Live data from Hacker News

Apple Has Opened the Backdoor to Increased Surveillance and Censorship

eff.org

231–240 of 323 posts

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#231
post #228

Earlier quoted context omitted.

The notion that scanning cloud data on device is somehow worse than doing the same thing on server is deeply flawed. If you have a false positive on device, nothing is sent to Apple's servers. It takes several (possibly false) positives at once to trigger a human review. If you have a single false positive on server, that data is sitting there where it can be subpoenaed and abused. Also, recent history shows that App…

> Also, recent history shows that Apple is willing to fight government demands to invade user privacy in court. I can only think of one instance where they did that (the San Bernardino shooter case), and the request was hugely overreaching (the FBI wanted them to compromise their software update signing services), and also they actually DID comply with giving the FBI access to their iCloud data -- just not the softwa…

> I can only think of one instance

You might want to Google it then. It’s well known that Apple has been asked and refused multiple times. It’s really easy to find. https://en.wikipedia.org/wiki/FBI–Apple_encryption_dispute

This is a big part of the reason people are surprised and concerned about the scanning program, because it seems like a departure from what Apple has said and done about privacy of iPhone data for the last decade.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#232

Earlier quoted context omitted.

but once a system is in place, it becomes easier to do things that are a variation on what that system already does. As opposed to doing it from scratch. Also, I think the outcry would be larger if they did it from scratch compared to if they did it as an extension to some existing, known capability. If that's the case, they'd have less to lose in doing such a thing if the base system is already in place.

> but once a system is in place No, the GP was correct. As soon as any closed-source software implements automatic software updates, you've always one malicious update away from the system betraying you. Having "a system in place" for doing potentially evil things is unnecessary. Interim steps of any kind are unnecessary. What Apple has done this week doesn't bring the iPhone closer or further to your hypothetical dy…

Yes, it's always "one malicious update away", but what I'm saying is different to that.

You're talking about "installing" a change, and talking about more about their capability to change what happens with your data.

I'm talking about 1) the effort required to _write_ the change and -- more importantly -- 2) the potential backlash being different as to whether it's a modification of an existing functionality vs an entirely new type of functionality. This second point is a major one, because it would be seen as much worse if it looks to the public like they've gone out of their way to do something wrong, and would be much more damaging to their reputation. IMO anyway.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#233
post #198

Earlier quoted context omitted.

I don't want to call names, but here is something: 1. On-device scanning is leaked by some well-known people 2. It gets massive attention 3. Not long after, Apple releases their announcement in very odd time 4. If you read all of their material, there are typos and some are clearly in WIP level 5. It does not make sense to announce, since there is reserved event for all of this in the very close future

Uh, no. Technical docs often live long term with typos. This is a perfectly timed leak to take pressure off regulation pushes by waving one of the biggest honking carrots in front of Western political establishments. This has political quid pro quo written all over it, and anyone who thinks this type of backhanded signalling isn't common isn't paying enough attention.

This is one point of view. However, there was chance to win over both parties (customers and governments), by announcing everything together. Why do it now, since it is very short time for September, and that time does not really matter anything on regulation level? Or are the scheduled votings coming very very soon?

This holds strong arguments against new regulations whether it was leaked or not. Difference being specific attention.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#234
post #124

Earlier quoted context omitted.

but once a system is in place, it becomes easier to do things that are a variation on what that system already does. As opposed to doing it from scratch. Also, I think the outcry would be larger if they did it from scratch compared to if they did it as an extension to some existing, known capability. If that's the case, they'd have less to lose in doing such a thing if the base system is already in place.

Great explainer why this won’t happen: https://pingthread.com/thread/1424873629003702273 > For the conspiracy to work, it'd need Apple, NCMEC and DOJ working together to pull it off voluntarily and it to never leak. If that's your threat model, OK, but that's a huge conspiracy with enormous risk to all participants

I'm not sure how that's relevant to my comment. I'm not saying any particular thing will happen. I was just disagreeing with the person who said "The only thing that prevents ... from executing arbitrary code on your system is their promise to keep the scope of updates limited. You already operate under this trust model." My disagreement is that it's more complex than "the only thing".

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#235

Earlier quoted context omitted.

Apple's new system is scanning personal property that doesn't belong to them and isn't yet in their cloud. Gmail files that get scanned are contained on Google's property, in their cloud, on their machines. Entirely different context. It's the difference between the USPS coming into my home without permission and going through my documents, records, mail - versus if I send mail through their system and they track it,…

> Apple's new system is scanning personal property that doesn't belong to them and isn't yet in their cloud. Apple's new system only scans photos you attempt to upload to their cloud. Nothing else is scanned. Scanning the files on server, the way Google and Microsoft do it, means that false positive data is lying around where it can be subpoenaed and used to incriminate innocent people. >Innocent man, 23, sues Arizon…

It doesn't matter if the scan is conditional.

It matters that the capability is there.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#236

Earlier quoted context omitted.

> So why wouldn't that same whisteblower complain if Apple expands their CSAM detection system to other use cases ? I assume Apple could make it very difficult, if not impossible, to detect what they're searching for when they are using hashes created and transmitted by all their own hardware and software. But, even if they did publish the hashes and those were somehow verified in free-press countries by a trusted 3r…

> I assume Apple could make it very difficult, if not impossible, to detect what they're searching for when they are using hashes created and transmitted by all their own hardware and software. Correct, it would be easy to slip in additional hashes without the team knowing what those hashes represented. HOWEVER, as soon as these additional hashes match something, the first person to see them will be an Apple employee…

> the first person to see them will be an Apple employee performing manual review

In China, iCloud is already run by the government.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#237
post #149

Earlier quoted context omitted.

As I understand it, in Canada, having a picture of your child in a bathtub is child porn. So I can see this going horribly wrong.

Citation needed. Many parents here have photos of their kids in bathtubs.

Many people steal bicycles and are not in handcuffs or even prosecuted. Doesn‘t mean it‘s legal, right?

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#238

Earlier quoted context omitted.

Once again, this scan takes place on _their_ servers on data that is stored on _their_ servers. It does not take place on the device itself, which is the case with this new Apple thing.

Once again, the notion that everything on the device is scanned under Apple's system was never true. Only photos you attempt to upload to Apple's iCloud are scanned. If you turn off iCloud photos, NOTHING is scanned. >Q: So if iCloud Photos is disabled, the system does not work, which is the public language in the FAQ. I just wanted to ask specifically, when you disable iCloud Photos, does this system continue to cre…

It’s a difference in policy vs technical capability. Currently the policy is only scan when iCloud Photos is enabled, but the capability to scan at any/all times is just a policy change away.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#239
post #18

Earlier quoted context omitted.

This analogy only works at a superficial, technical level. When a virus scanner finds a virus, it alerts me and I can either quarantine or delete it. It’s up to me to decide if what it’s found is actually a virus, or a false positive. When Apple's tool thinks it’s found the material it’s looking for, the assumption is that I am a pedophile who collects CSAM.

Rather than oppose a measure to protect children because of the fear of a few false positives, why can't you accept the fact that the societal benefit outweighs the potential risk? A few innocent men might be condemned to rot -- or be murdered -- in prison, but Apple has developed a system that mostly protects your privacy and could save the lives of potentially millions of children around the world. The rights of a…

> Rather than oppose a measure to protect children because of the fear of a few false positives, why can't you accept the fact that the societal benefit outweighs the potential risk?

But Apple apologists has been telling me all day that I could stop the system from scanning if I just disable iCloud.

If a person can disable it that easily, then the system is effectively useless.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#240

My opinion about: 1. Every pedophile know about the existence of this system, so I don't think it will be useful to fight those monster, maybe only marginally; 2. Anyway, is that legal ? Even if some crazy store material on his Apple hardware isn't that illegal search non usable in law courts ? 3. Child abuse is often used as Trojan horse to introduce questionable practice. What if: - the system is used to looking fo…

Today they look for child porn, tomorrow it will be "Covid Misinformation" (which is today's terrorism). A blind man with a stick can see it coming.

The honest among of us, and perpetrators, have seen this coming.

It’s the paid shills and unpaid fools who do bidding of masters they are unaware of exist that you have to be on the look out for. HN has been under massive astroturfing/disinformation campaigns that the honest people here can’t separate reality from fiction. I don’t even want to think about how badly larger entities are dealing with it.

Post reply on HN