WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan
161–170 of 372 posts
Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan
#162Earlier quoted context omitted.
I still have a company issued laptop (Windows based). I don’t need a laptop for personal stuff.
If you value privacy you won't use a company laptop for personal business.
I have a desktop (not laptop) for my own stuff and a laptop for company stuff and a dock and KVM setup for it.
I am not using the company laptop for personal stuff.
Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan
#163Earlier quoted context omitted.
> Yet I keep seeing this jump. There's no evidence this will happen. Apple can already technically do anything they want to compromise the security of your device in the next software update, so could Google or Samsung or any other company. But when in Apple's history have they done this? There is zero reason to believe this is the next step other than speculation and fear mongering.
> Apple can already technically do anything they want to compromise the security of your device in the next software update But they're making it easier for governments to come along and force them to do more. Or even for themselves, but I tend to think they're less of an issue. I know "it's a slippery slope" gets overused... but if you keep taking baby slips down that slope, it only gets slipperier. You should avoid…
It is as easy as always been. Only problem is that this might give them new ideas. As the most of the politics are probably non-tech people, they don’t know what is possible.
For tech person, functionality like this (on-device scanning and flagging) is super trivial to add. Antivirus engines have existed decades.
Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan
#164Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan
#165Earlier quoted context omitted.
I'm not really sure about feature phones either. Modern Nokia ones come preloaded with Facebook and Whatsapp.
You can remove them from the screen and they are not used unless activated.
Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan
#166Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan
#167Earlier quoted context omitted.
The problem I have with this approach is that it introduces on-device scan for images. All what is needed to adopt it to scan for different kind of images is to connect it to different database, say, Winnie the Pooh memes featuring CCP chairman, and boom, jailed dissenters. And ability to scan all images is but a minor firmware update away. Server scanning makes it clear that the company running the servers has acces…
But Apple only plans to scan photos that are synced with iCloud, don't they? So you could just switch to an E2E encrypted alternative and drop iCloud completely.
I think its more than that. images sent with iMessage are stored in iCloud, even if the device is not necessarily uploading.
How else would that have such warnings they claim in their announcement. [1]
And we have seen these systems have their scope/use case changed in the past [2]
To the point in the other discussion [3]. OP stated that Apples plans to scan and then upload suspected images are illegal. But i would think that they are only scanning images, client side, that users themselves are attempting to upload (either though attachments, or automatic iCloud backups etc) which would put Apple in the clear. In this case that would be iCloud images, or those that piggyback iCloud services like iMessage etc.
[1] https://www.apple.com/child-safety/ [2] https://www.eff.org/deeplinks/2020/08/one-database-rule-them... [3] https://news.ycombinator.com/item?id=28110159
Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan
#168Earlier quoted context omitted.
The CASM scanning happens on device, right? At least so we’ve heard. My sense is Apple is trying to keep CASM off their servers. Scanning phones before it gets there was their solution to what I assume is a government demand/ultimatum. “Do this or we repatriate your foreign entity taxes” or some other shit. I too feel that Apple just caved and eroded trust that took decades to build up. The only way this gets sorted…
As I understand it (and I've not spent too long on this, just picking at various articles) - there are two separate things at play here. Firstly - CASM scanning is done via fingerprinting - the image is fingerprinted on device and when uploaded to iCloud that fingerprint is compared with the "dodgy images" fingerprints and an alert raised if a threshold of matches is reached (what's the threshold and with whom?) Seco…
Nope. The comparison is done on the device and the threshold is set there as well.
I am not sure how alarmed I am yet at this whole affair but I do know that maybe 50% of posts I read about this have glaringly incorrect information which definitely dampers my alarmism.
Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan
#169So I was ignorant on the issue and completely against the approach of Apple. Then HN taught me that any company storing images on their infrastructure in the US must report pedophilic images to the US government. At this point, the approach taken by Apple seems like the best one to me, if you don't want to store pictures in clear on your servers. What other technical approach are people advocating for? Another point…
Simple. 1. Encrypt everything. 2. Don't store images on your servers at all. There's nothing to report if all you have is some encrypted blob. Alternatively, just don't consume any user data at all. Data is and should be a massive liability.
My thoughs as well.
If you don't want there very dangerous weapon you have thought out to be abused, don't create a physical assembly of it and don't tell anyone who has a habit of abusing powerful weapons.
Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan
#170Earlier quoted context omitted.
Source? I am not aware of a law in the US that requires Apple to actively scan images, or to store them unencrypted (or keep copies of the keys).
Every cloud infrastructure holder is required for doing that. Closing an eye does not take a duty away. You must be actively pursuing that. Encryption would start flood of new laws https://www.govinfo.gov/app/details/USCODE-2011-title18/USCO...