Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

241–250 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#241

Earlier quoted context omitted.

Not the OP, but by good old fashioned police work, I assume non-dragnet methods, where everybody's device isn't scanned in an automated way. So instead of sifting through a massive collection of automatically collected data, taken from a vast majority of innocent people, you'd deal with explicit reports of CSAE. You'd then be able to get a warrant to obtain ISP (and other) records, cross-reference and proceed from th…

The system is basically what you describe except the explicit report is precisely what Apple send to NCMEC. By the time it gets to the police, there will be an identified crime. This has been the case for many years. I don't have the numbers to hand but I believe NCMEC receives around the order of 100 million referrals a year. EDIT: it's 20 million according to https://www.missingkids.org/ourwork/ncmecdata https://ww…

But we've already established there is no public oversight over the contents of the NCMEC database and that there cannot ever be, by design. Furthermore, it's known to contain hashes of non-CSAE images simply because they were found in a CSAE-related context.

So how can this system guarantee civil freedom? How can it be guaranteed that it won't be exploited by the small number of people in power to actually inspect it and manipulate it?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#242
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

That would be fine except an informed choice depends on accurate information, and this letter starts off saying things that are patently false.

“ Apple's proposed technology works by continuously monitoring photos saved or shared on the user's iPhone, iPad, or Mac. ”

No it doesn’t, photos just saved in the phone are never scanned by either of the systems Apple is implementing, and shared photos are only scanned in two very specific situations.

Also they avoid pointing out the iMessage aspect of this is opt in only, so it only applies to children and only if parents choose to enable it, and it's off by default.

You can completely avoid all scanning entirely by not opting in children for the iMesage scan, which is irrelevant to you if you don’t have children anyway, and not using iCloud Photo Library. Photos you keep on your phone or share using other services will not be scanned. Anyone just reading this letter wouldn't know any of that. How is this promoting informed choice?

Bear in mind the iCloud Photo Library scan is being implemented in order to meet a legal obligation. Apple is required by law to scan photos uploaded to their cloud service.

So really there are two issues here. One is the question of parental authority over optionally enabling the scan for their children’s use of iMessage. That's a legitimate concern over the privacy of children, no question.

The other is whether this is an appropriate way for Apple to comply with US law requiring scanning of uploaded images, and whether that law is appropriate. Again, entirely legitimate concerns that this letter obfuscates completely.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#243

Earlier quoted context omitted.

Does anyone really think of Germany as "bastion of free speech"? It is one of few european countries that still have (actively used) anti-blasphemy laws[1] and laws against insulting foreign leaders[2]. [1] https://friendlyatheist.patheos.com/2016/02/27/in-rare-move-... [2] https://www.theatlantic.com/international/archive/2016/04/ge...

Fun fact, it's also the only place that I know of where you can get fined for calling a German a Nazi.

[deleted]

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#244

Horrible. Apple has every right not to facilitate child exploitation, your rights be damned. Don’t like it? Don’t buy an iPhone. end of story.

Four of the top ten posts as of writing is about this issue. I'm glad people are finding something they are interested in to talk about, but at this point this issue is hardly intellectually interesting. It's like people are being forced to buy an iPhone or something.

I guess a lot of owners of Apple devices are also making use of a lot of their services/features making it hard, or at least inconvenient, costly and time-consuming to switch out i.e. vendor lock-in with open alternatives. This is why it's good to try to avoid this situation occurring in the first place. But that's at odds with how you're 'supposed' to use their devices and ecosystem and you may as well have not chosen Apple in the first place. Most people have already gone 'all-in'. Too bad when they implement something (like this) that could be used to target innocent people at some point in the future. Apple obviously don't intend it to be used in this way. But a bit like the Pegasus debacle with it only targeting criminals, it's obviously a vulnerability waiting to be exploited.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#246

Earlier quoted context omitted.

Do you have any qualms? For you does the CP protection end justify any means? Where would you personally draw the line on mass surveillance by LE for the sake of your specific LE goals? CP aside, are there other crimes that you feel should be folded-in to a dragnet like this?

You probably don't realise it, because you're coming from a perspective that has been heavily influenced in a particular way, but some of these questions are kind of insulting and don't really assume good faith (or even basic decency) on my part. > "does the CP protection end justify any means?" Like, is this legitimately a question you think I might answer "yes" to? This is the equivalent of "do you support the rape…

I apologise if you you genuinely felt my questions were assuming bad faith. It was not my intention.

> "does the CP protection end justify any means?"

It's a style of argumentation. Not personal. When trying to find where to draw a line in the sand, one way is to draw a line that almost certainly encompasses us both. We are obliged to consider: if not this line (obviously) then what line?

My intent was to find your limit. Do you have any qualms with what you may do under the law? For you personally, how much erosion of innocents' liberties would be acceptable?

Based on your earlier comment, I was not asking Apple, I was asking a LEO who acts with some but limited justification. Legal and moral. And I would like to ask in good faith about how you see those limits.

>> This is the equivalent of "do you support the rape of children?

No need to make it black and white. Almost nobody supports this. I am sure you don't. Please assume good faith on my part too. There are always trade-offs. How far would you go?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#247
post #3

Because it’s based on machine learning, why can’t some of the network and weights used for the hash be shared? So we can be sure it is not possible to match anything else than children. The sub narrow network used for detecting only CP is of course secret, but then we know it can’t be used for revealing pictures of police, activists etc

Like stated below, I’m seriously worried about Adversarial examples that fool the network into A) hiding bad pictures being not recognized B) triggering false positives on harmless pictures to discredit people. Opening up the network would mate it even easier to create the adversarials… Im not sure there is a winning position in the approach they used

Do you use iCloud photos now? CSAM checking has already been used for years (on almost all photos services btw).

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#248
post #242
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

That would be fine except an informed choice depends on accurate information, and this letter starts off saying things that are patently false. “ Apple's proposed technology works by continuously monitoring photos saved or shared on the user's iPhone, iPad, or Mac. ” No it doesn’t, photos just saved in the phone are never scanned by either of the systems Apple is implementing, and shared photos are only scanned in tw…

Probably the main issue is that every time a technology or regulation that starts like that (“you don’t need to worry if you’re not doing anything wrong”) is then inevitably expanded into repressive activities by governments around the world.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#249
post #144

Apple is forgetting the network effect of professionals that made them billionaires. I personally evangelized my clients in the past for years to switch to Apple ecosystem. In my view this is weaponization of personal devices on a mass scale with clear intent of normalization of surveillance state on a global level. The fact that this comes after NSO spyware investigation speaks volumes. They don't care about privacy…

The empowerment that you feel you once lent to Apple may no longer be part of their growth plan. Whether or not it actually mattered at the time.

The empowerment at the time was a honest and professional assessment of using MacOS X vs Windows. Apple embraced PC vs Mac marketing as I can remember.

The empowerment today is the same professional stance. Explaining the technical facts to my customers. Nobody will like the idea that their phone or personal computer will actively police on the behalf of big brother.

Serious business people don't have to "follow" tech closely. That's why they pay us.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#250
post #50

Related but slightly off-topic: am I the only one that thinks more technology is not the answer to catching crooks? Can’t the police do good old fashioned police work to catch people doing these things? Why does EVERYONE need to be surveilled for the 0.01% (or less?) who don’t behave properly. To further this point: why do we need cameras on every street, facial recognition systems and 3-letter orgs storing huge data…

Where are you hearing that cops are getting defunded? The curious should look up the budget of the NYPD and LAPD looking mighty funded to me!
Post reply on HN