Live data from Hacker News

EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

eff.org

111–120 of 215 posts

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#111

Earlier quoted context omitted.

The request from the FBI in the San Bernardino case was to change a passcode limit constant and retry timeouts. Those are about as trivial to implement as any of the convoluted government coercion database attacks against CSAM detection being proposed here.

The difference here is, that apple would have to develop a new feature for them, test it, and waste millions in lawers to protect themselves from accusations of tampering with the evidence (which a software update definitely is, and who knows what FBI wanted in that software update, maybe even to insert a fake sms to the sms database, or many other things a good defense lawyer could bring to the jury). Here, it's dif…

> FBI just adds the hashes to the database

This is the crux of the argument right here, and I have yet to see a detailed description of how the FBI would go about doing that.

The most detail I’ve seen is in this thread, which suggests that it would be difficult for the FBI to do it, or at least do it more than once.

https://twitter.com/pwnallthethings/status/14248736290037022...

Has anyone seen something like this in the other direction? Something that walks through “the FBI would do this, then this, etc. and now they’ve coopted Apple’s system”?

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#112

Earlier quoted context omitted.

2/3rds of their original letter was spent describing a parental control over sensitive content detection in iMessage as an end to end encryption back door. At best, that is highly cynical. At worst, it is an intentional conflation of different features to raise false alarm.

It's not cynical at all. It's what EFF has been warning about since 2019 and before. (Disclosure: I worked at EFF during this period. We were extremely concerned about the potential role of client-side scanners and the concerted push being made at that time by the intelligence community to present this as a "solution" to end-to-end encryption's privacy features.) https://www.eff.org/deeplinks/2019/11/why-adding-clien…

Your link and most of the concern is about known CSAM detection announced for iCloud Photo Library, yet, again, 2/3rds of the original letter was about iMessage. Point me to the expert consensus that the parental control features announced were a threat to end to end encryption.

The iMessage feature is a parental control feature where kids over 13 receiving on-device classified sensitive images have to click through to unblur them, and kids under 13 will do the same and also have their parents receive a notification that such an action was taken. The parent in any case does not receive a copy of the image. The EFF described it as such:

“Whatever Apple Calls It, It’s No Longer Secure Messaging”

and

“Apple is planning to build a backdoor into…its messaging system.”

The Center for Democracy and Technology who wrote this letter they have co-signed said:

“Plan to replace its industry-standard encrypted messaging system creates new risks in US and globally”

I, respectfully, don’t see much evidence that these are consensus views. Furthermore, I don’t see how you can characterize this feature as a back door without believing safe browsing checks on links received in iMessage is an encryption back door.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#113

Earlier quoted context omitted.

It is not a lie. The scanning is done on device, but photos are not scanned unless they are going to be uploaded to iCloud. Apple has explicitly stated this.

Oh, well if Apple says... I'm sure their statement somehow completely aligns with all the potentially conflicting interpretations one can draw from their PR, their stated objectives, and the implementation details observed, and it always will - forever.

Apple has released fairly detailed technical summaries of their system, far beyond what could be hidden behind "conflicting interpretations" of material written by a PR department. Have you read them? Are you claiming that Apple is lying?

If your contention is that Apple is lying now, then you have no reason to think Apple—or any other corporation for that matter—hasn't been lying about your data security for the past decade. Who knows, maybe Google Chrome is sending everyone's passwords in plain text to the NSA.

If your contention is that Apple might turn evil in the future, that charge could be levied against against any other company at any time. It's functionally unfalsifiable.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#114
post #103

Earlier quoted context omitted.

The invocation of 30 images like it's a barrier confuses me. I created a bunch of preimages posted on github, I could easily create 30 or 3000 but at this point all I'd be doing is helping apple cover up their bad hash algorithm[1]. I pointed out above that the attacker could use legal pornography images selected to make it look like child porn. This isn't hard. Doing it 30 times is no particular challenge. I didn't…

If someone is trying to frame a known individual, the 30 image threshold may not be a significant barrier, I'll grant you that. But if you're enlisting Apple's algorithm to perform a dragnet search of the citizenry (e.g. leaked state secrets) then this mechanism cannot be effective unless the material in question is comprised of at least 30 photographs.

I'll grant you that!

I have some residual nitpicks, on that point: many leaked data troves are much larger than that, though it is a material restriction.

The 30 threshold isn't leakless. Say you only have one hit, it still gets reported to Apple. The software also emits a small rate of "chaff", fake hits to help obscure the sub-threshold real hits. But it could still be used to produce a list of possible matches, including anyone with targeted material plus people who emitted fake matches, producing a list of potential targets much smaller than the whole population, for enhanced surveillance.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#115
post #36

Earlier quoted context omitted.

If Apple is performing the searching of user private data due to pressure or incentive from the government it would make apple an agent of the government from the perspective of the fourth amendment. As such, these warrantless searches would be unlawful. If what you suggest were true, we should be even more angry with Apple: it would mean that rather than just lawfully invading their users privacy, that they were a p…

The time to be angry with apple was years ago when they launched their false marketing campaign claiming privacy on their closed devices. A lot of people fell for it, and were happy to believe whatever they said. All the while they have been two-face-timing by turning over user data to governments (including the US and putting user data on Chinese servers) anyway, with the highest data turnover rates actually. Everyo…

What can I, as an individual, do to protect my digital privacy then? Would that mean ditching the Apple ecosystem, and going full linux laptop & phone? As much as I would love to buy a pinephone, they just don't seem like a truly viable alternative...

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#116
post #92

> As we’ve explained in Deeplinks blog posts, Apple’s planned phone-scanning system opens the door to broader abuses. It decreases privacy for all iCloud photo users, and the parental notification system is a shift away from strong end-to-end encryption. It will tempt liberal democratic regimes to increase surveillance, and likely bring even great pressures from regimes that already have online censorship ensconced i…

"it just gives an additional parental control in addition to the many numerous parental controls (with them kids have no privacy already)" Wait, sending data (of matching CP hashes) to law enforcement is parental control?

Yours is a very fair negative reaction. The information in the EFF’s includes a portion where it seems to be concerned only about alerting parents[1]. I think many parents would find that reasonable. However, the fact that the information will also be sent to the government [2] is just plainly an abuse of privacy, goes outside of the relationship between parent and child, and I do not imagine that parents would find that reasonable.

> [1] Moreover, the system Apple has developed assumes that the "parent" and "child" accounts involved actually belong to an adult who is the parent of a child, and that those individuals have a healthy relationship. This may not always be the case; an abusive adult may be the organiser of the account, and the consequences of parental notification could threaten the child’s safety and wellbeing. LGBTQ+ youths on family accounts with unsympathetic parents are particularly at risk. As a result of this change, iMessages will no longer provide confidentiality and privacy to those users through an end-to-end encrypted messaging system in which only the sender and intended recipients have access to the information sent.

> [2] When a preset threshold number of matches is met, it will disable the account and report the user and those images to authorities.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#117
post #48

Earlier quoted context omitted.

It is not about the encryption, it is about what an "end" is. Generally, we consider the "end" to be the end user. If someone else can see the message along the way, it is not end to end anymore from a user perspective, even if it is from a network perspective. And Apple has complete control over your device through software updates. So that the leak is from your device or from the network is a mostly meaningless tec…

As a parent, I consider myself the "end user" of my child's device, not my child. That I might be looped in on any messages sent or received by this device is not at all a leak, it's a convenience—much like how I can receive messages sent to me on my phone and my laptop.

When someone sends a message to your child, the message is for your child, not for you. Your child is the "end point" and you are an evesdropper.

This is a case where I think it is justified, as long as your child is a minor and you are his legal guardian. But as acceptable as it is, you are still a spy and the app is spyware.

The fears, justified or not, is that the same feature that can be used for parental control can also be used on adults without their consent.

Personally, I think that right now, the fears are overblown, but I also think that Apple got the backlash they deserved. Privacy is not to be taken lightly, it is something that both protects freedom and helps criminals, also a strong political stance. It is not just a marketing took against Google.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#118

Earlier quoted context omitted.

The request from the FBI in the San Bernardino case was to change a passcode limit constant and retry timeouts. Those are about as trivial to implement as any of the convoluted government coercion database attacks against CSAM detection being proposed here.

The passcode limit constant is enforced by the secure enclave. I don't know if it's been proven that the secure enclave component of the device can be changed without the device being unlocked. I'm not even sure it possible for any operating system updates to occur on a device which is locked.

The technical feasibility of the FBI’s request was never the question, nor the basis of Apple’s objection.

Of course it’s even easier for Apple to say “no” to the government if they literally cannot do what the government is asking.

That’s the basis of the EFF’s objection to Apple’s plans: they think that by implementing this CSAM system, Apple will turn an impossibility into a possibility.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#120
post #92

> As we’ve explained in Deeplinks blog posts, Apple’s planned phone-scanning system opens the door to broader abuses. It decreases privacy for all iCloud photo users, and the parental notification system is a shift away from strong end-to-end encryption. It will tempt liberal democratic regimes to increase surveillance, and likely bring even great pressures from regimes that already have online censorship ensconced i…

"it just gives an additional parental control in addition to the many numerous parental controls (with them kids have no privacy already)" Wait, sending data (of matching CP hashes) to law enforcement is parental control?

Apple announced two separate things in one press release: a CSAM-scanning system, and a parental control that uses AI to attempt to detect nude pictures in iMessages and alert the parents. The latter system does not send any info to Apple or any authorities.
Post reply on HN