Skip to main content
QUICK REVIEW

[论文解读] Bugs in our Pockets: The Risks of Client-Side Scanning

Hal Abelson, Ross Anderson|arXiv (Cornell University)|Oct 14, 2021
Privacy-Preserving Technologies in Data参考文献 29被引用 13
一句话总结

本文批判了客户端扫描(CSS)技术,这是一种在加密前扫描用户设备中非法内容的提议技术,认为其通过允许大规模监控严重损害了隐私与安全。尽管声称仅针对非法内容(如儿童性虐待材料CSAM),CSS仍带来系统性风险,使敌对势力得以滥用,并削弱人们对数字系统的信任。

ABSTRACT

Our increasing reliance on digital technology for personal, economic, and government affairs has made it essential to secure the communications and devices of private citizens, businesses, and governments. This has led to pervasive use of cryptography across society. Despite its evident advantages, law enforcement and national security agencies have argued that the spread of cryptography has hindered access to evidence and intelligence. Some in industry and government now advocate a new technology to access targeted data: client-side scanning (CSS). Instead of weakening encryption or providing law enforcement with backdoor keys to decrypt communications, CSS would enable on-device analysis of data in the clear. If targeted information were detected, its existence and, potentially, its source, would be revealed to the agencies; otherwise, little or no information would leave the client device. Its proponents claim that CSS is a solution to the encryption versus public safety debate: it offers privacy -- in the sense of unimpeded end-to-end encryption -- and the ability to successfully investigate serious crime. In this report, we argue that CSS neither guarantees efficacious crime prevention nor prevents surveillance. Indeed, the effect is the opposite. CSS by its nature creates serious security and privacy risks for all society while the assistance it can provide for law enforcement is at best problematic. There are multiple ways in which client-side scanning can fail, can be evaded, and can be abused.

研究动机与目标

  • 分析客户端扫描(CSS)作为执法机构访问加密通信的解决方案所涉及的安全与隐私风险。
  • 挑战CSS在隐私与公共安全之间提供平衡妥协的主张。
  • 证明CSS本质上可实现大规模监控,并且容易被国家与非国家行为体滥用。
  • 论证CSS通过在个人设备上引入持久后门,损害了所有用户的安全,而不仅限于嫌疑人。
  • 主张应对CSS作为政策工具进行严格公开审查并予以拒绝,因其具有不可逆且高度侵入性的特性。

提出的方法

  • 分析CSS的技术架构,包括设备端扫描、加密验证及策略执行机制。
  • 评估CSS的威胁模型,重点关注国家行为体、犯罪组织及亲密伴侣等敌对行为者如何利用客户端设备中的漏洞。
  • 考察现实案例,包括苹果公司2021年的提案以及GCHQ的AI驱动监控愿景,以说明扫描范围的扩展。
  • 评估安全实现的可行性,强调尽管研究广泛,仍缺乏经证实、可验证且可信的设计。
  • 将CSS与以往的监控模式(如密钥托管和线路监听)进行比较,强调其在法律与技术层面更低的滥用门槛。
  • 运用政策与经济分析表明,CSS降低了监控成本,使大规模数据收集变得可扩展且系统化。
Figure 1: Scanning operation flows. Left : Server-side scanning. Right : Client-side scanning (the main changes are in orange)
Figure 1: Scanning operation flows. Left : Server-side scanning. Right : Client-side scanning (the main changes are in orange)

实验结果

研究问题

  • RQ1客户端扫描能否在不助长大规模监控的前提下,实现安全且透明的部署?
  • RQ2在用户设备上部署扫描逻辑会引入哪些技术与系统性漏洞?
  • RQ3与传统监控方法相比,CSS在隐私影响与法律监督方面有何差异?
  • RQ4在个人设备上扫描所有用户数据的系统部署会产生哪些长期影响?
  • RQ5CSS的范围能否真正限制在非法内容上,还是存在不可避免的扩张路径?

主要发现

  • 客户端扫描从根本上将监控从基于逮捕令的定向访问转变为对所有用户设备的大规模、自动化扫描,从而在整体上破坏隐私。
  • 即使仅设计用于扫描儿童性虐待材料(CSAM),CSS仍为将监控扩展至其他内容类别树立了先例。
  • 该技术扩大了个人设备的攻击面,使其易受政府及亲密伴侣等敌对行为者的利用。
  • 移动操作系统的不透明性使得无法验证扫描策略是否真正仅限于无争议的非法内容。
  • CSS并非隐私保护方案;它允许远程、大规模访问私人数据,实质上等同于工业级监控。
  • 传统线路监听的法律与经济成本被取代为一种使监控廉价且无处不在的系统,从而消除了对滥用行为的关键制衡。
Figure 2: From server-side to client side: New compromise paths and advantage points for adversaries ( \textcolor blue $\longrightarrow$ : compromise paths in server-side scanning; \textcolor red $\longrightarrow$ : compromise paths in CSS; \textcolor red $\ext@arrow 0359$ $\relbar$ → ${\textcolor{w
Figure 2: From server-side to client side: New compromise paths and advantage points for adversaries ( \textcolor blue $\longrightarrow$ : compromise paths in server-side scanning; \textcolor red $\longrightarrow$ : compromise paths in CSS; \textcolor red $\ext@arrow 0359$ $\relbar$ → ${\textcolor{w

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。