Live data from Hacker News

Apple Has Opened the Backdoor to Increased Surveillance and Censorship

eff.org

271–280 of 323 posts

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#271
post #252
post #147

Earlier quoted context omitted.

HTTPS and E2EE were not common many years ago

This really has nothing to do with those protocols as scanning happens on-device when files are just lying around.

the comment i was replying to stated:

> Why haven't those vendors been already co-opted by governments (Kaspersky on the Russian side, Microsoft in the USA side) into scanning for illegal, copyrighted or secret material and reporting on it

My reply about the only-recent prevalence of E2EE and HTTPS was an implication that the governments mentioned didn't need to get those companies (such as anti-virus companies, etc) to scan for [insert scary material here] as they would have just been able to hoover it up on the wire (as was shown happens in the US by Snowden)

Thus the question of "Why haven't those vendors been already co-opted by governments" is answered IMO - it wasn't necessary.

Edit: to be fair - i now see what you mean - "never leaving the device and still getting scanned" vs "scanned in transit"

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#272
post #203

Earlier quoted context omitted.

The US government is NOT forcing Apple to scan customer data, in fact the entire legal framework of this scanning in the US critically depends on Apple performing the scanning without Government coercion. If the Government forced the scanning or even substantially incentivized it, then it would require a warrant per the fourth amendment.

> The US government is NOT forcing Apple to scan customer data Unfortunately we do not know that for certain. Companies were compelled to sign up to PRISM against their will. Yahoo in particular tried to resist and were threatened with financial destruction [1]. The Feds can essentially levy any sum of daily fines on a company like Yahoo or Apple any time they see fit, with a rubber stamp from the FISA court; they ef…

> Unfortunately we do not know that for certain.

If they were forced the searches would be an unlawful violation of the constitution. Various tech companies have repeatedly testified under oath that they are performing the searches of customer data of their own free will and for their own benefit.

I wouldn't argue that it's an impossibility-- but if true it would be a shocking revelation that would result in hundreds or even thousands of cases being overturned once it was exposed. And if it were true it shouldn't improve our opinion of Apple's actions in the slightest: instead of being just an unethical invasion of privacy for commercial gain, they'd instead be complicit in a secret conspiracy to illegally violate the rights of hundreds of millions of Americans.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#273
post #225

Earlier quoted context omitted.

> this is a black pattern of going down step-by-step. This is very hard to argue. Functionality like spying all your files is trivial to add, and technically we haven't really moved anywhere. "Now technology is there", is not valid argument since it has always been there. Scanning your files and send some metadata is the feature which requires least effort to make from everything that Apple has released. It might fee…

And Google's entire Code of Conduct used to be "Don't Be Evil". Things change. Money drives all decisions, at all levels above the visceral. Unfortunately, historical precedent for any given business entity provides absolute zero evidence of probable future behavior. :-\

Shouldn't we change our behavior after the bad things happen? Not based on speculation? I have dumped Google completely once they changed drastically.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#274

There is another information leak that I have not seen mentioned in any news report. If an image hash matches the CSAM database, then it is sent to Apple, encrypted and with the “safety voucher”. Apple can decrypt the image only if they receive enough vouchers, and so they claim that they do not have any information about the user in case the number of vouchers is lower than the threshold. But actually they do have i…

Thing is, iCloud Photos are already not E2E encrypted, so it's sort of irrelevant if they're requiring "vouchers" in this case.

The argument is could this new system result in a court ordering a blanket "send us the backups for anyone who gets a match for any reason" order from some court.

This is highly likely in my opinion.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#275

My opinion about: 1. Every pedophile know about the existence of this system, so I don't think it will be useful to fight those monster, maybe only marginally; 2. Anyway, is that legal ? Even if some crazy store material on his Apple hardware isn't that illegal search non usable in law courts ? 3. Child abuse is often used as Trojan horse to introduce questionable practice. What if: - the system is used to looking fo…

Today they look for child porn, tomorrow it will be "Covid Misinformation" (which is today's terrorism). A blind man with a stick can see it coming.

I can't reply to or upvote ~stalkersyndrome's response to add my applause, but I'll do it here instead. He's right. It's inconvenient, and people don't like reading that, which is why it's downvoted to dead, but alas, this is the same reason people avoid getting counseling, because they haven't worked up the courage to be honest with themselves yet. We'll get there, I hope.

https://news.ycombinator.com/item?id=28156934

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#276
post #124

Earlier quoted context omitted.

but once a system is in place, it becomes easier to do things that are a variation on what that system already does. As opposed to doing it from scratch. Also, I think the outcry would be larger if they did it from scratch compared to if they did it as an extension to some existing, known capability. If that's the case, they'd have less to lose in doing such a thing if the base system is already in place.

Great explainer why this won’t happen: https://pingthread.com/thread/1424873629003702273 > For the conspiracy to work, it'd need Apple, NCMEC and DOJ working together to pull it off voluntarily and it to never leak. If that's your threat model, OK, but that's a huge conspiracy with enormous risk to all participants

No, it does not require Apple, NCMEC and DOJ working together.

Apple could intercept hashes that are sent and compare to their own database.

Someone in the NCMEC could add non CSAM hashes to their database.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#277

Pushing Spyware Engine is literally abuse to all people including children and it's much worse then any problem they would claim to fight. Even if you believe them. By this move people are indoctrinated with the idea that being watched by someone big and powerful is Ok. They learn to accept such abuse and what can be worse for any safety of anyone than learning that? If one is serious about any safety one should lear…

So this one time I was tasked to verify a complaint of child pornography and image the infrastructure for evidentiary purposes, if necessary. It was the first time I’d ever been exposed to it as a naïve operations kid at a hosting provider. Imagine my surprise and horror to find that not only was the complaint accurate, it led to a completely polished thumbnail site on par with PornHub. Boom, right there, no login. N…

Interesting that you chose to so thoroughly explore such a heinous site when all you had to do was image it and provide a copy to the authorities. More interesting that you then depict its graphic content in such detail here.

Perhaps a thorough search of your hard drives and NAS are in order citizen. No need to report to your local precinct, we've already pushed the updated scan list to your devices for analysis.

Remember, every scan just renews your innocence!

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#278
post #157

Earlier quoted context omitted.

Very naive to assume those hashes won't be treated differently on the backend. The most logical thing would be to send those directly to the CPC/NSA, since Apple's human review is clearly a smokescreen at the point where non-CP hashes are added.

But someone has to write code to hold multiple sets of hashes. And someone has to write the code which treats reports differently. It all has to be written and maintained. Thus developers at Apple will still know that the system is being used for something other than CSAM.

Is the hash matching being done on device or off device?

Up thread it was said that the device will hash the picture then send hash off for matching.

If that is a case, then the hashes coming off your device can be intercepted and checked vs other databases.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#279

Earlier quoted context omitted.

This fact is well known and changes nothing. The problem is that the system exists at all. The fine print WILL change - it always does, and that's also a well known fact.

By that logic, Google will definitely begin selling their treasure trove of user data to anyone with a checkbook, because the fine print WILL change.

Yes, that's a very reasonable assumption. I assume all information I give out will be shared beyond my control, unless the recipient promises in writing to protect it and would suffer proportionally if they broke that promise. In practice, this only happens when federal regulations apply (i.e., health care or banking).

If you want to rely on other people behaving a certain way in the future, either form a personal relationship or write up a contract.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#280
post #28
post #19

Earlier quoted context omitted.

"Virus Scanner" is optional, many ways to disable it, you won't be arrested if you are infected, and government doesn't get to decide what virus is. Apple scanning is NOT optional, if they have false match or mess up you will be charged/investigated for one of THE most hated crimes in human history, even if you win the case the damage will be irreparable. You lost your mind if you think governments are not going to s…

It is optional to use iCloud Photos. There's no indication you get arrested if they find something, it isn't reported directly to FBI. Apple will just disable your account, and there is an appeals process to restore it if they made a mistake. There's more nuance here beyond the clickbait headlines.

> There's no indication you get arrested if they find something

Yes, you are.

> it isn't reported directly to FBI

NCMEC is the FBI.

>Apple will just disable your account, and there is an appeals process to restore it if they made a mistake.

Good luck appealing from your jail cell or with confiscated devices

>There's more nuance here beyond the clickbait headlines.

Please stop spreading false information

Post reply on HN