Live data from Hacker News

In internal memo, Apple addresses concerns around new Photo scanning features

9to5mac.com

121–130 of 430 posts

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#121
post #64

Earlier quoted context omitted.

Hopefully so they can remove their current ability to decrypt user photos for whatever reason they want. The current state is they can decrypt any user photos on iCloud. Doing client side scanning and this CSAM detection implementation could allow them to remove their ability to decrypt EXCEPT in very specific situations. It's not true end-to-end encryption since in some cases the content can be decrypted without the…

If they can decrypt in a “specialized” situation, then they can decrypt in any situation. All that has to be done is to broaden the classifier step by step. Or someone else gets access to the back door. That’s why there can be zero allowed back doors.

The database ships with iOS. Apple can do anything they want in iOS updates. In fact, this was exactly the “back door” the FBI requested Apple use half a decade ago. Per this standard, all Apple end to end products are already backdoored, and nothing new was announced.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#122

Apple's mistake is that they seemingly believe there is pushback because people misunderstand how it works. The reality is more nuanced: People understand exactly how it works, and how it works is that it is turn-key onboard spyware, that Apple pinky-swears isn't being used wrong today . For example if the scope/mission expands (e.g. foreign governments), suddenly you've created a drag-net for whatever "badness" is o…

Also, there's a "we can't show you the exact CP image that one of yours matched, because that would also be illegal" catch-22 that basically gives them the power to shroud this whole system in legally-obligated secrecy. Secrecy which will no doubt be abused to hide much more.

I do worry this is basically automating and scaling up the whole "idiot working at the mall photo development booth turns family in for child porn because they took pictures of 3 year old in bath" story that shows up every now and then.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#123
post #114

Let’s not confuse the 2 parts that Apple is implementing; - one is parental control, it’s upon request, uses ML, it’s “local” (that is, it’s sent to the parent) - the other one is plain hash matching, which does not “save the children” but rather is “catch the viewer” — exclusively. This has no impact on the abuse of the CSAM subjects because it only matches publicly-known content. I don’t know why NCMEC is excited s…

> I don’t know why NCMEC is excited since stopping the viewer does not stop the abuse, this does not affect them.

They get to keep their jobs :)

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#124

Apple's mistake is that they seemingly believe there is pushback because people misunderstand how it works. The reality is more nuanced: People understand exactly how it works, and how it works is that it is turn-key onboard spyware, that Apple pinky-swears isn't being used wrong today . For example if the scope/mission expands (e.g. foreign governments), suddenly you've created a drag-net for whatever "badness" is o…

And HN's mistake is thinking any of this will matter. Apple only cares about money, always has, always will. And I'm willing to bet they are going to continue beating their revenue and profit record quarter after quarter. When their actions do not affect the one thing they care about, why should they care what anyone says?

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#125

I honestly don't get the uproar here. This is opt-in, so how is it any more outrageous than existing MDM software that people opt-in to for work reasons which are way more invasive?

the CSAM part is not opt-in.

technically you could not update to ios 15 or disable icloud, but it's not opt-in by any means.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#126
I was planning to switch to iPhone this year. I no longer am. I do not want any device that would turn me in to police. For any reason. That is just not okay. To start with, because software has bugs. To end with, because principles matter.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#127
post #100

Earlier quoted context omitted.

Add hashes of police uniforms and now you cannot take pictures of law enforcement. Add hashes of politicians. Businessmen in suits. Army uniforms. At the end you have a weapon that can only shoot civilians.

Do you know how discovery works in court? I'm guessing not. Once a hash matches, law enforcement would need a subpoena to access the raw image. If a person were to be arrested, that evidence would be turned over to the defense. It would be very obvious that a picture of a police officer was not child pornography. Are you under the impression people are jailed for hash collisions? Because that's not the case at all...…

I don't think the suggestion is that a hash of a police uniform will be used to convict of CP but rather the idea that a new law will be passed that - in order to protect the police from 'harassment' - will outlaw taking pictures of the police.

So in that case in discovery the picture of a police officer would be evidence that you broke that hypothetical law. The technology deployed to protect the children opens up the possibility of its deployment for other things later, based on legal requirements of course.

For example don't take pictures of copyrighted material would be something people might want to work on.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#128
Unfortunalty if our experience from the past with such events teaches us anything, it's that a minority of us will stop using apple products (or keep not doing it) but the rest of the world will quickly forget and carry on as usual.

Worse, if your decision to not use an iphone makes others people life slightly anoying for 2 seconds a week, many will bash on you.

As a FOSS user with no FB nor whatsapp account that ask to avoid photos to be taken of him with smartphones, I can tell you I pay regularly the price the price for what I think is doing the right thing. It's just easier to let the abuse go on.

And we have other fights in life. I didnt pick up smoking (pot of cigarets), stopped drinking alcohol, became vegetarian. They all come with social challenges. Add then you have your familly, job, health and goals that needs your care, attention and time.

At some point you just want to say "screw them", create your own bubble of freedom and let them enjoy their distopia. Except we kind of live in it, don't we?

I'm usually an upbeat person but these types of event arrive in a never ending stream, and today I feel tired.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#129

Earlier quoted context omitted.

I didn't say anything about breaking E2E encryption. Anything a human in the middle can review in any event isn't E2E encrypted. Call it something else. The issue is the hash algorithm is secret. The decryption threshold is secret. The database of forbidden content can't be audited. People claim it includes entirely legal images. And it's a small step from scanning local only files.

It's still end-to-end for non-CSAM-matching content. Sounds fair, as long as it's strictly for CSAM check purposes.

> as long as it's strictly for CSAM check purposes

And that's precisely the leaky part of this setup. Nothing about this system's design prevents that from changing on a mere whim or government request.

Next year they could be adding new back-end checks against political dissident activity, Uyghur Muslims, ... and we'd be none the wiser.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#130
post #74

Earlier quoted context omitted.

Could be throwing a bone to politicians who say E2E encryption protects criminals. Not saying I agree, but I could see this being a compromise on Apple's part.

They can’t be this stupid, right? They should know this has huge security implications. I can’t see how it can be justified for some political brownie point.

> They should know this has huge security implications.

I've missed where this has security implications. Did you mean privacy implications?

Post reply on HN