Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

361–370 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#361

A new aspect of this is that because this is self-reported, and the end goal is to involve the criminal justice system, there is now (essentially) an API call that causes law enforcement to raid your home. What would be the result of 'curl'ing back a few random hashes as positives from the database? Do I expect to be handcuffed and searched until it's sorted out? What if my app decides to do this to users? A maliciou…

A report to the cybertips line does not equal a police raid. Unfortunately the scale of the problem and the pace of growth is such that only the worst of the worst content is likely to be prosecuted.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#362
post #284

I'm gonna go out on a limb here. At the end of the day laws are relative so to say. The thought behind such a system is noble indeed, but as we've seen, anything any government gets their hands on, they will abuse it. Classic example being PRISM et al. In theory it's great to be able to catch the bad guys, but it was clearly abused. This is from countries that are meant to be free, forward thinking etc, not any autho…

It's not even hypothetical, it's already known that Apple has to use servers operated by China for their operations there [1] so this capability will be fully within their hands now too to arbitrarily censor and report iPhone users for any material they want to disallow.

[1] https://www.businessinsider.com/apple-data-china-censors-app...

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#363
I won't get into the CSAM discussion but for anyone that has a stash of non-DRMed content I think it's a good idea to look into alternatives to Apple devices. Sooner rather than latter the same kind of system will be auto-deleting or alerting authorities about copyrighted material and I doubt that too much care will be taken to ensure that you didn't actually have a right to those copies.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#364
post #226

It's funny to see anyone here could find this acceptable. I wonder what's comments would be after Apple start to scan phones for anti-censorship or anti-CCP materials in China. Or for some gay porn in Saudi Arabia. Because you know in some countries there are materials that local government find more offensive than mere child abuse. And once surveillance tech is deployed it's certainly gonna be used to oppress people…

Won't anyone think of the children! And Tim Cook personally promised to not look at anything in my unencrypted iCloud backup, they really care about privacy!

And you can be sure that there's no way for the PRC, that already runs its own iCloud, to use this. America's favorite company wouldn't allow that.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#366
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

> closed social networks It’s not clear that governments would give the open social networks an easier ride either. It could be argued that distributed FOSS developers are easier to pressurise into adding back doors, unless we officially make EFF our HR/Legal department. The other problem is workers have a right to be paid. The alternatives are FOSS and/or distributed social media. Who in good conscience would ask a…

> … who amongst us will do UX…

imho, we have everything in the foss world working tightly except great UX/UI. in my experience in the open source world – which is not insignificant – great UX is the only thing stopping us from a paradigm shift to actual tech liberation.

even outside of corporate funded work/commits, we see an astounding number of people donating incredible amounts of their time towards great quality code. but we still thoroughly lack great UX/UI.

i’m not talking about “good”, we have some projects with “good” UX, but very very few with great.

there are many reasons and I’d be happy to share what some of them are, but in my mind great UX is unquestionably one of two primary things holding us back from actual truly viable software liberation.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#367
post #345

Earlier quoted context omitted.

> It could be argued that distributed FOSS developers are easier to pressurise into adding back doors All millions of them at the same time?

Of course not. You'd only need a few important ones, and all you'd have to do is compromise them in one way or another. This can be done via coercion, via money, or by physically or virtually breaking into their system(s). For example, if money can be an incentive, you can stimulate a FOSS dev to add a NOBUS vulnerability in code. Also, since all the code is public, organizations like NSA can do in-house fuzzing, kee…

And any other researcher can fuzz the code themselves too and make their findings public.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#368
So many questions that akes this Tweet look odd. It's a "Client side tool" - so what? An app you install? That law enforcement can install? That Apple can silently install.

It lets "Apple Scan"? So Apple is going to proactively scanning your photos using a tool then install?

So many questions about this. It doesn't add up.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#369
post #278
post #32

Earlier quoted context omitted.

> Stop. Using. Apple. But is there a realistically better alternative? Pinephone with a personally audited Linux distro? A jailbroken Android device with a non-stock firmware that you built yourself? A homebuilt RaspberryPi based device? A paper notepad and a film camera and an out of print street map?

The best bet is probably a pixel phone with GrapheneOS. (Do note, that copperhead os is a scam and is not to be used ) Gnu/linux phones have nonexistent security, other than being niche (so security by obscurity at most). And also, they are not yet usable as a daily driver for me personally, at least.

> Do note, that copperhead os is a scam and is not to be used

Can you expand on this point a little bit?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#370
post #352

Earlier quoted context omitted.

"Nonexistent security" is not an accurate description. It's just a totally different approach to security. It's verifiability . https://puri.sm/posts/defending-against-spyware-like-pegasus... https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque...

That’s not how security works. Whether or not I am allowed to check that my entrance has no locks whatsoever doesn’t make it harder to open it. And the reverse, even if I don’t know the details of the lock in my door, it will not let others pass through.

> even if I don’t know the details of the lock in my door, it will not let others pass through.

You absolutely can not make that assertion without being able to verify the lock.

Post reply on HN