4 ms·
> So, sending actual CSAM would also work as an attack, but would be detected by the victim and could be corrected (delete images). What if they are placed on
by GeckoEidechse 5y ago
> So, sending actual CSAM would also work as an attack, but would be detected by the victim and could be corrected (delete images).
What if they are placed on the iDevice covertly? Say you want to remove politician X from office. If you got the money or influence you could use a tool like Pegasus (or whatever else there is out there that we don't know of) to place actual CSAM images on their iDevice. Preferably with an older timestamp so that it doesn't appear as the newest image on their timeline. iCloud notices unsynced images and syncs them while performing the CSAM check, it comes back positive with human review (cause it was actual CSAM) and voilà X got the FBI knocking on their door. Even if X can somehow later proof innocence by this time they'll likely have been removed from office over the allegations.
Thinking about it now it's probably even easier:
Messaging apps like WhatsApp allow you to save received images directly to camera roll which then auto-syncs with iCloud (if enabled). So you can just blast 30+ (or whatever the requirement was) CSAM images to your victim while they are asleep and by the time they check their phone in the morning the images will already have been processed and an investigation started.
- zepto 5y agoIf you are placing images covertly, you can just use real CSAM or other compromat.