Apple Just Gave Millions of Users a Reason to Quit Their iPhones
forbes.com
forbes.com
This is the problem I'm currently struggling with.
I could go to Android, which is relatively good but still run by Google (one of the most data-hungry corporations around). I kind of want the Z Flip 3, but not if it's running the kind of operating system that thinks of me as a data source and not a customer.
I could go to linux phones, execpt no, they have absolutely no concept of competence in any form, and frequently die with less than two hours of battery life under their belts.
I might decide to root/jailbreak, but that's the kind of resistance that invites malicious intruders to take advantage of the broken security models of our duopolist platform economics to sell my data to the highest bidder.
This isn't a rhetorical position: what do I do in this scenario? I want to leave Apple, but I can't find a good alternative and iMessage might be the dollar-store adhesive keeping me to the lesser of two evils.
As for alternatives, anything would do. Android doesn't do client side scanning of files since that's your chief concern. If you want more you can always root and play around.
> I want to leave Apple, but I can't find a good alternative and iMessage might be the dollar-store adhesive keeping me to the lesser of two evils.
Can't learn unless you try things.
I for one am happy with stock android and signal/telegram/whatsapp/sms.
I have freedom to root/modify as much as I want, I'm not forced to accept arbitrary company policies.
I very much doubt losing a handful of sales from angry nerds will change that.
Hearing normal folk asking "will I get in trouble for photos of my baby" kind of shows its not just a bunch of angry nerds. Angry nerds will just put gas on fire with simple "yes" answers.
This is a reasonable question, and absolutely something people should wonder about.
> simple "yes" answers.
This is an outright lie. The only honest answer is no.
Keep doing that and angry nerds will end up looking like tinfoil hat wearers and will lose any influence on future civil liberties.
Are you sure about that?, I'm not... And all the news so far reinforces that oppinion...
Getting falsely accused of something like this will ruin you even if in the end you win.
Here's apple fucking up human review and destroying a teens life https://www.theregister.com/2021/05/29/apple_sis_lawsuit/
Imagine that with CSAM... Perceptual filter there seems pretty poor in terms of collision resistance
> Are you sure about that?,
Yes.
> I'm not... And all the news so far reinforces that oppinion...
There are no news articles that explain how anyone will be falsely accused for having pictures of their own baby.
> Perceptual filter there seems pretty poor > in terms of collision resistance
I don’t think you know anything about how poor the filter is. What is the false positive rate on randomly selected photos?
The system is even resistant against intentionally created false positives.
Here is the relevant paragraph from Apple’s documentation:
“as an additional safeguard, the visual derivatives themselves are matched to the known CSAM database by a second, independent perceptual hash. This independent hash is chosen to reject the unlikely possi- bility that the match threshold was exceeded due to non-CSAM images that were ad- versarially perturbed to cause false NeuralHash matches against the on-device en- crypted CSAM database. If the CSAM finding is confirmed by this independent hash, the visual derivatives are provided to Apple human reviewers for final confirmation.”
https://www.apple.com/child-safety/pdf/Security_Threat_Model...
...
Umm... hash collisions that everyone keeps warning about is not enough?, all the discussions so far, I'll just go ahead and assume your comment here is in bad faith.
> The system is even resistant against intentionally created false positives.
Famous last words... Here's one of the top posts for reddit.com/r/apple
https://old.reddit.com/r/apple/comments/p930wu/i_wont_be_pos...
Here's a really high quality collision: https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX//issu...
Here's 2 totally different images off by a single BIT: https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX//issu...
Here's a dog and a kid colliding: https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX//issu...
It took a few days after extracting the model to show how flawed it is... Apple's only 'security' feature here was obscurity...
It's so broken the person doing analysis above stopped as Apple will only change the hash function to include his pictures as training data instead of fixing the whole system.
Are you still convinced?
Having a second 'perceptual' hash doesn't really add much value... I'm not an expert, here's a better view on why: https://news.ycombinator.com/item?id=28243031
Also funniest bit from that on how broken it is
"Finding a SHA1 collision took 22 years, and there are still no effective preimage attacks against it. Creating the NeuralHash collider took a single week."
> Umm... hash collisions that everyone keeps warning about is not enough?
No they are not enough. Hash collisions alone don’t cause the system to detect CSAM, even if they are generated intentionally.
If you don’t know this, then you simply don’t understand how the system works.
> all the discussions so far, I'll just go ahead and assume your comment here is in bad faith.
What part is in bad faith?
>> The system is even resistant against intentionally created false positives.
> Famous last words...
All of those links show the same thing. That it’s possible to manufacture hash collisions.
Nobody is debating that point.
Not one of those links explain how a photo of your baby would trigger the system.
> Are you still convinced?
Yes.
> Having a second 'perceptual' hash doesn't really add much value...
Does it not? Can you explain why it doesn’t?
> I'm not an expert,
I guess that means you can’t explain what you are saying because you don’t understand it.
> here's a better view on why: https://news.ycombinator.com/item?id=28243031
That comment is incoherent, and not an explanation of a vulnerability.
> Also funniest bit from that on how broken it is "Finding a SHA1 collision took 22 years, and there are still no effective preimage attacks against it. Creating the NeuralHash collider took a single week."
This quote demonstrates why we can reject that comment.
They appear to know the difference between a perceptual hash and a cryptographic hash from their earlier statements, and yet here they compare them as if they are expected to behave in a similar way.
Nobody who understands how perceptual hashing works would expect there not to be collisions or to think there was a meaningful comparison with SHA-1. The system doesn’t rely on the hash to behave like a cryptographic hash because it is not one.
Either that commenter is confused, or being deliberately misleading. Let’s assume they are just confused.
I have to assume you don’t know the difference between a cryptographic hash and a perceptual hash otherwise you wouldn’t have quoted this.
There is also a massive backlash going on against them. It hit a major tech news outlet here in Norway and was linked from the biggest national newspaper just a few days after it became known, so I guess there will be multiple waves of backlash.
These “vote with your dollar” comments all have the same energy.
Your comment may be interpreted as "sit down and shut up". Perhaps that's not your intent.
If you’re running stock android you’re running a closed OS that can be set up to spy on you just as easily as iOS. The existence of AOSP does not confer any “protection” if you run stock android, because you can’t know what other code google added onto it.
As much as they might want, Google cant scan local phone files with server side code...
Apple on the other hand just has to break a small pinky promise, code and infra is already there.
See the difference?
One is relying on a pinky promise, one is knowing they cant if you dont upload.
> If you’re running stock android you’re running a closed OS
Here's the source code: https://source.android.com/
What parts are closed source? How does this compare to Apple where everything is closed source?
> because you can’t know what other code google added onto it.
There are security researchers you know? the shitstorm that would appear on funny business will rival the one you see now.
In this day and age, if you don't trust your phone vendor with your data, you shouldn't be using it. They can do anything at any time and you wouldn't know. Even if there is no tracking code on your phone at this moment, they can put it on at any time.
Can't find the news article anymore but there was an incident where Google accidentally turned on airplane mode for every pixel at once via their remote control tools.
Apple does too, its called software updates.
Here's the deal:
- Google could develop software/infrastructure to scan on your phone client side.
- Apple has it deployed already.
This is just false.
What Apple has deployed doesn’t do anything nefarious, and is not easily repurposed.
Both companies would need to deploy a new mechanism via software update.
Seems like it's very easily repurposed since it's already activated (by mistake?) - https://news.ycombinator.com/item?id=28285567
Not all Pixel devices; mine doesn't even have Play services installed:
The same thing could happen with Linux on mobile. The Pinephone Beta is targeted at developers. However, it's only $200 so you could buy one if you want to support the community.
I personally like to believe that I value my privacy but de-googling sounds like a large inconvenience. The cynic in me also partially believes that it's pointless and another company will just be(gin) churning my data.
I was thinking of switching from my pixel to an iphone but this recent misstep by apple has dissolved the belief I've had that they are a privacy centric company.
And, of course, there, we've chosen to not care. So government social workers constructing databases of homeless with the express purpose to deny them emergency medical care is done at least in Belgium and the Netherlands, maybe elsewhere. And that's just one example.
If child services is involved, we now consider a mother's medical records fair game in divorce proceedings (and how long is it really going to take to drop that requirement too?). If you manage to download your spouse's facebook chats, or outlook, or whatsapp backup, you get to use them in divorce too, by the way (yes, I know about "no fault" divorces, but if they "depend" on someone else already you technically don't owe any alimony since someone else already took that over). Tax records are used to find people for parking tickets. Medical records are monitored live, so people can get arrested instead of cared for in hospitals if they're behind on their taxes. Child services, the front side (e.g. street workers, or the ones that are kind-of sports coaches in the street and do, say, basketball), by the way, are now forced to find "kids" for the police to arrest. NOT specific kids, mind you, when there's been a protest and the police needs kids to arrest, these people have it as their JOB to find kids for that (and yes, I'm sure they do try to find a few that were in the protest first).
To make matters worse, you can look at the organisational structure, which again, no-one seems to realise. The chief of police, who asks these social workers to find kids to arrest, is appointed directly by the major. The major, of course, is an elected official, who is absolutely not neutral. So it's a matter of time until a "Vlaams-Belang" major gets caught making sure it's "brown" kids that get arrested for every protest by replacing the chief of police with a raging lunatic racist. Or worse.
But we're worried that Apple might pass pictures that you're essentially carrying in your pocket to the police? I don't understand people ...
These days it actually makes sense to ask your doctor NOT to keep a medical file on you, which is a right you still have in Belgium. If you do get in trouble, you're FAR better off without one. You don't get to refuse to unlock your phone anyway in Belgium, so what's the point of having the pictures on your phone behind a lockscreen?
We might have to accept a solution that is technically inferior, yet overall superior. There is no guarantee that the quality of available consumer products is a monotonic function, so we shouldn't act like it is.
And perhaps it is time to experiment with a lifestyle that has less smartphone involvement.
It's the best time to start seriously investing development resources in this alternative.
This inspired me to write both companies about my buying experience. Off to do that!
Go back to a feature phone. That's always an option. After all, we could all live just fine with them until 2007.
While I don't agree with that assessment, the more important question is: would jailbreaking my device reliably prevent Apple from scanning my photos? I really doubt so. Moreover, it would be difficult to prove it either way.
A few months ago, I got a Pixel and installed CalyxOS on it. I'm self hosting Nextcloud for my files. It involves a bit of maintenance work to keep it going, but I take the adage "Program or be programmed" seriously.
If I ever got lazy, I'd switch to an /e/ phone.
> This is the problem I'm currently struggling with.
> I could go to Android, which is relatively good but still run by Google (one of the most data-hungry corporations around). I kind of want the Z Flip 3, but not if it's running the kind of operating system that thinks of me as a data source and not a customer.
> I could go to linux phones, execpt no, they have absolutely no concept of competence in any form, and frequently die with less than two hours of battery life under their belts.
> I might decide to root/jailbreak, but that's the kind of resistance that invites malicious intruders to take advantage of the broken security models of our duopolist platform economics to sell my data to the highest bidder.
> This isn't a rhetorical position: what do I do in this scenario? I want to leave Apple, but I can't find a good alternative and iMessage might be the dollar-store adhesive keeping me to the lesser of two evils.
Best option is lineage os, or cyanogenmod as it used to be called.
But why is iMessage so great (asking as a non-apple user)? Is it even e2e?
Great alternatives which are not locked into a specific OS are Signal, Threema, and Matrix.
Specifically, Matrix -- which is also a protocol -- looks quite interesting to me. Similar to email, you can choose your client software. You are also free to set up your own matrix server but you don't have to.
peer pressure... fear of exclusion from social circles.
It basically has a large market share and people using it dont want to use other messaging tools.
This does not exist outside US.
Yes
Linux phones seem like an okay option. Replacing my Mac with a System76 was an easier option.
Open source hardware and software seems like the only sustainable option long term. If it's not ready today, that's okay, it needs support to get there.
More discussion about Linux phones here: https://news.ycombinator.com/item?id=28164208
That's not the right way to think of this. The point is to send a strong message to Apple that this is not cool. Just as people didn't buy MacBooks without Esc keys, or bad butterfly mechanisms.
The MacBook itself got popular because the most technically knowledgeable people used them, got their families to use them, and was seen using them.
As Apple sees their numbers, they will put 1+1 together and decide that it's not worth it for them--they're a company out to make profits. It doesn't matter how much people complain if they keep buying. This makes a better Apple, and we can then again purchase the Apple products that live up to our standards. If we say, it sucks but it's better than the other one, this is a downward slope with no recovery.
If anything that is the thing that makes it hopeless, hearing again and again the voices shouting "it won't work", "we are weak, they are strong".
I do not say or even think these voices are paid shills, but I can hardly see how much better job one could do to demotivate anyone from doing resistance.
That said,let me add some facts:
- we won the crypto wars
- we won the nym wars
- Google and others have massively upgraded backbone security
- Matrix exist
- Signal exist
- Open source phones, PCs and even ebook tablets are shaping up really fast
- lots of people want to do something
So please people. Stop running the enemies errands.
If you have nothing good to say - don't say anything.
I can't describe how incredibly stupid this is. This is peak dystopia. An absurd example from history - "maybe we should rethink the Inquisition, no? They are kidnapping and torturing people based on no evidence" "Don't be a downer!".... "Let's brainstorm on this religion thing a bit with its pointless wars, flying airplanes into buildings and killing people?" "If you don't have anything good to say, don't."
Now - Matrix and Signal exists, but it takes two to tango. If you have no one to message there, because everybody uses iMessage/WhatsApp/Messenger, you are screwed.
Open source phones and PCs exist, but they are much more expensive for the same configuration and the open source software has its own problems. Just look at the whole Linux landscape. I just looked up System76 laptop with i7, 8 GB RAM and 240 GB SSD - it comes out at 1300 dollars. That's more than the brutto average wage in my country for the same configuration that costs about 700 dollars if you buy from mainstream brands.
I got disillusioned with open source when I tried connecting an iPhone to Linux. This is what it looks like in 2021 - https://itsfoss.com/iphone-antergos-linux/ . Full of esoteric terminal commands which operate a program written by some dude from who knows where with no guarantees what it really does, because I am not gonna bother learning about iPhone+Linux+USB delicacies enough to understand that code.
So in my opinion, it's easier to actually regulate the big corp overlords.
Did you misread something or am I misunderstanding you?
(If you meant to support me I misunderstood and the rest does probably not apply.)
Following you example I'm exhorting the people who say we should just give in and let the powers that be continue their inquisition or what not.
> Now - Matrix and Signal exists, but it takes two to tango. If you have no one to message there, because everybody uses iMessage/WhatsApp/Messenger, you are screwed.
It starts somewhere. I was part of getting first WhatsApp started and then Telegram started and I am also reachable via Signal. (Sadly I do not keep up to date on my Matrix accounts, bit they are there.)
The good thing is just by being there you make a difference:
When someone logs into Telegram or Signal and if they accept to match contacts with their address book they'll see you are there in addition to a few others and it feels less like a ghost town.
WhatsApp felt a bit odd last I tried it, but it used to work this way there too.
(PS: one kind of advocacy I recommend against is bulk messaging all contacts about a new messager that is end-to-end encrypted. My wife told about how weird that felt for her colleague when a friend of the colleague did that.
Instead just be there, and when as you see more people arrive create persistent groups and make it worthwhile.)
This only matters to the privacy conscious and those who enjoy platform wars.
I believe most people would be outraged if they bought a home and the homeowner's association had the right to go into their house any time of day and review all the photos they took claiming that it's a policy to protect the kids for child porn.
On the other hand it seems people are quite happy for the police to do that, at least into other peoples homes.
We let Google scan our emails for advertising. We let Amazon put listening devices in our homes. We let Facebook run amok.
The general public has almost no concern about privacy other than some limited notion a about the physical sanctity of our front doors.
I'm guilty of the home smart speaker as I have a few google/nest minis around my apartment. I don't plan on getting anymore because they're just basically used as glorified alarm clocks and speakers. In theory I would ideally replace them but the effort seems like a large inconvenience since the impact would be minimal considering I still use an Android phone.
Which device captures more data and shares it more?
Does another person have any right to challenge me? Most parents would feel comfortable infringing the civil liberties of another to protect children from some perceived harm that holding a camera might entail.
The point is that we have massive inconsistencies in our respect for privacy and our hysteria over the behaviour of others.
The majority will not change phones..
A list of banned content that lives on your phone sets a new and alarming precedent.
A list of banned content already exists on Facebook servers, and we have no way of auditing if that list only includes CP. Where's all the outrage over that?
The worry seems to boil down to; "they could CHANGE it in the future". If the concern is about the potential for a future system, then such concerns are infinite, since infinite new systems could always be proposed or deployed. I would rather conserve my outrage for that moment, rather than be the boy who cried wolf.
Though this certainly isn't an argument for apathy. I think the amount of push-back Apple is getting is probably healthy, even if it's hyperbolic.
This is simply not true. I have to assume you know that.
Here's how the conversation goes:
Android User: "With Android I could just turn off Google Cloud"
iOS User: "Apple also only scans as part of iCloud upload process also. So just disable iCloud Photos"
Android User: "But that's a slippery slope! They COULD scan all content of the phone with no effort!"
iOS User: "But they're not currently, and don't plan to. Doing it locally makes it some-what auditable. Also their system as designed would only work for data uploaded to iCloud."
Android User: "So you TRUST Apple to just not add that capability later!? What if a government forces them to?"
iOS User: "So you trust Google not to aswell? If any Government forces Apple to add this on-device, they would certainly require the same of Android"
Android User: "But Apple COULD add it more easily, because this is clearly a backdoor!"
iOS User: "I don't think that word means what you think it means"
I am switching to flip-phone and waiting for Xperia (SailfisOS). This thing that Apple created ruined all respect and motivated me (finally) to move to FOSS for the most part.
Since they already co-opted Chrome, I presume that could also do it with Android. That would give them immediate entry with working phones and a known OS.
Having a serious 3rd option would be nice.
said the website with almost 50 advertising cookies.
No one's gonna quit their iPhone because of this one.
I feel what might really happen is that the moderators may end up leaking someone’s private pictures. I think there was another thread earlier on HN which talked about how Apple’s repair team did something similar with someone’s photos, and there is also Apple’s iCloud disaster that happened with the actresses.
But I feel the Pandora’s box is already opened with regard to this. Even if Apple may not relent to another government’s desires to add extra things to be checked for, the various governments of the world may want to implement something like this on their own, if they haven’t already.
So where does that leave me? One of the pinephone things? Rooted Android with no google services?
I think that's understandable, but it's too broad. There are things like GrapheneOS and Calyx.
Their cloud offering is fully E2EE (to the best of everybodies knowledge), so doing it à la Google Drive or OneDrive is not possible. If you can not access the unencrypted content and have/will not backdoord the encryption mechanism, yet are still being forced to implement such a scheme by a legal entity, client side is pretty much your only option.
As a side-note, IMO the company does not have a strong enough moral compass to assign the required man-hours into a project of this magnitude just out of good will. I would assume they are being forced to do so.
Do you have a source for that? I was not able to find one.
This source, for example, suggests iCloud is not fully encrypted:
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
I stand corrected, the vast majority is not E2EE'd. Now there unfortunately is no information about the at-rest encryption "On server". Going by the iCloud encryption debate in china [1] and the alleged security modules used [2], they probably have the keys to "Photos" iCloud. Which is consistent with the Reuters claim that "backed-up [...] encrypted services remain available to Apple employees and authorities".
[1] https://www.nytimes.com/2021/05/17/technology/apple-china-ce...
[2] https://cpl.thalesgroup.com/encryption/hardware-security-mod...
Any OS/company could currently already deploy any change whenever they want in any random update.
So unless you have evidence that proves otherwise…
It’s kind of sad, it seems any kind of rational discussion about this topic is impossible.
Separately, if you are a child, and I presume you are not if you are reading this, photos sent in messages are scanned to catch if you are sending something sexually explicit. You can opt not to send, but if you do your parents are informed. So this is relevant if you are a child or if you have a child with an iPhone. Otherwise, it is not relevant to you.
Please help me understand what is so outrageous about these systems that would make you throw away your Apple products and move to something (what?) else.
Apple was objectively better than Google until they decided to start spying on my pics with an algo that has a terrible false positive rate, all the while after basically forcing you via war of attrition to comply with the constant ++ beyond annoying popups compelling you to use iCloud.
Literally just create an alternative. The other potential competitor who made Essential (Andy Rubin iirc?) literally just gave up after 3 quarters - I guess he would know how to pull out of a project after getting ingested by Google twice in a row.
The ecosystem is a joke. I hope the FTC destroys Apple over the App Store literally just to spite them for this dark move but I'm not optimistic.
The media doth protest too much methinks? As yet another journalist or elite gets busted for child porn.
Do you invite the police into your home to watch what you do to make sure you aren't breaking any laws?
Here is the relevant paragraph from Apple’s documentation:
“as an additional safeguard, the visual derivatives themselves are matched to the known CSAM database by a second, independent perceptual hash. This independent hash is chosen to reject the unlikely possi- bility that the match threshold was exceeded due to non-CSAM images that were ad- versarially perturbed to cause false NeuralHash matches against the on-device en- crypted CSAM database. If the CSAM finding is confirmed by this independent hash, the visual derivatives are provided to Apple human reviewers for final confirmation.”
https://www.apple.com/child-safety/pdf/Security_Threat_Model...
I had read through the technical whitepaper [1], which does not include this information. Thank you for sharing. Since the second hash only works on pictures that Apple can decrypt within this system ("for an account that exceeded the match threshold"), this merely saves the human reviewers at Apple time.
[1] https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
Apple’s CSAM mechanism can’t be ‘picked’ in the way that you claim. The two ‘locks’ are not separate. You can’t pick them one at a time.
> I had read through the technical whitepaper [1], which does not include this information. Thank you for sharing. Since the second hash only works on pictures that Apple can decrypt within this system ("for an account that exceeded the match threshold"), this merely saves the human reviewers at Apple time.
This is false. The second hash is independent and designed to prevent attacks based on adversarial spoofing of neuralhash.
Nobody, not even Apple, denies that someone can generate neuralhash collisions.
You can only assert that this is a vulnerability by making the false claim that a neuralhash collision alone will cause the system to flag an image.
> The second hash is independent
lol
The locks are not separate. You have to open both with the same ‘key’, I.e. the image.
From the documentation:
“the visual derivatives themselves are matched to the known CSAM database by a second, independent perceptual hash”
The “lock” in this case involves one key, and two hashes. If they were separate, you’d be able to ‘pick’ them one at a time with separate keys.
You can’t.
If such a system should be built they surely have gone out of their way to preemptively secure it.
I'm still very much of the opinion that we need people both in police, politics and in tech with balls - or whatever the equivalent is for women - to tell people that we cannot just interfere with everyones right just to hopefully maybe catch a few more baddies, but again:
If such a system needs to be built, this is an amazingly well thought out system.