Live data from Hacker News

Apple’s new abuse prevention system: an antritust/competition point of view

blog.quintarelli.it

111–120 of 318 posts

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#111
post #73

Earlier quoted context omitted.

> Someone who posesses an action movie likes action movies, while someone who posesses child porn likes child porn. Unless it's planted. [0] Or sent to you. [1] Or (farther out there) happens to be embedded on a site you visited and ends up in your browser cache. [0]: https://www.nytimes.com/2016/12/09/world/europe/vladimir-put... [1]: https://www.nytimes.com/2019/06/17/nyregion/alex-jones-sandy...

It only scans images in your iCloud Photo Library. Not paying for iCloud? No scanning. Not in your photo library? No scanning. And even then, only for known content, not new content.

So the attacker only needs to get access to your iCloud. Your iPhone will happily sync down photos uploaded elsewhere.

You don't have to be paying for iCloud, either. There's a free tier, so I'd imagine almost all iPhones are using some tier of it.

iCloud account break-ins aren't exactly rare. An accusation, even if false, could ruin an innocent person's life.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#112
post #108

Earlier quoted context omitted.

It’s not naive, it’s math.

It's not a math problem, it's a human problem. suppose you have a partner who is a 'petite' woman of 34. She enjoys posting nudies on a website, but without her face in that picture. Someone who collects child porn downloads it, because he enjoys that picture. A year later he gets caught by the police and all his pictures get marked as 'verified child porn'. Suddenly you get marked as owning child porn.

That isn’t CSAM.

https://www.nytimes.com/interactive/2019/09/28/us/child-sex-...

Apple’s thing has some sort of threshold anyway so one image would not trigger it. I don’t buy your example - the CSAM images are not what you’re describing.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#113

> But when a backdoor is installed, the backdoor exists and history teaches that it’s only a matter of time before it’s also used by the bad guys and authoritarian regimes. Problem is that this scanning is necessarily fuzzy and there is going to be a false positive rate to it. And the way that you'll find out that you've tripped a false positive is that the SWAT team will knock your door down and kill your dog (at a…

>Problem is that this scanning is necessarily fuzzy and there is going to be a false positive rate to it. And the way that you'll find out that you've tripped a false positive is that the SWAT team will knock your door down and kill your dog (at a minimum).

Not true. Hash matches are to be human reviewed. So no, people won't get "swatted" accidentally as you allege.

The other concerns people have been voicing are certainly valid though (IMHO).

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#114
post #45

Earlier quoted context omitted.

This is a great point. You don't even need to unlock an iPhone to take a picture. So in theory anyone with access to your phone for a few seconds could incriminate you with little effort.

This is not true. The check is only against known CSAM hashes.

Just photograph a known bad picture.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#115

Earlier quoted context omitted.

I would say most (if not all) know how easily you can change the scope of a database like this(like you said yourself) to check for other inconvenient terms, links, memes, etc that do not "toe the party line"(whether is eastern or western - I don't care) and shut down inconvenient discourse. The point is: This is too easy to abuse.

Being specific with the arguments and addressing the nuance matters imo. Most of the HN responses are dumb, get the details wrong, and don’t take the trade offs seriously. That kind of thing causes me to dismiss them entirely. There are legitimate arguments and risks which I’d concede, but they’re not what most people in the comments are talking about.

The trade-off here is to get pedophiles off of Apple services and on to something else, we give Apple an entry point into examining our private data. I understand it's hashes now, that does nothing to prevent this from expanding.

"People just don't understand!!" has never been a convincing argument.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#116
post #45

Earlier quoted context omitted.

This is a great point. You don't even need to unlock an iPhone to take a picture. So in theory anyone with access to your phone for a few seconds could incriminate you with little effort.

This is not true. The check is only against known CSAM hashes.

Picture of a picture?

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#117

Earlier quoted context omitted.

This is not true. The check is only against known CSAM hashes.

Just photograph a known bad picture.

Then that's a different photo and will have a different hash.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#118
post #75

Earlier quoted context omitted.

Were iCloud photos already scanned CSAM? In the on-device system, if you're not using iCloud are the photos scanned? If that's true, as an iCloud user you are exactly as likely to be charged with a crime based on your photos as you were before, but you now get E2E encryption. Obviously I'd prefer E2E without any scanning. If I wanted to upload a pirated mp3 to icloud, I wouldn't want the RIAA knocking on my door. How…

> If that's true, as an iCloud user you are exactly as likely to be charged with a crime based on your photos as you were before Is this strictly true? I feel like the evidence that a photo was present on specific device is different from evidence that a photo was uploaded by a specific account (and a specific ip address probably). It seems like it would be far easier for the government to justify a search warrant if…

Maybe there’s some plausible deniability if a warrant uncovered nothing - but I think they would always be able get a warrant and try to find the device and more evidence based on the upload.

From what I’ve read the on-phone scanning only alerts after multiple photos and is designed to have a 1 in a trillion false positive rate. If the iCloud scan is similar they would have a strong case for getting a warrant based on uploads.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#119
post #93

Earlier quoted context omitted.

This is wrong - the iCloud check is against known CSAM hashes, the false positive rate is essentially zero.

This seems naive, there are always false positives

No. You can design a system where the FPR is essentially zero. Even if shitty md5 is used.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#120
post #115

Earlier quoted context omitted.

Being specific with the arguments and addressing the nuance matters imo. Most of the HN responses are dumb, get the details wrong, and don’t take the trade offs seriously. That kind of thing causes me to dismiss them entirely. There are legitimate arguments and risks which I’d concede, but they’re not what most people in the comments are talking about.

The trade-off here is to get pedophiles off of Apple services and on to something else, we give Apple an entry point into examining our private data. I understand it's hashes now, that does nothing to prevent this from expanding. "People just don't understand!!" has never been a convincing argument.

This is just a slippery slope argument.

The implementation specifically for detecting CSAM can be okay while using that for other purposes can not be okay.

The goal is to stop child sexual abuse, FB reports millions of cases a year with a similar hash matching model for messenger.

> ""People just don't understand!!" has never been a convincing argument."

That's not my argument - I just think most of the HN comments on this issue both miss the relevant details, and are wrong.

Post reply on HN