8 ms·
There's no need to make them mandatory, most people already have cameras and microphones in their homes, schools and workplaces that the government can access.
by sorethescore 6y ago
There's no need to make them mandatory, most people already have cameras and microphones in their homes, schools and workplaces that the government can access. This is more about getting access to the social graph.
- SheinhardtWigCo 6y agoI don’t think that is accurate. Just as with end-to-end encrypted messaging apps, they would have to use targeted 0-day exploits to access the cameras and microphones in people’s homes. End-to-end encryption doesn’t protect the social graph. They already know who is talking to who; they just don’t know what is being said.
- mixologic 6y agoThey are already subpoena'ing alexa and Google home recordings, Android and iPhone location data, cell tower pings etc. I don't think we're far away from court ordered wire taps to compel Google to enable the cameras and microphones.
- dannyw 6y agoAny such court orders would be sealed indefinitely as well. In 5-10 or so years I predict we will have another Snowden, describing that the NSA has been running a ring -1 process on every single Intel Management Engine co-processor in the entire world.
- ohazi 6y agoThe vast majority of "smart home" devices automatically shovel all of their camera data to the manufacturer's servers, because most consumers don't want to deal with a NAS box and remote access. With this kind of architecture, law enforcement doesn't need 0-days, they only need a warrant/NSL, or to just ask the manufacturer nicely. Some manufacturers (e.g. Amazon/Ring) are a little too eager to essentially hand all of their data over to the police in real-time with almost no strings attached. Devices that don't already upload everything to the cloud (e.g. Apple and Google's pinky-promise that smart assistant audio is processed locally) automatically receive and apply software and firmware updates from the manufacturer / carrier that can arbitrarily change device behavior. The government can and probably does compel these companies to write and push custom firmware to targeted devices. "We encrypt your data so hard that we couldn't access it even if we wanted to" is almost always a lie, is never verifiable, and is ultimately subject to the same automatic firmware/software update problem. It will never be possible to secure systems like these from government snooping, and people largely don't seem to care.
- tpxl 6y agoThe vast majority of homes are not in any way smart.
- LocalH 6y agoApple devices don’t force updates. They’re very pushy, yes, and there are a couple of dark patterns in their update notification UI, but my devices aren’t running the latest iOS
- ohazi 6y agoAre you using your observations of Apple's user-facing iOS Update UI to conclude that they're not capable of pushing a silent update to an iOS device? You do realize that branded OS updates and even point releases are not the only units of software that receive updates from Apple, right? Google also asks you if you'd like to update Android, and they currently let you turn off auto-updates in the Play store, but they push updates to their nebulous, infinitely privileged "Play Services" packages frequently and without asking or informing the user. Even if Apple doesn't currently do something similar, it would be foolish to believe that they're not capable of doing so, as an ace-up-their-sleeve in an emergency scenario. Also baseband firmware is pushed by the carriers silently and is essentially unauthenticated. You really, really, really should not trust your phone, like, at all.
- ShorsHammer 6y ago> targeted 0-day exploits "this app wants access to your microphone: YES/NO"