6 ms·
The end isn't really compromised with their described implementation. The only thing sent is the hash and signature and that's only if there are enough matches
by fossuser 5y ago
The end isn't really compromised with their described implementation.
The only thing sent is the hash and signature and that's only if there are enough matches to pass some threshold.
I don't really view that as 'permanently compromised' - at least not in any way more serious that Apple's current capabilities to compromise a device.
I think e2ee still has meaning here - it'd prevent Apple from being able to see your photo content on their servers.
This is a nuanced issue, I don't think there's an obviously better answer and both outcomes have different risks. [0]
[0]: https://www.lesswrong.com/posts/PeSzc9JTBxhaYRp9b/policy-debates-should-not-appear-one-sided https://www.lesswrong.com/posts/PeSzc9JTBxhaYRp9b/policy-deb...
- sa1 5y agoYeah, and as argued in one of the blog posts - that's just a policy decision - not a capability decision - malleable to authoritarian countries' requests.
- fossuser 5y agoYes - and I agree that that's where the risk lies. Though I'd argue the risk has kind of always lied there given companies can ship updates to phones. You could maybe argue it'd be harder to legally compel them to do so, but I'm not sure there's much to that. The modern 'megacorp' centralized software and distribution we have is dependent on policy for the most part.
- sa1 5y agoYup, we can agree on that.
- matwood 5y agoThat's the problem I had with Ben's post - it's always been policy since Apple controls and distributes iOS.
- fossuser 5y agoYeah - the sense I got was he just liked the cleaner cut policy of a hard stop at the phone itself (and he was cool with the tradeoff of unencrypted content on the server). It does have some advantages - it's easier to argue (see: the disaster that is most of the commentary on this issue). It also could in theory be easier to argue in court. In the San Bernardino case - it's easier for Apple to decline to assist if assisting requires them to build functionality rather than just grant access. If the hash detection functionality already exists and a government demands Apple use it for something other than CSAM it may be harder for them to refuse since they can no longer make the argument that they can't currently do it (and can't be compelled to build it). That said - I think this is mostly just policy all the way down.
- matwood 5y agoI have no idea if this feature existing makes it harder or easier for Apple to refuse. Based on how the feature works, it would still require a special build of iOS just like what the FBI wanted in order to remove the unlock count years ago. Given the amount of nuance here, I also think it's important to differentiate between the FBI showing up and asking for something and government passing laws forcing encryption backdoors. The former is what Apple has fought to date b/c they can. The later is much harder to fight and Apple will most likely have to comply regardless of what features already exist or not (see China/iCloud). The later is also the most dangerous since politicians rarely understand technology enough to do something sensible. It remains to be seen, but Apple could be trying to get in front of long term law changes with an alternate solution.
- echelon 5y ago> The end isn't really compromised with their described implementation. They've turned your device into a dragnet for content the powers that be don't like. It could be anything. They're not telling you. And you're blindly trusting them to have your interests at heart, to never change their promise. You don't even know these people. You seriously want to cuddle up with that?
- fossuser 5y ago> "They've turned your device into a dragnet for content the powers that be don't like. It could be anything. They're not telling you" They're pretty explicitly telling us what it's for and what it's not for. > "And you're blindly trusting them to have your interests at heart, to never change their promise. You don't even know these people." You should probably get to work building your own phone, along with your own fab, telecoms, networks, - basically the entire stack. There's trust and policy all over the place. In a society with rule of law we depend on it. You think your phone couldn't be owned if you were important enough to be targeted?
- echelon 5y ago> They're pretty explicitly telling us what it's for and what it's not for. Nobody should blindly trust Apple. As an organization, they already love secrecy and shadows--what better place to sneak in and test this kind of feature, free from employee ethics and scrutiny? They've been cooking this up without telling anyone, which is also indicative of how above board they are. Who knows what else they're doing with this now or will do in the future. The CIA, FBI, MI6, Mossad, FSB, CCP, et al. will use this to learn more about their targets.
- salawat 5y agoYes. All the fabs and stuff we have now shoufd be devoted to implementing a surveillance state. This must happen. It cannot be any other way. This is what you sound like. The problem here isn't the tech. It's that Big Tech has deluded society into believing privacy and personal ownership of devices doesn't exist because it would inconvenice Big Tech. Law enforcement echoes it because they were spoiled by the brief period that they tasted ClearNet, and they don't want to return to having to investigate the old fashioned way. Every other major industry has increasingly started doing the same thing. It is not okay. We have no right to sell out future generation's privacy. It's cowardly, selfish, and does more harm to them in the long run.
- amelius 5y ago> The only thing sent is the hash and signature and that's if there are enough matches to pass some threshold. Not true. If there are enough matches, someone at Apple will have a look at your pictures. Even if they are innocent.
- fossuser 5y agoI think the one thumbnail of the matching hash? Just to make sure there isn't a (they argue one in a trillion, but I don't know if I buy that) false positive. That's if there is enough matches to trigger the threshold in the first place, otherwise nothing is sent (even if there are matches below that threshold). Alternatively this is running on all unencrypted photos you have in iCloud and all matches are known immediately. Is that preferable?
- amelius 5y ago> I think the one thumbnail of the matching hash? So it is sending pictures? That makes your argument quite a bit weaker. > Is that preferable? Nope, E2EE without compromises is preferable.
- fossuser 5y agoI think the thumbnail is only when the threshold is passed and there's a hash match. The reason for that is an extra check to make sure there is no false positive match based on hatch match (they claim one trillion to one, but even ignoring that probably pretty rare and strictly better than everything unencrypted on iCloud anyway). > Nope, E2EE without compromises is preferable. Well that's not an option on offer and even that has real tradeoffs - it would result in less CSAM getting detected. Maybe you think that's the acceptable tradeoff, but unless government legislatures also think so it doesn't really matter. This isn't the clipper chip, this is more about enabling more security and more encryption by default but still handling CSAM. The CSAM issue is a real problem: https://www.nytimes.com/interactive/2019/09/28/us/child-sex-abuse.html https://www.nytimes.com/interactive/2019/09/28/us/child-sex-...