Live data from Hacker News

Apple Has Opened the Backdoor to Increased Surveillance and Censorship

eff.org

101–110 of 323 posts

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#101

My opinion about: 1. Every pedophile know about the existence of this system, so I don't think it will be useful to fight those monster, maybe only marginally; 2. Anyway, is that legal ? Even if some crazy store material on his Apple hardware isn't that illegal search non usable in law courts ? 3. Child abuse is often used as Trojan horse to introduce questionable practice. What if: - the system is used to looking fo…

I agree!

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#102
post #95
post #77

Earlier quoted context omitted.

They didn't pull out. Apple discloses over 30,000 customers' data each year without a warrant under PRISM (aka FISA 702) as disclosed in their own transparency report (listed under "FISA orders"). PRISM is just the internal NSA name for it. It continues unabated.

FISA orders are written by a Judge. Only judges can write these, this is the literal definition of a warrant. Warrants require specifics - Person X, person Y. These are enumerable. There is paperwork. PRISM, based on the data available, is all about consuming data WITHOUT a warrant -- vacuuming data associated with identities that are not associated with ANY identities subject to a court order. Violating laws and pos…

[deleted]

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#103

A question to you legal experts out there: if a potential CSAM match is found during client-side scanning, but such a match has not yet been confirmed by an Apple employee to actually be CSAM, does Apple have the option, legally speaking, to SIMPLY DELETE the "gray-area" content in-place (just like a regular virus scanner), instead of sending it to Apple for further analysis? Someone performs "an implication by malic…

It seems like this system was designed specifically so that this would be impossible, and such a feature would go against what seem to be design goals of this system.

They went through the trouble of making this whole “private set” matching so that the client does the matching but doesn’t know the result of the matching. Only the server can (once enough matches are made that the key is available).

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#104
There is another information leak that I have not seen mentioned in any news report. If an image hash matches the CSAM database, then it is sent to Apple, encrypted and with the “safety voucher”. Apple can decrypt the image only if they receive enough vouchers, and so they claim that they do not have any information about the user in case the number of vouchers is lower than the threshold.

But actually they do have information: they know that a user has a specific number of images which are perceptually similar to known CSAM material. This information is not conclusive, but it’s also not nothing. For example, could a court order Apple to release the unencrypted iCloud backups of all users who had at least one match?

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#105
post #6

An Apple recruiter recently reached out to me. I am in a fortunate position to turn down opportunities, so I made sure to explain that I am not interested in working for a company that is at the forefront of enabling further infringement on people's privacy. If you are able to push back, do it in any small way that you can.

I don't want to be that guy, but for this job there were lining up 300 more people. Nobody except of a tiny group of nerdy guys (including myself, ofc) is against this apple csam move. Just ask your parents or your non-tech friends if it's "ok" to scan people's phones to find those "bad pedophiles" in order to jail then up for the rest of their life. You will be surprised how much support Apple's initiative has in th…

> You will be surprised how much support Apple's initiative has in the broad public.

I wouldn't be, but that's not the issue, the broad public is gullible, the overwhelming majority probably still believe that Iraq had WMDs before invasion.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#106
post #31

Earlier quoted context omitted.

> It scans your photos, for known CSAM images No, it scans photos for arbitray (fancy) hashes, and Apple chooses to limit it to CSAM images. Nothing about the tech prevents it from being expanded to other kinds of images. And from what I understand, nothing prevents it from being expanded to other filetypes either, does it? The only thing that ties this tech to CSAM images is Apples promise (and claim) to keep the sc…

The only thing that prevents Apple, Microsoft, or Ubuntu from executing arbitrary code on your system is their promise to keep the scope of updates limited. You already operate under this trust model.

but once a system is in place, it becomes easier to do things that are a variation on what that system already does. As opposed to doing it from scratch.

Also, I think the outcry would be larger if they did it from scratch compared to if they did it as an extension to some existing, known capability. If that's the case, they'd have less to lose in doing such a thing if the base system is already in place.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#107
post #81

Earlier quoted context omitted.

> I wonder where all of the network cables go? Remember the smiley face in the slide deck?

I do not. It would be helpful to enumerate the specifics of this rather than to play the role of a cheshire cat and say nothing. (I am independently looking for this, but cannot currently confirm)

Sorry, I thought it was part of the collective. ICYMI:

https://slate.com/technology/2013/10/nsa-smiley-face-muscula...

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#108
post #6

An Apple recruiter recently reached out to me. I am in a fortunate position to turn down opportunities, so I made sure to explain that I am not interested in working for a company that is at the forefront of enabling further infringement on people's privacy. If you are able to push back, do it in any small way that you can.

In many ways Apple is also the world leader on consumer privacy, pushing for changes when the rest of the industry is walking in the opposite direction. Paying with Apple Pay makes you safer because it gives out minimal payment information; the Target fiasco would've been avoided.

Sign in with Apple allows users to provide minimal information in signing up for accounts; the idea that casual users should know how to setup email aliases is a joke. Apple private relay is the closest to getting grandma to use TOR. Apple is working on stopping pixel tracking in email.

Apple is also leading on the story of user permissions, which is a broken model where you blame users for accepting all the snooping in their lives, for not reading the TOS, and for their failure to negotiate against Walmart.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#109

Guarantee they will begin scanning your devices for unauthorized copyright material very soon if they have not already.

Didn't iMusic or whatever upload users' personal high quality files to cloud, to stream them back in lower quality, and then deleted the originals from the users devices? I remember something like that making the news. Imagine being a musician and Apple deletes your originals to stream your own music back to you in low quality.

[deleted]

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#110
post #31

Earlier quoted context omitted.

The only thing that prevents Apple, Microsoft, or Ubuntu from executing arbitrary code on your system is their promise to keep the scope of updates limited. You already operate under this trust model.

but once a system is in place, it becomes easier to do things that are a variation on what that system already does. As opposed to doing it from scratch. Also, I think the outcry would be larger if they did it from scratch compared to if they did it as an extension to some existing, known capability. If that's the case, they'd have less to lose in doing such a thing if the base system is already in place.

> but once a system is in place

No, the GP was correct. As soon as any closed-source software implements automatic software updates, you've always one malicious update away from the system betraying you. Having "a system in place" for doing potentially evil things is unnecessary. Interim steps of any kind are unnecessary.

What Apple has done this week doesn't bring the iPhone closer or further to your hypothetical dystopia than it already was. Or Chrome, or Windows, or Android, etc. They update themselves. Every update your devices have done in the past decade could have betrayed you.

Anything that automatically updates is always one step away.

Post reply on HN