Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

241–250 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#241

So if I understand correctly, they want to scan all your photos, stored on your private phone, that you paid for, and they want to check if any of the hashes are the same as hashes of child porn? So... all your hashes will be uploaded to the cloud? How do you prevent them from scanning other stuff (memes, leaked documents, trump-fights-cnn-gif,... to profile the users)? Or will a huge hash database of child porn hash…

This is the big one right here.

A malware will definitely be created, almost immediately, that will download files that are intentionally made to match CP - either for the purposes of extortion or just watching the world burn.

I'm usually sticking my neck out in defence of more government access to private media than most on HN because of the need to stop CP, but this plan is so naive, and so incredibly irresponsible, that I can't see how anyone with any idea of how easy it would be to manipulate would ever stand behind it.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#242
post #152

Earlier quoted context omitted.

I feel it's a little disingenuous to describe millions of innocent people being surveilled as "the offenders" because there are a handful of actual offenders among them.

I didn't do that...? There's a small number of victims, a small number of offenders (but much more than "a handful"), and hundreds of millions of other users. This change is in the direct interest of victims, direct opposition to offenders. Most normal people probably support the measures in solidarity with group 1, HN generally doesn't.

Having private devices randomly snooped for forbidden materials is fine, okay. So why limit this to phones?

There are kidnapped children being locked inside homes. If you don't open your doors and accept weekly full home inspections, I think it's safe to say you support offenders and hate victims if you oppose this. I mean, we're all against people kidnapping and abusing children.

There's a small number of victims, a small number of offenders (but much more than "a handful"), and hundreds of millions of other home owners. This change is in the direct interest of victims, direct opposition to offenders.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#243
Every so often I feel a wave of revulsion that the computer I use the most — my iPhone — is an almost completely closed system controlled by someone else.

Contrast this with my desktop where, in the press of a few buttons, I am presented with the source code for the CPU frequency scaling code.

Bring on the Linux phones.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#244

Earlier quoted context omitted.

>EU legislation is underway to ensure that it stays this way. which one?

Devices with radio capabilities (i.e., all mobile devices) must be designed to prevent executing "unauthorized" software.

I'm asking for a specific proposal. I'm interested in reading it. Searching for "EU legislation unauthorized software" yields no results.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#245
post #98

Earlier quoted context omitted.

A reasonable person would call it a normal picture if they encountered it in isolation. Like I said, content which is not even borderline are included. By both a legal and moralistic standard they're not CSAM. Not even nearly. Of course, this is a minority of the content in the database. But even 1 such image is gross neglect of stated purpose in my book.

But are these photos that are combined in a row with other CP, and thus indicative that if you have this photo, it’s from a CP collection? Why would I have any content in my phone that would be in that database?

Imagine things like:

- A kitchen with nobody in frame.

- A couch with nobody in frame.

- Outdoor scenery with nobody in frame.

- A bathroom with nobody in frame.

Is it hard to believe you wouldn't download something like this without knowing where it came from?

I'm not talking about borderline stuff. I'm talking about content that has not even a hint of pornography or illegality.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#246

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

- Don't you want to get the terrorists?

- Yea yeah

- Great. Give me access to every part of your life so i know you're not a terrorist.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#247

What I find disturbing is that almost all commenters here took that rumour for a fact. There's nothing to substantiate it, there's no evidence of scan actually happening, and there's no historical precedence of similar thing done by Apple. And yet, people working in tech with supposedly developed critical thinking took the bait. Why? Is it simply because it fits their world view?

You’re right of course but I think in this case it was due to the reputation of the poster on Twitter. At least, that’s the only reason I would take this rumor seriously. But yeah, a rumor is a rumor still.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#248

This might be unpopular opinion but catching people sharing CP images is like catching end users of drugs. Yes it's illegal but the real criminals are the ones producing drugs. But it's very difficult to get to them, so you just arrest end users. Another side note is about near future when someone comes up with synthetic CP images, will they also be criminalised?

It's not just unpopular, it's also wrong: when you use drugs, you are almost entirely harming yourself (leaving aside funding all sorts of illegal activities, just focusing on the act itself). When you propagate CSAM material, you are causing psychological harm to the victims, plus can cause them to physically harm themselves or get harmed by others. So you are a criminal, harming a victim as well. You can read about…

How would a victim of CSA ever find out that I downloaded a particular file? Surely the harm there is caused by the distributor, not the consumer.

Conversely, when I use drugs, I'm paying someone, so I'm actually directly funding criminals. Depending on the country and the drugs, this is often putting cash in the hands of a very violent cartel.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#249

Sorry to say that, but stuff like this has to happen at some point when people don't own their devices. Currently, nearly no one owns their phone and at least EU legislation is underway to ensure that it stays this way. The next step will be to reduce popular services (public administration, banking, medicine) to access through such controlled devices. Then we are locked in. And you know what? Most people deserve to…

Let us comb this a bit.

When you mention that set of population as deserving the consequences, it does not seem too far to me from "People who want trains instead of cars deserve trains". Is this relevant? The big problem is, people buy controversial services, hence finance them and endorse them, hence strengthen them, and in some cases these services make the acceptable ones extinct: the big problem is that people do not refuse what is not sensible, and sensible people have to pay.

Already here where I live, I cannot get essential services¹ because that practice made them extinct!!!

¹(exactly: public administration, tick; banking, very big tick; medicine, not yet. And you did not mention ___the cars___, and more...)

Other note: you wrote

> nearly no one owns their phone

and some of us are stuck with more reliable older devices, which soon may need some kind of replacement. If you know the exceptions to the untrustable devices, kindly share brand/model/OS/tweak.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#250

This will go great with zero-click iMessage exploits like this one: https://9to5mac.com/2021/07/19/zero-click-imessage-exploit/ Edit: Actually, this won't even require an exploit if they also scan media for people who have enabled "iMessage in iCloud". Just send someone an image in the DB (or an image that's been engineered to generate a false positive) and wait for them to get raided.

One could envision false positive images that don’t even display in iMessage when sent or that are nested in other file types, etc.
Post reply on HN