Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

271–280 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#271
post #13

Earlier quoted context omitted.

>So... all your hashes will be uploaded to the cloud? That isn't how I interpret "client-side". The privacy implications are far more subtle.

It's still really, really bad. It always starts with child porn, and in a few years the offline Notes app will be phoning home if you write speech criticising the government in China. This technology inevitably leads to the sueveillance, suppression and murder of activists and journalists. It always starts with protecting the kids or terrorism. Perceptual hashes like what Apple is using are already used in WeChat to…

> in a few years the offline Notes app will be phoning home if you write speech criticising the government in China.

A totalitarian autocracy like China does not need this technology to search for wrongspeech, sadly. You are of course aware that all Chinese iCloud users get their data stored in a special set of datacenters that Apple actually doesn't control.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#272

Earlier quoted context omitted.

It's not just unpopular, it's also wrong: when you use drugs, you are almost entirely harming yourself (leaving aside funding all sorts of illegal activities, just focusing on the act itself). When you propagate CSAM material, you are causing psychological harm to the victims, plus can cause them to physically harm themselves or get harmed by others. So you are a criminal, harming a victim as well. You can read about…

How would a victim of CSA ever find out that I downloaded a particular file? Surely the harm there is caused by the distributor, not the consumer. Conversely, when I use drugs, I'm paying someone, so I'm actually directly funding criminals. Depending on the country and the drugs, this is often putting cash in the hands of a very violent cartel.

You are correct, however vincnetas made the comparison between distributing CSAM and buying drugs, it is not aemreunal's fault, you are replying to the wrong person. A comparison that would make better sense would be to compare these in possession of CSAM and these that buy drugs.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#273
post #208

Earlier quoted context omitted.

How hard would it be to create a valid image that matches some 128bit hahs

If it’s a cryptographic hash - very hard.

It cannot be a cryptographically secure hash, simply because avoiding detection would then be trivial: change one channel in one pixel by one. Imperceptible change, different cryptographic hash.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#274
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

If it seems like this scanning is working as advertised, this will be a great marketing stunt for Apple. Actual predators will stop using Apple products out of fear of getting caught and they will be forced to use Android.

Now any person who owns an Android is a potential predator. Also, if you are trying to jailbreak your iPhone, you are a potential predator.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#275
post #21

Earlier quoted context omitted.

No, your hashes are not uploaded to the cloud, yes, hashes are downloaded to your phone. Yes, it will be interesting to see if it gets spammed with false positives, although it seems as though that can easily be identified silently to the user.

How hard would it be to create a valid image that matches some 128bit hahs

If the details of the "hashing" scheme used is publicized, I imagine it will be near trivial. It's a long-standing problem in computer vision, to find a digital description of an image such that two similar images compare equal or at least similar.

State-of-the-art for this field is deep learning, and a /huge/ problem with the DL approach is that you can generate adversarial examples. So for example, a picture of a teacup that is identified by /most/ networks as a dog. It's particularly damning, because it seems like you don't have to do this for particular deep networks, they get tricked the same way, so to speak.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#276

Earlier quoted context omitted.

Do you have sources for this ?

See my answer to your sister comment from @optimiz3 In Germany police requested contact tracing lists from restaurants in investigations.

Thank you, it clearly shows that the German government cannot be trusted to do the right thing.

And the underlying desire for having this information will no doubt prolong the Corona restrictions longer than necessary, which is certainly not in the interest of German citizens.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#277
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

> closed social networks It’s not clear that governments would give the open social networks an easier ride either. It could be argued that distributed FOSS developers are easier to pressurise into adding back doors, unless we officially make EFF our HR/Legal department. The other problem is workers have a right to be paid. The alternatives are FOSS and/or distributed social media. Who in good conscience would ask a…

> It could be argued that distributed FOSS developers are easier to pressurise into adding back doors, unless we officially make EFF our HR/Legal department.

How could this be argued?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#278
post #32
post #25

Earlier quoted context omitted.

That document you downloaded that is critical of the party will land you and your family in jail. Enjoy your iPhone. Seriously, folks, we shouldn't celebrate Apple's death grip over their platform. It's dangerous for all of us. The more of you that use it, the more it creates a sort of "anti-herd immunity" towards totalitarian control. Apple talks "privacy", but jfc they're nothing of the sort. Apple gives zero shits…

> Stop. Using. Apple. But is there a realistically better alternative? Pinephone with a personally audited Linux distro? A jailbroken Android device with a non-stock firmware that you built yourself? A homebuilt RaspberryPi based device? A paper notepad and a film camera and an out of print street map?

The best bet is probably a pixel phone with GrapheneOS. (Do note, that copperhead os is a scam and is not to be used)

Gnu/linux phones have nonexistent security, other than being niche (so security by obscurity at most). And also, they are not yet usable as a daily driver for me personally, at least.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#279
post #264

Earlier quoted context omitted.

It’s not just you. I have pictures of my kids playing in the bath. No genitals are in shot and it’s just kids innocently playing with bubbles. The photos aren’t even shared but they’d still get scanned by this tool. This kind of thing isn’t even unusual either. I know my parents have pictures of myself and my siblings playing in the bath (obviously taken on film rather than digital photography) and I know friends hav…

> No genitals are in shot That you even have to consider sexual interpretations of your BABY'S GENITALS is an affront to me. I have pictures of my baby completely naked, because it is, and I stress this, A BABY. They play naked all the time, it's completely normal.

Indeed, I'm guessing this must be some cultural shift that was successfully implanted in some cultures because I too find the idea completely bonkers.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#280
post #208

Earlier quoted context omitted.

How hard would it be to create a valid image that matches some 128bit hahs

If it’s a cryptographic hash - very hard.

This isn't cryptographic though. That would make the entire database absolutely trivial to bypass with tiny imperceptible random changes to the images.

It's a perceptual hash.

Post reply on HN