Live data from Hacker News

In internal memo, Apple addresses concerns around new Photo scanning features

9to5mac.com

311–320 of 430 posts

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#311

Earlier quoted context omitted.

Ah ok, so as long as it is profitable ethics don't matter. Got it.

Companies don't have to be ethical, they just have to be legal.

So just like everyone else?

We hold people to certain standards and can do the same for companies.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#312
post #304

Earlier quoted context omitted.

The tools are already in place for misuse. iPhones autoupdate by default, so Apple can push new malicious privacy-invading software to your device at any time without your intervention. Each update, even if done manually, re-enables autoupdate, requiring that you go turn it off. Apple is really into being able to run whatever code they want on your device without your intervention.

Sure, but by that reasoning, any system that has updates is by definition 100% insecure, and nothing else matters anymore… The world is not just black and white.

Unattended autoupdate is indeed insecure, as the Solarwinds hack nicely illustrated.

When the vendor can execute arbitrary code on your machine without intervention, that's effectively a backdoor of any/all kinds.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#313

Apple's mistake is that they seemingly believe there is pushback because people misunderstand how it works. The reality is more nuanced: People understand exactly how it works, and how it works is that it is turn-key onboard spyware, that Apple pinky-swears isn't being used wrong today . For example if the scope/mission expands (e.g. foreign governments), suddenly you've created a drag-net for whatever "badness" is o…

> A cryptographic hash + file size combo is unlikely to have a false positive within our lifetime The chance of a "technical" false positive is tiny, but they need to look all false positives: If some joker sends you a lewd picture through WhatsApp, WhatsApp by default saves every picture to your photo library, then you are now on the naughty list. Good luck trying to explain yourself out of that one.

WhatsApp saves all received images to your library? That seems hard to believe. I can't imagine that anyone would appreciate having their personal photo collection cluttered with other peoples photos and all of the meme images that people share.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#314
post #311

Earlier quoted context omitted.

Companies don't have to be ethical, they just have to be legal.

So just like everyone else? We hold people to certain standards and can do the same for companies.

I don't agree with Apple's move here either just explaining that they are not doing anything illegal no matter how much we may not like it. Of course we can choose not to buy their products but do you think the average person considers it before they make a decision on their next phone?

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#315

Earlier quoted context omitted.

So they can claim only Pedos use android

Android could take the opposite approach. I.e. someone can write an app that generates CP, so those who want it can have it without any actual children involved.

In the current US legal zeitgeist CP is illegal because it's morally wrong. Yeah, also to protect the children, but an image can be deemed by a judge to be CP even if no real children are involved. Under the current doctrine it's something like "I'll know it when I see it", so such app would most likely be generating illegal images.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#316
"We know that the days to come will be filled with the screeching voices of the minority."

Nice one Apple. Hopefully they're not referring to the minority that buy their products as a result of them being marketed with privacy and security as setting them aside from their competitors.

Here is a list [1] of at least some of the 'minority'

WhatsApp have also fired back at them [2].

[1] https://appleprivacyletter.com/

[2] https://www.theverge.com/2021/8/6/22613365/apple-icloud-csam...

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#317

Earlier quoted context omitted.

The difference is that Google doesn’t advertise itself as a bastion of privacy. Google spying on you is expected. More consumers also pay for iCloud vs Google Drive. Expectations change when you’re paying for a service.

Isn't the difference that with google drive, they scan the files you upload to their servers? And, this latest apple debacle is on scanning files locally on the device itself?

If Apple is to be believed (and doesn't change anything later) then they're doing the same thing. They're scanning the things that are being uploaded to iCloud. They're just doing it locally instead of doing it after they're on the iCloud servers.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#318
post #137

Earlier quoted context omitted.

About that "manual review"... Refer to pages 10 and 11 of the technical paper. >The server then uses the decryption key to decrypt the inner encryption layer and extract the NeuralHash and visual derivatives for the CSAM matches. This "visual derivative" term shows up repeatedly. To me, the implication seems to be that Apple doesn't look at the actual suspected image before deciding whether to proceed with a report.…

> who would want to be in the business of reviewing reports of probably-illegal images? I could think of a couple of companies this could be outsourced to, with strict business and privacy agreements in place, of course, and also conveniently on the lowest end of European minimum wage for the tier 1 reviewers.

[deleted]

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#319
post #273

Earlier quoted context omitted.

This is spin by Apple, driven by ignorance or deliberately misleading statements. NCMEC's database contains images that are not CSAM, not illegal and are not even borderline (grey area). The fact there is a match in NCMEC's database does not mean the content is CSAM. It does not even mean it's illegal. In fact, it doesn't even mean there's a single person in the picture frame. And no, this is not theoretical. NCMEC's…

> NCMEC's database contains images that are not CSAM, not illegal and are not even borderline (grey area). Got a handy link about this? A quick search doesn't show anything obvious. > This is spin by Apple, driven by ignorance or deliberately misleading statements. The claim was that Apple got access to all the pictures on the phone which isn't correct according to their technical summary. Nothing to do with the vali…

I think the problem is that no one will ever be able to validate what's in that database. "I need to see that database so I can ensure that it's all CP" isn't going to go over well.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#320
post #247
post #137

Earlier quoted context omitted.

About that "manual review"... Refer to pages 10 and 11 of the technical paper. >The server then uses the decryption key to decrypt the inner encryption layer and extract the NeuralHash and visual derivatives for the CSAM matches. This "visual derivative" term shows up repeatedly. To me, the implication seems to be that Apple doesn't look at the actual suspected image before deciding whether to proceed with a report.…

Visual derivative is a preprocessed picture itself, and it's part of the "safety voucher". It may be grayscale and resized/normalized in other ways. Only apple knows exactly what it is. It's only a matter of time until internet trolls find a way to abuse this. The database is stored on user's devices, so someone downloading it and permuting innocuous images enough until they match the database, and then spreading the…

Most of the time, Apple seems to think through what bad actors will do with their stuff. Their scale and (perceived) reputation basically requires this.
Post reply on HN