Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

231–240 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#231

Earlier quoted context omitted.

No need to look at russia only, what about Germany, one of those "bastions of free speech". Also, wasn't the rational for the crypto ban the same? Either terrorism or Child Porn? If you support E2E you're effectively supporting child porn? https://gigaom.com/2009/06/16/germany-to-vote-on-block-list-...

Does anyone really think of Germany as "bastion of free speech"? It is one of few european countries that still have (actively used) anti-blasphemy laws[1] and laws against insulting foreign leaders[2]. [1] https://friendlyatheist.patheos.com/2016/02/27/in-rare-move-... [2] https://www.theatlantic.com/international/archive/2016/04/ge...

The second one is outdated - not only did the prosecutors drop the case against him for insufficient evidence, his situation led Germany to subsequently repeal the law against insulting foreign leaders. He received plenty of support, both from the public and from the public broadcaster on which he recited the controversial poem.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#232
post #216

If it’s just a list or hashes, any possessor of CSAM could simply modify a few pixels to make it no-matching, no? How "flexible" is the matching? And if it is flexible, what about false positives? What if I have a pictured of my naked son on my device and I get flagged? Will the picture of my son get uploaded to the cloud "for further analysis" even though I don’t have iCloud enabled and never signed up for this? Edi…

I think it makes sense to take a step back and ask yourself if Apple, or any sensible Western company, would set up a system that could falsely flag millions of people, or even a hundred. Even without going into implementation details, it seems clear that they would not have a system that would flag standard family photos.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#233

Google Photos and Gmail openly and heavily scan server-side, and I'm sure a lot of us use them, how do we reconcile that?

On the server side. That is the difference. I know that if I put something on Google Drive it is in clear in the Google servers. What I don't want is Google performing a scan of the internal memory of my Android device! Server side they can do whatever they want, and I choose what data they can access, but on my device not.

You know it’s still only photos being uploaded to iCloud that are scanned right? Or are you just totally unfamiliar with the actual issue? If you are familiar, can you explain the practical difference between these approaches that makes one worse?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#234
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

I think the biggest challenge is a lack of consumer choice. Part of this is the complete failure of the FTC and the SEC in the 21st century. Maybe Pinephone will be compelling some day in the future but it isn't now. I don't want to be on tech support for my entire family trying to get some toy phone to work. We've built phones that are generally simple enough for a random grandma to do the couple things they need to do but the problem is to them FB, etc. IS the internet. That is where they see the pictures of their grandkids, they don't care about anything else.

I think there is a #4 that could be on the list. People within Apple could try to push back and protest and walk-out or any other means to try to make this fight go viral. However, the media and population write large will push back "... for the children." I've always thought that these problems are more solvable with Whistleblower Awards plus Witness Protection packages for the major enablers. There are lots of people in these rings or with someone who is but they are dependent on those same bad people for their necessities. Also, some of these rings are crime group adjacent and witnesses would need protection.

From what I'm reading, it seems like turning off iCloud (maybe just for photos?) will turn off this scanning. It is unclear to me what server side scanning Apple was/wasn't doing on photos uploaded to iCloud previously/currently. The one thing that occurred to me is that this is almost seems like this is a cya, Section 230 protection in disguise. There has been more discussions about Big Tech and 230, and this is one way to say "Look, we are compliant on our platform. Don't remove our protections or break us up, we are your friend!"

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#235
post #139

Unpopular opinion: I think the outrage over this is quite overblown. This kind of hash checking is done by damn near all cloud providers - Google Photos, Dropbox, Gmail, Discord, Reddit, OneDrive, Facebook, Twitter, you name it. Apple have actually been very reluctant to implement this. If you don’t like it, you don’t need to enable iCloud Photos. In the exact same way as if you don’t want your images scanned by Drop…

It's being done on the local device, not just the cloud.

Why does it matter where the scanning is done, if the scans are done to the same content under the same circumstances?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#236

Earlier quoted context omitted.

Does anyone really think of Germany as "bastion of free speech"? It is one of few european countries that still have (actively used) anti-blasphemy laws[1] and laws against insulting foreign leaders[2]. [1] https://friendlyatheist.patheos.com/2016/02/27/in-rare-move-... [2] https://www.theatlantic.com/international/archive/2016/04/ge...

Fun fact, it's also the only place that I know of where you can get fined for calling a German a Nazi.

In many countries (including the US) there are circumstances where defamation law can create civil or criminal liability for such a claim, but yeah, usually not merely for stating it without certain other things also being true about the situation.

Conversely, there are cases in Germany where calling someone a Nazi would not lead to a fine. One very clear example:

Person A: [Unambiguously asserts a sincere adherence to Nazi ideology]

Person B: Did you hear that, everyone? Person A is a Nazi.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#237

Earlier quoted context omitted.

Not the OP, but by good old fashioned police work, I assume non-dragnet methods, where everybody's device isn't scanned in an automated way. So instead of sifting through a massive collection of automatically collected data, taken from a vast majority of innocent people, you'd deal with explicit reports of CSAE. You'd then be able to get a warrant to obtain ISP (and other) records, cross-reference and proceed from th…

> you'd deal with explicit reports Where would these reports come from though? Without these dragnet methods, it would seem like a very simple matter to get away with owning this kind of material.

This is a reality you have to accept. It is a simple matter to get away with owning this kind of material, dragnet method or not.

There is no point in trying to eradicate all such material and bring the number to absolute zero. It's impossible. The only way to semi-ensure this would be absolute slavery of the citizenry, which I hope is a non-goal.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#238
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

"vote with your fit" is as ineffective as taking less showers. It is a non-solution (what helps is growing less food in a desert, aligning government with the needs of most people)

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#239

I’m not sure what to think of the backlash here. I’m sure that people aren’t trying to minimize the evil of child pornography and exploitation. But anything that has the potential to stop or slow it should be fairly considered. People complaining that Apple is scanning your photos, they are already doing that. Where was this backlash when they released the memories feature? Why is scanning your photos for good pictur…

It's important not to conflate the new features. CSAM uses hashes of known photos and is only run on photos going to iCloud (turning off iCloud turns off CSAM). Photos sent to iCloud have been checked against CSAM for years on the server. The change here is moving it from server to client (which I hope is to make iCloud photos E2E encrypted).

Completely agree with your second point. All the 'what ifs' have existed forever. Either iOS users trust Apple will only do what stated or they don't. Nothing has changed.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#240
post #216

If it’s just a list or hashes, any possessor of CSAM could simply modify a few pixels to make it no-matching, no? How "flexible" is the matching? And if it is flexible, what about false positives? What if I have a pictured of my naked son on my device and I get flagged? Will the picture of my son get uploaded to the cloud "for further analysis" even though I don’t have iCloud enabled and never signed up for this? Edi…

I think it makes sense to take a step back and ask yourself if Apple, or any sensible Western company, would set up a system that could falsely flag millions of people, or even a hundred. Even without going into implementation details, it seems clear that they would not have a system that would flag standard family photos.

I wouldn't over-/underestimate the support capabilities of a big corp like Apple.

I remember the Twitter account takeover hack a year ago, which was possible only because customer support had some 2FA-bypass: https://en.wikipedia.org/wiki/2020_Twitter_account_hijacking

To prevent false-positives, who knows if they have a "review" team that takes a tiny little peek at my naked son. Do you know for sure that no such system is in place or ever will be in place? What if they do get hundreds of thousands of false positives in the future? How would they improve their system if not by reviewing the existing system with real data?

Post reply on HN