Live data from Hacker News

Apple Has Opened the Backdoor to Increased Surveillance and Censorship

eff.org

201–210 of 323 posts

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#201
post #113
post #82

Earlier quoted context omitted.

> I personally think that PRISM works by externally intercepting data communication lines running to these facilities. Similar to the rumors that international comms links have been tapped. The companies themselves have not participated, but the data path has been compromised. That wouldn't work without the company being at least passively complicit. Links between datacenters are encrypted. If you want even basic PCI…

This thinking is based on trusting "encrypted" links. Did you build the hardware that drives these links? Did you audit the Verilog or code that operates this hardware? I know of at least one way a to implement a "secure" TLS product that you could purchase and deploy in your datacenter that would leak all of the the keying material to compromise every data connection to the NSA. You would be 100% in compliance of al…

Mmmmhmmm. Guess who gets the NSL? Legal and exec team. Guess who are selected occupationally for the ability to keep one's mouth shut?

The velvet glove gets more mileage than you think.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#202

Earlier quoted context omitted.

5. The system can easily be abused by governments or malicious actors to frame innocent people. People merely suspected of keeping such images are de-facto punished and stripped of rights even without standing before a judge or getting a conviction.

Google has been scanning your entire account for kiddie porn for the past decade. >a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le... Their system can easily be abused by governments or malicious actors to frame innocent people.

Once again, this scan takes place on _their_ servers on data that is stored on _their_ servers. It does not take place on the device itself, which is the case with this new Apple thing.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#203

Earlier quoted context omitted.

> is also the world leader on consumer privacy is also an early PRISM adopter and well known on cooperation with totalitarian regimes. Censoring Belarus protesters happened several months ago.

Apple isn't the Dutch East India Company. It is better to ask the citizens of the American democracy to keep their government accountable than it is to ask Apple to be so powerful that it can shrug off national governments. You don't want CSAM scanning in the USA? Then ask your national government to change its laws requiring companies to be so vigilant against CSAM. Or we can ask that Apple become so powerful that t…

The US government is NOT forcing Apple to scan customer data, in fact the entire legal framework of this scanning in the US critically depends on Apple performing the scanning without Government coercion. If the Government forced the scanning or even substantially incentivized it, then it would require a warrant per the fourth amendment.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#204

Earlier quoted context omitted.

> I am not interested in working for a company that is at the forefront of enabling further infringement on people's privacy Conducting scans on device instead of on server is your idea of infringement of privacy? Apple's system keeps everything off their servers until there is an instance where many images on device match known examples of child porn and a human review is triggered. Google's system scans everything…

>Conducting scans on device instead of on server is your idea of infringement of privacy? Why are you asking if the poster still beats their wife? (More specifically, you're pre-supposing scanning must happen, which by itself is a highly debatable assertion) Your point with Google is absolutely sound, but you seem to stop short of actually accepting that actual privacy (no peeking damnit) is dead on arrival. This is…

> you're pre-supposing scanning must happen

No, I'm relaying the fact that scanning does happen, and has been happening for the past decade.

>The system that scans cloud drives for illegal images was created by Microsoft and Dartmouth College and donated to NCMEC. The organization creates signatures of the worst known images of child pornography, approximately 16,000 files at present. These file signatures are given to service providers who then try to match them to user files in order to prevent further distribution of the images themselves, a Microsoft spokesperson told NBC News. (Microsoft implemented image-matching technology in its own services, such as Bing and SkyDrive.)

https://www.nbcnews.com/technolog/your-cloud-drive-really-pr...

>a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account

https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le...

Apple refused to implement this until they found a more private method to handle things.

Only photos you upload to iCloud are scanned and nothing happens unless multiple images match known examples of kiddie porn. In that case, a human review is triggered to make sure you didn't just have several false positives at once.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#205

Earlier quoted context omitted.

5. The system can easily be abused by governments or malicious actors to frame innocent people. People merely suspected of keeping such images are de-facto punished and stripped of rights even without standing before a judge or getting a conviction.

Google has been scanning your entire account for kiddie porn for the past decade. >a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le... Their system can easily be abused by governments or malicious actors to frame innocent people.

Apple's new system is scanning personal property that doesn't belong to them and isn't yet in their cloud.

Gmail files that get scanned are contained on Google's property, in their cloud, on their machines.

Entirely different context.

It's the difference between the USPS coming into my home without permission and going through my documents, records, mail - versus if I send mail through their system and they track it, scan the envelope, etc.

The iPhone used to be pretty obviously personal property, now Apple is saying that's clearly no longer going to be the case going forward.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#206

Guarantee they will begin scanning your devices for unauthorized copyright material very soon if they have not already.

I doubt iOS devices contain enough pirated material on-disk, on average, to make that worth any part of the cost (money, reputational).

Most iOS device probably don't contain any child pornography either.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#207
post #121

Guarantee they will begin scanning your devices for unauthorized copyright material very soon if they have not already.

For many years, anti-virus vendors were able to do that. Why haven't those vendors been already co-opted by governments (Kaspersky on the Russian side, Microsoft in the USA side) into scanning for illegal, copyrighted or secret material and reporting on it? Even open source products like ClamAV rely on a opaque database of virus strings.

Kaspersky is blacklisted as a government security vendor for anything remotely resembling classified or sensitive material. Also, virus databases are open to having their definition databases perused by the user. You can actually dissect what is being scanned for. Apple's system is not, and goes through great pains to be as opaque as possible. Understandably so it may be, from a rational free agent point of view it is still a threat at scale.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#208

My opinion about: 1. Every pedophile know about the existence of this system, so I don't think it will be useful to fight those monster, maybe only marginally; 2. Anyway, is that legal ? Even if some crazy store material on his Apple hardware isn't that illegal search non usable in law courts ? 3. Child abuse is often used as Trojan horse to introduce questionable practice. What if: - the system is used to looking fo…

I think this is a bad move by Apple even if the point is to set up E2EE later. However, one thing that everyone seems to forget is that all these pictures were already being sent un-encrypted to iCloud. ALL of the same issues already completely exist today and were already being scanned and we have heard no outcry. ALL of the same loopholes and unreasonable warrants can be used against you today with all of the un-en…

Even if it is possible in other ways as well today, this is a black pattern of going down step-by-step.

When it will be when people will say no? These are all small steps only.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#209

Earlier quoted context omitted.

I think that the FBI/NCMEC wouldn’t allow the use of the hashes for this. A criminal could load its image collection, one by one, and see which images are deleted. The result is a collection of images that are “FBI safe”.

But this strongly suggests that the entire Apple/NCMEC initiative is a "suveillance-and-arrest" system first and foremost (preserving hash secrecy at the cost of user privacy), while the goal of "stop-known-CSAM-distribution-in-iCloud" (developing an in-house CSAM database at the cost of scanning effectiveness) being secondary.

This seems to come from the NCMEC, not from Apple. I remember another thread (can’t find the link) from someone explaining how difficult it was for them to get access to PhotoDNA and the relative hashes.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#210

Earlier quoted context omitted.

> I am not interested in working for a company that is at the forefront of enabling further infringement on people's privacy Conducting scans on device instead of on server is your idea of infringement of privacy? Apple's system keeps everything off their servers until there is an instance where many images on device match known examples of child porn and a human review is triggered. Google's system scans everything…

>Conducting scans on device instead of on server is your idea of infringement of privacy? It's an infringement on my right to freedom of speech. Client-side scanning merely opens the door for my device to censor me from sending any message of my choosing and impacts my ability to freely communicate. What is today child abuse, tomorrow is health information and further descends to political and religious memes, or wha…

> Client-side scanning merely opens the door for my device to censor me from sending any message of my choosing and impacts my ability to freely communicate.

Nonsense.

Only photos you attempt to upload to Apple's iCloud are scanned. If you don't like it, turn off iCloud photos.

>Q: So if iCloud Photos is disabled, the system does not work, which is the public language in the FAQ. I just wanted to ask specifically, when you disable iCloud Photos, does this system continue to create hashes of your photos on device, or is it completely inactive at that point?

A: If users are not using iCloud Photos, NeuralHash will not run

https://techcrunch.com/2021/08/10/interview-apples-head-of-p...

All the files you upload to your Google/Microsoft account are already being scanned today.

Post reply on HN