Live data from Hacker News

Apple’s device surveillance plan is a threat to user privacy – and press freedom

freedom.press

91–100 of 145 posts

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#91
post #13

There is an easy way to cast your vote for saying yes to Privacy. Turn off auto-updates and don't update to iOS 15. Spread the word.

This is not guaranteed to work. At some point Apple might show you an update dialog, and you might click "yes" by mistake.

I think it requires you to enter your passcode, at least it does for me, when auto-update is disabled.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#92

This technology will soon be out of Apple’s control. Higgins correctly highlights the immense pressure Apple will get from governments and other actors to bend the technology and use it for something else than csam. It will happen, people are probably already thinking how to apply such pressure. Sooner or later Apple will cave in and they will have only themselves to blame when freedom supports in Sudan or LGBTQ acti…

> Higgins correctly highlights the immense pressure Apple will get from governments and other actors to bend the technology and use it for something else than csam. It will happen, people are probably already thinking how to apply such pressure. Sooner or later Apple will cave in and they will have only themselves to blame when freedom supports in Sudan or LGBTQ activists in Saudi Arabia will be jailed. I'm having tr…

Apple can also choose to exit that country. There aren't many countries which Apple would even consider risking its global reputation in order to retain that market. US, China, Europe, maybe the UK. That's about it.

If Saudi Arabia or Sudan tried to turn the screws, the business case for Apple is absolutely clear-cut: they leave. This isn't even up for debate. There's far too much at risk globally than there is to gain domestically from compliance.

Not only do they avoid serious damage to their global reputation (something they'll be extremely sensitive to, as the last two weeks have taught them) it would represent a massive opportunity for Apple to earn weeks of free media coverage that aligns with their security narrative.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#93

Earlier quoted context omitted.

If enough people do that, then no reason that they won't just enable it in 14 too.

Assuming that I was not gaslit by other people, I was under impression that would at least require some change to EULA. Otherwise it sounds like a nuclear option by Apple, with dire effects.

iOS 14 EULA:

> By using the Apple Software, you agree that Apple may download and install automatic Apple Software Updates onto your Device and your peripheral devices.

> Apple and its licensors reserve the right to change, suspend, remove, or disable access to any Services at any time without notice.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#94
post #86

Earlier quoted context omitted.

> an adversary could trick Apple’s algorithm into erroneously matching an existing image This is a very real, possible attack. Apple ships its CSAM model on device so any attacker can have a copy of the model. Then the attacker creates an image that triggers CSAM but looks like a panda [1]. Now the attacker sends tons of triggering photos to the unsuspecting victim, who now gets questioned by the FBI. 1: https://medi…

So the attacker creates an image then the user has to download it. Then the FBI digs in and see it was a crafted false positive, then begin to investigate who sent it and why. Then the user takes civil action against the person who sent it for harassment.

More precisely, 30 carefully crafted false positives. All of which need to be imported into your iPhone's photo library to sit alongside pictures of your dog and your mum. And then they have to get past human review. Not impossible, but so far beyond implausible that it can be dismissed as ridiculous.

And if this trick ever works, it could only be done once before Apple has the opportunity to plug holes in their NeuralHash algorithm and fix any deficiencies in the manual review process.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#95

Apple has lost the nerds and I can’t think of a time that has ever gone well for a company. We are the people advising other people what to get, what is cool. I can’t think of anything less cool than an iPhone right now. I dumped mine and I don’t think I’m alone.

[deleted]

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#96
post #7

There business model has always been a threat to user privacy and press freedom, many people were just okay with it cause Apple told them otherwise. Open source is the only model where you can verify though, and so Apple was about blind trust and never about privacy.

Why is this being downvoted? Depressing to see that open source software is not respected here.

I didn't downvote it, but I can understand why some people might have. Because while it's superficially true, it's disingenuous in practice. All security is, at its core, a network of trust between you and other entities. Open source isn't secure because it's open, it's secure because you trust Canonical, you trust Linus Torvalds, you trust GNU, etc. And those people trust other people—hence the "network" of trust.

Saying that you can inspect the source code is true in theory. But unless you've done the full audit yourself, you're personally as blind as you are with closed source code. You're choosing to trust whichever security researchers deeply understand the security implications of all the gobbledegook in all the USB drivers, and you're trusting that Canonical is shipping you the same version that security researchers have validated. For 99.9% of users, it all comes down to blind trust.

As Linus himself once said: "If you have ever done any security work and it didn't involve the concept of a network of trust, it was not a security work. It was masturbation."

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#97

Earlier quoted context omitted.

Assuming that I was not gaslit by other people, I was under impression that would at least require some change to EULA. Otherwise it sounds like a nuclear option by Apple, with dire effects.

iOS 14 EULA: > By using the Apple Software, you agree that Apple may download and install automatic Apple Software Updates onto your Device and your peripheral devices. > Apple and its licensors reserve the right to change, suspend, remove, or disable access to any Services at any time without notice.

Sure, they could probably push it through into any iOS, but all currently available documents claim it’s a iOS 15 feature and presumably there will be lot’s of new legalese like specifically for those new features.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#98

Earlier quoted context omitted.

iOS 14 EULA: > By using the Apple Software, you agree that Apple may download and install automatic Apple Software Updates onto your Device and your peripheral devices. > Apple and its licensors reserve the right to change, suspend, remove, or disable access to any Services at any time without notice.

Sure, they could probably push it through into any iOS, but all currently available documents claim it’s a iOS 15 feature and presumably there will be lot’s of new legalese like specifically for those new features.

You're not wrong about Apple's messaging around this. I was specifically responding to your claim that pushing it to iOS 14 would require modifications to the EULA. It would not.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#99

Apple has lost the nerds and I can’t think of a time that has ever gone well for a company. We are the people advising other people what to get, what is cool. I can’t think of anything less cool than an iPhone right now. I dumped mine and I don’t think I’m alone.

Right now? We've known Apple is backdoored since at least 2013 with Snowden revelations. Some of us chose to pay attention, others seemingly went back to sleep ...

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#100
post #76

Earlier quoted context omitted.

I am trying to say it's not possible to tell with certainty from a lowres picture that you are looking at false positive. For example low contrast CSAM imposed on a document could trigger NeuralHash match but the lowres image will look like a false positive.

For your example, wouldn't that only work to make the original source image that's polluting the CSAM database look like CSAM in lowres? The actual document-image the oppressive government is looking for that'd trigger the match wouldn't have the CSAM included. That said, I do think it'd be nice to have a better demonstration of exactly what this "derivative" the reviewers would be looking at is. There's a lot of var…

I agree, it would be useful if Apple could be clearer by what they mean by a derivative. I recall reading somewhere that it's a reduced resolution, grayscale copy of the image. I can't vouch for that, but that would be a plausible notion of what the "derivative" would be.

Personally I would also be placing a hard watermark in the middle of the image, or maybe some hard slashes randomly through the image, so that "clean" images cannot leak out of human review.

Let's imagine that the derivative is a 0.5 megapixel, grayscale, watermarked, HEIC-compressed copy of the original image. This would be plenty to determine with zero ambiguity that the image is actually "A1" classified, i.e. depicts a prepubescent minor ("A") engaged in a sex act ("1").

Post reply on HN