Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

701–710 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#701

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

Well, it's a lot like everything. No one wants abusers, murderers, and others out and about. But then, we can't search everyone's homes all of the time for dead bodies, or other crimes.

We would all be better off without these things happening, and anyone would want less of it to happen.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#702

Earlier quoted context omitted.

Indeed, I'm guessing this must be some cultural shift that was successfully implanted in some cultures because I too find the idea completely bonkers.

If babies playing naked are now child pornography, most Europeans above 50 should be jailed. As that seems unlikely, I guess CSAM just uses a constantly updated database of known hashes for matching.

It doesn't mean they can't look at the matches without jailing you (still a violation of privacy).

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#703
I think a lot of people are missing why apple is doing this now. They're doing this because they have a fairly secure eco system. They have also create a proxy that makes it difficult (impossible according to them) to know the client. More than likely this was implemented so when it does go to congress, they can say look we implemented a system. Otherwise the DOJ will continue to push for no encryption or backdoor encryption. There's no winning here.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#704
post #58

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

The NCMEC database that Apple is likely using to match hashes, contains countless non-CSAM pictures that are entirely legal not only in the U.S. but globally. This should be reason enough for you to not support the idea. From day 1, it's matching legal images and phoning home about them. Increasing the scope of scanning is barely a slippery slope, they're already beyond the stated scope of the database.

NCMEC is an private organization created by the U.S. Government, funded by the U.S. Government, operates with no constitutional scrutiny, operates with no oversight / accountability, could be prodded by the U.S. Government, and they tell you to "trust them".

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#705
post #645

Earlier quoted context omitted.

The NCMEC, who manages the CSAM database, is a private organization.

Wait, so two American companies, Apple and NCMEC, are working together to install spyware on all Apple devices world-wide, with no government involvement?

https://news.ycombinator.com/item?id=28081184 It's a bit worse than that.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#706

Earlier quoted context omitted.

>I would add that people have generated legal images that match the hashes. That seems like a realistic attack. Since the hash list is public (has to be for client side scanning), you could likely set your computer to grind out a matching image hash but of some meme which you then distribute.

The NCMEC hash list is private, and adversarial attacks require running gradient descent and being able to generate a hash value for arbitrary input.

At least one of these two things must be true: either Apple is going to upload hashes of every image on your device to someone else's server, or the database of hashes will be available somehow to your device.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#707
post #603
post #569

Earlier quoted context omitted.

The alternative is? Google phone? This is not an alternative if you care about privacy. The allegory presented sounds insane (growing your own food) but honestly if you're not rolling your own flashed ROM on a 'droid then your privacy is dead already; I understand throwing all your eggs in one basket is a terrible idea but Apples walled garden and heavy sandboxing was at least somewhat protective.

One option is getting a Phone that has an unlocked bootloader so one can load their own ROM without Goople Play Services. I have a Pixel 3a with LineageOS, no Google Play. I'm pretty happy with it. While the Pinephone isn't perfect yet, I would argue it will be able to replace Android/iOS in a few months.

Indeed it is still possible to get a Pinephone, Librem 5, or an Android phone with an unlockable bootloader such as Fairphone (in Europe), Teracube, and lots of Samsung Galaxy phones and put LineageOS on it.

The issue is that "the masses" just "go with the flow" and act like if everybody else is jumping off a cliff then it's ok to jump off a cliff too, and it is these mobs that move the markets and determine which products and services become the most popular.

However, in relatively free countries it is still possible to live one's life on one's own terms and not be in the same herd with the sheeple. It is definitely possible to live life without an iPhone and to have an Android phone with F-Droid rather than the Google Play Store as one's primary phone.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#708
post #634
post #569

Earlier quoted context omitted.

The alternative is? Google phone? This is not an alternative if you care about privacy. The allegory presented sounds insane (growing your own food) but honestly if you're not rolling your own flashed ROM on a 'droid then your privacy is dead already; I understand throwing all your eggs in one basket is a terrible idea but Apples walled garden and heavy sandboxing was at least somewhat protective.

Alternative is crowdfunding to create something like Pinephone, etc.

Like Teracube and Light Phone. For ppl in Europe I recommend Fairphone -- probably the best phone there is right now.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#709

Earlier quoted context omitted.

> closed social networks It’s not clear that governments would give the open social networks an easier ride either. It could be argued that distributed FOSS developers are easier to pressurise into adding back doors, unless we officially make EFF our HR/Legal department. The other problem is workers have a right to be paid. The alternatives are FOSS and/or distributed social media. Who in good conscience would ask a…

> It could be argued that distributed FOSS developers are easier to pressurise into adding back doors All millions of them at the same time?

But the nature of FOSS software is such that if an undesirable feature is added it can be taken out by the user or the project can be forked.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#710

The slippery slope argument is that the use of this method on private files, i.e. not shared with others except for the service provider can legitimise the expansion of such scamming scopes. While this argument can and have indeed happened in other instances, this is akin to saying that we should not give anyone any powers to do anything because it is a slippery slope that they can use it to do bad things. What then…

I think the checks and balances are pretty fragile and very susceptible to public opinion. Two instances: 1) Post 9/11 Patriot Law 2) McCarthy era: https://www.e-ir.info/2011/11/03/the-extraordinary-injustice...

Sure. And as I mentioned, there will be screw ups along the way. As with any new capability/tech be it nuclear power or recombinant DNA or ability to locate CP, there can be legitimate uses that we can rally behind and ways for them to be abused.

Checks and balances are never a done deal. If we reject checks and balances and as a result reject new tech because of abuse potential, how then should we as a civilisation advance?

Post reply on HN