Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

211–220 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#211

Sucks since we pay for icloud backups and get the lesser service

This isn't even tied to iCloud, they can scan your device even if you don't use iCloud.

iOS downloads CSAM scanning code from Apple and runs it locally—hence, client-side tool.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#212
post #207

Earlier quoted context omitted.

So we know they are using perceptual hashing and what kind?

"Hashes using a new and proprietary neural hashing algorithm Apple has developed, and gotten NCMEC to agree to use."

That sounds like we know it’s perceptual but not what kind, and therefore we don’t know the collision characteristics.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#213

Could we get a more useful link here, people? CSAM? According to Google that's Confocal Scanning Acoustic Microscopy. Or something. And what with the tweeters? I think my laptop just gave me thighburns from the CPU bloat that clicking on that link caused. Eight seconds to render the page? Why do folks still use this twerker website?

If your machine takes 8 seconds to render a Twitter page, perhaps you need a new machine.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#214

What I find disturbing is that almost all commenters here took that rumour for a fact. There's nothing to substantiate it, there's no evidence of scan actually happening, and there's no historical precedence of similar thing done by Apple. And yet, people working in tech with supposedly developed critical thinking took the bait. Why? Is it simply because it fits their world view?

The world has changed. May not be completely accurate yet, but fits 2021 like a glove:

https://sneak.berlin/20210202/macos-11.2-network-privacy/

https://sneak.berlin/20201112/your-computer-isnt-yours/

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#215
Well, this is very problematic for a privacy concerned company. Under no circumstances do I want Apple to scan my private files/photos, aspecially so if it means that an alarm can allow someone to determine if it is a positive or a false positive.

Also, this functionality isn't something they should be able to implement without telling their end users.

It is also problematic because it will just make the cyber criminals more technical aware of what counter measures they must take to protect their illegal data.

The consequence is very bad for the regular consumer: the cyber criminal will be able to hide, and the government has the possibility to scan your files. End consumer lose, again.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#216
post #30

Earlier quoted context omitted.

Or regulation saying that this is illegal, because it invades users privacy too much.

Which'd be fine if we had one global government with world wide jurisdiction. Or technology choices from companies which couldn't be pressured by governments outside your personal regulation jurisdiction. I wouldn't hold your breath waiting for those regulations to become law in, say, Chine or Turkey or Saudi Arabia. I'd bet even Israel won't pass them, surely NSO have enough political lobbying swing (and probably al…

>Which'd be fine if we had one global government with world wide jurisdiction.

I wholeheartedly disagree. A world wide goverment would be catastrophic for whistleblowing. Atleast as a whistleblower you can live somewhat safely in a country opposing your own. With a one world government you would have nowhere to run.

And I wouldn't expect them to protect citizen's interests any better than current governments do. Contrary, I think this lack of balance in the world would embolden them further.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#217
post #54

Earlier quoted context omitted.

Since you worked on an actual contract catching these sorts of people you are perhaps in a unique position to answer the question: will this sort of blanket surveillance technique in general but also in iOS specifically - actually work to help catch them?

I have direct knowledge of examples of where individuals were arrested and convicted of sharing CP online and they were identified because a previous employer I worked for used PhotoDNA analysis on all user uploaded images. So yeah, this type of thing can catch bad people. I’m still not convinced Apple doing this is a good thing, especially on private media content without a warrant, even though the technology can he…

now im afraid, i have two young children < 5 years old. i have occasionally took pictures of them naked with some bumps on the skin or mosquito bite and sent them to my wife over whatsapp to look at and decide do we need to send them to doctor, do i have to fear now that i will be marked as distributing CP.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#218

Sorry to say that, but stuff like this has to happen at some point when people don't own their devices. Currently, nearly no one owns their phone and at least EU legislation is underway to ensure that it stays this way. The next step will be to reduce popular services (public administration, banking, medicine) to access through such controlled devices. Then we are locked in. And you know what? Most people deserve to…

>EU legislation is underway to ensure that it stays this way.

which one?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#219
post #208

Earlier quoted context omitted.

How hard would it be to create a valid image that matches some 128bit hahs

If it’s a cryptographic hash - very hard.

But the probability is still not zero, and the number of iPhones in the world is large. A hash collision is possible, however unlikely.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#220
post #6

I understand the hesitation here, but fundamentally this is like trying to close pandoras box. If something is technically possible to do AND governments demand it be done, it will be done. If not by Apple, by someone else. Rather than complain about it, I am interested in what alternative solutions exist, or how concerns regarding privacy and abuse of this system could be mitigated.

>what alternative solutions exist,

stop trading freedom for security.

Post reply on HN