Live data from Hacker News

WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

theverge.com

331–340 of 372 posts

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#331
post #324
post #322

Earlier quoted context omitted.

Sure, different devices can be used they share the same key as stated in the document. But it’s still not clear how that key is derived. It’s not clear, as implemented that Apple do not hold a master key to decrypt all data (as they do currently). In fact, if the key is randomly generated, if you have one device (as many users do) and you lose that device. Do you lose all your data? Even if you have your iCloud passw…

Most likely you can’t browse your photos online anymore, unless they add some kind of method to export keys from the device(s). I speculate that it is possible to lose all of your data if you lose all of your devices. There might be option to create local backup from device keys, so it would not be the dead end.

Given the lack of an explicit announcement this seems very unlikely.

I don’t think Apple are stupid, it would have been a clear PR win if they said “we’re adding E2EE”.

Given no explicit statement, and how drastically it changes the nature of their service, I don’t think your speculation is justified.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#332

Earlier quoted context omitted.

Imagine now a young child being sexually abused in front of a camera for all its years of existence, and that there's no knock on the door.

False dichotomy, how long will it take the predators to learn not to use apple devices as cameras? Yet the privacy implications will last forever. Once it's implemented, it only takes a rubber-stamp warrant to compel Apple to scan your device for anything the government deems concerning. In fact, no warrant needed in most countries.

> how long will it take the predators to learn not to use apple devices as cameras?

Which is why you make it mandatory on all devices sold, not just apple.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#333
post #120

Earlier quoted context omitted.

>The problem I have with this approach is that it introduces on-device scan for images. Windows already does this via Windows Defender. This is a basic AV functionality and much more privacy preserving.

But Windows Defender doesn't report you to law enforcement when it believes it found a virus.

Neither does this.

https://www.howtogeek.com/719825/how-to-stop-windows-10s-ant...

If Microsoft receives an illegal file through this channel, they are legally obligated to report it in the US.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#334
post #270

Earlier quoted context omitted.

Interesting, time for American teens to switch to WhatsApp, Telegram or Signal. Kids have sex life finds a way. Has Apple thought this through?

Interesting observation. This might be more damaging to Apple than anything else. Without iMessage/Facetime, a large part of the peer pressure teens get for having an iPhone is gone. Now they might start asking for a Galaxy or something like that.

Tweens, yes. Teens can be opted into the feature but it only offers the (teen) user a warning before viewing the image, it never notifies the parent.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#335

Earlier quoted context omitted.

But Windows Defender doesn't report you to law enforcement when it believes it found a virus.

Neither does this. https://www.howtogeek.com/719825/how-to-stop-windows-10s-ant... If Microsoft receives an illegal file through this channel, they are legally obligated to report it in the US.

...if a human actually gets the file, figures out what type it is, and examines it for themselves, they'd be obligated to report it. With the number of Win10 devices in the world, how big would their security team have to be to hand-groom every automatically submitted "suspicious" sample? (For that matter, why would a vanilla JPG get flagged as "suspicious" in the first place?)

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#336
post #35

So I was ignorant on the issue and completely against the approach of Apple. Then HN taught me that any company storing images on their infrastructure in the US must report pedophilic images to the US government. At this point, the approach taken by Apple seems like the best one to me, if you don't want to store pictures in clear on your servers. What other technical approach are people advocating for? Another point…

Apple's banned image reporting wont stay iCloud only.iMessage is next. Maybe all data on your phone. 1) phone scanning is overkill for pics already on their servers. You don't build this and take the PR flack for something you can already do server side 2) Even if it's somehow not Apple's plan, they will be forced to use it on iMessage. Congress has been trying to for years.See the EARN IT act[0]. Apple just erroneou…

From everything that I've read, iCloud Photo Library is currently encrypted on the server, with a key that Apple only uses when presented with a warrant. If I ran the company (disclaimer: I do not) I'd implement this with an airgapped system in a vault somewhere, where a very small number of people have access to bring encrypted images in on a CD-R under two-person control.

That being said, one of two things is true. Either Apple does exactly what they say, in which case they are not able to perform server-side content / fingerprint scanning, or Apple is outright lying about only using their key on behalf of law enforcement. This latter case would open them to all sorts of legal liabilities, like a suit from shareholders for false reports. It would also require the silence of every Apple engineer who has ever been involved in at least their iCloud Photo program, and probably a bunch of server infrastructure as well. Additionally, they'd be legally obligated to report their scan results to the NCMEC but would have to do so in a way that doesn't give away that they're lying about how their systems work.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#337
post #176
post #35

So I was ignorant on the issue and completely against the approach of Apple. Then HN taught me that any company storing images on their infrastructure in the US must report pedophilic images to the US government. At this point, the approach taken by Apple seems like the best one to me, if you don't want to store pictures in clear on your servers. What other technical approach are people advocating for? Another point…

>if you don't want to store pictures in clear on your servers Reading https://support.apple.com/en-us/HT202303 , it seems that Apple may encrypt pictures on their servers, but they have the key. The list of what's actually end-to-end encrypted doesn't include photos. So, they may be scanning on your phone, but they can scan on their servers if they wanted to.

I posted more detail upthread but what I've found suggests that Apple does have a key to decrypt pictures but they claim to use it only to respond to a warrant. (They could of course be lying about that, but I don't believe they are.)

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#338
post #105
post #42

Earlier quoted context omitted.

Apple doesn’t scan iCloud for CSAM and refuses to do it. Which is why they researched intensively on differential privacy.

But they could, as iCloud Photos is not e2e (Apple can read all of it) and they turn over the user data on over 30,000 users per year to the USG without even a warrant. This is just farce.

Does that 30k number include iCloud Photo data? Do you have a citation for this?

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#339

I'm in two minds about this Apple news. In one part, the pro-privacy part of me is of course aghast at the whole idea. However... If you "read the room", there have been increasing noises from the global political world in recent years, and perhaps especially in the US. So if you think about it that way, it might be a case of Apple jumping before they were pushed. I mean, let's face it, if you wait for the politicos…

> let's face it, if you wait for the politicos to come up with a solution and force it through with legislation, they really would put in actual backdoors and encryption bans given half the chance. They've tried to do this for decades and have failed. If they're going to do it then let it be on record. Let's see how voters like it.

Bad news, buddy: https://www.patrick-breyer.de/en/posts/message-screening/?la...

ETA: in short, about a month ago they did get the votes, at least in the EU, and it's now "allowed" for providers to scan all content. In a little while, they're going to have a vote to change "allowed" to "required", and we have no reason to think it'll go differently.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#340
post #56

“other tech experts“ want to keep Apple from using End2End encryption so they have a reason why they don’t provide it to their customers. With Apple‘s approach Apple can only decrypt Data hosted with them if the (false) positives are over a threshold. It‘s a pretty neat way to implement a usecase so deeply wrong. All other companies protesting now want to keep access to userdata in the clear. Apple‘s approach is the…

Just to be clear, the EU already voted to allow snooping, the law "currently in the works" is to require it:

https://www.patrick-breyer.de/en/posts/message-screening/?la...

Post reply on HN