Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

51–60 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#51
post #15

Earlier quoted context omitted.

I’m sure It’s in the TOS.

To start scanning my local photos on my local phone and report back?

Apple has been scanning your photos locally for quite some time now. They've been detecting faces, making collections, finding pets, etc. This is just another step in what they have already been doing.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#52
post #18
post #6

I understand the hesitation here, but fundamentally this is like trying to close pandoras box. If something is technically possible to do AND governments demand it be done, it will be done. If not by Apple, by someone else. Rather than complain about it, I am interested in what alternative solutions exist, or how concerns regarding privacy and abuse of this system could be mitigated.

No, we can complain about it, and we can win. Remember when the government tried to ban encryption in early 1990s? Remember SOPA that the internet killed?

And the Clipper chip!

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#53
It's quite easy to extrapolate this and in a few steps end up in a boring dystopia.

First it's iPhone photos, then it's all iCloud files, that spills into Macs using iCloud, then it's client side reporting of local Mac files, and somewhere along all other Apple hardware I've filled my home with have received equivalent updates and are phoning home to verify that I don't have files or whatever data they can see or hear that some unknown authority has decided should be reported.

What is the utopian perspective of this which counterbalances the risks for this to be a path worth taking?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#54

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

Since you worked on an actual contract catching these sorts of people you are perhaps in a unique position to answer the question: will this sort of blanket surveillance technique in general but also in iOS specifically - actually work to help catch them?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#55
post #17
post #6

I understand the hesitation here, but fundamentally this is like trying to close pandoras box. If something is technically possible to do AND governments demand it be done, it will be done. If not by Apple, by someone else. Rather than complain about it, I am interested in what alternative solutions exist, or how concerns regarding privacy and abuse of this system could be mitigated.

I don't understand this argument at all. Look at the Clipper Chip debacle in the 90s. It was technically feasible and the government very much wanted to do it. And the reason they didn't is push back from the public, saying this is a bad idea that can easily be misused, even if it does make some law enforcement things easier. I don't see how this is any different. Sacrificing the privacy of the many to help catch a r…

> Eliminating the 4th amendment or mandating clear walls sure would make the cops' job easier. But no one thinks that's even a remotely good idea.

Yet.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#56
post #39
post #32

Earlier quoted context omitted.

> Stop. Using. Apple. But is there a realistically better alternative? Pinephone with a personally audited Linux distro? A jailbroken Android device with a non-stock firmware that you built yourself? A homebuilt RaspberryPi based device? A paper notepad and a film camera and an out of print street map?

Not really, and I'm not going to sway anyone deeply into the ecosystem. My hope is that those of you that share my viewpoint will call your legislators and demand regulations or a break up. There are forces of good within the DOJ that are putting together an antitrust case against Apple, and the more of us that lend our voices, the louder and more compelling the argument. The DOJ is really the last lever we have, and…

Other companies seem even less interested in fighting government surveillance so I don't see how weakening Apple will help anything.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#57

Also, if they send perceptual hashes to your device - it's possible images could be generated back from those hashes. These aren't cryptographic hashes, so I doubt they are very good one-way functions. Another thought - notice that they say "if too many appear". This may mean that the hashes don't store many bits of information (and would not be reversible) and that false positives are likely - ie, one image is not e…

It's also just plain absurd. Hundreds of pictures of my own children at the beach in their bathing suits? No problem. Hundreds of photos of other peoples' children in bathing suits? Big problem. Of course, the algorithm is powerless to tell the difference.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#58

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

The NCMEC database that Apple is likely using to match hashes, contains countless non-CSAM pictures that are entirely legal not only in the U.S. but globally.

This should be reason enough for you to not support the idea.

From day 1, it's matching legal images and phoning home about them. Increasing the scope of scanning is barely a slippery slope, they're already beyond the stated scope of the database.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#59

So if I understand correctly, they want to scan all your photos, stored on your private phone, that you paid for, and they want to check if any of the hashes are the same as hashes of child porn? So... all your hashes will be uploaded to the cloud? How do you prevent them from scanning other stuff (memes, leaked documents, trump-fights-cnn-gif,... to profile the users)? Or will a huge hash database of child porn hash…

That's the stated purpose, but keep in mind that these databases (NCMEC's in particular, which is used by FB and very likely Apple) contain legal images that are NOT child porn.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#60
post #58

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

The NCMEC database that Apple is likely using to match hashes, contains countless non-CSAM pictures that are entirely legal not only in the U.S. but globally. This should be reason enough for you to not support the idea. From day 1, it's matching legal images and phoning home about them. Increasing the scope of scanning is barely a slippery slope, they're already beyond the stated scope of the database.

Could you say more about these legal photos? That's a pretty big difference from what I thought was contained in the DB.
Post reply on HN