Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

281–290 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#281
post #54

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

Since you worked on an actual contract catching these sorts of people you are perhaps in a unique position to answer the question: will this sort of blanket surveillance technique in general but also in iOS specifically - actually work to help catch them?

Just as being banned from one social media platform for bad behavior pushes people to a different social media platform, this might very well push the exactly wrong sort of people from iOS to Android.

If Android then implements something similar, they have the option to simply run different software, as Android lets you run whatever you want so long as you sign the wavier.

"You're using Android?! What do you have to hide?" -- Apple ad in 2030, possibly

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#282
post #86

Earlier quoted context omitted.

> Unshared data shouldn't be subject to search. Once it's shared, I can make several cases for an automated scan, but a cloud backup of personal media should be kept private. Our control of our own privacy matters. Not for the slippery slope argument or for the false positive argument, but for its own sake. We shouldn't be assuming the worst of people without cause or warrant. I have a much simpler rule: Your device…

I don't think this rule makes any sense, because it just abstracts all the argument into the word "betray". The vast majority of iPhone users won't consider it a betrayal that they can't send images of child abuse, any more than they consider it a betrayal that it doesn't come jailbroken. The victims of child abuse depicted in these images may well have considered it a betrayal by Apple that they allowed their privac…

I don't think you read your ancestor post carefully enough. I at least don't see any room for ambiguity.

The rule is that your (note the emphasis) device won't ever willingly betray you. There's nothing here that implicates the majority in any way. Simply, your own device should never work against you.

This actually sounds like a great rule to prevent this kind of authoritarian scope creep.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#283

Also, if they send perceptual hashes to your device - it's possible images could be generated back from those hashes. These aren't cryptographic hashes, so I doubt they are very good one-way functions. Another thought - notice that they say "if too many appear". This may mean that the hashes don't store many bits of information (and would not be reversible) and that false positives are likely - ie, one image is not e…

In cryptography creating a one-way function is not a problem. The only thing required for that is loosing information, which is trivial. For example taking the first n bytes of a file is a one-way hash function (for most files). So reversing the hashes is most definitely not a problem.

Creating collisions could be though, eg. brute forcing a normal picture by modifying random pixels by a bit into matching an illegal content’s hash is a possibility.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#284
I'm gonna go out on a limb here.

At the end of the day laws are relative so to say. The thought behind such a system is noble indeed, but as we've seen, anything any government gets their hands on, they will abuse it. Classic example being PRISM et al. In theory it's great to be able to catch the bad guys, but it was clearly abused. This is from countries that are meant to be free, forward thinking etc, not any authoritarian regimes.

People in this thread are asking what Saudi Arabia, China etc will do with such power that Apple is adding, you bet your ass that they'll use it for their own gain.

I want to believe in such systems for the good. I want child abusers caught. But a system that equally can be abused by the wrong people (and I guarantee you that will be western countries too) ain't it.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#285
post #53

It's quite easy to extrapolate this and in a few steps end up in a boring dystopia. First it's iPhone photos, then it's all iCloud files, that spills into Macs using iCloud, then it's client side reporting of local Mac files, and somewhere along all other Apple hardware I've filled my home with have received equivalent updates and are phoning home to verify that I don't have files or whatever data they can see or hea…

> It's quite easy to extrapolate this and in a few steps end up in a boring dystopia.

It's only boring until we get another Hitler or equivalent.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#286
post #274
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

If it seems like this scanning is working as advertised, this will be a great marketing stunt for Apple. Actual predators will stop using Apple products out of fear of getting caught and they will be forced to use Android. Now any person who owns an Android is a potential predator. Also, if you are trying to jailbreak your iPhone, you are a potential predator.

The twitter comments also mentioned scanning for political propaganda etc. This could work against Apple if normal folks don't want all their stuff scanned on behalf of unnamed agencies.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#287
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

> closed social networks It’s not clear that governments would give the open social networks an easier ride either. It could be argued that distributed FOSS developers are easier to pressurise into adding back doors, unless we officially make EFF our HR/Legal department. The other problem is workers have a right to be paid. The alternatives are FOSS and/or distributed social media. Who in good conscience would ask a…

> It could be argued that distributed FOSS developers are easier to pressurise into adding back doors

All millions of them at the same time?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#288
Saudis: We want a list of everyone who ever shared a photo of Khashoggi (no matter in which app).

Apple: Say no more, here they are. Hope you won't imprison all of them, as that would decrease our services revenue substantially, lol.

Also Apple: Privacy is a human right, buy more iphones.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#289
post #262

Every so often I feel a wave of revulsion that the computer I use the most — my iPhone — is an almost completely closed system controlled by someone else. Contrast this with my desktop where, in the press of a few buttons, I am presented with the source code for the CPU frequency scaling code. Bring on the Linux phones.

Can you recommend one?

Either a PinePhone or a Librem 5. There's not much more choice than that atm.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#290
post #96

Earlier quoted context omitted.

What about pictures of you own children naked ?

Since this is using a db of known images. I doubt that would be an issue. I believe the idea here is that once police raid an illegal site, they collect all of the images in a db and then want to know a list of every person who had these images saved.

But it said they use a "perceptual hash" - so it's not just looking for 1:1, byte-for-byte copies of specific photos, it's doing some kind of fuzzy matching.

This has me pretty worried - once someone has been tarred with this particular brush, it sticks.

Post reply on HN