Live data from Hacker News

Apple’s new abuse prevention system: an antritust/competition point of view

blog.quintarelli.it

121–130 of 318 posts

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#121

Earlier quoted context omitted.

This is wrong - the iCloud check is against known CSAM hashes, the false positive rate is essentially zero.

> the false positive rate is essentially zero I highly doubt that

Based on what? Unless you point out a flaw in the math, it’s zero.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#122
post #80

Earlier quoted context omitted.

I think that's for files uploaded to onedrive etc. Not for all the files on any windows pc

The encouranged windows 10 setting is to sync your whole profile to OneDrive.

Does this imply that apple was not checking the photos stored in their servers for CP? Then icloud must have been the best way to share it

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#123
I don't think this issue is widespread enough and harmful enough to society to risk the privacy of all Apple users. Full stop.

I haven't been particularly impressed with Apple's security record[1] lately, and I don't trust them to not mess this up.

1 - https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-a...

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#124
post #115

Earlier quoted context omitted.

Being specific with the arguments and addressing the nuance matters imo. Most of the HN responses are dumb, get the details wrong, and don’t take the trade offs seriously. That kind of thing causes me to dismiss them entirely. There are legitimate arguments and risks which I’d concede, but they’re not what most people in the comments are talking about.

The trade-off here is to get pedophiles off of Apple services and on to something else, we give Apple an entry point into examining our private data. I understand it's hashes now, that does nothing to prevent this from expanding. "People just don't understand!!" has never been a convincing argument.

I think HN takes the incorrectly perceived moral high ground and ignore the fact that there is a real duty to act here.

There are people who profit from CSAM and in turn this creates a market for abuse. Unless we create structures which disincentivizes these behaviors — right now there are none - they will continue to grow. What Apple is building will basically make any criminal who sells to someone sloppy enough to store in iCloud risk being traced as the origin of the CSAM. Back to the darkest web they go.

Anti CSAM is inevitable. You will find similar systems for all major providers eventually.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#125
post #123

I don't think this issue is widespread enough and harmful enough to society to risk the privacy of all Apple users. Full stop. I haven't been particularly impressed with Apple's security record[1] lately, and I don't trust them to not mess this up. 1 - https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-a...

Why do you think this?

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#126

Earlier quoted context omitted.

Just photograph a known bad picture.

Then that's a different photo and will have a different hash.

These aren’t cryptographic hashes. They are perceptual hashes and a picture of a picture could absolutely end up with the same phash value.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#127

Earlier quoted context omitted.

Just photograph a known bad picture.

Then that's a different photo and will have a different hash.

is there really no fuzziness to it? If not, can’t this be defeated by simply reencoding the image?

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#128
Why stop at scanning photos in your phone?

With lower power sensors, head-mounted devices with always-on-sensors, and whatnot, why not sample real-time hashes that can tip LEO about potential crimes happening?

Then why sacrifice recall in order to achieve high accuracy?

Err on the side of uploading more hashes. Then feed it all into a ML so it can use other data to filter out potential false positives.

Then if in a distance future, any LEO wants to investigate you for whatever reason, the set of potential hashes associated with your account will provide sufficient evidence for any court to authorize further non-hashed data access (it doesn't matter if they were all false positives)

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#129
post #80

Earlier quoted context omitted.

The encouranged windows 10 setting is to sync your whole profile to OneDrive.

Does this imply that apple was not checking the photos stored in their servers for CP? Then icloud must have been the best way to share it

It at least looks like apple is the last one to do this. google, flickr, facebook, twitter etc did this since forever.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#130
post #28

There is no such thing as a trustworthy third party and even trusting yourself is questionable at the best of times. We are constantly balancing a bunch of different considerations with regards to the way that we compute, purchase devices, and utilize services. Security and privacy are of course important, and Apple to date has had a fairly good (if shallow) track record in this regard, at least in the United States.…

> "As mentioned in the article, this does absolutely nothing towards protecting children other than directing all but the biggest idiots towards platforms that can't be linked to them, which I'd imagine, they already are." I suspect you're more wrong than you think about this. People share large volumes of CSAM through lots of different services - I knew someone who worked on the problem at Linked In (!). HN likes to…

Is CSAM a specific list of images that does not change, or does a government body actively control this list? Is there anything that would technically prevent the addition of a specific image of an enemy of the state? Hypothetical question, how will Apple respond when the FBI asks Apple to scan for images they know are also on the phone of the latest domestic terrorist? And how likely do you think the FBI will try to expand the scope of images that are scanned?
Post reply on HN