Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

71–80 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#71

So if I understand correctly, they want to scan all your photos, stored on your private phone, that you paid for, and they want to check if any of the hashes are the same as hashes of child porn? So... all your hashes will be uploaded to the cloud? How do you prevent them from scanning other stuff (memes, leaked documents, trump-fights-cnn-gif,... to profile the users)? Or will a huge hash database of child porn hash…

I agree, I would add that people have generated legal images that match the hashes.

So I want to ask what happens if you have a photo that is falsely identified as one in question and then an automated mechanism flags you and reports you to the FBI without you even knowing. Can they access your phone at that point to investigate? Would they come to your office and ask about it? Would that be enough evidence to request a wiretap or warrant? Would they alert your neighbors? How do you clear your name after that happens?

edits: yes, the hash database is downloaded to the phone and matches are checked on your phone.

Another point is that these photos used to generate the fingerprints are really legal black holes that the public is not allowed to inspect I assume. No one wants to be involved in looking at them, no one wants to be known as someone who looks at them. It could even be legally dangerous requesting to find out what has been put into the image database I assume.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#72

Also, if they send perceptual hashes to your device - it's possible images could be generated back from those hashes. These aren't cryptographic hashes, so I doubt they are very good one-way functions. Another thought - notice that they say "if too many appear". This may mean that the hashes don't store many bits of information (and would not be reversible) and that false positives are likely - ie, one image is not e…

It's also just plain absurd. Hundreds of pictures of my own children at the beach in their bathing suits? No problem. Hundreds of photos of other peoples' children in bathing suits? Big problem. Of course, the algorithm is powerless to tell the difference.

I believe it's built on hashing, so it'll only find images in the db they have with already known content. Your own photos won't get mixed up.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#73
It is lovely when your "own" device is working against you to catch if you are in possession of illegal numbers https://en.wikipedia.org/wiki/Illegal_number. And surely we can trust Apple that it will only be used for this kind of content instead of for example government leaks.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#74
post #53

It's quite easy to extrapolate this and in a few steps end up in a boring dystopia. First it's iPhone photos, then it's all iCloud files, that spills into Macs using iCloud, then it's client side reporting of local Mac files, and somewhere along all other Apple hardware I've filled my home with have received equivalent updates and are phoning home to verify that I don't have files or whatever data they can see or hea…

> What is the utopian perspective of this which counterbalances the risks for this to be a path worth taking?

Apple takes care of everything for you, and they have your best interests at heart. You will be safe, secure, private and seamlessly integrated with your beautiful devices, so you can more efficiently consume.

What's not to like about a world where child crime, terrorism, abuse, radical/harmful content and misinformation can be spotted in inception and at the source and effectively quarantined?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#76
how the fuck am i supposed to know if that image i downloaded from some random subreddit is of a girl who is 17.98 years old? how long until we just use a NN to identify images of children automatically? she looks pretty young so i guess you will get disemboweled alive in prison? what is stopping someone from planting an image on your phone or a physical picture somewhere on your property? im so tired of this fucking dogma around child porn. you can always identify the presence of dogma by the accompanying vacuum of logic that follows in its wake. a teenage girl can go to jail for distributing pictures that she took of herself. do i even need to say more?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#77

Earlier quoted context omitted.

It's also just plain absurd. Hundreds of pictures of my own children at the beach in their bathing suits? No problem. Hundreds of photos of other peoples' children in bathing suits? Big problem. Of course, the algorithm is powerless to tell the difference.

I believe it's built on hashing, so it'll only find images in the db they have with already known content. Your own photos won't get mixed up.

Ah, I guess unsurprisingly the twitter thread is light on details. I saw "perceptual hash" which I usually interpret to mean some kind of feature-based semantic hash that is not as sensitive to small edits. Even if it isn't currently used, the door is open for it to be implemented in the future.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#78

So if I understand correctly, they want to scan all your photos, stored on your private phone, that you paid for, and they want to check if any of the hashes are the same as hashes of child porn? So... all your hashes will be uploaded to the cloud? How do you prevent them from scanning other stuff (memes, leaked documents, trump-fights-cnn-gif,... to profile the users)? Or will a huge hash database of child porn hash…

your phone phones the phone manufacturer to phone the police to iphone you

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#79
post #48
post #31

Earlier quoted context omitted.

Not the right logic here. Check your idea more seriously. Mac os is just an example.

Your advice might be sound with the proper operating system choice, but the fact that you made such a glaring error in your initial comment makes it hard to take you seriously. It also brings into question whether you actually have a good understanding of privacy/security, or are just LARPing.

Error? Seriously? Did you make a wrong assumption that I care? About karma? I share my experience and my point of view. Nothing more, nothing less. And the most important point is not technical. The most important point is personal habits. To overcome smartphone addiction. We put our lives, thoughts and photos on closed technology and have false expectations that someone will care for our security or wellbeing.

On a serious note: If you want privacy/security as a semi-professional use: No mobile phone. https://www.qubes-os.org/ with https://www.qubes-os.org/doc/certified-hardware/

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#80
post #61

I'm a little bit confused here and hope maybe some of you can clear this up. My parents took lots of photos of me as a baby/small child. Say lying naked on a blanket or a naked 2yr old me in a kiddie pool in the summer in our backyard. Those are private photos and because it was the 1970s those were just taken with a normal non-digital camera. They were OBVIOUSLY never shared with others, especially outside immediate…

I believe there is a large database of known child pornography.

Unless someone has been distributing photos of your kids as child porn (which would probably be good to know) it's unlikely any of your photos will match the hashes of the photos in that database.

I'm not sure that's how it works, but that's what I've gathered from the other comments on this post.

Post reply on HN