I want to ignore most of this article to complain about an inaccuracy that keeps coming up. > More broadly, they said the change will break end-to-end encryption for iMessage, which Apple has staunchly defended in other contexts. But... it wouldn't. The iMessage feature doesn't expose the contents of your message to anyone else under any circumstance. If you're a child under 13 and your parents have opted in to this…
Let's also not pretend that some of this confusion done is 100% willfully by some of the news organizations reporting on this because it benefits them to conflate the two. We even see it a little from places like EFF who appear to believe their ends justify the means.
Apple urged to drop plans to scan iMessages, images for sex abuse
61–70 of 129 posts
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#62Earlier quoted context omitted.
> I want true end to end enc. People who say things like this rarely also want the hassle that comes with it. Key exchanges, re-keying: all a big PITA. But iMessage (and WhatsApp) do key exchanges facilitated by a trusted broker. If you didn't trust the broker, you would have to do more work when making an initial exchange with a peer and more work if they lost their phone/keys. iMessage has always been a compromise…
Key exchange would be easy in real life, just bump phones when you meet someone. It's only difficult on IRC.
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#63I want to ignore most of this article to complain about an inaccuracy that keeps coming up. > More broadly, they said the change will break end-to-end encryption for iMessage, which Apple has staunchly defended in other contexts. But... it wouldn't. The iMessage feature doesn't expose the contents of your message to anyone else under any circumstance. If you're a child under 13 and your parents have opted in to this…
It's possible that they determined that dealing with the backlash in one go would be easier than having two separate blowups. Most consumers have only fuzzy, vague senses of brands based on a poorly-understood game of Telephone linked to each news cycle. This only counts as "one" privacy ding against Apple for most people, whereas two separate news cycles would do much more damage to their reputation around privacy.
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#64Im not sure if im missing something here, but from what I understand, what Apple is proposing is an enormous privacy boon that seems to be completely misunderstood. All cloud providers are required to, and do, make these scans. The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, excep…
- I don't want the rules to change in the future for what will be scanned.
- I don't want to support Apple scanning for pictures of Tank Man for the CCP.
- I don't want an untested proprietary algorithm making decisions about me that could alter my life. It's already been shown that you can make innocent pictures that collide with CP hashes. This screams of future abuse.
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#65Earlier quoted context omitted.
The concern is that Apple is handing governments a new tool to go “give me a list of all users that have this photo”. It could track down dissidents based on this and combined with metadata is probably sufficient to pinpoint who took a particular picture. Think you shared that picture of police brutality anonymously? Think again.
Apple can already decrypt your iCloud photos, same with google etc. I don’t get this argument as they can already do that.
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#66Earlier quoted context omitted.
I don't think so, it doesn't really need to "analyze" your messages to do preview urls, show videos... Those are more like frontend stuff IMO
No more frontend than running a basic subject recognition on a photo.
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#67Im not sure if im missing something here, but from what I understand, what Apple is proposing is an enormous privacy boon that seems to be completely misunderstood. All cloud providers are required to, and do, make these scans. The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, excep…
If the CSAM detection were released with encrypted iCloud backups (or generally E2EE iCloud), then I think I'd probably be entirely less outraged. This narrative would make sense then.
Apple claims the on-device CSAM scanning only occurs on device if the photo in question is uploaded to iCloud. Apple is surely already scanning iCloud photos on their cloud, so without E2EE to iCloud, what's the point?
My ability to control a device I own, with Apple, was already suspect. Apple's use of on-device scanning is a slippery slope: it's not a question of if it will be used for nefarious means, but when. The claim that the scanning is only done for cloud-destination images is suspect and could be changed by gagged government coercion and a minor update.
The feature itself has little going for it in efficacy too: like most of the US's punishment bureaucracy / legal system / policing. Real child predators likely already avoid the cloud. These kind of slippery slope arguments against crime are often used by law enforcement to erode privacy rights: they don't actually catch more bad guys, but they do spy on more law abiding citizens.
Who's to say that in the future, law enforcement won't use this kind of technology for the war on drugs or other failed law enforcement initiatives? Law enforcement often uses violence or terrorism, for example, as justification for its own expansion and more privacy-invading initiatives, but terrorism is a very low threat, and only 4% of crimes in the US are violent (as defined by the FBI). CSAM has been used for decades as justification for the state to nose more in private citizens' business too. It's certainly an issue, but there have to be better ways to reduce child harm.
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#68So, what parts of my phone are actually being scanned by this system? It seems like it's rummaging through any images that are touch iCloud, which would include: - iMessage - WhatsApp - Camera - Matrix (?) - Any other application that you give 'photo' permission to?
Messages will be scanned for CSAM content if you are a child, then parents will get notified that they received a dickpick.
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#69Earlier quoted context omitted.
> I want true end to end enc. People who say things like this rarely also want the hassle that comes with it. Key exchanges, re-keying: all a big PITA. But iMessage (and WhatsApp) do key exchanges facilitated by a trusted broker. If you didn't trust the broker, you would have to do more work when making an initial exchange with a peer and more work if they lost their phone/keys. iMessage has always been a compromise…
Key exchange would be easy in real life, just bump phones when you meet someone. It's only difficult on IRC.
If iMessage had been designed to require a brokerless key exchange, its security would be superior (though in this case, Apple's interception software trumps everything). But iMessage would appear to be less convenient than alternatives like WhatsApp (brokered key exchange, re-keying).
Re: Apple urged to drop plans to scan iMessages, images for sex abuse
#70Earlier quoted context omitted.
They could comply with a nation state's demands to scan a billion iPhones for a politically dangerous photo.
You'd need 30 of them. And upload them iCloud. I guess the neural part is a bit of a blackbox, im not sure if theres a way for external parties to verify its legitimatcy. But again, any change to would go noticed.
If a nation state can demand Apple uses their existing function to scan your phone for political images, then they can likewise demand that 1 hit would be enough, and that there's no requirement for it to be uploaded to iCloud before the scanning can start.