Apples new program for scanning images sent on iMessage steps back from the companys prior support for the privacy and security of encrypted messages. The program, initially limited to the United States, narrows the understanding of end-to-end encryption to allow for client-side scanning. While Apple aims at the scourge of child exploitation and abuse, the company has created an infrastructure that is all too easy to redirect to greater surveillance and censorship. The program will undermine Apples defense that it cant comply with the broader demands.
For years, countries around the world have asked for access to and control over encrypted messages, asking technology companies to nerd harder when faced with the pushback that access to messages in the clear was incompatible with strong encryption. The Apple child safety message scanning program is currently being rolled out only in the United States.
The United States has not been shy about seeking access to encrypted communications, pressuring the companies to make it easier to obtain data with warrants and to voluntarily turn over data. However, the U.S. faces serious constitutional issues if it wanted to pass a law that required warrantless screening and reporting of content. Even if conducted by a private party, a search ordered by the government is subject to the Fourth Amendments protections. Any warrant issued for suspicionless mass surveillance would be an unconstitutional general warrant. As the Ninth Circuit Court of Appeals has explained, "Search warrants . . . are fundamentally offensive to the underlying principles of the Fourth Amendment when they are so bountiful and expansive in their language that they constitute a virtual, all-encompassing dragnet[.]" With this new program, Apple has failed to hold a strong policy line against U.S. laws undermining encryption, but there remains a constitutional backstop to some of the worst excesses. But U.S constitutional protection may not necessarily be replicated in every country.
Apple is a global company, with phones and computers in use all over the world, and many governments pressure that comes along with that. Apple has promised it will refuse government demands to build and deploy government-mandated changes that degrade the privacy of users. It is good that Apple says it will not, but this is not nearly as strong a protection as saying it cannot, which could not honestly be said about any system of this type. Moreover, if it implements this change, Apple will need to not just fight for privacy, but win in legislatures and courts around the world. To keep its promise, Apple will have to resist the pressure to expand the iMessage scanning program to new countries, to scan for new types of content and to report outside parent-child relationships.
It is no surprise that authoritarian countries demand companies provide access and control to encrypted messages, often the last best hope for dissidents to organize and communicate. For example, Citizen Labs research shows thatright nowChinas unencrypted WeChat service already surveils images and files shared by users, and uses them to train censorship algorithms. When a message is sent from one WeChat user to another, it passes through a server managed by Tencent (WeChats parent company) that detects if the message includes blacklisted keywords before a message is sent to the recipient. As the Stanford Internet Observatorys Riana Pfefferkorn explains, this type of technology is a roadmap showing how a client-side scanning system originally built only for CSAM [Child Sexual Abuse Material] could and would be suborned for censorship and political persecution. As Apple has found, China, with the worlds biggest market, can be hard to refuse. Other countries are not shy about applying extreme pressure on companies, including arresting local employees of the tech companies.
But many times potent pressure to access encrypted data also comes from democratic countries that strive to uphold the rule of law, at least at first. If companies fail to hold the line in such countries, the changes made to undermine encryption can easily be replicated by countries with weaker democratic institutions and poor human rights recordsoften using similar legal language, but with different ideas about public order and state security, as well as what constitutes impermissible content, from obscenity to indecency to political speech. This is very dangerous. These countries, with poor human rights records, will nevertheless contend that they are no different. They are sovereign nations, and will see their public-order needs as equally urgent. They will contend that if Apple is providing access to any nation-state under that states local laws, Apple must also provide access to other countries, at least, under the same terms.
For example, the Five Eyesan alliance of the intelligence services of Canada, New Zealand, Australia, the United Kingdom, and the United Stateswarned in 2018 that they will pursue technological, enforcement, legislative or other measures to achieve lawful access solutions if the companies didnt voluntarily provide access to encrypted messages. More recently, the Five Eyes have pivoted from terrorism to the prevention of CSAM as the justification, but the demand for unencrypted access remains the same, and the Five Eyes are unlikely to be satisfied without changes to assist terrorism and criminal investigations too.
The United Kingdoms Investigatory Powers Act, following through on the Five Eyes threat, allows their Secretary of State to issue technical capacity notices, which oblige telecommunications operators to make the technical ability of providing assistance in giving effect to an interception warrant, equipment interference warrant, or a warrant or authorisation for obtaining communications data. As the UK Parliament considered the IPA, we warned that a company could be compelled to distribute an update in order to facilitate the execution of an equipment interference warrant, and ordered to refrain from notifying their customers.
Under the IPA, the Secretary of State must consider the technical feasibility of complying with the notice. But the infrastructure needed to roll out Apples proposed changes makes it harder to say that additional surveillance is not technically feasible. With Apples new program, we worry that the UK might try to compel an update that would expand the current functionality of the iMessage scanning program, with different algorithmic targets and wider reporting. As the iMessage communication safety feature is entirely Apples own invention, Apple can all too easily change its own criteria for what will be flagged for reporting. Apple may receive an order to adopt its hash matching program for iPhoto into the message pre-screening. Likewise, the criteria for which accounts will apply this scanning, and where positive hits get reported, are wholly within Apples control.
Australia followed suit with its Assistance and Access Act, which likewise allows for requirements to provide technical assistance and capabilities, with the disturbing potential to undermine encryption. While the Act contains some safeguards, a coalition of civil society organizations, tech companies, and trade associations, including EFF andwait for itApple, explained that they were insufficient.
Indeed, in Apples own submission to the Australian government, Apple warned the government may seek to compel providers to install or test software or equipment, facilitate access to customer equipment, turn over source code, remove forms of electronic protection, modify characteristics of a service, or substitute a service, among other things. If only Apple would remember that these very techniques could also be used in an attempt to mandate or change the scope of Apples scanning program.
While Canada has yet to adopt an explicit requirement for plain text access, the Canadian government is actively pursuing filtering obligations for various online platforms, which raise the spectre of a more aggressive set of obligations targeting private messaging applications.
For the Five Eyes, the ask is mostly for surveillance capabilities, but India and Indonesia are already down the slippery slope to content censorship. The Indian governments new Intermediary Guidelines and Digital Media Ethics Code (2021 Rules), in effect earlier this year, directly imposes dangerous requirements for platforms to pre-screen content. Rule 4(4) compels content filtering, requiring that providers endeavor to deploy technology-based measures, including automated tools or other mechanisms, to proactively identify information that has been forbidden under the Rules.
Indias defense of the 2021 rules, written in response to the criticism from three UN Special Rapporteurs, was to highlight the very real dangers to children, and skips over the much broader mandate of the scanning and censorship rules. The 2021 Rules impose proactive and automatic enforcement of its content takedown provisions, requiring the proactive blocking of material previously held to be forbidden under Indian law. These laws broadly include those protecting the sovereignty and integrity of India; security of the State; friendly relations with foreign States; public order; decency or morality. This is no hypothetical slippery slopeits not hard to see how this language could be dangerous to freedom of expression and political dissent. Indeed, Indias track record on its Unlawful Activities Prevention Act, which has reportedly been used to arrest academics, writers and poets for leading rallies and posting political messages on social media, highlight this danger.
It would be no surprise if India claimed that Apples scanning program was a great start towards compliance, with a few more tweaks needed to address the 2021 Rules wider mandate. Apple has promised to protest any expansion, and could argue in court, as WhatsApp and others have, that the 2021 Rules should be struck down, or that Apple does not fit the definition of a social media intermediary regulated under these 2021 Rules. But the Indian rules illustrate both the governmental desire and the legal backing for pre-screening encrypted content, and Apples changes makes it all the easier to slip into this dystopia.
This is, unfortunately, an ever-growing trend. Indonesia, too, has adopted Ministerial Regulation MR5 to require service providers (including instant messaging providers) to ensure that their system does not contain any prohibited [information]; and [...] does not facilitate the dissemination of prohibited [information]. MR5 defines prohibited information as anything that violates any provision of Indonesias laws and regulations, or creates community anxiety or disturbance in public order. MR5 also imposes disproportionate sanctions, including a general blocking of systems for those who fail to ensure there is no prohibited content and information in their systems. Indonesia may also see the iMessage scanning functionality as a tool for compliance with Regulation MR5, and pressure Apple to adopt a broader and more invasive version in their country.
The pressure to expand Apples program to more countries and more types of content will only continue. In fall of 2020, in the European Union, a series of leaked documents from the European Commission foreshadowed an anti-encryption law to the European Parliament, perhaps this year. Fortunately, there is a backstop in the EU. Under the e-commerce directive, EU Member States are not allowed to impose a general obligation to monitor the information that users transmit or store, as stated in the Article 15 of the e-Commerce Directive (2000/31/EC). Indeed, the Court of Justice of the European Union (CJEU) has stated explicitly that intermediaries may not be obliged to monitor their services in a general manner in order to detect and prevent illegal activity of their users. Such an obligation will be incompatible with fairness and proportionality. Despite this, in a leaked internal document published by Politico, the European Commission committed itself to an action plan for mandatory detection of CSAM by relevant online service providers (expected in December 2021) that pointed to client-side scanning as the solution, which can potentially apply to secure private messaging apps, and seizing upon the notion that it preserves the protection of end-to-end encryption.
For governmental policymakers who have been urging companies to nerd harder, wordsmithing harder is just as good. The end result of access to unencrypted communication is the goal, and if that can be achieved in a way that arguably leaves a more narrowly defined end-to-end encryption in place, all the better for them.
All it would take to widen the narrow backdoor that Apple is building is an expansion of the machine learning parameters to look for additional types of content, the adoption of the iPhoto hash matching to iMessage, or a tweak of the configuration flags to scan, not just childrens, but anyones accounts. Apple has a fully built system just waiting for external pressure to make the necessary changes. China and doubtless other countries already have hashes and content classifiers to identify messages impermissible under their laws, even if they are protected by international human rights law. The abuse cases are easy to imagine: governments that outlaw homosexuality might require a classifier to be trained to restrict apparent LGBTQ+ content, or an authoritarian regime might demand a classifier able to spot popular satirical images or protest flyers.
Now that Apple has built it, they will come. With good intentions, Apple has paved the road to mandated security weakness around the world, enabling and reinforcing the arguments that, should the intentions be good enough, scanning through your personal life and private communications is acceptable. We urge Apple to reconsider and return to the mantra Apple so memorably emblazoned on a billboard at 2019s CES conference in Las Vegas: What happens on your iPhone, stays on your iPhone.
Read the original here:
If You Build It, They Will Come: Apple Has Opened the Backdoor to Increased Surveillance and Censorship Around the World - EFF
- Protections for e-data clear Senate committee [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Quinn: Supreme Court should clarify Fourth Amendment rights in the digital age [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Fourth amendment | Wex Legal Dictionary / Encyclopedia ... [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Fourth Amendment to the United States Constitution ... [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- The Fourth Amendment is destroyed by the Roberts led Supreme Court. - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Court may let cops search smartphones [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Supreme Court to hear case on police searches of cellphones [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Fourth Amendment in the digital age: Supreme Court to decide if police can search cellphones without a warrant [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- What Scalia knows about illegal searches [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- Should police be allowed to search your smartphone - Video [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- Fourth Amendment to the United States Constitution - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Rand Paul Third Party Records Should Get Fourth Amendment Protection O'Reilly Factor 6 11 2013 - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- The Shaky Legal Foundation of NSA Surveillance on Americans [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- Pennsylvania Supreme Court rules police don't need warrants to search cars [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Local police: Updated vehicle-search law still requires probable cause [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Liberal Supreme Court Justice Comes To The Defense Of Scalia [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Gerald Celente - Trends In The News - America's Spiritual Death - (1/20/14) - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Smartphones and the Fourth Amendment - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Fourth Amendment Searches And Seizures - Video [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- Fourth Amendment Defined & Explained - Law [Last Updated On: May 6th, 2014] [Originally Added On: May 6th, 2014]
- Enforcement Techniques For Violations Of The Fourth Amendment - Video [Last Updated On: May 6th, 2014] [Originally Added On: May 6th, 2014]
- I-Team: Do police seek search warrant friendly judges? [Last Updated On: May 7th, 2014] [Originally Added On: May 7th, 2014]
- Is Big Brother Listening? Applying the Fourth Amendment in an Electronic Age - Video [Last Updated On: May 9th, 2014] [Originally Added On: May 9th, 2014]
- It Costs Less to Care [Last Updated On: May 10th, 2014] [Originally Added On: May 10th, 2014]
- The Fourth Amendment - Video [Last Updated On: May 10th, 2014] [Originally Added On: May 10th, 2014]
- Magistrate waxes poetic while rejecting Gmail search request [Last Updated On: May 11th, 2014] [Originally Added On: May 11th, 2014]
- License reader lawsuit can be heard, appeals court rules [Last Updated On: May 15th, 2014] [Originally Added On: May 15th, 2014]
- Seize the Rojo - Video [Last Updated On: May 16th, 2014] [Originally Added On: May 16th, 2014]
- NSA Spying Has a Disproportionate Effect on Immigrants [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Motorists sue Aurora, police in 2012 traffic stop after bank robbery [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Judge Says NSA Phone Surveillance Likely Unconstitutional - Video [Last Updated On: May 21st, 2014] [Originally Added On: May 21st, 2014]
- New York Attorney Heath D. Harte Releases a Statement on Fourth Amendment Rights [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- Bangor Area School District teachers vote no to random drug [Last Updated On: May 24th, 2014] [Originally Added On: May 24th, 2014]
- The Fourth Amendment Rights - Video [Last Updated On: May 24th, 2014] [Originally Added On: May 24th, 2014]
- I Don't Care About The Contitution, Take Your Fourth Amendment And Shove It The Hills Hotel - Video [Last Updated On: May 27th, 2014] [Originally Added On: May 27th, 2014]
- Lonestar1776 at Illegal Checkpoint 80 Miles Inside Border - Standing UP & Pushing Back! pt 2/2 - Video [Last Updated On: September 1st, 2014] [Originally Added On: September 1st, 2014]
- Suit charges Daytona Beach's rental inspection program violates civil rights [Last Updated On: September 2nd, 2014] [Originally Added On: September 2nd, 2014]
- 4th Amendment - Laws.com [Last Updated On: September 6th, 2014] [Originally Added On: September 6th, 2014]
- YOU CAN ARREST ME NOW (cops refuse) - Video [Last Updated On: September 6th, 2014] [Originally Added On: September 6th, 2014]
- The Feds Explain How They Seized The Silk Road Servers [Last Updated On: September 8th, 2014] [Originally Added On: September 8th, 2014]
- Defence asks judge in NYC to toss out bulk of evidence in Silk Road case as illegally obtained [Last Updated On: September 9th, 2014] [Originally Added On: September 9th, 2014]
- Volokh Conspiracy: Does obtaining leaked data from a misconfigured website violate the CFAA? [Last Updated On: September 9th, 2014] [Originally Added On: September 9th, 2014]
- Family of a mentally ill woman files lawsuit against San Mateo Co. after deadly shooting [Last Updated On: September 10th, 2014] [Originally Added On: September 10th, 2014]
- Minnesota Supreme Court upholds airport drug case decision [Last Updated On: September 12th, 2014] [Originally Added On: September 12th, 2014]
- Law Talk - Obamacare Rollout; Fourth Amendment, NSA Spying Stop & Frisk DUI Check Points lta041 - Video [Last Updated On: September 12th, 2014] [Originally Added On: September 12th, 2014]
- Volokh Conspiracy: The posse comitatus case and changing views of the exclusionary rule [Last Updated On: September 15th, 2014] [Originally Added On: September 15th, 2014]
- Guest: Why the privacy of a public employees cellphone matters [Last Updated On: September 16th, 2014] [Originally Added On: September 16th, 2014]
- Volokh Conspiracy: Apples dangerous game [Last Updated On: September 19th, 2014] [Originally Added On: September 19th, 2014]
- Judge expounds on privacy rights [Last Updated On: September 20th, 2014] [Originally Added On: September 20th, 2014]
- Great privacy essay: Fourth Amendment Doctrine in the Era of Total Surveillance [Last Updated On: September 20th, 2014] [Originally Added On: September 20th, 2014]
- The Fourth Amendment By Maison Erdman - Video [Last Updated On: September 20th, 2014] [Originally Added On: September 20th, 2014]
- Volokh Conspiracy: When administrative inspections of businesses turn into massive armed police raids [Last Updated On: September 22nd, 2014] [Originally Added On: September 22nd, 2014]
- The chilling loophole that lets police stop, question and search you for no good reason [Last Updated On: September 23rd, 2014] [Originally Added On: September 23rd, 2014]
- E.O. 12333: End-Running the Fourth Amendment | The Dissenter [Last Updated On: September 25th, 2014] [Originally Added On: September 25th, 2014]
- Fourth Amendment: The History Behind "Unreasonable ... [Last Updated On: September 25th, 2014] [Originally Added On: September 25th, 2014]
- Pet Owners Look to Muzzle Police Who Shoot Dogs [Last Updated On: September 27th, 2014] [Originally Added On: September 27th, 2014]
- Volokh Conspiracy: A few thoughts on Heien v. North Carolina [Last Updated On: September 29th, 2014] [Originally Added On: September 29th, 2014]
- Volokh Conspiracy: Third Circuit on the mosaic theory and Smith v. Maryland [Last Updated On: October 1st, 2014] [Originally Added On: October 1st, 2014]
- Volokh Conspiracy: Third Circuit gives narrow reading to exclusionary rule [Last Updated On: October 2nd, 2014] [Originally Added On: October 2nd, 2014]
- Volokh Conspiracy: Supreme Court takes case on duration of traffic stops [Last Updated On: October 2nd, 2014] [Originally Added On: October 2nd, 2014]
- Search & Seizure, Racial Bias: The American Law Journal on the Philadelphia CNN-News Affiliate WFMZ Monday, October 6 ... [Last Updated On: October 4th, 2014] [Originally Added On: October 4th, 2014]
- Argument preview: How many brake lights need to be working on your car? [Last Updated On: October 4th, 2014] [Originally Added On: October 4th, 2014]
- The 'Barney Fife Loophole' to the Fourth Amendment [Last Updated On: October 4th, 2014] [Originally Added On: October 4th, 2014]
- Search & Seizure: A New Fourth Amendment for a New Generation? - Promo - Video [Last Updated On: October 4th, 2014] [Originally Added On: October 4th, 2014]
- Lubbock Liberty Workshop With Arnold Loewy On The Fourth Amendment - Video [Last Updated On: October 5th, 2014] [Originally Added On: October 5th, 2014]
- Ap Government Fourth Amendment Project - Video [Last Updated On: October 5th, 2014] [Originally Added On: October 5th, 2014]
- Volokh Conspiracy: Oral argument in Heien v. North Carolina [Last Updated On: October 6th, 2014] [Originally Added On: October 6th, 2014]
- Feds Hacked Silk Road Without a Warrant? Perfectly Legal, Prosecutors Argue [Last Updated On: October 7th, 2014] [Originally Added On: October 7th, 2014]
- Supreme Court Starts Term with Fourth Amendment Case [Last Updated On: October 7th, 2014] [Originally Added On: October 7th, 2014]
- Feds Say That Even If FBI Hacked The Silk Road, Ulbricht's Rights Weren't Violated [Last Updated On: October 8th, 2014] [Originally Added On: October 8th, 2014]
- Argument analysis: A simple answer to a deceptively simple Fourth Amendment question? [Last Updated On: October 8th, 2014] [Originally Added On: October 8th, 2014]
- Mass Collection of U.S. Phone Records Violates the Fourth Amendment - Video [Last Updated On: October 8th, 2014] [Originally Added On: October 8th, 2014]
- Leggett sides with civil liberties supporters [Last Updated On: October 10th, 2014] [Originally Added On: October 10th, 2014]
- Search & Seizure / Car Stops: A 'New' Fourth Amendment for a New Generation? - Video [Last Updated On: October 10th, 2014] [Originally Added On: October 10th, 2014]
- Broken Lights And The Fourth Amendment National Constitution Center - Video [Last Updated On: October 10th, 2014] [Originally Added On: October 10th, 2014]
- The Fourth Amendment- The Maininator Period 4 - Video [Last Updated On: October 10th, 2014] [Originally Added On: October 10th, 2014]
- Judge nukes Ulbricht's complaint about WARRANTLESS FBI Silk Road server raid [Last Updated On: October 11th, 2014] [Originally Added On: October 11th, 2014]
- Montgomery County will not hold immigrants without probable cause -- Gazette.Net [Last Updated On: October 13th, 2014] [Originally Added On: October 13th, 2014]
- Debate: Does Mass Phone Data Collection Violate The 4th Amendment? [Last Updated On: October 15th, 2014] [Originally Added On: October 15th, 2014]
- Does the mass collection of phone records violate the Fourth Amendment? [Last Updated On: October 18th, 2014] [Originally Added On: October 18th, 2014]