EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning
eff.org
eff.org
That particular statement doesn't make much sense to me. The parental notification system is just a frontend action (one of many, like link previews and such). What does that have to do with iMessage's encryption?
I can see an argument about a shift away from privacy (though it only pertains to minors under 13 receiving sexually explicit images). But I think it's misleading to say that it relates to iMessage's encryption in any way.
Generally, we consider the "end" to be the end user. If someone else can see the message along the way, it is not end to end anymore from a user perspective, even if it is from a network perspective. And Apple has complete control over your device through software updates. So that the leak is from your device or from the network is a mostly meaningless technical detail.
And obviously both the sender and receiver software processes the unencrypted messages in a variety of ways.
This is a case where I think it is justified, as long as your child is a minor and you are his legal guardian. But as acceptable as it is, you are still a spy and the app is spyware.
The fears, justified or not, is that the same feature that can be used for parental control can also be used on adults without their consent.
Personally, I think that right now, the fears are overblown, but I also think that Apple got the backlash they deserved. Privacy is not to be taken lightly, it is something that both protects freedom and helps criminals, also a strong political stance. It is not just a marketing took against Google.
I also think this behavior is creepy and would do it myself. But interestingly it is preparing them for a world in which there really are no secrets anymore.
I vehemently disagree that a feature could be classed as spyware if it clearly and unambiguously declares exactly what it's going to do prior offering a choice whether or not to do it. By that logic, the mere presence of a "report phishing" button in any cloud email service would be sufficient to declare it as spyware.
But fine, whatever. You're welcome to call any form of parental oversight of a child below the age of thirteen "spyware" if you like, so long as you accept that it's entirely my choice as a parent. This feature isn't on by default. If your opinions as a parent are different, don't turn it on. It's not your place to deny me access to this opt-in tool which can help keep my child safe.
Once I had a laptop, she told me she wished there was software she could install on all of her children's computers that would allow her to view what each of us was doing on her TV.
I considered that spying - even if it was intentional on her part. I detested how few rights I had as a child.
That is called being a teenager, I think.
Parents don't have an inherent right to know every single thing in a child's life. By that token, if a child is gay, and their parents are rabid anti-gay bigots, they still have a "right" to know whether their child is seeking out information relevant to LGBT teens. I'm sorry, but I wholeheartedly reject that premise.
Understandably the term might be used differently or more loosely elsewhere.
And yes it is obviously a spyware.
The report phishing analogy is also completely wrong because it does not include any surveillance. You report the phishing and send the message to some authority. It is the same as going to the police after receiving a threatening mail, whereas the spyware is like the postal service opening each of your letters.
In my HS computer science class all it took was asking the teacher to use her computer to format a floppy because “my floppy drive was broken” and i needed a new disk. She agreed and not 15 mins later i had my workstation booting with no management or oversight.
And to the extent that it might be true, it's still not a valid excuse for objecting to the existence of any such tools.
I don't care if the sender hasn't given consent, I don't give them consent to send porn or naked photos to my kids !
Children are a different story, they are not free, they are under the control and responsibility of their legal guardians. In fact, the status of a child and the status of a slave are not so different, that's why there are very strict laws regarding child labor, because otherwise it could easily end up in actual slavery.
Here the problem is not parental control, that is fine, the problem is that the backdoor is now in place and could be potentially used against adults with all the nasty implications. Again, I think the fears are overblown, but I understand that it makes people uncomfortable, especially since they may have bought an overpriced device on the premises of privacy. Most of the most egregious privacy violations start with "think of the children", even more than terrorists and covid.
If I buy a car it doesn't matter that I own it? If I rent it to you I can't set the terms of that rental?
This is just nuts from the EFF.
See: baby monitors.
Furthermore, by law the parent still effectively owns anything "given" to a pre-teen child. If the parent wants to take the device away from them and sell it, they're well within their rights to do so.
> Furthermore, by law the parent still effectively owns anything "given" to a pre-teen child.
Now that’s very broad. Which country/state/etc? I think if you actually looked instead of assuming, you’ll find that people under 18 can definitely own things.
This surveillance is a huge can of worms. Apple should stay faraway.
From the letter: "Moreover, the system Apple has developed assumes that the "parent" and "child" accounts involved actually belong to an adult who is the parent of a child, and that those individuals have a healthy relationship. This may not always be the case; an abusive adult may be the organiser of the account, and the consequences of parental notification could threaten the child’s safety and well being. LGBTQ+ youths on family accounts with unsympathetic parents are particularly at risk."
Should Apple should require verification of parental status? Ie upload birth certificate, photos of parents, child, whatever is necessary to establish true legal guardianship. Still doesn't protect the children from abusive parents though.
These features need to be killed off yesterday.
Am I entitled to know when my pre-teen child has received a message that contains a potentially explicit attachment, or text which matches the traits of child grooming? Hell yes.
This has been true of all operating systems with integrated software updates since the advent of software updates. In this respect, nothing has changed for over a decade.
Now we all accept it as annoying but necessary?
My guess is this may meet a similar fate.
In particular, you can be concerned about E2E encryption being compromised while still believing parents should have some transparency over whether their kids are receiving explicit images. Not clear EFF offers a solution that meets both, but I did not say they are opposed to the latter.
I would be surprised to hear that the genesis of this idea was inside of Apple vs. one or more govts pressuring Apple to add this functionality for them.
It is also likely they even suggested that Apple should market this as anti-pedo tech to receive the least pushback from users.
If what you suggest were true, we should be even more angry with Apple: it would mean that rather than just lawfully invading their users privacy, that they were a participant in a conspiracy to violate the constitutional rights of hundreds of millions of Americans.
We should be angry with _ourselves_. What's happening now is that this has hit closer to a lot more people, who are now dissecting every detail, blaming others, performing mental gymnastics, and launching 'open letters' so that their brand identity and perceptions aren't proven wrong. Convincing them to roll back their recent changes will not somehow make Apple devices private, when it was never private to begin with.
Non-surveillance phones: https://news.ycombinator.com/item?id=28164208
Non-surveillance laptops: https://news.ycombinator.com/item?id=28216287
I don't really buy the implication though. "The time to be angry is years ago"; "We should be angry with ourselves". If these are true, what are you saying? That we should suck it up and be quiet? That we missed our chance and need to deal with it?
Fairly sure this is one of those logical fallacies used on young children who forgot to use the bathroom before a long road trip.
Of course, we’ll accept it and the dullest of us will even cheer it as “doing the right thing” while stating that they “have nothing to hide”.
[0] https://www.nytimes.com/2021/08/20/podcasts/the-daily/apple-...
But it still doesn't change that Apple needs to stop on-device scanning.
They could open source the OS allowing independent auditing and independent privacy focused builds to emerge so people have a way to opt out, as they have on Android via projects like CalyxOS.
That is of course if privacy was actually a serious Apple objective.
If Android also implements something like that I could end up with a Linux phone as my main phone and an Android one at home for the 2FA of banks and other mandatory apps. No WhatsApp but I'll manage.
https://news.ycombinator.com/item?id=28261147
Unfortunately it got flagged after getting 41 upvotes. :(
edit: and now it's disappeared...
What’s clear is the potential for future abuse mandated by various gov (though that could easily be the same even without all these CSAM measures.. not a new threat). However, the other things are erroneously lumped in with it. It only weakens privacy for iCloud photos if you have CP or photos in a CP database, and it doesn’t prevent E2E with texting… it just gives an additional parental control in addition to the many numerous parental controls (with them kids have no privacy already), and is totally unrelated to the CSAM effort.
I admire the EFF in many ways, but I wish they’d be more exact here given their access to expert knowledge.
Apple has historically avoided being pressured by governments to allow this kind of surveillance by arguing they can't be forced to create functionality that doesn't exist, or hand over information they don't have. It's the argument they made in the San Bernadino case.
If they release this, it'll be much harder to avoid giving governments that existing ability for other, non-CSAM uses.
In this case, I actually kind of buy Apple's argument that this will make it harder to cowtow to governments (assuming they encrypt iCloud photos at some point). Right now they can scan iCloud data and hand over photos and accounts without user's knowledge. They can do that without informing users (like they currently do with backups). With this in place the database and logic ships with the OS. They would have to implement and ship any changes world-wide. Users will have to install that update. An alternative is Apple silently making a server-side change affecting specific customers or countries. With that said, I do understand people's concern over the change.
[1] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
People like to pretend crypto is always E2E or nothing, but escrowed keys do mean that the process of checking cloud-backed data has an auditable release process, that the keys to your data are outside the cloud-hosted infrastructure, and that there is no support for blanket data scanning.
> assuming they encrypt iCloud photos at some point
iCloud photos are already encrypted. See above.
Here, it's different.. let's say there's a new wikileaks, photos of secret documents... and again, first a few journalists get the data, start slowly writing articles, and FBI just adds the hashes to the database, and they can find out who has the photos, with metadata even who had the first, before the journalist, and they can find a leak.
This is the crux of the argument right here, and I have yet to see a detailed description of how the FBI would go about doing that.
The most detail I’ve seen is in this thread, which suggests that it would be difficult for the FBI to do it, or at least do it more than once.
https://twitter.com/pwnallthethings/status/14248736290037022...
Has anyone seen something like this in the other direction? Something that walks through “the FBI would do this, then this, etc. and now they’ve coopted Apple’s system”?
Australia contacts Apple and demands they augment CSAM detection so that every iPhone in the USA is now scanning for image hashes supplied by Australia.
Apple says no.
End of hypothetical.
“ The Australian Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (TOLA) allows government agencies to issue “technical assistance” and “technical capability” notices to providers of communications services. The notices require that the providers give the authorities help in conducting criminal enforcement intercepts, and that they make changes in their systems to ensure that they can give that help.”
…
“In any event, the FBI chose a curiously roundabout way of getting access to ANOM messages. For ANOM devices operating outside of the United States, “an encrypted [blind carbon copy or BCC]” of each message that a user sent was transmitted to a server located outside of the United States, which then decrypted and reencrypted the message with an encryption key known to the FBI. Those reencrypted messages were sent to another server that was owned by the FBI, outside of the United States.
In the summer of 2019, the FBI started negotiating to build the legal structure that would make this technical architecture work. In essence, the FBI went looking for a third country that would host the BCC server and could lawfully accept all of the decrypted messages and send the copies to the FBI. As the affidavit notes, “Unlike the Australian beta test, the third country would not review the content in the first instance.” This would have been a fascinating negotiation. Both participants wanted to make criminal cases and avoid privacy scandals. The U.S. would want to be sure that the third country had full legal authority to intercept the contents of every ANOM message, and that the country was also willing to share the full ANOM take with the U.S. in something like real time.”
I'm not saying the US Government wouldn't care that it's unconstitutional—we know they'd ignore the constitution when they can get away with it. But they'd also have to convince Apple's lawyers to go along with unconstitutional surveillance. You don't think Apple wouldn't be itching for another opportunity to prove their strength against a Government? Especially now? Apple would love nothing more than to have more opportunities like they got with the San Bernardino iPhone.
I know for a fact there are efforts at creating fusion centers across national boundaries. The question you need to ask is not if but what will make you interesting enough to mobilize against.
Thou shalt not build the effing Panopticon, nor it's predecessors. Is that so hard to not do.
Of course it’s even easier for Apple to say “no” to the government if they literally cannot do what the government is asking.
That’s the basis of the EFF’s objection to Apple’s plans: they think that by implementing this CSAM system, Apple will turn an impossibility into a possibility.
No. Because the hash causes searches to be performed on citizens' private property, this would be an unambiguous, indisputable, clear-cut violation of the 4th Amendment.
Apple simply tells the DOJ if any non-CSAM content is added surreptitiously to the DB, Apple will drop CSAM scanning. Also, if DOJ makes any request to scan for non CSAM by court order or warrant, Apple will in kind drop support for the technology.
Apple is making the good faith effort here. If DOJ makes a bad faith effort, Apple is in now way required to continue to participate.
From my understanding Apple blindly accepts the list of hashes from their trusted soueces.
All of these processes will be subject to discovery in the very first trial generated by this technology. If there is evidence that governments are polluting the DB with non-CSAM content, then warrants issued on evidence from the DB can be overturned. Prosecutors in DOJ and FBI etc. have a strong incentive to ensure that DB doesn't turn into a free-for-all dragnet because it could work to invalidate their ability to use evidence from legitimate CSAM cases.
Or people who have photos that hash the same as CP.
So what’s the actual realistic issue here? This keeps getting thrown around as if it’s likely, yet not only are there numerous steps against this in the Apple chain, this would already be a huge issue with Dropbox, Facebook, Microsoft, Google, etc who do CP scanning according to all of the comments on HN.
That's trivial. If the attacker can get one image onto your device they can get several.
It's very easy to construct preimages for Apple's neural hash function, including fairly good looking ones (e.g. https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX/issue... )
> collide with another secret hash function
The supposed other 'secret' hash function cannot be secret from the state actors generating the databases.
Also, if it has a similar structure/training, it's not that unlikely that the same images would collide by chance.
> also have a human look at it and agree it’s CP
That's straight-forward: simply use nude or pornographic images which looks like they could be children or ones where without context you can't tell. It's a felony for them to fail to report child porn if they see it in review, and the NCMEC guidance tells people when in doubt to report.
Besides, once someone else has looked at your pictures your privacy has been violated.
Also if you’re a gov actor trying to frame someone, why bother with a pre-image when you could put the real images on it?
None of that is new today — all that’s new is Apple is joining the effort to scan for CSAM, and instead of doing it on server they’re doing it on device right before you upload in a way that attempts to be more secure and private than other efforts.
Say I sneak (psedo-)child porn onto your device. How do I get authorities to search you without potentially implicating myself? An anonymous tipline call is not likely to actually trigger a search.
With automated mass scanning that problem is solved: All users will be searched.
I think the big cloud providers scanning your private data is of dubious ethics, but it's like complaining that your mail carrier is reading the content of your postcards.
So long as you send unencrypted data to a third party your privacy will be limited, regardless of what our laws or norms say. People usually know this, and so many do avoid uploading things to these places or encrypt what they upload.
When its your device itself doing the scanning, ahead of any encryption-- then that protection goes out the window.
Sometimes the same violation of privacy is made more acceptable by a clear boundary that you can stay on one side of to protect your privacy. Your devices vs someone elses devices is the most clear historical boundary in this case, and apple is breaking it.
I don't think it's unreasonable to expect the erosion of the private boundary to have an effect. And we can't say that the scanning by providers does nothing, -- the convictions prove otherwise. We can only hope that all those convictions were deserved, the nature of this crime is such that its hard to prove someone wasn't framed.
It's already happening. Except we just choose to SWAT people instead, since it's faster, easier, and there's effectively no liability on the behalf of the caller.
Once the capability is in place on everyone's devices, how are we supposed to guarantee it will never be used maliciously? Just say no to the capability.
> Also if you’re a gov actor trying to frame someone, why bother with a pre-image when you could put the real images on it?
Because the capability for this is now built-in in everyone's phones.
At which point everything you brought up about attacks on the hash function is completely irrelevant because the attacker can put actual child porn from the database on your device.
My primary concern about its ethics has always been the breach of your devices obligation to act faithfully as your agent. My secondary concern was the use of strong cryptography to protect Apple and its sources from accountability. Unfortunately, the broken hash function means that even if they weren't using crypto to conceal the database, it wouldn't create accountability.
Attacks on the hash-function are still relevant because:
1. the weak hash function allows state actors to denyably include non-child porn images in their database and even get non-cooperating states to include those hashes too.
2. The attack is lower risk for the attacker if they never need to handle unlawful images themselves. E.g. they make a bunch of porn images into matches, if they get caught with them they just point to the lawful origin of the images. While the victim won't know where they came from.
Wait, sending data (of matching CP hashes) to law enforcement is parental control?
> [1] Moreover, the system Apple has developed assumes that the "parent" and "child" accounts involved actually belong to an adult who is the parent of a child, and that those individuals have a healthy relationship. This may not always be the case; an abusive adult may be the organiser of the account, and the consequences of parental notification could threaten the child’s safety and wellbeing. LGBTQ+ youths on family accounts with unsympathetic parents are particularly at risk. As a result of this change, iMessages will no longer provide confidentiality and privacy to those users through an end-to-end encrypted messaging system in which only the sender and intended recipients have access to the information sent.
> [2] When a preset threshold number of matches is met, it will disable the account and report the user and those images to authorities.
Which database? I get the impression that people think there is a singular repository for thoroughly vetted and highly controlled CP evidence submission. No such thing exists.
An independent audit for both the secret secondary perceptual hashing algorithm and the chain of custody policies/compliance for the "US db" and the disconcertedly open ended "not yet chosen non-US db"?
The concern people have is logic on their phone snitching on them, with scenarios based on authoritative regimes setting the baseline of what is scanned/reported.
Apple is not serving as judge, jury and executioner (unless there is an electric shock delivery system being added to the iPhone 13)
In fact it doesn’t make any difference at all, since they already have full access to everything you do on the phone, so if you don’t trust them you shouldn’t use an iphone.
I do not share your same concern of some abused db _today_.
If you’re concerned about non-CP being scanned for, then you should already be concerned about that with everyone else. Thus if you’re asking for auditing of Apple, then you should widen your request. If you do, then sure, I can understand that. If you’re not concerned about the existing system, then I think you’re being non-consistent.
Most people in comments to me seem to be non-consistent, and are being overly knee jerk about this… myself included initially.
This would be the source of the inconsistency - that the code to do scanning is on the client side of the uploader rather than the server side of the uploader does not change any abuse scenarios, but exclusively serves "slippery slope" arguments of full on-device surveillance.
It absolutely does. When the scanning is server-side, companies can only scan the files you choose to send to their servers but with a client-side system in place, all it takes is a change in company policy and a few simple directory config changes to result in ANY file on your device being scanned.
Slippery slope or not, the client-side system massively lowers the bar for abuse and that cannot be ignored.
"Pedophiles are taking pornographic photos of kids on their phones and then sharing them outside of iCloud. But wait, you don't want us to compare each photo you capture against ML models capable of identifying child porn? Why are you defending and siding with pedophiles?"
The only surefire way to avoid a slippery slope is to keep away from the edge.
No, it won't. The human reviewer only sees very low resolution thumbnails, to check there's a "match". The content is not verified, so the two DBs could contain anything.
Who controls what is in the database? What independent oversight ensures that it’s only CSAM images? The public certainly can’t audit it.
What is stopping the CCP from putting pro-Uighur or Xi Winnie the Pooh images into the database? Or from the US using this to locate images that are interesting from an intelligence perspective (Say for example pictures of Iranian Uranium centrifuges)? Apple says they will only add images that more than one government request? All it would take is a few G men to show up at Apple with a secret court order to do this no?
So… China and Hong Kong? The Five Eyes nations?
...but they don't have to do anything that elaborate because Apple is using powerful cryptography against their users to protect themselves and their data sources from any accountability for the content of the database: The hashes in the database are hidden from everyone who isn't Apple or a state agent. There is no opportunity to learn, much less challenge the content of the database.
[1] https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX/issue...
I think there are plenty of reasons to be concerned about future laws and future implementations, but let’s be honest about the real risks of this today as it’s currently implemented.
> They have to come from the intersection of two databases from two jurisdictions.
My message directly answered that. A state actor can modify an apparent childporn image to match an arbitrarily hash and hand that image to other agencies who will dutifully include it in their database.
> Then you’d have to match _nearly exact photos_
It's unclear what you mean here. It's easy to construct completely different images that share a neuralhash. Apple also has no access to the original "child porn" (in quotes because it may not be), as it would be unlawful to provide it to them.
> but let’s be honest about the real risks
Yes. Lets be honest: Apple has made a decision to reprogram devices owned by their customers to act against their users best interest. They assure us that they will be taking steps to mitigate harm but have used powerful cryptography to conceal their actions and most of their supposed protections are unfalsifable. You're just supposed to explicitly take the word of a party that is already admittedly acting against your best interest. Finally, at best their protections are only moderate. Almost every computer security vulnerability could be dismissed as requiring an impossible series of coincidences, at yet attacks exist.
Even if a state actor constructs an image that is an NeuralHash collision for the material they wish to find, that only gets them through one of the three barriers Apple has erected between your device and the images being reported to a third party. They also need to cause 30 image matches in order to pass threshold secret sharing, and they need to pass human review of these 30 images.
Arguably investigation by NCMEC represents a fourth barrier, but I'll ignore that because it's beyond Apple's control.
> You just have to blindly trust that Apple
This has been true of all closed source operating systems since forever. Functionally, nothing has changed. And whatever you think of the decision Apple has made, you can't argue that they tried to do it in secret.
I pointed out above that the attacker could use legal pornography images selected to make it look like child porn. This isn't hard. Doing it 30 times is no particular challenge. I didn't use pornographic images in the examples I created out of good taste, not because it would be any harder.
[1] I've made a statement that I won't be posting any more preimages for now for that reason: https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX/issue...
I have some residual nitpicks, on that point: many leaked data troves are much larger than that, though it is a material restriction.
The 30 threshold isn't leakless. Say you only have one hit, it still gets reported to Apple. The software also emits a small rate of "chaff", fake hits to help obscure the sub-threshold real hits. But it could still be used to produce a list of possible matches, including anyone with targeted material plus people who emitted fake matches, producing a list of potential targets much smaller than the whole population, for enhanced surveillance.
It would be interesting to know what the "chaff" rate is and whether any intelligence agency could stomach that amount of surveillance, particularly since it's by no means certain that any of them are real. In fact it seems to me that it's very unlikely indeed, especially if the material is in any way radioactive. After all, finding a match this way requires quite a few assumptions:
1. The target owns an iPhone;
2. The target has enabled iCloud Photo Library;
3. The target has a photo library small enough, or is paying for sufficient iCloud storage space, that the flagged images are included in the (sub)set stored in the cloud;
4. The target has imported the flagged images into their photo library rather than to iCloud Drive or any third party app like SpiderOak, Mega or Tresorit.
And that whatabout argument is supposed to justify the creation of a client-side scanning system that would massively lower the bar for abuse?
So third party auditors as well?
When it comes to keeping data private we face adversaries whos only rules seem to be what they can get away with. Against that, full transparency when it comes to the construction of our security infrastructure really needs to be the starting position.
What story are you referring to here?
So what you’re describing is something that is a concern for the future that could exist anyway (and maybe already does at places like Google that have _zero_ auditable processing of data that already scan for CP from the same database above). But let’s not pretend that’s today.
Or if someone hacks your device and uploads one of those photos to your iCloud.
(I still have no idea why people aren't pointing this out more aggressively -- phones get hacked probably every minute of every day, and acquiring those actual photos isn't that difficult once you're willing to commit felonies -- hash collisions are a distraction)
And we’re just not seeing that being the case. Because all these providers have been doing this for so many years, including the nearly 17 million photos identified by Facebook last year, you’d figure there would be a lot more noise if this was really going on.
In fact, I would venture to say it’s far easier to hack a Facebook account than it is iCloud that has many on-device-based security protections that a cloud login without mandatory 2FA (and often SMS when it is used).
Police and prosecutors have to do that because they have to attest to the judge that it is actually CSAM. And, unlike any private party, law enforcement is legally authorized to possess and review CSAM, so they don’t run any risk (aside from the risk of seeing horrifying images).
Unlike SWATing, the police don’t have to go to a person’s house to review suspected CSAM that is submitted by a service provider like Google or Apple. So it’s possible that there are existing collisions for PhotoDNA that make innocent files trigger an alert. But no one would know externally because once law enforcement reviews the file and sees it is a false positive, they just ignore it. The account owner would never know. The service provider might do forensics if they interpret the incident as an attempted attack.
Probably because the group that has/is willing to handle CSAM is small enough that it doesn't overlap much the other groups (e.g. account hijackers, or people who want to grief a specific person and have the necessary technical skills and the patience to actually pull it off). For criminals it may not be worth the extra heat it would bring, but from what I've heard about 4chan, I'm surprised there is not a bigger overlap among "for the lulz" griefers.
https://www.androidauthority.com/smartphone-users-survey-201...
To put it bluntly, this fantasy that any significant portion of people who live east of Tahoe even knows, much less cares, about CSAM scanning is plainly absurd. All the headlines and breathless coverage about the fatal mistake Apple is making has resulted in… Apple’s stock soaring to record highs.
Some creeps will get caught. Some will switch to another way of sharing that material. Apple will get shielded from liability for hosting this content in iCloud.
I then bought a System76 laptop to move away from my Macboom.
Basically all electronics manufacturers have bad software now. It's assumed and rampant. Firmware on TVs, preinstalled apps on phones and tablets. You can't buy current-grade gear for a reasonable price without unwanted muck.
As it stands I still had to pay the Windows tax.
There’s always an option to be part of the government and be on the side that takes advantage of this tech to take out rivals, make your job easier etc. but implementation of always watching devices is a hill to die on.
Does anyone have a link to previous discussion on this topic? Might help avoid endless re-hashes of the same arguments and misinformation.
There have been a ton of letters, calls to action, complaints and outrage about apple's actions.
Many of the conversations are HIGHLY repetitive.
I would strongly urge folks to review past discussions before re-hashing things (again) or focus on new elements.
And these headlines "Global Coalition"? I hope folks realize there is also a "global coalition" of governments that are working to do much more to get access to your information. Australia, China, the EU (yes, go on about GDPR but actual privacy - forget about it), UK etc.
There may also be a "global coalition" of users who like apple's products.
A better headline is EFF writes open letter with 90 other civil liberties groups to Tim Cook?
Edited to list prior topics on HN about this:
Apple's plan to “think different” about encryption opens a backdoor to your life
EFF: https://www.eff.org/deeplinks/2021/08/apples-plan-think-diff... 2260 points|bbatsell|16 days ago|824 comments
Apple Has Opened the Backdoor to Increased Surveillance and Censorship
EFF: https://www.eff.org/deeplinks/2021/08/if-you-build-it-they-w...
618 points|taxyovio|10 days ago|303 comments
Tell Apple: Don’t Scan Our Phones
EFF: https://act.eff.org/action/tell-apple-don-t-scan-our-phones
161 points|sunrise54|4 days ago|30 comments
Is EFF opposition really new news?
I've also noticed this weird forumulation more often. "Please stop xxxx" rather than an actual discussion of a topic. Ironic to try and suppress a conversation by claiming someone elses comments are suppression?
I was just mentioning - maybe it's worth reading the comments on the FOUR prior articles about this EXACT entity complaining about Apple (ignoring the other 30+ HN posts on this) for this specific issue.
This is not "suppressing the news".
I create this account explicitly because of this new feature. I've been posting constantly about it. If there's a new article on this I will try (and encourage others) to post such a summary as you did at the top of the article for anyone who hasn't been following.
Open to any questions you have about this from a "how do I catch up" perspective.
The human element here is “world governments and multinational corps beholden to nobody want to insert the first of possibly many back doors into your emotional life”
Sit down. You’re just looking for attention for your ability to notice a basic pattern.
1) we’ve seen over and over
2) adds little to the context at hand
You’re not wrong. You’re late to the game spotting patterns of reposting (it happens deal with it for yourself) and undermining the context (putting it on others to do better by your expectations.)
You have a body and mind that can be trained to find and reflect on more interesting patterns and ideas. Have at it. Don’t bemoan all of reality not conforming to your current state of cognitive awareness
A fair number are other "open letters" as well.
Helpful.
In this case we have been gettings tons of claims that what apple doing will see them charged with child porn felonies etc with almost no foundation.
We've also had lots of claims based on a failure to actually read about what apple is doing (ie, will scan all content not just that scheduled for upload to icloud etc).
I have seen a little misinformation relating to this subject - direct lies, fake news, fake links etc, but a negligible amount.
For example, I see a lot of people who are simply wrong about how the hash matching works. One way to be wrong is to think it’s a cryptographic hash. Another way to be wrong is to think it’s just a perceptual hash match.
The problem is that these are both not crazy. The actual solution is far more complex and non-obvious than most people would suspect.
I think this is a genuine problem with the system. It is hard for almost anyone to imagine how it could be trustworthy.
But agreed, the technical bits may not be obvious (though apple released I thought a pretty darn complete paper on how it all works).
Unless you understand the technical bits you have know way of knowing how rarely this is likely to happen in practice.
The best you can do would be to not review people’s private photos at all.
That AI assistant lives in the cloud in an Apple data center, not on your device.
"The recipient’s parents will be informed of the content without the sender consenting to their involvement."
Are parents really outraged by this? Are people sending porn upset about this?
My own view is as a parent if you send porn to my kids, I shouldn't NEED your consent to be alerted to this. I paid for the device, so it should do what I want, and if I turn this feature on than it should alert me.
That said - I don't find it very compelling. Parent paid for device. Parent is responsible for child. Parent should be allowed to control device (including setting a kids account instead of adult which trigger this etc). So I want to preserve MY right to both the device and to take care of my child. EFF seems to be focusing oddly on the rights of someone who DIDN'T pay for device.
Listen - I don't get the EFF argument any more than you do.
It's also the consensus position of a very large number of other digital rights groups and infosec experts. Do you believe they are also cynical and raising a false alarm?
The iMessage feature is a parental control feature where kids over 13 receiving on-device classified sensitive images have to click through to unblur them, and kids under 13 will do the same and also have their parents receive a notification that such an action was taken. The parent in any case does not receive a copy of the image. The EFF described it as such:
“Whatever Apple Calls It, It’s No Longer Secure Messaging”
and
“Apple is planning to build a backdoor into…its messaging system.”
The Center for Democracy and Technology who wrote this letter they have co-signed said:
“Plan to replace its industry-standard encrypted messaging system creates new risks in US and globally”
I, respectfully, don’t see much evidence that these are consensus views. Furthermore, I don’t see how you can characterize this feature as a back door without believing safe browsing checks on links received in iMessage is an encryption back door.
Many governments (e.g. Germany) wanted location instead of token based tracking with central storage of location pretty much up until the point where Apple and Google said that it won't happen .
This is based on my perception of Germany tech media coverage of the issue.
IMO this is off topic, but I think it absolutely has done that, and has demonstrated it. I'm surprised governments haven't screamed about it more loudly, but maybe they didn't want to do that in an example where they were clearly on the wrong side (pushing for privacy-violating approaches).