3 ms·
We still need to rely on the automated "secret backend system" that nobody supposedly knows anything about
by collaborative 5y ago
We still need to rely on the automated "secret backend system" that nobody supposedly knows anything about
- toxik 5y agoYou (or at least Apple's customers) trust in and rely on Apple's proprietary software to do its job all the time. How is this different? I find this argument very weak.
- Hackbraten 5y ago1. You can at least somewhat audit the software running on an iPhone, for example by means of reverse engineering. You can’t audit the server side. 2. It’s one thing to rely on proprietary services like Find My or Siri. It’s another thing to rely on a secret server-side app that has the power to destroy your life.
- idunnoman 5y ago"Hey Siri, accuse me of something that will ruin my life and reputation even if I'm not guilty".
- fetzu 5y agoWhat I somehow fail to grasp in the first argument is that this whole system is designed specifically so that it runs client-side. AFAIK all the alternatives (as in « cloud photo services ») have been doing the exact same thing on the server side for decades. If you upload your photos to the cloud, a lot of service actually already have the power to destroy your life.
- collaborative 5y agoThis is all about Apple users waking up to the fact that they've been had
- strangetortoise 5y agoafaik none of Apples other "proprietary software" is designed to pass my personal images to a human for visual inspection if it mistakenly outputs 2 high-enough numbers after a handful of convolution operations and matrix multiplications.
- FabHK 5y agoThey pass a "visual derivative" to "a human", but only after some matrix multiplications etc. that result in extremely low probability false positives. It could also happen that you lose your phone and "a human" finds it and randomly puts in the correct passcode on the first try and visually inspects your personal images. In fact, that seems vastly more likely [1]. [1] About 4% of smartphones are lost or stolen every year [https://www.mcafee.com/blogs/consumer/family-safety/almost-5-of-smartphones-lost-every-year/ https://www.mcafee.com/blogs/consumer/family-safety/almost-5... ], but make it just 1/1000, so 1e-3. Then a 6 digit passcode, 1e-6, so we're at 1e-9 per year, or 1000x as likely as being falsely flagged, assuming Apple's numbers (which can easily be achieved by calibrating the threshold).
- collaborative 5y agoTell this to the victims of Pegasus. If anyone were able to get their hands on the "secret backend system" we wouldn't be talking about spy games, we'd be talking about people's lives being ruined
- roody15 5y agoApple still has not patched the security exploit in iMessage used by Pegasus. Apple has released two ios security updates since the Pegasus revelations but still has not patched it most widely used exploit… hmmmm. Now apple is getting a local client side scanning tool ready. Interesting timing.
- collaborative 5y agoI don't think what you are saying is far-fetched
- read_if_gay_ 5y agoNo. I trusted Apple’s proprietary software before this, because they maintained that they care about privacy, and there have been examples of that. Now, I don’t trust them anymore.
- simion314 5y agoThere is a big difference, if say Apple tracking of what you run is problematic you get a bad user experience like apps starting after 1 minute of waiting, or if Apple App Store contains malware you will probably get some annoying issue while Apple will try to silently cleanup their mess BUT with this system there is a difference, this is designed not to serve you or protect you, it is designed to do some checks then if some specific rules match send some guys on you to destroy your life, today is FBI tomorrow other authoritarians. Issues in any other Apple software will not send the police on you. Why would you install a software on your desktop/laptop that is designed to snitch on you, you would need to get some advantage or be forced by some law. For now I see only disadvantages but please let me know of any real advantage and not speculation Disadvantages: - closed software with hidden db can't be trusted, so as a user you will always have a doubt that some non CP images are in the db(Apple always collaborates with governments) - bugs in this stuff will cause you big problems(we seen in the past how false accusation destroyed peoples life) and we also seen bad actors abusing this kind of stuff. - this is also clearly a beginning, now that Apple has the capability then even if they were saints a judge could force them to add new hashes, change the configs etc.