Apple urged to drop plans to scan iMessages, images for sex abuse
aljazeera.com
aljazeera.com
People who say things like this rarely also want the hassle that comes with it. Key exchanges, re-keying: all a big PITA. But iMessage (and WhatsApp) do key exchanges facilitated by a trusted broker. If you didn't trust the broker, you would have to do more work when making an initial exchange with a peer and more work if they lost their phone/keys.
iMessage has always been a compromise with subtle rough edges. But we trusted Apple because they talked about privacy and made it clear that their business model meant that we should trust them more than competitors. But now, precisely because of how good and effective they secured their devices -- they fear regulation and thought that they could further compromise things and people would go along with it.
We are over a year into a pandemic which involved wide-scale lockdowns. Physical key exchange is a nonstarter for broad adoption.
I think the emphasis is on the -ed in involved. That's a temporary condition which is already resolving in much of the world. You may also be overestimating lockdown compliance among average people.
If iMessage had been designed to require a brokerless key exchange, its security would be superior (though in this case, Apple's interception software trumps everything). But iMessage would appear to be less convenient than alternatives like WhatsApp (brokered key exchange, re-keying).
We would be in a much better position right now with email privacy if the version of PGP that doesn't defend from an active attack would have been deployed worldwide.
That’s a wee bit different from showing YouTube previews imo.
> And nice that you abuse your karma to downvote people who don't agree with you.
I did not downvote you; not that you be able to tell if I did, anyway.
"More than 90 policy and rights groups ask company to abandon plans for scanning phones of adults for images of child sex abuse.". Maybe YOU weren't talking about csam, but everyone else was including the article author, if you even read it.
I pointed out that's not true (that's probably why other people downvoted your comment) and that you're apparently confusing the iMessage stuff with the CSAM scanning stuff which, as I already said, are completely separate from each other.
https://developer.apple.com/library/archive/technotes/tn2444...
I want the real thing.
If you used iOS/iMessage, you have always trusted Apple. To be truly 'end to end' you would assume that there's no opportunity for another party to intercept your messages: the only trust would be in the keys you exchanged with your peer.
1. They are a trusted broker for iMessage key exchanges. You didn't do the key exchange, you assumed that when Apple did so on your behalf that you're really communicating with the peer you think you are.
2. They designed the iOS features that you trust keep iMessage data inaccessible to other untrusted software on your device.
3. They designed the secure enclave and make public statements that they won't compromise it for law enforcement. You trust that their deeds in private match their public statements.
I'm not in agreement with this being ok, but if it truly is on device, it still technically can be E2EE
What do you think this software does when it finds a matching hash entry? Toss a notification to ask you nicely to pop round your nearest FBI office?
What meaning does 'end-to-end' have anymore if this applies? If Apple wrote software on-device to forward a copy of all messages prior to encryption to iCloud for 'backup', would it still be end-to-end? What if they sent it to an AdTech firm to index for interesting terms that match products you should be pitched? The software in this case is still Apple's, running on-device.
I'd suggest you read up a bit on this - https://www.apple.com/child-safety/
What we're discussing is this feature:
"The Messages app will add new tools to warn children and their parents when receiving or sending sexually explicit photos.
When receiving this type of content, the photo will be blurred and the child will be warned, presented with helpful resources, and reassured it is okay if they do not want to view this photo. As an additional precaution, the child can also be told that, to make sure they are safe, their parents will get a message if they do view it. Similar protections are available if a child attempts to send sexually explicit photos. The child will be warned before the photo is sent, and the parents can receive a message if the child chooses to send it.
Messages uses on-device machine learning to analyze image attachments and determine if a photo is sexually explicit. The feature is designed so that Apple does not get access to the messages."
There are no visual derivatives, no neural hashes, and nothing is sent to apple.
> More broadly, they said the change will break end-to-end encryption for iMessage, which Apple has staunchly defended in other contexts.
But... it wouldn't. The iMessage feature doesn't expose the contents of your message to anyone else under any circumstance.
If you're a child under 13 and your parents have opted in to this feature, you get a choice of seeing naked-pictures sent to you and having your parents be notified that you chose to, and bypassing it with no notifications of anything. (But once you're 13+, no notifications would occur.)
There are potential issues with this, mostly relating to abusive families being controlling. They'd have to do weird things like forcing their teenaged children to keep making new under-13 accounts to actually take advantage of it like that, though. And none of these issues impact the e2e status of iMessage in any way.
Apple really screwed up PR by launching the iMessage feature alongside the scanning-and-reporting iCloud Photos feature. There's so much confusion out there about this.
(The breaking-e2e aspect does exist with the iCloud Photos scanning... not that it's currently e2e, of course.)
It's possible that they determined that dealing with the backlash in one go would be easier than having two separate blowups. Most consumers have only fuzzy, vague senses of brands based on a poorly-understood game of Telephone linked to each news cycle. This only counts as "one" privacy ding against Apple for most people, whereas two separate news cycles would do much more damage to their reputation around privacy.
The EFF's first article objecting to these features objected to the parental control on the grounds that if, say, I send your 12 or under kid a sex photo and your kid elects to continue after being warned the image might be harmful, and then elects to still continue after receiving a warning that if they do so their parent will be notified and see the image too, it is violating my privacy because I did not consent for the parents to see the sex pictures I'm sending to their kid.
Now their objection seems to be that if I'm, say, a 12 or under gay kid who is not out to my parents, receive a sex image on my phone that might reveal I'm gay, and I elect to view that image after being explicitly told my parents will see it too and confirming that I still want to view it, I might get outed to my parents.
Note that in both these scenarios the child knows their phone has parental controls enabled, has to go through two full screen dialogs that try to discourage them from viewing the image to view it, both of those have rejecting the photo as the highlighted option, and the second explicitly reminds them that if they view the photo their parents will be notified and shown a blurred version of the photo. And note that if they choose to reject the photo rather than view it, there is no parental notification.
For years, privacy advocates (including the EFF) have said when governments wanted to legislate controls server side or at the ISP level to provide a safer net environment for young children that the right approach is to give parents the tools to ensure a safe net environment for their children.
So now we are getting a parental control that goes out of its way to not notify parents or share a blurred photo with them unless the child explicitly chooses to view it knowing that this will happen--and they are objecting to that.
After this it is hard to imagine any parental control system that the EFF would approve of and that is actually even remotely effective. It makes them look like an organization that is just going to raise knee jerk reactions to every proposed solution, nor matter how reasonable.
When an organization raises objections to every attempt to solve real problems at some point policy makers stop caring what they have to say, and the EFF has either reached that point or is real close to it. They need to start suggesting alternate solutions to those problems if they want people that matter to listen to them.
This is rapidly becoming a topic not worth reading more about due to the misinformation and shilling from all sides.
"Regardless of popular sanction, war is mass murder. Conscription is slavery, and taxation is robbery. The libertarian in short, is almost completely the child in the fable, pointing out insistently that the emperor has no clothes. Throughout the ages, the emperor has had a series of psuedo-clothes provided for him by the nation's intellectual caste. In past centuries, the intellectuals informed the public that the state or it's rulers were divine. Or at least, clothed in divine authority and therefore what might look to the naive and untutored eye as despotism, mass murder, and theft on a grand scale, was only the divine working it's benign and mysterious ways in the body politic. —Murray Rothbard, For a New Liberty"
I’m still a fan of the ACLU, even with their spotty record on gay rights, but it might just be a matter of time.
On top of that, at some point they must have asked if it was okay to contact me, and I must have inadvertently said yes, and now I get regular text messages from random people across the country asking if I will help out. About half the time it's for something in a state (like Georgia during the election) which is several thousand miles from where I live. No amount of begging has gotten this flow of unsolicited text messages to stop.
It does if it contains the flagged content.
When we say end-to-end, we mean that even Apple cannot know what is on the wire which won't be the case anymore.
- iMessage - WhatsApp - Camera - Matrix (?) - Any other application that you give 'photo' permission to?
Messages will be scanned for CSAM content if you are a child, then parents will get notified that they received a dickpick.
The article seems to cover both sides of the argument fairly and nails the concerns over Apple's on-device scanning:
> If governments had previously asked Apple to analyze people’s photos, the company could have responded that it couldn’t. Now that it has built a system that can, Apple must argue that it won’t.
Edit: BBC as well it seems: https://www.bbc.co.uk/news/technology-58109748
https://www.cnn.com/2021/08/17/tech/apple-child-safety-tools...
Most media is deeply unprofitable, and it compensates for this by taking payment for ads disguised as organic content (have first hand experience with this that has honestly made me cynical).
Most media won’t bite the hand that literally feeds them.
The other sibling replies posted various articles if you're interested.
What do you mean here: I don't think makes things any safer for child _users_ of iPhones, does it? It's scanning for images of child sexual abuse.
(To anyone inclined to respond without reading the context, I'm not suggesting that there's no privacy concern if you're not sharing CP. I'm addressing OP's hypothetical that some parents will see owning an iPhone as safer for their child)
The second feature is iMessage specific. Parents have to enable this on their account on behalf of their children, and it only applies to minors (_probably_ just children under 13, possibly older; I am not clear on that). This looks for (mostly outbound?) messages going to the child's phone for “unsafe” images (e.g., nudity). If those messages are found, _the parent_ is notified. No one else.
I have _more_ concerns about the second feature as it is likely to be abused by controlling parents and is more likely to negatively impact children who are questioning their gender or sexuality. But this is _explicitly_ a feature to protect kids from sharing sexual images of themselves.
Though I still don't see how the parent comment's theory holds: I suspect that the PR backlash would be far smaller/nonexistent for this feature than for the CSAM one, as we already accept that the rights of minors are heavily curtailed.
They built two different systems, one that I think is good / that would be a selling point to parents, and one that could be a powerful weapon.
¹: The “notifying parents” thing is a little iffy; I'm not sure what to think about it.
There's nothing wrong with taking pictures of yourself nude and/or sharing these with whoever you want. This goes towards territory that I find deeply uncomfortable.
No. The system looks for files that are similar to known illegal content. It is not a general purpose underage nude photograph detector.
I think the parent comment is in reference not to the current system, but to potential future functionality, enabled by opening the Pandora's Box of client-side scanning.
Though I agree that underage nudity detection in particular is a little fanciful
Feature 1: CSAM detection. Only on upload of images to iCloud Photos.
Feature 2: nudity detection for minor children controlled via the parents' iCloud account. It is not an “underage” nude photograph detector, but a nude photograph detector. All done on-device. The only person(s) notified are THE PARENTS. This is all opt-in and age-restricted. I do not know whether it will affect teens sexting or only under-13s.
Notifying the parents is optional (controlled by parents), and only for accounts below a certain age afaik. It primarily notifies the phone's user.
Or:
Hi Dave i’ve been noticing that you have been discussing Covid vaccines with your friends. Apple thinks your position on this causes public harm so we will be adding additional information to each of your messages that discuss this subject. Thank you for being part of our team.
- I'm sorry Dave, I'm afraid I can't do that.
All cloud providers are required to, and do, make these scans.
The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, except in this specific case, secured and controlled by your device.
This means they couldn't comply with a nation states demand to secretly decrypt your data, even if they were legally compelled too, unless they change how the cryptography at play here works.
Which I expect, would not go unnoticed.
Am I missing something?
- I don't want the rules to change in the future for what will be scanned.
- I don't want to support Apple scanning for pictures of Tank Man for the CCP.
- I don't want an untested proprietary algorithm making decisions about me that could alter my life. It's already been shown that you can make innocent pictures that collide with CP hashes. This screams of future abuse.
There is NO end to end encryption being rolled out at the same time (so they can still decrypt and hand over your data in the cloud).
> This means they couldn't comply with a nation states demand to secretly decrypt your data, even if they were legally compelled too, unless they change how the cryptography at play here works.
Not only is this completely wrong (they can hand over your decrypted cloud data right now), it's wrong even going forwards with the assumption you made above about real E2EE (which we don't have...) - All they have to do is add a few hashes from that nation state to their catalog and your data is whisked away to apple for them to do with as they please (which right now is meaningless, since they currently have access to it anyways, but makes your point about E2EE a lot less compelling).
But its still possible that Apple are preparing for a scenario where it does become a requirement in the future.
As for the E2EE part, I can't imagine that this wouldn't be launched with E2EE alongside, otherwise theres literally no point whatsoever, they could have just done the scan on iCloud.
As for why this combats 'your data being whisked away', check the technical documentation. What they're doing with Private Set Intersection and Threshold Secret Sharing are clear steps to make this system unexploitable, anonymous, and so that it doesn't leak any metadata whatsoever.
https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
Think you shared that picture of police brutality anonymously? Think again.
A government could already coerce Apple into handing over iCloud data.
The cryptography at play here, combined Private Set Intersection and Threshold Secret Sharing are clear steps to make it as hard as possible for any institution to body this for that reason.
Y'all are starting to make me more sympathetic to Apple. Their biggest misstep was making these announcements simultaneously without foreseeing how many people would (willingly or otherwise) conflate them.
The only phones where iMessage photo scanning happens are those for children under a certain age (maybe 13?) whose parents who have opted into child protection where the phone scans for nude photos and notifies the parents.
People are conflating these two _different_ but _related_ features and their goals and limits.
Also, dissidents can just turn off iCloud sync and no scanning will happen.
They are, however, required to disclose it if they find it.
That said, many cloud providers do in fact scan for this content. Apple was the odd one out.
If the CSAM detection were released with encrypted iCloud backups (or generally E2EE iCloud), then I think I'd probably be entirely less outraged. This narrative would make sense then.
Apple claims the on-device CSAM scanning only occurs on device if the photo in question is uploaded to iCloud. Apple is surely already scanning iCloud photos on their cloud, so without E2EE to iCloud, what's the point?
My ability to control a device I own, with Apple, was already suspect. Apple's use of on-device scanning is a slippery slope: it's not a question of if it will be used for nefarious means, but when. The claim that the scanning is only done for cloud-destination images is suspect and could be changed by gagged government coercion and a minor update.
The feature itself has little going for it in efficacy too: like most of the US's punishment bureaucracy / legal system / policing. Real child predators likely already avoid the cloud. These kind of slippery slope arguments against crime are often used by law enforcement to erode privacy rights: they don't actually catch more bad guys, but they do spy on more law abiding citizens.
Who's to say that in the future, law enforcement won't use this kind of technology for the war on drugs or other failed law enforcement initiatives? Law enforcement often uses violence or terrorism, for example, as justification for its own expansion and more privacy-invading initiatives, but terrorism is a very low threat, and only 4% of crimes in the US are violent (as defined by the FBI). CSAM has been used for decades as justification for the state to nose more in private citizens' business too. It's certainly an issue, but there have to be better ways to reduce child harm.
I guess the neural part is a bit of a blackbox, im not sure if theres a way for external parties to verify its legitimatcy.
But again, any change to would go noticed.
If a nation state can demand Apple uses their existing function to scan your phone for political images, then they can likewise demand that 1 hit would be enough, and that there's no requirement for it to be uploaded to iCloud before the scanning can start.
Read the technical documentation.
They're combining Private Set Intersection and Threshold Secret Sharing in a way that means that 1 hit, isn't enough. They can't even tell how many red flags you have.
Just by forcing Apple to add a bunch of image hashes they can't do anything, it'd still require multiple matches before Apple can see the images.
Oh and the OS sends fake encrypted "matches" at random to Apple's servers so that you can't use even that to fingerprint the user.
If they change the system to just start scanning local photos globally there really is Nothing to stop them from pushing out an iOS update today that does the same thing.
No scanning is required by law. In fact, the law states you don't have to go out of your way to invade privacy to scan. So yes, you and tons of other people are missing a big piece in this.
Good for Apple for stopping, and good for society to pressure them to stop. Seems like a win-win all around.
Is there some big news that I missed? Do you have a link to that info?