Live data from Hacker News

In internal memo, Apple addresses concerns around new Photo scanning features

9to5mac.com

81–90 of 430 posts

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#81

I don't understand the claim that this system improves their ability to detect anything. If it's really true that the system only works on data uploaded to icloud then apple could have easily just done all the scanning in the cloud, because icloud is not end-to-end encrypted. In that case, all this feature does is move the computational cost of scanning from Apple's datacenters to Apple's users, saving Apple money an…

Respectfully you've missed what this is. This has nothing to do with data sent up to iCloud - at that point not only can those photos be checked via hash they can be further reviewed if there is a positive/high degree match

The issue is that this mechanism applies to photos (/data) on the local device that wouldn't otherwise make its way up to iCloud.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#82
> Today marks the official public unveiling of Expanded Protections for China, and I wanted to take a moment to thank each and every one of you for all of your hard work over the last few years. We would not have reached this milestone without your tireless dedication and resiliency.

> Keeping China safe is such an important mission. In true Apple fashion, pursuing this goal has required deep cross-functional commitment, spanning Engineering, GA, HI, Legal, Product Marketing, PR and the CCP. What we announced today is the product of this incredible collaboration, one that delivers tools to protect China, but also maintain Apple’s deep commitment to user privacy.

> We’ve seen many positive responses today. We know some people have misunderstandings, and more than a few are worried about the implications, but we will continue to explain and detail the features so people understand what we’ve built. And while a lot of hard work lays ahead to deliver the features in the next few months, I wanted to share this note that we received today from NCMEC. I found it incredibly motivating, and hope that you will as well.

> I am proud to work at Xinjiang with such an amazing team. Thank you!

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#83
post #64
post #61

Earlier quoted context omitted.

Then ask yourself why they shipped this scanning on the client-side. This is the first step towards normalizing client-side scanning of encrypted content across the entire device .

Hopefully so they can remove their current ability to decrypt user photos for whatever reason they want. The current state is they can decrypt any user photos on iCloud. Doing client side scanning and this CSAM detection implementation could allow them to remove their ability to decrypt EXCEPT in very specific situations. It's not true end-to-end encryption since in some cases the content can be decrypted without the…

If they can decrypt in a “specialized” situation, then they can decrypt in any situation. All that has to be done is to broaden the classifier step by step. Or someone else gets access to the back door. That’s why there can be zero allowed back doors.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#86

I don't understand the claim that this system improves their ability to detect anything. If it's really true that the system only works on data uploaded to icloud then apple could have easily just done all the scanning in the cloud, because icloud is not end-to-end encrypted. In that case, all this feature does is move the computational cost of scanning from Apple's datacenters to Apple's users, saving Apple money an…

I must have the same misunderstanding. I don’t know why this has to be device side for iCloud photos..

Because security researchers imply Apple eventually plan to turn this on for all local photos, even with icloud turned off.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#89

Apple's mistake is that they seemingly believe there is pushback because people misunderstand how it works. The reality is more nuanced: People understand exactly how it works, and how it works is that it is turn-key onboard spyware, that Apple pinky-swears isn't being used wrong today . For example if the scope/mission expands (e.g. foreign governments), suddenly you've created a drag-net for whatever "badness" is o…

Sometimes the slippery slope is not a fallacy, but the natural consequence of seeking more control. This feature can be horribly misused in the future, for example, to find people who have sent/received/downloaded Tiannanmen pictures, because instant messaging pictures can be automatically added to your albums. You can't trust a feature whose only impediment from being abused in the future is such pinky promise.

Add hashes of police uniforms and now you cannot take pictures of law enforcement.

Add hashes of politicians. Businessmen in suits. Army uniforms.

At the end you have a weapon that can only shoot civilians.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#90
post #61

Earlier quoted context omitted.

Then ask yourself why they shipped this scanning on the client-side. This is the first step towards normalizing client-side scanning of encrypted content across the entire device .

Why would Apple want to do this? It doesn’t benefit them at all. Their competitive advantage is having people trust their devices, if not their values. People are making an extreme claim that Apple went out of their way to implement a fancy system to ruin their own value proposition, and the evidence they have to offer is mere speculation.

You seem to be operating under the assumption that device owners are the only customers of the Apple ecosystem.
Post reply on HN