Live data from Hacker News

Apple’s new abuse prevention system: an antritust/competition point of view

blog.quintarelli.it

151–160 of 318 posts

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#151
post #115

Earlier quoted context omitted.

The trade-off here is to get pedophiles off of Apple services and on to something else, we give Apple an entry point into examining our private data. I understand it's hashes now, that does nothing to prevent this from expanding. "People just don't understand!!" has never been a convincing argument.

This is just a slippery slope argument. The implementation specifically for detecting CSAM can be okay while using that for other purposes can not be okay. The goal is to stop child sexual abuse, FB reports millions of cases a year with a similar hash matching model for messenger. > ""People just don't understand!!" has never been a convincing argument." That's not my argument - I just think most of the HN comments o…

Slippery slope fallacy is often implied incorrectly when it comes to people. Human nature is subject to the "foot in the door" sales tactic.

https://en.wikipedia.org/wiki/Foot-in-the-door_technique

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#152
post #146

Earlier quoted context omitted.

If you actually think there is going to be a fully automated system dispatching police SWAT teams throughout the US without a manual (or judicial) review then.... I really don't know what to tell you.

It'll all be shadow-ban type stuff, your account will be turned off, without appeal, things of that nature.

That's a different thread of comments. This one is about automated dispatching of SWAT teams.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#153

> But when a backdoor is installed, the backdoor exists and history teaches that it’s only a matter of time before it’s also used by the bad guys and authoritarian regimes. Problem is that this scanning is necessarily fuzzy and there is going to be a false positive rate to it. And the way that you'll find out that you've tripped a false positive is that the SWAT team will knock your door down and kill your dog (at a…

This is wrong - the iCloud check is against known CSAM hashes, the false positive rate is essentially zero.

This isn’t a normal file hash. It’s not SHA or bcrypt. A wide variety of states (1s and 0s) can have the same hash.

The idea is to take an image and have all of its possible derivatives create the same hash.

For example, if a hash was made of the Mona Lisa, any copy no matter how large, small, black and white, would have the same hash.

Think of all the ways the Mona Lisa could be transformed and still be the Mona Lisa.

The combinations of ones and zeros would be in the billions. If not more.

And all those possible combinations of ones and zeros go back to the same “hash.”

That’s extremely resourceful intensive.

My guess is that they are going to transform the images into a very low resolution, black and white thumbnail. Then compare it against known abuse images that have been similarly transformed.

Or they’re using AI. They might be using AI.

Either way, it’s guesswork. How many images might be transformable to the same black and white thumbnail. I don’t know.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#155
post #113

> But when a backdoor is installed, the backdoor exists and history teaches that it’s only a matter of time before it’s also used by the bad guys and authoritarian regimes. Problem is that this scanning is necessarily fuzzy and there is going to be a false positive rate to it. And the way that you'll find out that you've tripped a false positive is that the SWAT team will knock your door down and kill your dog (at a…

> Problem is that this scanning is necessarily fuzzy and there is going to be a false positive rate to it. And the way that you'll find out that you've tripped a false positive is that the SWAT team will knock your door down and kill your dog (at a minimum). Not true. Hash matches are to be human reviewed. So no, people won't get "swatted" accidentally as you allege. The other concerns people have been voicing are ce…

Eh, humans make mistakes, that may reduce the false positives but if this program runs long enough, I'm sure it will happen to someone when someone accidentally presses the wrong button.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#156
post #81

Earlier quoted context omitted.

> Society has decided both are separate crimes Actually it's legislators and the courts that come up with these laws and they are complicated. The question is if these laws reduce child abuse or simply increase spying, and in the end what is the acceptable balance between these two.

Legislators are a proxy for society. Do you believe that if you polled the US that any sizable portion of the country would be in support of legalizing CP?

If you polled the population, chances are they'd support torture, rape and execution as punishment for abusers.

The real crime is child abuse. Material related to that is also illegal because it presumably creates demand for the abuse. Whether that's actually true I don't know.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#157
I don't see why we would believe they are not already doing this? Today's news is just that they can now legally take action on it.

Also the whole SWAT scenario is a bit far-fetched, as they will most likely read thru your entire life (don't forget they already have access to it) to make sure they don't look stupid on the news.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#158
post #92

Earlier quoted context omitted.

This is wrong - the iCloud check is against known CSAM hashes, the false positive rate is essentially zero.

One in one trillion chance per year, per the paper on the Apple site.

I would like to bet Apple's market value against that number being correct in an adversarial context.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#159
post #88

It'll start with protecting children. We all want to protect children, don't we? Why do you want children abused? Are you a child abuser, what do you have to hide? Next it's elderly people. We don't want our forgetful elders to get lost, do we? What if grandma wanders off but is in someone's picture, surely you want the police to know right that second where she is? Next up, terrorists! Four adult brown men in an unm…

> It'll start with protecting children. We all want to protect children, don't we? Why do you want children abused? Are you a child abuser, what do you have to hide? To be clear, this is continued enforcement for years-old regulation. The feature is only enabled in the US where it is required. The implementation is changing from cloud-based matching (which requires photos to be readable by their cloud infrastructure)…

> while making the system E2E encrypted w two additional key release mechanisms (key escrow via separate audited HSM systems, the given threshold disclosure of the image encryption key)

such a long sentence to say "backdoor"

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#160
post #88

It'll start with protecting children. We all want to protect children, don't we? Why do you want children abused? Are you a child abuser, what do you have to hide? Next it's elderly people. We don't want our forgetful elders to get lost, do we? What if grandma wanders off but is in someone's picture, surely you want the police to know right that second where she is? Next up, terrorists! Four adult brown men in an unm…

> It'll start with protecting children. We all want to protect children, don't we? Why do you want children abused? Are you a child abuser, what do you have to hide? To be clear, this is continued enforcement for years-old regulation. The feature is only enabled in the US where it is required. The implementation is changing from cloud-based matching (which requires photos to be readable by their cloud infrastructure)…

Could you point to the regulation that requires this?
Post reply on HN