Live data from Hacker News

EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

eff.org

141–150 of 215 posts

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#141
post #117

Earlier quoted context omitted.

When someone sends a message to your child, the message is for your child, not for you. Your child is the "end point" and you are an evesdropper. This is a case where I think it is justified, as long as your child is a minor and you are his legal guardian. But as acceptable as it is, you are still a spy and the app is spyware. The fears, justified or not, is that the same feature that can be used for parental control…

The parent paid for the device, don't they then own it? Or can kids sign up for phone plans and buy $1,200 devices these days? Normally, if I buy a device, I want control. If I chose to get alerted to porn being sent to my 10 year old - that should be permitted. I don't care if the sender hasn't given consent, I don't give them consent to send porn or naked photos to my kids !

It doesn't matter how much the device cost or how much you want control or how justified your access is, if you are able to intercept private messages sent between two other people then those messages can't reasonably be considered encrypted end-to-end

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#142

Earlier quoted context omitted.

None of that explains how Australia could ever successfully coerce Apple into performing widespread surveillance of US citizens. The fact that Australia is a "five eyes" country doesn't make it any more plausible than if the demand came from China or Russia.

It explains how Australia could coerce Apple into performing widespread surveillance of Aus citizens. Then it’s trivial for the US to coerce Apple into switching that functionality on in the US.

Any widespread warrantless surveillance of the private physical property of US citizens, performed at the direction of the US Government, would be an absolute clear-cut unambiguous breach of the 4th Amendment.

I'm not saying the US Government wouldn't care that it's unconstitutional—we know they'd ignore the constitution when they can get away with it. But they'd also have to convince Apple's lawyers to go along with unconstitutional surveillance. You don't think Apple wouldn't be itching for another opportunity to prove their strength against a Government? Especially now? Apple would love nothing more than to have more opportunities like they got with the San Bernardino iPhone.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#143
post #136

With all the news of CSAM going to be scanned on iPhones, which people are even going to keep such content on iPhones anymore? The news of this has been so prominent in the media, people not even in tech have heard about it plenty. If you are a Person of Interest that consumes/distributes such content and are a tad aware of the news, you aren't going to use iPhones/iCloud storage anymore.

Apple will then have a list of all the people who have an iDevice but disabled iCloud in August, 2021.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#144
post #93

Earlier quoted context omitted.

Sure - but who wants a human reviewing their private photos? I don’t. Unless you understand the technical bits you have know way of knowing how rarely this is likely to happen in practice.

Not me, but if they only review after a flag, that's best you can do I think? facebook works this way too. Users flag photos and someone looks and deals with them.

‘No worse than facebook’ is probably the most damning thing you can say about a tech company.

The best you can do would be to not review people’s private photos at all.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#145
post #134

Earlier quoted context omitted.

> But as acceptable as it is, you are still a spy and the app is spyware. I vehemently disagree that a feature could be classed as spyware if it clearly and unambiguously declares exactly what it's going to do prior offering a choice whether or not to do it. By that logic, the mere presence of a "report phishing" button in any cloud email service would be sufficient to declare it as spyware. But fine, whatever. You'r…

When I was a child, my mother refused to buy me any computers. I had to earn money mowing lawns and raking leaves to buy a laptop. Once I had a laptop, she told me she wished there was software she could install on all of her children's computers that would allow her to view what each of us was doing on her TV. I considered that spying - even if it was intentional on her part. I detested how few rights I had as a chi…

> I detested how few rights I had as a child.

That is called being a teenager, I think.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#146
post #54

Earlier quoted context omitted.

> (though that could easily be the same even without all these CSAM measures.. not a new threat) Apple has historically avoided being pressured by governments to allow this kind of surveillance by arguing they can't be forced to create functionality that doesn't exist, or hand over information they don't have. It's the argument they made in the San Bernadino case. If they release this, it'll be much harder to avoid g…

Ehh. I'd argue Apple has a mixed record. It's well known that iCloud backups are unencrypted and often handed over to authorities. In Jan 2020[1], it was reported they planned to encrypt backups, but dropped the rollout due to pressure from the FBI. I'm surprised they don't get called out because the difference between this and San Bernadino makes sense to me from a technical standpoint, from a practical standpoint a…

iCloud backups _are_ encrypted, but have an HSM-escrowed key process on court order.

People like to pretend crypto is always E2E or nothing, but escrowed keys do mean that the process of checking cloud-backed data has an auditable release process, that the keys to your data are outside the cloud-hosted infrastructure, and that there is no support for blanket data scanning.

> assuming they encrypt iCloud photos at some point

iCloud photos are already encrypted. See above.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#147
post #77

Earlier quoted context omitted.

They have to come from the intersection of two databases from two jurisdictions. So already that’s out as you suggest. Then you’d have to match _nearly exact photos_, which isn’t a vector for general photos of some random minority. Then you’d need 30 of such specific photos, a match with another secret hash, and then a human reviewer at Apple has to say yes it’s CP before anything else happens. I think there are plen…

Every step you've described is unfalsifyable: You just have to blindly trust that Apple is doing these things, and that e.g. authoritarian regemes haven't compromised Apple staff with access to the data. > They have to come from the intersection of two databases from two jurisdictions. My message directly answered that. A state actor can modify an apparent childporn image to match an arbitrarily hash and hand that im…

> Every step you've described is unfalsifyable: You just have to blindly trust that Apple is doing these things, and that e.g. authoritarian regemes haven't compromised Apple staff with access to the data.

So third party auditors as well?

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#148

Earlier quoted context omitted.

The technical feasibility of the FBI’s request was never the question, nor the basis of Apple’s objection. Of course it’s even easier for Apple to say “no” to the government if they literally cannot do what the government is asking. That’s the basis of the EFF’s objection to Apple’s plans: they think that by implementing this CSAM system, Apple will turn an impossibility into a possibility.

We were never in a world where Apple was unable to do what the government was asking. Nothing impossible has been made possible, and Apple has made a stand against small changes - like changing constants - before.

It's not "impossibility". It's cost. The FBI cannot force Apple to do free work to circumvent security. Can they force them to add one more hash? Is that work?

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#149
post #68

Earlier quoted context omitted.

What's the point of that? If you don't trust Apple, why would you use Photos.app in the first place? They already have 100% control over that, and can spy as much as they want to. No need to go by way of the CSAM database, that would be absurd.

I've never been a customer of Apple but I'll try and imagine the experience... I might trust them to assemble hardware and write software for my consumer needs - but that doesn't mean I trust them to competently reason about me potentially being a pedo. That is only a small part of a much larger point, but it is reason enough alone.

Apple's responsibility ends with notifying law enforcement, at which point presumably there would be a subpoena for evidence and a trial.

The concern people have is logic on their phone snitching on them, with scenarios based on authoritative regimes setting the baseline of what is scanned/reported.

Apple is not serving as judge, jury and executioner (unless there is an electric shock delivery system being added to the iPhone 13)

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#150

Earlier quoted context omitted.

Do you ask for the same audit at Facebook, Google, Microsoft, Dropbox, and countless others who are already doing this and have been for years? I do not share your same concern of some abused db _today_.

Neither Google nor Microsoft scan pictures people have on their devices running Android or Windows. I'm not sure how that's even applicable to Facebook and Dropbox.

Microsoft, Google, Facebook, Dropbox, etc. all scan photos which are cloud hosted for CSAM. Apple's new system scans only photos which are cloud hosted for CSAM.

This would be the source of the inconsistency - that the code to do scanning is on the client side of the uploader rather than the server side of the uploader does not change any abuse scenarios, but exclusively serves "slippery slope" arguments of full on-device surveillance.

Post reply on HN