#jeffreischiller

dredmorbius@joindiaspora.com

Bugs in Our Pockets

... Client-side scanning, as the agencies’ new wet dream is called, has a range of possible missions. While Apple and the FBI talked about finding still images of sex abuse, the EU was talking last year about videos and text too, and of targeting terrorism once the argument had been won on child protection. It can also use a number of possible technologies; in addition to the perceptual hash functions in the Apple proposal, there’s talk of machine-learning models. And, as a leaked EU internal report made clear, the preferred outcome for governments may be a mix of client-side and server-side scanning.

In our report, we provide a detailed analysis of scanning capabilities at both the client and the server, the trade-offs between false positives and false negatives, and the side effects – such as the ways in which adding scanning systems to citizens’ devices will open them up to new types of attack. ...

...

If device vendors are compelled to install remote surveillance, the demands will start to roll in. Who could possibly be so cold-hearted as to argue against the system being extended to search for missing children? Then President Xi will want to know who has photos of the Dalai Lama, or of men standing in front of tanks; and copyright lawyers will get court orders blocking whatever they claim infringes their clients’ rights. Our phones, which have grown into extensions of our intimate private space, will be ours no more; they will be private no more; and we will all be less secure. ...

Authors are a who's who of cryptographic and security brilliance: Hal Abelson, Ross Anderson, Steven M. Bellovin, Josh Benaloh, Matt Blaze, Jon Callas, Whitfield Diffie, Susan Landau, Peter G. Neumann, Ronald L. Rivest, Jeffrey I. Schiller, Bruce Schneier, Vanessa Teague, and Carmela Troncoso.

Full paper (PDF): https://arxiv.org/abs/2110.07450

https://www.lightbluetouchpaper.org/2021/10/15/bugs-in-our-pockets/

#privacy #infosec #infotech #cryptography #surveillance #smartphones #MobileComputing #HalAbelson #RossAnderson #SevenMBellovin #JoshBenaloh #MattBlaze #JonCallas #WhitfieldDiffie #SusanLandau #PeterGNeumann #RonaldRivest #JeffreISchiller #BruceSchneier #VanessaTeague #CarmelaTroncoso