Apple is about to announce a new technology for scanning individual users’ iPhones for banned content. While it will be billed as a tool for detecting child abuse imagery, its potential for misuse is vast based on details entering the public domain.
The neural network-based tool will scan individual users’ iDevices for child sexual abuse material (CSAM), respected cryptography professor Matthew Green told The Register today. Rather than using age-old hash-matching technology, however, Apple’s new tool – due to be announced today along with a technical whitepaper, we are told – will use machine learning techniques to identify images of abused children. “What I know is that it involves a new ‘neural matching function’ and this will be trained on [the US National Centre for Missing and Exploited Children]’s corpus of child sexual abuse images. So I was incorrect in saying that it’s a hash function. It’s much more powerful,” said Green, who tweeted at length about the new initiative overnight. “I don’t know exactly what the neural network does: can it find entirely new content that “looks” like sexual abuse material, or just recognize exact matches?” the US Johns Hopkins University academic told El Reg. Indiscriminately scanning end-user devices for CSAM is a new step in the ongoing global fight against this type of criminal content. In the UK the Internet Watch Foundation’s hash list of prohibited content is shared with ISPs who then block the material at source. Using machine learning to intrusively scan end user devices is new, however – and may shake public confidence in Apple’s privacy-focused marketing. Apple infamously refuses to talk to The Register, so asking it to comment on this is a fruitless exercise. Doubtless Cupertino will point to its scanning of (deliberately) unencrypted iCloud backups as precedent for this, saying it’s just an incremental step in the ongoing fight against the true evil of child sexual exploitation. Nonetheless, we’ve asked the fruity firm to comment and faithfully promise here to reproduce their response for the delight and delectation of El Reg’s readership. Governments in the West and authoritarion regions alike will be delighted by this initiative, Green feared. What’s to stop China (or some other censorious regime such as Russia or the UK) from feeding images of wanted fugitives into this technology and using that to physically locate them? Upcoming Android privacy changes include ability to blank advertising ID, and ‘safety section’ in Play store Apple scrambles to quash iOS app sideloading demands with ‘think of the children’ defense Apple, you’ve AirDrop’d the ball: Academics detail ways to leak contact info of nearby iThings for spear-phishing Brit cybercops issue tender to rip and replace their formerly flaw-ridden CyberAlarm tool “That is the horror scenario of this technology,” said Green. “Apple is the only service that still operates a major E2EE service in China, in iMessage. With this technology public, will China demand that Apple add scanning capability to iMessage? I don’t know. But I’m sure a lot more worried about it than I was two days ago.” According to Green, who said he had spoken to people who had been briefed about the scheme, the scanning tech will be implemented in a “two party” design. As he explained it: “Apple will hold the unencrypted database of photos (really the training data for the neural matching function) and your phone will hold the photos themselves. The two will communicate to scan the photos on your phone. Alerts will be sent to Apple if *multiple* photos in your library match, it can’t just be a single one.” The privacy-busting scanning tech will be deployed against America-based iThing users first, with the idea being to gradually expand it around the world as time passes. Green said it would be initially deployed against photos backed up in iCloud before expanding to full handset scanning. If this is the future of using Apple devices, it might not only be sex offenders who question Apple’s previously-stated commitment to protecting user privacy. ® Similar topics MORE Apple Privacy Corrections Send us news Other stories you might like USA enlists Big Tech to help it develop and execute cyber security plans Players in ‘Joint Cyber Defense Collaborative’ include Microsoft, AWS, and Google Simon Sharwood, APAC Editor Fri 6 Aug 2021 // 03:15 UTC The United States’ Cybersecurity and Infrastructure Security Agency (CISA) has announced the “standup” of a body called the “Joint Cyber Defense Collaborative” (JCDC) that it hopes will spark ideas for new and improved national responses against electronic threats. The aim of the effort is to get the private sector working alongside government agencies, so they can develop and implement better cyber security plans than are currently in operation. It’s also hoped the group will help “to unify defensive actions should an incident occur”. The organisation has therefore been given four jobs – namely: Continue reading US proposes tracking digital cash and taxing it to pay for, you know, roads and stuff Uncle Sam wants digital asset brokers to log customer info but didn’t clarify who counts as a broker or not Katyanna Quach Fri 6 Aug 2021 // 00:50 UTC US senators revised a section of the bipartisan infrastructure bill on Thursday to ensure cryptocurrency miners, hardware vendors, and software developers are exempt from collecting user data required to report taxes. Congress is stepping up its efforts to prevent crypto investors evade their taxes whenever they buy or sell Bitcoin and the like. The new legislation focuses on “brokers,” requiring everyone involved in handling digital financial transactions to record the payer and payee’s names, addresses, and other forms of data logged in the 1099 tax forms for the Internal Revenue Service. But the definition of who is a broker or not was too broad, according to experts. Now, the bill has been altered to make it clear that cryptocurrency miners, blockchain engineers, or vendors selling hardware to run hashing algorithms to mint digital coins are exempt from the new rules. They will not have to collect personal data of everyone using their services or chips. Continue reading US ‘dropped the ball’ on security by going it alone claims Huawei US CSO Where there’s a will, there’s Huawei Thomas Claburn in San Francisco Fri 6 Aug 2021 // 00:13 UTC Andy Purdy, CSO for Huawei USA, believes the US needs to be more active in the development of global security standards rather than being aloof. “The US has fundamentally dropped the ball when it comes to participation in global security standards,” Purdy told The Register. “We need really strong standards and the US should be a major player.” Instead of working with China and other technologically sophisticated nations, the US under the Trump administration took a confrontational stance. Huawei, a China-based global telecom conglomerate, suffered during this period and the mistrust laid bare during those years lingers. Continue reading Mozilla slams post-cookie ad tech proposals SWAN and UID2 – needs much more work Replacements for cookie-based tracking still pose privacy problems Thomas Claburn in San Francisco Thu 5 Aug 2021 // 20:19 UTC Mozilla on Wednesday published an assessment of two proposed ad tracking mechanisms intended to fill the void left by third-party cookies and found that both make web privacy worse. Third-party cookies – files deposited by code on websites to track people online and serve them targeted ads – are on their way out, eventually. Google and the rest of the online ad industry have been working feverishly to come up with replacement technology that allows the lucrative business of ad targeting to continue in a way that preserves user privacy, at least enough to satisfy regulators. Google and its ad tech allies are doing so through a set of proposals referred to as the Privacy Sandbox, which have suffered some setbacks. Continue reading Fastly CEO opens up on that June outage that crippled so many websites Admits some customers, including one in top ten yet to return its network Paul Kunert Thu 5 Aug 2021 // 18:36 UTC Remember that monster outage in June when Fastly managed to take down huge chunks of the internet? The CEO of the US-based cloud computing services provider has admitted some customers still do. The blackout happened on June 8 and the following day, in a post incident report, Fastly explained it was due to an undiscovered software bug triggered by a customer’s “valid configuration change,” which caused 85 per cent of its network to return an error message. CEO Joshua Bixby said yesterday the bug was detected within one minute of it tripping swathes of the network, and engineers “returned 95 per cent of our network to normal within 49 minutes,” he told analysts on a calendar Q2 earnings call. Continue reading Full Stream ahead: Microsoft will end ‘classic’ method of recording Teams meetings despite transcription concerns ‘All meeting recordings will be saved to OneDrive and SharePoint’ from 16 August Tim Anderson Thu 5 Aug 2021 // 16:16 UTC Microsoft’s technology for recording Teams meetings, Stream, will fully transition to a new version from 16 August, though some users have concerns over transcription features still under development. Stream is a service for uploading, viewing, and sharing videos. Among its most common uses is for recording Teams meetings. Stream had its own storage and user interface, but in September last year, at its Ignite event, the company introduced “a new journey for Microsoft Stream.” In essence, the change integrates Stream into Microsoft 365. “The web app will be part of office.com – like Word, PowerPoint and Excel web apps – and will enable users to discover, share, and manage videos like any Office document.” Microsoft started to call the old service Classic Stream, while referring to the new service as Stream. Continue reading A little Dataiku haiku for you: Hungry investors / throw data management firm / even more money $400m Series E values outfit at $4.6bn Lindsay Clark Thu 5 Aug 2021 // 15:27 UTC In line with investors’ obsession with all things to do with data, Dataiku, a provider of data management software, has secured a $400m investment that values the business at around $4.6bn. The Series E investment round was led by Tiger Global and also included ICONIQ Growth, CapitalG, FirstMark Capital, Battery Ventures, Dawn Capital, and Snowflake Ventures, set up by that other cloud data company which achieved a jaw-dropping IPO last year. It is just a year since Dataiku received $100m in a Series D round, which valued the firm at over $1bn. Why the company might now be worth four times that amount is up to investors to argue. Continue reading SK hynix to create US-HQ’d NewCo for Intel’s outgoing $9bn NAND biz Chipzilla exec and vineyard owner Robert Crooke to run operation … in between picking grapes Chris Mellor Thu 5 Aug 2021 // 14:34 UTC SK hynix intends to set up its soon-to-be acquired Intel NAND business as a standalone US-headquartered company. Robert Crooke, Intel GM for NAND products and vineyard owner, revealed this in a LinkedIn blog post, writing: “I am honoured to be the CEO of this company. Stay tuned for our new company name, I’ll share it here!” He writes about building “a new multibillion-dollar global company” that has the tech and the “operational scale to become a powerhouse in the NAND storage and memory industry”. And he has more than 150 open positions for people to join him in that endeavour, along with the existing base. Continue reading Got a cheap Cisco router in your home office? If it’s one of these, there’s an exposed RCE hole you need to plug Patches issued for two CVE-rated vulns Gareth Corfield Thu 5 Aug 2021 // 13:28 UTC Cisco has published patches for critical vulns affecting the web management interface for some of its Small Business Dual WAN Gigabit routers – including a 9.8-rated nasty. The two vulnerabilities affect the RV340, RV345, RV340W, and RV345P products, which are aimed at SMEs and home office setups. Attackers abusing them on unpatched devices are able to execute arbitrary code and also force reboots of affected routers, causing a denial-of-service condition. CVE-2021-1609, rated 9.8 on the CVSS v3.1 scale, allows attackers to “remotely execute arbitrary code” thanks to improper validation of HTTP requests, according to Cisco’s advisory. Continue reading Paperless office? 2.8 trillion pages printed in 2020, down by 14% or 450 billion sheets Big brands might take solace that in 2025, 4.4 million pages will still be printed every minute Paul Kunert Thu 5 Aug 2021 // 12:32 UTC Around 450 billion fewer pages were printed from home and office devices in 2020 as COVID-19 disrupted the world of work. The direction of travel has been obvious in recent times: people were printing less even before the pandemic took hold, but the decline was sharper last year as volumes plunged 14 per cent on 2019 levels to a total of 2.8 trillion pages, according to IDC. Continue reading 8 years ago another billionaire ploughed millions into space to harvest solar power and beam it back down to Earth Caltech received $100m for the project and is only just telling us now Laura Dobberstein Thu 5 Aug 2021 // 11:33 UTC Billionaire Donald Bren was behind a quiet $100m donation in 2013 that established Caltech’s Space-based Solar Power Project (SSPP) in an attempt to harness solar power from outer space, the California private research university revealed this week. The real estate magnate was inspired by a 2011 article in Popular Science (perhaps this one?). He also knew a thing or two concerning power distribution problems from his experience master planning cities like Irvine, California. Bren subsequently approached Caltech to discuss his ideas. Caltech said he has no stake in the tech and won’t make any money from it. The donation is being disclosed now, eight years later, as SSPP wants to highlight upcoming project milestones. Continue reading SITUATION PUBLISHING The Next Platform DevClass Blocks and Files Continuous Lifecycle London M-cubed The Register – Independent news and views for the tech community. Part of Situation Publishing SIGN UP TO OUR DAILY NEWSLETTER Subscribe Biting the hand that feeds IT © 1998–2021 Do not sell my personal information Cookies Privacy Ts&Cs
