Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

91–100 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#91
I really have to wonder why Apple chose to do this.

As far as I know, this kind of scanning is not legally mandated. So, either they think that this will truly make the world a better place and are doing it out of some sense of moral responsibility, or they've been pressured into it as part of a sweetheart deal on E2E ("we won't push for crypto backdoors if you'll just scan your users' phones for us"). Either way it doesn't thrill me as a customer that my device is wasting CPU cycles and battery life under the presumption that I might possess data my current jurisdiction deems illegal.

For all the acclaim privacy-forward measures like GDPR get here, I'm surprised there isn't more outright repudiation of this frankly Orwellian situation.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#93
post #54

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

Since you worked on an actual contract catching these sorts of people you are perhaps in a unique position to answer the question: will this sort of blanket surveillance technique in general but also in iOS specifically - actually work to help catch them?

[deleted]

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#94
post #61

I'm a little bit confused here and hope maybe some of you can clear this up. My parents took lots of photos of me as a baby/small child. Say lying naked on a blanket or a naked 2yr old me in a kiddie pool in the summer in our backyard. Those are private photos and because it was the 1970s those were just taken with a normal non-digital camera. They were OBVIOUSLY never shared with others, especially outside immediate…

The idea is it detects specific images humans classified. Not any unclothed child.

So far. Many websites already use NN trained to detect any nudity. It is only a matter of time before it lands on all consumer computing devices. The noose will keep on tightening because people keep debating instead of protesting.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#95
post #70
post #60

Earlier quoted context omitted.

Could you say more about these legal photos? That's a pretty big difference from what I thought was contained in the DB.

If there are pictures recovered alongside CSAM but are not CSAM themselves they can be included in the database. The thing I can publicly say is that the database is not strictly for illegal or even borderline imagery. NCMEC try to keep the contents, processes and access to the database under wraps for obvious reasons.

So are we talking about images which are not actually CSAM but a reasonable person would consider to be CSAM if they encountered them? Or is it just the README.txt for whatever popular bittorrent client?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#96
post #58

Earlier quoted context omitted.

The NCMEC database that Apple is likely using to match hashes, contains countless non-CSAM pictures that are entirely legal not only in the U.S. but globally. This should be reason enough for you to not support the idea. From day 1, it's matching legal images and phoning home about them. Increasing the scope of scanning is barely a slippery slope, they're already beyond the stated scope of the database.

Can you give more information about this? What kind of legal images might it match?

What about pictures of you own children naked ?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#98
post #95
post #70

Earlier quoted context omitted.

If there are pictures recovered alongside CSAM but are not CSAM themselves they can be included in the database. The thing I can publicly say is that the database is not strictly for illegal or even borderline imagery. NCMEC try to keep the contents, processes and access to the database under wraps for obvious reasons.

So are we talking about images which are not actually CSAM but a reasonable person would consider to be CSAM if they encountered them? Or is it just the README.txt for whatever popular bittorrent client?

A reasonable person would call it a normal picture if they encountered it in isolation. Like I said, content which is not even borderline are included.

By both a legal and moralistic standard they're not CSAM. Not even nearly.

Of course, this is a minority of the content in the database. But even 1 such image is gross neglect of stated purpose in my book.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#99
post #46
post #22

Earlier quoted context omitted.

What are the implications?

False positives, what if someone can poison the set of hashes, engineered collisions, etc. And what happens when you come up positive - does the local sheriff just get a warrant and SWAT you at that point? Is the detection of a hash prosecutable? Is it enough to get your teeth kicked in, or get you informally labeled a pedo by your local police? On the flip side, since it's running on the client, could actual pedophi…

False positives are clearly astronomically unlikely. Not a real issue.

Engineered collisions seem unlikely too. Not impossible. Unless there is a straight up cryptographic defect in the hash algorithm, it seems hard to see how engineered collisions could be made to happen at any scale.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#100
If you like this, I have some other innovations that you may be interested in:

* A car that automatically pulls over when a police cruiser attempts to intercept you

* A front door that unlocks when a cop knocks

* A camera that uses AI to detect and prevent the photography of minors, police, and critical infrastructure

* A Smart TV that counts the number of people in your living room to ensure you aren't performing an unauthorized public broadcast of copyrighted content

Surely, at least one of those sounds ridiculous to you. As well-intentioned as this scanning may be, it violates a core principle of privacy and human autonomy. Your own device should not betray you. As technologists, just because we can do something doesn't mean we should.

Post reply on HN