Live data from Hacker News

Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

9to5mac.com

271–280 of 785 posts

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#271
post #22

Earlier quoted context omitted.

Not in a society.

Privacy cannot be defined in solitary situations. : ) The only place where privacy has meaning is in the company of other people. Including society as a kind of group of people.

> Privacy cannot be defined in solitary situations. : )

Here lies the paradox.

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#272
post #11

> Apple previously withdrew plans for its own CSAM-scanning feature for iCloud Photos, following pushback from customers and human rights groups. Apple’s solution was more privacy-preserving than what is now proposed by the UK government. Preface: I don't have an opinion on one side or the other. Question: what were the arguments lobbied against apple that caused them to withdraw? Also, is CSAM the motivating factor…

Apple's solution was to run every photo through a perceptual hash algorithm with a neural network inside of it and then compare that against a list of known hashes. This is actually not materially different from the system that every image host has used for a while now. The main difference was that they were going to use a bunch of cryptography to ensure that...

- Images could be scanned only after a threshold number of illegal images had been flagged

- Law enforcement agencies could not use the system to flag non-CSAM images

Part of the way they achieve the former - and what makes the system unworkable - is that it's client-sided.

To be clear, every service already scans for CSAM. But the naive way of doing this - comparing SHA-2 message digests - can be trivially manipulated into producing false negatives. Just flip a bit in the image and it becomes a new image. Perceptual hash algorithms instead use notions of image similarity to protect against this, but it also introduces the possibility of false positives - i.e. images that look innocuous but match against CSAM and get you flagged. This is not merely a problem to be solved, but a consequence of such systems being differentiable, which is necessary for them to actually work.

For remote scans, you can at least keep the perceptual hash algorithm secret and avoid leaking information about what images do and don't get flagged. This will frustrate attempts at adversarial training. However, when you put the perceptual hash on everyone's phone, it can be extracted, and people who don't like the idea of running a spying dragnet will deliberately break the hash just to tell you to fuck off. So people were making tools that would modify one image to look like another, which could be used to either hide CSAM or, worse, making cat pictures that get your iCloud flagged.

There's also a bit of moral insult involved with having your phone do things that aren't in your benefit, even if this ostensibly were to keep the feds from demanding explicit backdoors[0]. This system is laughably easy to defeat if you're jailbroken - just turn the daemon off. Hence why Apple made no attempt to integrate it into macOS where users have root access[1].

Law enforcement would never firewall their capabilities to "just CSAM." That's not how the law works. You can't sue your drug dealer for not giving you the weed you paid for, and for similar reasons, law enforcement is never going to only wiretap pedophiles and not drug dealers. There's a few exceptions to this[2], but generally, you should assume that if you're about to give the feds the legal capability to spy, it will be used for every crime down to and potentially including routine traffic stops.

Apple's bulwark against that was to have the system only scan for images that were flagged by multiple independent child protection agencies. However, this isn't a guarantee; the western world routinely collaborates in very not independent ways. There's no guarantee that, say, Europe's pedo-fighters wouldn't have had their arms twisted by their countries' intelligence apparatus, operating in concert with the American CIA who was arm-twisting NCMEC. Apple promised they'd be reviewing all reports before forwarding them to law enforcement, but in this situation there's nothing preventing them from having their arms twisted here, too[3].

[0] For the record, there was no evidence that Apple was using this system to enable iCloud end-to-end encryption. They'd already turned that off because of a UX problem: too many people were permanently locking themselves out of their own data and Apple couldn't break into it for them.

[1] Root access on macOS is complicated by the fact that SIP and boot security exists. They could at least theoretically have made the kernel refuse to terminate the CSAM scanner process at all, but that would be a speed bump at best. Users absolutely can turn off SIP or boot modified kernels on Macs that would remove whatever protection Apple added to the CSAM scanner. And Apple currently has no interest in locking owners out of macOS like they did with iOS.

[2] The NSA actually does try to keep their spying tools to themselves, because they have to fight nation-states, not criminals. Even then, they'll still slip hints under the door and tell the FBI they can only use them if they can make up a story that doesn't expose how the NSA's spying apparatus works.

[3] National Security Letters are one hell of a drug.

Apple could also have their arm twisted to add backdoors, but they've already shown that they'll yell loudly if that happens. Furthermore, the existence of software signatures means that such a backdoor would generate irrefutable paper trails, which is the sort of thing that intelligence agencies hate. It's much easier for them to just quietly extend an existing quasi-backdoor than to create an explicit one that loudly screams "DO NOT USE YOUR PHONE TO DO CRIMES"

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#273
post #80

Earlier quoted context omitted.

Yeah, ok, try harder than a Reddit thread where supposedly authoritative commenters can’t even spell encrypt. The idiot pmendes is wrong (if he was correct then no one knowledgeable on the subject would classify that system as E2EE - something more to read about). The encryption keys are not managed in iCloud which you can read yourself: https://support.apple.com/guide/security/how-imessage-sends-... https://www.appl…

> The idiot pmendes is wrong (if he was correct then no one knowledgeable on the subject would classify that system as E2EE What exactly is pmendes wrong about? Are you referring to this comment: > In iMessage the message contents are in fact end to end encripted. Each device encripts the message using the recipient keys and then sends the message. The problem is that iCloud manages the keys by itself so you have no…

[deleted]

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#274

Stuff like this is why I'm an Apple fanboy. I'm happy to pay a premium and be locked into their walled garden for some things if it means supporting a company that has the power to shift policy in favor of human rights (privacy in this case).

Sounds like their PR works. I bet that's the exact "feeling" they're aiming for.

Yea, and even if it is actionable and "real" - they're .. i think, correct me if i'm wrong, by law a for-profit company. Meaning none of this is noble, this is just aligned with our interests because they believe that to be the most profitable image for them currently.

Which is all well a good for now, but profit directions can change, and i suspect it's easier to change a direction guided by profit than a direction guided by morals. Ie i suspect their current "good direction" is less stable than some would suggest.

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#275
post #149

Earlier quoted context omitted.

Which is a good reason to avoid giving your data to either one in the first place. If I don't have a choice though, I'll take the company over the government any day.

Difficulty: "Any day" meaning 1917 in Russia or 1933 in Germany. (Edit: for my next trick, I will read the post more carefully before replying)

I don't understand this comment the Tsar and the Nazi's were both governments.

Another good example is the Dutch housing all the data in an building that was used to track down and kill the right people.

The data existing is the problem. The ideal situation is that there is no data.

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#276

The UK keeps trying to throw their weight around only to find out they aren’t that big. The CMA with Xbox and now this. They aren’t large enough for Apple and Microsoft to make massive changes just to accommodate a relatively small market.

> The UK keeps trying to throw their weight around only to find out they aren’t that big.

Their (former) empire is a part of their cultural identity. It's going to take a few more generations to shed the expectations of what was.

The days of two washed-up subjects of the crown taking Kafiristan all on their lonesome are dead and gone.

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#277

Earlier quoted context omitted.

In even more fairness, Meta has literally skipped the EU for Threads instead of increasing privacy. In their case, it's just a careful balance of virtue signaling, it had no qualms about pushing their spyware to hundreds of millions of people, violating basic human rights in the process. Check Article 12: https://www.un.org/en/about-us/universal-declaration-of-huma...

Your comment would have been stronger if you left out the piece re: the Universal Declaration of Human Rights, because it's an eye roller. Article 12 is: > No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks. I'm no fan of Meta or the…

>attacks upon his honour and reputation

Yikes, seems like this is built to keep people from saying things about powerful people that they don't like.

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#278
post #201

Earlier quoted context omitted.

Your comment would have been stronger if you left out the piece re: the Universal Declaration of Human Rights, because it's an eye roller. Article 12 is: > No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks. I'm no fan of Meta or the…

> voluntarily downloading an app that's all true until an app becomes the only way to interact with certain groups of people. i certainly wouldn't call my usage of Discord voluntary. it doesn't actually matter how often i read their privacy policy and shake my head. either I break off contact with a large part of the internet that's important to me or I begrudgingly agree "voluntarily" to their terms and conditions.

So what you're really complaining about is that other people will not follow your choices. If your relations have such a hard line that a single app is "the only way to interact with certain groups of people", they are the ones to blame, not the maker of the app.

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#279
post #201

Earlier quoted context omitted.

Your comment would have been stronger if you left out the piece re: the Universal Declaration of Human Rights, because it's an eye roller. Article 12 is: > No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks. I'm no fan of Meta or the…

> voluntarily downloading an app that's all true until an app becomes the only way to interact with certain groups of people. i certainly wouldn't call my usage of Discord voluntary. it doesn't actually matter how often i read their privacy policy and shake my head. either I break off contact with a large part of the internet that's important to me or I begrudgingly agree "voluntarily" to their terms and conditions.

I have a mobile phone SIM which only provides customer support over WhatsApp.

Re: Apple says it'll remove iMessage and FaceTime in UK rather than break encryption

#280

i simply prefer not to believe anything that any government or any trillion dollar company says about encryption and privacy. Apple: > "We have never heard of PRISM", "We do not provide any government agency with direct access to our servers" https://web.archive.org/web/20130609061546/https://www.culto... ..some things are just not discussed on public forums.

We now know that PRISM was (is?) the NSA internal source designation for data acquired through FISA warrants executed by the FBI. So actually Apple was being honest. They had not heard of PRISM, because that term was only used inside the NSA. And they were not allowing direct government access to their servers, they were responding to FISA warrants.

While technically true, it's also a complete BS. It's in the same vain as Torrent websites are not hosting copyrighted content - technically true but complete BS.
Post reply on HN