Earlier quoted context omitted.
It differs, but iOS already scans images locally and we really don't know what they do with the meta data, and what "hidden" categories there are.
Yes, exactly why Apple breaching user trust matters.
Security Threat Model Review of the Apple Child Safety Features [pdf]
71–80 of 393 posts
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#72Earlier quoted context omitted.
Heck, what is the process for current management to honor them?
Weirdly enough, I trust the current management to do the right thing. But that can be changed at a whim, and in my opinion, the greatest security threat to this whole thing.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#73Earlier quoted context omitted.
Yes, exactly why Apple breaching user trust matters.
And how is telling you in great detail about what they’re planning to do months before they do it and giving you a way to opt out in advance a breach of trust? What more did you expect from them?
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#74Is there a good argument for doing the scanning on the phone and not on the iCloud servers?
No. Contrary to Craig's claims, Google & Microsoft et al. do similar hash matching on the cloud, instead of 'looking at images'.
I'm not saying I necessarily agree that this is better, all-told (mixed feelings), but I think it's worth acknowledging why a rational actor might consider this superior to Google doing whatever the fuck they want with anything you upload.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#75Earlier quoted context omitted.
Apple shipped iCloud Private Relay which is a “1-line code change that hooks into CFNetwork” away from MITMing all your network connections, by this standard.
For me the standard is that I don't want any 1-line code change between me and near-perfect Orwellian surveillance.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#76What is the process to make sure the next management will honor these promises?
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#77Earlier quoted context omitted.
No. Contrary to Craig's claims, Google & Microsoft et al. do similar hash matching on the cloud, instead of 'looking at images'.
But people consider that bad! With this system, Apple can never look at your photos in the cloud. They are a pipe for the bits, but they don't examine the contents, except on your device. I'm not saying I necessarily agree that this is better, all-told (mixed feelings), but I think it's worth acknowledging why a rational actor might consider this superior to Google doing whatever the fuck they want with anything you…
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#78I strongly considered switching away from Apple products last weekend; but this document has convinced me otherwise. The threats people identify have minimal risk. If a total stranger offers you a bottle of water, you may worry about it being spiked, but him having offered the bottle doesn't make it more, or less, likely that he'll stab you after you accept it. They're separate events, no "slippery slope". It's very…
The problem is that this "hard" technological core (the crypto) is subject to an awful lot of "soft" policy issues around the edge - and there's nothing but "Well, we won't do that!" in there.
Plus, the whole Threat Model document feels like a 3AM brainstorming session thrown together. "Oh, uh... we'll just use the intersection of multiple governments hashes, and, besides, they can always audit the code!" Seriously, search the threat model document for the phrase "subject to code inspection by security researchers" - it's in there 5x. How, exactly, does one go about getting said code?
Remember, national security letters with gag orders attached exist.
Also, remember, when China and Apple came to a head over iCloud server access, Apple backed down and gave China what they wanted.
Even if this, alone isn't enough to convince you to move off Apple, are you comfortable with the trends now clearly visible?
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#79Earlier quoted context omitted.
But people consider that bad! With this system, Apple can never look at your photos in the cloud. They are a pipe for the bits, but they don't examine the contents, except on your device. I'm not saying I necessarily agree that this is better, all-told (mixed feelings), but I think it's worth acknowledging why a rational actor might consider this superior to Google doing whatever the fuck they want with anything you…
I mean, Apple can, as long as iCloud remains unsecured by e2e, the roadmap for which remains MIA.
Re: Security Threat Model Review of the Apple Child Safety Features [pdf]
#80> Apple will publish a Knowledge Base article containing a root hash of the encrypted CSAM hash database included with each version of every Apple operating system that supports the feature. Additionally, users will be able to inspect the root hash of the en- crypted database present on their device, and compare it to the expected root hash in the Knowledge Base article. This is just security theater, they already si…
> And there is no way to audit that the database is what they claim it is, doesn't contain multiple databases that can be activated under certain conditions, etc. They describe a process for third parties to audit that the database was produced correctly.
The story here is that there is a black box of pictures. Apple will then use their own black box of undeclared rules to pass things along to the feds which they have not shared what would be considered offending in any way shape or form other than "we will know it when we see it". Part of the issue here is that Apple is taking the role of a moral authority. Traditionally Apple has been incredibly anti-pornography and I suspect that anything that managed to get into the database will be something Apple will just pass along.