Live data from Hacker News

EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

eff.org

31–40 of 215 posts

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#31
post #23

> As we’ve explained in Deeplinks blog posts, Apple’s planned phone-scanning system opens the door to broader abuses. It decreases privacy for all iCloud photo users, and the parental notification system is a shift away from strong end-to-end encryption. It will tempt liberal democratic regimes to increase surveillance, and likely bring even great pressures from regimes that already have online censorship ensconced i…

> It only weakens privacy for iCloud photos if you have CP or photos in a CP database Who controls what is in the database? What independent oversight ensures that it’s only CSAM images? The public certainly can’t audit it. What is stopping the CCP from putting pro-Uighur or Xi Winnie the Pooh images into the database? Or from the US using this to locate images that are interesting from an intelligence perspective (S…

Their use of a highly vulnerable[1] "neural" perceptual hash function makes the database unauditable: An abusive state actor could obtain child porn images and invisibly alter them to match the hashes of the ideological or ethnically related images they really want to match. If challenged, they could produce child porn images matching their database, and they could had these images to other governments to unknowingly or plausibly denyably include.

...but they don't have to do anything that elaborate because Apple is using powerful cryptography against their users to protect themselves and their data sources from any accountability for the content of the database: The hashes in the database are hidden from everyone who isn't Apple or a state agent. There is no opportunity to learn, much less challenge the content of the database.

[1] https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX/issue...

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#32

Does Tim Cook have a choice here? I would be surprised to hear that the genesis of this idea was inside of Apple vs. one or more govts pressuring Apple to add this functionality for them. It is also likely they even suggested that Apple should market this as anti-pedo tech to receive the least pushback from users.

Apple doesn't have a history of complying with every request from governments and police. They care more about their bottom line IMHO. So I was surprised by this "feature". I don't see how it sells more phones for them. Actually it could scare away some customers because of false positives. Everybody with small kids risks a match on some of their children pictures.

If Android also implements something like that I could end up with a Linux phone as my main phone and an Android one at home for the 2FA of banks and other mandatory apps. No WhatsApp but I'll manage.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#33
post #18

> [...] and the parental notification system is a shift away from strong end-to-end encryption. That particular statement doesn't make much sense to me. The parental notification system is just a frontend action (one of many, like link previews and such). What does that have to do with iMessage's encryption? I can see an argument about a shift away from privacy (though it only pertains to minors under 13 receiving se…

EFF would probably argue that technologies like safe browsing are also a shift away from E2E encryption. They were strongly against email spam protection in the 90s for this reason.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#34

Does Tim Cook have a choice here? I would be surprised to hear that the genesis of this idea was inside of Apple vs. one or more govts pressuring Apple to add this functionality for them. It is also likely they even suggested that Apple should market this as anti-pedo tech to receive the least pushback from users.

The latest episode of The Daily podcast [0] from The New York Times said that Apple executives were told by members of Congress at a hearing that if they didn't do something about CSAM on their platform the federal government would force them through legislation. And it's not a completely idle threat; just look at the proposed EARN-IT Act of 2020 [1], which would pretty much outlaw end-to-end encrypted services without a law enforcement backdoor.

[0] https://www.nytimes.com/2021/08/20/podcasts/the-daily/apple-...

[1] https://en.m.wikipedia.org/wiki/EARN_IT_Act_of_2020

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#35
post #21

Earlier quoted context omitted.

> It only weakens privacy for iCloud photos if you have CP or photos in a CP database Or people who have photos that hash the same as CP.

Or possess tampered photos that were engineered to be a hash collision.

You’d have to not only have over 30 hash collisions, but also have it collide with another secret hash function, and then also have a human look at it and agree it’s CP.

So what’s the actual realistic issue here? This keeps getting thrown around as if it’s likely, yet not only are there numerous steps against this in the Apple chain, this would already be a huge issue with Dropbox, Facebook, Microsoft, Google, etc who do CP scanning according to all of the comments on HN.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#36

Does Tim Cook have a choice here? I would be surprised to hear that the genesis of this idea was inside of Apple vs. one or more govts pressuring Apple to add this functionality for them. It is also likely they even suggested that Apple should market this as anti-pedo tech to receive the least pushback from users.

If Apple is performing the searching of user private data due to pressure or incentive from the government it would make apple an agent of the government from the perspective of the fourth amendment. As such, these warrantless searches would be unlawful.

If what you suggest were true, we should be even more angry with Apple: it would mean that rather than just lawfully invading their users privacy, that they were a participant in a conspiracy to violate the constitutional rights of hundreds of millions of Americans.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#37

Earlier quoted context omitted.

> ...if you have CP or photos in a CP database... Which database? I get the impression that people think there is a singular repository for thoroughly vetted and highly controlled CP evidence submission. No such thing exists.

It’s an intersection between a US db and a not yet chosen non-US db, which then will have a human reviewer verify its CP before sending off to the authorities.

> What more could one ask for?

An independent audit for both the secret secondary perceptual hashing algorithm and the chain of custody policies/compliance for the "US db" and the disconcertedly open ended "not yet chosen non-US db"?

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#38
post #31
post #23

Earlier quoted context omitted.

> It only weakens privacy for iCloud photos if you have CP or photos in a CP database Who controls what is in the database? What independent oversight ensures that it’s only CSAM images? The public certainly can’t audit it. What is stopping the CCP from putting pro-Uighur or Xi Winnie the Pooh images into the database? Or from the US using this to locate images that are interesting from an intelligence perspective (S…

Their use of a highly vulnerable[1] "neural" perceptual hash function makes the database unauditable: An abusive state actor could obtain child porn images and invisibly alter them to match the hashes of the ideological or ethnically related images they really want to match. If challenged, they could produce child porn images matching their database, and they could had these images to other governments to unknowingly…

They have to come from the intersection of two databases from two jurisdictions. So already that’s out as you suggest. Then you’d have to match _nearly exact photos_, which isn’t a vector for general photos of some random minority. Then you’d need 30 of such specific photos, a match with another secret hash, and then a human reviewer at Apple has to say yes it’s CP before anything else happens.

I think there are plenty of reasons to be concerned about future laws and future implementations, but let’s be honest about the real risks of this today as it’s currently implemented.

Post reply on HN