Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

131–140 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#131

Earlier quoted context omitted.

Yeah. I will say, though, I am happy that people are having the uncomfortable realization that they have very little control over what their iPhone does.

Now we just need everyone to have that same realization about almost all the software we use on almost all the devices we own. As a practical matter 99.99% of us operate on trust.

Remember that emission cheating scandal? Where we supposedly had a system in place to detect bad actors and yet it was detected by a rare case of some curious student exploring how things work or some such.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#132

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

> It was illegal to export "strong encryption" for many years, remember? I've seen multiple reports that European lawmakers are planning to require some kind of scanning for CSAM. If this goes into effect, technology isn't going to block those laws for you. Your Purism phone will either be forced to comply or be illegal.

The point is that with a Purism phone or custom ROM on my Android phone, I could disable these "legally required" features, because the law is fucking dumb, and my rights matter more.

The law can ban E2EE, cryptocurrencies, and privacy, but so long as we have some degree of technical freedom we can and will give it the middle finger.

Apple does not offer this freedom. Here we see the walled garden of iOS getting worse and more freedom-restricting by the year. When the governments of the world demand that Apple become an arm of the dystopia, Apple will comply, and its users will have no choice but to go along with it.

Apple, knowing that it is a private company completely and utterly incapable of resisting serious government demands (ie GCBD in China) should never have developed this capability to begin with.

If Apple is going to open this Pandora's box, they ought to open up their devices too.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#133

> Apple generates the on-device perceptual CSAM hash database through an intersection of hashes provided by at least two child safety organizations operating in separate sovereign jurisdictions – that is, not under the control of the same government. Any perceptual hashes appearing in only one participating child safety organization’s database, or only in databases from multiple agencies in a single sovereign jurisdi…

Curious, does any technological system used widely, standup to the threat levels you mentioned?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#134

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

> there's a legitimate "slippery slope" argument

The slippery slope argument is the only useful argument here.

The fundamental issue with their PSI/CSAM system is that they already were scanning iCloud content [1] and that they're seemingly not removing the ability to do that. If the PSI/CSAM system had been announced along side E2E encryption for iCloud backups, it would be clear that they were attempting to act in their users best interests.

But it wasn't, so as it stands there's no obvious user benefit. It then becomes a question of trust. Apple are clearly willing to add functionality at the request of governments, on device. By doing this they lose user trust (in my opinion).

> In the long run, we solve this, at least in liberal democracies, by voting people into office who understand technology, understand the value of personal encryption

But this is clearly not the way it happens in practice. At least in part, we vote with our wallets and give money to companies willing to push back on governmental over-reach. Until now, Apple was one such company [2].

I realize that Apple likely don't "care" about privacy (it's a company, not a individual human). But in a purely cynical sense, positioning themselves as caring about privacy, and pushing back against governmental over-reach on users behalf was useful. And while it's "just marketing" it benefits users.

By implementing this functionality, they've lost this "marketing benefit". Users can't buy devices believing they're supporting a company willing to defend their privacy.

[1] https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-...

[2] https://epic.org/amicus/crypto/apple/

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#135
post #109

Earlier quoted context omitted.

> I really don't understand this view. You are using proprietary software, you are always an N-line change away from someone doing something you don't like. This situation doesn't change this. And I don't understand why it has to be black and white, I think the N is very important in this formula and if it is low that is a cause for concern. Like an enemy building a missile silo on an island just off your coast but p…

The size of N doesn't really matter. I'm sure Apple ships large PRs in every release, as any software company does.

Maybe not if you assume Apple is evil but for the case of Apple being good intentioned but having its hand forced, they will have a much harder time resisting a 1 line change than a mandate to spend years to develop a surveillance system

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#136
post #106
post #48

Earlier quoted context omitted.

Mostly hysterical may technically be an exaggeration, but mostly misinformed, and often dis-informative is not. This isn’t just about people weighing things they dislike more strongly. It’s also about groupthink, confirmation bias, and a lack of curiosity. HN doesn’t have an immune system against straight up misinformation.

> HN doesn’t have an immune system against straight up misinformation. It certainly doesn't! Misinformation and disinformation are terms du jour, but as far as I can tell they are indistinguishable from old-fashioned people-being-wrong-on-the-internet. If you expect an internet forum to be immune from that...well, that's too much to expect. As far as I can tell (and moderating HN for years has really hammered this ho…

Responding to your edit: I think Zepto understands that and tried to direct the conversation that way. For example: https://news.ycombinator.com/item?id=28120649

They even spent time engaging with someone who said CSAM shouldn’t matter by arguing that the fact that lots of the general population cares about it makes it a concern worth thinking about.

Even I did, in my own way: https://news.ycombinator.com/item?id=28165116

Perhaps our responses here are in frustration - that we weren’t able to engage with the matters at hand with people of similar skill and interests. I suppose one way to read your post is that HN isn’t suited for that level of discussion on breaking news with emotional resonance. Maybe another space.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#137

> Apple generates the on-device perceptual CSAM hash database through an intersection of hashes provided by at least two child safety organizations operating in separate sovereign jurisdictions – that is, not under the control of the same government. Any perceptual hashes appearing in only one participating child safety organization’s database, or only in databases from multiple agencies in a single sovereign jurisdi…

Curious, does any technological system used widely, standup to the threat levels you mentioned?

Probably not.

Does any technological system used widely justify itself by saying "it would take two national jurisdictions cooperating to break this?"

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#138
Sounds like it still comes down to trust. Quoting from the paper:

"Apple will refuse all requests to add non-CSAM images to the perceptual CSAM hash database; third party auditors can confirm this through the process outlined before. Apple will also refuse all requests to instruct human reviewers to file reports for anything other than CSAM materials for accounts that exceed the match threshold."

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#139
I don’t like the idea of stuff running on my device, consuming my battery and data, when the only point is to see if I am doing something wrong?

An analogy I can come up with is: the government hires people to visit your house every day, and while they’re there they need your resources (say, food, water, and electricity). In other words, they use up some of the stuff you would otherwise be able to use only for yourself — constantly — and the only reason they’re there is to see if you’re doing anything wrong. Why would you put up with this?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#140
post #9

Their use of the phrase "This claim is subject to code inspection by security researchers like all other iOS device-side security claims" stood out to me. Could someone tell me how that inspection works? Are there researchers who are given the source code? (I posted this on another thread [0] earlier, but it's more relevant here) [0]: https://news.ycombinator.com/item?id=28175619

Apple actually gives special devices to Security Researchers that allow them further access into the device than a normal consumer device: https://developer.apple.com/programs/security-research-devic... In this way, third party security researchers can verify their claims. It actually works out pretty well for them since third party security researchers often find pretty severe vulnerabilities through this program.

[deleted]
Post reply on HN