Live data from Hacker News

Bugs in our pockets: the risks of client-side scanning

arxiv.org

101–110 of 138 posts

Re: Bugs in our pockets: the risks of client-side scanning

#102

Eventually we’ll see cryptographic attestation of open source binaries on our phones. Until then, all popular phones will run closed source software, and it will be necessary to trust the vendor. Even then, the vendor may also be the chip maker. Apple would do well to look at sourcing an independent chip vendor for their on-device enclaves. That would give them a trust advantage over Android phones.

http://users.ece.cmu.edu/~ganger/712.fall02/papers/p761-thom...

I don't believe this is a technology problem. This is a legislative problem. We (well, some of us) have the Bill of Rights and the justice system for a reason. We need to codify who owns our data (we do) and what third parties can do with it (nothing unless we say they can, individually).

LEO can't do a damn thing unless they have probable cause. This dragnet BS needs to stop.

We are absolutely empowered to change the rules to suit us.

Re: Bugs in our pockets: the risks of client-side scanning

#103
post #100

IMO that boils down to "who owns what you use". And "there is no free lunch". Applies both to services and devices.

I paid Apple for my iPhone and for storage. I see no reason they should go out of their way to spy on me.

While the indiscriminate collection of data is another issue entirely, I struggle to see that I — or, indeed, most of us — are important enough to be focused on in particular, out of the many billions who’s data is inevitably collected by various three-letter agencies.

Re: Bugs in our pockets: the risks of client-side scanning

#104
post #89

Earlier quoted context omitted.

So long as you are secure in your own systems, you don’t care if they come for the Jews? What about when they come for the gays? How long until you do care? Will there be anyone left to care when they come for you?

There wasn't anyone to care when they came for Assange, the gays and the jews were particularly would in condemning him.

Ah, yes, some casual, blatant and unsubstantiated homophobia and racism… What more could one want on a Wednesday* morning?

Edit: Correct day of the week

Re: Bugs in our pockets: the risks of client-side scanning

#105
post #89

Earlier quoted context omitted.

There wasn't anyone to care when they came for Assange, the gays and the jews were particularly would in condemning him.

Ah, yes, some casual, blatant and unsubstantiated homophobia and racism… What more could one want on a Wednesday* morning? Edit: Correct day of the week

(I am curious about where we have Monday at UTC-ts 1635318700...)

Re: Bugs in our pockets: the risks of client-side scanning

#106
post #100

Earlier quoted context omitted.

I paid Apple for my iPhone and for storage. I see no reason they should go out of their way to spy on me.

While the indiscriminate collection of data is another issue entirely, I struggle to see that I — or, indeed, most of us — are important enough to be focused on in particular, out of the many billions who’s data is inevitably collected by various three-letter agencies.

The problem with this line of thinking is that it presupposes the surveillance is justified. It isn't.

The practical objection is that you have no recourse if you are focused on. So it's a numbers game. One that we shouldn't be playing.

You say most of us. How many innocent lives are you willing to destroy in the quest to vanquish an imaginary foe?

Re: Bugs in our pockets: the risks of client-side scanning

#107

Earlier quoted context omitted.

Bullshit, Microsoft shoves that shit down people's throats. As an example of this, I never once opted into any kind of data sharing, set telemetry to the lowest allowed setting, and don't remember ever signing into a system-wide Microsoft account, yet when I eventually discovered deeply hidden privacy options I found that my MS account had a log of every single application I had ever used on my W10 laptop.

Really?? Where do you find this? I'd like to document this for myself in case I end up in a discussion about such matters.

I found the data somewhere in the MS account profile page.

Re: Bugs in our pockets: the risks of client-side scanning

#108

Earlier quoted context omitted.

Ah, yes, some casual, blatant and unsubstantiated homophobia and racism… What more could one want on a Wednesday* morning? Edit: Correct day of the week

(I am curious about where we have Monday at UTC-ts 1635318700...)

Fuck, that is actually a damn good point… It feels like Monday because I got up early. Excuse me!

Re: Bugs in our pockets: the risks of client-side scanning

#109
post #106

Earlier quoted context omitted.

While the indiscriminate collection of data is another issue entirely, I struggle to see that I — or, indeed, most of us — are important enough to be focused on in particular, out of the many billions who’s data is inevitably collected by various three-letter agencies.

The problem with this line of thinking is that it presupposes the surveillance is justified. It isn't. The practical objection is that you have no recourse if you are focused on. So it's a numbers game. One that we shouldn't be playing. You say most of us. How many innocent lives are you willing to destroy in the quest to vanquish an imaginary foe?

I hear you, loud and clear. I don’t know where the balance lies, truth be told, because I can see both sides to the argument.

Re: Bugs in our pockets: the risks of client-side scanning

#110
Can we coin the word spy-tech and go on with our day?

I read a post here about when radioactive toys were popular, back in the early 1900s. Radioactivity fell so much out of grace, that these days we prefer to die of global warming than to use nuclear power.

In a similar vein, a world where most people go back to pen and paper and watching public TV on bootlegged devices so that they can (try to) escape continuous surveillance by electronic devices is conceivable. Give it enough time and grisly precedents, and companies like Apple and Samsung will only be able to sell new devices to corporate customers.

Post reply on HN