Pretty confident Apple is going to ditch client-side CSAM scanning in favor of server-side CSAM scanning. This will be an improvement, but will leave them in a tight corner with E2EE.
Still a massive improvement: the deployment of client-side scanning for cloud backups would have been an asterisk on all device privacy forever, particularly as cloud backups become increasingly non-optional.
There would have been enormous pressure for companies to deploy similar technologies, and to expand the content they scan for. Some would have handled this pressure gracefully, but many would not have.
It is amazing how close we came to a world where law enforcement runs powerful scanning algorithms on the private data stored on your personal device, and how many smart, decent people were on board with that.
Anyway, what Apple needs to do know is decide whether E2EE for iCloud is even possible. The (coming) commitment to server-side scanning of private photo backups is going to make this awkward for them.
Just one more thought: say what you want about Apple, but they are very competent product people. They sometimes launch duds, but they don’t (usually) try to launch products that people actively dislike.
The fact that they launched this product — and tried to defend it even over the objections of their own employees — should tell you how much government pressure they are under right now re: encryption.
And they didn’t just try to launch it. It would be in iOS 15 right now if there hadn’t been massive blowback.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Matthew Green

Matthew Green Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @matthew_d_green

11 Dec
Watching this log4j bug metastasize, I’m seeing people ask why industry doesn’t fund open source. I don’t have a great answer, but I have some thoughts following the experience with Heartbleed in ‘14. 1/
When Heartbleed dropped, it was very similar to log4j: an underfunded OSS project (OpenSSL) that nobody thought about, but was *everywhere*. It took everyone by surprise, and even woke industry up. The result was a surge of funding. 2/
Industry (not the government, who still though “infrastructure” meant dams and bridges) suddenly realized they were using this stuff everywhere. So the Linux Foundation created the Core Infrastructure Initiative (now the OpenSSF). coreinfrastructure.org 3/
Read 11 tweets
11 Dec
When is “turn off the cloud” no longer a viable option.
I think it’s optimistic that 40% of people think our devices will continue to be useful in the future without a connection to a cloud service.
Ok. I did not phrase this question well so let me try again. At what point do you think our mobile devices will become sufficiently tied to cloud services that “turn off cloud” is no longer an option — either explicitly, or *effectively*.
Read 6 tweets
6 Dec
The HSM universe is a nightmare. It’s genuinely terrible.
It’s like someone at the NSA in 1991 decided what the use-cases and APIs should look like, and nobody ever cared to bring any of it into the 21st century. It’s such garbage.
This is the “use cases” section for Amazon CloudHSM and reading the manual it’s like: yup, that’s pretty much all you could ever do with this garbage API.
Read 5 tweets
4 Dec
I love Bell Labs (in the 1960s) for their combination of technical prescience and terribly-stupid prediction quality. ethw.org/w/images/c/c7/… Image
This is how they thought electronic payments would work. In fairness, it’s not that bad compared to the status quo 1965-2015. Image
It’s kind of amazing when you feed this through Kubrick. ImageImageImageImage
Read 4 tweets
2 Dec
I think it’s funny how little computer security people know about the Dapp ecosystem. It’s like they’re living in the hotel from The Shining and they have no idea what’s going down in Room 237.
Crypto/security people: we can’t *possibly* run a secure messaging app over the web because everything’s too insecure!

Dapp folks: let’s secure $100m using Javascript served by Cloudflare.
In case you don’t know what I’m on about. coindesk.com/business/2021/…
Read 6 tweets
1 Dec
Oof. I would say that NSS gives me the willies but all these crypto libraries give me the willies. googleprojectzero.blogspot.com/2021/12/this-s…
Oh god oh god. Image
Where am I going to store my post-quantum RSA keys in this data structure? Has anyone even thought about this?
Read 4 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(