Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

181–190 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#181
post #64
post #55

Earlier quoted context omitted.

That’s where I’m at. They could have just started doing this without even saying anything at all.

But in that case they would eventually be caught red-handed and won't get to do the "for the children" spiel and get it swept under the rug like it's about to be.

The goal is not for it to be swept under the rug. The goal is for it to deflect concerns over the coming Privacy Relay service.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#182

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

I agree that this is a policy issue. The EU passed a new law just a last month regarding this [0].

I thought this was the implementation for the EU. If it was - it was fast?

[0] https://news.ycombinator.com/item?id=27753727

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#183
> The system is designed so that a user need not trust Apple, any other single entity, or even any set of possibly-colluding entities from the same sovereign jurisdiction (that is, under the control of the same government)

Who's to say authoritarian governments don't team up? We just saw this happen over the last decade with the rise of nationalism everywhere.

We already know governments can put significant pressure on private companies. Don't capitulate, Apple. Blow the whistle. You're getting screwed and you have our support if you just stand up for what you said 5 years ago.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#184

What’s not discussed in this Paper is how it won’t be used by third-party actors to falsely accuse someone. Does nobody remember the iCloud hack? What about instead of downloading Jennifer Lawrence’s photos, a hacker uploaded children to get someone falsely accused?

Google, Microsoft and a bunch of other services already scan for CSAM materials, yet this hasn’t been an issue so far. In fact I can’t really find a single case when someone was framed like this, despite how easy it is to fill someone’s account with CSAM and call the cops/wait. I don’t like the privacy and property rights issues of this but the whole someone will use this to frame someone is quite BS.

1) how would you know someone's being framed if it's not detected as such? in this case it just looks like the target had CSAM on their machine/account and they are found guilty, despite their objections, maybe because no-one really looked closely at the evidence, or it was planted well enough.

2) if it is detected as a plant. Would you know it? Would it fly above our radar? There is evidence this happens [1], some cases are quite high profile [2].

3) This technique is already in use. Russia is allegedly using it to discredit opponents [3]. Do you think you would hear from it if it was done by secret services of any country to discredit or get rid of foreign targets or even some at home?

4) it's the ultimate weapon against foes and opponents. It's a dangerous one but I have to wonder how many estranged spouses get revenge planting evidence [4], or how many journalists or troublemakers have been the recipient of some carefully crafted planting. I mean, nearly anyone reading HN could do it sufficiently well to get someone in serious trouble, it's not really a technical issue so it's not hard to imagine it's being done.

[1]: https://www.independent.co.uk/news/uk/crime/handyman-planted...

[2]: https://www.miaminewtimes.com/news/shaq-hit-with-lawsuit-for...

[3]: https://www.nytimes.com/2016/12/09/world/europe/vladimir-put...

[4]: https://www.crimeonline.com/2019/07/04/wife-plants-child-por...

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#185
post #51
post #22

Earlier quoted context omitted.

> And there is no way to audit that the database is what they claim it is, doesn't contain multiple databases that can be activated under certain conditions, etc. Although this is true, the same argument already applies to "your phone might be scanning all your photos and stealthily uploading them" -- Apple having announced this program doesn't seem to have changed the odds of that. At some point you have to trust yo…

Which is why I am confused by a lot of this backlash. Apple already controls the hardware, software, and services. I don't see why it really matters where in that chain the scanning is done when they control the entire system. If Apple can't be trusted with this control today, why did people trust them with this control a week ago?

They risk a whistleblower if they don't announce this news while implementing that in a country with a free press.

It's better to be forthright, or you risk your valuation on the whims of a single employee.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#186
A key point that needs to be mentioned: we strongly dislike being distrusted.

It might well be a genetic heritage. Being trusted in a tribe is crucial to survival, and so is likely wired deep into our social psychology.

Apple is making a mistake by ignoring that. This isn’t about people not trusting Apple. It’s about people not feeling trusted by Apple.

Because of this, it doesn’t matter how trustworthy the system is or what they do to make it less abusable. It will still represent distrust of the end user, and people will still feel that in their bones.

People argue about the App Store and not being trusted to install their own Apps etc. That isn’t the same. We all know we are fallible and a lot of people like the protection of the store, and having someone to ‘look after’ them.

This is different and deeper than that. Nobody want to be a suspect for something they know they aren’t doing. It feels dirty.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#187

I don’t like the idea of stuff running on my device, consuming my battery and data, when the only point is to see if I am doing something wrong? An analogy I can come up with is: the government hires people to visit your house every day, and while they’re there they need your resources (say, food, water, and electricity). In other words, they use up some of the stuff you would otherwise be able to use only for yourse…

So 3rd amendment defense? These are digital soldiers being quartered in our digital house.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#188

What’s not discussed in this Paper is how it won’t be used by third-party actors to falsely accuse someone. Does nobody remember the iCloud hack? What about instead of downloading Jennifer Lawrence’s photos, a hacker uploaded children to get someone falsely accused?

Google, Microsoft and a bunch of other services already scan for CSAM materials, yet this hasn’t been an issue so far. In fact I can’t really find a single case when someone was framed like this, despite how easy it is to fill someone’s account with CSAM and call the cops/wait. I don’t like the privacy and property rights issues of this but the whole someone will use this to frame someone is quite BS.

Here is one case which was allegedly caused by malware. Several people were arrested and subsequently acquitted.

I would say that the opt-out preference on iPhones that by default uploads all photos to iCloud combined with a remote execution payload like Pegasus would render such an attack plausible.

https://en.wikipedia.org/wiki/United_States_v._Solon?wprov=s...

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#189
Here's what I don't get: who is importing CSAM into their camera roll in the first place? I for one have never felt the urge to import regular, legal porn into my camera roll. Who the hell is going to be doing that with stuff they know will land them in prison? Who the hell co-mingles their deepest darkest dirtiest secret amongst pictures of their family and last night’s dinner?

I can believe that some people might be so technically illiterate that they'd upload CSAM to a private Facebook group thinking it was secure. But as far as I'm aware it's not possible to password protect photo albums using the built-in Photos app.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#190
post #186

A key point that needs to be mentioned: we strongly dislike being distrusted. It might well be a genetic heritage. Being trusted in a tribe is crucial to survival, and so is likely wired deep into our social psychology. Apple is making a mistake by ignoring that. This isn’t about people not trusting Apple. It’s about people not feeling trusted by Apple. Because of this, it doesn’t matter how trustworthy the system is…

The part Federighi's "interview" where he can't understand how people perceive this as a back door [1] seems incredibly out of touch. The back door is what everyone is talking about. Someone at Apple should at least be able to put themselves in their critics' shoes for a moment. I guess we need to wait to hear Tim Cook explain how this is not what he described 5 years ago [2].

[1] https://youtu.be/OQUO1DSwYN0?t=425

[2] https://youtu.be/rQebmygKq7A?t=57

Post reply on HN