Earlier quoted context omitted.
The NCMEC database that Apple is likely using to match hashes, contains countless non-CSAM pictures that are entirely legal not only in the U.S. but globally. This should be reason enough for you to not support the idea. From day 1, it's matching legal images and phoning home about them. Increasing the scope of scanning is barely a slippery slope, they're already beyond the stated scope of the database.
To be fair the Twitter thread says (emphasis mine) "These tools will allow Apple to scan your iPhone photos for photos that match a specific perceptual hash, and report them to Apple servers if too many appear. " I don't know what the cutoff is, but it doesn't sound like they believe that possession of a single photo in the database is inherently illegal. That doesn't mean this is overall a good idea. It simply weake…
Apple enabling client-side CSAM scanning on iPhone tomorrow
121–130 of 757 posts
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#122Earlier quoted context omitted.
That document you downloaded that is critical of the party will land you and your family in jail. Enjoy your iPhone. Seriously, folks, we shouldn't celebrate Apple's death grip over their platform. It's dangerous for all of us. The more of you that use it, the more it creates a sort of "anti-herd immunity" towards totalitarian control. Apple talks "privacy", but jfc they're nothing of the sort. Apple gives zero shits…
> Stop. Using. Apple. But is there a realistically better alternative? Pinephone with a personally audited Linux distro? A jailbroken Android device with a non-stock firmware that you built yourself? A homebuilt RaspberryPi based device? A paper notepad and a film camera and an out of print street map?
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#123If you like this, I have some other innovations that you may be interested in: * A car that automatically pulls over when a police cruiser attempts to intercept you * A front door that unlocks when a cop knocks * A camera that uses AI to detect and prevent the photography of minors, police, and critical infrastructure * A Smart TV that counts the number of people in your living room to ensure you aren't performing an…
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#124Earlier quoted context omitted.
I agree, I would add that people have generated legal images that match the hashes. So I want to ask what happens if you have a photo that is falsely identified as one in question and then an automated mechanism flags you and reports you to the FBI without you even knowing. Can they access your phone at that point to investigate? Would they come to your office and ask about it? Would that be enough evidence to reques…
>I would add that people have generated legal images that match the hashes. That seems like a realistic attack. Since the hash list is public (has to be for client side scanning), you could likely set your computer to grind out a matching image hash but of some meme which you then distribute.
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#125So if I understand correctly, they want to scan all your photos, stored on your private phone, that you paid for, and they want to check if any of the hashes are the same as hashes of child porn? So... all your hashes will be uploaded to the cloud? How do you prevent them from scanning other stuff (memes, leaked documents, trump-fights-cnn-gif,... to profile the users)? Or will a huge hash database of child porn hash…
No, your hashes are not uploaded to the cloud, yes, hashes are downloaded to your phone. Yes, it will be interesting to see if it gets spammed with false positives, although it seems as though that can easily be identified silently to the user.
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#126Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#127Earlier quoted context omitted.
False positives, what if someone can poison the set of hashes, engineered collisions, etc. And what happens when you come up positive - does the local sheriff just get a warrant and SWAT you at that point? Is the detection of a hash prosecutable? Is it enough to get your teeth kicked in, or get you informally labeled a pedo by your local police? On the flip side, since it's running on the client, could actual pedophi…
False positives are clearly astronomically unlikely. Not a real issue. Engineered collisions seem unlikely too. Not impossible. Unless there is a straight up cryptographic defect in the hash algorithm, it seems hard to see how engineered collisions could be made to happen at any scale.
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#128Earlier quoted context omitted.
False positives, what if someone can poison the set of hashes, engineered collisions, etc. And what happens when you come up positive - does the local sheriff just get a warrant and SWAT you at that point? Is the detection of a hash prosecutable? Is it enough to get your teeth kicked in, or get you informally labeled a pedo by your local police? On the flip side, since it's running on the client, could actual pedophi…
False positives are clearly astronomically unlikely. Not a real issue. Engineered collisions seem unlikely too. Not impossible. Unless there is a straight up cryptographic defect in the hash algorithm, it seems hard to see how engineered collisions could be made to happen at any scale.
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#129Earlier quoted context omitted.
What about pictures of you own children naked ?
This isn't CSAM or illegal, nor would it ever end up in a database. Speaking generally, content has to be sexualized or have a sexual purpose to be illegal. Simple nudity does not count inherently.
That’s not entirely true. If a police officer finds you in possession of a quantity of CP, especially of multiple different children, you’ll at least be brought in for questioning if not arrested/tried/convicted, whether the images were sexualized or not.
> nor would it ever end up in a database
That’s a bold blanket statement coming from someone who correctly argued that NCMEC’s database has issues (as in I know your previous claim is true because I’ve seen false positives for completely innocent images, both legally and morally). That said, with the amount of photos accidentally shared online (or hacked), to say that GP’s scenario can not ever end up in a database seems a bit off the mark. It’s very unlikely as sibling commenter said, but still possible.
Re: Apple enabling client-side CSAM scanning on iPhone tomorrow
#130CSAM? According to Google that's Confocal Scanning Acoustic Microscopy. Or something.
And what with the tweeters? I think my laptop just gave me thighburns from the CPU bloat that clicking on that link caused. Eight seconds to render the page? Why do folks still use this twerker website?