This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…
Apple's child protection features spark concern within its own ranks: sources
391–400 of 860 posts
Re: Apple's child protection features spark concern within its own ranks: sources
#392Earlier quoted context omitted.
That is, it seems like Apple really wanted to preserve "end-to-end" encryption,“ … except they still have not mentioned anything about E2E encryption… and they currently don’t encrypt icloud backups. You would think apple would get ahead of this story and mention … or maybe they don’t have any E2E plans at all.
This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…
I disagree completely on this. For one, users aren't aware that using iCloud means that Apple has your decryption key and can thereby read and share all of your phone's data.
And two, opt-out is a dark pattern. Particularly if you surround it with other hurdles, like long click-wrap and confusing UI, it's no longer a fair choice, but psychological manipulation to have users concede and accept.
Third, as it's hinted, smarter criminals, the ones the FBI should actually worry about, will know to opt-out. So instead the vast majority of innocent users have their privacy violated in order to help authorities catch "dumb" criminals who could have very well been caught through countless other avenues.
disclaimer: I just read Bruce Schneier's "Click Here To Kill Everybody" after the pipeline ransomware attack, and these points come straight from it.
Re: Apple's child protection features spark concern within its own ranks: sources
#393Apple's track record on user protection compared to Google or Samsung has been very good. For example, resisting wide net Federal "because terrorism" warrants as much as they legally can. There's a reason why Apple 0 day exploits sell for way more on the black market than Android exploits. Trust is hard to earn, easy to lose and even harder to regain. User trust is such a huge part of Apple's business and success, it…
The opposite is true.
They're both shit though. Use FOSS operating systems you can administrate or don't bother with smartphones.
Re: Apple's child protection features spark concern within its own ranks: sources
#394I'm going to start rallying for my employer to dump apple as a vendor if they stay the course.
Re: Apple's child protection features spark concern within its own ranks: sources
#395There are two things that make me think this will be walked back. Firstly, and most importantly, this kind of backdoor is the kind of thing that makes big corps prohibit the use/purchases of devices. Secondly, it seems rife for abuse: dont like someone who uses an ios device, msg them some cp and destroy their entire life.
One makes them look bad and the other makes them lose money. Which do you think they will choose?
Re: Apple's child protection features spark concern within its own ranks: sources
#396Earlier quoted context omitted.
I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…
Something probably did happen. Apple no doubt became increasingly aware of just how legally culpable they are for photos uploaded to iCloud. For content that is pirated Apple would receive a slap on the wrist, but for content that shows the exploitation of children? And that Apple is hosting on their owned servers? There is no doubt every government will throw their full legal weight behind that case. Now they are st…
Re: Apple's child protection features spark concern within its own ranks: sources
#397This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…
I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…
This seems like an incredible reach to me.
Re: Apple's child protection features spark concern within its own ranks: sources
#398Earlier quoted context omitted.
And that's all it ever was, perceived differentiation. They were never truly concerned with privacy ever.
Not really you were essentially immune to a lot of the ad spying and individual databases that google built up on you to sell to 3rd parties that advertised to you. Also apps were given much less freedom to spy on you or access your on device file. Apple just threw all the good sentiment they built up over google down the shitter and try to convince us otherwise with "think of the children".
Re: Apple's child protection features spark concern within its own ranks: sources
#399Earlier quoted context omitted.
The technical risk to user privacy - if your threat model is a coerced Apple building surveillance features for nation state actors - is exactly the same between CSAM detection and Photos intelligence which sync results through iCloud. In fact, the latter is more generalizable, has no threshold protections, and so is likely worse.
It's the legal risk that is the biggest problem here. Now that every politician out there knows that this can be done for child porn, there'll be plenty demanding the same for other stuff. And this puts Apple in a rather difficult position, since, with every such demand, they have to either accede, or explain why it's not "important enough" - which then is easily weaponized to bash them. And not just Apple. Once tech…
Re: Apple's child protection features spark concern within its own ranks: sources
#400Earlier quoted context omitted.
I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…
Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As the project progressed, however, it's like they missed "the forest for the trees" and didn't quite realize that their plan to protect end-to-end encryption doesn't mean that much if one "end" is now forced to run tech that can be abused by governments. Sincere or not, the "the only way we could do true X is by making X utterly…
Consider the this new hypothetical future state:
1) photos are encrypted on iCloud
2) photos are hash scanned before being encrypted and uploaded.
In this new state no valid subpoena can get access to the encrypted photos on iCloud without also getting the key on your device. What is your metric where this is not a better state than the current state where every photo is available in the clear to any government that asks and must be preserved when given a valid order to do so?If you don’t upload photos to iCloud there is no change.
In all scenarios you have to trust Apple to write software that does what they say and that they won’t write software in response to a subpoena to target you specifically.
The attack with the hash scanning is someone gets a hash for something in your photos specifically (that doesn’t match a ton of people) and through some means gets it into the database (plausible), but can’t get anything without going though this route. Specifically subpoenas can’t just get all your photos without going through this route.
My conclusion is that you are more protected in the hash scan and encrypt state than in current state.