Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

261–270 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#261
post #2

I signed this, but I'm very doubtful this will ever achieve something. But this made me wonder: is there an history of people complaining about this sort of things and actually achieving something? I think this might have happened with MSFT's hailstorm/passport, where in the end industry opposition meant the project was abandoned, but I can't recall other instances.

Not in a sense of "signed letter", but more like a "huge feedback". Six years ago MSFT planned to reduce free storage for existing OneDrive users to 5GB (after bumping it to 15GB + 15GB of Camera Roll bonus) [1]. Like other users, I was unhappy as I have been using OneDrive with the promise of bigger storage than Google.

Sure enough, over 72k votes at OneDrive's UserVoice [2] cause MSFT to back down. They still reduce the storage to 5GB, but existing users (myself included) can opt out of it.

[1] https://www.theverge.com/2015/12/11/9890966/microsoft-onedri...

[2] https://onedrive.uservoice.com/forums/262982-onedrive/sugges...

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#262
post #60
post #50

Related but slightly off-topic: am I the only one that thinks more technology is not the answer to catching crooks? Can’t the police do good old fashioned police work to catch people doing these things? Why does EVERYONE need to be surveilled for the 0.01% (or less?) who don’t behave properly. To further this point: why do we need cameras on every street, facial recognition systems and 3-letter orgs storing huge data…

>One thought: is it because over 10, 20, 30+ years the police have been de-funded everywhere Police funding has shot up in America. It's everything else thats been cut. >what’s the problem. There's no problem. It's just a drawn out power grab with a weak pretext.

> Police funding has shot up in America. It's everything else thats been cut.

What else in America has been cut? I'd be interested in that very long list (since you're saying that everything else is seeing cuts; the understood meaning being that a very large number of major items are seeing their budgets slashed). The spending data I see year in year out, or across decades, is showing the opposite.

Healthcare spending has skyrocketed over the last 20-30 years, including healthcare spending by the government (eg Medicaid, Medicare). They're not slashing Medicaid or Medicare, those programs have far outrun inflation and are drowning the US budget.

Social Security hasn't been slashed. Even the leading Republicans no longer dare talk seriously about cutting Social Security (30-40 years ago they commonly did). Trump could hardly run away faster from that conversation, it's the third rail of US politics, absolutely nobody dares.

Education spending has not been slashed. US teachers are among the best paid in the world and Americans spend more per capita on education at all levels than just about any other nation (while getting mediocre results for their epic investment, as with healthcare spending).

Defense spending of course continues to rise.

The US welfare state has continued to perpetually expand. US social welfare spending is larger as a share of GDP than it is in Canada; and it's closing in on Britain (the US will catch Britain on social welfare spending as a % of GDP this decade). The US social safety net has gotten larger, not smaller, over the decades. Programs like housing first didn't even exist 30 years ago; food security programs like SNAP continue to get bigger over the decades, they're not vanishing.

US Government spending has continued to soar year by year. Typically 5-8% annual spending increases are normal (just look at the radical spending increases during the Bush and Obama years, or any of the recent budgets). Total government spending (Federal + State + Local) has continued to climb, it has not been slashed or reduced. Total US government spending is taking more out of the US economy than it ever has outside of WW2 - you have to go back to WW2 level spending to find something comparable.

Total US government spending has increased by roughly 225% over the past two decades (more than triple the rate of inflation over that time). The soaring spending shows no sign of letting up.

The major US Government agencies - such as NASA, NSA, FBI, DHS, VA, DoJ, etc - have not had their budgets slashed over the last few decades, they keep climbing year after year.

The only big one I can think of is infrastructure spending, which has not kept up with inflation because both sides have refused to raise gasoline taxes.

What kind of results do we have to show for the massive increase in government spending? Are our streets now lined with gold? Things are better than they have ever been, is that right? Is our quality of life equivalent to Switzerland, Norway, Denmark, Sweden? Because we now have their per capita government spending levels. The government systems of the US are spending the equivalent of 45% of the economy each year.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#263
I kind of stopped after:

>fundamental privacy protections for all users of Apple products.

Users of Apple (should and largely do) accept they are not in control. Apple has always been clear this is a feature not a bug.

This is the logical next step to justify that their lock-in/monopoly has unique features beside making them more money.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#264

Earlier quoted context omitted.

Maybe it does not seem a reasonable price to you, but for people who don't know, the HiFive Unmatched [1] sells for 679$ [2]. This is the most powerful RISC-V platform you can buy today. It comes as a Mini-ITX board including 16Gb of DDR4 ram, 1Gbps ethernet, usb 3.2, PCI Express and NVMe. Of course it is less powerful than an x64 machine at the same price point, but it should work reasonably well when paired with an…

I find it weird how none of these links state the CPU frequency prominently (or at least I didn't notice it). Not even the product sheet has it.

On another hand, I don't remember the last time I was interested in a CPU's frequency. In isolation it gives no insights about the performance of a CPU, not even single-threaded performance. Even with the exact specs I wouldn't know how to interpret them, and I doubt many people would.

Nowadays I just check the benchmarks of a CPU to have a rough idea of it's performance.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#265
post #105

Earlier quoted context omitted.

Can’t speak for everybody of course, but I am currently planning the migration away from the Apple ecosystem and I’m heavily invested (watch, phone, MacBook, Mac Pro, Apple TV). I’ve also been recommending to friends and family to move to droids with microG. The largest concern I have for them is that they’re stuck between the devil and the deep blue sea. Most people aren’t going to run a droid without google, or Lin…

> I am currently planning the migration away from the Apple ecosystem Me too. I told my wife today that I'll be looking at a feature phone as I'm not sure I can be bothered with jumping through all the hoops required to de-Google an Android phone. I remember a time before mobile phones, I was just fine without one - smartphones aren't that good, just convenient.

I suspect it might be more effective to go to an Apple store and attempt to return your iphone and iPad (though probably they are outside of return windows.)

I’m seriously considering doing that. Make it painful for the local staff by demanding a refund. Don’t take no for an answer for quite some time. Explain that they just broke the product with a remote update that you had no choice in, so thats why you’re only returning it now. When they ask how it broke explain that they started scanning all your content, thereby claiming it as their own. If they want to own the phone, then they need to buy it back. Etc.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#266
post #105

Earlier quoted context omitted.

Can’t speak for everybody of course, but I am currently planning the migration away from the Apple ecosystem and I’m heavily invested (watch, phone, MacBook, Mac Pro, Apple TV). I’ve also been recommending to friends and family to move to droids with microG. The largest concern I have for them is that they’re stuck between the devil and the deep blue sea. Most people aren’t going to run a droid without google, or Lin…

> I am currently planning the migration away from the Apple ecosystem Me too. I told my wife today that I'll be looking at a feature phone as I'm not sure I can be bothered with jumping through all the hoops required to de-Google an Android phone. I remember a time before mobile phones, I was just fine without one - smartphones aren't that good, just convenient.

The thing is, people who are young enough to not live in the time without mobile phones will have no recourse.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#267
post #153

https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni... Apple uses sophisticated cryptography to make absolutely certain that you cannot hold them accountable for abuses of this system against you, NONE of which are prevented by its complex construction. The private set intersection is an alternative to sending you a list of bad-image hashes which uses significantly more bandwidth than simply sending you the…

> The private set intersection is an alternative to sending you a list of bad-image hashes which uses significantly more bandwidth than simply sending you the list. How can the image hashes take up more space than the images themselves? Are you sure about this?

That’s not what they wrote, double check your comprehension.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#268
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

> a non-insignificant amount of people in tech take this seriously We're all here to make ourselves feel good saying we Took A Stand. In reality, four weeks from now, do you think anybody will still be talking about it? I made this same mistake. I was pretty convinced that people were taking Copilot seriously, and that there was possibly going to be ramifications for Microsoft. I wasn't particularly looking forward t…

>I'm not sure what to do about it

For starters, please give up the defeatist attitude. They deserve the frontlash; even if it serves no purpose, as you describe it.

Apple have placed 'Privacy' at the core of their messaging, in order to sell their high-end products. In comparison to the already excessive pearl clutching based on moral panic within the ecosystem e.g. sanitising and censoring language and apps. This is a scope-creep via thought terminating clichés like 'think of the children' and the boogeymen, which will not be enough of an explanation, when Apple ID's start getting locked out for capturing entirely innocent moments of their children's lives, or the intimate holiday snaps etc. Conversely, someone can weaponise it by sending you content that will besmirch your good name, or send you away for a stint in prison.

Nonetheless, they will be a couple of moves away from either a lawsuit/collective action or a pushback from consumers, especially when the algorithm (wrongly) labels you as paedo, porn baron or worse -- then placing you in a Kafkaesque nightmare to explain yourself.

https://www.apple.com/privacy/docs/A_Day_in_the_Life_of_Your...

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#269
Notice, for example, that Thunderbird is sending file names and SHA-256 hashes when you open most (e.g. .pdf) attachments, in the clear, to Google. This seems worse to me (in the Apple case, the information is revealed only if enough files from one device match against a predefined hash list) and nobody really cares...

I have just tested with a fresh profile with a freshly downloaded thunderbird-78.12.0.tar.bz2 (x64 Linux, en-US) using a Burp proxy. Here is the function that does it: https://searchfox.org/mozilla-central/source/toolkit/compone...

Here is the about:config tweak to turn it off: browser.safebrowsing.downloads.remote.url

Here is an example request: POST https://sb-ssl.google.com/safebrowsing/clientreport/download...

Content is Protobuf-encoded payload containing:

- full path to the mailbox including the username and "secret" random profile name (e.g. /home/jenda/.thunderbird/ioi8uk0k.tbtest/Mail/hrach.eu/Inbox)

- SHA-256 of the file

- attachment file name (e.g. 10-test-blahblah.pdf)

Post reply on HN