Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

411–420 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#411

Earlier quoted context omitted.

This is a moot point unless you always verify and check all hardware and software that you use, including communications devices.

You don't need to verify everything yourself. You can verify any small part and rely on the community to verify the rest. Or pay someone to verify. However, for all that you need verifiability , which Apple lacks.

> You can verify any small part and rely on the community to verify the rest. Or pay someone to verify.

The only difference in this is who you trust. Be it Apple, the community or someone you pay, you're still trusting that someone else's interests align with yours and they did things correctly.

In other words, this is not a technical problem. It's a problem that needs to be solved through regulation, because 99% of the people can't verify by themselves that their devices are actually private and secure.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#412

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

If you truly want to "protect the children" you should have no issue for the police to visit and inspect your, and all of your neighbors houses. Every few days. Unannounced, of course. And if you were to resist, you MUST be a pedophile who is actively abusing children in their basement.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#413

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

Having known many victims of sexual violence and trafficking, I feel for the folks that honestly want that particular kind of crime to stop. Humans can be complete scum. Most folks in this community may think they know how low we can go, but you are likely being optimistic.

That said, law enforcement has a nasty habit of having a rather "binary" worldview. People are either cops, or uncaught criminals. ..and they wonder why they have so much trouble making non-cop friends (DISCLAIMER: I know a number of cops).

With that worldview, it can be quite easy to "blur the line" between child sex traffickers, and parking ticket violators. I remember reading a The Register article, about how anti-terrorism statutes are being abused by local town councils to do things like find zoning violations (for example, pools with no CO).

Misapplied laws can be much worse than letting some criminals go. This could easily become a nightmare, if we cede too much to AI.

And that isn't even talking about totalitarian regimes, run by people of the same ilk as child sex traffickers (only wearing Gucci, and living in palaces).

”Any proposal must be viewed as follows. Do not pay overly much attention to the benefits that might be delivered were the law in question to be properly enforced, rather one needs to consider the harm done by the improper enforcement of this particular piece of legislation, whatever it might be.”

-Lyndon B. Johnson

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#414
post #58

Earlier quoted context omitted.

The NCMEC database that Apple is likely using to match hashes, contains countless non-CSAM pictures that are entirely legal not only in the U.S. but globally. This should be reason enough for you to not support the idea. From day 1, it's matching legal images and phoning home about them. Increasing the scope of scanning is barely a slippery slope, they're already beyond the stated scope of the database.

The database seems legally murky. First of all, who would want to actually manually verify that there aren't any images in it that shouldn't be? If the public can even request to see it, which I doubt, would you be added to a watch list of potentially dangerous people or destroy your own reputation? Who adds images to it and where do they get those images from? My point is that we have no way to verify the database w…

Not an American, but shouldn't you be able to FOIA this?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#415
post #120

Earlier quoted context omitted.

> The problem with allowing this is that you’re paving the way for future tyrants to use it against us. It's funny how everybody talk about the future. This is happenning now. Remember how a certain german guy took the power some 90 years ago ? He was elected.

I trust we live in a different world today, but it is concerning to read about mandated vaccines to get a job and mandated contact-tracing in countries such as Germany.

Apps weren't mandated, restaurants and such are required to request you check in, but people didn't always fill them or otherwise filled them with junk (especially after they were abused)

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#416
post #245

Earlier quoted context omitted.

But are these photos that are combined in a row with other CP, and thus indicative that if you have this photo, it’s from a CP collection? Why would I have any content in my phone that would be in that database?

Imagine things like: - A kitchen with nobody in frame. - A couch with nobody in frame. - Outdoor scenery with nobody in frame. - A bathroom with nobody in frame. Is it hard to believe you wouldn't download something like this without knowing where it came from? I'm not talking about borderline stuff. I'm talking about content that has not even a hint of pornography or illegality.

So why is it in there and why do they care?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#418
post #389
post #326

Earlier quoted context omitted.

The fact that even the 'smart' people from HN can't wait for their new M1 laptop to arrive convinced me that humans are a lost cause.

So, it’s not that other platforms are any better! Are you sure intel, AMD, Arm or windows TPM aren’t snitching on you? Do we need to make our own silicon from ingot? There’s no technological solution to this problem, only social and legislative.

Is this the real reason why there is the Windows 11 x64 silicon cut-off?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#419
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

I don't think this is a fair characterization; it should not be most people's life goal to fight for their privacy against big companies. Some people make it theirs, and that's fine, but I think it's def not something to expect from most people, in the same way that you don't expect everyone to be actively fighting for clean tap water or drivable roads.

Instead, we as a collective decided to offload these tasks to the government and make broad decisions through voting. This allows us to focus on other things (at work, with our actual job, at home, you can focus with what matters for you, whatever that might be).

For instance, I tried to avoid Facebook for a while and it was working well, I just missed few acquaintances but could keep in touch with the people who matter for me. Then suddenly they acquired Whatsapp. What am I to do? Ask my grandmother and everyone in between to switch to Telegram? Instead, I'm quite happy as a European about the GDPR and how the EU is regulating companies in these regards. It's definitely not yet there, but IMHO we are going in the right direction.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#420
post #394
post #370

Earlier quoted context omitted.

> even if I don’t know the details of the lock in my door, it will not let others pass through. You absolutely can not make that assertion without being able to verify the lock.

What if I have a locksmith verify it for me? Like Apple and Android have been checked by several security researchers and while they absolutely have holes, there is are at least gates that can have them. Sandboxing is the bare minimum an OS should do if it wants to have third party applications installed.

You can only hire someone to verify your lock if the lock is verifiable in the first place. Apple is trying to make it non-verifiable.
Post reply on HN