Earlier quoted context omitted.
> If they wish to enforce rules over what is stored on their server The whole point of end-to-end encryption is that what is stored on their server is statistically uniform binary white noise. If they wish to enforce that, there are a plethora of server-side tools (like the Diehard test suite) with which to do so.
You are completely correct from a computer science perspective - unfortunately, this is not a computer science discussion. As far as the FBI are concerned, “storing encrypted child porn on behalf of people with the keys to decrypt it” still counts as “storing child porn”. You can disagree with that (and there are many good reasons to do so) - but “it’s encrypted so it’s fine” isn’t going to convince anybody who matte…
Bugs in our pockets: the risks of client-side scanning
21–30 of 138 posts
Re: Bugs in our pockets: the risks of client-side scanning
#22Earlier quoted context omitted.
I've had an iDevice since 2007. I've never signed up for the paid iCloud. I get the standard 5GB plan that all Apple accounts receive. I have never accidentally uploaded a photo to it. I have never enabled it. I don't understand how your situation happens as it has never happened to me. It makes no sense other than someone (maybe you forgot, a significant other, a kid) played around with some settings? There's no oth…
There's nothing better than knowing everything and never having to play around with settings to discover what they do, never forgetting what you've set your settings to, and not having children, family members, or friends do the same. There's no way any reasonable person could ever have their uploads accidentally turned on without their full knowledge and consent so that definitely invalidates any reason to argue aga…
People not being able to understand the devices they use is why devs have gotten us to this point. People are too uneducated to do proper back ups, so some enterprising people came up with a way to do that for you. Peeps still get it wrong. Some other asshats come along and take advantage of uneducated people, and do malicious stuff. Fuck 'em. We should just end the cloud because we as a society can't handle it or the responsibility of operating our own equipment. /s
Re: Bugs in our pockets: the risks of client-side scanning
#23Re: Bugs in our pockets: the risks of client-side scanning
#24It's not their device to scan.
While I don't like client-side scanning, that's overly reductive. "Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning. Really client…
Re: Bugs in our pockets: the risks of client-side scanning
#25Develop CSS in a manner that minimizes the noted risks. Such mechanisms are a fundamental compromise, philosophically. I am skeptical that those on opposing ends of the privacy debate will find sufficient common ground to achieve responsible implementations.
Deeper concerns regarding the misprioritization of security in consumer infotech design prevent meaningful basis to realize a suitable compromise for CSS tech, anyway.
Re: Bugs in our pockets: the risks of client-side scanning
#26Earlier quoted context omitted.
But none of these conundrums could exist if Apple had no access to the user's device, nor control over the software running on it. "Who owns your computer" is still the central question; we're just Sapir-Whorfing ourselves around it within the implicit language of walled gardens. "Apple owns your computer" is the unspoken premise, and it's not axiomatic. Stallman was very, very right.
There's a huge tangle of things with "Apple owns your computer" but I don't think most of it applies to the icloud question. If you wanted to store photos in icloud on a Windows machine, you'd be using the Apple icloud client. Apple has at least some control over what software they write and ship does[1]. They can break 3rd party clients almost at will, so if they choose to be hostile to 3rd party clients that contro…
Re: Bugs in our pockets: the risks of client-side scanning
#27Earlier quoted context omitted.
Client side scanning of inappropriate pictures is of content you'd ordinarily be sending them as anyways as well. The proposal was only to do this if cloud services were/are enabled.
> Client side scanning of inappropriate pictures is of content you'd ordinarily be sending them as anyways as well. The proposal was only to do this if cloud services were/are enabled. I have an iPhone. The Photos app keeps telling me that it's unable to upload things to iCloud because my account is full. I never turned it on. I never intended to upload any photos to the cloud. I haven't signed into my iCloud account…
Now I get that they need to check that I have a valid license. Fair enough. Anything beyond that should be opt-in.
Re: Bugs in our pockets: the risks of client-side scanning
#28It's not their device to scan.
While I don't like client-side scanning, that's overly reductive. "Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning. Really client…
It is hardly difficult to draw a distinction between ensuring a field looks like an expected datatype and ML analysis guessing at photo content.
In fact, trying to construct an argument conflating the two pretty much immediately runs in to the fact that one is adversarial, so it only works if you studiously ignore intent.
Re: Bugs in our pockets: the risks of client-side scanning
#29Earlier quoted context omitted.
> Client side scanning of inappropriate pictures is of content you'd ordinarily be sending them as anyways as well. The proposal was only to do this if cloud services were/are enabled. I have an iPhone. The Photos app keeps telling me that it's unable to upload things to iCloud because my account is full. I never turned it on. I never intended to upload any photos to the cloud. I haven't signed into my iCloud account…
Bullshit, Microsoft shoves that shit down people's throats. As an example of this, I never once opted into any kind of data sharing, set telemetry to the lowest allowed setting, and don't remember ever signing into a system-wide Microsoft account, yet when I eventually discovered deeply hidden privacy options I found that my MS account had a log of every single application I had ever used on my W10 laptop.
Re: Bugs in our pockets: the risks of client-side scanning
#30Earlier quoted context omitted.
> since 2007 I'm speculating here, but I wonder if part of your experience is based on the fact that you're a long time user. Features like auto-uploading to Photo Library are new, and Apple is generally decent about informing you of new features before opting in. Brand new account setups are a different story. You're encouraged to use all of the latest/greatest stuff (and why not, current topic notwithstanding?). Bo…
Maybe. I'm very anti-cloud from the first moments I ever heard of it and saw the first puffy shapes in slide decks. I don't trust it. It's not in my control and I don't know who does control it. That scares the bejeebus out of me. I'm not the unsuspecting dupe that devs are targeting to get a new user tricked into something. I'm very much aware of the shenanigans devs try and pay attention to that shit from the go. H…
And yeah.. The cloud is just someone else's computer. Would you store all your stuff on your friend's computer? Well most people store everything they have on the computers of people they don't even know...