Live data from Hacker News

Bugs in our pockets: the risks of client-side scanning

arxiv.org

81–90 of 138 posts

Re: Bugs in our pockets: the risks of client-side scanning

#81

Earlier quoted context omitted.

There's nothing better than knowing everything and never having to play around with settings to discover what they do, never forgetting what you've set your settings to, and not having children, family members, or friends do the same. There's no way any reasonable person could ever have their uploads accidentally turned on without their full knowledge and consent so that definitely invalidates any reason to argue aga…

With server side scanning, if someone accidentally enables uploading you are in exactly the same position. It being enabled on upload, which side it runs changes nothing in all the scenarios you are sarcastically ranting about.

> It being enabled on upload, which side it runs changes nothing in all the scenarios you are sarcastically ranting about.

You're wrong because at the very minimum it means that my device's battery isn't consumed for the scanning.

Further, enabling uploading won't work if the cloud account is full (as is currently the case).

Turning off connectivity prevents the upload and scanning from occurring.

Re: Bugs in our pockets: the risks of client-side scanning

#82
post #78

Earlier quoted context omitted.

You're the customer of a cloud service. Do you want the one that does or does not scan your own files so that a false positive could cause you to be arrested, incur thousands of dollars in legal fees and suffer severe and permanent reputational damage yourself?

Considering that using a service which is known by all to not scan, and is therefore the place the media says is ‘child molester friendly’ could cause the same reputational damage? Might just throw my phone in a campfire.

I'm not a lawyer, so may be wrong, but am I the only one to think that the presumption of innocence principle does not exist anymore? As there are areas where is does not, and there are "gray" areas that effectively are the same.

Re: Bugs in our pockets: the risks of client-side scanning

#83
post #48

Earlier quoted context omitted.

As another poster said, it's not a choice of whether or not your content is scanned; it's a choice of where. If you upload pictures to the cloud—which is the only scenario in which Apple's scanning was stated to happen¹—then it's a choice between scanning on your device, which allows for the possibility of E2E encryption, or definitely no encryption and scanning on the server. At present, Apple doesn't scan photos on…

There are other options. For example, a full e2e encryption system where only the user owns the keys and nothing is scanned. This is already possible today with any general purpose computer.

Indeed, and you’re welcome to disable iCloud and use any of those systems, right?

Re: Bugs in our pockets: the risks of client-side scanning

#84
I'm in the libertarian lion's den . . . and I only read the abstract.

What I see from a historical standpoint, pre-cloud, mobile phone/computer, personal encryption etc is that anything stored be it something on paper, something in your house, safety deposit box, whatever was available to law enforcement with controls via the courts or other mechanism. It was available when there was a legal matter. Is there disagreement that legal matters should allow for full disclosure whether criminal or civil?

Is the problem that law enforcement and other state institutions through legislative channels and courts getting just too much access without legal justification?

Notional idea: could you have a key vault? Only with court order the keys are released and your devices get opened up? Even if not implementable would that work for most people?

I do get the government mass surveillance aspect and think that needs way more scrutiny and people should be vicious in their defense of themselves and society. But it also smells like we lost that battle as private companies are doing pretty well at surveilling individuals and communities.

Re: Bugs in our pockets: the risks of client-side scanning

#85
post #16

Earlier quoted context omitted.

But none of these conundrums could exist if Apple had no access to the user's device, nor control over the software running on it. "Who owns your computer" is still the central question; we're just Sapir-Whorfing ourselves around it within the implicit language of walled gardens. "Apple owns your computer" is the unspoken premise, and it's not axiomatic. Stallman was very, very right.

There's a huge tangle of things with "Apple owns your computer" but I don't think most of it applies to the icloud question. If you wanted to store photos in icloud on a Windows machine, you'd be using the Apple icloud client. Apple has at least some control over what software they write and ship does[1]. They can break 3rd party clients almost at will, so if they choose to be hostile to 3rd party clients that contro…

Well services generally shouldn't be controlling what software can connect either!

The argument over whose computer it is applies pretty similarly. My computer is not part of their infrastructure, and they should only be controlling the software on their infrastructure.

Re: Bugs in our pockets: the risks of client-side scanning

#86
post #78

Earlier quoted context omitted.

You're the customer of a cloud service. Do you want the one that does or does not scan your own files so that a false positive could cause you to be arrested, incur thousands of dollars in legal fees and suffer severe and permanent reputational damage yourself?

Considering that using a service which is known by all to not scan, and is therefore the place the media says is ‘child molester friendly’ could cause the same reputational damage? Might just throw my phone in a campfire.

> Considering that using a service which is known by all to not scan, and is therefore the place the media says is ‘child molester friendly’ could cause the same reputational damage?

Even putting aside how much of a stretch that is, how is anybody else supposed to know which service you use? It's your personal files. That nobody else should have access to them is the point.

It's not as if Apple or whomever should be providing anyone with a list of their customers, as that should cause you to not use them too. As far as I know they don't currently make their customer list public.

Re: Bugs in our pockets: the risks of client-side scanning

#87
post #16

Earlier quoted context omitted.

But none of these conundrums could exist if Apple had no access to the user's device, nor control over the software running on it. "Who owns your computer" is still the central question; we're just Sapir-Whorfing ourselves around it within the implicit language of walled gardens. "Apple owns your computer" is the unspoken premise, and it's not axiomatic. Stallman was very, very right.

There's a huge tangle of things with "Apple owns your computer" but I don't think most of it applies to the icloud question. If you wanted to store photos in icloud on a Windows machine, you'd be using the Apple icloud client. Apple has at least some control over what software they write and ship does[1]. They can break 3rd party clients almost at will, so if they choose to be hostile to 3rd party clients that contro…

It seems to me that Apple does their best to ensure you end up using icloud against your will through a a series of very confusing opt-out prompts and defaults.

Maybe it would be nice to have a tool that would allow you to see exactly what data the client side scanner is “allowed” to “see”?

Re: Bugs in our pockets: the risks of client-side scanning

#88
post #68

Given how the average person and even the majority of people on tech have been acting the last 6 years I'm at the point where I don't care. I can protect myself, everyone else is their own responsibility. The more we remove privacy by tech the less we lose it by law which I now think is the much worse outcome.

So long as you are secure in your own systems, you don’t care if they come for the Jews? What about when they come for the gays?

How long until you do care? Will there be anyone left to care when they come for you?

Re: Bugs in our pockets: the risks of client-side scanning

#89
post #68

Given how the average person and even the majority of people on tech have been acting the last 6 years I'm at the point where I don't care. I can protect myself, everyone else is their own responsibility. The more we remove privacy by tech the less we lose it by law which I now think is the much worse outcome.

So long as you are secure in your own systems, you don’t care if they come for the Jews? What about when they come for the gays? How long until you do care? Will there be anyone left to care when they come for you?

There wasn't anyone to care when they came for Assange, the gays and the jews were particularly would in condemning him.
Post reply on HN