Live data from Hacker News

WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

theverge.com

251–260 of 372 posts

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#251
post #244

Earlier quoted context omitted.

Google is checking, apparently, Gmail for cp. Apple is doing it, soon, on your phone. Checking your mail for analog cp requires a warrant and can only be done by police. See the difference?

> Apple is doing it, soon, on your phone. Apple is only checking images you choose to upload to iCloud photos to see if you are uploading a collection of CSAM. This is entirely optional, and they have publicly explained what they are doing. They are not sniffing through your communications as they see fit.

One last try, after that I'll stop since you are all over these submissions defending Apple here.

Take traditional mail. That is not opened, it is, usually, not read. Nor is content checked. It can, and is, opened in case of warrants (let's ignore totalitarian regimes here). What Google is doing when it comes to photos, as was Apple before, is opening every envelope containing photos to check wether or not it was CP. Already bad enough because they still opened your mail. You could avoid that by just using another mail carrier, so.

What Apple is doing now is checking you photos before you put them in the envelope. In case they find too many stuff they don't like they open all your other photo albums. And they tell authorities. Without any means for you to prevent that. It's like the postal service looking at your mail before they pick it up.

All that without oversight by courts. Without proper legal and investigative proceedings. Heck, even without any law, currently, forcing them to do that.

The more recent incidents where that or similar things happened were:

- the USSR

- the DDR with the Stasi

- Nazi Germany

- Western allies during WW2 through dedicated censorship bureaus

All of those were historically deemed unacceptable, maybe necessary for the greater good so. Now a private entity, with a global reach, does the same thing in principle. Even with the technical capabilities to do it on a much larger scale, and more thoroughly. And because of Apple being private is, for some reason, ok for you.

Not sure if further discussion woth you has a point, I'll just leave it at that.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#252
post #171

Earlier quoted context omitted.

> You don't build this and take the PR flack for something you can already do server side That’s exactly what you do if you plan to enable E2E.

Yep. That certainly is the next step. And then, once you are scanning encrypted data, iMessage is next whether you want it or not.

It is not the next step, it is already there, if you read the technical papers. Additional encryption level comes to iCloud images with this change, and Apple can’t see your photos anymore unless CSAM threshold is achieved.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#253
post #235

Earlier quoted context omitted.

>Is there some evidence you have of this plan? Sounds like this is just a fear you have. The EARN IT act. It may not be Apple's plan, Apple's plan, as you suggest, might only be for doing scanning on encrypted iCloud and excluding encrypted iMessage. But what Apple will be pushed to do after that is pretty clear.

If the government passes a law mandating that encrypted messages be scanned, it won’t be done using this CSAM mechanism, and it won’t only be Apple doing it. In short, you might be right to be afraid of this outcome, but it has nothing whatsoever to do with CSAM countermeasures.

Read the article and discussion here https://news.ycombinator.com/item?id=28118350. It makes the point pretty well.

>That, of course, is the rub: Apple controls the algorithm, both in terms of what it looks for, what bugs it may or may not have, and also the inputs, which in the case of CSAM scanning is the database from NCMEC. Apple has certainly worked hard to be a company that users trust, but we already know that that trust doesn’t extend everywhere: Apple has, under Chinese government pressure, put Chinese user iCloud data on state-owned enterprise servers, along with the encryption keys necessary to access it. What happens when China announces its version of the NCMEC, which not only includes the horrific imagery Apple’s system is meant to capture, but also images and memes the government deems illegal?

>The fundamental issue — and the first reason why I think Apple made a mistake here — is that there is a meaningful difference between capability and policy. One of the most powerful arguments in Apple’s favor in the 2016 San Bernardino case is that the company didn’t even have the means to break into the iPhone in question, and that to build the capability would open the company up to a multitude of requests that were far less pressing in nature, and weaken the company’s ability to stand up to foreign governments. In this case, though, Apple is building the capability, and the only thing holding the company back is policy.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#254
post #244

Earlier quoted context omitted.

> Apple is doing it, soon, on your phone. Apple is only checking images you choose to upload to iCloud photos to see if you are uploading a collection of CSAM. This is entirely optional, and they have publicly explained what they are doing. They are not sniffing through your communications as they see fit.

One last try, after that I'll stop since you are all over these submissions defending Apple here. Take traditional mail. That is not opened, it is, usually, not read. Nor is content checked. It can, and is, opened in case of warrants (let's ignore totalitarian regimes here). What Google is doing when it comes to photos, as was Apple before, is opening every envelope containing photos to check wether or not it was CP.…

> One last try, after that I'll stop since you are all over these submissions defending Apple here.

Ad hominem is bad faith. It’s usually a sign that you know your arguments don’t hold up.

> What Apple is doing now is checking you photos before you put them in the envelope.

No, an ‘envelope’ is a totally misleading analogy. This has nothing to do with sending messages.

If you want an analogy try this one: Apple provides a warehouse for people who want to store copies of their precious photos. They give you a copier to make copies of your photos, you give them the copies, and they file them.

Because they don’t want a vault full of child porn, then equip the copier with a scanner to detect known child porn while it makes the copy.

That is all that is happening here. No sniffing through communications as they see fit, only a way to prevent you from uploading child porn to their service.

Anyone saying otherwise simply isn’t being truthful.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#255

Earlier quoted context omitted.

Scanning on their cloud storage is different from scanning on users devices. The latter is opening a door to mass surveillance that wasn't even there before. That is the problem, not the scanning itself.

The thing that is changing here is that the images are scanned on the device before being uploaded to the cloud, instead of being scanned on the server after they are uploaded to the cloud. If it hasn't been a problem that Google has been scanning your cloud data for the last decade, it didn't suddenly become a problem now.

The scanning was already a problem. A lesser one, as not using Google or iCloud avoided it. Now I can't, because technically Apple can now look directly at the phone. No idea hey it is so hard to get that difference.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#256
post #234

Earlier quoted context omitted.

> And it would be news to me, that it is now completely free of binary blobs and their claims always felt a little bit dishonest to me. It's the only phone running FSF-endorsed OS without binary blobs, PureOS. It's recommended by the FSF [0]. More details here [1]. [0] https://www.fsf.org/givingguide/v11/ [1] https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque...

Note that the FSF takes the position that binary blobs that are in non-writable memory and executed by secondary processors are part of the hardware and thus not relevant for judging the openness under RYF criteria. Which is how the Librem5 achieves that status, by deliberately picking components that do not use firmware upload from the host CPU but rather ship with the firmware in non-writable memory, and by adding…

[deleted]

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#257
post #235

Earlier quoted context omitted.

If the government passes a law mandating that encrypted messages be scanned, it won’t be done using this CSAM mechanism, and it won’t only be Apple doing it. In short, you might be right to be afraid of this outcome, but it has nothing whatsoever to do with CSAM countermeasures.

Read the article and discussion here https://news.ycombinator.com/item?id=28118350 . It makes the point pretty well. >That, of course, is the rub: Apple controls the algorithm, both in terms of what it looks for, what bugs it may or may not have, and also the inputs, which in the case of CSAM scanning is the database from NCMEC. Apple has certainly worked hard to be a company that users trust, but we already know tha…

I’ve read the article. It changes nothing.

I agree that it could be used to detect image collections (and only image collections) that are not porn, that users upload to iCloud Photo Library.

That is the only established abuse case. Apple has categorically denied that they will comply with it, just as they refused to help the FBI in the San Bernardino case.

Even if they do end up complying in China because China passed a law, authoritarianism in China is a red herring. This mechanism is of no consequence to the Chinese government.

All of has absolutely nothing to do with your claim that ‘iMessage is next’ and the article doesn’t support your claim.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#258

Earlier quoted context omitted.

The problem I have with this approach is that it introduces on-device scan for images. All what is needed to adopt it to scan for different kind of images is to connect it to different database, say, Winnie the Pooh memes featuring CCP chairman, and boom, jailed dissenters. And ability to scan all images is but a minor firmware update away. Server scanning makes it clear that the company running the servers has acces…

> ability to scan all images is but a minor firmware update away ios already does on-device ml-based photo categorisation for some time, afaik no way to turn it off.

And now it's pretty much the same thing, but with a SWAT team knocking your door out when the ML messes up.

Yay progress.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#259
post #112

Earlier quoted context omitted.

I find it laughable whenever someone says "this is the last straw" because it just shows how incredibly misinformed they are. Yes, backdooring E2E encryption in general is a bad idea. However, consider two things: * iCloud Photos was never E2E encrypted in the first place. They already can scan your photos all they want server-side, and they have been scanning for CSAM since 2019, while Google has been scanning for i…

> Would you rather they keep photos non-E2E forever and have even more unfettered access to them than a "backdoor" allows? It does NOT scan photos that are not uploaded to the cloud, despite being on-device. Yes I'd rather they do this. The fact that they're implementing on device checks doesn't suggest to me that they will be deploying E2E encryption. It suggests to me that they will be expanding on device scanning…

Their PR did not handle this well. If you look at the spec, new encryption level has been added, which allows access by Apple only if CSAM hash threshold is reached. It is E2EE with backdoor now.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#260
post #236

Earlier quoted context omitted.

Not easy probably, but likely doable, when someone think it is worth the effort. When the goal is security, because you feel (rightfully or not) targeted by state level intelligence, false sense of security can be dangerous: https://www.hackread.com/hackers-steal-data-air-gapped-pcs-m...

The work in that link has some pretty far-reaching requirements to claim that, that do not generalize to random phone hardware.

It was just a random link. There are plenty of other articles in that area I read about, because I do care about privacy. I do not have them at hand - but the point stands - it is possible. So if there are speakers connected - I assume someone could listen.

Maybe not at all likely (in my case) but when we talk about real security and for some people this is indeed a question of live and death, then I don't want to promote half solutions.

edit: to clarify. , yes a microphone killswitch is probabyl useful in the way that it eliminates most common attack vectors to silently listening to people, but it is potential harmful if people would rely on it for 100% - but do get listened to and send to gulag because the local KGB did in fact took the effort to implement such spyware

Post reply on HN