Live data from Hacker News

Apple Has Opened the Backdoor to Increased Surveillance and Censorship

eff.org

111–120 of 323 posts

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#111

My opinion about: 1. Every pedophile know about the existence of this system, so I don't think it will be useful to fight those monster, maybe only marginally; 2. Anyway, is that legal ? Even if some crazy store material on his Apple hardware isn't that illegal search non usable in law courts ? 3. Child abuse is often used as Trojan horse to introduce questionable practice. What if: - the system is used to looking fo…

Perhaps we should also rise again the question about who controls own computer because any abuse starts there.

Only full control over own device can prevent abuses. Especially when device comes any close to definition of being personal. You should be able to install own software on the personal device. Including os and bios/firmware.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#112

Earlier quoted context omitted.

If you are not compiling your operating system, every library and every application from scratch then you are blindly trusting third parties. And if you are assuming Apple can't be trusted when they say they won't expand this to non-CSAM use cases then not sure why you would then trust Microsoft, Ubuntu etc.

> If you are not compiling your operating system, every library and every application from scratch then you are blindly trusting third parties. This implies that trust is always the same and that if you trust one entity (because you did not event limit your answer to corporations) you are supposed to trust everyone and if that is not the case then you have some kind of logical error in your thinking. It also implies…

That makes sense—so long as you lose trust in the entity when they actually betray that trust.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#113
post #82
post #38

Earlier quoted context omitted.

Sorry, but I do not believe that is what the leak revealed. There was a slide that indicated that data from Apple and other companies was now part of the PRISM program. I am not trying to deny or refute Snowden's whistleblowing. I think it is highly likely that PRISM exists. What I dispute are the speculations that the companies listed are complicit. The 2012 date is quite suspicious - it is precisely the same year t…

> I personally think that PRISM works by externally intercepting data communication lines running to these facilities. Similar to the rumors that international comms links have been tapped. The companies themselves have not participated, but the data path has been compromised. That wouldn't work without the company being at least passively complicit. Links between datacenters are encrypted. If you want even basic PCI…

This thinking is based on trusting "encrypted" links. Did you build the hardware that drives these links? Did you audit the Verilog or code that operates this hardware?

I know of at least one way a to implement a "secure" TLS product that you could purchase and deploy in your datacenter that would leak all of the the keying material to compromise every data connection to the NSA. You would be 100% in compliance of all technical requirements, but your data would be utterly transparent. You would not be able to detect this using an internal or external audit.

Did you purchase your rack-to-rack equipment from the equivalently Trojaned "Solar Winds" vendor? The "Solar Winds" event was a "commercially" botched exploit.

Sorry, NSL(s) do not scale. It is an ever expanding "circle of trust".

Containing secrets is only effective if they are only shared within "your shared culture" and your culture is very stable -- nobody leaves because of a difference of opinion.

NSL can only be effective if nobody knows.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#115

Earlier quoted context omitted.

So why wouldn't that same whisteblower complain if Apple expands their CSAM detection system to other use cases ? And iOS is a modular operating system. They could easily swap out the Photos.framework for different state actors and support that in perpetuity. They were already doing this when cross-building for ARM/x86.

> So why wouldn't that same whisteblower complain if Apple expands their CSAM detection system to other use cases ? I assume Apple could make it very difficult, if not impossible, to detect what they're searching for when they are using hashes created and transmitted by all their own hardware and software. But, even if they did publish the hashes and those were somehow verified in free-press countries by a trusted 3r…

> I assume Apple could make it very difficult, if not impossible, to detect what they're searching for when they are using hashes created and transmitted by all their own hardware and software.

Correct, it would be easy to slip in additional hashes without the team knowing what those hashes represented.

HOWEVER, as soon as these additional hashes match something, the first person to see them will be an Apple employee performing manual review. When they see a picture of Winnie The Pooh or a photograph of some classified spy plane, they're going know that the CSAM system is being used for purposes other than CSAM.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#116
post #95
post #77

Earlier quoted context omitted.

They didn't pull out. Apple discloses over 30,000 customers' data each year without a warrant under PRISM (aka FISA 702) as disclosed in their own transparency report (listed under "FISA orders"). PRISM is just the internal NSA name for it. It continues unabated.

FISA orders are written by a Judge. Only judges can write these, this is the literal definition of a warrant. Warrants require specifics - Person X, person Y. These are enumerable. There is paperwork. PRISM, based on the data available, is all about consuming data WITHOUT a warrant -- vacuuming data associated with identities that are not associated with ANY identities subject to a court order. Violating laws and pos…

Judges can write lots of orders but that doesn't make them search warrants which are defined by the US constitution as requiring probable cause. FISA court orders are not search warrants.

FISA Amendments Act (FAA) section 702 is the legal basis claimed by the NSA in a secret interpretation by the FISA court as the basis for PRISM targeted collection without search warrants, including US persons/citizens.

It's on Wikipedia if you don't believe me:

https://en.m.wikipedia.org/wiki/Foreign_Intelligence_Surveil...

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#117

My opinion about: 1. Every pedophile know about the existence of this system, so I don't think it will be useful to fight those monster, maybe only marginally; 2. Anyway, is that legal ? Even if some crazy store material on his Apple hardware isn't that illegal search non usable in law courts ? 3. Child abuse is often used as Trojan horse to introduce questionable practice. What if: - the system is used to looking fo…

Perhaps we should also rise again the question about who controls own computer because any abuse starts there. Only full control over own device can prevent abuses. Especially when device comes any close to definition of being personal. You should be able to install own software on the personal device. Including os and bios/firmware.

*laughs in Minix land

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#118

There is another information leak that I have not seen mentioned in any news report. If an image hash matches the CSAM database, then it is sent to Apple, encrypted and with the “safety voucher”. Apple can decrypt the image only if they receive enough vouchers, and so they claim that they do not have any information about the user in case the number of vouchers is lower than the threshold. But actually they do have i…

Not just that, random folks can send you media through multiple ways & you could get embroiled unnecessarily too, innocuous QR code might automatically download an image if your apps are configured that way.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#119

Pushing Spyware Engine is literally abuse to all people including children and it's much worse then any problem they would claim to fight. Even if you believe them. By this move people are indoctrinated with the idea that being watched by someone big and powerful is Ok. They learn to accept such abuse and what can be worse for any safety of anyone than learning that? If one is serious about any safety one should lear…

So this one time I was tasked to verify a complaint of child pornography and image the infrastructure for evidentiary purposes, if necessary. It was the first time I’d ever been exposed to it as a naïve operations kid at a hosting provider.

Imagine my surprise and horror to find that not only was the complaint accurate, it led to a completely polished thumbnail site on par with PornHub. Boom, right there, no login. No nothing. Five high, seven wide thumbnails. No two of the same child. A complete search engine based on Solr that could filter the thousands of images by age of the victim. By the number of adults participating in the rape. A threaded comment section on each image where people discussed children in their neighborhood and their fantasies of abducting them. An erotic literature section where parents wrote about how they’ve been sexually attracted to their children since changing their first diaper.

I’ll never forget a photo of two men brutally raping a girl of about 9 or 10, because it was one of the highest voted on the site. One of the comments, which I still remember when I close my eyes at night, simply said “its better when they cry”. It’s been eleven years and I’ve seen and dealt with much more of it since then, and I still weep to this day thinking about the pain inflicted on those children, the pure evil of those who enjoy it, and even the design and engineering team who bafflingly put their skills toward building that nadir of human achievement.

Tell me again what “the real abuse” is and educate me, please, because you sound pretty confident that the frighteningly common story I just told isn’t that big of a deal. I can’t believe anyone sane would compare going through your photo collection, even egregiously, to the rape and exploitation of children and think, yeah, you know, based on my value system door number one is the “much worse” injustice. Your opinion is fucking sickening and the exact type of detached inhumanity that is poisoning this industry top to bottom.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#120
post #81

Earlier quoted context omitted.

I do not. It would be helpful to enumerate the specifics of this rather than to play the role of a cheshire cat and say nothing. (I am independently looking for this, but cannot currently confirm)

Sorry, I thought it was part of the collective. ICYMI: https://slate.com/technology/2013/10/nsa-smiley-face-muscula...

Thanks.

This can be entirely explained if the NSA had already performed a "solar winds" supply chain attack on the vendor that supplied the TLS encrypt / decrypt endpoints. Is the vendor of that hardware known or discoverable?

Google would have no idea the traffic could be intercepted. The NSA could use the Smiley face, perhaps with a nudge, nudge, wink, they are now a "supplier of data" on slides.

Post reply on HN