Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

301–310 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#301

I really have to wonder why Apple chose to do this. As far as I know, this kind of scanning is not legally mandated. So, either they think that this will truly make the world a better place and are doing it out of some sense of moral responsibility, or they've been pressured into it as part of a sweetheart deal on E2E ("we won't push for crypto backdoors if you'll just scan your users' phones for us"). Either way it…

Sales on China and wealthy arabic totalitarian regimes. Customer asks, customer gets.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#302
post #212

Earlier quoted context omitted.

"Hashes using a new and proprietary neural hashing algorithm Apple has developed, and gotten NCMEC to agree to use."

That sounds like we know it’s perceptual but not what kind, and therefore we don’t know the collision characteristics.

We know perceptual hashing and cryptography have incompatible requirements. Think of an image, the same image with 1 pixel changed, and a very different image. A perceptual hash should say 1 and 2 were related and not 3. Cryptographers call that failing a chosen plaintext attack.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#303

Earlier quoted context omitted.

No need for hypotheticals, 2020 was a huge win for the police state. The UK and Israel allowed cops to monitor cell phone locations to crack down on unlawful gatherings in private homes. https://www.theguardian.com/world/2020/mar/17/israel-to-trac... The problem with allowing this is that you’re paving the way for future tyrants to use it against us.

Why does this surprise anybody? People nowadays voluntarily carry tracking devices. This will not stop getting worse until that behavior is denormalized. The power to be gained from abusing it is beyond irresistable. Expecting those in power to not abuse it is like expecting a heroin junkie to be a good pharmacist.

> People nowadays voluntarily carry tracking devices

on the strict premise that tracking is exceptional fair use from a law enforcement agency. Do not mix up the voluntary accolites of Zuck and people who want tools. (The use of 'tools' in the sentence is an originally unintended pun. I will keep the term 'accolites', though tempted to replace it for the pun.)

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#304

Earlier quoted context omitted.

Since this is using a db of known images. I doubt that would be an issue. I believe the idea here is that once police raid an illegal site, they collect all of the images in a db and then want to know a list of every person who had these images saved.

But it said they use a "perceptual hash" - so it's not just looking for 1:1, byte-for-byte copies of specific photos, it's doing some kind of fuzzy matching. This has me pretty worried - once someone has been tarred with this particular brush, it sticks.

You can’t do a byte-for-byte hash on images because a slight resize or minor edit will dramatically change the hash, without really modifying the image in a meaningful way.

But image hashes are “perceptual” in the sense that the hash changes proportionally with the image. This is how reverse image searching works, and why it works so well.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#305
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

Is this anything new, though? The communications haven't been E2E protected ever since people started using phones.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#306
post #264

Earlier quoted context omitted.

> No genitals are in shot That you even have to consider sexual interpretations of your BABY'S GENITALS is an affront to me. I have pictures of my baby completely naked, because it is, and I stress this, A BABY. They play naked all the time, it's completely normal.

Indeed, I'm guessing this must be some cultural shift that was successfully implanted in some cultures because I too find the idea completely bonkers.

If babies playing naked are now child pornography, most Europeans above 50 should be jailed.

As that seems unlikely, I guess CSAM just uses a constantly updated database of known hashes for matching.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#308
post #176

Earlier quoted context omitted.

Does this mean you don't support copyright?

Do you support mandatory cavity searches after every shopping trip? Property laws are important, you should do your part to uphold them.

I think this kind of client-side hashing and comparing to a database list is similar to the scanners at every Wal-Mart and the procedures at airports.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#309
post #305
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

Is this anything new, though? The communications haven't been E2E protected ever since people started using phones.

Because E2E didn't exist when the phone was invented but there have been significant improvements since then.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#310
post #262

Earlier quoted context omitted.

Can you recommend one?

Either a PinePhone or a Librem 5. There's not much more choice than that atm.

And neither are usable as daily driver for the majority of people.

I really don’t want to wait half a minute for taking a picture, and would prefer if the phone would not be untouchably warm after the fact.

Post reply on HN