11 ms·
They have a podcast together called Dithering which is pretty good (but not free) - they're friends. I think John's article is better than Ben's, but they're b
by fossuser 5y ago
They have a podcast together called Dithering which is pretty good (but not free) - they're friends.
I think John's article is better than Ben's, but they're both worth reading.
Ben takes the view that unencrypted cloud is the better tradeoff - I'm not sure I agree. I'd rather have my stuff e2ee in the cloud. If the legal requirements around CSAM are the blocker then Apple's approach may be a way to thread the needle to get the best of both worlds.
- deleted 5y ago[deleted]
- AlexandrB 5y agoOne logical conclusion of systems like this is that modifying your device in any "unauthorized" way becomes suspicious because you might be trying to evade CSAM detection. So much for jail-breaking and right to repair! I think I'd rather have the non-e2ee cloud.
- fossuser 5y agoI don't really buy that - you could just turn off iCloud backup and it'd avoid their current implementation.
- echelon 5y agoAnd you think this will be the ultimate implementation? Let the devil in, and he'll treat himself to tea and biscuits.
- fossuser 5y agoI think it's possible to have nuanced policy in difficult areas where some things are okay and others are not.
- 7v3x3n3sem9vv 5y agoDid we learn nothing from the Snowden revelation?
- sa1 5y agoFor me it's the worst of both worlds - e2ee has no meaning if the ends are permanently compromised - and there's no local vs cloud separation anymore which you can use to delineate what is under your own control - nothing's under your control.
- fossuser 5y agoThe end isn't really compromised with their described implementation. The only thing sent is the hash and signature and that's only if there are enough matches to pass some threshold. I don't really view that as 'permanently compromised' - at least not in any way more serious that Apple's current capabilities to compromise a device. I think e2ee still has meaning here - it'd prevent Apple from being able to see your photo content on their servers. This is a nuanced issue, I don't think there's an obviously better answer and both outcomes have different risks. [0] [0]: https://www.lesswrong.com/posts/PeSzc9JTBxhaYRp9b/policy-debates-should-not-appear-one-sided https://www.lesswrong.com/posts/PeSzc9JTBxhaYRp9b/policy-deb...
- sa1 5y agoYeah, and as argued in one of the blog posts - that's just a policy decision - not a capability decision - malleable to authoritarian countries' requests.
- fossuser 5y agoYes - and I agree that that's where the risk lies. Though I'd argue the risk has kind of always lied there given companies can ship updates to phones. You could maybe argue it'd be harder to legally compel them to do so, but I'm not sure there's much to that. The modern 'megacorp' centralized software and distribution we have is dependent on policy for the most part.
- sa1 5y agoYup, we can agree on that.
- 5y ago
- samename 5y agoFriends can disagree. Everyone has their own biases - good and bad. I think it’s always good to keep people’s biases in mind when reading their work.
- fossuser 5y agoI agree, but it doesn't necessarily mean what they say is wrong. I like that they disagree - the issue doesn't have an obviously correct answer.
- syshum 5y agoIs it really E2EE if there is an MITM application scanning and reporting everything????? Seems like the existence of this scanning agent by default makes it not E2EE anymore