Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

211–220 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#211

Google Photos and Gmail openly and heavily scan server-side, and I'm sure a lot of us use them, how do we reconcile that?

On the server side. That is the difference. I know that if I put something on Google Drive it is in clear in the Google servers.

What I don't want is Google performing a scan of the internal memory of my Android device!

Server side they can do whatever they want, and I choose what data they can access, but on my device not.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#212

Earlier quoted context omitted.

It's good that you're principled enough to do that but you guys will be rounding errors in Apple's revenue. Most people don't even know about this and those that do, most wont care. Even of those who do know and do care, most aren't motivated enough to change their habits beyond writing a few angry words on a forum Apple are never going to read anyway. Those that do change their buying habits, yourselves, are by far…

I think the problem with your response is that you aren't proposing anything better. It just sounds like you're saying "give in, it doesn't make a difference anyway". That capitulating, "crabs in a barrel" attitude is why things are the way they are. The majority just sits around waiting for something to happen and for some miracle to happen; for a leader to show up, galvanize the masses to change their ways and save…

Couldn't say it any better.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#213

Earlier quoted context omitted.

> "Can’t the police do good old fashioned police work to catch people doing these things?" I'm a detective that works exclusively on online child sexual offences. The short answer to this is "no", although the question doesn't make much sense to me. Policing has always been near the forefront of technology. Perhaps you could expand more on what "good old fashioned police work" means, in this context?

Not the OP, but by good old fashioned police work, I assume non-dragnet methods, where everybody's device isn't scanned in an automated way. So instead of sifting through a massive collection of automatically collected data, taken from a vast majority of innocent people, you'd deal with explicit reports of CSAE. You'd then be able to get a warrant to obtain ISP (and other) records, cross-reference and proceed from th…

The system is basically what you describe except the explicit report is precisely what Apple send to NCMEC.

By the time it gets to the police, there will be an identified crime.

This has been the case for many years. I don't have the numbers to hand but I believe NCMEC receives around the order of 100 million referrals a year.

EDIT: it's 20 million according to https://www.missingkids.org/ourwork/ncmecdata

https://www.missingkids.org/footer/media/keyfacts - around 99% are from tech company referrals, 1% from members of the public

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#214
post #89

Earlier quoted context omitted.

RISC-V is "nice to have". I do not know of anybody who sells RISC-V computers or boards at a reasonable price.

Maybe it does not seem a reasonable price to you, but for people who don't know, the HiFive Unmatched [1] sells for 679$ [2]. This is the most powerful RISC-V platform you can buy today. It comes as a Mini-ITX board including 16Gb of DDR4 ram, 1Gbps ethernet, usb 3.2, PCI Express and NVMe. Of course it is less powerful than an x64 machine at the same price point, but it should work reasonably well when paired with an…

I find it weird how none of these links state the CPU frequency prominently (or at least I didn't notice it). Not even the product sheet has it.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#215
Just a reminder that proprietary software that auto-updates does not serve you and should never have been treated as such. Sometimes it's most convenient / best to use proprietary, and that's fine, but please be aware that all vendors with root level access (google + android, microsoft + windows, etc) are just 1 update away from this situation.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#216
If it’s just a list or hashes, any possessor of CSAM could simply modify a few pixels to make it no-matching, no? How "flexible" is the matching?

And if it is flexible, what about false positives? What if I have a pictured of my naked son on my device and I get flagged? Will the picture of my son get uploaded to the cloud "for further analysis" even though I don’t have iCloud enabled and never signed up for this?

Edit: A sibling post has this link, which answers some of these questions: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#217
post #197
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

> 1. Vote with your feet - Put your money in the pockets of the people aligned to your values. As much as I dislike this invasion of privacy, I still trust Apple's products, ecosystem & stewardship over the alternatives (for use by whole family). Although this is the first time in recent memory where not having a viable alternative to consider is irksome as I don't see where the negative push back will come from to p…

The UK porn filter is already seeing works to extending to fighting against extremism on the Internet.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#218
post #197
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

> 1. Vote with your feet - Put your money in the pockets of the people aligned to your values. As much as I dislike this invasion of privacy, I still trust Apple's products, ecosystem & stewardship over the alternatives (for use by whole family). Although this is the first time in recent memory where not having a viable alternative to consider is irksome as I don't see where the negative push back will come from to p…

What scare me is that now that this capability will be out there, a court could compel Apple to go a lot farther

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#219
I'm not sure what the solution is.. Child abuse is an extremely severe problem. In the future encrypted-messaging may be used by terrorists developing some weapon of mass destruction like a virus. I'm concerned about privacy, but is it tenable to have true E2EE regardless of the harm? For better or worse it seems that human societies will prioritise physical safety over most things.

Even if we have true E2EE, a bad authoritarian regime in the future can simply make it illegal. It's more imperative than ever to prevent such a regime arising in the first place..

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#220
post #4

How to complain: don't buy an iphone next time you need a new phone

Boycotting products to change a company's mind won't work because: - not enough people even know about this issue, understand the consequences or remember to act on it the next time a new phone is due - not enough alternatives on the market, and we're probably already boycotting them for other reasons - even with lower sales a company might not see the cause-and-effect There is a general trend in the industry to take…

> Boycotting products to change a company's mind won't work because:

In this case not buying the product is to avoid a viperous feature and protect house of from being spied on. Any boycott effects are tertiary.

Post reply on HN