5 ms·
This is a better way to frame the discussion, IMHO. The conversation is around Apple, which is critical, but we need to compare them to the rest of the industr
by wiremine 5y ago
This is a better way to frame the discussion, IMHO.
The conversation is around Apple, which is critical, but we need to compare them to the rest of the industry, and discuss the government/citizen tradeoffs in that light. I.e., holistically, not per company.
- iratewizard 5y agoTrue. The constant migration of everything to the cloud has lots of consequences just like this. If the false positive are as common as the fotoForensics guy states, this could also become a new weapon for corporate warfare. A small competitor to a market Apple wants to control happens to have assets stored in an apple cloud? Guess who's offices are getting raided today?
- deleted 5y ago[deleted]
- kbenson 5y agoThat is indeed what the article does, does it not? It makes the case that storing online with a decryption key that can be used with a search warrant is probably the right trade off, and the way other companies sometimes implement this. Then you get to choose whether to push your data to the third party or not, given the risks involved. The author even notes they were opposed to Facebook's end-to-end encryption previously, I assume because as for defaults it sets a precedent and makes it unsearchable, but I'm not sure the specific tradeoffs they weigh and points they consider since it's behind a paywall (and I'm not sure I agree). > discuss the government/citizen tradeoffs in that light. I.e., holistically, not per company. Right now the differences are essentially per-company, since we've let our experiences be controlled almost entirely by a small subset of companies. To abstract the implementation from the primary implementer is to obfuscate some of the cause and effect here. We should discuss this as a societal tradeoff, as you note, but we should not ignore that this was spurred by a company running out in front of what was required of it and implementing this system which many see as at the expense of their users privacy.
- zepto 5y ago> Then you get to choose whether to push your data to the third party or not, given the risks involved. You get to choose whether to push your data to Apple and trigger the scanning with their solution too. The key escrow option is strictly worse.
- kbenson 5y ago> You get to choose whether to push your data to Apple and trigger the scanning with their solution too. That's purely an implementation detail, and subject to change at any time. That's why people are upset. One solution is limited to you actually pushing your data off your private device, the other is limited to a list of items you say you want to push off your device, but actually happens on your device. That's the difference between someone searching a large warehouse you and many others have stored belongings, and someone coming into your house and searching through your items freely as long as they're on the list. Beyond the difference in privacy that search entails fundamentally, people are very worried that the list itself is limited only by policy, and truly, the search of items on that list has full access to your private details but for the grace of those performing the search and controlling the list. The key escrow option is strictly worse than the current implementation, but it is also naturally constrained and the exposure is entirely user controlled. If you do not put data online in that situation, there is no way for them to process it without first exfiltrating it, which we already have laws and systems in place to hamper.
- zepto 5y ago> That's purely an implementation detail, and subject to change at any time. That’s an evergreen complaint. If they want to introduce a general purpose scanning mechanism they can do so at any time. This is not that. > That's why people are upset. I don’t think so. I think they are upset because they don’t like the fact that Apple has any power over them and this remind them of that even though it is not in fact an abuse. I actually agree with this, but I don’t think that claiming Apple’s implementation to be something it is not is helpful. The key escrow solution is strictly worse in any future. If key escrow becomes established as a norm between cloud providers and law enforcement, then no free alternative will ever be possible.