Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

81–90 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#81
post #56
post #44

Earlier quoted context omitted.

That it is. I'm bit fancied of the ignorance of the people, until it is Apple who is doing it. And Apple is minority compared to other platforms. I haven't heard much of complains about Windows sending all your file hashes and most of the files into their servers, what they have been doing a very long time with Windows Defender. It is literally the same what Apple is doing now, but without restrictions. Google and ot…

I don’t use Windows Defender nor Google Photos nor other cloud service providers to scan my photos. I barely use gmail. I knew that Google was terrible so I have already minimized my use of Google services. Same with Facebook. But Apple!? I guess the dominos have finally gotten to me.

It is not so straightforward to not use Windows Defender if you are using Windows 10. You must edit group policies in quite deep to disable automatic scanning and startup.

Google Drive includes backups of your phone, so it is not limited to Google Photos. Literally everything that is stored unencrypted on Google servers.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#82
post #77

At this point we need to be doing more than signing open letters to companies that are completely free to ignore them. If you work for Apple and don't stand up to this, you should find it extremely hard to find employment or acceptance anywhere. If you're a hiring manager, throw the resumes of anyone that worked at Apple in the trash. It should be a black mark on you if you continue to work and contribute to Apple af…

Maybe we should ask for more leaktivism from morally inclined employees instead of trying to push water uphill. Sunlight disinfects power.

Has that ever changed anything? Like, really?

Sure, we get up in arms for a little bit, but come the next news cycle its back to business as usual.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#83

At this point we need to be doing more than signing open letters to companies that are completely free to ignore them. If you work for Apple and don't stand up to this, you should find it extremely hard to find employment or acceptance anywhere. If you're a hiring manager, throw the resumes of anyone that worked at Apple in the trash. It should be a black mark on you if you continue to work and contribute to Apple af…

As much as I dislike what Apple is doing here, Apple is a long way down the list of companies that should be a black mark on your resume.

Oracle is a MUCH better target, for example.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#85
At this stage it doesn't matter if it is carefully calculated effort to gradually strip off people from the very sense of any privacy with longing effects on a society (like I described here [1]) or it's some company trying to legalize Spyware Engine for it's own convenience covering it with some story to justify it. Usually they use children for such cover story because people have direct emotional response to that topic and thus stop thinking for just enough time to miss the important issue.

The important issue here is an attempt of Spyware Engine installation/legalization on personal device.

I think this is much more serious than many people might see it at the moment. I think it is attack on a very fabric of free democratic society where human rights have real meanings. It is done by people who do not share those values or not familiar with them or simply do not care about them or even worse - doing it on purpose.

Many can think of their personal device as their home. Some can even think of it as extension of their mind. It is very personal space and attempts to invade it can/should be considered not less serious then invasion into your private home.

Even critics can admit that your personal device indeed can be in your private home space and connectivity of such personal device should not automatically mean that someone or something like AI under control of someone should access it and spy on you without warrant.

Companies are doing shitty things for some time now and they are getting away with them. This can be a reason why they move forward with unacceptable practices of surveillance. Perhaps those companies do not understand that surveillance is completely incompatible with free democratic societies respecting human rights and there is no way they can succeed in combining two incompatible things unless they wish to repeat China way of doing thing. And I believe the later would not be met gladly I even think not so much possible without using firearms to which people would resist with the same effort like they did many times in history to protect own freedom.

At this stage I think it is much more serious than just writing a letter.

There should be a law protection of your personal computer from any Spyware Engine/Agent for any reason other then warrant to avoid bigger and possibly deadly confrontations. Just like your home as your personal space should be protected from Search without warrant in Fourth Amendment [2]. Your personal device is much more personal then your home in a way and deserve to be guarded accordingly. I am not a lawyer and perhaps Fourth Amendment is already enough but then it should be used properly to prevent Spyware Engines in personal devices.

* Amendment IV

The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized. * [2]

The Fourth Amendment originally enforced the notion that “each man’s home is his castle”, secure from unreasonable searches and seizures of property by the government. It protects against arbitrary arrests, and is the basis of the law regarding search warrants, stop-and-frisk, safety inspections, wiretaps, and other forms of surveillance, as well as being central to many other criminal law topics and to privacy law. [2]

[1] https://news.ycombinator.com/item?id=28084578

[2] https://www.law.cornell.edu/constitution/fourth_amendment

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#86
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

> especially when the goal Apple announces appears to be for the greater good. Not surprising at all. In Russia, _every_ measure to limit internet freedom was introduced under the pretence of fighting child pornography and extremism. Then, of course, it was used to block the websites of political opponents.

Not only in Russia. It's sad to see a country (in central europe) which puts a guy 8 years in jail for raping children more than 8 years, justifying such invazive software as defence against CP.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#87
So, if I understand correctly, the NCMEC provides a bunch of hashes of CSAM for Apple to match. This way Apple doesn’t get exposed to the content of images themselves? Then Apple will provide a user’s details plus the IDs of matching content. This identifies the direction of travel for any CSAM content?

So, now NCMEC and any local NCMEC can provide new hashes and identify – possibly even historically – the epicentre of the distribution of a group of images.

Except, if Apple only gets the hashes, what’s to stop a bad actor in a NCMEC from providing non CSAM images to Apple for other purposes?

Seems like this technology should be illegal without a warrant. It’s a wire tap.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#88
post #83

At this point we need to be doing more than signing open letters to companies that are completely free to ignore them. If you work for Apple and don't stand up to this, you should find it extremely hard to find employment or acceptance anywhere. If you're a hiring manager, throw the resumes of anyone that worked at Apple in the trash. It should be a black mark on you if you continue to work and contribute to Apple af…

As much as I dislike what Apple is doing here, Apple is a long way down the list of companies that should be a black mark on your resume. Oracle is a MUCH better target, for example.

Oracle's on the blacklist too. One does not preclude the other.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#89
post #49

Earlier quoted context omitted.

Processor microcode is closed source (Intel/AMD), including most of the BIOS code. You are having hard time to build your devices. Maybe we can see change in the future.

* enter RISC-V *

RISC-V is "nice to have". I do not know of anybody who sells RISC-V computers or boards at a reasonable price.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#90
post #80

Earlier quoted context omitted.

If you work for Apple, you have provided a non-zero amount of support to them and their actions. Even if you're just the janitor that cleans the offices in the evening, you are providing material support. That gives you a non-zero liability for their actions. There are no generals without the soldiers. Yes, maybe for some of their employees its a choice between starving or working for Apple. I bet for the vast majori…

> And even for the ones that would starve, I'm sorry, but I put the well-being of the entirety of society and our collective future over their lives. God, just listen to yourself. Personally I think their plans are fairly balanced and reasonable. Like it or not, there are legitimate interests here. It's a difficult trade-off and conversation. Ostracizing people and saying you would literally rather have people DIE is…

What makes you think I haven't listened to myself? And don't bring God into this, he's left the conversation a long long time ago; This shit's on us. I really couldn't care less if you think their plans are balanced or reasonable -- I don't agree with that on a fundamental level because Apple has long passed that threshold. This is just their latest digging a deeper hole. And why should I feel obligated to add to a conversation that has long gone nowhere? What can I add to it that wouldn't just get ignored anyways. I might as well inject my honest opinion, however much it'll be ignored.
Post reply on HN