Live data from Hacker News

WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

theverge.com

311–320 of 372 posts

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#311
post #280

Earlier quoted context omitted.

And their actions show that they aren’t likely to do any of the scary things they are being accused of. That’s the point - people keep claiming some nefarious slippery slope, which is of course in the realm of possibility , but is not actually happening.

Apple stores user iCloud backups and their encryption keys on Chinese government-controlled servers in China, and gives the Chinese government full access to those servers. And routinely grants the US government warrantless access to those same backups in the US. So what actions are you referring to that show they won't do any of those scary things?

Right, so presumably you’d agree that the people who are saying that CSAM detection is a problem because China might abuse it are just being silly, right?

As for the US government having access to the backups, that’s required by law.

You can always make the paranoid case that Apple wants to do this because they are somehow lying about their values, or you can make the case that their hand has been forced.

You could also note that they promised to implement e2e backups but haven’t yet, and this is rumored to be because the FBI asked them not to.

If you assume that Apple is doing this stuff because they want to, then of course you’ll see this next move as just another bad thing they are doing.

If on the other hand you consider that they don’t want to do these things but are being forced to until they have a better option, then you can look at this move as a way to get out of a double bind.

Now they can turn on e2e without being accused of creating a safe haven for pedophiles.

Both pathways are plausible, but given the investment in privacy Apple has been making and the consistency with which they state their values and boundaries, I don’t think they want to be creating backdoors.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#312

Earlier quoted context omitted.

So, you trust Apple to install this spyware and only use it in the way they currently describe. Great! But what happens the second they get an order from $GOVERNMENT that tells them to use the spyware to also look at other documents on the device? I think it's pretty obvious what Apple will say. They'll say "OK." They have no plausible deniability to tell $GOVERNMENT to go pound sand - they have demonstrated the capa…

They could have done what you describe at any time in history. This doesn't change anything in that regard. Either you trust Apple enough to use their products or you don't.

They could have done that any time because their code is proprietary, their hardware closed & won't boot code not signed by apple + they gate keep all third party apps from their walled garden.

It would be much harder for them to pull of if the system was open with user actually in control.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#313

Earlier quoted context omitted.

On a DSLR front: are there now DSLR/cameras that do the type of "computational photography" that pixel or iphones are doing? Not having to edit the pictures is a huge plus, and JPG files in Nikon, even with dynamic range on, are pretty mediocre compared to Pixel phone.

Generally, if you are shelling out the kind of money for a dslr or mirrorless, you want control over the final image. I shoot in raw and tweak the images I like by hand in darkroom. Lightroom is another option if you want to support adobe. It takes longer but the end result looks MUCH better than anything your phone can produce. That said, sometimes I just want to take a selfie and not fiddle too much. Thats when I u…

What might be useful for the next generation of prosumer cameras is being able to capture depth data (which is probably the main differentiator allowing computational photography to work on smartphones), with editing tools like Photoshop eventually supporting it.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#314
post #259
post #112

Earlier quoted context omitted.

> Would you rather they keep photos non-E2E forever and have even more unfettered access to them than a "backdoor" allows? It does NOT scan photos that are not uploaded to the cloud, despite being on-device. Yes I'd rather they do this. The fact that they're implementing on device checks doesn't suggest to me that they will be deploying E2E encryption. It suggests to me that they will be expanding on device scanning…

Their PR did not handle this well. If you look at the spec, new encryption level has been added, which allows access by Apple only if CSAM hash threshold is reached. It is E2EE with backdoor now.

Unless you have a public reference, I really doubt this is the case.

Because they’d also need to be announcing that you can no longer reset your iCloud password and recover to a new device. And I’ve not seen anything that suggests this.

So I suspect it is encrypted at rest, with a key known to Apple as before as well as this CSAM approach.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#315
post #127

Earlier quoted context omitted.

I have to remind again, that iOS is a blackbox, closed source system. All this speculation applies also for a moment before they added anything. They might have had this code ready for years already. All we have is what they say. It is already very trivial to scan everything on on your device and send that metadata. Few lines of code. At the moment when they say about scanning everything in phone publicly without opt…

The difference is now every government knows too. They can't pretend they don't have the capability. And if they can scan for CP, why can't they scan for "whatever" else instead.

This is not the first time they have run into this - due the to AppStore being a walled garden they are the sole gate keeper who decides what goes in and what not. Makes sure the users are safe and everything. Perfect, right ?

Well, until protesters want to use an app in the store to coordinate their protests yet the government wants you to reject it, so the protesters can't use it:

https://www.applefritter.com/content/teargas-walled-garden-i...

With users not being able to install the app themselves Apple is the single point of failure with no plausible deniability like Android (any any sane OS in general) has. And they did reject the app.

And just a few months before this happened I attended a talk about free software from FSF and they mentioned just the same thing about iOS and the gate keeper being the single point of failure a repressive regime can apply pressure on. Turned on to not be far fetched at all...

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#316
post #314
post #259

Earlier quoted context omitted.

Their PR did not handle this well. If you look at the spec, new encryption level has been added, which allows access by Apple only if CSAM hash threshold is reached. It is E2EE with backdoor now.

Unless you have a public reference, I really doubt this is the case. Because they’d also need to be announcing that you can no longer reset your iCloud password and recover to a new device. And I’ve not seen anything that suggests this. So I suspect it is encrypted at rest, with a key known to Apple as before as well as this CSAM approach.

There is public reference on Apple site[1].

Citing final phrase on the paper to TLDR their system:

> Apple is able to learn the relevant image information only once the account has more than a threshold number of CSAM matches, and even then, only for the matching images.

This applies only for images, so you can still reset your password. Technically, there are two layers of encryption on images. Regular server-side encryption and this "E2EE like" encryption, which allows access for CSAM matches in specific threshold.

[1]: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#317
post #104

Earlier quoted context omitted.

Thats not facebook. Some scummy companies do sell user data, but facebook does not and never has.

For Facebook to be selling my data, it isn't necessary that they email a data broker some spreadsheet of my personal data. Selling advertisers access to an incredibly intimate and private picture of my personal life so that they can best exploit my specific life circumstances to unduly influence me is exactly what bothers me about Facebook "selling my data." To claim that Facebook isn't selling my data is a semantic…

“literally sell all your data to anyone who wants”

This, which started the discussion, is just downright false. Who does Facebook sell my private photo albums to for instance? How could I buy someone’s photos?

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#318

Earlier quoted context omitted.

The right to secret communication. The right of not being under surveillance. The government cannot open letters without a warrant, but somehow Apple, Google, MS and co can sniff through electronic communication as they see fit because of a clause in an EULA. No idea how came there, but maybe the days when Stasi surveillance was the poster child of government intrusion into private life are too long gone to be rememb…

> The government cannot open letters without a warrant, but somehow Apple, Google, MS and co can sniff through electronic communication This is no different than a private doctor testing for illicit drugs and reporting results to the DEA (they literally do this for ADHD patients.)

I know American ADHD patients. None of them take drug tests.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#319
post #316
post #314

Earlier quoted context omitted.

Unless you have a public reference, I really doubt this is the case. Because they’d also need to be announcing that you can no longer reset your iCloud password and recover to a new device. And I’ve not seen anything that suggests this. So I suspect it is encrypted at rest, with a key known to Apple as before as well as this CSAM approach.

There is public reference on Apple site[1]. Citing final phrase on the paper to TLDR their system: > Apple is able to learn the relevant image information only once the account has more than a threshold number of CSAM matches, and even then, only for the matching images. This applies only for images, so you can still reset your password. Technically, there are two layers of encryption on images. Regular server-side e…

This document contains the following:

> As part of setup, the device generates an encryption key for the user account, unknown to Apple.

The question is, how is this generated. Can it be re-derived from information Apple has? If not, how will Apple handle cases where the user loses or breaks their device?

Is it derived from the iCloud password? Currently Apple can reset your iCloud password and restore access to your images. Will Apple no longer be able to do this in the future?

It’s really unclear to me, and I’d want explicit answers to these questions personally.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#320
post #319
post #316

Earlier quoted context omitted.

There is public reference on Apple site[1]. Citing final phrase on the paper to TLDR their system: > Apple is able to learn the relevant image information only once the account has more than a threshold number of CSAM matches, and even then, only for the matching images. This applies only for images, so you can still reset your password. Technically, there are two layers of encryption on images. Regular server-side e…

This document contains the following: > As part of setup, the device generates an encryption key for the user account, unknown to Apple. The question is, how is this generated. Can it be re-derived from information Apple has? If not, how will Apple handle cases where the user loses or breaks their device? Is it derived from the iCloud password? Currently Apple can reset your iCloud password and restore access to your…

This seems to be explained on white paper of PSI system[1]. A lot of math is included, but on the page 30 there is a mention that different devices can be used. I am not the one who can explain that well.

[1]: https://www.apple.com/child-safety/pdf/Apple_PSI_System_Secu...

Post reply on HN