5 ms·
For me, it was well thought-out. Apple betrayed my trust as a consumer and the response in the past week was plain gaslighting. I thought about it for a couple
by ByteWelder 5y ago
For me, it was well thought-out. Apple betrayed my trust as a consumer and the response in the past week was plain gaslighting. I thought about it for a couple of days and then decided that I don't want to support a company like that anymore.
(edit)I was planning to buy a new MBP/iPhone/Watch in Q4, so this made it easier to decide on those purchases earlier.(/edit)
It's correct that the CSAM scanning is currently only effective when iCloud is enabled - and for US customers only.
For me, this detail is irrelevant. The backdoor might be inactive for now, but there would still be a backdoor on my phone.
- wayoutthere 5y agoYou’re fooling yourself if you don’t think the government has a dozen other ways to backdoor you. Heck they basically just have packet scanners sitting on the networks of all the major telecoms, and almost certainly have compromised SSL root signing keys so they can trivially decrypt your traffic. Anything that goes over the network is fair game. Love it or not, we live in a police state enforced by surveillance. Most Americans are just waking up to this because they’re not a member of a population actively oppressed by the police. Socialist / anarchist / labor communities that are more than shitposting groups meet almost exclusively in-person because their communications have long been targeted by law enforcement.
- mohanmcgeek 5y agoThe government doing this is one thing but corporations controlled by a few vocal groups deciding what you can do and what you are allowed to know is a completely different thing.
- wayoutthere 5y agoAgain, this has always been the case in the US. Newspapers were owned by wealthy businesses with a message to spread, as were the radio stations, then it was the big 3 TV networks for a long time, now it’s the 5 big tech companies. The gatekeeping is a feature, not a bug. If you look to other societies, this happens there too. There is a symbiotic relationship between mass media and government at a fundamental level. There’s a reason that the first things you do after a coup are to lock down the Internet and sieze the TV / radio broadcast infrastructure.
- mohanmcgeek 5y agoExcept in these cases, it's not the government asking these companies to take down the "misinformation" videos. In fact, some of these companies try to add "misleading" label to actual, official government announcements.. Trying to run a parallel, unelected government.
- wayoutthere 5y agoWhich, again, has always been the case. It’s a very new phenomenon where an individual can deliver speech directly to thousands of people. The media were the gatekeepers of information and influencers of mass opinion, and they would frequently run stories with counterfactual information that suited their purposes. Companies have always tried to run parallel, unelected governments. Whether it’s “company towns,” banana republics, or social media restrictions doesn’t matter. No, I think the root of the problem is that the ability to disseminate information widely across a population is not a good thing. I do think there should be real regulation on mass speech that is proportional to the audience size. If you have 100k followers on Instagram, that should come with some responsibilities.
- mohanmcgeek 5y ago> has always been the case I don't know what your point is. Even if this is true, (which it definitely isn't), should they continue to hold unlimited powers? Blood has been shed over centuries to limit the powers of the government and to get the rights we have. I am not sure where you get the idea that free speech means speech without consequences. If I have a million followers and a sell something dubious, people would sue me for befrauding them
- gjsman-1000 5y agoHere's the thing. You might hate Apple for what they did. But I'm looking at the competition (Google, Amazon, Microsoft) and they're still worse for privacy in well-documented ways. It's an evil but it's still the least among evils.
- mateuszf 5y ago> It's an evil but it's still the least among evils. Nope, you can use a degoogled android. There's still a matter of hardware that's not open but there's not much we can do that without sacrificing a lot of usability.
- gjsman-1000 5y agoThen you can't use the Play Store (legally at least) and can't use paid apps. You're still taking a massive usability hit.
- mateuszf 5y agoYeah, provided I don't find alternative open-source / self-hosted apps. I'm not saying it's easy, but it seems doable in medium/long term - if you value privacy and owning your data.
- donohoe 5y agoYeah, but you're still stuck with Android. Thats just an insecure mess right there.
- mateuszf 5y agoIt depends on the ROM. I've heard good about GrapheneOS. It was even recommended by Snowden. https://twitter.com/Snowden/status/1175430722733129729?s=09 https://twitter.com/Snowden/status/1175430722733129729?s=09
- djrogers 5y ago> The backdoor might be inactive for now, but there would still be a backdoor on my phone The key (from Apple's POV) is that this is done on your device, so the model can be audited, and users will know if it changes or is suddenly enabled where it wasn't before. Apple has documented the entire threat model and their design decisions realted to each threat vector. It's worth reading the document, as it becomes pretty clear that this is a step towards enabling E2E for iCloud Photos. The alternative to what Apple did is cloud-based scanning, which is less transparent, permanently disallows E2EE, and is more vulnerable to being changed by national decree. If CSAM scanning is going to (or is already) mandatory, I vastly prefer Apple's method here. [1] https://www.apple.com/child-safety/pdf/Security_Threat_Model_Review_of_Apple_Child_Safety_Features.pdf https://www.apple.com/child-safety/pdf/Security_Threat_Model...
- nzealand 5y ago> If CSAM scanning is going to (or is already) mandatory, I vastly prefer Apple's method here. This is such a good point. The US government has been heavily pushing for backdoors, and can gag discussion under threat of national security. It also seems counter productive to punish the one corporation who is apparently being transparent about this. Nobody here likes marketing BS, but this reaction here on HN is why we get marketing BS instead of technical details. Edit: Legally, these searches do not violate the 4th amendment because the government pretends hash scans are entirely voluntary. Most ISPs and email companies "voluntarily" choose to hash match. I can't remember the specifics, but ISPs that refuse to do this have been threatened with legal action. https://www.bjcl.org/blog/hashing-it-out-how-an-automated-crackdown-on-child-pornography-is-shaping-the-fourth-amendment https://www.bjcl.org/blog/hashing-it-out-how-an-automated-cr...
- breuleux 5y agoEven if we were to call this a "backdoor", it's a backdoor that creaks quite loudly. I mean, what's the attack vector here? The plan, as far as I'm aware, is to upload a list of hashes to each device that have been vetted by multiple child protection agencies. In order to surveil other things, additional hashes would need to be transferred that wouldn't be vetted by these agencies. That would be noticed, and that's the point where I would consider my trust to be betrayed.
- rovr138 5y ago>I mean, what's the attack vector here? The plan, as far as I'm aware, is to upload a list of hashes to each device that have been vetted by multiple child protection agencies. I hope not. If hashes are uploaded to devices, they can be extracted and images that clash against it can be created. I think they're going to be creating hashes of images locally that are being uploaded and send it with the image. Then if the hash is found to match one on their database, that's flagged. The problem then is, if they're matching on their side, what prevents them from receiving some order that forces them to match for other images?
- breuleux 5y ago> If hashes are uploaded to devices, they can be extracted and images that clash against it can be created. Many organizations have the hashes, so they could leak nonetheless. Either way, I don't think that's a major problem. If the system interprets a picture of a pineapple as CSAM, you only need to produce the picture of a pineapple to defend yourself against any accusations. If clashes are too commonplace, the entire system would become unreliable and would have to be scrapped. In any case, I have looked it up. The database is indeed on the device, but it's encrypted: https://www.apple.com/child-safety/pdf/CSAM_Detection_Technical_Summary.pdf https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni... > Instead of scanning images in the cloud, the system performs on-device matching using a database of known CSAM image hashes provided by NCMEC and other child-safety organizations. Apple further transforms this database into an unreadable set of hashes, which is securely stored on users’ devices. Overall, after reading the PDF, here is my understanding of the process: 1. Apple gathers a set of "bad hashes" 2. They upload to each device a map from a hashed bad hash to an encrypted bad hash 3. The device runs an algorithm that determines whether there are matches with hashed bad hashes 4. For each match, the device uploads a payload encrypted using a secret on-device key, and a second payload that contains a "share" of the secret key, encrypted using the neural hash and encrypted bad hash. 5. The device also periodically uploads fake shares with dummy data to obfuscate the number of matches that actually occurred. Apple can't tell fake shares from real ones unless they have enough real shares. 6. Once Apple has enough real shares, they can figure out the secret key and know which hashes caused a match. The main concern I have, and as a non-expert, is step 2: it requires Apple to provide their key to an auditor who can cross-check with child protection agencies that everything checks out and no suspect hashes are included in the payload. In theory, that needs to be done every time a new on-device database is uploaded, but if it is done, or if child protection agencies are given the secret so that they can check it themselves, I think this is a fairly solid system (notwithstanding the specifics of the encryption scheme which I don't have the competence to evaluate). The thresholding is also a reassuring aspect of the system, because (if it works as stated) the device can guarantee that Apple can't see anything at all until a certain number of images match, not even the count of matching images. The threshold could only be changed with an OS update. There's certainly a lot of things to discuss and criticize about their system, but it's going to be difficult to do so if nearly no one even bothers reading about how it works. It's frustrating.
- askonomm 5y agoYou're in for a rough ride if you change entire platforms and ecosystems every time someone disappoints you. Afaik, Microsoft and Google do a lot worse than Apple, so where are you going to go? Linux?
- rendall 5y ago> You're in for a rough ride if you change entire platforms and ecosystems every time someone disappoints you. As an aside, this entirely explains US politics.