Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

511–520 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#511

Earlier quoted context omitted.

I honestly don't like too much these smug takes > 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 99% of the population will delegate the decision of what code is allowed to run to someone, be it the manufacturer, the government, some guy on the Internet or whatever. For that 99% of the population,…

Not GP but... >99% of the population will delegate the decision of what code is allowed to run to someone, be it the manufacturer, the government, some guy on the Internet or whatever. For that 99% of the population, by the way, it's actually more beneficial to have restrictions on what software can be installed to avoid malware I do not agree with this. You are saying people are too stupid to make decisions and that…

> >99% of the population will delegate the decision of what code is allowed to run to someone, be it the manufacturer, the government, some guy on the Internet or whatever. For that 99% of the population, by the way, it's actually more beneficial to have restrictions on what software can be installed to avoid malware

> I do not agree with this. You are saying people are too stupid to make decisions and that is amoral in my opinion.

How much of the code running on your data do you personally inspect? (Don’t forget device firmware) When your browser ships an update, do you reverse-engineer the binary? Do you review all of the open source code you use looking for back doors?

Would it be accurate to say that you don’t do that because you’re stupid? I don’t think that’s reasonable, any more than it would be to say you should carry around a test kit for any food you are planning to buy at the supermarket.

> Technology moves faster than what any law maker can create.

This is a common claim but it’s too simplistic. Laws do get passed relatively quickly when there’s a clear need - think about how things like section 230 arrived relatively soon after the rise of the web - but in most cases it’s more a clarification of existing laws. For example, cryptocurrency wasn’t mentioned in previous laws by name but the IRS had no trouble taxing it under existing laws.

Privacy shows why the “just let people choose” approach doesn’t work: you the individual have no negotiating clout with Facebook or Google, and there are many cases like revenge porn where the problem is only visible after the decision has been made.

Laws are how societies agree to function. If you don’t like the laws, you need to get involved because there simply isn’t a way to get good results by demanding that the system accommodate people who don’t show up.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#513
post #32

Earlier quoted context omitted.

> Stop. Using. Apple. But is there a realistically better alternative? Pinephone with a personally audited Linux distro? A jailbroken Android device with a non-stock firmware that you built yourself? A homebuilt RaspberryPi based device? A paper notepad and a film camera and an out of print street map?

Viable alternatives were long gone. I really miss the days of Symbian and Meego, phones that are hackable yet intuitive to use (I.e. Nokia N900, N9). Realistically now we have Tizen and Jolla OS, which had backings from Samsung but nobody gave two damn about it. I bet even if any of these vanilla mobile OS gets big enough they’ll get bought by the 3 giants and suffocated to death just like how Microsoft sniped Nokia.

Samsung is one of the companies I trust the least with regards to security, privacy, and overall competence in software.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#514
post #212

Earlier quoted context omitted.

That sounds like we know it’s perceptual but not what kind, and therefore we don’t know the collision characteristics.

We know perceptual hashing and cryptography have incompatible requirements. Think of an image, the same image with 1 pixel changed, and a very different image. A perceptual hash should say 1 and 2 were related and not 3. Cryptographers call that failing a chosen plaintext attack.

Agreed, but we don’t know the collision characteristics of this algorithm so knowing this difference is moot in this context.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#515

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

Having known many victims of sexual violence and trafficking, I feel for the folks that honestly want that particular kind of crime to stop. Humans can be complete scum. Most folks in this community may think they know how low we can go, but you are likely being optimistic. That said, law enforcement has a nasty habit of having a rather "binary" worldview. People are either cops, or uncaught criminals. ..and they won…

> People are either cops, or uncaught criminals. ..and they wonder why they have so much trouble making non-cop friends (DISCLAIMER: I know a number of cops).

Ehh let's not make a habit of asserting anecdote as fact, please. Saying you know cops is like saying you know black people and that somehow it affords you some privilege others do not possess.

This is a weak and ad-hom argument.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#516
post #354

Earlier quoted context omitted.

You are actually creating a false dichotomy here. There are more sides to this. And you are creating (as said a false) black and white image here. I strongly believe that nobody wants to further victimize people by publicly showing images of their abuse. And I believe very strongly that putting hundreds of millions of people under blanket general suspicion is a dangerous first step. Imagine if every bank had to searc…

Using your bank analogy for a second: banks already do report on activity to authorities who can then identify people to investigate based on patterns. I've heard that large transactions (>10k) or near-sized ones are flagged. A great deal of skepticism is being given to the NCMEC database in these comments, which I'm surprised by as from what information I have I think this is being exaggerated. At the same time we h…

> I've heard that large transactions (>10k) or near-sized ones are flagged.

Thi sis transmission of funds and there are laws regulating the monitoring of those.

I used bank vaults were you put things into the vaults without the bank often times knowing what is in there. If they knew, they would need to report to authorities.

So Apple doing this scan would be the bank opening all vaults, scanning the contents and reporting things to the IRS (I think this is the tax thing in the US if I am not mistaken - in Germany it would be the Finanzamt).

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#517
post #28

Earlier quoted context omitted.

>Treat your phones as an enemy. Use real computers with VPN and software like Little Snitch when online. I'm assuming your "real computer" is a mac (since little snitch is mac only). What makes you think apple won't do the same for macos? Also, while you have greater control with a "real computer", you also have less privacy from the apps themselves, since they're unsandboxed and have full access to your system.

They said "_software like_ Little Snitch"... Don't assume.

I get that, but on the other hand if someone says "if you care about privacy, you should use an e2e messenger like whatsapp", then I'll have serious doubts about whether you're actually knowledgeable or just spouting buzzwords.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#518
post #58

Earlier quoted context omitted.

The NCMEC database that Apple is likely using to match hashes, contains countless non-CSAM pictures that are entirely legal not only in the U.S. but globally. This should be reason enough for you to not support the idea. From day 1, it's matching legal images and phoning home about them. Increasing the scope of scanning is barely a slippery slope, they're already beyond the stated scope of the database.

The database seems legally murky. First of all, who would want to actually manually verify that there aren't any images in it that shouldn't be? If the public can even request to see it, which I doubt, would you be added to a watch list of potentially dangerous people or destroy your own reputation? Who adds images to it and where do they get those images from? My point is that we have no way to verify the database w…

It’s a database of hashes, not images, though, right? I would argue the hashes absolutely should be public, just as any law should be public (and yes, I am aware of some outrageously brazen exceptions to even that).

Anyone should be able to scan their own library against the database for false positives. “But predators could do this too and then delete anything that matches!” some might say, but in a society founded on the presumption of innocence, that risk is a conscious trade-off we make.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#519
post #359

The terrifying part about this is potential abuse. We have seen people arrested for having child porn in their web cache just from clicking on a bad link. I could inject your cache with any image I want using JS. Presumably the same could apply to your phone. Most messengers save images automatically. I presume the images are immediately scanned against hashes once saved. And the report is immediately made if it pass…

I've read that people intentionally bomb telegram groups with CP. Telegram automatically downloads shared images. This is going to be a crapfest.

Maybe this is a necessary crapfest though, to demonstrate how absurd these measures are.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#520
post #264

Earlier quoted context omitted.

> No genitals are in shot That you even have to consider sexual interpretations of your BABY'S GENITALS is an affront to me. I have pictures of my baby completely naked, because it is, and I stress this, A BABY. They play naked all the time, it's completely normal.

Yeah that’s a fair point. The only reason I was careful was just in case those photos got leaked and taken out of context. Which is a bloody depressing thing to consider when innocently taking pictures of your own family :(

I might have phrased that ambiguously, I mean "an affront to me" as in "to me, that's an affront", not that you have somehow insulted me.

I say let children be free, no court is going to indict you because you have baby pictures on your phone.

Post reply on HN