Live data from Hacker News

Bugs in our pockets: the risks of client-side scanning

arxiv.org

121–130 of 138 posts

Re: Bugs in our pockets: the risks of client-side scanning

#121

I just disabled Google Play Services on my Android phone to increase privacy... then I started to get spammed with about 10 notifications every 10 seconds (not a joke) to tell me that those 10 apps would not work properly without Google Play Services enabled even if they did work properly... Google and/or LG allowed me to disable 7 of these apps, but the others could not be uninstalled or disabled using the GUI... I…

Don't disable google play services, run something like microg (easiest way to do so is probably https://lineage.microg.org/ ). Apps are written to expect you to be spied upon and in order for them to not push you to "fix" that, you must lie to them. Moving entirely to f-droid is not an option for most people, as they use their phones to communicate and doing so involves a certain amount of dirtying yourself.

Re: Bugs in our pockets: the risks of client-side scanning

#122

Eventually we’ll see cryptographic attestation of open source binaries on our phones. Until then, all popular phones will run closed source software, and it will be necessary to trust the vendor. Even then, the vendor may also be the chip maker. Apple would do well to look at sourcing an independent chip vendor for their on-device enclaves. That would give them a trust advantage over Android phones.

What makes you think cryptographic attestation will favor open source binaries? Don't you think it's much more likely that cryptographic attestation will tilt the field even more in favor closed-source binaries, given who hold the keys to everyone's kingdom?

Re: Bugs in our pockets: the risks of client-side scanning

#124
post #100

IMO that boils down to "who owns what you use". And "there is no free lunch". Applies both to services and devices.

I paid Apple for my iPhone and for storage. I see no reason they should go out of their way to spy on me.

that's the misconception – the iPhone isn't a good but a service receiver.

Think iCloud, Facetime, iMessage, Push, FindMyPhone etc.

So Apple won't leave after you once have the phone – they remain with you. And spying isn't what Apple calls it. Smart services always have a tendency to be encroaching.

On one side Apple wants to read your lips to know your wishes in advance but on the other the authorities demand access to that knowledge.

Re: Bugs in our pockets: the risks of client-side scanning

#126
post #97

I just disabled Google Play Services on my Android phone to increase privacy... then I started to get spammed with about 10 notifications every 10 seconds (not a joke) to tell me that those 10 apps would not work properly without Google Play Services enabled even if they did work properly... Google and/or LG allowed me to disable 7 of these apps, but the others could not be uninstalled or disabled using the GUI... I…

Which Android version? Some of us have no Google Play Services and no relevant notifications on older devices.

Android 10 on an LG device

Re: Bugs in our pockets: the risks of client-side scanning

#127

I just disabled Google Play Services on my Android phone to increase privacy... then I started to get spammed with about 10 notifications every 10 seconds (not a joke) to tell me that those 10 apps would not work properly without Google Play Services enabled even if they did work properly... Google and/or LG allowed me to disable 7 of these apps, but the others could not be uninstalled or disabled using the GUI... I…

Don't disable google play services, run something like microg (easiest way to do so is probably https://lineage.microg.org/ ). Apps are written to expect you to be spied upon and in order for them to not push you to "fix" that, you must lie to them. Moving entirely to f-droid is not an option for most people, as they use their phones to communicate and doing so involves a certain amount of dirtying yourself.

I don't see why you say not to remove the Google Play Services because I found alternative apps that work just as good, but either way, it was I think my only option because my LG G8 is not supported by LineageOS/microg.

Re: Bugs in our pockets: the risks of client-side scanning

#128
post #97

Earlier quoted context omitted.

Which Android version? Some of us have no Google Play Services and no relevant notifications on older devices.

Android 10 on an LG device

Well, time to really ditch newer Android for either older versions or customizations, or open alternatives.

Re: Bugs in our pockets: the risks of client-side scanning

#129
post #7

Earlier quoted context omitted.

A significant number of concerns aren't about the feature as proposed by Apple, but the slippery slope it creates.

True but slippery slopes are simply a thing. Like the Overton window. Every move takes a step further and moves something else from ridiculous into feasible. And personally, I know this won't affect me. I don't own such content. I don't use the cloud without encryption first (thanks Cryptomator). However I just hate the feeling of my own phone constantly looking over my shoulder on someone else's behalf. Is that so w…

I think we're saying the same thing. 100% agree here. I think (hope) the vast majority of folks wouldn't be affected by the proposal. But the backlash against it has been justified for exactly the reasons you outline.

Re: Bugs in our pockets: the risks of client-side scanning

#130
post #78

Earlier quoted context omitted.

Considering that using a service which is known by all to not scan, and is therefore the place the media says is ‘child molester friendly’ could cause the same reputational damage? Might just throw my phone in a campfire.

> Considering that using a service which is known by all to not scan, and is therefore the place the media says is ‘child molester friendly’ could cause the same reputational damage? Even putting aside how much of a stretch that is, how is anybody else supposed to know which service you use? It's your personal files. That nobody else should have access to them is the point. It's not as if Apple or whomever should be…

Not equivalent to CSAM - just examples of Apps that get some degree of judgement that can be problematic.

What would you think about someone that you were talking to that showed you something on their phone (a restaurant listing you were both thinking of going to, or something on Maps), but then a Parler notification popped up? What if they were married and Grindr or Tinder or whatever notification popped up?

Would you judge them? Would you expect many other people to judge them, even if you don’t?

Don’t get me wrong, I don’t think Apple’s products would be problematic that way. But a big reason why is because they have and likely will continue to make decisions like the one we are discussing.

If they went full end to end super privacy, then got named by the feds repeatedly in whatever the next big csam/terrorist/whatever scandal, that could change, and that is even assuming Congress people don’t join in the action, which they’ve already shown an interest in doing.

Post reply on HN