Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

71–80 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#71
post #33
post #7

I was actually looking to buy the new iPhone should they add back TouchID, but this has been quite the turnoff. Are Pixel phones the only android phones that allow you to do secure boot with non stock images and basically long term cripple phone functionality once its unlocked?

Google does the same with Google Drive. Apple is just late for the party.

Apple does the same with iCloud as Google does with Google Drive.

Apple just now moved it to scan on the device.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#72
post #63
post #46

Earlier quoted context omitted.

They said FOSS, not OSS. F means free as in freedom. As in you’re free to modify the software running on your phone at will and to your liking and Apple or some government can’t get in your way.. not even for the kids .

So all 12 people in the world who know how to read, modify and install and OS can run their paranoid versions of iOS?

If it were FOSS one person could build a paranoid version and everybody else could use it.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#73
post #63
post #46

Earlier quoted context omitted.

They said FOSS, not OSS. F means free as in freedom. As in you’re free to modify the software running on your phone at will and to your liking and Apple or some government can’t get in your way.. not even for the kids .

So all 12 people in the world who know how to read, modify and install and OS can run their paranoid versions of iOS?

Personally I'm hugely in favour of phrasing it in terms of "Right to Repair". Most people don't know how to repair their car or John Deere tractor either: and that's where the experts come in who do it for you.

In this case, you or me might be the expert, who can provide solutions for other people such as an "installer" to do whatever.

I personally don't really have a problem with Apple's plan here by the way; I think the way they're doing it is actually quite balanced and reasonable. But other people should be free to make a different personal decision on this. What I would like is to modify some other aspects of my iPhone though, like some things on the keyboard that still bug me after several years.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#74
post #67

I’m not sure what to think of the backlash here. I’m sure that people aren’t trying to minimize the evil of child pornography and exploitation. But anything that has the potential to stop or slow it should be fairly considered. People complaining that Apple is scanning your photos, they are already doing that. Where was this backlash when they released the memories feature? Why is scanning your photos for good pictur…

The concern is less about outing people with CSAM and more about Apple building a powerful tool for government surveillance that will most certainly be abused by countries like China and Saudi Arabia when they request that politically dangerous images be added to the database if Apple wants to continue business in their country. It is incredibly myopic of Apple to implement this feature. You must consider, as an engi…

This isn't a powerful tool, it's more akin to a rudimentary hash check. It's not going to match photos that aren't already known to authorities. And any time a user is flagged, the material in question is sighted by an Apple employee before a decision is made whether to forward it onto the relevant authorities.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#75
post #3

Because it’s based on machine learning, why can’t some of the network and weights used for the hash be shared? So we can be sure it is not possible to match anything else than children. The sub narrow network used for detecting only CP is of course secret, but then we know it can’t be used for revealing pictures of police, activists etc

Because the technology is not the point. I just don’t want Apple to search anything in my photos. Because those are my photos. Not theirs. My phone doesn’t need a program that search for abused child photography since there is not such material on it.

I don’t care if their thing is open or closed source : My iPhone is mine and I don’t want them to do anything on it that can get me arrested because of a false positive.

We must not accept those intrusions.

This thing is as serious as if IKEA regularly sent robots in your house to check all the photo albums on your IKEA shelf to check them against some database. Why does it sounds dumb when it’s IKEA but more acceptable when it’s your phone constructor ?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#76

At this point we need to be doing more than signing open letters to companies that are completely free to ignore them. If you work for Apple and don't stand up to this, you should find it extremely hard to find employment or acceptance anywhere. If you're a hiring manager, throw the resumes of anyone that worked at Apple in the trash. It should be a black mark on you if you continue to work and contribute to Apple af…

Apple is fundamentally about making Nice Phones, and are among the least morally complicated organizations in the US. If we followed your way, we'd be banning over half the country from occupation. Just look at the moral complexity of the US armed forces, which is entangled in stories of collateral damage from drone strikes, burning of opium fields in Afghanistan, or hundreds of thousands of civilian deaths in Iraq.

I think, at it's core and what drives most people to work there, is Apple is fundamentally about improving humanity's experience through computing.

I don't mean that as a buzzword soup either. They're the most valuable company in the world for a reason. It also means they're the spotlight for all the moral dilemmas we face as a global society more deeply integrating computing into our daily lives. So I have to disagree.

Apple is trying to take a stand saying, "We will be proactive about policing the one activity that nearly everyone considers morally reprehensible," and tacitly they're saying in that, "This is more important than our whole mission to bring privacy back to computing users."

Because what they're building completely invalidates that. They're effectively saying that -- as of August 5, 2021 -- Apple is privacy-hostile.

Then to connect that back to their true mission, or what anyone working for the most powerful computing company in the world ought to consider their true mission: they're about improving the human condition through computing. Working for Apple now signals that you believe humans are better off without privacy.

Buying from Apple now signals that you believe humans are better off without privacy. Apple is privacy-hostile.

It doesn't have to stay that way. There can still be some pride in making short the number of days from August 5, 2021 to the day that Apple makes a stand for the liberty of all humans to feel secure in their ability to use computers in all forms without an ever-watchful million unknown eyes over their shoulder.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#77

At this point we need to be doing more than signing open letters to companies that are completely free to ignore them. If you work for Apple and don't stand up to this, you should find it extremely hard to find employment or acceptance anywhere. If you're a hiring manager, throw the resumes of anyone that worked at Apple in the trash. It should be a black mark on you if you continue to work and contribute to Apple af…

Maybe we should ask for more leaktivism from morally inclined employees instead of trying to push water uphill.

Sunlight disinfects power.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#78
post #49

Earlier quoted context omitted.

Processor microcode is closed source (Intel/AMD), including most of the BIOS code. You are having hard time to build your devices. Maybe we can see change in the future.

* enter RISC-V *

So we force Apple to migrate away from ARM? Or should the next iPhone have a swappable CPU?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#79

I’m not sure what to think of the backlash here. I’m sure that people aren’t trying to minimize the evil of child pornography and exploitation. But anything that has the potential to stop or slow it should be fairly considered. People complaining that Apple is scanning your photos, they are already doing that. Where was this backlash when they released the memories feature? Why is scanning your photos for good pictur…

I think the point is that yes, they have always had the power to do these things - but they haven't thus far. We rely on entities with power (companies, governments, people) to exercise restraint in how they exercise it. Those that DO exercise restraint gain trust since exercising restraint demonstrates an understanding of the consequences of not doing so.

What the Apple move is doing is showing that they are willing to relax their restraint. It gets tricky because everyone agrees that the specific goal here is honorable, but the manner by which they are using their power to achieve it is generalizable to areas that are less honorable. Once they are willing to use their power to accomplish one highly honorable goal, it's not a big ask for them to use it for a slightly less honorable goal in the future. Iterate that a few times and you can find yourself in a very bad place. It's the classic slippery slope argument - when you know there is a slope that leads to dangerous places, you need to not ever start down it no matter how righteous the motive is in starting down that path in the first place. There's a reason we have the old saying "the path to hell is paved with good intentions".

The existence of power isn't what matters: it's the intention and willingness to exercise it. Apple is now demonstrating that they have changed their stance in how they choose to exercise their extreme power. That's worthy of scrutiny.

For a concrete example of where I expect this to naturally lead to: instead of a database of child pornography being the source of the hashes to search for, the Chinese government provides a set of hashes of all known digital photos of the Tianenmen square protests of 1989. Does it really seem implausible for a government like China's to NOT use this kind of technology for that purpose? It's not hard to cook up similar examples all over the place.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#80

Earlier quoted context omitted.

I think this is rather hyperbolic. Vast majority of people at Apple have nothing to do with this. And even people involved in this, I’m not sure how much I can blame them. Soldiers vs generals kind of argument. Also, they likely see the pedo-fighting side of things and think are in the right.

If you work for Apple, you have provided a non-zero amount of support to them and their actions. Even if you're just the janitor that cleans the offices in the evening, you are providing material support. That gives you a non-zero liability for their actions. There are no generals without the soldiers. Yes, maybe for some of their employees its a choice between starving or working for Apple. I bet for the vast majori…

> And even for the ones that would starve, I'm sorry, but I put the well-being of the entirety of society and our collective future over their lives.

God, just listen to yourself.

Personally I think their plans are fairly balanced and reasonable. Like it or not, there are legitimate interests here. It's a difficult trade-off and conversation. Ostracizing people and saying you would literally rather have people DIE is not adding to the conversation. The way you talk about it makes it sound like this is about the Nuremberg laws or something.

Post reply on HN