Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

261–270 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#261

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

If what kills my enemies also kills my friends, then I don't want it.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#262

Every so often I feel a wave of revulsion that the computer I use the most — my iPhone — is an almost completely closed system controlled by someone else. Contrast this with my desktop where, in the press of a few buttons, I am presented with the source code for the CPU frequency scaling code. Bring on the Linux phones.

Can you recommend one?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#263
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

You could go back even further if you wanted. Possibly to the first handwritten letter delivered by a third party. That's where all the potential for censorship and tampering started. Truth is even if our tools evolve, our chains evolve faster.

Case in point being the Black Chamber run by the Thurn und Taxis post in Brussels in the 16th Century.

https://link.springer.com/chapter/10.1057/9780230298125_11

Signals intelligence intercept and analysis centres have been called Black Chambers for a long time, including the first such group in the US, predecessor to the NSA:

https://en.wikipedia.org/wiki/Black_Chamber

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#264

Earlier quoted context omitted.

now im afraid, i have two young children < 5 years old. i have occasionally took pictures of them naked with some bumps on the skin or mosquito bite and sent them to my wife over whatsapp to look at and decide do we need to send them to doctor, do i have to fear now that i will be marked as distributing CP.

It’s not just you. I have pictures of my kids playing in the bath. No genitals are in shot and it’s just kids innocently playing with bubbles. The photos aren’t even shared but they’d still get scanned by this tool. This kind of thing isn’t even unusual either. I know my parents have pictures of myself and my siblings playing in the bath (obviously taken on film rather than digital photography) and I know friends hav…

> No genitals are in shot

That you even have to consider sexual interpretations of your BABY'S GENITALS is an affront to me. I have pictures of my baby completely naked, because it is, and I stress this, A BABY. They play naked all the time, it's completely normal.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#265
The terrifying part about this is potential abuse. We have seen people arrested for having child porn in their web cache just from clicking on a bad link. I could inject your cache with any image I want using JS.

Presumably the same could apply to your phone. Most messengers save images automatically. I presume the images are immediately scanned against hashes once saved. And the report is immediately made if it passes the reported threshold. There’s no defence against this. Your phone number is basically public information and probably in a database somewhere. You have no protection here from abuse, if you’re a normal citizen. I bet most people don’t even turn the auto save setting off on WhatsApp.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#266
post #208

Earlier quoted context omitted.

If it’s a cryptographic hash - very hard.

But the probability is still not zero, and the number of iPhones in the world is large. A hash collision is possible, however unlikely.

128 bit hashes are “expect your first collision when each human buys 2305 iPhones, all with one terabyte storage, and then fills them up with photos that are an average of 1MB in file size”

https://en.wikipedia.org/wiki/Birthday_attack

http://www.wolframalpha.com/input/?i=2%5E64%20%2F%20%288e9%2...

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#268
You demo this tech working with child porn, it maybe shows it's worth with some Isis training videos but before long China will be demanding access on their terms as a condition of accessing their markets.

And at that point the well meaning privacy advocate who worked hard to get some nice policies to protect users is booted off the project because you can hardly tell the shareholders and investors who own the company that you're going to ignore $billions in revenue or let your rival get ahead because of some irrelevant political movement on the other side of the world.

It's happened plenty of times before and it'll happen again.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#269
post #208

Earlier quoted context omitted.

How hard would it be to create a valid image that matches some 128bit hahs

If it’s a cryptographic hash - very hard.

The tweets talk about perceptual hashes, not cryptographic hashes.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#270
This is horrifying. Does this only affect iMessage, or the photos library? Is it remote? Does it require physical access?

As I understand it: it's a tool (that sends a command of some sort) that compels an iphone to perform the hashing match operation, and output results. Is that correct? Does it notify the user?

If I had to build it within apple's privacy framework, that'd probably be my approach: remote command causes sepos unlock of photos library (even running the job on sepos?) to do photo scanning. sepos returns hashes that match

Post reply on HN