacy on their closed devices. A lot of people fell for it, and were happy to believe whatever they said. All the while they have been two-face-timing by turning over user data to governments (including the US and putting user data on Chinese servers) anyway, with the highest data turnover rates actually. Everyone was happy to turn a blind eye to these happenings as long as it didn't affect them.

We should be angry with _ourselves_. What's happening now is that this has hit closer to a lot more people, who are now dissecting every detail, blaming others, performing mental gymnastics, and launching 'open letters' so that their brand identity and perceptions aren't proven wrong. Convincing them to roll back their recent changes will not somehow make Apple devices private, when it was never private to begin with.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#75

Earlier quoted context omitted.

We had SWAT teams for a long time before SWATing became popular. The publicity that this has gotten is only going to increase the chances that all these services start getting abused. And who is to say that it hasn't happened already and been entirely successful, but nobody believed the victim.

So you think we’re going to see a rise in people uploading CP to others cloud providers?

Yes. I would bet the large majority of people here who are now quick to point out that other cloud providers have been doing this for years didn't know that fact a month ago. We're now well armed with that information due to arguing about this Apple issue. The fact that you're so quick to inform me of the facts is precisely why I think its more likely to happen.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#76

Earlier quoted context omitted.

> (though that could easily be the same even without all these CSAM measures.. not a new threat) Apple has historically avoided being pressured by governments to allow this kind of surveillance by arguing they can't be forced to create functionality that doesn't exist, or hand over information they don't have. It's the argument they made in the San Bernadino case. If they release this, it'll be much harder to avoid g…

The request from the FBI in the San Bernardino case was to change a passcode limit constant and retry timeouts. Those are about as trivial to implement as any of the convoluted government coercion database attacks against CSAM detection being proposed here.

The passcode limit constant is enforced by the secure enclave. I don't know if it's been proven that the secure enclave component of the device can be changed without the device being unlocked. I'm not even sure it possible for any operating system updates to occur on a device which is locked.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#77
post #31

Earlier quoted context omitted.

Their use of a highly vulnerable[1] "neural" perceptual hash function makes the database unauditable: An abusive state actor could obtain child porn images and invisibly alter them to match the hashes of the ideological or ethnically related images they really want to match. If challenged, they could produce child porn images matching their database, and they could had these images to other governments to unknowingly…

They have to come from the intersection of two databases from two jurisdictions. So already that’s out as you suggest. Then you’d have to match _nearly exact photos_, which isn’t a vector for general photos of some random minority. Then you’d need 30 of such specific photos, a match with another secret hash, and then a human reviewer at Apple has to say yes it’s CP before anything else happens. I think there are plen…

Every step you've described is unfalsifyable: You just have to blindly trust that Apple is doing these things, and that e.g. authoritarian regemes haven't compromised Apple staff with access to the data.

> They have to come from the intersection of two databases from two jurisdictions.

My message directly answered that. A state actor can modify an apparent childporn image to match an arbitrarily hash and hand that image to other agencies who will dutifully include it in their database.

> Then you’d have to match _nearly exact photos_

It's unclear what you mean here. It's easy to construct completely different images that share a neuralhash. Apple also has no access to the original "child porn" (in quotes because it may not be), as it would be unlawful to provide it to them.

> but let’s be honest about the real risks

Yes. Lets be honest: Apple has made a decision to reprogram devices owned by their customers to act against their users best interest. They assure us that they will be taking steps to mitigate harm but have used powerful cryptography to conceal their actions and most of their supposed protections are unfalsifable. You're just supposed to explicitly take the word of a party that is already admittedly acting against your best interest. Finally, at best their protections are only moderate. Almost every computer security vulnerability could be dismissed as requiring an impossible series of coincidences, at yet attacks exist.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#78
post #68

Earlier quoted context omitted.

> What more could one ask for? An independent audit for both the secret secondary perceptual hashing algorithm and the chain of custody policies/compliance for the "US db" and the disconcertedly open ended "not yet chosen non-US db"?

What's the point of that? If you don't trust Apple, why would you use Photos.app in the first place? They already have 100% control over that, and can spy as much as they want to. No need to go by way of the CSAM database, that would be absurd.

I've never been a customer of Apple but I'll try and imagine the experience... I might trust them to assemble hardware and write software for my consumer needs - but that doesn't mean I trust them to competently reason about me potentially being a pedo. That is only a small part of a much larger point, but it is reason enough alone.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#79

Earlier quoted context omitted.

But the FBI can’t just add the hashes to the db. That’s why it’s the intersection of two dbs in two jurisdictions… to prevent exactly that kind of attack. Then they need to pass a human reviewer as well.

Five Eyes

You are suggesting that another country could launder the request on behalf of the USA in order to circumvent the 4th Amendment. Okay then, let's play that out.

Australia contacts Apple and demands they augment CSAM detection so that every iPhone in the USA is now scanning for image hashes supplied by Australia.

Apple says no.

End of hypothetical.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#80

Earlier quoted context omitted.

The request from the FBI in the San Bernardino case was to change a passcode limit constant and retry timeouts. Those are about as trivial to implement as any of the convoluted government coercion database attacks against CSAM detection being proposed here.

The passcode limit constant is enforced by the secure enclave. I don't know if it's been proven that the secure enclave component of the device can be changed without the device being unlocked. I'm not even sure it possible for any operating system updates to occur on a device which is locked.

Not on the iPhone 5C which was the phone used by the terrorist and did not have an SE. Locked iPhones can be updated from DFU, but I think SE firmware can’t.
Post reply on HN