Live data from Hacker News

Apple plans to scan US iPhones for child abuse imagery

ft.com

271–280 of 390 posts

Re: Apple plans to scan US iPhones for child abuse imagery

#271
post #165
post #92

Earlier quoted context omitted.

I bet(or know...) the people who verify those images don't get paid anywhere near enough.

The conventional wisdom for people integrating PhotoDNA is that false positives are vanishingly rare. If you run it against your data and you get a hit then you should call the FBI.

It would be better if the false positive rate was known to be nonzero.

And what, in this context, is "your data?" Is a photo on an iPhone Apple's data?

I'd argue that the thing you should do if you get a hit is to delete your data, unless you want to spend enormous amounts of time and money defending yourself from prosecution by people who believe that false positives are vanishingly rare.

Re: Apple plans to scan US iPhones for child abuse imagery

#272
post #191

Earlier quoted context omitted.

So this means it is checking if you are sharing known CP images? That does seem to be much less invasive and problematic as there is likely no good reason to be sharing these images.

Yes, that's exactly it. It uses a database compiled by NGOs and specialized firms comprising of file hashes matching child porn. These lists are handled by humans. Fuzzy means that it takes compression and the like into account, because even if just one pixel out of 20 thousand is different, the hash is different too. Fuzzy hash still recognizes it as the same image, so using an algorithm to alter the color etc. won'…

> These lists are handled by humans.

That's also true for the no-fly list and the Terrorist Screening Database,[1] yet those are full of false positives. And unlike those lists, CSAM databases cannot be independently verified. To do so would require having the original images, which is illegal.

1. https://en.wikipedia.org/wiki/Terrorist_Screening_Database

Re: Apple plans to scan US iPhones for child abuse imagery

#274

Are they going to compensate the owners for the CPU time, electricity and bandwidth this will cost?

I asked a similar question in both threads here and both times I got downvoted by some courageous folks without an answer.

I also would like to know if I already agreed to this and where can I read the agreement that I signed?

Re: Apple plans to scan US iPhones for child abuse imagery

#275
post #213

Earlier quoted context omitted.

> Child abusers evolve and are very happy if law enforcement doesn't. Yes. And now they will evolve by developing a simple system to modify pixels in images when they copy and transmit that will easily defeat this hashing system. The only effect this will have is that moral panickers like you will have got everybody's privacy invaded over your moral panic of the day.

Again, you don't appear to know how this works. Look up fuzzy hash, i even mentioned it in the comment.

I was a kid in the 80s and teenager in the 90s. My favorite thing during that time was pirating video games. A game would come out, and it was cracked, usually within hours and often before the game was even released to be sold. That's when "zero day" had a different meaning. All the "warez" ftp sites had a section for 0 day warez. The cryptologists and math brains would come up with new protection methods to protect their IP from being copied. Spend millions, probably billions for all of these projects. Yet, some kid in their basement with a commodore 64 was always able to crack them. Sometimes it would take longer. There were a few that took years, but once figured out, unlocked hundreds of titles previously secured.

This is, and always is, a game of cat and mouse. Law enforcement is always catching up. They are the cryptologists here. They are never ahead, always behind, because they don't know the new protections peddlers are using until they have been in use and later discovered.

No matter what vector you plug, they will use another, and the game continues (sick game). Maybe divide the image into 32 different quadrants and rearrange them, then put them back in the correct order when viewing through a specific image viewer. I'm sure that would bypass whatever detections they've come up in their fuzzy fingerprinting with as the entire image is now different. By the time they catch someone using this, they'll have already moved on to something different, as they always do.

I will never be ok with warrantless searches of my personal property, no matter the reason or justification or subject, and no matter who it is done by (government or private company). And I say that as a survivor of some pretty horrific shit as a kid to the point I fucking tremble with absolute rage when thinking about it 35+ years later. I would be banned from everything for life if I were to honestly state what I would do with these types of people. The movie "Saw" is tame in comparison. I have no compassion or sympathy for these sickos. But when reading world history, I can absolutely see the importance of "innocent until proven guilty" and Blackstone's Ratio "It is better that ten guilty persons escape than that one innocent suffer." Most of human history was the opposite, and it was brutal and full of literal witch hunts. Are we progressing as a species, or regressing in terms of human rights when it comes to technology?

Re: Apple plans to scan US iPhones for child abuse imagery

#276
post #172
post #124

Earlier quoted context omitted.

Don't worry, AI is very good at these things and never makes mistakes. It is so advanced it even understands nuance and complex communication mechanisms like sarcasm in text, even if it's only a single sentence to contrast! It will be able to know exactly the context of each image and it will affect only the sickos. We're also working on watching your face through the camera to see your true expression when viewing t…

There is zero AI classification involved, it’s a lookup vs hashes of known child porn images. You would need a hash collision, misidentified photo in the dataset, or legitimate use case to end up with a false positive.

Ok. Hashed-based image rec. Where are the hashes? Is the comparison done in my phone against a downloaded database, or is a hash of every image on my phone uploaded for comparison on a server? Could this program then be expanded to other classes of images? Animal abuse imagery? Terrorism? Hashes of known bomb-making instructions? How about people sharing illegal pdfs and text files? Will the MPAA be allowed to submit hashes of their copyrighted material? In short: What other warrantless government inspections of my files will Apple allow?

Re: Apple plans to scan US iPhones for child abuse imagery

#277

Earlier quoted context omitted.

> "The odds of This number is equivalent to generating 1 billion UUIDs per second for about 85 years." If we're talking about random files, sure. What if the files are intentionally created to match the desired hash? The malicious actor doing this could be a private party intending to disrupt your life, but it could also be law enforcement as a means of gaining access to your device when it would otherwise require a…

Couldn't someone that motivated come up with a dozen other ways to frame someone? This seems a little alarmist to me.

Once someone develops the tool for that, it WILL become available in the wild. Then, any script kid will be able to "swat" you in a even more insidious way.

Re: Apple plans to scan US iPhones for child abuse imagery

#278
post #102
post #23

Earlier quoted context omitted.

What will happen is that criminals who actually had bad intent will move off of the platform and the ones who get the brunt of the blame are the innocent who had no ill intent.

The process is described above, but it’s very hard to “innocently” end up with one of those images that they are looking for from the database. And the way it’s being done (hashes), a collision is highly unlikely. If it does occur it doesn’t mean it’s similar in nature (e.g. innocent picture of own child in bath). The hash isn’t looking at the image content in the sense of “what’s in the picture”, just the bits of th…

Presuming that is what they're doing, it won't stay that way for long.

It's absurdly easy to change the hash of a file. In the case of something like JPEG, you don't even have to change the file itself, you can just change the metadata. Apple could presumably only hash the image itself, but again, all you have to do is make tiny, imperceptible to humans changes to the image and the hash is totally different.

Long story short, this is either nearly pointless and privacy invasive, or it's about to get drastically more invasive to be effective.

Re: Apple plans to scan US iPhones for child abuse imagery

#279
post #31

Earlier quoted context omitted.

> perfectly innocent photos on someone's phone of their own children They are using a library of human verified images to compare the hashes. Probably similar to PhotoDNA[0]. There can be false positives, but AFAIK the algorithms are not trying to identify naked children, but comparing 2 similar image hashes. [0] - https://en.wikipedia.org/wiki/PhotoDNA

It's still bad. I used to scrape pictures from many legal pornography sites. I still have hundreds of thousands of pictures. Since many are user uploaded, I imagine a small number could be real CP. Thank God, I don't use Apple. (I should probably delete them, since I've basically never used them... although they could be useful for one of those end-of-world Raspberry Pi builds: https://back7.co/home/raspberry-pi-quic…

> Since many are user uploaded, I imagine a small number must be real CP.

I mean, that is actually illegal. The problem here is the possession of child pornography.

Re: Apple plans to scan US iPhones for child abuse imagery

#280
post #172

Earlier quoted context omitted.

There is zero AI classification involved, it’s a lookup vs hashes of known child porn images. You would need a hash collision, misidentified photo in the dataset, or legitimate use case to end up with a false positive.

Ok. Hashed-based image rec. Where are the hashes? Is the comparison done in my phone against a downloaded database, or is a hash of every image on my phone uploaded for comparison on a server? Could this program then be expanded to other classes of images? Animal abuse imagery? Terrorism? Hashes of known bomb-making instructions? How about people sharing illegal pdfs and text files? Will the MPAA be allowed to submit…

It’s done on Apple’s servers using your iCloud backups. For good or ill this lets people opt out by disabling iCloud.

I would hope most privacy conscious people disable iCloud, but that’s another story.

Post reply on HN