Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

221–230 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#221
post #205

Earlier quoted context omitted.

Disingenuous false equivalence for anyone who knows the difference between server side and client side

Isn't it bit ironical or naive to trust their current software as it is (which is almost full blackbox), and then speculate what they could do without saying, when they add something? As far as I understand, you can disable this feature, because it is tied to iCloud sync. Based on their spec [1], this feature avoids to do the same as Google and others doing (scan everything on cloud), instead they scan on device, whi…

Exactly. Many people who are upset about having their images scanned before going to iCloud don't seem to realize all the big providers (Apple, Google, FB, Twitter, MS, etc...) have been scanning images with CSAM for years already.

The client side/server side also does not matter because iOS users have had to trust Apple implicitly since day 1. All the 'what ifs' existed whether or not Apple added this feature.

I speculate that Apple is going to announce an expansion of E2E to more services at the iPhone event this year, and this feature is getting in front of political complaints that could lead to real privacy destroying legislation/LEO complaints.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#222
post #206

Let‘s play a simple game. Go to https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni... and then replace - "National Center for Missing and Exploited Children“ with „the new Trump administration“ - „child pornography“ with „LGBT content“ Doesn't look fun anymore, does it? (use „the new Clinton administration“ and „images of guns“ if you are conservative)

I'm not sure of the point you're getting at. You can do this with effectively anything. Replace "gay marriage" with "child sexual exploitation" in "I support gay marriage". Does that mean we shouldn't support anything?

> Does that mean we shouldn't support anything?

Op is pointing out what a universal evil Apple's scanning of personal property at scale is.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#223

I'm not sure what the solution is.. Child abuse is an extremely severe problem. In the future encrypted-messaging may be used by terrorists developing some weapon of mass destruction like a virus. I'm concerned about privacy, but is it tenable to have true E2EE regardless of the harm? For better or worse it seems that human societies will prioritise physical safety over most things. Even if we have true E2EE, a bad a…

The solution is for law enforcement to show evidence of a crime to get a subpoena.

If you don’t think it works, check out your local list of Megan’s Law participants.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#224
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

> 1. Vote with your feet - Put your money in the pockets of the people aligned to your values.

This is impossible. Just like modern democratic voting, you don’t get to vote on an individual policy. You vote on a bundle and that bundle almost certainly includes policies (or in this case “features”) that you don’t agree with.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#225
post #165
post #50

Related but slightly off-topic: am I the only one that thinks more technology is not the answer to catching crooks? Can’t the police do good old fashioned police work to catch people doing these things? Why does EVERYONE need to be surveilled for the 0.01% (or less?) who don’t behave properly. To further this point: why do we need cameras on every street, facial recognition systems and 3-letter orgs storing huge data…

American police has never been de-funded, and if you really think "good old fashioned" police work ever actually worked for most people, you are misinformed. Without even discussing policing across racial and poverty lines, one only needs to look at police failing to catch serial killers, rapists, and even just house burglars. The situation was much worst 10, 20, 30+ years ago. Nowadays police have some of their work…

I don't know why this is downvoted, you are absolutely right.

Prosecutions based, essentially, on community suspicion are what lead to countless black men being wrongfully convicted of the rape of white women.

Police embracing cutting edge science like DNA sequencing is what allows unreliable antiquated evidence like (gasp) eyewitness testimony to be given it's proper weight.

Perhaps people consider DNA evidence to be "good old-fashioned policing" nowadays but it was within people's lifetimes that it was as new was quantum computing is today.

The sooner the "good old fashioned policing" meme dies the better.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#226
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

> a non-insignificant amount of people in tech take this seriously We're all here to make ourselves feel good saying we Took A Stand. In reality, four weeks from now, do you think anybody will still be talking about it? I made this same mistake. I was pretty convinced that people were taking Copilot seriously, and that there was possibly going to be ramifications for Microsoft. I wasn't particularly looking forward t…

You can do two things: - fight : you will either join the establishment or have your life ruined but you won't change things - adapt : accept the things are the way they are and make the best of the situation In either case you can still get caught by the machine and get ground up, it has always been like that and as long as we are human it will always be like that. Any change that will happen is generational, 20 or 40 years from now the issues that are important to you now will be addressed by people who floated up to the top and are in position to make changes.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#227
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

> 1. Vote with your feet - Put your money in the pockets of the people aligned to your values.

Too bad many people have been trapped within the Apple bubble and are unable to jump ship because they have no idea how the rest works, how they get their data over there and don't have the time to do all this.

This is why Apple IS a monopolist and this is how it ends up being a problem.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#228

Earlier quoted context omitted.

> "Can’t the police do good old fashioned police work to catch people doing these things?" I'm a detective that works exclusively on online child sexual offences. The short answer to this is "no", although the question doesn't make much sense to me. Policing has always been near the forefront of technology. Perhaps you could expand more on what "good old fashioned police work" means, in this context?

Not the OP, but by good old fashioned police work, I assume non-dragnet methods, where everybody's device isn't scanned in an automated way. So instead of sifting through a massive collection of automatically collected data, taken from a vast majority of innocent people, you'd deal with explicit reports of CSAE. You'd then be able to get a warrant to obtain ISP (and other) records, cross-reference and proceed from th…

> you'd deal with explicit reports

Where would these reports come from though? Without these dragnet methods, it would seem like a very simple matter to get away with owning this kind of material.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#229
post #153

https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni... Apple uses sophisticated cryptography to make absolutely certain that you cannot hold them accountable for abuses of this system against you, NONE of which are prevented by its complex construction. The private set intersection is an alternative to sending you a list of bad-image hashes which uses significantly more bandwidth than simply sending you the…

> The private set intersection is an alternative to sending you a list of bad-image hashes which uses significantly more bandwidth than simply sending you the list.

How can the image hashes take up more space than the images themselves? Are you sure about this?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#230
post #122

This letter doesn't really read correctly. If you're going to write an open letter, this might be better worded. >Apple's proposed technology works by continuously monitoring photos saved or shared on the user's iPhone, iPad, or Mac. It does a check if it's being uploaded to iCloud Photos. It is not (currently, at least) continuously monitoring photos saved or shared; shared is Messages specific for child accounts. >…

Yes, there seems to be a lot of conflation between the two separate systems (in the media, and in comments on here). As you say, it’s important to be precise, otherwise people won’t take your arguments seriously. To summarise: One system involves hash checking. This is performed when photos are being uploaded to iCloud. The hashes are calculated on-device. Private set intersection is used to determine whether the pho…

Based on my reading, the first system is interesting in that the threshold is also cryptographically determined. Each possible hit forms part of a key, and until a complete key is made none of the images can be reviewed.

Should also be noted the second system sends no images to Apple or is reviewed by Apple employees in any way. It's just using the same on device ML that finds dog pics for example.

I think Apple PR screwed up here announcing all these features at once on one page, and not having the foresight they would be conflated. It also didn't help that a security researcher leaked it the night before without many of the details (iCloud only for example).

Context should also be included. CSAM has been happening for years on most (all?) photo hosts, and is probably one of the blockers to full E2E encryption for iCloud photos (I so hope that's coming now!).

Finally, nothing has really changed. Either iOS users trust Apple will use the system only as they have said or they won't. Apple controls the OS, and all the 'what if' scenarios existed before and after this new feature. As described, it is the most privacy preserving implementation of CSAM to date.

Post reply on HN