Live data from Hacker News

Apple plans to scan US iPhones for child abuse imagery

ft.com

151–160 of 390 posts

Re: Apple plans to scan US iPhones for child abuse imagery

#151

Earlier quoted context omitted.

Pardon my ignorance on the subject, but is it feasible to create a false-positive hash match? Isn't a hash directly correlated to the file content? So if the file content is changed at all, the hash should be completely different, should it not?

You have two primary misunderstandings AFAICT. (1) You're assuming it's a "traditional" hash, as opposed to a perceptual hash. The former is purely based off file contents and thus any transformations applied on an image will lead to a new pseudorandom hash. By contrast, perceptual hashes are made to be able to still return a positive when a photo is resized, accumulated artifacts etc. This proposal is to use phashes…

irrc a cryptosecure hash is computationally infeasible to generate a new sample that has the same hash.

that is if you know hash (or reasonably small, ie only a percent of the total bit space), it's improbable bordering on impossible to generate a false positive .

Re: Apple plans to scan US iPhones for child abuse imagery

#152

This article raises serious privacy concerns. Just building the infrastructure for on-device scanning and reporting is extremely troubling. A slippery slope, or a break in the dam, as others have said. My view is that we've been on that slope for a long time, and this changes little. We just have to trust Apple, as has always been the case. When I look at the technical details, it seems to me to be a reasonable compr…

> As described here, the scanning only applies to images also uploaded to iCloud ("[the] algorithm will continuously scan photos that are stored on a US user’s iPhone and have also been uploaded to its iCloud back-up system"). While we don't know whether this description is accurate, it suggests that if you don't back up images to iCloud your device won't do any scanning locally. Apple already has the keys to your iCloud backups, so if you value privacy you're probably not backing up to iCloud anyhow.

If we had a way to guarantee that it would stay that way, it'd be less concerning. As it stands, clearly there are plans to scan on the device itself, otherwise there would be no need to roll out software on iPhones at all.

> Hash collisions aside, this should only produce matches against images that are already in a government database. It will match manipulated images (e.g., rotated or cropped), but it won't match new images.

Agreed, but the issue is the government can stick whatever photos in the DB they want. And we have no way to verify what's in there, since they're not gonna release thousands of CP images for us to audit them.

> Apple has the control to do all sorts of invasive things to our privacy. They could be scanning and reporting all kinds of things already, and we might not even know. Or they could start doing so tomorrow. From this point of view we're already trusting them to do right by us as their customers, and this feature doesn't change that.

It changes plenty. Currently Apple more or less promises not to spy on you, and so they have to actually be lying to do so. Is lying an option for them? Sure, but that's different than them just announcing in advance "hey we're gonna start scanning every photo you have and crossreferencing against a somewhat-transformation-invariant secret government database". I'd prefer that they have to lie to me to spy on me, since that at least has the potential for backlash if discovered. If they get this feature rolled out we're all fucked.

Re: Apple plans to scan US iPhones for child abuse imagery

#153

I really don't see how this is going to end well, there could be perfectly innocent photos on someone's phone of their own children doing perfectly normal things that kids do. Like a kid running butt naked around the house, or a photo of something like a rash that is sent to a nurse friend for advice on what it is etc. I'm all for protecting children from being abused, but how are they going to filter what is normal…

What I don't understand is how is it even constitutional in the US. Isn't it a warrant-less search? It's not like scanning content on a cloud. The cloud owns the device on which you store your data. But you own your mobile.

Re: Apple plans to scan US iPhones for child abuse imagery

#154
post #139

Earlier quoted context omitted.

This is on your device, not hosted by a third party (and therefore not a third party liability). Kind of like if your microwave was checking that there wasn't any illegal activity happening in your home and phoning home if it has a suspicion. As others mentioned, privacy erosion only goes one way. This is a frontier being breached, i.e. searching your physical device without a warrant, and as usual in the name of CP…

No it’s not. Read the article: the proposed mechanism is implemented as part of photo upload to iCloud.

The title says "scan US phones", the article is behind a paywall.

Re: Apple plans to scan US iPhones for child abuse imagery

#155
post #13

Apple should perhaps dogfood their system on their own employees first: https://www.losaltosonline.com/news/hills-man-arrested-on-ch...

Not employees but all of their board and all of their investors.

Also lets draft on all the children of senate and congress

https://quotepark.com/quotes/1911588-immortal-technique-the-...

Re: Apple plans to scan US iPhones for child abuse imagery

#156

While they are at it they should up the ante and also add COVID misinformation filters, so that a phone refuses to save it and/or doesn't send it anywhere. Would be very topical. There is also racism and other almost universally recognized wrongthink. If you decide to police offline activity as if it's a cloud platform, why not implement all the online platform's automatic content filtering/censorship? /s

COVID "misinformation", anti-lockdown protests, any movements that are commonly labelled as domestic terrorism (boog bois, antifa, maybe even BLM; in China it will be anything that speaks out against the CCP, etc) - the potential for abuse is massive.

Anyone that trusts the feds to do the right thing here is incredibly naive. They get to operate a black-box database; if your phone has any photos that match an entry in the db you will be reported to the authorities. I can't believe on HN of all places there's not 10x more of an outcry.

Re: Apple plans to scan US iPhones for child abuse imagery

#157
post #153

I really don't see how this is going to end well, there could be perfectly innocent photos on someone's phone of their own children doing perfectly normal things that kids do. Like a kid running butt naked around the house, or a photo of something like a rash that is sent to a nurse friend for advice on what it is etc. I'm all for protecting children from being abused, but how are they going to filter what is normal…

What I don't understand is how is it even constitutional in the US. Isn't it a warrant-less search? It's not like scanning content on a cloud. The cloud owns the device on which you store your data. But you own your mobile.

Not if you give permission, which you do by your purchase agreement.

Re: Apple plans to scan US iPhones for child abuse imagery

#158
post #43

I bet Apple understands this is a bad idea (dilutes their "privacy" brand image) I wonder what forces have pushed Apple to this point.

perhaps they're being required by law and gagged for indicating as such

https://theintercept.com/2018/06/25/att-internet-nsa-spy-hub...

Re: Apple plans to scan US iPhones for child abuse imagery

#159
post #154

Earlier quoted context omitted.

No it’s not. Read the article: the proposed mechanism is implemented as part of photo upload to iCloud.

The title says "scan US phones", the article is behind a paywall.

https://archive.is/https://www.ft.com/content/14440f81-d405-...

Re: Apple plans to scan US iPhones for child abuse imagery

#160

Earlier quoted context omitted.

In the United States, the process of reporting potential images of CSAM is defined by the government, and a technology company’s active responsibility ends with a report to the National Center for Missing and Exploited Children’s CyberTipline: https://www.missingkids.org/gethelpnow/cybertipline#whathapp...

From the article: > The automated system would proactively alert a team of human reviewers if it believes illegal imagery is detected, who would then contact law enforcement if the material can be verified. The scheme will initially roll out only in the US. This is dystopian and needs to be opposed, not applauded.

> will initially roll out only in the US.

Ok so they’re planning to eventually roll out this spyware worldwide. I do not know how Americans can think China is bad in this while allowing this to happen.

Post reply on HN