Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

81–90 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#81
Well this really debunks my common phrase “Apple is a Privacy company, not a Security company”

I can’t say I’m surprised they are implementing this (if true), under the radar. I can’t imagine a correct way or platform for Apple to share this rollout publicly. I’m sure nothing will come of this, press will ignore the story, and we all go back to our iPhones

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#83
post #34

Earlier quoted context omitted.

Actually we are the weak point. The phone stuff is just unregulated capitalism.

Sure, but that still leaves the question of why mobile banking and not mobile games w/ pc banking.

I don't agree with some (most?) of the parent posters comments in this threa.

But I feel there's a valid argument to be made that if your adversary is the sort of people who'd be feeding Apple image hashes to find people, you're probably be wise to carry a regular phone on which you do boring norm-core sorts of things.

A phone you use to take pictures of cats and pay your rent using banking apps and call your parents - while not using it to communicate with your dealer or your anarchist collective or your friendly investigative journalist.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#85

So if I understand correctly, they want to scan all your photos, stored on your private phone, that you paid for, and they want to check if any of the hashes are the same as hashes of child porn? So... all your hashes will be uploaded to the cloud? How do you prevent them from scanning other stuff (memes, leaked documents, trump-fights-cnn-gif,... to profile the users)? Or will a huge hash database of child porn hash…

No need to upload every hash or download a huge database with very hash. If I were building this system, I'd make a bloom-filter of hashes. This means O(1) space and time checking of a hash match, with a risk of false positives. I'd only send hashes to check against a full database.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#86

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

> Unshared data shouldn't be subject to search. Once it's shared, I can make several cases for an automated scan, but a cloud backup of personal media should be kept private. Our control of our own privacy matters. Not for the slippery slope argument or for the false positive argument, but for its own sake. We shouldn't be assuming the worst of people without cause or warrant.

I have a much simpler rule: Your device should never willingly* betray you.

*With a warrant, police can attempt to plant a bug, but your device should not help them do so.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#87
post #17

Earlier quoted context omitted.

I don't understand this argument at all. Look at the Clipper Chip debacle in the 90s. It was technically feasible and the government very much wanted to do it. And the reason they didn't is push back from the public, saying this is a bad idea that can easily be misused, even if it does make some law enforcement things easier. I don't see how this is any different. Sacrificing the privacy of the many to help catch a r…

> Eliminating the 4th amendment or mandating clear walls sure would make the cops' job easier. But no one thinks that's even a remotely good idea. Yet.

Frighteningly, there really are people who think that's a good idea. The "If you've done nothing wrong you have nothing to hide" crowd. And the cops.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#88
post #58

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

The NCMEC database that Apple is likely using to match hashes, contains countless non-CSAM pictures that are entirely legal not only in the U.S. but globally. This should be reason enough for you to not support the idea. From day 1, it's matching legal images and phoning home about them. Increasing the scope of scanning is barely a slippery slope, they're already beyond the stated scope of the database.

To be fair the Twitter thread says (emphasis mine) "These tools will allow Apple to scan your iPhone photos for photos that match a specific perceptual hash, and report them to Apple servers if too many appear."

I don't know what the cutoff is, but it doesn't sound like they believe that possession of a single photo in the database is inherently illegal. That doesn't mean this is overall a good idea. It simply weakens your specific argument about occasional false positives.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#89
post #53

It's quite easy to extrapolate this and in a few steps end up in a boring dystopia. First it's iPhone photos, then it's all iCloud files, that spills into Macs using iCloud, then it's client side reporting of local Mac files, and somewhere along all other Apple hardware I've filled my home with have received equivalent updates and are phoning home to verify that I don't have files or whatever data they can see or hea…

I mean, Apple isn't too far from the Mac thing you mention. Since Catalina running an executable on macOS phones home and checks for valid signatures on their servers.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#90
post #5

I wonder when I gave Apple permission to do this?

I’m sure It’s in the TOS.

Maybe the part in every TOS that says the company can change the TOS at any time without warning and you should regularly check the TOS page and stop using the service if you saw a change and didn't like it?
Post reply on HN