Live data from Hacker News

Apple Has Opened the Backdoor to Increased Surveillance and Censorship

eff.org

31–40 of 323 posts

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#31
post #14

This is effectively a virus scanner. Files are hashed (in a fancy way), compared against known hashes, and matches are reported. Your Windows desktop has Windows Defender. EFF lost a lot of credence to me after the Best Buy case. They made this big fuss about how Geek Squad employees were agents of the state for reporting CSAM on a customers hard drive, while doing a requested file recovery. When searched, the defend…

> It scans your photos, for known CSAM images No, it scans photos for arbitray (fancy) hashes, and Apple chooses to limit it to CSAM images. Nothing about the tech prevents it from being expanded to other kinds of images. And from what I understand, nothing prevents it from being expanded to other filetypes either, does it? The only thing that ties this tech to CSAM images is Apples promise (and claim) to keep the sc…

The only thing that prevents Apple, Microsoft, or Ubuntu from executing arbitrary code on your system is their promise to keep the scope of updates limited. You already operate under this trust model.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#32
post #14

This is effectively a virus scanner. Files are hashed (in a fancy way), compared against known hashes, and matches are reported. Your Windows desktop has Windows Defender. EFF lost a lot of credence to me after the Best Buy case. They made this big fuss about how Geek Squad employees were agents of the state for reporting CSAM on a customers hard drive, while doing a requested file recovery. When searched, the defend…

> This is effectively a virus scanner. Files are hashed (in a fancy way), compared against known hashes, and matches are reported. Your Windows desktop has Windows Defender.

1) I don't run Windows.

2) The principle of antivirus software is different: the software scans your files but does everything locally and with the end user in full control over what happens next, and of their data. Windows Defender does not report you to the fuzz when it finds a match -- yet. Given that it is apparently now enforcing copyright laws in addition to protecting the end user against viruses, that may change.

> The case was dismissed on a technicality.

If the cops want to catch chomos and bring them to justice, they can assiduously avoid bringing the fruit of the poisoned tree into the courtroom. The societal risks of allowing them to bring ill-gotten evidence to trial are too great, no matter how evil we think the defendant is.

> It scans your photos, for known CSAM images, when you are using iCloud backups, in order to comply with the law that they must scan their hosting services for CSAM.

The USA has no such law (yet). Service providers have a duty to report if they find CSAM, not a duty to scan for it. Even if they had such a duty, they could scan the copy that lives on their servers, rather than pushing spyware to users' devices and blatantly breaking the trust that a user's device implicitly serves the user's needs.

> We seem to have taken the idea that sometimes bad things are promoted through "think of the children" to mean we must oppose anything involving the protection of children.

That's a disingenuous strawman. No one is objecting to laws that punish child abusers, or to legitimate forensic techniques to catch them. We're objecting to companies -- and now end-user devices -- being deputized to participate in law enforcement dragnets likely in violation of the U.S. Constitution, other national constitutions, and the principles of a free society (the applicable one being: LE doesn't get to search you without a damned good reason signed off by a judge on a warrant, and by extension they don't get to twist OEMs' arms to build devices to search you on their behalf).

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#33
post #29

Earlier quoted context omitted.

If you are a parent you very much will appreciate your children not receiving or sending explicit photos. As someone who cares for society I am thrilled that Apple is preventing the dissemination of CSAM.

I think most people are fine with the measures taken in Messages, much less so with the measures taken with scanning of images and reporting to authorities, and the possible scope creep that is only prevented by policy, rather than by capability.

The only thing stopping Apple from doing anything on your device is policy, rather than by capability.

They do control the OS and apps after all.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#34
post #14

This is effectively a virus scanner. Files are hashed (in a fancy way), compared against known hashes, and matches are reported. Your Windows desktop has Windows Defender. EFF lost a lot of credence to me after the Best Buy case. They made this big fuss about how Geek Squad employees were agents of the state for reporting CSAM on a customers hard drive, while doing a requested file recovery. When searched, the defend…

What are your thoughts on state actors asking Apple to use this technology to imprison dissidents? This effectively criminalizes anything the state deems unacceptable, which in some countries includes criticizing the ruling party. Is it right for an American company to open their gates to that?

Why has that state actor not already forced Apple to deploy a special firmware image to all citizens via software update functionality? Yes, this can be used to search for banned memes, but if a country has that flex, they would already be doing so.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#35
post #14

This is effectively a virus scanner. Files are hashed (in a fancy way), compared against known hashes, and matches are reported. Your Windows desktop has Windows Defender. EFF lost a lot of credence to me after the Best Buy case. They made this big fuss about how Geek Squad employees were agents of the state for reporting CSAM on a customers hard drive, while doing a requested file recovery. When searched, the defend…

Did you read the article?

A scanner of any kind is a tool that user chooses among several options in App Store based on community review, is preferably open source, with parameters that user sets, and content and specific directories that user would like to scan. In many cases, people don’t want to install any scanner. The job of a virus scanner in particular is to protect the user.

Apple’s scanner is not installed by user, can scan for arbitrary information, is closed source, uses an unknown database and harms most users.

It’s more like a virus or Trojan than a virus removal program.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#36
post #18

Earlier quoted context omitted.

This analogy only works at a superficial, technical level. When a virus scanner finds a virus, it alerts me and I can either quarantine or delete it. It’s up to me to decide if what it’s found is actually a virus, or a false positive. When Apple's tool thinks it’s found the material it’s looking for, the assumption is that I am a pedophile who collects CSAM.

Rather than oppose a measure to protect children because of the fear of a few false positives, why can't you accept the fact that the societal benefit outweighs the potential risk? A few innocent men might be condemned to rot -- or be murdered -- in prison, but Apple has developed a system that mostly protects your privacy and could save the lives of potentially millions of children around the world. The rights of a…

Sarcasm doesn't land well here, especially when it's a long comment.

Thinking about false positives is the wrong thing to focus on. The point is the technology could be applied to any image such as Tiannanmen Square, Hong Kong, depictions of God, Muhammad, or Jesus, etc.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#37

Guarantee they will begin scanning your devices for unauthorized copyright material very soon if they have not already.

I doubt iOS devices contain enough pirated material on-disk, on average, to make that worth any part of the cost (money, reputational).

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#38
post #2

I am beginning to wonder if this was the plan all along. Back in 2013 via the Snowden leaks, it was revealed Apple was associated with the NSA domestic surveillance program, PRISM. It appears they (NSA and Apple, et al) pulled out due to the level of negative PR. After 8 years, the intelligence community and tech companies figured out they could sell their surveillance through a thinly veiled effort to “protect X gro…

Sorry, but I do not believe that is what the leak revealed.

There was a slide that indicated that data from Apple and other companies was now part of the PRISM program.

I am not trying to deny or refute Snowden's whistleblowing. I think it is highly likely that PRISM exists. What I dispute are the speculations that the companies listed are complicit.

The 2012 date is quite suspicious - it is precisely the same year that a new Apple datacenter in Prineville came online. Facebook also has a datacenter. Literally next door. Facebook also appears on those slides. I am not sure who else is also now in the area.

I wonder where all of the network cables go?

I personally think that PRISM works by externally intercepting data communication lines running to these facilities. Similar to the rumors that international comms links have been tapped. The companies themselves have not participated, but the data path has been compromised.

The NSA has previously tapped lines (AT&T), but they made the mistake of doing it inside the AT&T building. Google "Room 641A at 611 Folsom Street, SF". That is where "beam splitting" was done. This eventually leaked out. The NSA isn't stupid, I doubt they wanted to repeat that sort of discovery. The best way to keep something from being discovered is to not let people know. This is why I think it is believable and likely that the companies listed on the slides have no idea what has been done.

I will also note that PRISM and "beam splitting" are a rather cosy coincidence.

I think it is most likely that PRISM is implemented without the knowledge of anyone except the NSA and in Prineville there is some "diversion" of network cabling to a private facility that is tapping the lines.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#39
post #34

Earlier quoted context omitted.

What are your thoughts on state actors asking Apple to use this technology to imprison dissidents? This effectively criminalizes anything the state deems unacceptable, which in some countries includes criticizing the ruling party. Is it right for an American company to open their gates to that?

Why has that state actor not already forced Apple to deploy a special firmware image to all citizens via software update functionality? Yes, this can be used to search for banned memes, but if a country has that flex, they would already be doing so.

Why didn't Apple do this without announcing it?

The answer is Apple risks a whistleblower on their hands if they do it secretly, regardless of the targeted country. Remember Google's project Dragonfly?

Plus, software needs to be maintained. I don't see how they could do that in perpetuity without a major risk to their valuation. So all moves do need to be made public while the software is created in countries that have a free press.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#40
post #31

Earlier quoted context omitted.

> It scans your photos, for known CSAM images No, it scans photos for arbitray (fancy) hashes, and Apple chooses to limit it to CSAM images. Nothing about the tech prevents it from being expanded to other kinds of images. And from what I understand, nothing prevents it from being expanded to other filetypes either, does it? The only thing that ties this tech to CSAM images is Apples promise (and claim) to keep the sc…

The only thing that prevents Apple, Microsoft, or Ubuntu from executing arbitrary code on your system is their promise to keep the scope of updates limited. You already operate under this trust model.

> You already operate under this trust model.

Do I? Can you elaborate? Do you notice a difference between a company (potentially) doing this behind closed doors and as quietly as possible and doing this in a public official way?

What if I tell you I don't use any of the operating systems you listed? Does your answer change?

I have a question: Would you welcome such a move? Do you believe that taking things a bit further would be nice because "we might catch a few criminals"?

Post reply on HN