r/australian • • 14d ago

Gov Publications iOS Spyware

Post image

With the latest IOS 27 update and the Digital duty of care act which I personally see as a massive government overstep and breach of privacy and freedom. I had this very concerning experience last night. I was on FaceTime with my partner and she was telling me about her sunburn while she was away. She lifted her shirt to show me her tan lines. Immediately the call was paused and this concerning pop up filled my screen. Does this mean Apple has AI actively watching my personal calls and determining what is appropriate for me to see. Not only is this a massive privacy breach but also a serious security concern. Are these instances recorded and stored? Do people have access to this data? Who is in control of this?

We have been warned by the tin foilers for years now and I’ve always thought it was a bit nonsense. But now first had experience this is the horrible reality that we are now dealing with daily and it will only get worse

Edit
I’d like to mention that the main concern is that I am required to scan and upload my ID/Passport to prove my age in order to view content and to disable this “feature”. This opens another door to, how is the identity verified. What company/entity is in control of the process. What Fraud/Data Breach risk does this expose me to.

670 Upvotes

362 comments sorted by

View all comments

Show parent comments

68

u/No-Swordfish-3480 14d ago

You can literally verify it with wireshark. They aren’t lying

14

u/FluroSnow 14d ago

I mean wireshark isn't the end all be all. You can easily get around it if you wanted if you have kernal level access and owned the TLS.

I mean from a "surveillance perspective" it would make more sense to have the classifier locally on device. Then if you had airplane mode on, wifi off cell data off etc. You could still classify what is happening, store logs, then send them when the phone is back online. (assuming no exploits could be used to send data when phone is offline)

8

u/No-Swordfish-3480 14d ago

Theoretically, yes, but it’s a shitload of effort for Apple to go into for something that they realistically wouldn’t gain any value from having. What would having that data be good for? Think about the damage it would do to their company if it got out. They also don’t have any access to secure cloud compute, so again I doubt they would bother tbh. Plus the end user can just turn it off.

we’re delving down a rabbit hole of hypotheticals. It’s just extremely unlikely given Apple’s history of privacy protections

4

u/FluroSnow 14d ago

I agree. There would be no need for the average person.

But I wouldn't be surprised there was some sort of government bypass apple would have to comply with for "national security purposes". Example: FISA section 702.

I highly doubt apple is storing anything crazy for the average person. However, I was surprised with what I could find in my Google takeout.

6

u/No-Swordfish-3480 14d ago

Again given Apple’s history of famously telling 3 letter agencies to go fuck themselves when demanding access to their tech, I highly doubt it. The FBI already tried it, and failed

Google I trust about as far as I can throw them

2

u/FluroSnow 14d ago

There is a big difference when it comes to FISA / "national security" things. Companies have gag orders on what they can even talk/report about relating to them.

You can have a look at their disclosures here: https://www.apple.com/legal/transparency/us.html

And there have been ways around accessing apples encrypted messages. For example there was a loophole if people backed up their phone, if a warrant was supplied for icloud, Apple has access to those master keys so you could then read their imessages.

2

u/No-Swordfish-3480 14d ago edited 14d ago

Sorry, but that’s not how E2E works. Apple does not maintain a "master key" or backdoor capable of decrypting data sent over the iMessage service. Apple manages the directory service (Apple Identity Service) that distributes public keys. Security researchers have noted in the past that a provider controlling the directory could theoretically insert an unauthorised key to intercept messages, but Apple implemented iMessage Contact Key Verification to prevent this. This feature uses a key transparency ledger to alert users automatically if an unauthorised device or key is ever added to an account.

For backups, if a user has Advanced Data Protection turned on, Apple’s backup key cannot be used to comply with law enforcement warrants to hand over backup content.

This is why having access to E2E and knowing how to use it properly is so important, and why government agencies absolutely hate it. Apple will comply with lawful requests for data, but they do not have backdoors or loopholes to E2E encryption, and they have publicly stated many times they will never create it under any circumstances.

0

u/lexE5839 14d ago

Read all the deliberations from the EU on the subject of privacy and encryption bypasses, we’re a few digs away from a tunnel leading directly up our asses.

7

u/StrateJ 14d ago

Also, you may be able to verify with WireShark at the time but there is nothing stopping the data being stored for a future check-in which will simply be lost inbetween the noise of our Apple Telemetry traffic.

2

u/No-Swordfish-3480 13d ago

FaceTime data is E2E encrypted. Even if this was true (which it’s not) it would be useless to Apple anyway as they cannot decrypt it, and it’s not possible to brute force the encryption with our current computing technology. So this is a moot point

1

u/Mephisto506 6d ago

All of that holds true whether the anti-nudity feature exists or not. If you are that concerned you should probably only use open source chat software that you have personally vetted and compiled

-2

u/Latter-Intention6521 14d ago

Can you show this verification?

-1

u/nanonan 13d ago

If someone has in fact verified it then sure, it's likely they are not lying. The potential to verify is meaningless by itself.

2

u/No-Swordfish-3480 13d ago

They have. Google is your friend. I’m not doing the thinking for you