Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

231–240 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#231

What I find disturbing is that almost all commenters here took that rumour for a fact. There's nothing to substantiate it, there's no evidence of scan actually happening, and there's no historical precedence of similar thing done by Apple. And yet, people working in tech with supposedly developed critical thinking took the bait. Why? Is it simply because it fits their world view?

I found another source (https://www.macobserver.com/analysis/apple-scans-uploaded-co...) saying apple was already running these scans on iCloud using homomorphic encryption… in 2019. It doesn’t really make sense for them to run it on device. Apple has the keys to unlock iCloud backups on their server and a sizable portion of users have those enabled, so why bother to run these on device?

I’m not sure if it’s a rumor or not but there was a thread on HN the other day about Facebook exploring homomorphic encryption for running ads on WhatsApp and I wonder if wires got crossed?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#232

Ive already been itching to de-cloud, and de-tech my life. If were already getting to this stage of surveillance I guess thats just another sign I should be getting on top of it. Today its csam. Tomorrow "misleading information". etc.

Im looking to do the same - this pandemic has made me feel quite claustrophobic about the encroachment of tech, and work into my personal life. Im planning on getting a dumb-ish nokia phone and leaving my smartphone at home to try and wean myself off it. What are your plans?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#233
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

(1) happened with the first multitasking OS, or possibly when CPUs got microcode; Android and iOS are big increases in freedom in comparison to the first phones.

(2) and (3) are bad, but a tangential bad to this: it’s no good having an untainted chat layer if it’s running on an imperfect — anywhere from hostile to merely lowest-bidder solution — OS. (And most of the problems we find in software have been closer to the later than the former).

(4) for all their problems, the American ones held off doing that until there was an attempted coup, having previously resisted blocking Trump despite him repeatedly and demonstrably violating their terms.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#234
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

> closed social networks

It’s not clear that governments would give the open social networks an easier ride either. It could be argued that distributed FOSS developers are easier to pressurise into adding back doors, unless we officially make EFF our HR/Legal department.

The other problem is workers have a right to be paid. The alternatives are FOSS and/or distributed social media. Who in good conscience would ask a tech worker to give away their labour for free, in the name of everyone else’s freedom?

In a world of $4k rent, who amongst us will do UX, frontend, backend, DevOps, UO, and Security for 7 billion people, for anything but the top market rate?

The real alternative is to attack the actual problem: state overreach. Don’t attack people for using SnapChat — get them to upend the government’s subservience to intrusive law enforcement.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#235
post #102

Earlier quoted context omitted.

This isn't CSAM or illegal, nor would it ever end up in a database. Speaking generally, content has to be sexualized or have a sexual purpose to be illegal. Simple nudity does not count inherently.

> Simple nudity does not count inherently. That’s not entirely true. If a police officer finds you in possession of a quantity of CP, especially of multiple different children, you’ll at least be brought in for questioning if not arrested/tried/convicted, whether the images were sexualized or not. > nor would it ever end up in a database That’s a bold blanket statement coming from someone who correctly argued that NC…

>That’s not entirely true

That's why I said it's not inherently illegal. Of course, if you have a folder called "porn" that is full of naked children it modifies the context and therefore the classification. But, if it's in a folder called "Beach Holiday 2019", it's not illegal nor really morally a problem. I'm dramatically over-simplifying of course. "It depends" all the way down.

>That’s a bold blanket statement

You're right, I shouldn't have been so broad. It's possible but unlikely, especially if it's not shared on social media.

It reinforces my original point however, because I can easily see a case where there's a totally voluntary nudist family who posts to social media getting caught up in a damaging investigation because of this. If their pictures end up in the possession of unsavory people and gets lumped into NCMEC's database then it's entirely possible they get flagged dozens or hundreds of times and get referred to police. Edge case, but a family is still destroyed over it. Some wrongfully accused people have their names tarnished permanently.

This kind of policy will lead to innocent people getting dragged through the mud. For that reason alone, this is a bad idea.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#236

Sorry to say that, but stuff like this has to happen at some point when people don't own their devices. Currently, nearly no one owns their phone and at least EU legislation is underway to ensure that it stays this way. The next step will be to reduce popular services (public administration, banking, medicine) to access through such controlled devices. Then we are locked in. And you know what? Most people deserve to…

Why do they DESERVE to be so? Despite what you say there was and is no mechanism to really change or affect the course of these affairs.

Apple? How? Your other option is Android, who do you choose when they start to do it?

Or when governments decide to mandate that ALL phones need to legally have "scanning all the files on it and report them back to the police database" mechanisms?

The EU? Particularly how? An organization that has been deliberately structured to supersede the legitimacy of nation states and export it's power to all of it's members at the whim -- sometimes it seems -- of some aging out of touch bureaucrats.

I'm not even a #brexiter, btw.

Should Scotland become an independent nation? There was a public debate and people had opinions -- and there were mechanisms in place to act on and make a change, as an example.

There has been no public debate on this in a national sense (anywhere), and also no mechanisms by which people could decide to change it. I'm not sure people deserve it.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#237
post #200

Earlier quoted context omitted.

An Android device running non-stock is a realistically better scenario. The big problem there is that the state of Android drivers means your hardware options are severely cut down (in practice, to a selection about the size of Apple's - the Pixel line and some assorted others).

do you still get patches via google play services?

With non-stock (assuming not jailbroken but just a totally different operating system) I think (I might be wrong... I should know for sure but I awkwardly don't) you aren't even allowed to use Google Play Services at all?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#239
post #6

I understand the hesitation here, but fundamentally this is like trying to close pandoras box. If something is technically possible to do AND governments demand it be done, it will be done. If not by Apple, by someone else. Rather than complain about it, I am interested in what alternative solutions exist, or how concerns regarding privacy and abuse of this system could be mitigated.

>what alternative solutions exist, stop trading freedom for security.

This is too vague. We need something concrete.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#240
post #28
post #23

Since Snowden I use my phone in minimalistic way. Phone calls. Minimal texting. No games. Banking apps if necessary. Treat your phones as an enemy. Use real computers with VPN and software like Little Snitch when online. Use cameras for photography and video. The benefits of this approach are immense. I have long attention span. I don't have fear of missing out. If governments wan't the future to be painted by tracin…

>Treat your phones as an enemy. Use real computers with VPN and software like Little Snitch when online. I'm assuming your "real computer" is a mac (since little snitch is mac only). What makes you think apple won't do the same for macos? Also, while you have greater control with a "real computer", you also have less privacy from the apps themselves, since they're unsandboxed and have full access to your system.

They said "_software like_ Little Snitch"... Don't assume.
Post reply on HN