5 ms·
A system on my phone where it has a list of bad files and a threshold on how many of those files are allowed. If the threshold is reached Apple can read them. B
by almostdigital 5y ago
A system on my phone where it has a list of bad files and a threshold on how many of those files are allowed. If the threshold is reached Apple can read them. Both the bad files list and threshold is controlled by Apple and is explicitly designed to be un-auditable...
Honestly I would have been fine with Apple scanning my all photos after they are uploaded to iCloud but this is deeply disturbing
- gowld 5y agoHow is this system, where Apple sees far less photos, worse? You can't audit anything Apple does on their servers.
- feross 5y agoNow that a fully built system for breaking end-to-end encryption is shipped directly in the OS, we're one configuration change away from massive scope creep. First terrorist content, then "misinformation", then political speech. Apple will be unable to resist government demands to use this preexisting backdoor with a different set of perceptual hashes.
- shuckles 5y agoDisabling end to end encryption is always “one configuration change” away, presumably by substituting keys. How closely do you keep track of which keys are used to encrypt Health data - which is end to end encrypted - versus photos - which are not?
- dannyw 5y agoIf Apple substitutes keys, then that is a detectable event (by jailbroken devices) and that would make news. This is Apple explicitly announcing they are actively backdooring all iOS and Mac devices, and using your CPU cycles to determine whether you should be reported to the government.
- shuckles 5y agoNot really. Key management is done by the SEP, which can’t be introspected. And again, database updates take an iOS update so the back door threat is the exact same.
- Hackbraten 5y ago> database updates take an iOS update macOS already supports silent database updates, for example for Gatekeeper and MRT signatures. Why wouldn’t Apple use this feature on iOS, too?
- shuckles 5y agoBecause it’s bad for privacy.
- Hackbraten 5y agoWhat do you mean by that?
- davidcbc 5y agoIt's not built to break end-to-end encryption because photos in iCloud aren't end-to-end encrypted https://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303
- feross 5y agoThen ask yourself why they shipped this scanning on the client-side. This is the first step towards normalizing client-side scanning of encrypted content across the entire device.
- davidcbc 5y agoHopefully so they can remove their current ability to decrypt user photos for whatever reason they want. The current state is they can decrypt any user photos on iCloud. Doing client side scanning and this CSAM detection implementation could allow them to remove their ability to decrypt EXCEPT in very specific situations. It's not true end-to-end encryption since in some cases the content can be decrypted without the user key but it's significantly closer than what they have today. That being said I don't know if that is their plan or not, but it is a plausible reason to make this change.
- ScoobleDoodle 5y agoIf they can decrypt in a “specialized” situation, then they can decrypt in any situation. All that has to be done is to broaden the classifier step by step. Or someone else gets access to the back door. That’s why there can be zero allowed back doors.
- Thorrez 5y agoThey can decrypt iCloud content currently, so it wouldn't be a step back. On the topic of backdoors, automatic update systems could be used as backdoors.
- 5y ago
- midev 5y agoThis doesn't break end-to-end encryption. If you're going to comment on this topic you need to be technically aware of how it works. You're just spreading nonsense.
- serf 5y ago>How is this system, where Apple sees far less photos, worse? https://en.wikipedia.org/wiki/Hash_collision https://en.wikipedia.org/wiki/Hash_collision option three : don't allow Apple to judge user data at all.
- gowld 5y agoThat's non-responsive to the topic of the thread.
- almostdigital 5y agoIt's disturbing because of how effective it could be. It's at OS level, anything you have on your phone can be scanned. Even if an app tries to circumvent it by keeping files encrypted at rest it can scan them in-memory. And since it's all done client-side you'd never know it was happening until it found a match and sent it to Apple.
- deleted 5y ago[deleted]
- JohnJamesRambo 5y agoThis is how I feel as well. I don’t use iCloud photos but if I did, sure scan them for CP, I don’t care. Maybe you will catch some bad guys that willingly gave you their photos. But scanning everyone’s phones is beyond creepy and feels like exactly what the fourth amendment is about. It’s British soldiers suddenly having the ability to search EVERY home in colonial America as often as they want. > Amendment 4. The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized. I have moved away from Apple ecosystem, already purchased another phone yesterday. The Constitution is holy to me, it’s all we have protecting us from technological dystopia.
- juniperplant 5y agoMay I ask what phone? I am not here to criticize.
- JohnJamesRambo 5y agoI’m a cheap bastard so I got a Pixel 2 used for ~$55. I’m sure people will tell me Android is no better and I’d be open to hearing that but they don’t scan your phone as far as I know. I also have the option to install things like Calyx OS, Graphene OS I believe.
- juniperplant 5y agoThanks for sharing.
- PenguinCoder 5y agoConstitution applies between the government and you. Apple is not (knowingly) a government agency, they're a private business. Therefore the amendment doesn't apply to their actions. Vote with the wallet instead.
- matwood 5y ago> Honestly I would have been fine with Apple scanning my all photos after they are uploaded to iCloud Apple has already been doing exactly this for years. Now they are going to check the photos right before uploading to iCloud which is actually more privacy friendly than they do now. It also lets Apple turn on e2e for iCloud photos if they want. I understand the 'what if' and slippery slope arguments, but wow, there is so much misunderstanding in this thread. Apple makes the OS and doesn't need a fancy system to scan all the files on the device if that's what they want to do. I highly suggest reading this: https://www.apple.com/child-safety/ https://www.apple.com/child-safety/ and the associated PDFs. Apple PR hosed this up by putting 3 distinct features on one page that people seem to be conflating.
- almostdigital 5y ago> Apple has already been doing exactly this for years. Is that an assumption made based on that "everyone is doing it" or is there some evidence? > Apple makes the OS and doesn't need a fancy system to scan all the files on the device if that's what they want to do. If the goal is to scan all the files on everyones device this system is exactly what they need. It's not like they could upload hashes of every file on every users phone continuously.
- diebeforei485 5y agoThey've said it themselves, this has been known for years- https://digit.fyi/apple-admits-scanning-photos-uploaded-to-icloud/ https://digit.fyi/apple-admits-scanning-photos-uploaded-to-i...
- xdennis 5y ago> Now they are going to check the photos right before uploading to iCloud which is actually more privacy friendly than they do now. That's like having the judge, jury, and executioner in my house.