Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

741–750 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#741
post #492
post #384

Earlier quoted context omitted.

Not POTS, but cell phones could have been E2E at least since cellular switched to digital.

The first digital phones ran on 56 bit (symmetric?) encryption. They certainty weren't powerful enough to run public key cryptography at safe key sizes, which is needed for secure e2e.

Not at key sizes considered safe today, but 384 bit RSA was considered secure for some uses around then.

The RSA-155 Challenge (512 bits) was not beaten until 1999.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#742
post #729

Earlier quoted context omitted.

Unless I'm missing something, those are just theoretical examples of how one could potentially deliberately try to find hash collisions, using a different, simpler perceptual hash function: https://twitter.com/matthew_d_green/status/14230842449522892... So, it's theoretical, it's a different algorithm, and it's a case where someone is specifically trying to find collisions via machine learning. (Perhaps by "reversing…

You're not missing something, but you're not likely to get real examples because as I understand it the algorithm and database are private, the posters above are just guardedly commenting with (claimed) insider knowledge, they're not likely to want to leak examples (and not just that it's private, but with the supposed contents.. Would you really want to be the one saying 'but it isn't, look'? Would you trust someone…

To be clear, I definitely didn't want examples in terms of links to the actual content. Just a general description. Like, was a beach ball misclassified as a heinous crime, or was it perfectly legal consensual porn with adults that was misclassified, or was it something that even a human could potentially mistake for CSAM. Or something else entirely.

I understand it seems like they don't want to give examples, perhaps due to professional or legal reasons, and I can respect that. But I also think that information is very important if they're trying to argue a side of the debate.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#743
post #695
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

Fuck you.

Could you please stop posting flamebait and unsubstantive comments? We ban accounts that post like this, obviously.

https://news.ycombinator.com/newsguidelines.html

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#744

Earlier quoted context omitted.

The NCMEC, who manages the CSAM database, is a private organization.

Not quite, they're an NGO and the CyberTipline which it operates (the database Apple will use) was established by S.1738 [PROTECT our Children Act of 2008], and they get an appropriation from Congress to run that and work with law enforcement. It's kind of like the PCAOB... private 501.3(c) with congressional oversight and funding. I think the strategy is that the organization is able to do more for helping children…

Interesting how that shields them from any and all government transparency.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#745

Earlier quoted context omitted.

The NCMEC hash list is private, and adversarial attacks require running gradient descent and being able to generate a hash value for arbitrary input.

Is it possible to narrow in on a hash using gradient descent? You can correlate distance between inputs to distance between hashes somehow?

Replying to my own question since I can’t edit anymore: it turns out “perceptual hashing,” which I didn’t know much about, has exactly this property, that small changes in the input result in small changes in the output.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#746

So if I understand correctly, they want to scan all your photos, stored on your private phone, that you paid for, and they want to check if any of the hashes are the same as hashes of child porn? So... all your hashes will be uploaded to the cloud? How do you prevent them from scanning other stuff (memes, leaked documents, trump-fights-cnn-gif,... to profile the users)? Or will a huge hash database of child porn hash…

No-no-no. It's not your phone. If it was your phone - you would have a root access to it. It's their phone. And it's their photos. They just don't like when there's something illegal on their photos, so they will scan it, just in case.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#747
post #488

Earlier quoted context omitted.

I’m not sure this is true? The $1000 version has absolutely ridiculous performance for it’s price class. To the point it’s nearly as good as my desktop system.

My desktop system is a 24-core Zen 2. The M1 shouldn't be faster, and I'm certain the difference is almost purely a matter of software, but in reality the M1 certainly feels a lot faster. Yes, the desktop has higher throughput. Of course it does. But that doesn't mean I don't feel a fraction of a second's lag whenever I do basically anything, and on the M1 that just... doesn't exist.

FWIW in a benchmark of a lua parser my friend is writing my M1 beat my 5950X Ryzen by a factor of 2x. According to him the L1/L2 cache makes the difference.

So it's not just a matter of feel.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#748
post #570

Earlier quoted context omitted.

> Perhaps heed the warnings? And then take what actions, exactly? “Guys this is trouble” is …fine, but without “and we should therefore do”, it’s just kind of spitting into the wind.

The first ( and only ) way to solve any problem is to first admit it is a problem. It doesn't even need to be an "action". You will have to be at least conscious of what is happening. That is not what is happening, right now ( or before that ) many are defending Apple, and also an attitude of not "my problem". Writing off any warning as either pessimistic or conspiracy. Having some healthy dose of skepticism is somew…

Yeah I think a lot of us are conscious of the problem but you're right, the scale/critical mass isn't quite there yet hmm.

BTW I think one of the roots of our problem is that we seem to end up in these really weird "winner take all" distributions with only 2-3 main winners and rarely any serious alternatives. It happens with operating systems, browsers, it also happens within programming language communities, like Javascript, etc. Everybody piles up into one of the 2-3 most popular framework options (React, etc). Same thing for Linux distributions. etc.

It would be nice if we could figure out some sort of nudge or hack that would reduce this tendency and encourage more distribution of mass.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#749
post #729

Earlier quoted context omitted.

You're not missing something, but you're not likely to get real examples because as I understand it the algorithm and database are private, the posters above are just guardedly commenting with (claimed) insider knowledge, they're not likely to want to leak examples (and not just that it's private, but with the supposed contents.. Would you really want to be the one saying 'but it isn't, look'? Would you trust someone…

To be clear, I definitely didn't want examples in terms of links to the actual content. Just a general description. Like, was a beach ball misclassified as a heinous crime, or was it perfectly legal consensual porn with adults that was misclassified, or was it something that even a human could potentially mistake for CSAM. Or something else entirely. I understand it seems like they don't want to give examples, perhap…

> Just a general description.

I gave that above in a sibling thread.

> I understand it seems like they don't want to give examples, perhaps due to professional or legal reasons, and I can respect that.

In my case, it’s been 7 years so I’m not confident enough of my memory to give a detail description of each false positive. All I can say is that the photos that were false positive that included people were either very obviously fully clothed and doing something normal, or the photo was of something completely innocuous all together (I seem to remember an example of the latter was the Windows XP green field stock desktop wallpaper, but I’m not positive on that).

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#750

Earlier quoted context omitted.

See my answer to your sister comment from @optimiz3 In Germany police requested contact tracing lists from restaurants in investigations.

Thank you, it clearly shows that the German government cannot be trusted to do the right thing. And the underlying desire for having this information will no doubt prolong the Corona restrictions longer than necessary, which is certainly not in the interest of German citizens.

> German government cannot be trusted to do the right thing

Oh dear, one thing we could definitely state that German government is absolutely could be trusted to do the right thing

Post reply on HN