Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

251–260 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#251
post #23

Since Snowden I use my phone in minimalistic way. Phone calls. Minimal texting. No games. Banking apps if necessary. Treat your phones as an enemy. Use real computers with VPN and software like Little Snitch when online. Use cameras for photography and video. The benefits of this approach are immense. I have long attention span. I don't have fear of missing out. If governments wan't the future to be painted by tracin…

If you're treating your phone as hostile why would you skip gaming apps but use banking ones? That seems backwards if you're assuming your mobile is the weak point.

In the EU the PSD2 directive obliged banks to provide strong authentication for customers login process and various operations on the account incl. payments ofc. Most of the time mobile applications are being used in the result - for either login confirm or as software OTP generators (biometric verification is also supported); the lists of printed codes are rather obsolete now and some banks may actually charge your extra for sending you text messages with such codes. I know there are hardware security tokens but in all these years I haven't seen anyone using such here.

So, it's rather hard to avoid banking apps.

Also, the PSD2 directive implements the duty of providing API infrastructure for third-parties. [1]

https://www.ecb.europa.eu/paym/intro/mip-online/2018/html/18...

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#252
post #237
post #200

Earlier quoted context omitted.

do you still get patches via google play services?

With non-stock (assuming not jailbroken but just a totally different operating system) I think (I might be wrong... I should know for sure but I awkwardly don't) you aren't even allowed to use Google Play Services at all?

back in the day it was not allowed, and then they allowed it somewhat begrudgingly. this was like 10y ago though.

no idea what the situation is now, but i wouldn't consider a phone that doesn't get those patches (project mainline) on time to be a serious option.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#253
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

You could go back even further if you wanted. Possibly to the first handwritten letter delivered by a third party. That's where all the potential for censorship and tampering started.

Truth is even if our tools evolve, our chains evolve faster.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#255

Earlier quoted context omitted.

>EU legislation is underway to ensure that it stays this way. which one?

Devices with radio capabilities (i.e., all mobile devices) must be designed to prevent executing "unauthorized" software.

What do you mean, authorized by whom? The software applications I run have not been greenlit by any third party. Think about a model in which you code, than wait for authorization before deployment... The worst pulp novel.

What exactly are you talking about, the OS?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#256
post #228

Earlier quoted context omitted.

It’s not just you. I have pictures of my kids playing in the bath. No genitals are in shot and it’s just kids innocently playing with bubbles. The photos aren’t even shared but they’d still get scanned by this tool. This kind of thing isn’t even unusual either. I know my parents have pictures of myself and my siblings playing in the bath (obviously taken on film rather than digital photography) and I know friends hav…

> While the difference between innocent images and something explicit easy for a human to identify, I’m not sure I’d trust AI to understand that nuance. In this case it’s not AI that’s understanding the nuance, it’s authorities that identify the exact pictures they want to track and then this tool lets them identify what phones/accounts have that photo (or presumably took it). If ‘AI’ is used here it is to detect if…

Is there some way of verifying that the fingerprints in this database will never match sensitive documents on their way from a whistleblower to journalists, or anything else that isn't strictly illegal? How will this tech be repurposed over time once it's in place?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#257

Well this really debunks my common phrase “Apple is a Privacy company, not a Security company” I can’t say I’m surprised they are implementing this (if true), under the radar. I can’t imagine a correct way or platform for Apple to share this rollout publicly. I’m sure nothing will come of this, press will ignore the story, and we all go back to our iPhones

Apple, like all companies is a Money company.

And a "subject to other powers" company.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#258
post #30

Earlier quoted context omitted.

Which'd be fine if we had one global government with world wide jurisdiction. Or technology choices from companies which couldn't be pressured by governments outside your personal regulation jurisdiction. I wouldn't hold your breath waiting for those regulations to become law in, say, Chine or Turkey or Saudi Arabia. I'd bet even Israel won't pass them, surely NSO have enough political lobbying swing (and probably al…

But we don't have a global government, so the next best thing is for individual countries to pass such regulation, which would prevent products violating privacy like this from being offered and sold in those countries. Think of GDPR, which is essentially each member of the EU saying in unison, "your product/service must comply with these data protection laws, or you can't legally do business with any of our citizens…

> Come to think of it, I wonder if this Apple thing would even fly under GDPR?

Possibly? I’m not a lawyer, but if this is about compliance with a legal obligation, and they’re under that category of pressure? I think GDPR would allow that?

Certainly seems more likely allowed than the stuff Facebook complained Apple was preventing them from doing.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#259
post #210

Earlier quoted context omitted.

It's in "direct" opposition to them in the same way drink driving laws are in "direct" opposition to people who have no intention of driving drunk. It's a restriction on their liberty and privacy that they willingly support because of the overall positive effects. Anyway I'll duck out of this now the driveby downvotes annoy me.

If drunk driving laws were enforced by mandating a breathalyzer in every car and nobody really knew how the breathalyzer worked and also it maybe doubled as an instrument for the government to catch you doing fifteen other things then I might consider that a fair comparison. But yes, there's a lot of drive-by engagement in this thread, thank you for at least engaging with it directly.

Funny enough, the recent infrastructure bill in the US includes provisions for all new cars to be fitted with breathalyzer-like devices.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#260
post #118

This matches up with how I view Apples corporate thinking. "we know what's best" "the consumer is not to be trusted". Apple limits access to hardware, system settings, they block apps that don't meet moral standards, are "unsafe", or just might cause apple to not make as much money. They do not significantly care what people say they want after all they know best. A lot of people love not having options and having th…

This isn't exclusive to Apple - Microsoft recently decided that starting from August Windows Defender will have the option for blocking PUAs enabled by default for those users who doesn't have other third-party security software [1]. This also I belive falls under "we know what's best" and "the customer is not to be trusted" or "is too stupid to run things by on its own".

This does looks good on paper - caring for customers and their security, peace of mind but tomorrow it might be a total vendor-lock with no ways of installing any other software than one approved by the corporate entities.

[1] - https://www.ghacks.net/2021/08/03/windows-10-blocks-potentia...

Post reply on HN