3 ms·
You forgot the most important point of the last 24 hours: "Apple has created a system for detecting CSAM on local devices which has already proven vulnerable t
by drvdevd 5y ago
You forgot the most important point of the last 24 hours:
"Apple has created a system for detecting CSAM on local devices which has already proven vulnerable to cheap perceptual hash collision attacks. It's now highly inconceivable Apple will be able to deploy this technology as-is without having their users exploited."
In other words it's not just about privacy or thoughtcrimes anymore but should be viewed as actually dangerous to use their devices. I feel a bit dramatic even typing that out but I.. think it's true?
- floatingatoll 5y agoI would also warn you against owning any device with a radio. Carriers control the radio towers and can be compelled by government agencies and selfish corporate interests to exploit remote execution vulnerabilities in radio chips in order to plant CSAM content onto devices. How dramatic is too dramatic? When does something that hasn’t happened to you or anyone you know become a risk you’re willing to sacrifice personal convenience to mitigate? Will you be divesting yourself of all wireless radio hardware? If not, then why would you be worried about users being exploited through a more clumsy and less effective process such as CSAM signature hacking? The piece of information you’re taking for granted, that few in free/tech/lib are confronting, is the assumption that this process can be exploited at scale to harm millions of people. So far as I can tell, there will probably be zero or one false positive CSAM matches that pass the known algo, the unknown algo, the human blurred comparison, and the human unblurred comparison — all steps that must occur before law enforcement is invoked to collect digital evidence - in the first year. How many false positives (to the nearest 10^X) do you think the system will generate in the first year that result in law enforcement actions? Your words suggest that everyone is vulnerable, and there are 10^9 users, so do you believe there will be 10^9 false positives in the first year? Do you think only a thousand people will be affected, so 10^3? How do you judge which is more likely correct? It is unlikely that this system will generate 10^9 false positives, or else it never would have passed QA. I encourage you to consider how you would personally quantify this risk, and then also look up the quantified risks for killing someone while driving a car or getting struck by lightning while indoors. I don’t know what the actual reality will be, but I don’t think it's a very large X.
- drvdevd 5y agoThank you for your comments. And I think you are probably correct about the true risk/X entailed here. As well as the risk of simply using anything with a radio - I can't think of a single device I own that hasn't had a radio attack of some sort published (including all Apple devices, of course). If I'm honest what makes me feel bad about this is probably just that- a feeling based on what I consider to be an algorithm designed around the presumption of guilt. It's much the same way I feel about taking my shoes off in line at airport security. It's an act which I've largely come to ignore but which still produces that vague feeling of discomfort that somehow feels like the opposite of security. That this is occurring on my Apple devices - my favorite devices - is also just depressing.