Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

301–310 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#301
I think that the used technology described in CSAM Detection Technical Summary (the so called NeuralHash) is a really bad idea, basically it uses the output of a neural network (likely a CNN) trained using the now classical triplet loss (see page 5). The problem with those methods that they are not always reliable, for instance the same type of networks and same training procedure is used in neural face recognition that proved to be vulnerable (A recent example is the 'Master Faces' That Can Bypass Over 40% Of Facial ID, etc).

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#302
post #153

https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni... Apple uses sophisticated cryptography to make absolutely certain that you cannot hold them accountable for abuses of this system against you, NONE of which are prevented by its complex construction. The private set intersection is an alternative to sending you a list of bad-image hashes which uses significantly more bandwidth than simply sending you the…

The existence of Spyware Engine is a problem, not technical details of how current version suppose to work . Suppose to work because we have not idea what it will do. Did you see the source code? We are not that naive to believe for a second that this Spyware Engine will do what is claimed. This is simply viewed as calculated attempt to legalize Spyware Engine on a personal device covered by some bs story intended to…

No, the existence and non-existence of a spyware engine doesn't constitute a problem. These companies spend billions of dollars, paying thousands of engineers a year, to develop solutions to problems that often don't even exist. It's safe to say that the sheer scale of every one of these tech companies means that this isn't something that incrementally gets worse, within a 6 month sprint they could push an update overnight going from step 0 to step 5 of total spyware.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#303

Earlier quoted context omitted.

> a non-insignificant amount of people in tech take this seriously We're all here to make ourselves feel good saying we Took A Stand. In reality, four weeks from now, do you think anybody will still be talking about it? I made this same mistake. I was pretty convinced that people were taking Copilot seriously, and that there was possibly going to be ramifications for Microsoft. I wasn't particularly looking forward t…

[flagged]

These companies are just pseudo-departments of governments. They are working together on this rubbish

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#304
post #184

Earlier quoted context omitted.

For what it's worth, police funding in US rivals and exceeds military funding of other countries.

Asking in earnest: are you speaking in absolute terms or relative terms? That is, does the percentage of funding (as compared to the rest of the budget) exceed most other countries’ military funding, or just the absolute amount?

Absolute.

Today, the U.S. collectively spends $100 billion a year on policing and a further $80 billion on incarceration.

Just the spending on policing is larger than what other countries spend on military. Actually, the only country that spends more on military is China [1], after taking in incarceration costs, it is 2.5 times the military expenditure of India.

[1] https://www.sipri.org/publications/2021/sipri-fact-sheets/tr...

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#305
post #175

Earlier quoted context omitted.

The existence of Spyware Engine is a problem, not technical details of how current version suppose to work . Suppose to work because we have not idea what it will do. Did you see the source code? We are not that naive to believe for a second that this Spyware Engine will do what is claimed. This is simply viewed as calculated attempt to legalize Spyware Engine on a personal device covered by some bs story intended to…

I agree with you, but if you'd take the time to read my post you would see that I am arguing that it's not good even by their own claims! They talk a lot about complex crypto to protect privacy but the primary thing it's doing is hiding what apple is matching against, which shields them against accountability. I fully agree that even if the behavior were currently threading the needle it would still be an extremely b…

> They talk a lot about complex crypto to protect privacy but the primary thing it's doing is hiding what apple is matching against, which shields them against accountability.

NCMEC partners are not allowed to share the raw hashes, and I imagine Apple's contract with NCMEC to create a photo-comparison tool that will have auditable code (well, compiled code, but still) includes such a provision to slow or stop CSAM sharing enterprises from completely reverse engineering and cheating the system.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#306
post #63
post #46

Earlier quoted context omitted.

They said FOSS, not OSS. F means free as in freedom. As in you’re free to modify the software running on your phone at will and to your liking and Apple or some government can’t get in your way.. not even for the kids .

So all 12 people in the world who know how to read, modify and install and OS can run their paranoid versions of iOS?

Just buy a device with it already installed, Calyx and Fairphone offer these for instance.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#307
post #187

Somewhat offtopic, but the subject caused me to make a disappointing realization: The most sure way for someone to obtain child porn images that won't trigger a hit in these known child-abuse-image databases would be for someone to take new photos. Is there a reason we can be confident that these databases aren't creating a market for novel child abuse at a greater rate than they're taking abusers out of the communit…

Or if it's just a simple hash, change a single, impercetible pixel in the photo.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#308

At this point we need to be doing more than signing open letters to companies that are completely free to ignore them. If you work for Apple and don't stand up to this, you should find it extremely hard to find employment or acceptance anywhere. If you're a hiring manager, throw the resumes of anyone that worked at Apple in the trash. It should be a black mark on you if you continue to work and contribute to Apple af…

People have asked of this for Facebook employees for years, with little effect.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#309
post #96
post #87

So, if I understand correctly, the NCMEC provides a bunch of hashes of CSAM for Apple to match. This way Apple doesn’t get exposed to the content of images themselves? Then Apple will provide a user’s details plus the IDs of matching content. This identifies the direction of travel for any CSAM content? So, now NCMEC and any local NCMEC can provide new hashes and identify – possibly even historically – the epicentre…

NCMEC's database already contains non-CSAM. What you suggest is not theoretical, it's reality today. I really think people are missing this point. NCMEC's database is not an infallible, audited and trustworthy source of despicable imagery. It's a mess contributed to by thousands of companies, individuals and police. It's also so intertwined with the FBI that I don't think it's truly correct to call NCMEC independent,…

> What you suggest is not theoretical, it's reality today.

As others have stated, do you have proof? Inside knowledge of this supposed reality? Even some major news publication with no direct evidence would be credible enough to support this statement.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#310
post #269

Notice, for example, that Thunderbird is sending file names and SHA-256 hashes when you open most (e.g. .pdf) attachments, in the clear, to Google. This seems worse to me (in the Apple case, the information is revealed only if enough files from one device match against a predefined hash list) and nobody really cares... I have just tested with a fresh profile with a freshly downloaded thunderbird-78.12.0.tar.bz2 (x64…

At least mozilla lets you disable that, does apple?

after seeing recent events around mozilla, I suspect they would not allow disabling that if they could get away with it

(don't get me wrong, "everybody sucks")

Post reply on HN