Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

491–500 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#491
post #393

Earlier quoted context omitted.

Why would any fan of someones work buy a knock-off copy? We can safely assume they are a fan, otherwise why would even buy it? Also, painting is a physical object. It's a one of a kind. EDIT: your objection and many many other questions like that are nicely argued against here: https://www.youtube.com/watch?v=mhBpI13dxkI (The Surprising History of Copyright talk by Karl Fogel)

Do you think people will want to create new stories if others can undercut and sell their work for less?

Yes. Definitely. Absolute staggering majority of people writing books don't sell even one copy. And my bet is - they know what are the chances.

EDIT1:

More than that. People don't live of royalties. Publishers do. Can people create without being paid upfront by publishers? Obviously yes. They can be paid upfront in kickstarter-like arrangement. They can be paid via donations later. They can even be paid via "retroactive funding of public goods" [0]. Or they can be never paid - just as they are today.

[0] - https://medium.com/ethereum-optimism/retroactive-public-good...

EDIT2:

Also, imagine how much good could come of long-standing IP properties owned by Disney if not for them sitting on it. Vide disaster that is current management of Star Wars.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#492
post #384

Earlier quoted context omitted.

Because E2E didn't exist when the phone was invented but there have been significant improvements since then.

Not POTS, but cell phones could have been E2E at least since cellular switched to digital.

The first digital phones ran on 56 bit (symmetric?) encryption. They certainty weren't powerful enough to run public key cryptography at safe key sizes, which is needed for secure e2e.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#493

Earlier quoted context omitted.

Have people already forgotten that Microsoft implemented the tech to routinely scan your cloud storage a decade ago? >The system that scans cloud drives for illegal images was created by Microsoft and Dartmouth College and donated to NCMEC. The organization creates signatures of the worst known images of child pornography, approximately 16,000 files at present. These file signatures are given to service providers who…

I'm OK with software generating signatures from cloud drive images to eliminate child porn pictures and catch pedophiles.

You should read the rest of the linked Twitter thread, because the issue is that if the hash algorithm has a collision vulnerability, any image could be manipulated to show up as "child porn" to the scanner.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#495
post #226

It's funny to see anyone here could find this acceptable. I wonder what's comments would be after Apple start to scan phones for anti-censorship or anti-CCP materials in China. Or for some gay porn in Saudi Arabia. Because you know in some countries there are materials that local government find more offensive than mere child abuse. And once surveillance tech is deployed it's certainly gonna be used to oppress people…

[deleted]

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#496

Earlier quoted context omitted.

> I do not agree with this. You are saying people are too stupid to make decisions and that is amoral in my opinion. I'm not saying that at all. I'm saying that it's impossible for all people to make informed decisions on all the issues that surround them, because of both knowledge and time. And it doesn't just happen with computer and privacy, see food, for example. Do you make all decisions about what's allowed or…

But who will formulate these laws that are supposed to give people freedom when we already have malicious state actors pushing for the complete opposite? Who will put pressure on governments to formulate just laws if people are so hopelessly misinformed and cannot possibly take the time to understand the issue of being parted with their freedom? The suggestion is not that people need to continually invest large amoun…

> But who will formulate these laws that are supposed to give people freedom

I'd bet that most people in HN live in democracies.

> Who will put pressure on governments to formulate just laws if people are so hopelessly misinformed and cannot possibly take the time to understand the issue of being parted with their freedom?

You don't need to know biochemistry and medicine to know that you don't want carcinogenic elements in your food, right? In the same sense, you don't need to know how to check that a channel is private and secure in order to push for regulations that make your communication channels secure.

>It is that they should inform themselves once in order to understand the issue and be able to ensure their governments are not secretly becoming totalitarian states.

Which is exactly the same thing I'm proposing: push for regulations that align with their interests.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#497
post #388

Earlier quoted context omitted.

The selling point of Macs is the Apple ecosystem and UX. If you avoid Apple, what's the point of M1? Linux on equivalent AMDs is cheaper and more compatible.

> If you avoid Apple, what's the point of M1? - (Potentially) programmable top notch security chip with no overhead encryption - Fanless (Air), cool running, fast processor with very low power consumption - All metal body - Top notch HiDPI screen with color accuracy. - Top notch sensors - Excellent, illuminated keyboard - Big trackpad with pressure sensitivity and taptic engine - Excellent battery life - Excellent ba…

Is the M1 keyboard significantly better than MBP (with the touchbar)? because that keyboard was crap. To be absolutely fair, good keyboards are hard to come by these days, and that's also why i'm using a logitech from 2006 via ps2 adapter.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#498
I would like to hear the strongest case for the privacy trade-off. How many more children will be physically recovered versus existing methods? What is the reduction in money flow to abduction activities?

This might be naive, but I would guess that the best way to fight this kind of thing is to let people know more of the case details. People would protect themselves, find the crimes, and stop unwittingly supporting them. For instance, if it can be shown that cryptocurrency or encrypted messengers are used to a significant extent, the community will either find a technical solution, or stop using it.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#499

Earlier quoted context omitted.

> My point is that privacy and security is not something that will be solved by federation or open source. I disagree. Here's why: > For open source and federation to be useful in that regard, you need most people to actively research and check that the tools that they use are private and secure. This is the key point. You do not need most people. You need some people. And you can always find some people who verify e…

> This is how Signal and Matrix appeared and became (relatively) famous. And what happens when another app comes and says that "it's secure" and people start using it instead of Signal or Matrix? What happens if Signal starts requiring some payments (running servers is not free) and people move to other apps? Maybe those other apps are open source and federated, but the federation protocol is found later to have a ba…

> And what happens when another app comes and says that "it's secure" and people start using it instead of Signal or Matrix?

First, early adopters come and verify it. They bring their friends. If it's really secure and they find no serious bugs, more people join. Then, a bridge is created between the services.

> What happens if Signal starts requiring some payments (running servers is not free) and people move to other apps?

This is a problem with a non-federated protocol actively fighting against third-party apps and servers. It will definitely happen with Signal in this way, which is why I'm not using it and not recommending.

> Maybe those other apps are open source and federated, but the federation protocol is found later to have a backdoor, or some instances run data mining on the messages, or something like that.

Such backdoor will be quick and easy to fix, and to verify that it's fixed. Unlike with Apple's Pegasus. No system is ever 100% secure.

> Who will be faster, the users flocking to those apps or the few number of verifiers getting to work and detecting those issues?

Users are typically very slow to move. See Whatsapp & Facebook. But what's your point?

> If you want most apps to be like Signal or Matrix, the solution is easy: push for legislation and certifications that ensure that, no matter the app, a certain level of security and privacy is enforced.

This is definitely an important thing to do, but it's not enough. There is such legislation already in Europe: GDPR. Unfortunately it cannot dramatically change the industry quickly, because of the monopolies and network effects.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#500
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

Great, so what's the solution? What are you doing to fix it? Do you roll your own silicon? Do you grow your own food (we have no idea what someone could be putting in it)? Are you completely off-grid? Or are you as completely dependent on society writ large as everyone else?

Making holier than thou comments about everyone else being sheep isn't helpful or thought provoking. Offer an alternative if it is a bad one (looking at you Mastodon). So here's mine: we need to change the power of digital advertising. Most of the most rent seeking companies generate revenue primarily selling ads to get more people to buy more crap. I want a VAT on all revenue passing through the digital advertising pipeline. My hope is that if these things are less profitable, it will reduce the over-sized impact these companies (social, infotainment [there is no news anymore], search, etc.) have on our economy and life. People are addicted to to fomo and outrage (faux?), I don't that that will ever change but we can try to make it less profitable.

Post reply on HN