Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

161–170 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#161

Earlier quoted context omitted.

Even if someone went browsing for it, yes that's illegal but there's no benefit in their therapist reporting them for just visiting terrible websites. But also there are definitely ways to get accidentally exposed. That's an absolutely awful thing to call the cops over.

I think you're demonstrating incredibly poor judgment here. CSAM is a crime with real victims. Even if your patient came across it innocently, someone is out there intentionally distributing it and that needs to be investigated.

Have you considered the implications of what you're saying?

A whistleblower goes to a therapist, stressed out over their pending decision to reveal official misconduct. They've been investigating ways to post something on the internet that can't be immediately taken down by the corrupt government officials they want to expose. They express their discomfort, in confidence, to their therapist, about using something they've discovered is also used for CSAM.

You think it's a good thing for the therapist to be required to report this? Should they report that the patient admitted to viewing CSAM with no context so the whistleblower gets investigated and arrested, or should they provide the context -- that the patient is about to expose the corruption of the government receiving the report?

For that matter, consider what it does when someone is actually a pedophile. They find out that if they try to seek therapy to address their perverse attraction to kids, the therapist isn't allowed to keep their confidence and they'll be arrested, so instead of seeking professional help, they keep abusing kids. Is that the result we wanted? There is a reason doctor-patient confidentiality was a thing.

Re: Apple defeats liability for not scanning iCloud for CSAM

#162
post #62

Earlier quoted context omitted.

I don't think these are the same. Outlawing CSAM gives law enforcement the ability to shutdown markets and prevent commercial distribution of CSAM. Sexually abusing children is heinous, but sexually abusing children for financial gain is even worse.

There are even people involved in commercial distribution of it that claim to not even be interested in children, just in profit or even allegedly “for a sense of community” (someone actually said this after getting caught, he was in his 20s but I can’t remember his name — he might have been one of the red room guys). On top of that, while there are different types of child abusers, the worst ones almost invariantly…

[deleted]

Re: Apple defeats liability for not scanning iCloud for CSAM

#163
post #91

Earlier quoted context omitted.

Owning your device (instead of the manufacturer, a set of unlisted governments, big software corporations, etc.) means no scanning.

It also means no banking app will work

Banks are probably the most Orwellian surveillance apparatus of all. Almost every time I read an arrest warrant there is a whole section where banking records are used to damn someone. The equivalent level of banking privacy to graphene is roughly walking in to the teller to withdraw a few thousand cash once a month and then paying literally everything with that (or an anonymized crypto).

Re: Apple defeats liability for not scanning iCloud for CSAM

#164

Earlier quoted context omitted.

I think you're demonstrating incredibly poor judgment here. CSAM is a crime with real victims. Even if your patient came across it innocently, someone is out there intentionally distributing it and that needs to be investigated.

Have you considered the implications of what you're saying? A whistleblower goes to a therapist, stressed out over their pending decision to reveal official misconduct. They've been investigating ways to post something on the internet that can't be immediately taken down by the corrupt government officials they want to expose. They express their discomfort, in confidence, to their therapist, about using something the…

I used to have a good friend that was a stripper (I promise, I wasn't the client...). Some of her biggest customers were people that wanted therapy without the paper trail of going to a licensed therapist. This is a big thing for pilots as well, since their health records and mental care are intensely scrutinized. A stripper will provide comfort, verbal relief, and physical love for $100 hour you can tell them anything and their reputation is bad enough no one will bother to believe them if they say something bad about you.

Re: Apple defeats liability for not scanning iCloud for CSAM

#166

Earlier quoted context omitted.

Our society is pretty aligned that distribution is another kind of harm. Non-consented distribution of sexual images (eg: revenge porn) is also a crime. Children don’t need to be the ones to press charges in child porn unlike with adults. That’s a good thing.

> Our society is pretty aligned that distribution is another kind of harm. As well as possession. I don't actually know if those are different for CSAM, but I would assume so because they are for drugs.

Meh, I assume "possession" (of drugs) is how the law is worded because otherwise law enforcement would have to catch someone in the act of using or distributing, which must be much harder to do.

Mere possession of a substance is surely not what society cares about.

Re: Apple defeats liability for not scanning iCloud for CSAM

#167

Earlier quoted context omitted.

I think you're demonstrating incredibly poor judgment here. CSAM is a crime with real victims. Even if your patient came across it innocently, someone is out there intentionally distributing it and that needs to be investigated.

Have you considered the implications of what you're saying? A whistleblower goes to a therapist, stressed out over their pending decision to reveal official misconduct. They've been investigating ways to post something on the internet that can't be immediately taken down by the corrupt government officials they want to expose. They express their discomfort, in confidence, to their therapist, about using something the…

Well, in the jurisdictions that I care about the courts and lawmakers have already decided this and the legal requirement is to report.

If its your license to practice on the line you know what choice you're going to make.

Re: Apple defeats liability for not scanning iCloud for CSAM

#168
post #155
post #64

Earlier quoted context omitted.

The world where the operating system on my phone (GrapheneOS) isn't conspiring against me or uploading my files to someone else's computer.

But you still need backups right? For most people "the cloud" is where you backup stuff. If you have a personal backup strategy that doesn't involve the cloud, you are not "most people". Doing backups the right way take some skill and investment if you want to do it by yourself. It may involve setting up a NAS, and some discipline with physical media. You have to do your own security too. Most people don't want to do…

> But you still need backups right?

I back up files to my own cloud with a Nextcloud integration for Android. That being said, a monthly or so backup of devices via USB/Ethernet, like we used to in the pre-cloud area, would be enough for all intents and purposes. It's not like what people have on their phones is generally very valuable.

Re: Apple defeats liability for not scanning iCloud for CSAM

#169

Earlier quoted context omitted.

Beyond the privacy marketing angle, e2e allows companies with global exposure to sidestep any unpleasantness when they get a subpoena from Bumfuck, Nowhere. Sure, the NSA, GCHQ and Mossad have a way to exfiltrate the unencrypted data but proprietary e2e is a good thing for most people IMO. Shifts the risk from "my messages are theoretically available to most law enforcement in the globe" to "YOU’RE STILL GONNA BE MOS…

Side channel is academic at best. Watching memory changing on a complex code base without having said code base is near impossible. 1. Run code 2. Watch memory changes 3. Correlate those to real data If your code is doing anything complicated that's an intense thing to determine. If you're deep enough for a side channel there's likely a lot easier way of getting in.

Brainfart on my part. I was referring to what @majorchord was worrying about, the unencrypted messages in the client get exfiltrated and get sent to the spooks using steganography on some benign request, edited my comment.

My mental model is that most competent intelligence agencies have a PRISM 3.0 deal with FAANG, including on E2E products or at least have devs on the payroll. I imagine that any backdoor is only used on important targets, so no intel sharing with Cletus the deputy.

Re: Apple defeats liability for not scanning iCloud for CSAM

#170

Earlier quoted context omitted.

Yes that's exactly his point. E2E is often sold as preventing the owners of the server from being able to read the messages at all, even if they are evil and misleading you. That's obviously only the case if they aren't also the sole providers of the "ends".

There are actual methods to do this though just not sure anyone does it yet. 1. 3rd party audit of a current repo hash 2. Public hosting of hash 3. Modern attested compute can check the current startup and running code hash and return to the user for their own checks. 4. User encrypts the last known hash they used or trust a 3rd party to perform the check like azure's methods. Another way is to open source it and rep…

I seem to recall that Apple provided an audit
Post reply on HN