6 ms·
Meh. Dropbox and Google Drive can run arbitrary queries over your files stored there. iCloud (assuming they finish e2ee transition) will have to push the same h
by aj3 5y ago
Meh. Dropbox and Google Drive can run arbitrary queries over your files stored there. iCloud (assuming they finish e2ee transition) will have to push the same hashes to everyone. It's not transparent and we don't have a way to inspect what exactly are they searching for, but at least there's a way in principle to reverse engineer the algorithm and to monitor how often hash database gets updated.
In my book that's a step in the direction of privacy, compared to old status quo.
- wiremine 5y agoThis is a better way to frame the discussion, IMHO. The conversation is around Apple, which is critical, but we need to compare them to the rest of the industry, and discuss the government/citizen tradeoffs in that light. I.e., holistically, not per company.
- iratewizard 5y agoTrue. The constant migration of everything to the cloud has lots of consequences just like this. If the false positive are as common as the fotoForensics guy states, this could also become a new weapon for corporate warfare. A small competitor to a market Apple wants to control happens to have assets stored in an apple cloud? Guess who's offices are getting raided today?
- deleted 5y ago[deleted]
- kbenson 5y agoThat is indeed what the article does, does it not? It makes the case that storing online with a decryption key that can be used with a search warrant is probably the right trade off, and the way other companies sometimes implement this. Then you get to choose whether to push your data to the third party or not, given the risks involved. The author even notes they were opposed to Facebook's end-to-end encryption previously, I assume because as for defaults it sets a precedent and makes it unsearchable, but I'm not sure the specific tradeoffs they weigh and points they consider since it's behind a paywall (and I'm not sure I agree). > discuss the government/citizen tradeoffs in that light. I.e., holistically, not per company. Right now the differences are essentially per-company, since we've let our experiences be controlled almost entirely by a small subset of companies. To abstract the implementation from the primary implementer is to obfuscate some of the cause and effect here. We should discuss this as a societal tradeoff, as you note, but we should not ignore that this was spurred by a company running out in front of what was required of it and implementing this system which many see as at the expense of their users privacy.
- zepto 5y ago> Then you get to choose whether to push your data to the third party or not, given the risks involved. You get to choose whether to push your data to Apple and trigger the scanning with their solution too. The key escrow option is strictly worse.
- kbenson 5y ago> You get to choose whether to push your data to Apple and trigger the scanning with their solution too. That's purely an implementation detail, and subject to change at any time. That's why people are upset. One solution is limited to you actually pushing your data off your private device, the other is limited to a list of items you say you want to push off your device, but actually happens on your device. That's the difference between someone searching a large warehouse you and many others have stored belongings, and someone coming into your house and searching through your items freely as long as they're on the list. Beyond the difference in privacy that search entails fundamentally, people are very worried that the list itself is limited only by policy, and truly, the search of items on that list has full access to your private details but for the grace of those performing the search and controlling the list. The key escrow option is strictly worse than the current implementation, but it is also naturally constrained and the exposure is entirely user controlled. If you do not put data online in that situation, there is no way for them to process it without first exfiltrating it, which we already have laws and systems in place to hamper.
- zepto 5y ago> That's purely an implementation detail, and subject to change at any time. That’s an evergreen complaint. If they want to introduce a general purpose scanning mechanism they can do so at any time. This is not that. > That's why people are upset. I don’t think so. I think they are upset because they don’t like the fact that Apple has any power over them and this remind them of that even though it is not in fact an abuse. I actually agree with this, but I don’t think that claiming Apple’s implementation to be something it is not is helpful. The key escrow solution is strictly worse in any future. If key escrow becomes established as a norm between cloud providers and law enforcement, then no free alternative will ever be possible.
- mcherm 5y ago> iCloud [...] will have to push the same hashes to everyone Why? What's to prevent them from pushing specific hashes to a specific phone?
- shuckles 5y agoThere are three primary sources stating that the database will be embedded in iOS. Remote hash updates introduces privacy risk.
- pavel_lishin 5y agoThis entire scheme introduces privacy risk. There is no technical reason why they could not push individual hashes to individual phones, only policy ones.
- shuckles 5y agoIn an alternative universe where they built a remotely updated database, yes. But that’s not this universe. I’m going to go further and say that people are doing a very bad job articulating why the incremental privacy risk of the scheme is significant, over the always-existent privacy risk of a proprietary vendor updating software they entirely control to scan data uploaded to a cloud service which guarantees no protection from vendor access. A later software update to include more hashes or whatever could always regress privacy.
- feanaro 5y agoOne is a proprietary third-party, optional service acting against you, the other is your own device acting against you. That's the difference and it should be pretty easy to understand.
- shuckles 5y agoSo if you could delete the Photos app, you’d believe there is no longer any fundamental privacy risk?
- BiteCode_dev 5y agoNot for people that didn't trust the cloud and didnt out their life in there in the first place.
- miles 5y ago> Meh. Dropbox and Google Drive can run arbitrary queries over your files stored there. However, unlike with Apple's invasive on-device scanning, you can encrypt files before storing them at Dropbox or Google Drive. There are even simple turnkey solutions like Sookasa: "Sookasa acts as a transparent layer over Google Drive to encrypt your sensitive files on the cloud and across connected devices..." https://www.sookasa.com/GD https://www.sookasa.com/GD "Sookasa protects data both on devices and in the cloud, and decouples the data from the encryption keys, meaning your data stays secure no matter where it goes." https://www.sookasa.com/dropbox-security/ https://www.sookasa.com/dropbox-security/
- endisneigh 5y agoHow do you know Sookasa isn’t doing the same thing? It doesn’t appear to be open source.
- shuckles 5y agoYou can irreversibly transform the image data of photos added to the Photos app as well.
- bmarquez 5y agoCryptomator is another encryption software which can encrypt files before they're uploaded to the cloud, and it's open source. https://github.com/cryptomator/cryptomator https://github.com/cryptomator/cryptomator
- aborsy 5y ago
- feanaro 5y agoHuh? You can choose not to use any cloud service if you want. If you buy an iPhone, you can't... Choose not to use the iPhone you just bought. This isn't a step towards privacy and it sounds (to me at least) like quite the logical contortion to argue that it is.
- devoutsalsa 5y agoI don’t keep child porn on my phone (or any where else. I also don’t keep smallpox in my freezer or nuclear weapons on my basement. Noninvasive scans for these things probably make the world a better place in some ways. The part I object to having my life disrupted by having my personal accounts unilaterally deleted by a fucking buggy bot. Our phones are too important to us to just have them shut off without notice. That’s bullshit.
- deleted 5y ago[deleted]
- treesknees 5y agoApple has said multiple times that accounts are not shut off with any automated system, that portion of the process is handled by humans.
- chimen 5y agoGood! Because I trust those even less. If possible, once banned, no one to answer on any of the communication channels, Google style.
- JAlexoid 5y agoSo... They will have humans looking at pictures to determine if it's child pornography? Well... That's a dream job for a pedo
- giantrobot 5y agoWho do I call (and how do I call them) if the person agrees with the automated false positive and disables my account/phone and reports me to the police? Just being accused of having CSAM is ruinous. What's my recourse if there's an innocent bug in their system that reports me to the police? I was at Apple for more than a decade and a half. I saw an untold number of Michael Bolton bugs [0]. It's one thing when a bug causes a dropped frame in a video or a menu takes a tenth of a second too long to appear. It's another when it ruins your life and bankrupts you defending yourself. [0] https://www.youtube.com/watch?v=NnPBSy5FsOc&t=02m24s https://www.youtube.com/watch?v=NnPBSy5FsOc&t=02m24s