Live data from Hacker News

Bugs in our pockets: the risks of client-side scanning

arxiv.org

111–120 of 138 posts

Re: Bugs in our pockets: the risks of client-side scanning

#111

Eventually we’ll see cryptographic attestation of open source binaries on our phones. Until then, all popular phones will run closed source software, and it will be necessary to trust the vendor. Even then, the vendor may also be the chip maker. Apple would do well to look at sourcing an independent chip vendor for their on-device enclaves. That would give them a trust advantage over Android phones.

> Apple would do well to look at sourcing an independent chip vendor for their on-device enclaves. That would give them a trust advantage over Android phones.

They are designing all of the critical chips (SoC and crypto/enclave) themselves already, TSMC only manufactures them - and if there is one company capable to verify that the chips that TSMC produce actually match the designs, it's Apple.

Re: Bugs in our pockets: the risks of client-side scanning

#112
post #71
post #70

Earlier quoted context omitted.

> The more we remove privacy by tech the less we lose it by law On its face, that seems like a false dichotomy. Can you expand? Generally, I see the erosion of our right against unreasonable search and seizure to be something that hurts everyone (regardless of an individual's ability to make fewer searchable spaces).

If 99.8% of people can have all their information sized by law enforcement then law enforcement won't see the point of a costly political battle to overturn the 4th amendment. Much like advertising those of us tech savvy enough to install add blockers are subsidized by those who don't.

"We didn't violate your privacy because we bought the information from a private company that violated your privacy. But it's ok, because you clicked a button, or signed a EULA."

That's the legal justification behind law enforcement fusion centers gathering, deanonymizing, and sharing data harvested by adtech firms, device manufacturers, and service providers.

It's a gotcha with the same intellectual weight as "I know you are but what am I?"

We need legislation with consequences lethal to companiesthat violate privacy.

Something like this - Every individual variable that a company wants to obtain from a person should be consensual with no option to select all, and the data and permission should be ephemeral. At any time a person should be able to inspect, delete, or allow continued possession of private data. They should be able to allow or deny sale or transfer of the data, and any recipient of the data must confirm permissions before taking receipt. Any algorithm or software or human analysis of data must be public and transparent. A record of any decision or business logic involving private data must be kept, and that record becomes private data, subject to the same constraints.

Stealing someone's identity should have a mandatory minimum of 2 years of community service, and total loss of opt in privileges for 5 years. No free web services or social media if you fuck around with someone else's privacy. Violations result in fines, paid to the victim and more community service.

A business caught abusing private data is subjected to a fine of 5% of company net worth per day. Half of the fine goes to the regulatory bureau, half to the victims.

Law enforcement must obtain warrants specific to known individuals - no geofencing or search term fishing expeditions. Digital data is subject to the same 4th amendment protections as physical papers and property.

Leaks would mean the end of an organization. If a company can't protect private data, then it can't participate in collecting it.

I'm sure there are flaws, but the gist of this seems a good starting outline. Anything less won't solve the problems and there should still be a mechanism for consensual participation in data markets. This would nuke credit bureaus, rein in isps and big tech abuses.

Re: Bugs in our pockets: the risks of client-side scanning

#113
post #76
post #68

Given how the average person and even the majority of people on tech have been acting the last 6 years I'm at the point where I don't care. I can protect myself, everyone else is their own responsibility. The more we remove privacy by tech the less we lose it by law which I now think is the much worse outcome.

> I can protect myself, everyone else is their own responsibility. How does that work if everyone expects you to communicate with them via Whatsapp and their Gmail, or even if you don't, they will happily backup all communication with you in the cloud?

Yup, including your phone numbers, addresses, pictures they take of you, and more.

Re: Bugs in our pockets: the risks of client-side scanning

#114
post #5

Completely agree with the final sentences in their conclusion/recommendations: "In a world where our personal information lies in bits carried on powerful communication and storage devices in our pockets, both technology and laws must be designed to protect our privacy and security, not intrude upon it. Robust protection requires technology and law to complement each other. Client-side scanning would gravely undermin…

Does this count for something like AV, too? I grew up in a world where AV and anti malware only worked offline / client-side. What about spam filters and AV on mail servers? I often hear a commercial for Crowdstrike on Darknet Diaries podcast, which apparently is some kind of combination of a SIEM and ML (though that might be marketing). Would that be the panacea according to this paper? Or is this specific about a client-server model where the server hosts the data? Because the solution to that is rather simple 1) FOSS client 2) public-key cryptography where the private key does not enter the server. Sure, a cloud might make that illegal, but that's why the cloud is just someone else's server. Use your own instead.

Re: Bugs in our pockets: the risks of client-side scanning

#115
post #68

Given how the average person and even the majority of people on tech have been acting the last 6 years I'm at the point where I don't care. I can protect myself, everyone else is their own responsibility. The more we remove privacy by tech the less we lose it by law which I now think is the much worse outcome.

So long as you are secure in your own systems, you don’t care if they come for the Jews? What about when they come for the gays? How long until you do care? Will there be anyone left to care when they come for you?

> How long until you do care?

What's missing from this question is the recognition the answer can very easily be "probably never". Nothing says "they" (who?) will come for you (for some reason this is always implied) and it is eminently possible the person you are questioning doesn't mind living in a fascist hellscape where their neighbours are regularly dragged off to death camps.

Of course, all of that ignores the fact that your question is histrionic. The problems you are referring to are not modern problems and comparing them is a disservice to both situations.

Re: Bugs in our pockets: the risks of client-side scanning

#116

Earlier quoted context omitted.

As another poster said, it's not a choice of whether or not your content is scanned; it's a choice of where. If you upload pictures to the cloud—which is the only scenario in which Apple's scanning was stated to happen¹—then it's a choice between scanning on your device, which allows for the possibility of E2E encryption, or definitely no encryption and scanning on the server. At present, Apple doesn't scan photos on…

> it's a choice between scanning on your device, which allows for the possibility of E2E encryption No, it isn’t a choice at all. Your statement is factually incorrect, and presents a false situation. Apple has no obligation, legal or otherwise, to perform CSS. Nothing is stopping Apple from allowing E2EE right now.

While this is true in general, I think it's actually not true for Apple with respect to iPhotos (possibility of true end to end encryption), since they also make the photo processing software and the camera itself. The sensor data needs to be rendered to a file before it is even possible to encrypt it, so Apple could capture and scan that if they wanted to. You can't encrypt light waves before they hit the physical sensors.

Of course, the same is true of messaging. Apple owns the keyboard software and nothing stops them from putting a keylogger in to capture text before it ever hits the messaging app that encrypts it (and it pretty much needs to have one for predictive text to be possible).

They obviously can and arguably should choose to ignore the data streams before they hit the network clients and can be encrypted, but the capability will always be there.

I think part of the issue here is Apple owning all of the hardware, the OS, and the network client. People don't want to trust network clients, but you have no choice but to trust the OS and hardware vendors. If you don't trust them, your only option for guaranteed private communication is to not use computers. You either need to resort to the organized crime/terrorist model of using hand carry via couriers who credibly believe you'll kill them if they rat you out, or the military model of building your own communications devices.

Re: Bugs in our pockets: the risks of client-side scanning

#117

I'm in the libertarian lion's den . . . and I only read the abstract. What I see from a historical standpoint, pre-cloud, mobile phone/computer, personal encryption etc is that anything stored be it something on paper, something in your house, safety deposit box, whatever was available to law enforcement with controls via the courts or other mechanism. It was available when there was a legal matter. Is there disagree…

> Is there disagreement that legal matters should allow for full disclosure whether criminal or civil?

Yes, I don't agree with this.

> Is the problem [...] too much access without legal justification?

That is also a problem, which isn't new (it existed in the time you described in the opening of your post as well).

> Only with court order the keys are released and your devices get opened up?

This doesn't work (and we know it doesn't, there's so many times it failed already because of systemic issues with the idea), so as a hypothetical it only serves to distract from the fundamental truth that it cannot be a solution.

> I do get the government mass surveillance aspect [...] But [...] we lost that battle

With that mindset, you have indeed lost :)

Re: Bugs in our pockets: the risks of client-side scanning

#119
post #100

Earlier quoted context omitted.

I paid Apple for my iPhone and for storage. I see no reason they should go out of their way to spy on me.

While the indiscriminate collection of data is another issue entirely, I struggle to see that I — or, indeed, most of us — are important enough to be focused on in particular, out of the many billions who’s data is inevitably collected by various three-letter agencies.

> important enough

Ah, so because you are not inconvenienced right now it's not an issue. That's not a good way to approach a systemic injustice, except if you look at other people's suffering and can still sleep fine.

Re: Bugs in our pockets: the risks of client-side scanning

#120
post #106

Earlier quoted context omitted.

The problem with this line of thinking is that it presupposes the surveillance is justified. It isn't. The practical objection is that you have no recourse if you are focused on. So it's a numbers game. One that we shouldn't be playing. You say most of us. How many innocent lives are you willing to destroy in the quest to vanquish an imaginary foe?

I hear you, loud and clear. I don’t know where the balance lies, truth be told, because I can see both sides to the argument.

> I can see both sides

There is the side that says "we should know everything, because we own you" and the side that says "I prefer not to be owned". There is no good-faith way to see both sides of that, that is just avoiding a hard question because it is convenient.

Post reply on HN