Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

201–210 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#201

Earlier quoted context omitted.

I think the problem with your response is that you aren't proposing anything better. It just sounds like you're saying "give in, it doesn't make a difference anyway". That capitulating, "crabs in a barrel" attitude is why things are the way they are. The majority just sits around waiting for something to happen and for some miracle to happen; for a leader to show up, galvanize the masses to change their ways and save…

> I think the problem with your response is that you aren't proposing anything better. That's because I honestly can't think of anything better. However that doesn't make my response invalid. > The majority just sits around waiting for something to happen and for some miracle to happen; for a leader to show up, galvanize the masses to change their ways and save the day. At the same time you don't believe that will ev…

I think your proclamation of it all being futile is a bit premature and can be disheartening for those that do want to act. It may even play a part in negative change, leading to some people dropping their original intention because you successfully convinced them that nothing can possibly change.

Yet, I'm not convinced that you can reasonably know this. So if we can all agree that what's happening here with Apple is a bad thing, perhaps it's for the best to refrain from posting pessimistic takes?

All actions have consequences, even posting to a message board. I think it is wise to formulate an intended consequence in mind before you act.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#202

Earlier quoted context omitted.

No need to look at russia only, what about Germany, one of those "bastions of free speech". Also, wasn't the rational for the crypto ban the same? Either terrorism or Child Porn? If you support E2E you're effectively supporting child porn? https://gigaom.com/2009/06/16/germany-to-vote-on-block-list-...

Does anyone really think of Germany as "bastion of free speech"? It is one of few european countries that still have (actively used) anti-blasphemy laws[1] and laws against insulting foreign leaders[2]. [1] https://friendlyatheist.patheos.com/2016/02/27/in-rare-move-... [2] https://www.theatlantic.com/international/archive/2016/04/ge...

Fun fact, it's also the only place that I know of where you can get fined for calling a German a Nazi.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#203

Earlier quoted context omitted.

> "Can’t the police do good old fashioned police work to catch people doing these things?" I'm a detective that works exclusively on online child sexual offences. The short answer to this is "no", although the question doesn't make much sense to me. Policing has always been near the forefront of technology. Perhaps you could expand more on what "good old fashioned police work" means, in this context?

Do you have any qualms? For you does the CP protection end justify any means? Where would you personally draw the line on mass surveillance by LE for the sake of your specific LE goals? CP aside, are there other crimes that you feel should be folded-in to a dragnet like this?

You probably don't realise it, because you're coming from a perspective that has been heavily influenced in a particular way, but some of these questions are kind of insulting and don't really assume good faith (or even basic decency) on my part.

> "does the CP protection end justify any means?"

Like, is this legitimately a question you think I might answer "yes" to?

This is the equivalent of "do you support the rape of children?".

I'll gladly comment on more specific points if you are genuinely struggling to understand how Apple could honestly implement this system in good faith.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#204
post #50

Related but slightly off-topic: am I the only one that thinks more technology is not the answer to catching crooks? Can’t the police do good old fashioned police work to catch people doing these things? Why does EVERYONE need to be surveilled for the 0.01% (or less?) who don’t behave properly. To further this point: why do we need cameras on every street, facial recognition systems and 3-letter orgs storing huge data…

> Can’t the police do good old fashioned police work

There is no "old fashioned" work. The police is a relatively new concept. And these issues (Child Porn) are really 21 century issues.

> Why does EVERYONE need to be surveilled for the 0.01% (or less?) who don’t behave properly.

Because you think they are surveilling people to catch the bad people. You have too much faith in the system.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#205
post #33

Earlier quoted context omitted.

Google does the same with Google Drive. Apple is just late for the party.

Disingenuous false equivalence for anyone who knows the difference between server side and client side

Isn't it bit ironical or naive to trust their current software as it is (which is almost full blackbox), and then speculate what they could do without saying, when they add something?

As far as I understand, you can disable this feature, because it is tied to iCloud sync. Based on their spec [1], this feature avoids to do the same as Google and others doing (scan everything on cloud), instead they scan on device, which limits exposed data what Apple sees. So this is improvement compared to other available solutions.

[1] https://www.apple.com/child-safety/pdf/Expanded_Protections_...

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#206

Let‘s play a simple game. Go to https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni... and then replace - "National Center for Missing and Exploited Children“ with „the new Trump administration“ - „child pornography“ with „LGBT content“ Doesn't look fun anymore, does it? (use „the new Clinton administration“ and „images of guns“ if you are conservative)

I'm not sure of the point you're getting at. You can do this with effectively anything. Replace "gay marriage" with "child sexual exploitation" in "I support gay marriage". Does that mean we shouldn't support anything?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#207

Earlier quoted context omitted.

> I am currently planning the migration away from the Apple ecosystem Me too. I told my wife today that I'll be looking at a feature phone as I'm not sure I can be bothered with jumping through all the hoops required to de-Google an Android phone. I remember a time before mobile phones, I was just fine without one - smartphones aren't that good, just convenient.

I made the switch a couple months ago and its harder than you think. There is a lot of convenience you take for granted in the smartphone age.

What did you switch to?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#208
post #50

Related but slightly off-topic: am I the only one that thinks more technology is not the answer to catching crooks? Can’t the police do good old fashioned police work to catch people doing these things? Why does EVERYONE need to be surveilled for the 0.01% (or less?) who don’t behave properly. To further this point: why do we need cameras on every street, facial recognition systems and 3-letter orgs storing huge data…

> "Can’t the police do good old fashioned police work to catch people doing these things?" I'm a detective that works exclusively on online child sexual offences. The short answer to this is "no", although the question doesn't make much sense to me. Policing has always been near the forefront of technology. Perhaps you could expand more on what "good old fashioned police work" means, in this context?

Not the OP, but by good old fashioned police work, I assume non-dragnet methods, where everybody's device isn't scanned in an automated way. So instead of sifting through a massive collection of automatically collected data, taken from a vast majority of innocent people, you'd deal with explicit reports of CSAE. You'd then be able to get a warrant to obtain ISP (and other) records, cross-reference and proceed from there. If there's reasonable suspicion, you'd get the suspect's address and go talk to them in person.

Before we started trying to push government-sanctioned and unwanted spyware engines on private devices, I imagine the process looked something like that. Is this incorrect?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#209

Earlier quoted context omitted.

Apple does the same with iCloud as Google does with Google Drive. Apple just now moved it to scan on the device.

Correct. https://9to5mac.com/2020/02/11/child-abuse-images/ And if you have your iCloud sync toggle on, since your devices are intended to be uploaded, the client is doing the hashing.

This is different now. They scanned only suspected ones. Now they are expanding it to every user. To avoid same privacy issues as Google is doing (scan everything on cloud), they scan everything on device, and only leaking suspected information to upstream and preventing the upload to stop sharing.

IF we can trust that they really scan locally only those files which would end up into the cloud, then this is improvement. But trust is all we have, because the system is already full blackbox.

https://www.apple.com/child-safety/pdf/Expanded_Protections_...

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#210
post #177

Earlier quoted context omitted.

> "Can’t the police do good old fashioned police work to catch people doing these things?" I'm a detective that works exclusively on online child sexual offences. The short answer to this is "no", although the question doesn't make much sense to me. Policing has always been near the forefront of technology. Perhaps you could expand more on what "good old fashioned police work" means, in this context?

Thanks for your reply - I meant that police caught criminals before the internet (I do not know the effectiveness and am unknowledgeable on this subject generally), however they did that, getting out there speaking to suspects and victims, and investigating with evidence I would guess

Well, police still investigate with evidence, but the potential scope of "evidence" is pretty much the whole physical universe. File hashes and TCP packet captures are evidence, DNA fragments are evidence, weather patterns are evidence, in the same way that people's memories are evidence.

Through the decades, the respect shown to eyewitness testimony has generally declined, and crimes with no eyewitness evidence are still expected to be solved.

For offences with a huge online aspect there is no prospect of "getting out there" until you work out where "there" is, because it could be anywhere in the world.

Post reply on HN