Live data from Hacker News

Apple Has Opened the Backdoor to Increased Surveillance and Censorship

eff.org

251–260 of 323 posts

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#251
post #140

Earlier quoted context omitted.

Apple should just scan the pictures that are in iCloud (their servers). They just assumed that if you have the iCloud option enabled on your device that it gave them the right to do the scan on your phone/computer. I want to also point out that A/V companies never said they were going to scan for child abuse images on your computer and report you if they found any. Like you said, the optics are terrible.

> Apple should just scan the pictures that are in iCloud (their servers). They just assumed that if you have the iCloud option enabled on your device that it gave them the right to do the scan on your phone/computer. End result is the same. Difference is, that now Apple has very limited access to your images. You can only trust in closed systems. When you step into the Apple ecosystem, you are giving a lot of trust.…

Apple has unlimited access now, all that stands in their way is the thinnest of policy lines.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#252
post #147
post #121

Earlier quoted context omitted.

For many years, anti-virus vendors were able to do that. Why haven't those vendors been already co-opted by governments (Kaspersky on the Russian side, Microsoft in the USA side) into scanning for illegal, copyrighted or secret material and reporting on it? Even open source products like ClamAV rely on a opaque database of virus strings.

HTTPS and E2EE were not common many years ago

This really has nothing to do with those protocols as scanning happens on-device when files are just lying around.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#253
post #251
post #140

Earlier quoted context omitted.

> Apple should just scan the pictures that are in iCloud (their servers). They just assumed that if you have the iCloud option enabled on your device that it gave them the right to do the scan on your phone/computer. End result is the same. Difference is, that now Apple has very limited access to your images. You can only trust in closed systems. When you step into the Apple ecosystem, you are giving a lot of trust.…

Apple has unlimited access now, all that stands in their way is the thinnest of policy lines.

> Apple has unlimited access now

Always been. You don't own your iOS based device which is very closed source and mostly unusable for any other operating systems.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#254
post #75
post #65

Earlier quoted context omitted.

Because apple has to change terms of service to permit this But also this is a terrible argument. As a frog i will not wait until i am boiled to raise complaints.

> Because apple has to change terms of service to permit this Apple's ToS change with every iOS release. You have to accept to continue. Do you ever read them?

No, because they are void where I live.

(More specifically, in the EU any terms/conditions imposed after sale of goods are non-enforcable).

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#255
post #6

An Apple recruiter recently reached out to me. I am in a fortunate position to turn down opportunities, so I made sure to explain that I am not interested in working for a company that is at the forefront of enabling further infringement on people's privacy. If you are able to push back, do it in any small way that you can.

In many ways Apple is also the world leader on consumer privacy, pushing for changes when the rest of the industry is walking in the opposite direction. Paying with Apple Pay makes you safer because it gives out minimal payment information; the Target fiasco would've been avoided. Sign in with Apple allows users to provide minimal information in signing up for accounts; the idea that casual users should know how to s…

Apple failed to deploy E2EE iCloud because the FBI asked nicely (with a wrench in hand probably).

The leading narrative on /r/apple is now that "oh this invasive spyware has to exist so that apple can do E2EE iCloud", which is nonsense.

If they had done their job and deployed E2EE iCloud we wouldn't "need" this system in the first place.

It's a classic government pattern:

1. Create the problem (blocking E2EE such that providers have unencrypted copies of your content)

2. Screech and complain about this

3. Demand they do the thing you really wanted in the first place to solve the problem you created

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#256

My opinion about: 1. Every pedophile know about the existence of this system, so I don't think it will be useful to fight those monster, maybe only marginally; 2. Anyway, is that legal ? Even if some crazy store material on his Apple hardware isn't that illegal search non usable in law courts ? 3. Child abuse is often used as Trojan horse to introduce questionable practice. What if: - the system is used to looking fo…

> 2. Anyway, is that legal ? Even if some crazy store material on his Apple hardware isn't that illegal search non usable in law courts ? Yes, it's considered legal. Apple reviews the content first. Courts say this means it is not an illegal government search. It's a search by a private party, who then manually decides to notify the government.

> Yes, it's considered legal.

No, it's not. At least not here in Germany. By law, even police officers are not allowed to look at child porn. The only institution explicitely allowed to do so is the BSI.

The rest of the population implicitely incriminates themselves when they look at (not own) child porn, including Apple's legal entity or employees.

See [1] for 184b Strafgesetzbuch

I'm trying to point out that with this action Apple bluntly decided to ignore a whole lot of countries and their federal laws, which is not something I would embrace - even when they had good intentions.

[1] https://www.gesetze-im-internet.de/stgb/__184b.html

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#257

Earlier quoted context omitted.

I think this is a bad move by Apple even if the point is to set up E2EE later. However, one thing that everyone seems to forget is that all these pictures were already being sent un-encrypted to iCloud. ALL of the same issues already completely exist today and were already being scanned and we have heard no outcry. ALL of the same loopholes and unreasonable warrants can be used against you today with all of the un-en…

Even if it is possible in other ways as well today, this is a black pattern of going down step-by-step. When it will be when people will say no? These are all small steps only.

I agree and my first statement was this is bad. My point was why has no one been complaining about it already being very bad and reacting with "I'm selling all iDevices" when it gets worse?

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#258
post #72

Earlier quoted context omitted.

I don't want to be that guy, but for this job there were lining up 300 more people. Nobody except of a tiny group of nerdy guys (including myself, ofc) is against this apple csam move. Just ask your parents or your non-tech friends if it's "ok" to scan people's phones to find those "bad pedophiles" in order to jail then up for the rest of their life. You will be surprised how much support Apple's initiative has in th…

If you think that you’re completely wrong. I have been asked about it by four non technical people so far after it made national news in the UK. There is a lot of anti surveillance sentiment here and it’s appearing in general public regularly. I regularly go out with groups of random people on Meetup with no shared technical interest as well and I’m surprised at how much anti tracking and surveillance sentiment there…

>no one used NHS track and trace

Why would they? so they can get to stay quarantined for 2 weeks?

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#259

Just a very bad move.

Not being an Apple fan, I'm enjoying the schadenfreude of watching them destroy the arguably most-favored, though one of the last remaining, qualities of Apple products -- people used to see them as the great protectors of their privacy.

It fits, though. They also used to be considered the masters of UI design, and the best at hardware innovation, and in manufacturing. They've mostly destroyed those reputations, as well.

It's actually good when old institutions/companies fail, because the opportunities created for others. The problem is that their failure often takes many years (i.e. look at IBM). If only we could accelerate the process across FAANG, the world would then truly be a better place (and their mission statements fulfilled).

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#260
post #82
post #38

Earlier quoted context omitted.

Sorry, but I do not believe that is what the leak revealed. There was a slide that indicated that data from Apple and other companies was now part of the PRISM program. I am not trying to deny or refute Snowden's whistleblowing. I think it is highly likely that PRISM exists. What I dispute are the speculations that the companies listed are complicit. The 2012 date is quite suspicious - it is precisely the same year t…

> I personally think that PRISM works by externally intercepting data communication lines running to these facilities. Similar to the rumors that international comms links have been tapped. The companies themselves have not participated, but the data path has been compromised. That wouldn't work without the company being at least passively complicit. Links between datacenters are encrypted. If you want even basic PCI…

>That wouldn't work without the company being at least passively complicit. Links between datacenters are encrypted.

They aren't always. In fact the Snowden leaks were the actual event that got many of these companies to do just that.

You mentioned MUSCULAR, but it was that revelation that the DC to DC connections were not in fact encrypted. I believe that program was taps on the DC connections, since the SSL connectivity was added and then removed in the front end, leaving the replication in the clear. Google seemed to be relying on the physical security of those links and them not being on some shared infra. [1]

WARNING: the link below has classified info from the Snowden leaks. If you have a security clearance, dont click it.

[1] https://www.washingtonpost.com/world/national-security/nsa-i...

Post reply on HN