Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

471–480 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#471
post #305
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

Is this anything new, though? The communications haven't been E2E protected ever since people started using phones.

No, but stock phones haven't always been spying on users client side.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#472
post #455

Earlier quoted context omitted.

You can only hire someone to verify your lock if the lock is verifiable in the first place. Apple is trying to make it non-verifiable.

Anything concrete on that? For a fact we know that ios has strong sandboxing, secure bootchain and apps are revokably verified.

> For a fact we know

Not sure about that. No source code. Also, Pegasus.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#473

Earlier quoted context omitted.

We also saw the police query "check-in" databases which were pitched to the public as "for contact-tracing purposes only". Scope creep is inevitable.

Source? Most of these systems didn't disclose location.

Singapore:

https://fortune.com/2021/02/01/singapore-covid-data-tracetog...

https://www.straitstimes.com/singapore/politics/police-can-a...

https://www.straitstimes.com/singapore/proposed-restrictions...

https://www.straitstimes.com/singapore/politics/bill-limitin...

(Note that one mostly-united political party controls 89.2% of Singapore's legislature seats, and can pass any laws or amend its constitution to their liking.)

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#474
post #54

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

Since you worked on an actual contract catching these sorts of people you are perhaps in a unique position to answer the question: will this sort of blanket surveillance technique in general but also in iOS specifically - actually work to help catch them?

I'm the person you're responding to, and I think so? My contract was on data that wasn't surveilled, it was willingly supplied in bad faith. Fake names, etc. And there was cause / outside evidence to look into it. I can't really go into more details than that, but it wasn't for an intelligence agency. It was for another party that wanted to hand something over to the police after they found out what was happening.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#475
Everyone worried about Apple, but Apple is company and follows the laws of the countries it operates in. If this is legal, or even more required by the goverment agencies: Apple will comply. And there is nothing wrong with it. If you don't like the laws of your country, you need to work for that, not just go after Apple on social media.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#476

Earlier quoted context omitted.

Not GP but... >99% of the population will delegate the decision of what code is allowed to run to someone, be it the manufacturer, the government, some guy on the Internet or whatever. For that 99% of the population, by the way, it's actually more beneficial to have restrictions on what software can be installed to avoid malware I do not agree with this. You are saying people are too stupid to make decisions and that…

> I do not agree with this. You are saying people are too stupid to make decisions and that is amoral in my opinion. I'm not saying that at all. I'm saying that it's impossible for all people to make informed decisions on all the issues that surround them, because of both knowledge and time. And it doesn't just happen with computer and privacy, see food, for example. Do you make all decisions about what's allowed or…

But who will formulate these laws that are supposed to give people freedom when we already have malicious state actors pushing for the complete opposite? Who will put pressure on governments to formulate just laws if people are so hopelessly misinformed and cannot possibly take the time to understand the issue of being parted with their freedom?

The suggestion is not that people need to continually invest large amounts of time to manually verify their freedom is being upheld. It is that they should inform themselves once in order to understand the issue and be able to ensure their governments are not secretly becoming totalitarian states.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#477
post #435

Earlier quoted context omitted.

Nearly all the HW items have equivalent or superiour replacements, and a fair amount are dependent on the Apple ecosystem. Without Apple's ecosystem it's a good system but overpriced, and that's before you run into Linux compatibility problems. For example, take the monitor - there are monitors with higher refresh rates or more resolution (Retina does 'only' 6K). Also, Mac OS colour processing has no good equivalent…

Don't higher density displays take more power? Can we actually start making laptop displays that cap out at 1080 or 1440p?

For me (and many out there) DPI is more important than slightly higher battery consumption which becomes less of an issue with other components such as SoC mitigate that with more optimized power usage.

Retina Display when it first arrived was literally THE reason I started switching to Apple ecosystem as it was exponentially better to look at that screen, and I'd even pay more for a 4K display on a MacBook if they brought it.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#478

Earlier quoted context omitted.

> Controlled by another third party. Everything is controlled by a third party except self-hosting. Mastodon allows that too. Closed networks don't. > Yes, you can switch to ProtonMail or something more secure if you want So you answered your own question. > but that won't solve the problems of the 99% of people that will use general providers and won't even know they can't switch. My point is that they are able to s…

> My point is that they are able to switch due to the openness of the platform. And my point is that most won't, and the ones that do will still go to another platform that's controlled by another third party and they'll still need to rust that the platform is not doing things they don't like. > Millions will immediately switch given a possibility. Switch to where? To another company that could do weird things out of…

> My point is that privacy and security is not something that will be solved by federation or open source.

I disagree. Here's why:

> For open source and federation to be useful in that regard, you need most people to actively research and check that the tools that they use are private and secure.

This is the key point. You do not need most people. You need some people. And you can always find some people who verify everything and self-host for you. This is how Signal and Matrix appeared and became (relatively) famous.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#479

Earlier quoted context omitted.

> You can verify any small part and rely on the community to verify the rest. Or pay someone to verify. The only difference in this is who you trust. Be it Apple, the community or someone you pay, you're still trusting that someone else's interests align with yours and they did things correctly. In other words, this is not a technical problem. It's a problem that needs to be solved through regulation, because 99% of…

> The only difference in this is who you trust. Not really. There is a huge difference between trusting a single for-profit entity (who provides backdoor to iCloud in China) or huge number of independent people (each would like to get famous/rich for finding bugs).

Yes, because the "huge number of independent people" have never missed any serious bugs or backdoor, and they also verify every piece of equipment you use.
Post reply on HN