Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

151–160 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#151
post #57
post #42

Don't support Apple! *You must sign up for a Microsoft GitHub account to sign our petition. While I like the sentiment of protest, I don't understand this logic of putting it on a closed platform of one of Apple's biggest competitors who also doesn't respect your privacy.

You made me ponder about "Microsoft Github account" vs "Github account", or large corporation vs smaller corporation. So many smaller corporations end up getting acquired by larger corporations anyways. It's all kind of a broken system huh?

I wish I would practically escape it. On personal projects, I’ve moved everything to Sourcehut and GitLab, but so many projects I want to contribute to are still on GitHub for legacy reasons and don’t feel it’s worth the effort to migrate (though everything heavy on the libre side have moved). Some projects, like Elm (programming language), use GitHub for both as the source of its package management and identity so it’s impossible to escape the lock-in.

But this is why Microsoft bought it: to get closer to monopoly (GitHub, Copilot, NPM, VS Code, Azure, etc.) making people buy into a platform they feel they cannot escape. I think it is important to tag the parent company when talking about GitHub so users understand who they are really dealing with by hosting their projects on this Git forge and what restrictions this puts on their contributors.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#152

At this point we need to be doing more than signing open letters to companies that are completely free to ignore them. If you work for Apple and don't stand up to this, you should find it extremely hard to find employment or acceptance anywhere. If you're a hiring manager, throw the resumes of anyone that worked at Apple in the trash. It should be a black mark on you if you continue to work and contribute to Apple af…

"If you're a hiring manager, throw the resumes of anyone that worked at Apple in the trash."

Well,... NO. Those are the very people trying to depart Apple, so surely the very ones we should try to support?

I'm not saying they should attract a more favourable review in the application/hiring process, just that the ones who should attract approbation are those staying behind to continue supporting Apple. (Assuming you go along with the entire proposition that pressuring developers will alter Apple's corporate misbehaviour in the first place.)

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#153
https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

Apple uses sophisticated cryptography to make absolutely certain that you cannot hold them accountable for abuses of this system against you, NONE of which are prevented by its complex construction.

The private set intersection is an alternative to sending you a list of bad-image hashes which uses significantly more bandwidth than simply sending you the list. This alternative is superior for Apple because if they distributed the hashes it would be possible for someone to prove that they had begun matching against innocent images (such as ones connected to targeted races or religions, or sought to out particular pseudonyms by targeted images connected to them). It is inferior for the user for precisely the same reasons.

Some might be fooled into thinking the "threshold" behavior, somehow is in their interest: But no, Apple (or parties that have compromised them) can simply register the same images multiple times and bypass it and the privacy (for apple, but not for you) makes it impossible to detect that they've done that.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#155

Earlier quoted context omitted.

Ok, so what stops the CCP from submitting hashes of photos of the "tank man" to this hash set? And then jailing all those reported to possess it?

What's stopping them already...? It operates on iCloud photos. Those are already scanned. If a nation state wanted to flex this before they could have done so.

[deleted]

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#156
post #110
post #96

Earlier quoted context omitted.

NCMEC's database already contains non-CSAM. What you suggest is not theoretical, it's reality today. I really think people are missing this point. NCMEC's database is not an infallible, audited and trustworthy source of despicable imagery. It's a mess contributed to by thousands of companies, individuals and police. It's also so intertwined with the FBI that I don't think it's truly correct to call NCMEC independent,…

Wow. Also, many people trust Apple to do ‘the right thing’. But if Apple are trusting NCMEC and their local equivalents to provide valid CSAM hashes, Apple will never know if their technology is being abused, so they can conveniently point the finger elsewhere if it is. I can’t imagine this point has escaped their awareness.

> Also, many people trust Apple to do ‘the right thing’.

Well that's silly of them, thats the motto Google switched to after they gave up on the whole not being evil thing.

( https://www.engadget.com/2015-10-02-alphabet-do-the-right-th... )

:P

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#157

At this point we need to be doing more than signing open letters to companies that are completely free to ignore them. If you work for Apple and don't stand up to this, you should find it extremely hard to find employment or acceptance anywhere. If you're a hiring manager, throw the resumes of anyone that worked at Apple in the trash. It should be a black mark on you if you continue to work and contribute to Apple af…

"If you're a hiring manager, throw the resumes of anyone that worked at Apple in the trash." Well,... NO . Those are the very people trying to depart Apple, so surely the very ones we should try to support? I'm not saying they should attract a more favourable review in the application/hiring process, just that the ones who should attract approbation are those staying behind to continue supporting Apple . (Assuming yo…

Except that I can't do anything as a hiring manager to those that continue to stay at Apple. But I can help perpetuate the notion that if you work at Apple for any reason, you'll be un-hirable anywhere else.

The point of reasonable doubt passed a long time ago. If you didn't get out years ago, you're already part of the problem.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#158
post #128

Earlier quoted context omitted.

> a non-insignificant amount of people in tech take this seriously We're all here to make ourselves feel good saying we Took A Stand. In reality, four weeks from now, do you think anybody will still be talking about it? I made this same mistake. I was pretty convinced that people were taking Copilot seriously, and that there was possibly going to be ramifications for Microsoft. I wasn't particularly looking forward t…

> Like it or not, we aren't in control. The typical Apple customer is forking over thousands of dollars. They have substantial control. This isn't like a government where you need a plurality of voters to agree before anything starts to happen. Apple is running software on their phone that will either (a) do nothing or (b) call the police on them. The situation is questionable even for a normal consumer, let alone a…

[deleted]

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#159

Earlier quoted context omitted.

> I am currently planning the migration away from the Apple ecosystem Me too. I told my wife today that I'll be looking at a feature phone as I'm not sure I can be bothered with jumping through all the hoops required to de-Google an Android phone. I remember a time before mobile phones, I was just fine without one - smartphones aren't that good, just convenient.

It's good that you're principled enough to do that but you guys will be rounding errors in Apple's revenue. Most people don't even know about this and those that do, most wont care. Even of those who do know and do care, most aren't motivated enough to change their habits beyond writing a few angry words on a forum Apple are never going to read anyway. Those that do change their buying habits, yourselves, are by far…

What you are saying isn't that depressing, I think it makes a lot of sense. But perceived abuses do take time for people to eventually take action that can actually effect companies/states bottom lines.

I can imagine at some point a 0day targeting iOS devices that when they connect to a public wifi network with a compromised router, it distributes CP malware/botnet on to their device and then everyone else that connects to that device in the future (muddying the waters).

Similar actions could also be taken against other companies and state entities systems.

And these actions don't need to rely on most of the population to take them.

The more these "kill chain" like systems become automated and cheap to deploy, the more incentive individuals will have to pursue these types of attacks.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#160

Earlier quoted context omitted.

> I am currently planning the migration away from the Apple ecosystem Me too. I told my wife today that I'll be looking at a feature phone as I'm not sure I can be bothered with jumping through all the hoops required to de-Google an Android phone. I remember a time before mobile phones, I was just fine without one - smartphones aren't that good, just convenient.

It's good that you're principled enough to do that but you guys will be rounding errors in Apple's revenue. Most people don't even know about this and those that do, most wont care. Even of those who do know and do care, most aren't motivated enough to change their habits beyond writing a few angry words on a forum Apple are never going to read anyway. Those that do change their buying habits, yourselves, are by far…

This is a wonderful dose of realism, mixed with slightly too much cynicism.
Post reply on HN