Live data from Hacker News

WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

theverge.com

321–330 of 372 posts

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#321

Earlier quoted context omitted.

How does Nokia 215 solve the problem? All messages, including any images, wi now go through the carrier's network (and the recipient's carrier) and be subject to intercept, analysis, and sale by those two entities. I'm not sure how is that better? Wouldn't AOSP/Lineage with Signal installed be better?

Carriers, at least in the Czech Republic, are very restricted in what they can do. Regular phone calls and SMS messages are much more private than anything else out there.

It's not the carriers you need to worry about. Regular calls and SMS are absolutely not private.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#322
post #320
post #319

Earlier quoted context omitted.

This document contains the following: > As part of setup, the device generates an encryption key for the user account, unknown to Apple. The question is, how is this generated. Can it be re-derived from information Apple has? If not, how will Apple handle cases where the user loses or breaks their device? Is it derived from the iCloud password? Currently Apple can reset your iCloud password and restore access to your…

This seems to be explained on white paper of PSI system[1]. A lot of math is included, but on the page 30 there is a mention that different devices can be used. I am not the one who can explain that well. [1]: https://www.apple.com/child-safety/pdf/Apple_PSI_System_Secu...

Sure, different devices can be used they share the same key as stated in the document.

But it’s still not clear how that key is derived. It’s not clear, as implemented that Apple do not hold a master key to decrypt all data (as they do currently).

In fact, if the key is randomly generated, if you have one device (as many users do) and you lose that device. Do you lose all your data? Even if you have your iCloud password?

It doesn’t make sense. It would be a massive change to how iCloud currently operates and is used. And I find this extremely unlikely.

Right now, you can browse your photos online. That functionality is going away?

There are seemingly many open questions. But given that there’s no clear statement from Apple, I’m inclined to believe that they retain the ability to decrypt all data.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#323
post #305
post #26

Earlier quoted context omitted.

I blew my entire weekend trying to move off iPhone, to something more trustworthy (a problem that's getting harder, because of some other things going on): https://news.ycombinator.com/item?id=28111995

I run CalyxOS on a refurbished Pixel device. Works great, very privacy-respecting out of the box. Good at being a device that you actually own.

Thanks, I was looking at CalyxOS, and plan to try that "next weekend".

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#324
post #322
post #320

Earlier quoted context omitted.

This seems to be explained on white paper of PSI system[1]. A lot of math is included, but on the page 30 there is a mention that different devices can be used. I am not the one who can explain that well. [1]: https://www.apple.com/child-safety/pdf/Apple_PSI_System_Secu...

Sure, different devices can be used they share the same key as stated in the document. But it’s still not clear how that key is derived. It’s not clear, as implemented that Apple do not hold a master key to decrypt all data (as they do currently). In fact, if the key is randomly generated, if you have one device (as many users do) and you lose that device. Do you lose all your data? Even if you have your iCloud passw…

Most likely you can’t browse your photos online anymore, unless they add some kind of method to export keys from the device(s). I speculate that it is possible to lose all of your data if you lose all of your devices. There might be option to create local backup from device keys, so it would not be the dead end.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#325
post #26

Earlier quoted context omitted.

I blew my entire weekend trying to move off iPhone, to something more trustworthy (a problem that's getting harder, because of some other things going on): https://news.ycombinator.com/item?id=28111995

lineage os is what I use. oneplus devices are simply superb. but you are forewarned - you can blew through way more then a weekend de-oppressing you digital life.

Exactly. I've invested an hour or two :) towards trying to have the tech I use be less-creepy.

It turns out that compromises have to be made. And it's also a moving target.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#326
post #6
post #3

I really hope there is enough momentum to stop this. It's definitely the last straw for me in terms of apple products. I haven't bought a new iphone for 4 years, I'm slowly trying to switch to a lightphone (non smartphone). My mac needs a change but I will probably switch to linux. It's absolutely ridiculous what apple has become. The exact opposite of what they used to represent, when I loved them. God rest Steve Jo…

It’s too late either way. The fact that it even got this far through implementation says the vendor is not on my side. Not only that once capability is revealed it can be required by governments and manipulated under warrant. Particularly in some regimes, mine included, the vendor can be compelled to do something and not say anything. My comment doesn’t even cover how monumentally flawed the entire thing is either. S…

why would you miss apple music? spotify wipes the floor with apple music!?

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#327

Earlier quoted context omitted.

> The government cannot open letters without a warrant, but somehow Apple, Google, MS and co can sniff through electronic communication This is no different than a private doctor testing for illicit drugs and reporting results to the DEA (they literally do this for ADHD patients.)

I know American ADHD patients. None of them take drug tests.

I’m an American ADHD patient. My doctor made me (and his other patients) come in on random weekends for drug tests. He said the DEA made him report his records.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#328
post #244

Earlier quoted context omitted.

> Apple is doing it, soon, on your phone. Apple is only checking images you choose to upload to iCloud photos to see if you are uploading a collection of CSAM. This is entirely optional, and they have publicly explained what they are doing. They are not sniffing through your communications as they see fit.

One last try, after that I'll stop since you are all over these submissions defending Apple here. Take traditional mail. That is not opened, it is, usually, not read. Nor is content checked. It can, and is, opened in case of warrants (let's ignore totalitarian regimes here). What Google is doing when it comes to photos, as was Apple before, is opening every envelope containing photos to check wether or not it was CP.…

traditional mail is under federal jurisdiction from mailbox to mailbox. For obvious reasons. Storing files on a private company's servers is nothing like that whatsoever.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#329

Earlier quoted context omitted.

I know American ADHD patients. None of them take drug tests.

I’m an American ADHD patient. My doctor made me (and his other patients) come in on random weekends for drug tests. He said the DEA made him report his records.

It's easy to find other people saying they don't have to take drug tests. It seems more likely your doctor is mistaken or lying than many other doctors just ignore a legal requirement.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#330

Earlier quoted context omitted.

Generally, if you are shelling out the kind of money for a dslr or mirrorless, you want control over the final image. I shoot in raw and tweak the images I like by hand in darkroom. Lightroom is another option if you want to support adobe. It takes longer but the end result looks MUCH better than anything your phone can produce. That said, sometimes I just want to take a selfie and not fiddle too much. Thats when I u…

What might be useful for the next generation of prosumer cameras is being able to capture depth data (which is probably the main differentiator allowing computational photography to work on smartphones), with editing tools like Photoshop eventually supporting it.

lidar builtin to the mirrorless that takes a depth would be amazing. not just for computational photography but also to make focusing way more accurate!
Post reply on HN