Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

371–380 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#371

Earlier quoted context omitted.

Something probably did happen. Apple no doubt became increasingly aware of just how legally culpable they are for photos uploaded to iCloud. For content that is pirated Apple would receive a slap on the wrist, but for content that shows the exploitation of children? And that Apple is hosting on their owned servers? There is no doubt every government will throw their full legal weight behind that case. Now they are st…

I doubt a judge can find apple liable for hosting encrypted data if its illegal. That would mean every e2e storage solution, or even just encryption and storing files on a s3 bucket host would be liable. Apple should use it's gigantic legal arm to set good precedents for privacy in court.

First, there is nothing stopping a full legislative assault on end to end encryption, various such proposals have had traction recently in both the US and EU.

The lawyerly phrase is “knew or should have known.” It could be argued that now that this technology is feasible, failure to apply it is complicity.

Think about GDPR. Eventually homomorphic encryption is going to be at a point where “we need your data in the clear so we can do computations with it on the server” will cross from “failure to be on the bleeding edge of privacy research” to “careless and backwards.”

Re: Apple's child protection features spark concern within its own ranks: sources

#372
post #198

Earlier quoted context omitted.

This is the most honest take on this that I’ve seen. The slippery slope arguments don’t make sense, nor does the risk of false positives. But the idea of being suspected even in this abstract way, because of something other people do , is at the very least distasteful, bordering on offensive.

I would not say the slippery slope take doesn't make sense. It is perfectly possible that had no one cried out about this change then the next change would have been: Large government to Apple: "Please now also create a hash on each photo metadata field including date/time and location. Let us query these. AND BTW, this change must be kept secret. Thanks."

[deleted]

Re: Apple's child protection features spark concern within its own ranks: sources

#373

Earlier quoted context omitted.

I think you’re going to have to go to a flip phone, then. Not to be, uh, flippant. Because this feels like a rather obvious slippery slope that Google will be compelled to slide down as well. Feels like the only way to avoid such a thing would be dumb phone + Linux laptop/desktop.

Thankfully flip phones aren't necessary! Startups like Purism are at the cutting edge of building privacy-respecting devices, check it out here: https://puri.sm

and pinephone: https://www.pine64.org/pinephone/

Plan to get one as my next phone, although it should be said that both of these offerings are still a bit rough around the edges currently, but getting there

Re: Apple's child protection features spark concern within its own ranks: sources

#374
post #292

Apple's track record on user protection compared to Google or Samsung has been very good. For example, resisting wide net Federal "because terrorism" warrants as much as they legally can. There's a reason why Apple 0 day exploits sell for way more on the black market than Android exploits. Trust is hard to earn, easy to lose and even harder to regain. User trust is such a huge part of Apple's business and success, it…

> There's a reason why Apple 0 day exploits sell for way more on the black market than Android exploits.

FWIW, every article I see is about iOS exploits being cheaper than android because there are so many of them. Those articles all seem to be from around 2019, though. It seems like before 2019 what you said was true. I'm sure sure what prices are like within the last two years.

https://www.google.com/search?q=android+vs+ios+exploit+cost

Re: Apple's child protection features spark concern within its own ranks: sources

#375

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

> didn't quite realize that their plan to protect end-to-end encryption doesn't mean that much if one "end" is now forced to run tech that can be abused by governments

Not just one end, but specifically the end that their users thought they had control over.

Re: Apple's child protection features spark concern within its own ranks: sources

#376

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As the project progressed, however, it's like they missed "the forest for the trees" and didn't quite realize that their plan to protect end-to-end encryption doesn't mean that much if one "end" is now forced to run tech that can be abused by governments.

Sincere or not, the "the only way we could do true X is by making X utterly useless and meaningless" thing certainly seems like bureaucracy speaking. It's a testament to "the reality distortion field" or "drinking the Koolaid" but it shows that the "fall-off" of such fields can be steep.

Re: Apple's child protection features spark concern within its own ranks: sources

#377
post #297

Earlier quoted context omitted.

That’s wrong. They are also enabling on-device detection for Messages.

Communication safety in Messages is a different feature than CSAM detection in iCloud Photos. The two features are not the same and do not use the same technology. In addition: Communication safety in Messages is only available for accounts set up as families in iCloud. Parent/guardian accounts must opt in to turn on the feature for their family group. Parental notifications can only be enabled by parents/guardians f…

Yeah, for now this is what is stated. It should be alarming how much they pivoted and changed with out any background statment. Something more is at play.

Re: Apple's child protection features spark concern within its own ranks: sources

#378
post #318

Earlier quoted context omitted.

>As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone. Except for the "oops, due to an unexpected bug in our code, every image, document, and message on your device was being continuously scanned" mea culpa we will see a few months after this goes live.

The potential for this is overblown and I think a lot of people haven’t taken the time to understand how the system is set up. iOS is not scanning for hash matches and phoning home every time it sees one, it’s attaching a cryptographic voucher to every photo uploaded to iCloud that, if some number of photos represent hash matches (the fact of the match is not revealed until the threshold number is reached), then allo…

I hear you, 100%, but as a longtime Apple and iCloud user I have been through the absolute ringer when it comes to iCloud and have little faith in it operating correctly.

1. About 3 years ago, there were empty files taking up storage on my iCloud account, and they weren't visible on the website so I couldn't delete them. All it showed was that an excessive amount of storage was taken up. Apple advisors had no idea what was going on and my entire account had to be sent to iCloud engineers to resolve the issue. They never followed up, but it took months for these random ghost files to stop taking up my iCloud storage.

2. Sometimes flipping them on and off a lot causes delays in the OS and then you have to kill the Settings app and re open it to see if they're actually enabled. Back when ATT was just being implemented, I noticed it was grayed out on my phone every time I was signed in to iCloud, but was completely operational when I was signed out. Many others had this issue and there was literally no setting to change within iCloud; it was a bug that engineering literally acknowledged to me in an email (they acknowledged that it happened for some users and fixed it in a software update).

Screwups happen in an increasingly complex OS and I just feel that there will be a day when this type of bug surfaces in addition to everything that already happens to us end users.

Re: Apple's child protection features spark concern within its own ranks: sources

#379

Earlier quoted context omitted.

That is, it seems like Apple really wanted to preserve "end-to-end" encryption,“ … except they still have not mentioned anything about E2E encryption… and they currently don’t encrypt icloud backups. You would think apple would get ahead of this story and mention … or maybe they don’t have any E2E plans at all.

This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…

iMessage isnt true E2E encryption. Apple could easily decode messages for a 3rd party if they wanted to. This has been widely discussed on HN previously. All they have to do is insert an additional private key in the two party chat, as the connection is ultimately handled centrally.

There's a very good reason Signal (and previously Whatsapp) were recommended over iMessage.

Not to mention the inability to swap iMessage off for SMS which has made it a favourite exploit target for hacking firms like NSO.

Re: Apple's child protection features spark concern within its own ranks: sources

#380
post #100

Earlier quoted context omitted.

That is to say face scanning is equally insidious as the new feature?

The technical risk to user privacy - if your threat model is a coerced Apple building surveillance features for nation state actors - is exactly the same between CSAM detection and Photos intelligence which sync results through iCloud. In fact, the latter is more generalizable, has no threshold protections, and so is likely worse.

It's the legal risk that is the biggest problem here. Now that every politician out there knows that this can be done for child porn, there'll be plenty demanding the same for other stuff. And this puts Apple in a rather difficult position, since, with every such demand, they have to either accede, or explain why it's not "important enough" - which then is easily weaponized to bash them.

And not just Apple. Once technical feasibility is proven, I can easily see governments mandating this scheme for all devices sold. At that point, it can get even more ugly, since e.g. custom ROMs and such could be seen as a loophole, and cracked down upon.

Post reply on HN