Live data from Hacker News

Bugs in our pockets: the risks of client-side scanning

arxiv.org

1–10 of 138 posts

Re: Bugs in our pockets: the risks of client-side scanning

#4
post #2

It's not their device to scan.

While I don't like client-side scanning, that's overly reductive.

"Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning.

Really client-side scanning is only up for debate when E2EE is used. The Javascript that checks validity of forms before you submit them is a form of client-side scanning, but most of the time[1] nobody cares because it's data that you intend to send to the server anyways.

1: Inadvertent pastes into fields that phone-home for e.g. autocomplete can reveal otherwise private information, so "most of the time"

Re: Bugs in our pockets: the risks of client-side scanning

#5
Completely agree with the final sentences in their conclusion/recommendations:

"In a world where our personal information lies in bits carried on powerful communication and storage devices in our pockets, both technology and laws must be designed to protect our privacy and security, not intrude upon it. Robust protection requires technology and law to complement each other. Client-side scanning would gravely undermine this, making us all less safe and less secure."

Re: Bugs in our pockets: the risks of client-side scanning

#6
post #4
post #2

It's not their device to scan.

While I don't like client-side scanning, that's overly reductive. "Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning. Really client…

Client side scanning of inappropriate pictures is of content you'd ordinarily be sending them as anyways as well. The proposal was only to do this if cloud services were/are enabled.

Re: Bugs in our pockets: the risks of client-side scanning

#7
post #6
post #4

Earlier quoted context omitted.

While I don't like client-side scanning, that's overly reductive. "Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning. Really client…

Client side scanning of inappropriate pictures is of content you'd ordinarily be sending them as anyways as well. The proposal was only to do this if cloud services were/are enabled.

A significant number of concerns aren't about the feature as proposed by Apple, but the slippery slope it creates.

Re: Bugs in our pockets: the risks of client-side scanning

#8
post #4
post #2

It's not their device to scan.

While I don't like client-side scanning, that's overly reductive. "Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning. Really client…

> If they wish to enforce rules over what is stored on their server

The whole point of end-to-end encryption is that what is stored on their server is statistically uniform binary white noise. If they wish to enforce that, there are a plethora of server-side tools (like the Diehard test suite) with which to do so.

Re: Bugs in our pockets: the risks of client-side scanning

#9
post #4
post #2

It's not their device to scan.

While I don't like client-side scanning, that's overly reductive. "Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning. Really client…

But none of these conundrums could exist if Apple had no access to the user's device, nor control over the software running on it. "Who owns your computer" is still the central question; we're just Sapir-Whorfing ourselves around it within the implicit language of walled gardens. "Apple owns your computer" is the unspoken premise, and it's not axiomatic.

Stallman was very, very right.

Re: Bugs in our pockets: the risks of client-side scanning

#10
post #7
post #6

Earlier quoted context omitted.

Client side scanning of inappropriate pictures is of content you'd ordinarily be sending them as anyways as well. The proposal was only to do this if cloud services were/are enabled.

A significant number of concerns aren't about the feature as proposed by Apple, but the slippery slope it creates.

More about this slippery slope: https://news.ycombinator.com/item?id=28309202.
Post reply on HN