Live data from Hacker News

Security Threat Model Review of the Apple Child Safety Features [pdf]

apple.com

281–290 of 393 posts

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#281

Earlier quoted context omitted.

Cloud Scanning vulnerability: no transparency over data use. On the phone, you can always confirm the contents of what’s added to the safety voucher’s associated data. On the cloud, anything about your photos is fair game. Where does that fit in your set intersection?

> On the phone, you can always confirm the contents of what’s added to the safety voucher’s associated data. ...except you can't? Not sure where these assumptions come from.

It’s code running your device is the point, so while “you” doesn’t include everyone, it does include people who will verify this to a greater extent than if done on cloud.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#282

> Apple will publish a Knowledge Base article containing a root hash of the encrypted CSAM hash database included with each version of every Apple operating system that supports the feature. Additionally, users will be able to inspect the root hash of the en- crypted database present on their device, and compare it to the expected root hash in the Knowledge Base article. This is just security theater, they already si…

Apple shipped iCloud Private Relay which is a “1-line code change that hooks into CFNetwork” away from MITMing all your network connections, by this standard.

Any connection worth its salt should be TLS protected.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#283

Earlier quoted context omitted.

Actually it occurs to me that perhaps they're noticing a lot of CSAM is being produced with smartphone cameras and are hoping to snag the phone which produced the originals. If they can get new content into their database before the photographer deletes them, they might find the phone which took the originals—and then find the child victim. Beyond implausible, but then most law enforcement tends to rely on someone ev…

It is only supposed to detect CSAM already known to NCMEC, not identify new images.

That's my point. If the original photographer doesn't delete them by the time they're known to NCMEC and the hash database is updated, they would match. As I said, I recognise this is beyond implausible.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#284

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

> It was illegal to export "strong encryption" for many years, remember? I've seen multiple reports that European lawmakers are planning to require some kind of scanning for CSAM. If this goes into effect, technology isn't going to block those laws for you. Your Purism phone will either be forced to comply or be illegal. The point is that with a Purism phone or custom ROM on my Android phone, I could disable these "l…

> ... because the law is fucking dumb, and my rights matter more.

If they aren't _everybody's_ rights then they aren't really your rights either. They are at best a privilege, and at worst something you have just been able to get away with (so far).

> The law can ban E2EE, cryptocurrencies, and privacy, but so long as we have some degree of technical freedom we can and will give it the middle finger.

Sure, in that scenario techies can secretly give it the middle finger right up until the authoritarian government they idly watched grow notices them.

If someone is seriously concerned about that happening, they could always consider trying to divert the government away from such disaster by participating.

> When the governments of the world demand that Apple become an arm of the dystopia, Apple will comply, and its users will have no choice but to go along with it.

Government demands of this sort are normally referred to as legal and regulatory compliance. Corporations, which are a legal concept allowed by the government, generally have to conform to continue to exist.

> Apple, knowing that it is a private company completely and utterly incapable of resisting serious government demands (ie GCBD in China) should never have developed this capability to begin with.

IMHO, having some portion of a pre-existing capability doesn't matter when you aren't legally allowed to challenge the request or answer "no".

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#286

Earlier quoted context omitted.

Lots of people have made policy arguments. No US law requires client side scanning. No US law forbids E2E encryption. US courts don't let law enforcement agencies just demand everything they want from companies. Apple relied on that 5 years ago successfully.[1] And capitulating preemptively is bad strategy usually. What Neuenschwander said doesn't establish it isn't just an arbitrary limitation. [1] https://en.wikipe…

Each year, Apple gives up customer data on over 150,000 users based on US government data requests, and NSL and FISA requests[1]. The idea that Apple would fight this is a farce, as they regularly give up customers' data without a fight when the government requests it. [1] https://www.apple.com/legal/transparency/us.html

The idea that Apple would fight this is a farce, as they regularly give up customers' data without a fight when the government requests it.

There are laws regarding this, so they don't have a choice. If they get a subpoena from a FISA court, there's not much they can do, but that goes for every US-based company.

Whatever fighting is going on is behind the scenes, so we wouldn't know about it.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#287
post #260
post #134

Earlier quoted context omitted.

> there's a legitimate "slippery slope" argument The slippery slope argument is the only useful argument here. The fundamental issue with their PSI/CSAM system is that they already were scanning iCloud content [1] and that they're seemingly not removing the ability to do that. If the PSI/CSAM system had been announced along side E2E encryption for iCloud backups, it would be clear that they were attempting to act in…

> The fundamental issue with their PSI/CSAM system is that they already were scanning iCloud content This scanning was of email attachments being sent through an iCloud-hosted account, not of other iCloud hosted data (which is encrypted during operation.)

Do you have a public reference for this?

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#288
post #221

Earlier quoted context omitted.

> What I personally don’t understand is why Apple didn’t come out with a different message: we’ve made your iPhone so secure that we’ll let it vouch for your behalf when it sends us data to store. We don’t want to see the data, and we won’t see any of it unless we find that lots of the photos you send us are fishy. That is PR speak that would have landed worse in tech forums. I respect them more for not doing this. T…

> without your approval This isn’t true. You can always turn off iCloud Photo Library and just store the photos locally or use a different cloud provider.

I hate this argument. Pressing yes to the T&C once when you setup an Apple account doesn’t exactly constitute my approval imo (even if it does legally).

There’s no disable button or even clear indication that it’s going on.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#289

In other HN comments on this subject I've (hopefully) made it clear that I'm not really in favor of this project of Apple's, and that there's a legitimate "slippery slope" argument to be made here. So I hope people will entertain a contrarian question without downvoting me into oblivion. :) Here's the thing I keep circling around: assume that bad actors, government or otherwise, want to target political dissidents us…

> It was illegal to export "strong encryption" for many years, remember? I've seen multiple reports that European lawmakers are planning to require some kind of scanning for CSAM. If this goes into effect, technology isn't going to block those laws for you. Your Purism phone will either be forced to comply or be illegal. The point is that with a Purism phone or custom ROM on my Android phone, I could disable these "l…

When the governments of the world demand that Apple become an arm of the dystopia, Apple will comply, and its users will have no choice but to go along with it.

I would argue that Apple is creating systems so they can't become an arm of the dystopia.

For example, even if a government somehow forced Apple to include non-CSAM hashes to the database, the system only uses hashes from multiple child protection agencies in different jurisdictions where the CSAM is the same.

So Apple only uses the hashes that are the same between org A, B and C and ignores the rest.

This, along with the audibility Apple recently announced and the other features makes it so there's literally nothing counties can do to force Apple to comply with some dystopian nightmare…

Of course, with potentially more open operating systems, it would be trivial by comparison for state actors to create a popular/custom ROM for Android that's backdoored.

Re: Security Threat Model Review of the Apple Child Safety Features [pdf]

#290

I don’t like the idea of stuff running on my device, consuming my battery and data, when the only point is to see if I am doing something wrong? An analogy I can come up with is: the government hires people to visit your house every day, and while they’re there they need your resources (say, food, water, and electricity). In other words, they use up some of the stuff you would otherwise be able to use only for yourse…

So 3rd amendment defense? These are digital soldiers being quartered in our digital house.

Probably a clarification of the 4th in order; there are multiple levels of government and private institutions at play to disguise that the government is pressuring private institutions to do search and seizure on their behalf.
Post reply on HN