Live data from Hacker News

Apple Has Opened the Backdoor to Increased Surveillance and Censorship

eff.org

291–300 of 323 posts

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#291
post #196

Earlier quoted context omitted.

>The image profiles are part of the OS so there's no mechanism to deliver image profiles separately for different countries Haven't Apple already said it WILL be country specific? >Apple’s new feature for detection of Child Sexual Abuse Material (CSAM) content in iCloud Photos will launch first in the United States, as 9to5Mac reported yesterday. Apple confirmed today, however, that any expansion outside of the Unite…

Reporting is country specific and US only yes, but the profiles are delivered baked into the OS. I suspect this is so that pedophiles can't buy a phone mail order from Canada and bypass the system.

I think the profiles will need to be country specific too. What counts as CSAM in some places doesnt in others (here in the UK we have a ban on cartoons but bath pics are allowed for instance).

This is something Apple have been pressed on a lot. So far (I'd be happy to be corrected) they've only said "whatever local law permits". That sounds ok, till you realise Saudi will want gays reported and China wont like any Winnie the Pooh pics...

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#292
This is apple speaking out both sides of the mouth, because they will be punished by China if they don’t implement this.

China can submit hashes of political images Xi disagrees with to obtain lists of enemies.

The only way to sell this tool to the west is under the banner of protecting innocent children, this is their best shot of squaring the circle.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#293
post #233

Earlier quoted context omitted.

Uh, no. Technical docs often live long term with typos. This is a perfectly timed leak to take pressure off regulation pushes by waving one of the biggest honking carrots in front of Western political establishments. This has political quid pro quo written all over it, and anyone who thinks this type of backhanded signalling isn't common isn't paying enough attention.

This is one point of view. However, there was chance to win over both parties (customers and governments), by announcing everything together. Why do it now, since it is very short time for September, and that time does not really matter anything on regulation level? Or are the scheduled votings coming very very soon? This holds strong arguments against new regulations whether it was leaked or not. Difference being sp…

You can't forecast vote outcomes. Remember, politics is squishy. The totality of a policakers decision-making is more than just the facts, like it or not. How they are feeling toward you, the interests they perceive you advocating, how dedicated you appear to "the public interest" all factors into that Yea/Nay decision, and could be the difference between a relatively draconian statute NOW, or something so wishy-washy and limp-wristed you barely have to bother the accountant at all to adjust fiscal plans.

Perception management is a full time job, and at the core of marketing, lobbying, PR, and corporate strategy. If information does get out, it's because someone either blew the whistle, or because someone is fishing/doing clandestine signaling.

I'll be honest, it strikes me more as whistleblowing in this case; but there has been enough concerted effort at syndication I'm not necessarily closed to a strategic leak.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#294
post #227

Earlier quoted context omitted.

It is worse tho. The surveillance apparatus doesn't care much about your actual words and images, but your associations and relations. This makes finding needles much more efficient and pre-encryption exfiltration circumvents user added measures, like third party iCloud encryption. And I am pretty sure this will be baked into the OS deeper than your VPN/DNS's reach. Opening up this side channel isn't undone by trusti…

> Opening up this side channel isn't undone by trusting some "icloud deactivation". If you can't trust that, then you can't trust the whole OS and all this speculation has been as valid as any given time.

With this argument you can dissolve anything in "why even bother?". In the real world it very much makes a difference, if the breach of trust is secretly implementing a side channel, or secretly using a documented one. The latter e.g. can maybe by activated "by accident" plausibly, but having a backdoor at all is hard to justify. And for a company like Apple, the size of a breach of trust matters for financial incentives.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#295
post #289

Earlier quoted context omitted.

>Apple's content review change is explicitly FOR reporting people to police in a way that can be expanded beyond it's currently set purpose (child porn) later. I think it would be very hard to expand this beyond it's currently intended purpose, for the reasons I've given. It's terrible for identifying dissidents because it only catches them if they upload to iCloud servers. Dissidents are much more likely to be tech…

>It's terrible for identifying dissidents because it only catches them if they upload to iCloud servers. This is a configuration change. Without knowing the implementation, I'd bet a lunch that, for the time-being, the reason this thing is executed only upon upload to iCloud is because there's some simple business logic buried in there telling it to do so. >Dissidents are much more likely to be tech savvy than random…

>This is a configuration change.

Not it isn't, the check is built into the upload client, they'd have to implement an on-device storage scanning mechanism. That's a different type of system implemented in a different kind of service.

Not that doing that is hard at all, it's not rocket science and they already have full-system indexing and search, but that's also why this isn't a significant step down any kind of technical slippery slope. The problem here is legislative, not technical.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#296

Earlier quoted context omitted.

> Client-side scanning merely opens the door for my device to censor me from sending any message of my choosing and impacts my ability to freely communicate. Nonsense. Only photos you attempt to upload to Apple's iCloud are scanned. If you don't like it, turn off iCloud photos. >Q: So if iCloud Photos is disabled, the system does not work, which is the public language in the FAQ. I just wanted to ask specifically, wh…

I stand behind my comments for any type of client-side scanning. There are two upcoming changes from Apple that are often conflated. First, indiscriminate server-side scanning of photos in iCloud against a non-public source database. Second, client-side scanning of messages for child accounts looking for nudity. Again, client-side scanning is part of the changes that Apple is implementing and I'm projecting on how th…

> I'm projecting on how the terms and conditions of this client-side behavior can and almost certainly will change

The same gloom and doom imaginary projections can be made about what Google might do to Android in the future, and are just as accurate.

For instance, discovery from one of the antitrust suits shows that Google pressured device makers to hide Android privacy settings.

From this, I can project that Google will be completely removing privacy options in their entire ecosystem.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#297

Earlier quoted context omitted.

Other companies aren't "doing bad things" they are handling scanning the contents of their cloud services in a much more user hostile way. Keeping that data on their server means it can be subpoenaed and misused.

I mean, we can split hairs over the words to use, but ultimately "immoral and unethical things are being done by big companies that hold all your stuff". The sentiment is the same. What I'm getting at is that the things Google and Microsoft are doing are entirely irrelevant to the conversation at hand. Apple is going to compromise your device's privacy in the name of child safety, and will - invariably - eventually c…

> What I'm getting at is that the things Google and Microsoft are doing are entirely irrelevant to the conversation at hand.

It is not. Industry practices are entirely relevant.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#299

Earlier quoted context omitted.

In many ways Apple is also the world leader on consumer privacy, pushing for changes when the rest of the industry is walking in the opposite direction. Paying with Apple Pay makes you safer because it gives out minimal payment information; the Target fiasco would've been avoided. Sign in with Apple allows users to provide minimal information in signing up for accounts; the idea that casual users should know how to s…

As always when talking about security and privacy, you need to understand the threat model. Apple protects users from some threats while also becoming itself the biggest threat to users. And this is exactly what Apple wants. This is how you use Stockholm syndrome to entrench a feudal system. The relationship is not 3-way as Apple wants users to believe (Apple the defender, users the victim, third-parties the aggresso…

In what case is the software not the biggest threat, though? Software is completely malleable. How many people update their systems by downloading the source diffs of all the libraries and apps, reviewing them line by line, and compiling locally? For the vast majority, the underlying software is considered a trusted system out of necessity.

The surprising thing to me is that there have been so few critical reviews on the system as it exists today - they are 99.9% "what if" scenarios.

To put it a different way, the possibility has always existed that your trust could turn out to suddenly be misplaced in a single, near-instantaneous policy change. So most of the discussions are actually about reevaluating whether they should consider Apple devices to be a trusted system or not based on this policy change, and trying to predict future policy changes based on it.

The reality is that Apple's spat with the FBI was possible because the US legal system allows it. Other countries can demand anything they want, and Apple has to negotiate with them or decide whether they have to leave that market. The scanning is a US-only feature to comply with US regulations.

If say China adopts a policy Apple does not want to abide by, their choice is exclusively to leave the Chinese market and to potentially adapt to no Chinese manufacturing or even Chinese suppliers. But this is no more or less true than last week.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#300

Earlier quoted context omitted.

>Apple's new system only scans photos you attempt to upload to their cloud. And what if in the future they decide they need to scan more than images going to the cloud? What if there is some huge epidemic of child abuse or some other terrible thing and Apple decides they need to do more? Once you open Pandora's Box you can't close it.

What if in the future Google starts selling your location data to anyone willing to write them a check? Once you open the Pandora's Box of collecting location data, you can't close it.

Both will happen. Basically, Apple is able to scan data on your phone, and Google is able to scan data on their servers.
Post reply on HN