Live data from Hacker News

Apple Has Opened the Backdoor to Increased Surveillance and Censorship

eff.org

121–130 of 323 posts

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#121

Guarantee they will begin scanning your devices for unauthorized copyright material very soon if they have not already.

For many years, anti-virus vendors were able to do that. Why haven't those vendors been already co-opted by governments (Kaspersky on the Russian side, Microsoft in the USA side) into scanning for illegal, copyrighted or secret material and reporting on it?

Even open source products like ClamAV rely on a opaque database of virus strings.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#122

Guarantee they will begin scanning your devices for unauthorized copyright material very soon if they have not already.

Didn't iMusic or whatever upload users' personal high quality files to cloud, to stream them back in lower quality, and then deleted the originals from the users devices? I remember something like that making the news. Imagine being a musician and Apple deletes your originals to stream your own music back to you in low quality.

Yes, it did something like that. If and only if the user signed up for, paid for, and enabled the iTunes Match service, the whole point of which is to replace your local files with cloud music. (I don’t find this desirable myself, but I can see how some people might have.)

Apple screwed up big time in the functionality and messaging around it and some people found their original files deleted when they weren’t expecting it. Big problem.

But it was hardly some plot to scan users’ hard drives for copyrighted content and delete it. On the contrary, iTunes Match would happily launder a whole library full of pirated low-quality MP3s into legal, high quality, DRM-free AAC files.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#123

My opinion about: 1. Every pedophile know about the existence of this system, so I don't think it will be useful to fight those monster, maybe only marginally; 2. Anyway, is that legal ? Even if some crazy store material on his Apple hardware isn't that illegal search non usable in law courts ? 3. Child abuse is often used as Trojan horse to introduce questionable practice. What if: - the system is used to looking fo…

Of course it would be possible to implement content search, profiling and reporting mechanisms for such content, but this seems to be a singularly bad platform for that sort of search.

The image profiles are part of the OS so there's no mechanism to deliver image profiles separately for different countries. Also when the threshold number of matching images is reached, the matches are reported to a manual reviewer at Apple not a government. It only checks images on upload to iCloud photo storage.

So of course each of these limitations of the system could be changed, but you'd really need to change all of them and at that point you've created a completely different system. There's no simple change to this system that would suddenly turn it into a snitch for e.g. China or Saudi Arabia.

I've seen exactly the same objections raised every time any kind of device content search has become mainstream. Back in the 90s it was virus checking (Do you trust the AV company? What if they were bribed by the content companies?), full device indexing and search (Do you trust the OS vendor? What if they're in league with the government?). I'm very surprised this didn't blow up when Apple implemented ubiquitous image text recognition. Maybe it did. AV and device indexing mechanisms, which are ubiquitous, seem like a far more vulnerable target for such requirements.

So I don't really buy the slippery slope argument. In theory any government could pass a law requiring any company operating in it's jurisdiction to do anything, with an implementation suitable to that actual purpose. Of course this mechanism is motivated by laws in the US so it's a perfect example of exactly that, and it's a completely new system not a slippery slope subversion of an existing one. The real slippery slope here is legislative, not technical and I think that should be far, far more concerning.

I do think the legal and moral questions about this mechanism are legitimate. I think it would make more sense for Apple to scan photos in their cloud storage on the cloud storage rather than on upload. I understand there are theoretical privacy benefits to users from this implementation but the optics of having user's devices snitch on them are all wrong.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#124
post #31

Earlier quoted context omitted.

The only thing that prevents Apple, Microsoft, or Ubuntu from executing arbitrary code on your system is their promise to keep the scope of updates limited. You already operate under this trust model.

but once a system is in place, it becomes easier to do things that are a variation on what that system already does. As opposed to doing it from scratch. Also, I think the outcry would be larger if they did it from scratch compared to if they did it as an extension to some existing, known capability. If that's the case, they'd have less to lose in doing such a thing if the base system is already in place.

Great explainer why this won’t happen:

https://pingthread.com/thread/1424873629003702273

> For the conspiracy to work, it'd need Apple, NCMEC and DOJ working together to pull it off voluntarily and it to never leak. If that's your threat model, OK, but that's a huge conspiracy with enormous risk to all participants

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#125

There is another information leak that I have not seen mentioned in any news report. If an image hash matches the CSAM database, then it is sent to Apple, encrypted and with the “safety voucher”. Apple can decrypt the image only if they receive enough vouchers, and so they claim that they do not have any information about the user in case the number of vouchers is lower than the threshold. But actually they do have i…

There is strong evidence, that E2EE backups are coming. How about hold our horses until actual release of iOS 15?

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#126

I don't get people. It's not fucking E2E encryption when it is being scanned. That's just trying to change what encryption means.

While this true, you can’t say that it is worse than current state. (Only server side encryption, plaintext in the eyes of Apple)

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#127

Earlier quoted context omitted.

> Just ask your parents or your non-tech friends if it's "ok" to scan people's phones to find those "bad pedophiles" in order to jail then up for the rest of their life. You will be surprised how much support Apple's initiative has in the broad public. My Dad is an old teacher today and was formerly a farmer. My view is he clearly understands these issues and has done since I was a teenager sometime in the last mille…

> once this system is in place it will be used for anything, not just photos The system seems designed to make it hard to use it for anything else. How will a hash driven by a visual perception based neural net be used on ZIP files? How can you add ZIP files to your iCloud Photo Library? Sure, Apple could possibly do any number of bad and worse things. It’s a matter of trust that every time we update our iPhones that…

I think the main issue is just that Pandora's box is now open. Once you make this move, you can't go backwards.

If you'll indulge me, would you bet $1000 that this style of scanning isn't expanded in the next 3 years to include non-CSAM content?

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#128
post #6

An Apple recruiter recently reached out to me. I am in a fortunate position to turn down opportunities, so I made sure to explain that I am not interested in working for a company that is at the forefront of enabling further infringement on people's privacy. If you are able to push back, do it in any small way that you can.

Well done, I'm with you. I've being doing similar in the games industry for years. If we, the actual makers stand against immoral action it will both build pressure and incentive for alternative ways of doing business.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#129
post #6

An Apple recruiter recently reached out to me. I am in a fortunate position to turn down opportunities, so I made sure to explain that I am not interested in working for a company that is at the forefront of enabling further infringement on people's privacy. If you are able to push back, do it in any small way that you can.

In many ways Apple is also the world leader on consumer privacy, pushing for changes when the rest of the industry is walking in the opposite direction. Paying with Apple Pay makes you safer because it gives out minimal payment information; the Target fiasco would've been avoided. Sign in with Apple allows users to provide minimal information in signing up for accounts; the idea that casual users should know how to s…

> is also the world leader on consumer privacy

is also an early PRISM adopter and well known on cooperation with totalitarian regimes. Censoring Belarus protesters happened several months ago.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#130
post #121

Guarantee they will begin scanning your devices for unauthorized copyright material very soon if they have not already.

For many years, anti-virus vendors were able to do that. Why haven't those vendors been already co-opted by governments (Kaspersky on the Russian side, Microsoft in the USA side) into scanning for illegal, copyrighted or secret material and reporting on it? Even open source products like ClamAV rely on a opaque database of virus strings.

Top of that, there are many other tools which can do all the same. People are thinking like this has been hard work to add right now, and now future exploiting comes easier. Hard part has been creation of system, which locks Apple out of your pictures. Scanning your system files and sending some metadata is literally few lines of code and could have been pushed on week anytime in the past.
Post reply on HN