Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

131–140 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#131
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

> especially when the goal Apple announces appears to be for the greater good. Not surprising at all. In Russia, _every_ measure to limit internet freedom was introduced under the pretence of fighting child pornography and extremism. Then, of course, it was used to block the websites of political opponents.

No need to look at russia only, what about Germany, one of those "bastions of free speech".

Also, wasn't the rational for the crypto ban the same? Either terrorism or Child Porn? If you support E2E you're effectively supporting child porn?

https://gigaom.com/2009/06/16/germany-to-vote-on-block-list-...

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#132

Earlier quoted context omitted.

This isn't a powerful tool, it's more akin to a rudimentary hash check. It's not going to match photos that aren't already known to authorities. And any time a user is flagged, the material in question is sighted by an Apple employee before a decision is made whether to forward it onto the relevant authorities.

Ok, so what stops the CCP from submitting hashes of photos of the "tank man" to this hash set? And then jailing all those reported to possess it?

What's stopping them already...?

It operates on iCloud photos. Those are already scanned. If a nation state wanted to flex this before they could have done so.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#133

Google Photos and Gmail openly and heavily scan server-side, and I'm sure a lot of us use them, how do we reconcile that?

I don’t use Android, so genuine question here: does an Android phone automatically upload everything to iCloud like an iPhone does?

With the iOS ecosystem, in my experience having everything backed up to iCloud is the default position, and you have to turn it off manually.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#134
post #89

Earlier quoted context omitted.

* enter RISC-V *

RISC-V is "nice to have". I do not know of anybody who sells RISC-V computers or boards at a reasonable price.

Maybe it does not seem a reasonable price to you, but for people who don't know, the HiFive Unmatched [1] sells for 679$ [2].

This is the most powerful RISC-V platform you can buy today. It comes as a Mini-ITX board including 16Gb of DDR4 ram, 1Gbps ethernet, usb 3.2, PCI Express and NVMe.

Of course it is less powerful than an x64 machine at the same price point, but it should work reasonably well when paired with an SSD and a graphics card.

[1] https://www.sifive.com/boards/hifive-unmatched

[2] https://www.crowdsupply.com/sifive/hifive-unmatched

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#135

Earlier quoted context omitted.

Ok, so what stops the CCP from submitting hashes of photos of the "tank man" to this hash set? And then jailing all those reported to possess it?

What's stopping them already...? It operates on iCloud photos. Those are already scanned. If a nation state wanted to flex this before they could have done so.

Same reason you do not sue someone for patent infringement until it is too late for them to turn back?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#136

Most of the people see the adversary in Apple (or governments), I think there is something else: What about Adversarial Attacks. Let’s assume someone is going to spread regular memes modified as Adversarial examples to generate the same neural hash as the true bad images. Thinking back at the political campaigns, these could spread very easily among some voters for some party. Suddenly you have a pretty serious attac…

It requires a 'collection' of images to trigger an alert to apple who then has someone manually reviewing the photos before taking further action

there's still our justice system/due-process as well

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#137
post #36

I'm not usually the most idealistic when it comes to FOSS, but it's stories like this and Apple's stance of "trust us, we promise we know what we're doing and that nothing is going to go wrong" that makes me think all software should be legally required to be open source.

It would be if y’all slapped the AGPLv3 on your code instead of Apache/MIT/BSD. If we were to perform a cyber analog of what the founding fathers did for the USA 250 years ago, it would be something along the lines of declaring all software free from the tyranny of corporate control and state oppression. Free in perpetuity so that our digital projections onto hardware shall reside comfortably each in their own pursui…

> If we were to perform a cyber analog of what the founding fathers did for the USA 250 years ago, it would be something along the lines of declaring all software free from the tyranny of corporate control and state oppression.

… and then proceed to conduct asymmetric warfare against state and corporate cyber systems alike.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#138
post #81
post #56

Earlier quoted context omitted.

I don’t use Windows Defender nor Google Photos nor other cloud service providers to scan my photos. I barely use gmail. I knew that Google was terrible so I have already minimized my use of Google services. Same with Facebook. But Apple!? I guess the dominos have finally gotten to me.

It is not so straightforward to not use Windows Defender if you are using Windows 10. You must edit group policies in quite deep to disable automatic scanning and startup. Google Drive includes backups of your phone, so it is not limited to Google Photos. Literally everything that is stored unencrypted on Google servers.

Disabling all of Defender is complex, but disabling automatic sample submission is easy. It's an option in the Security settings app, and you're even allowed to disable it during first time set up (or were, last I installed Windows 10).

It nags you once, but you can ask it to stop.

Besides, uploading unseen executable code and scanning photos are far from the same tech. They're very different things.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#139
Unpopular opinion: I think the outrage over this is quite overblown.

This kind of hash checking is done by damn near all cloud providers - Google Photos, Dropbox, Gmail, Discord, Reddit, OneDrive, Facebook, Twitter, you name it. Apple have actually been very reluctant to implement this.

If you don’t like it, you don’t need to enable iCloud Photos. In the exact same way as if you don’t want your images scanned by Dropbox, you don’t upload the photos to Dropbox. It seems reasonable for Apple to implement something like to prevent iCloud becoming a repository for CSAM.

Edit: I’m unable to respond to the comment below this about hashes being performed locally, as I’m rate limited, but here’s my response anyway: The hashes are calculated on the local device, but only for photos which are about to be uploaded to iCloud Photos. The hashes are sent with the photos to iCloud. If a certain number of hashes in someone’s iCloud match (calculated using private set intersection), a manual review will be performed.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#140
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

> a non-insignificant amount of people in tech take this seriously We're all here to make ourselves feel good saying we Took A Stand. In reality, four weeks from now, do you think anybody will still be talking about it? I made this same mistake. I was pretty convinced that people were taking Copilot seriously, and that there was possibly going to be ramifications for Microsoft. I wasn't particularly looking forward t…

I still hope there is a chance that Apple may change course after they realise they may not have thought this through very well.

Especially the argument that this can be weaponised really easily worries me, and it looks like they overlooked it.

For example: some joker sends you a Whatsapp with a lewd picture, WhatsApp by default saves all pictures to your photo roll => you are now on the naughty list.

I really hope they come up with a good answer to that one (or just abandon this unholy plan).

Post reply on HN