Live data from Hacker News

WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

theverge.com

121–130 of 372 posts

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#121
post #3

I really hope there is enough momentum to stop this. It's definitely the last straw for me in terms of apple products. I haven't bought a new iphone for 4 years, I'm slowly trying to switch to a lightphone (non smartphone). My mac needs a change but I will probably switch to linux. It's absolutely ridiculous what apple has become. The exact opposite of what they used to represent, when I loved them. God rest Steve Jo…

I find it laughable whenever someone says "this is the last straw" because it just shows how incredibly misinformed they are. Yes, backdooring E2E encryption in general is a bad idea. However, consider two things: * iCloud Photos was never E2E encrypted in the first place. They already can scan your photos all they want server-side, and they have been scanning for CSAM since 2019, while Google has been scanning for i…

> It does NOT scan photos that are not uploaded to the cloud, despite being on-device.

Yet. Once it's on the device, it's a MUCH smaller step to use it in other ways. It's certainly easier fro governments to argue that they should be able to force it to be used arbitrarily... you know, for the children/terrorists/etc.

> And it's important to note the threshold and manual human review system put in place before the authorities receive any notification at all.

Until it's not. Once again, once it's in place, it's a lot easier for malevolent actors (governments) to force it to be used other ways.

This a back door. Plain and simple. The fact that it's not _currently_ going to be used for evil (depending on your definition of evil) does not mean it won't be in the near future. Back doors are bad. How many times does this need to be said?

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#122
post #34
post #9

Earlier quoted context omitted.

> It’s too late either way. The fact that it even got this far through implementation says the vendor is not on my side. Can Apple force people to install this even on devices they already sold?

If you don't use iCloud Photo Library or sync photos to the iCloud, none of this will apply to you. https://daringfireball.net/2021/08/apple_child_safety_initia...

So, you trust Apple to install this spyware and only use it in the way they currently describe. Great!

But what happens the second they get an order from $GOVERNMENT that tells them to use the spyware to also look at other documents on the device?

I think it's pretty obvious what Apple will say. They'll say "OK." They have no plausible deniability to tell $GOVERNMENT to go pound sand - they have demonstrated the capability already! Telling the spyware to scan different files is a trivial change from a technical perspective.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#123

Earlier quoted context omitted.

If this technology is that easily circumvented then why is there an expectation that it will be effective at all?

The CASM scanning happens on device, right? At least so we’ve heard. My sense is Apple is trying to keep CASM off their servers. Scanning phones before it gets there was their solution to what I assume is a government demand/ultimatum. “Do this or we repatriate your foreign entity taxes” or some other shit. I too feel that Apple just caved and eroded trust that took decades to build up. The only way this gets sorted…

> My sense is Apple is trying to keep CASM off their servers

It could (maybe) also be a prelude to enabling E2E encryption for everything in iCloud.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#124
post #120

Earlier quoted context omitted.

The problem I have with this approach is that it introduces on-device scan for images. All what is needed to adopt it to scan for different kind of images is to connect it to different database, say, Winnie the Pooh memes featuring CCP chairman, and boom, jailed dissenters. And ability to scan all images is but a minor firmware update away. Server scanning makes it clear that the company running the servers has acces…

>The problem I have with this approach is that it introduces on-device scan for images. Windows already does this via Windows Defender. This is a basic AV functionality and much more privacy preserving.

But Windows Defender doesn't report you to law enforcement when it believes it found a virus.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#125

Earlier quoted context omitted.

This is worse. If they ban encryption tech sector will kick up enough noise that even non tech people will at least notice. This way, it essentially opens a backdoor. Changing this from scanning hashes of pictures stored locally, to scanning for arbitrary things stored locally probably is not monumental task ( next in line probably hate speech ). And once you have that capability it's hard to argue to governments tha…

I'd say next in line would be stuff oppressive governments don't like. Winnie the Puuh might be front runner along with men standing shirtless in front of tanks.

Everything sold in China, already has that.

Remember ICloud is operated by Chinese company in china.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#126
post #34

Earlier quoted context omitted.

If you don't use iCloud Photo Library or sync photos to the iCloud, none of this will apply to you. https://daringfireball.net/2021/08/apple_child_safety_initia...

So, you trust Apple to install this spyware and only use it in the way they currently describe. Great! But what happens the second they get an order from $GOVERNMENT that tells them to use the spyware to also look at other documents on the device? I think it's pretty obvious what Apple will say. They'll say "OK." They have no plausible deniability to tell $GOVERNMENT to go pound sand - they have demonstrated the capa…

They could have done what you describe at any time in history. This doesn't change anything in that regard. Either you trust Apple enough to use their products or you don't.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#127

Earlier quoted context omitted.

But Apple only plans to scan photos that are synced with iCloud, don't they? So you could just switch to an E2E encrypted alternative and drop iCloud completely.

Yes but it probably took additional code to only scan pictures that are synced to iCloud. Probably not monumental task, to change to scan every picture.

I have to remind again, that iOS is a blackbox, closed source system. All this speculation applies also for a moment before they added anything. They might have had this code ready for years already. All we have is what they say. It is already very trivial to scan everything on on your device and send that metadata. Few lines of code. At the moment when they say about scanning everything in phone publicly without opt-out, then we should be worried. Once again, there is no way telling what they are doing already.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#128
The road to hell is paved with good intentions.

Everything starts off with "won't anyone think of the children?". Next thing you know, Apple is scanning your photos for faces of known "terrorists", etc.

I have children, and hate CP with a passion, but know that this is not the answer.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#129
post #35

So I was ignorant on the issue and completely against the approach of Apple. Then HN taught me that any company storing images on their infrastructure in the US must report pedophilic images to the US government. At this point, the approach taken by Apple seems like the best one to me, if you don't want to store pictures in clear on your servers. What other technical approach are people advocating for? Another point…

The problem I have with this approach is that it introduces on-device scan for images. All what is needed to adopt it to scan for different kind of images is to connect it to different database, say, Winnie the Pooh memes featuring CCP chairman, and boom, jailed dissenters. And ability to scan all images is but a minor firmware update away. Server scanning makes it clear that the company running the servers has acces…

> ability to scan all images is but a minor firmware update away

ios already does on-device ml-based photo categorisation for some time, afaik no way to turn it off.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#130
post #26
post #3

I really hope there is enough momentum to stop this. It's definitely the last straw for me in terms of apple products. I haven't bought a new iphone for 4 years, I'm slowly trying to switch to a lightphone (non smartphone). My mac needs a change but I will probably switch to linux. It's absolutely ridiculous what apple has become. The exact opposite of what they used to represent, when I loved them. God rest Steve Jo…

I blew my entire weekend trying to move off iPhone, to something more trustworthy (a problem that's getting harder, because of some other things going on): https://news.ycombinator.com/item?id=28111995

lineage os is what I use. oneplus devices are simply superb.

but you are forewarned - you can blew through way more then a weekend de-oppressing you digital life.

Post reply on HN