Live data from Hacker News

Apple Has Opened the Backdoor to Increased Surveillance and Censorship

eff.org

301–310 of 323 posts

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#301

Earlier quoted context omitted.

Google has been scanning your entire account for kiddie porn for the past decade. >a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le... Their system can easily be abused by governments or malicious actors to frame innocent people.

Apple's new system is scanning personal property that doesn't belong to them and isn't yet in their cloud. Gmail files that get scanned are contained on Google's property, in their cloud, on their machines. Entirely different context. It's the difference between the USPS coming into my home without permission and going through my documents, records, mail - versus if I send mail through their system and they track it,…

Oh, I like this USPS analogy but I'll clean it up. Google photos and chat are like a USPS that only stores and transmits post cards. It's understood by the creator/sender that anyone who has access to them can read them. Apple here is a USPS that sends sealed envelopes. They (say they) can't read what's inside as it's sent or stored. With this change they will create the 'capability' to show up whenever you decide to send an envelope and read it before you seal it up for sending.

Meh, nevermind. That's not much cleaner.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#302

Earlier quoted context omitted.

I mean, we can split hairs over the words to use, but ultimately "immoral and unethical things are being done by big companies that hold all your stuff". The sentiment is the same. What I'm getting at is that the things Google and Microsoft are doing are entirely irrelevant to the conversation at hand. Apple is going to compromise your device's privacy in the name of child safety, and will - invariably - eventually c…

> What I'm getting at is that the things Google and Microsoft are doing are entirely irrelevant to the conversation at hand. It is not. Industry practices are entirely relevant.

So what is your point then? Is it that Apple's punch in the gut here, while bad/wrong, is beyond criticism or outage because if you use Google, you'll get a slap to the face? Or is it that Apple actually isn't doing anything wrong simply because there is some roughly analogous behavior in your view by other companies?

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#303
post #196

Earlier quoted context omitted.

Reporting is country specific and US only yes, but the profiles are delivered baked into the OS. I suspect this is so that pedophiles can't buy a phone mail order from Canada and bypass the system.

I think the profiles will need to be country specific too. What counts as CSAM in some places doesnt in others (here in the UK we have a ban on cartoons but bath pics are allowed for instance). This is something Apple have been pressed on a lot. So far (I'd be happy to be corrected) they've only said "whatever local law permits". That sounds ok, till you realise Saudi will want gays reported and China wont like any W…

China already operates their own iCud storage so this is irrelevant to them.

Apple doesn't have any iCloud data centres in Saudi, so Saudi can't pass laws about what is or isn't stored in them.

Look, the way this works and how it's implemented matters. It's stunning to me how many people are thoroughly confused and jump to unwarranted conclusions about how this actually works and what that means.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#304

Earlier quoted context omitted.

In many ways Apple is also the world leader on consumer privacy, pushing for changes when the rest of the industry is walking in the opposite direction. Paying with Apple Pay makes you safer because it gives out minimal payment information; the Target fiasco would've been avoided. Sign in with Apple allows users to provide minimal information in signing up for accounts; the idea that casual users should know how to s…

As always when talking about security and privacy, you need to understand the threat model. Apple protects users from some threats while also becoming itself the biggest threat to users. And this is exactly what Apple wants. This is how you use Stockholm syndrome to entrench a feudal system. The relationship is not 3-way as Apple wants users to believe (Apple the defender, users the victim, third-parties the aggresso…

[deleted]

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#305
post #82
post #38

Earlier quoted context omitted.

Sorry, but I do not believe that is what the leak revealed. There was a slide that indicated that data from Apple and other companies was now part of the PRISM program. I am not trying to deny or refute Snowden's whistleblowing. I think it is highly likely that PRISM exists. What I dispute are the speculations that the companies listed are complicit. The 2012 date is quite suspicious - it is precisely the same year t…

> I personally think that PRISM works by externally intercepting data communication lines running to these facilities. Similar to the rumors that international comms links have been tapped. The companies themselves have not participated, but the data path has been compromised. That wouldn't work without the company being at least passively complicit. Links between datacenters are encrypted. If you want even basic PCI…

As I recall, Google reacted to the Snowden leaks by encrypting traffic within and between its datacenters, which it had not previously been doing.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#306
post #302

Earlier quoted context omitted.

> What I'm getting at is that the things Google and Microsoft are doing are entirely irrelevant to the conversation at hand. It is not. Industry practices are entirely relevant.

So what is your point then? Is it that Apple's punch in the gut here, while bad/wrong, is beyond criticism or outage because if you use Google, you'll get a slap to the face? Or is it that Apple actually isn't doing anything wrong simply because there is some roughly analogous behavior in your view by other companies?

My point is that Google and Microsoft have been scanning everything in your account (including data like emails and the files you mirror to their cloud drive) and have been doing so for the past decade.

Apple has announced a plan to scan only those photos you upload to iCloud Photos, and nothing else.

Further, Apple's scans will occur on device where a single false positive cannot be misused to incriminate you by anyone who can get a subpoena, because Apple's servers won't hold any data showing something happened.

Google and Microsoft's systems are much more invasive and much less private.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#307
post #95

Earlier quoted context omitted.

FISA orders are written by a Judge. Only judges can write these, this is the literal definition of a warrant. Warrants require specifics - Person X, person Y. These are enumerable. There is paperwork. PRISM, based on the data available, is all about consuming data WITHOUT a warrant -- vacuuming data associated with identities that are not associated with ANY identities subject to a court order. Violating laws and pos…

I can't figure it out, are you a corp shill or gubmint? Dang allows both if they are playing our side so this is truly confusing. Can't tell where they've pinned you, jeez they probably give out degrees for that level mental gymnastics.

I am neither. A similar exchange with sneak has happened previously.

It is a frustrating exchange.

The words that have been used attempt to tie two controversial topics together PRISM and FISA. The logic then seems to be that because companies can now report on FISA orders, this means they also willingly participated in PRISM.

What has been said seems to ignore that the FISA reporting by companies shows the number of identities that data has been provided for. PRISM on the other hand looks like a program to collect as much data as possible, regardless of identity.

At this point it is going to just be agree to disagree.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#308
post #124

Earlier quoted context omitted.

Great explainer why this won’t happen: https://pingthread.com/thread/1424873629003702273 > For the conspiracy to work, it'd need Apple, NCMEC and DOJ working together to pull it off voluntarily and it to never leak. If that's your threat model, OK, but that's a huge conspiracy with enormous risk to all participants

No, it does not require Apple, NCMEC and DOJ working together. Apple could intercept hashes that are sent and compare to their own database. Someone in the NCMEC could add non CSAM hashes to their database.

It sounds like you didn't read what I posted, and why the NCMEC can't just add arbitrary hashes.

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#309

Earlier quoted context omitted.

Apple talk about in their technical documentation https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni... page 9 : Synthetic Match Vouchers They generate false positives themselves to hide their knowledge of the true number of collisions.

If they don't keep track of which matches are false positives, wouldn't it be possible to be extremely unlucky and pass the threshold with nothing but false positives generated by Apple? This makes things worse not better.

No, the vouchers attached to the fake positives do not provide information for decrypting the images

Re: Apple Has Opened the Backdoor to Increased Surveillance and Censorship

#310
post #274

Earlier quoted context omitted.

Thing is, iCloud Photos are already not E2E encrypted, so it's sort of irrelevant if they're requiring "vouchers" in this case.

The argument is could this new system result in a court ordering a blanket "send us the backups for anyone who gets a match for any reason" order from some court. This is highly likely in my opinion.

That was in fact my question. Apple thought about tha and the solution looks robust indeed.
Post reply on HN