Live data from Hacker News

Bugs in our pockets: the risks of client-side scanning

arxiv.org

71–80 of 138 posts

Re: Bugs in our pockets: the risks of client-side scanning

#71
post #70
post #68

Given how the average person and even the majority of people on tech have been acting the last 6 years I'm at the point where I don't care. I can protect myself, everyone else is their own responsibility. The more we remove privacy by tech the less we lose it by law which I now think is the much worse outcome.

> The more we remove privacy by tech the less we lose it by law On its face, that seems like a false dichotomy. Can you expand? Generally, I see the erosion of our right against unreasonable search and seizure to be something that hurts everyone (regardless of an individual's ability to make fewer searchable spaces).

If 99.8% of people can have all their information sized by law enforcement then law enforcement won't see the point of a costly political battle to overturn the 4th amendment.

Much like advertising those of us tech savvy enough to install add blockers are subsidized by those who don't.

Re: Bugs in our pockets: the risks of client-side scanning

#72

Earlier quoted context omitted.

Apple develops a phone operating system and sells phones that run that operating system. What does it even mean to say “if Apple had no access to the user’s device”?

Yes, Apple is also the OS vendor. What it would mean to say "Apple has no access to the user's device" is, whatever an average, unsophisticated user understands it to mean -- because their informed consent is ethically all that matters here. It means precisely that Apple has no technical capability to remotely access the device. It means any (consented) Apple software update leaves behind no hooks or backdoors that e…

But average users are clearly aware of many high profile iPhone features that inherently involve Apple “remotely accessing the device,” assuming you're include all cases where the iPhone software can be configured to send data from the device to Apple servers. That’s what all iCloud services explicitly do.

Re: Bugs in our pockets: the risks of client-side scanning

#73

Earlier quoted context omitted.

As another poster said, it's not a choice of whether or not your content is scanned; it's a choice of where. If you upload pictures to the cloud—which is the only scenario in which Apple's scanning was stated to happen¹—then it's a choice between scanning on your device, which allows for the possibility of E2E encryption, or definitely no encryption and scanning on the server. At present, Apple doesn't scan photos on…

> it's a choice between scanning on your device, which allows for the possibility of E2E encryption No, it isn’t a choice at all. Your statement is factually incorrect, and presents a false situation. Apple has no obligation, legal or otherwise, to perform CSS. Nothing is stopping Apple from allowing E2EE right now.

I’m presuming that Apple wants to scan for CSAM, which I think they do. Personally, I’m also in favor of tightly-regulated scanning for CSAM.

The fact that they don’t support E2EE, despite their strong pro-privacy stance, supports my presumption. So it comes back to the same argument: presuming Apple is going to scan cloud images for CSAM (which, again, all other major provides already do, to my knowledge), then it’s just a question of how.

For someone like me, who believes scanning for CSAM is worthwhile, Apple’s solution is far superior and privacy-preserving compared to, say, Microsoft’s.

I think this argument really comes down to “no scanning at all” vs. “carefully applied scanning,” but that’s not how it’s framed by the people objecting. I think it’s because that’s an argument they’re not likely to win. And so, if they “win,” I think we’ll just end up with cheap and dumb server-side scanning, which would take a whole lot less effort and political trouble for Apple… and ironically, be much easier to subvert in the ways people against CSS worry about.

Re: Bugs in our pockets: the risks of client-side scanning

#74

Earlier quoted context omitted.

Yes, Apple is also the OS vendor. What it would mean to say "Apple has no access to the user's device" is, whatever an average, unsophisticated user understands it to mean -- because their informed consent is ethically all that matters here. It means precisely that Apple has no technical capability to remotely access the device. It means any (consented) Apple software update leaves behind no hooks or backdoors that e…

But average users are clearly aware of many high profile iPhone features that inherently involve Apple “remotely accessing the device,” assuming you're include all cases where the iPhone software can be configured to send data from the device to Apple servers. That’s what all iCloud services explicitly do.

Yes, but the distinction between "stores private data E2E encrypted on a secure server" and "uploads private data for Apple employees to review" is a bright line. Informed consent means we can't extrapolate from one to the other, if we pretend to be ethical.

It's not as if Apple's marketing doesn't heavily emphasize the "private", "E2E encrypted" aspects already.

Re: Bugs in our pockets: the risks of client-side scanning

#75
post #48

Earlier quoted context omitted.

As another poster said, it's not a choice of whether or not your content is scanned; it's a choice of where. If you upload pictures to the cloud—which is the only scenario in which Apple's scanning was stated to happen¹—then it's a choice between scanning on your device, which allows for the possibility of E2E encryption, or definitely no encryption and scanning on the server. At present, Apple doesn't scan photos on…

There are other options. For example, a full e2e encryption system where only the user owns the keys and nothing is scanned. This is already possible today with any general purpose computer.

See my peer reply to mdekkers.

Re: Bugs in our pockets: the risks of client-side scanning

#76
post #68

Given how the average person and even the majority of people on tech have been acting the last 6 years I'm at the point where I don't care. I can protect myself, everyone else is their own responsibility. The more we remove privacy by tech the less we lose it by law which I now think is the much worse outcome.

> I can protect myself, everyone else is their own responsibility.

How does that work if everyone expects you to communicate with them via Whatsapp and their Gmail, or even if you don't, they will happily backup all communication with you in the cloud?

Re: Bugs in our pockets: the risks of client-side scanning

#77
post #17
post #13

Earlier quoted context omitted.

You are completely correct from a computer science perspective - unfortunately, this is not a computer science discussion. As far as the FBI are concerned, “storing encrypted child porn on behalf of people with the keys to decrypt it” still counts as “storing child porn”. You can disagree with that (and there are many good reasons to do so) - but “it’s encrypted so it’s fine” isn’t going to convince anybody who matte…

This is the part where we need laws to protect privacy. This is arguably an overreach by the FBI in the first place and if it is legal it shouldn’t be.

Since Congress folks seem happy to threaten Apple too with changing the law to do what the FBI wants, I wouldn’t assume it would go the way you are thinking it will.

Re: Bugs in our pockets: the risks of client-side scanning

#78
post #19

Earlier quoted context omitted.

It's not even the just FBI; if the majority of your competitors claim to prevent child-porn from being stored on their servers and you don't, the reputational damage is real. Apple doesn't want to be the "Child Porn friendly cloud service."

You're the customer of a cloud service. Do you want the one that does or does not scan your own files so that a false positive could cause you to be arrested, incur thousands of dollars in legal fees and suffer severe and permanent reputational damage yourself?

Considering that using a service which is known by all to not scan, and is therefore the place the media says is ‘child molester friendly’ could cause the same reputational damage?

Might just throw my phone in a campfire.

Re: Bugs in our pockets: the risks of client-side scanning

#79
post #40
post #21

Earlier quoted context omitted.

I agree with you, but if the FBI wanted to serve a warrant to search my device, they can compel me to do so. Failure to unlock that device could put you into jail until you comply with the warrant.

US case law is not settled on that matter, and some courts have concluded that disclosing a password is testimonial and therefore covered by the fifth amendment. Courts that have ruled the other way have usually done so under narrow exceptions.

Generally, most lawyers would advise their clients to Stay away from an area or activities that can be described this way - because it’s a really good way to be ‘right but dead’ (really, bankrupt or in jail or whatever).

Re: Bugs in our pockets: the risks of client-side scanning

#80
I just disabled Google Play Services on my Android phone to increase privacy... then I started to get spammed with about 10 notifications every 10 seconds (not a joke) to tell me that those 10 apps would not work properly without Google Play Services enabled even if they did work properly... Google and/or LG allowed me to disable 7 of these apps, but the others could not be uninstalled or disabled using the GUI... I had to use ADB to remove them. One of those apps, believe it or not was the LG phone clock and another was the calculator.

After I removed all apps that were complaining about missing Google Play Services and installed alternatives for the ones that I needed like the calculator, everything was working fine. (thanks to f-droid for helping me find viable alternatives)

Post reply on HN