Live data from Hacker News

Bugs in our pockets: the risks of client-side scanning

arxiv.org

51–60 of 138 posts

Re: Bugs in our pockets: the risks of client-side scanning

#52
post #36
post #13

Earlier quoted context omitted.

You are completely correct from a computer science perspective - unfortunately, this is not a computer science discussion. As far as the FBI are concerned, “storing encrypted child porn on behalf of people with the keys to decrypt it” still counts as “storing child porn”. You can disagree with that (and there are many good reasons to do so) - but “it’s encrypted so it’s fine” isn’t going to convince anybody who matte…

In the US, a service provider incurs legal obligations when it has actual knowledge that it is hosting something that appears to be CSAM. A provider hosting encrypted data with no knowledge of what it decrypts to does not have such obligations. https://www.law.cornell.edu/uscode/text/18/2258A

While that's the law, the big factor here is actual regulatory and agency pressure to scan for CSAM for the images they harbor, given they were previously only doing so when CSAM was manually reported to them by users (as in, probably, given they only submitted 265 reports to NCMEC in 2020[0]). Think "we regulate a second iOS app-store or you fix your CSAM problem".

0: https://www.hackerfactor.com/blog/index.php?/archives/929-On....

Re: Bugs in our pockets: the risks of client-side scanning

#54
post #4

Earlier quoted context omitted.

While I don't like client-side scanning, that's overly reductive. "Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning. Really client…

> While I don't like client-side scanning, that's overly reductive. No it isn’t. It’s my device. I get to decide what runs on it.

And you decide to install the update. If iOS 15 is the only option, such as on the 13, you knowingly decided to purchase a device with this sort of scanning happening. Once more, you also decided to sign in to iCloud and enable storing photos in iCloud Photos, thus enabling the bit that controls whether or not photos are scanned.

Re: Bugs in our pockets: the risks of client-side scanning

#55
post #2

It's not their device to scan.

It’s their cloud service. If you want to upload to iCloud, you must agree to use their client, and their client implements CSS. If you don’t want to use their client, don’t use their service.

ofc, but I think we re talking of client side scanning as per the title

Re: Bugs in our pockets: the risks of client-side scanning

#56

Earlier quoted context omitted.

> Develop CSS No, do not. There is no reasonable privacy preserving manner in which you can do so. Spyware is fundamentally incompatible with privacy. I don't care how many god damn whitepapers they write about their novel perceptual hash cohort-based homomorphic 0-trust TPM scanner. It's still a rat.

As another poster said, it's not a choice of whether or not your content is scanned; it's a choice of where. If you upload pictures to the cloud—which is the only scenario in which Apple's scanning was stated to happen¹—then it's a choice between scanning on your device, which allows for the possibility of E2E encryption, or definitely no encryption and scanning on the server. At present, Apple doesn't scan photos on…

> it's a choice between scanning on your device, which allows for the possibility of E2E encryption

No, it isn’t a choice at all. Your statement is factually incorrect, and presents a false situation. Apple has no obligation, legal or otherwise, to perform CSS. Nothing is stopping Apple from allowing E2EE right now.

Re: Bugs in our pockets: the risks of client-side scanning

#57
Eventually we’ll see cryptographic attestation of open source binaries on our phones. Until then, all popular phones will run closed source software, and it will be necessary to trust the vendor. Even then, the vendor may also be the chip maker. Apple would do well to look at sourcing an independent chip vendor for their on-device enclaves. That would give them a trust advantage over Android phones.

Re: Bugs in our pockets: the risks of client-side scanning

#58

Earlier quoted context omitted.

It’s their cloud service. If you want to upload to iCloud, you must agree to use their client, and their client implements CSS. If you don’t want to use their client, don’t use their service.

ofc, but I think we re talking of client side scanning as per the title

Their iCloud photo upload client is what does the scanning, at the time you upload to their service. It just so happens that their client is bundled with the phone. I think the root of angst here is that nobody trusts that the client isn’t running even when you don’t choose to upload your photos to their cloud service.

Re: Bugs in our pockets: the risks of client-side scanning

#59
post #19
post #13

Earlier quoted context omitted.

You are completely correct from a computer science perspective - unfortunately, this is not a computer science discussion. As far as the FBI are concerned, “storing encrypted child porn on behalf of people with the keys to decrypt it” still counts as “storing child porn”. You can disagree with that (and there are many good reasons to do so) - but “it’s encrypted so it’s fine” isn’t going to convince anybody who matte…

It's not even the just FBI; if the majority of your competitors claim to prevent child-porn from being stored on their servers and you don't, the reputational damage is real. Apple doesn't want to be the "Child Porn friendly cloud service."

You're the customer of a cloud service. Do you want the one that does or does not scan your own files so that a false positive could cause you to be arrested, incur thousands of dollars in legal fees and suffer severe and permanent reputational damage yourself?

Re: Bugs in our pockets: the risks of client-side scanning

#60
post #4

Earlier quoted context omitted.

While I don't like client-side scanning, that's overly reductive. "Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning. Really client…

But none of these conundrums could exist if Apple had no access to the user's device, nor control over the software running on it. "Who owns your computer" is still the central question; we're just Sapir-Whorfing ourselves around it within the implicit language of walled gardens. "Apple owns your computer" is the unspoken premise, and it's not axiomatic. Stallman was very, very right.

Apple develops a phone operating system and sells phones that run that operating system. What does it even mean to say “if Apple had no access to the user’s device”?
Post reply on HN