Live data from Hacker News

Bugs in our pockets: the risks of client-side scanning

arxiv.org

21–30 of 138 posts

Re: Bugs in our pockets: the risks of client-side scanning

#21
post #13

Earlier quoted context omitted.

> If they wish to enforce rules over what is stored on their server The whole point of end-to-end encryption is that what is stored on their server is statistically uniform binary white noise. If they wish to enforce that, there are a plethora of server-side tools (like the Diehard test suite) with which to do so.

You are completely correct from a computer science perspective - unfortunately, this is not a computer science discussion. As far as the FBI are concerned, “storing encrypted child porn on behalf of people with the keys to decrypt it” still counts as “storing child porn”. You can disagree with that (and there are many good reasons to do so) - but “it’s encrypted so it’s fine” isn’t going to convince anybody who matte…

I agree with you, but if the FBI wanted to serve a warrant to search my device, they can compel me to do so. Failure to unlock that device could put you into jail until you comply with the warrant.

Re: Bugs in our pockets: the risks of client-side scanning

#22

Earlier quoted context omitted.

I've had an iDevice since 2007. I've never signed up for the paid iCloud. I get the standard 5GB plan that all Apple accounts receive. I have never accidentally uploaded a photo to it. I have never enabled it. I don't understand how your situation happens as it has never happened to me. It makes no sense other than someone (maybe you forgot, a significant other, a kid) played around with some settings? There's no oth…

There's nothing better than knowing everything and never having to play around with settings to discover what they do, never forgetting what you've set your settings to, and not having children, family members, or friends do the same. There's no way any reasonable person could ever have their uploads accidentally turned on without their full knowledge and consent so that definitely invalidates any reason to argue aga…

I don't want client side scanning, and I don't want the cloud. If only wishing made it so.

People not being able to understand the devices they use is why devs have gotten us to this point. People are too uneducated to do proper back ups, so some enterprising people came up with a way to do that for you. Peeps still get it wrong. Some other asshats come along and take advantage of uneducated people, and do malicious stuff. Fuck 'em. We should just end the cloud because we as a society can't handle it or the responsibility of operating our own equipment. /s

Re: Bugs in our pockets: the risks of client-side scanning

#24
post #4
post #2

It's not their device to scan.

While I don't like client-side scanning, that's overly reductive. "Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning. Really client…

Just as an aside, I think form validity checks that phone home to a server prior to submission are very questionable, and recording keystroke data from those is absolutely unethical under all circumstances (even if it's only to improve an autocomplete algorithm). Really, any out-of-band transmission from a web form to some other app / database is a potential security threat. The same is true with any kind of client-side scanning, which is part of the point: Although these files may only be scanned because they will be transmitted and stored in the cloud, the whole stack doing secondary scans is out-of-band and by definition insecure, i.e., it is designed to ultimately make human review possible. Who can access that side stream of data and when is intentionally left opaque in these types of proposals, and amounts to "trust us" hocus pocus which is usually a sure sign that proper security measures will not be taken.

Re: Bugs in our pockets: the risks of client-side scanning

#25
On the other hand, CSS might -- eventually, anyway -- offer the best compromise for facilitating reliable, responsible lawful access to mass consumer information technology.

Develop CSS in a manner that minimizes the noted risks. Such mechanisms are a fundamental compromise, philosophically. I am skeptical that those on opposing ends of the privacy debate will find sufficient common ground to achieve responsible implementations.

Deeper concerns regarding the misprioritization of security in consumer infotech design prevent meaningful basis to realize a suitable compromise for CSS tech, anyway.

Re: Bugs in our pockets: the risks of client-side scanning

#26
post #16

Earlier quoted context omitted.

But none of these conundrums could exist if Apple had no access to the user's device, nor control over the software running on it. "Who owns your computer" is still the central question; we're just Sapir-Whorfing ourselves around it within the implicit language of walled gardens. "Apple owns your computer" is the unspoken premise, and it's not axiomatic. Stallman was very, very right.

There's a huge tangle of things with "Apple owns your computer" but I don't think most of it applies to the icloud question. If you wanted to store photos in icloud on a Windows machine, you'd be using the Apple icloud client. Apple has at least some control over what software they write and ship does[1]. They can break 3rd party clients almost at will, so if they choose to be hostile to 3rd party clients that contro…

[deleted]

Re: Bugs in our pockets: the risks of client-side scanning

#27
post #6

Earlier quoted context omitted.

Client side scanning of inappropriate pictures is of content you'd ordinarily be sending them as anyways as well. The proposal was only to do this if cloud services were/are enabled.

> Client side scanning of inappropriate pictures is of content you'd ordinarily be sending them as anyways as well. The proposal was only to do this if cloud services were/are enabled. I have an iPhone. The Photos app keeps telling me that it's unable to upload things to iCloud because my account is full. I never turned it on. I never intended to upload any photos to the cloud. I haven't signed into my iCloud account…

Sadly, Windows phones home just the same if you have a local account.

Now I get that they need to check that I have a valid license. Fair enough. Anything beyond that should be opt-in.

Re: Bugs in our pockets: the risks of client-side scanning

#28
post #4
post #2

It's not their device to scan.

While I don't like client-side scanning, that's overly reductive. "Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning. Really client…

> The Javascript that checks validity of forms before you submit them is a form of client-side scanning

It is hardly difficult to draw a distinction between ensuring a field looks like an expected datatype and ML analysis guessing at photo content.

In fact, trying to construct an argument conflating the two pretty much immediately runs in to the fact that one is adversarial, so it only works if you studiously ignore intent.

Re: Bugs in our pockets: the risks of client-side scanning

#29

Earlier quoted context omitted.

> Client side scanning of inappropriate pictures is of content you'd ordinarily be sending them as anyways as well. The proposal was only to do this if cloud services were/are enabled. I have an iPhone. The Photos app keeps telling me that it's unable to upload things to iCloud because my account is full. I never turned it on. I never intended to upload any photos to the cloud. I haven't signed into my iCloud account…

Bullshit, Microsoft shoves that shit down people's throats. As an example of this, I never once opted into any kind of data sharing, set telemetry to the lowest allowed setting, and don't remember ever signing into a system-wide Microsoft account, yet when I eventually discovered deeply hidden privacy options I found that my MS account had a log of every single application I had ever used on my W10 laptop.

Really?? Where do you find this? I'd like to document this for myself in case I end up in a discussion about such matters.

Re: Bugs in our pockets: the risks of client-side scanning

#30
post #15

Earlier quoted context omitted.

> since 2007 I'm speculating here, but I wonder if part of your experience is based on the fact that you're a long time user. Features like auto-uploading to Photo Library are new, and Apple is generally decent about informing you of new features before opting in. Brand new account setups are a different story. You're encouraged to use all of the latest/greatest stuff (and why not, current topic notwithstanding?). Bo…

Maybe. I'm very anti-cloud from the first moments I ever heard of it and saw the first puffy shapes in slide decks. I don't trust it. It's not in my control and I don't know who does control it. That scares the bejeebus out of me. I'm not the unsuspecting dupe that devs are targeting to get a new user tricked into something. I'm very much aware of the shenanigans devs try and pay attention to that shit from the go. H…

It's not even the devs in general. It's their management and bean counters. Data is money.

And yeah.. The cloud is just someone else's computer. Would you store all your stuff on your friend's computer? Well most people store everything they have on the computers of people they don't even know...

Post reply on HN