Bugs in our pockets: the risks of client-side scanning
51–60 of 138 posts
Re: Bugs in our pockets: the risks of client-side scanning
#52Earlier quoted context omitted.
You are completely correct from a computer science perspective - unfortunately, this is not a computer science discussion. As far as the FBI are concerned, “storing encrypted child porn on behalf of people with the keys to decrypt it” still counts as “storing child porn”. You can disagree with that (and there are many good reasons to do so) - but “it’s encrypted so it’s fine” isn’t going to convince anybody who matte…
In the US, a service provider incurs legal obligations when it has actual knowledge that it is hosting something that appears to be CSAM. A provider hosting encrypted data with no knowledge of what it decrypts to does not have such obligations. https://www.law.cornell.edu/uscode/text/18/2258A
0: https://www.hackerfactor.com/blog/index.php?/archives/929-On....
Re: Bugs in our pockets: the risks of client-side scanning
#53It's not their device to scan.
Re: Bugs in our pockets: the risks of client-side scanning
#54Earlier quoted context omitted.
While I don't like client-side scanning, that's overly reductive. "Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning. Really client…
> While I don't like client-side scanning, that's overly reductive. No it isn’t. It’s my device. I get to decide what runs on it.
Re: Bugs in our pockets: the risks of client-side scanning
#55It's not their device to scan.
It’s their cloud service. If you want to upload to iCloud, you must agree to use their client, and their client implements CSS. If you don’t want to use their client, don’t use their service.
Re: Bugs in our pockets: the risks of client-side scanning
#56Earlier quoted context omitted.
> Develop CSS No, do not. There is no reasonable privacy preserving manner in which you can do so. Spyware is fundamentally incompatible with privacy. I don't care how many god damn whitepapers they write about their novel perceptual hash cohort-based homomorphic 0-trust TPM scanner. It's still a rat.
As another poster said, it's not a choice of whether or not your content is scanned; it's a choice of where. If you upload pictures to the cloud—which is the only scenario in which Apple's scanning was stated to happen¹—then it's a choice between scanning on your device, which allows for the possibility of E2E encryption, or definitely no encryption and scanning on the server. At present, Apple doesn't scan photos on…
No, it isn’t a choice at all. Your statement is factually incorrect, and presents a false situation. Apple has no obligation, legal or otherwise, to perform CSS. Nothing is stopping Apple from allowing E2EE right now.
Re: Bugs in our pockets: the risks of client-side scanning
#57Re: Bugs in our pockets: the risks of client-side scanning
#58Earlier quoted context omitted.
It’s their cloud service. If you want to upload to iCloud, you must agree to use their client, and their client implements CSS. If you don’t want to use their client, don’t use their service.
ofc, but I think we re talking of client side scanning as per the title
Re: Bugs in our pockets: the risks of client-side scanning
#59Earlier quoted context omitted.
You are completely correct from a computer science perspective - unfortunately, this is not a computer science discussion. As far as the FBI are concerned, “storing encrypted child porn on behalf of people with the keys to decrypt it” still counts as “storing child porn”. You can disagree with that (and there are many good reasons to do so) - but “it’s encrypted so it’s fine” isn’t going to convince anybody who matte…
It's not even the just FBI; if the majority of your competitors claim to prevent child-porn from being stored on their servers and you don't, the reputational damage is real. Apple doesn't want to be the "Child Porn friendly cloud service."
Re: Bugs in our pockets: the risks of client-side scanning
#60Earlier quoted context omitted.
While I don't like client-side scanning, that's overly reductive. "Client side scanning" (both in general, and in the recent Apple kerfuffle) is talking about a network client, that will be talking to servers that are owned by "them." If they wish to enforce rules over what is stored on their server then to enforce that right, the only two choices are to disallow E2EE or to perform client-side scanning. Really client…
But none of these conundrums could exist if Apple had no access to the user's device, nor control over the software running on it. "Who owns your computer" is still the central question; we're just Sapir-Whorfing ourselves around it within the implicit language of walled gardens. "Apple owns your computer" is the unspoken premise, and it's not axiomatic. Stallman was very, very right.