Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

531–540 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#531
post #22

Earlier quoted context omitted.

What are the implications?

To quote another tweet from Matthew Green, the author of the Twitter thread ( https://twitter.com/matthew_d_green/status/14231103447303495... ): > Regardless of what Apple’s long term plans are, they’ve sent a very clear signal. In their (very influential) opinion, it is safe to build systems that scan users’ phones for prohibited content. > That’s the message they’re sending to governments, competing services, China…

Is it? That’s just something the tweets have read in.

The message could equally well be ‘We won’t become an easy political target by ignoring a problem something most people care about like child porn, but we are going to build a point solution to that problem, so the public doesn’t force us to bow government surveillance requests.’

It’s easy to nod along with an anti-Apple slogan, but we need to consider what would happen if they didn’t do this.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#532

Earlier quoted context omitted.

Yes, because the "huge number of independent people" have never missed any serious bugs or backdoor, and they also verify every piece of equipment you use.

Nothing is ever perfectly secure. It's a question of whom you should trust for a lesser damage.

Apple spends a hell of a lot more time and money verifying that my iPhone is secure than say… the developers of any number of the mobile Linux ports.

Plus the hardware is nice and actually works.

I agree with what you say in principle but here I am using an iPhone to type this while it’s been nearly 2 years since I ordered my Librem 5.

Making decent mobile devices that are more secure than an iPhone is not an easy thing.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#533
post #337

Earlier quoted context omitted.

This sort of scanning has existed for well over a decade, and was originally developed by Microsoft (search PhotoDNA). The only thing that's changed here is that there is more encryption around, and so legal guidelines are being written to facilitate this, which has been happening for a long, long time. (I don't disagree with your overall point, and child porn is definitely the thin edge of the wedge, but this isn't…

Nothing is ever new. You can always find some vague prototype of an idea that failed to become ubiquitous ten years ago. When I read that this shouldn't be surprising, it has an aftertaste of "Dropbox is not interesting/surprising because ftpfs+CVS have existed for well over a decade"

> Nothing is ever new. You can always find some vague prototype of an idea that failed to become ubiquitous ten years ago.

This has been standard practice for well over a decade amongst all big internet platforms.

Like, one can argue that regardless, people's messages should not be readable for any reason, but that's gonna be a tough one to get through a court of law.

The obvious difference here is that backdooring encryption is an all or nothing affair, which may require new thinking (it definitely does).

But the ship around this particular form of backdooring has most definitely sailed.

Like, the only reason Apple is new to this game is because they haven't been in the storage/media sharing business for as long as their competitors.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#534
post #515

Earlier quoted context omitted.

Having known many victims of sexual violence and trafficking, I feel for the folks that honestly want that particular kind of crime to stop. Humans can be complete scum. Most folks in this community may think they know how low we can go, but you are likely being optimistic. That said, law enforcement has a nasty habit of having a rather "binary" worldview. People are either cops, or uncaught criminals. ..and they won…

> People are either cops, or uncaught criminals. ..and they wonder why they have so much trouble making non-cop friends (DISCLAIMER: I know a number of cops). Ehh let's not make a habit of asserting anecdote as fact, please. Saying you know cops is like saying you know black people and that somehow it affords you some privilege others do not possess. This is a weak and ad-hom argument.

> is like saying you know black people and that somehow it affords you some privilege others do not possess.

Of course it does. Interacting with black people (or any race) affords you insight into their life experiences, struggles, worldview etc...

Of course sociological discourse is highly subjective but this attitude on HN that anecdotal data has no value whatsoever is silly. Do you seriously expect every fact of every people to be published in some infallible academic journal?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#535
post #515

Earlier quoted context omitted.

Having known many victims of sexual violence and trafficking, I feel for the folks that honestly want that particular kind of crime to stop. Humans can be complete scum. Most folks in this community may think they know how low we can go, but you are likely being optimistic. That said, law enforcement has a nasty habit of having a rather "binary" worldview. People are either cops, or uncaught criminals. ..and they won…

> People are either cops, or uncaught criminals. ..and they wonder why they have so much trouble making non-cop friends (DISCLAIMER: I know a number of cops). Ehh let's not make a habit of asserting anecdote as fact, please. Saying you know cops is like saying you know black people and that somehow it affords you some privilege others do not possess. This is a weak and ad-hom argument.

I really appreciate having my words taken out of context, and wrapped in insults.

I probably could have done without the second sentence, but the first stands.

Have a nice day.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#536

Earlier quoted context omitted.

Not too lost 'cause you can run Linux on M1.

Until the manufacturer decides otherwise.

Then once the manufacturer makes that decision, switch. Honestly this comment is just nonsense.. Apple has always allowed other OSes on Mac. When that changes, buy a new computer.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#537
post #416

Earlier quoted context omitted.

So why is it in there and why do they care?

Maybe cropped photos, or innocent frames from videos containing abuse? Not sure what GP is referring to.

I am reminded of an infamous couch and pool that are notorious for appearing in many adult productions... Possibly stock footage of a production room or repeating prop intended for being subsampled for so that multiple or repeated works by the same person or group can be flagged. I recall a person of interest was arrested after of all things posting a completely benign YouTube tutorial video. My thought at the time was likely a prop match to the environment or some such within the video. The method is definitely doable. Partitioned out to every consumer device with unflinching acceptance? Yeahhhh.

Remember, these databases are essentially signature DB's, and there is no guarantee that all hashes are just doing a naive match on the entire file, or that all scans performedare fundamentally the same.

This is why I reject outright the legitimacy of any Client-based CSAM scanners. In a closed source environment, it's yet another blob, therefore an arbitrary code execution vector.

I'm sorry, but in my calculus, I'm not willing to buy into that, even for CSAM. It won't stay just filesystems. It won't stay just hash matching. The fact there's so much secrecy around ways and means implies there's likely dynamicity in what they are looking for, and with the permissions and sensors on a phone that many apps already ask for, my not one inch instincts are sadly firmly engaged with no signs of letting up.

I'm totally behind the fight. I'm not an idiot though, and I know what the road to hell is paved with. Law Enforcement and anti-CSAM agencies are cut a lot of slack, and enjoy a lot of unquestioning acceptance by the populace. In my book, this warrants more scrutiny, and caution not less. The rash of inconvenient people being rather frequently called out as having CSAM found on hard drives in media with no additional context indicates the CSAM definition is being wielded in a manner that produces a great degree of political convenience.

Again, more scrutiny, not less.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#539

Earlier quoted context omitted.

This is the big one right here. A malware will definitely be created, almost immediately, that will download files that are intentionally made to match CP - either for the purposes of extortion or just watching the world burn. I'm usually sticking my neck out in defence of more government access to private media than most on HN because of the need to stop CP, but this plan is so naive, and so incredibly irresponsible…

If you can recreate a file so it’s hash matches known CP then that file is CP my dude. The probability of just two hashes accidentally colliding is approximately: 4.3*10-60 Even if you do a content aware hash where you break the file into chunks and hash each chunk, you still wouldn’t be able to magically recreate the hash of a CP file without also producing part of the CP.

Adversarial examples are anything but random.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#540
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

Great, so what's the solution? What are you doing to fix it? Do you roll your own silicon? Do you grow your own food (we have no idea what someone could be putting in it)? Are you completely off-grid? Or are you as completely dependent on society writ large as everyone else? Making holier than thou comments about everyone else being sheep isn't helpful or thought provoking. Offer an alternative if it is a bad one (lo…

https://prism-break.org/en/ is a great start. in the absence of strong regulatory oversight, personal defense is a good measure.
Post reply on HN