Live data from Hacker News

EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

eff.org

61–70 of 215 posts

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#61
post #18

> [...] and the parental notification system is a shift away from strong end-to-end encryption. That particular statement doesn't make much sense to me. The parental notification system is just a frontend action (one of many, like link previews and such). What does that have to do with iMessage's encryption? I can see an argument about a shift away from privacy (though it only pertains to minors under 13 receiving se…

EFF would probably argue that technologies like safe browsing are also a shift away from E2E encryption. They were strongly against email spam protection in the 90s for this reason.

You mean when they said blanket banning email lists is bad and shouldn't be done? Because yeah that's still true.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#62
post #45

Earlier quoted context omitted.

> You’d have to not only have over 30 hash collisions That's trivial. If the attacker can get one image onto your device they can get several. It's very easy to construct preimages for Apple's neural hash function, including fairly good looking ones (e.g. https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX/issue... ) > collide with another secret hash function The supposed other 'secret' hash function cannot be se…

If this really was such a problem, then as I said, we’d have been getting reports of this over the past 10+ years it’s already been in place at big cloud providers. So where is all of this ruining of peoples lives by uploading CP on their devices? Also if you’re a gov actor trying to frame someone, why bother with a pre-image when you could put the real images on it? None of that is new today — all that’s new is Appl…

> So where is all of this ruining of peoples lives by uploading CP on their devices?

Once the capability is in place on everyone's devices, how are we supposed to guarantee it will never be used maliciously? Just say no to the capability.

> Also if you’re a gov actor trying to frame someone, why bother with a pre-image when you could put the real images on it?

Because the capability for this is now built-in in everyone's phones.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#63

Earlier quoted context omitted.

The request from the FBI in the San Bernardino case was to change a passcode limit constant and retry timeouts. Those are about as trivial to implement as any of the convoluted government coercion database attacks against CSAM detection being proposed here.

The difference here is, that apple would have to develop a new feature for them, test it, and waste millions in lawers to protect themselves from accusations of tampering with the evidence (which a software update definitely is, and who knows what FBI wanted in that software update, maybe even to insert a fake sms to the sms database, or many other things a good defense lawyer could bring to the jury). Here, it's dif…

But the FBI can’t just add the hashes to the db. That’s why it’s the intersection of two dbs in two jurisdictions… to prevent exactly that kind of attack. Then they need to pass a human reviewer as well.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#64

Earlier quoted context omitted.

Because that then would already be a problem for Facebook, Google, Microsoft, etc that host photos that hacked phones could be uploading today. And we’re just not seeing that being the case. Because all these providers have been doing this for so many years, including the nearly 17 million photos identified by Facebook last year, you’d figure there would be a lot more noise if this was really going on. In fact, I wou…

We had SWAT teams for a long time before SWATing became popular. The publicity that this has gotten is only going to increase the chances that all these services start getting abused. And who is to say that it hasn't happened already and been entirely successful, but nobody believed the victim.

So you think we’re going to see a rise in people uploading CP to others cloud providers?

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#65

Earlier quoted context omitted.

Do you ask for the same audit at Facebook, Google, Microsoft, Dropbox, and countless others who are already doing this and have been for years? I do not share your same concern of some abused db _today_.

Sure, but I don't expect it from third party cloud platforms - in the same way I wouldn't expect accountability from a garbage man who reports to the police after finding evidence of crime in my garbage. Apple is, for some insane reason, trying to establish the precedent that the contents of your Apple product are now part of the public space - where expectation of privacy isn't a thing.

But that isn’t true. This is only photos uploaded to iCloud.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#66
post #48
post #18

> [...] and the parental notification system is a shift away from strong end-to-end encryption. That particular statement doesn't make much sense to me. The parental notification system is just a frontend action (one of many, like link previews and such). What does that have to do with iMessage's encryption? I can see an argument about a shift away from privacy (though it only pertains to minors under 13 receiving se…

It is not about the encryption, it is about what an "end" is. Generally, we consider the "end" to be the end user. If someone else can see the message along the way, it is not end to end anymore from a user perspective, even if it is from a network perspective. And Apple has complete control over your device through software updates. So that the leak is from your device or from the network is a mostly meaningless tec…

As a parent, I consider myself the "end user" of my child's device, not my child. That I might be looped in on any messages sent or received by this device is not at all a leak, it's a convenience—much like how I can receive messages sent to me on my phone and my laptop.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#67
post #18

> [...] and the parental notification system is a shift away from strong end-to-end encryption. That particular statement doesn't make much sense to me. The parental notification system is just a frontend action (one of many, like link previews and such). What does that have to do with iMessage's encryption? I can see an argument about a shift away from privacy (though it only pertains to minors under 13 receiving se…

EFF would probably argue that technologies like safe browsing are also a shift away from E2E encryption. They were strongly against email spam protection in the 90s for this reason.

Framing the EFF's position as being against browser safety or spam protection is disingenuous.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#68

Earlier quoted context omitted.

It’s an intersection between a US db and a not yet chosen non-US db, which then will have a human reviewer verify its CP before sending off to the authorities.

> What more could one ask for? An independent audit for both the secret secondary perceptual hashing algorithm and the chain of custody policies/compliance for the "US db" and the disconcertedly open ended "not yet chosen non-US db"?

What's the point of that? If you don't trust Apple, why would you use Photos.app in the first place? They already have 100% control over that, and can spy as much as they want to. No need to go by way of the CSAM database, that would be absurd.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#69
post #45

Earlier quoted context omitted.

> You’d have to not only have over 30 hash collisions That's trivial. If the attacker can get one image onto your device they can get several. It's very easy to construct preimages for Apple's neural hash function, including fairly good looking ones (e.g. https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX/issue... ) > collide with another secret hash function The supposed other 'secret' hash function cannot be se…

If this really was such a problem, then as I said, we’d have been getting reports of this over the past 10+ years it’s already been in place at big cloud providers. So where is all of this ruining of peoples lives by uploading CP on their devices? Also if you’re a gov actor trying to frame someone, why bother with a pre-image when you could put the real images on it? None of that is new today — all that’s new is Appl…

What do you mean? People are arrested all the time for having CP on their machines, I see it in the news frequently. Impossible to know how many of them could have just been framed, no one is giving the benefit of the doubt to an accused pedo. And it never goes to trial due to the possibility of enormous prison sentences. If you’re innocent would you risk 100 years in federal prison going to trial or plead guilty and only face a few years?

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#70
post #55
post #45

Earlier quoted context omitted.

> You’d have to not only have over 30 hash collisions That's trivial. If the attacker can get one image onto your device they can get several. It's very easy to construct preimages for Apple's neural hash function, including fairly good looking ones (e.g. https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX/issue... ) > collide with another secret hash function The supposed other 'secret' hash function cannot be se…

> That's trivial. If the attacker can get one image onto your device they can get several. At which point everything you brought up about attacks on the hash function is completely irrelevant because the attacker can put actual child porn from the database on your device.

The apple system is a dangerous surveillance apparatus at many levels. The fact that I pointed out one element was broken in a post doesn't mean that I don't consider others broken.

My primary concern about its ethics has always been the breach of your devices obligation to act faithfully as your agent. My secondary concern was the use of strong cryptography to protect Apple and its sources from accountability. Unfortunately, the broken hash function means that even if they weren't using crypto to conceal the database, it wouldn't create accountability.

Attacks on the hash-function are still relevant because:

1. the weak hash function allows state actors to denyably include non-child porn images in their database and even get non-cooperating states to include those hashes too.

2. The attack is lower risk for the attacker if they never need to handle unlawful images themselves. E.g. they make a bunch of porn images into matches, if they get caught with them they just point to the lawful origin of the images. While the victim won't know where they came from.

Post reply on HN