9 ms·
Apple urged to drop plans to scan iMessages, images for sex abuse
- lysurgic 5y agoNo more Al Jazeera thank you. Nobody cares what the New York Times for terrorists says about anything.
- roamerz 5y agoSiri a few years into the future: Dave I noticed that when you sent your last tex message my AI determined with a 99% probability that you were driving. I’ll be notifying the local authorities and you will be receiving a citation for that. Please note that after the citation has been paid and you have been through rehabilitation they send me an unlock code so I can reenable your sms account. Or: Hi Dave i’ve been noticing that you have been discussing Covid vaccines with your friends. Apple thinks your position on this causes public harm so we will be adding additional information to each of your messages that discuss this subject. Thank you for being part of our team.
- pilsetnieks 5y ago- Open the pod bay doors, Siri. - I'm sorry Dave, I'm afraid I can't do that.
- bobbob1921 5y agoPretty clear cut for me: iMessage either offers robust end-to-end encryption , or it doesn’t. (Intentional backdoors place it in the latter ofcourse). I want true end to end enc.
- djrogers 5y agoHow is it not still E2EE?
- sigmar 5y agoIf a copy of your messages (even if it is only low resolution jpgs) get auto forwarded to Apple/FBI under certain circumstances it is not securely E2E encrypted
- wyldfire 5y agoApple's investigation code executes on the device, which allows them to preserve their definition of end-to-end as long as you plug your ears and ignore where the 'ends' are.
- zionic 5y agoI’m not interested in Apple’s newspeak definition of “E2EE” (where they are between the ends) or “Privacy” (terms and restrictions may apply). I want the real thing.
- ollien 5y agoIn this case, they wouldn't be "between" the ends, no? They'd be _at_ the ends, just as sending a message on Signal doesn't prevent someone from stealing your phone and reading your messages. I'm not in agreement with this being ok, but if it truly is on device, it still technically can be E2EE
- wyldfire 5y ago> but if it truly is on device, it still technically can be E2EE What do you think this software does when it finds a matching hash entry? Toss a notification to ask you nicely to pop round your nearest FBI office? What meaning does 'end-to-end' have anymore if this applies? If Apple wrote software on-device to forward a copy of all messages prior to encryption to iCloud for 'backup', would it still be end-to-end? What if they sent it to an AdTech firm to index for interesting terms that match products you should be pitched? The software in this case is still Apple's, running on-device.
- robertoandred 5y agoiMessage already analyzes your messages to preview urls, show YouTube videos, highlight dates, etc. Are those also backdoors?
- npteljes 5y agoHow do they manage the previews? Skype, for one, uses their servers to get the preview. Vastly different from a client-side preview (which some people wouldn't want either).
- skygazer 5y agoiMessage link preview images are generated by the sender. https://developer.apple.com/library/archive/technotes/tn2444/_index.html https://developer.apple.com/library/archive/technotes/tn2444...
- deleted 5y ago[deleted]
- coconut_man 5y agoI don't think so, it doesn't really need to "analyze" your messages to do preview urls, show videos... Those are more like frontend stuff IMO
- robertoandred 5y agoNo more frontend than running a basic subject recognition on a photo.
- blitzar 5y agoA bit like on-device machine learning features, like object detection in images and video, language analysis, and sound classification?
- robertoandred 5y ago
- wyldfire 5y ago> I want true end to end enc. People who say things like this rarely also want the hassle that comes with it. Key exchanges, re-keying: all a big PITA. But iMessage (and WhatsApp) do key exchanges facilitated by a trusted broker. If you didn't trust the broker, you would have to do more work when making an initial exchange with a peer and more work if they lost their phone/keys. iMessage has always been a compromise with subtle rough edges. But we trusted Apple because they talked about privacy and made it clear that their business model meant that we should trust them more than competitors. But now, precisely because of how good and effective they secured their devices -- they fear regulation and thought that they could further compromise things and people would go along with it.
- whatshisface 5y agoKey exchange would be easy in real life, just bump phones when you meet someone. It's only difficult on IRC.
- theshrike79 5y agoSo key signing parties would resurface? :)
- wyldfire 5y agoYes and no. It's not 'hard' it's just friction that's not present at baseline (when iMessage was designed, and for the most part still today). Sometimes you send messages to someone who you haven't ever met in person, or you met but didn't think to exchange keys at the time. And when Dave drops his phone in the lake and buys a new one, he would have to sheepishly re-meetup with everyone he interacts with. If iMessage had been designed to require a brokerless key exchange, its security would be superior (though in this case, Apple's interception software trumps everything). But iMessage would appear to be less convenient than alternatives like WhatsApp (brokered key exchange, re-keying).
- whatshisface 5y agoIt could offer both brokered and brokerless key exchange, distinguishing between messages from parties verified through each method by, I dunno, the color of the text bubble.
- ericmay 5y agoWell-intentioned program, but ultimately unforeseeable bad consequences in other areas. Good for Apple for stopping, and good for society to pressure them to stop. Seems like a win-win all around.
- nickthegreek 5y agoApple is not stopping.
- hoppyhoppy2 5y ago>Good for Apple for stopping Is there some big news that I missed? Do you have a link to that info?
- hoppyhoppy2 5y agoEarlier today on HN: https://news.ycombinator.com/item?id=28230248 https://news.ycombinator.com/item?id=28230248 https://news.ycombinator.com/item?id=28232068 https://news.ycombinator.com/item?id=28232068 https://news.ycombinator.com/item?id=28231094 https://news.ycombinator.com/item?id=28231094
- werber 5y agoAfter seeing all these posts here and not hearing much about it outside of this space I’m starting to think that the cost benefit analysis that Apple did was that the profit from very likely convincing parents to spend a little more to get their children an iPhone as their first phone (and probably lock those children into their ecosystem) because of these features was greater than the amount of users who would switch to something else and that any blowback would be diminished because “what about the children”
- sandworm101 5y agoI'm not sure we have an understanding of Apple's intentions. Given the massive backlash and the apparent maturity of their plans this must have been in the works for a while. They may have been under pressure from government actors to develop a program. Or they might see writing on the wall. Either way, I doubt they will ever share the total picture behind this move.
- dionian 5y agoThe leak of the email describing people with concerns as "screeching" didnt help.
- theshrike79 5y agoThe "screeching" comment was from NCMEC, not Apple.
- deleted 5y ago[deleted]
- wizzwizz4 5y agoAnd the NN totally-offline¹ optional configurable check is a good thing! Heck, I'd've enabled it on my own phone if I had an iPhone; it'd've made me feel that much better about carrying an internet-connected camera around with me wherever I went, if I knew it'd warn me if I accidentally photographed myself naked (or somehow decided to do so deliberately, in a moment of foolishness). They built two different systems, one that I think is good / that would be a selling point to parents, and one that could be a powerful weapon. ¹: The “notifying parents” thing is a little iffy; I'm not sure what to think about it.
- kemayo 5y agoI want to ignore most of this article to complain about an inaccuracy that keeps coming up. > More broadly, they said the change will break end-to-end encryption for iMessage, which Apple has staunchly defended in other contexts. But... it wouldn't. The iMessage feature doesn't expose the contents of your message to anyone else under any circumstance. If you're a child under 13 and your parents have opted in to this feature, you get a choice of seeing naked-pictures sent to you and having your parents be notified that you chose to, and bypassing it with no notifications of anything. (But once you're 13+, no notifications would occur.) There are potential issues with this, mostly relating to abusive families being controlling. They'd have to do weird things like forcing their teenaged children to keep making new under-13 accounts to actually take advantage of it like that, though. And none of these issues impact the e2e status of iMessage in any way. Apple really screwed up PR by launching the iMessage feature alongside the scanning-and-reporting iCloud Photos feature. There's so much confusion out there about this. (The breaking-e2e aspect does exist with the iCloud Photos scanning... not that it's currently e2e, of course.)
- joshstrange 5y agoLet's also not pretend that some of this confusion done is 100% willfully by some of the news organizations reporting on this because it benefits them to conflate the two. We even see it a little from places like EFF who appear to believe their ends justify the means.
- blitzar 5y agoThere are plenty of comments on HN that claim there are no details of what has been proposed while simultaneously claiming to have read the white paper. This is rapidly becoming a topic not worth reading more about due to the misinformation and shilling from all sides.
- robertoandred 5y agoThe more fear and confusion the EFF can spread, the more donations they get.
- xfitm3 5y agoIs aljazeera.com the only outlet willing to cover this aspect of Apple's decision? It seems like the US media is effectively ignoring the complaints.
- zionic 5y agoSeems so, our corporate media is largely comprised of cowards and pay-for-play. Most media is deeply unprofitable, and it compensates for this by taking payment for ads disguised as organic content (have first hand experience with this that has honestly made me cynical). Most media won’t bite the hand that literally feeds them.
- Cipater 5y agoSo did you do any research before you claimed that corporate media are staying silent on this issue? The other sibling replies posted various articles if you're interested.
- hoppyhoppy2 5y agohttps://www.reuters.com/article/uk-apple-privacy/exclusive-policy-groups-ask-apple-to-drop-plans-to-inspect-imessages-scan-for-abuse-images-idUSKBN2FK09P https://www.reuters.com/article/uk-apple-privacy/exclusive-p...
- pranau 5y agoNY Times had an article covering it yesterday - https://www.nytimes.com/2021/08/18/technology/apple-child-abuse-tech-privacy.html https://www.nytimes.com/2021/08/18/technology/apple-child-ab... The article seems to cover both sides of the argument fairly and nails the concerns over Apple's on-device scanning: > If governments had previously asked Apple to analyze people’s photos, the company could have responded that it couldn’t. Now that it has built a system that can, Apple must argue that it won’t.
- inanutshellus 5y agoit was on CNN's homepage yesterday... https://www.cnn.com/2021/08/17/tech/apple-child-safety-tools-backfire/index.html https://www.cnn.com/2021/08/17/tech/apple-child-safety-tools...
- bladefire 5y agoAll the religious people of the world are scared of being outed as evil pervs.
- jackpeterfletch 5y agoIm not sure if im missing something here, but from what I understand, what Apple is proposing is an enormous privacy boon that seems to be completely misunderstood. All cloud providers are required to, and do, make these scans. The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, except in this specific case, secured and controlled by your device. This means they couldn't comply with a nation states demand to secretly decrypt your data, even if they were legally compelled too, unless they change how the cryptography at play here works. Which I expect, would not go unnoticed. Am I missing something?
- samsa 5y agoCloud providers are not required to scan for this content. They are, however, required to disclose it if they find it. That said, many cloud providers do in fact scan for this content. Apple was the odd one out.
- newsbinator 5y agoThey could comply with a nation state's demands to scan a billion iPhones for a politically dangerous photo.
- jackpeterfletch 5y agoYou'd need 30 of them. And upload them iCloud. I guess the neural part is a bit of a blackbox, im not sure if theres a way for external parties to verify its legitimatcy. But again, any change to would go noticed.
- newsbinator 5y agoYou wouldn't need 30 of them or to upload them to iCloud. If a nation state can demand Apple uses their existing function to scan your phone for political images, then they can likewise demand that 1 hit would be enough, and that there's no requirement for it to be uploaded to iCloud before the scanning can start.
- omginternets 5y agoSo, what parts of my phone are actually being scanned by this system? It seems like it's rummaging through any images that are touch iCloud, which would include: - iMessage - WhatsApp - Camera - Matrix (?) - Any other application that you give 'photo' permission to?
- 1f60c 5y agoAs far as I know, it’s only iCloud Photos.
- aj3 5y agoThere are two different CSAM related features. One scans photos before they get uploaded to iCloud, other looks for indications of nudity and only works on minors' phones if their parents enabled this detection.
- theshrike79 5y agoPhotos in Photos.app will get scanned if you have iCloud enabled (required to download the CSAM hash database). Messages will be scanned for CSAM content if you are a child, then parents will get notified that they received a dickpick.
- websites2023 5y agoTo be clear, the content being scanned in messages is not a hash check against a database. It’s a plain old nudity detection algorithm similar to what Facebook has.
- DaftDank 5y agoIs there a possibility that this could be some kind of Dual_EC type of backdoor they are trying to insert under the guise of something "positive" -- i.e. CSAM? As others have said elsewhere, it seems so out of the blue like they were pressured from somewhere, which I guess I default to assuming government. After reading "The Hacker and the State" by Ben Buchanan, it made me even more aware of how much depth and penetration there is of the private-government partnership in the US.
- nszceta 5y agoiOS is closed source and builds are not reproducible by the public. You have zero control over what is running on the iPhone. It is also extremely challenging to go through each executable and firmware on the phone to probe for backdoors. Sophisticated backdoors won't be apparent even if you had the executable data dump for every iPhone system.
- DaftDank 5y agoRight, I understand that. I guess my question was more of a general one on whether people think Apple in particular would cooperate with the government in that way? Obviously the San Bernardino shooter case comes to mind as an example of Apple not just folding to the government pressure.
- nszceta 5y agoSearch "top secret ipod"