Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

601–610 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#601
post #59

Earlier quoted context omitted.

That's the stated purpose, but keep in mind that these databases (NCMEC's in particular, which is used by FB and very likely Apple) contain legal images that are NOT child porn.

Source for that info?

Think of it this way, take a regular, legal set of adult pornographic pictures. While legal, we'd still classify this set of pictures as known porn if we were tracking it.

Now the first few images might be the model completely clothed and not even be porn, maybe there's a picture of her lounging around a pool, then another picture of the pool itself. Still its part of a set of pictures that is known porn.

Heck most porn starts off with actors being clothed (so I hear lol).

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#602

Earlier quoted context omitted.

> And then take what actions, exactly? Don’t buy or use their products.

Unrealistic. My non-tech family and friends don’t care about this, and I can’t make them care. They don’t understand why it’s a problem; they agree with the motive and don’t understand that it’s not actually a solvable problem. It’s not totally dissimilar to the crypto backdoor problem. Normies think it’s great for only the feds to break encryption. Doesn’t work that way, but you can’t explain why to someone who does…

I have a different experience. My normie family and friends don't want a private company to access private media at all. Tech-illiteracy is no question of education and intelligence. This is a topic that is comparable to home searches.

Still good to keep up the pressure on public officials. That any interior minister is very happy about that doesn't have to be excused. Anyone else should be more like French people.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#603
post #569
post #557

Earlier quoted context omitted.

The warning: "Don't buy Apple products, their locked down hardware and walled garden is going to be trouble" People: Ignore warning, buy iPhone You: "Don't buy Apple products" isn't an action.

The alternative is? Google phone? This is not an alternative if you care about privacy. The allegory presented sounds insane (growing your own food) but honestly if you're not rolling your own flashed ROM on a 'droid then your privacy is dead already; I understand throwing all your eggs in one basket is a terrible idea but Apples walled garden and heavy sandboxing was at least somewhat protective.

One option is getting a Phone that has an unlocked bootloader so one can load their own ROM without Goople Play Services. I have a Pixel 3a with LineageOS, no Google Play. I'm pretty happy with it.

While the Pinephone isn't perfect yet, I would argue it will be able to replace Android/iOS in a few months.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#604
post #208

Earlier quoted context omitted.

If it’s a cryptographic hash - very hard.

But the probability is still not zero, and the number of iPhones in the world is large. A hash collision is possible, however unlikely.

The probability of Apple and all its devices winking out of existence due to quantum fluctuations is not zero. ‘Not zero’ is effectively zero if the number is small enough.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#605

Earlier quoted context omitted.

Great, so what's the solution? What are you doing to fix it? Do you roll your own silicon? Do you grow your own food (we have no idea what someone could be putting in it)? Are you completely off-grid? Or are you as completely dependent on society writ large as everyone else? Making holier than thou comments about everyone else being sheep isn't helpful or thought provoking. Offer an alternative if it is a bad one (lo…

The solution won't be technological, it will be in realm of laws and regulations. We are weak peasants and don't have any power over big tech, but we can change legal environment for them. IANAL but we (via our elected representatives) can push a law that prohibit restrictions on execution of users' code on their own devices. Or we can split app stores from vendors and obligate them to provide access to third-party s…

This. You can't change mass behavior by individual pleas. Especially when the behavior generates outsized profits that can be used to advertise and lobby in its support.

The most pressing things that should be supported, to have the world I think we want:

1. Mandate open app stores. Your device, your choice. *

2. Mandate open browsers. Your device, your choice. The internet is fundamentally an extension of the OS at this point, so an free (as in speech) connection choice is a requirement for an open OS. *

3. Mandate open apps. Your device, your choice. Installing unsigned apps can be warned, but not prohibited (outside of enterprise devices).

4. Mandate configurable tracking. Your device, your choice. There must be a clear option to disable all tracking, along with an API / payment ecosystem for apps to detect this and request alternative payment. I.e. "free if advertising on + $5.99 if advertising off".

5. Mandate right to repair. The manufacturer must provide necessary technical specifications (hard or soft) for a base level of modification and repair. If the manufacturer no longer supports the device, everything must be released to the public.

* Selection must be offered at time of device setup. Installing alternatives can be warned, but not prohibited (outside of enterprise devices).

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#606

Earlier quoted context omitted.

Until the manufacturer decides otherwise.

Then once the manufacturer makes that decision, switch. Honestly this comment is just nonsense.. Apple has always allowed other OSes on Mac. When that changes, buy a new computer.

The iPhone came out 14 years ago, and still doesn't allow switching OS. What more do you need?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#607

Earlier quoted context omitted.

> And then take what actions, exactly? Don’t buy or use their products.

Unrealistic. My non-tech family and friends don’t care about this, and I can’t make them care. They don’t understand why it’s a problem; they agree with the motive and don’t understand that it’s not actually a solvable problem. It’s not totally dissimilar to the crypto backdoor problem. Normies think it’s great for only the feds to break encryption. Doesn’t work that way, but you can’t explain why to someone who does…

Perhaps as I stated it, yeah it seems unrealistic.

However I do think there’s value in gentle, consistent evangelism of privacy in ways that don’t make people feel bad. Most folks actually don’t want their deeply private stuff to be accessible. I’ve found that there are good analogies and ways to think about it that folks can get on board with and start caring to some extent.

I absolutely agree that political progress is the ultimate solution. I think the only way that will happen is if enough people demand it.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#608

Earlier quoted context omitted.

The solution won't be technological, it will be in realm of laws and regulations. We are weak peasants and don't have any power over big tech, but we can change legal environment for them. IANAL but we (via our elected representatives) can push a law that prohibit restrictions on execution of users' code on their own devices. Or we can split app stores from vendors and obligate them to provide access to third-party s…

Lawmakers are more likely to enforce the direction this discussion is objecting to.

I agree, but we can elect different lawmakers. Let's push Louis Rossman to congress for example. I checked, his congressional district is represented by someone named Jerry Nadler, who's been sitting there since 1992 and (I'm pretty sure) is out of touch of his constituents since late 1990's.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#609
post #360

How easy is it to generate an image that has the same “perceptual hash” or whatever that are calling it? My guess is it has to be easier than cracking a non fuzzy hash? Do we know the algorithm they are using?

No, it's undisclosed: >Hashes using a new and proprietary neural hashing algorithm Apple has developed, and gotten NCMEC to agree to use. >We don’t know much about this algorithm. What if someone can make collisions? https://twitter.com/matthew_d_green/status/14230792585163448...

> neural

Oh boy..

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#610

Earlier quoted context omitted.

This is the big one right here. A malware will definitely be created, almost immediately, that will download files that are intentionally made to match CP - either for the purposes of extortion or just watching the world burn. I'm usually sticking my neck out in defence of more government access to private media than most on HN because of the need to stop CP, but this plan is so naive, and so incredibly irresponsible…

If you can recreate a file so it’s hash matches known CP then that file is CP my dude. The probability of just two hashes accidentally colliding is approximately: 4.3*10-60 Even if you do a content aware hash where you break the file into chunks and hash each chunk, you still wouldn’t be able to magically recreate the hash of a CP file without also producing part of the CP.

It's NOT a cryptographic hash.

It's the weights from the middle of a neural network that they're calling a "hash" because it encodes and generates an image it has classified as bad. Experts have trouble rationalizing about what weights mean in a neural network. This is going to end badly.

Post reply on HN