Live data from Hacker News

Apple’s new abuse prevention system: an antritust/competition point of view

blog.quintarelli.it

291–300 of 318 posts

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#291
post #88

Earlier quoted context omitted.

> It'll start with protecting children. We all want to protect children, don't we? Why do you want children abused? Are you a child abuser, what do you have to hide? To be clear, this is continued enforcement for years-old regulation. The feature is only enabled in the US where it is required. The implementation is changing from cloud-based matching (which requires photos to be readable by their cloud infrastructure)…

>E2E encrypted w two additional key release mechanisms Aka not E2E and therefore something that Cook should face a fraud charge for saying it is. Apple needs to make it true e2e yesterday, and tell the FBI that they can either approve of it, or never use an iPhone again.

I’m the one saying it is, not Apple.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#292

Earlier quoted context omitted.

It does set a terrible precedent, but it's possible this is a step towards E2E encryption on iCloud data; a way to comply with the law while preventing law enforcement from being able to subpoena other data. Apple is being its usual cryptic self about this, which is once again breeding uncertainty, but I still have hope in the end this will work out.

Again though, what is the guarantee this is only going to be used to scan data uploaded to the cloud? If Apple has the ability to exfiltrate data from a phone at whim, they lose any deniability or leverage they still have with authoritarian regimes that want all the data on a phone. It's not just a terrible precedent, it's a dangerous piece of malware.

They of course have the ability to exfiltrate data, they created the hardware and OS.

However since this is part of the opt-in iCloud photos sharing mechanism, it doesn’t appear they have started to exfiltrate data without consent.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#293
post #292

Earlier quoted context omitted.

Again though, what is the guarantee this is only going to be used to scan data uploaded to the cloud? If Apple has the ability to exfiltrate data from a phone at whim, they lose any deniability or leverage they still have with authoritarian regimes that want all the data on a phone. It's not just a terrible precedent, it's a dangerous piece of malware.

They of course have the ability to exfiltrate data, they created the hardware and OS. However since this is part of the opt-in iCloud photos sharing mechanism, it doesn’t appear they have started to exfiltrate data without consent.

>> They of course have the ability to exfiltrate data, they created the hardware and OS.

I don't in know why you're assuming they have a backdoor built in already. The whole point is that they don't, but they're going to add one.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#294
post #289
post #287

Earlier quoted context omitted.

> Under no circumstances is it justifiable to essentially enlist people's devices to police their owners, while using the electricity that you pay for, the internet service you pay for, and the device itself that you pay for to perform a function that is to absolutely no benefit to the user and in fact can only ever be harmful to them. This is an obvious misrepresentation. An opt-in system to detect when adults are t…

It's not a misrepresentation whatsoever. If Apple wishes to scan what's on their servers, that is their prerogative. They can use their compute resources and energy to do so. You needn't install spyware on a person's device that is of no benefit to the user. I'll reiterate, this can only ever be harmful to the user. Its utility right now is at its absolute best and most altruistic and it is still a violation of peopl…

Maybe they want to turn iCloud fully e2e, so cannot actually scan anymore on their servers.

They have to scan for CSAM by US law.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#295
post #88

It'll start with protecting children. We all want to protect children, don't we? Why do you want children abused? Are you a child abuser, what do you have to hide? Next it's elderly people. We don't want our forgetful elders to get lost, do we? What if grandma wanders off but is in someone's picture, surely you want the police to know right that second where she is? Next up, terrorists! Four adult brown men in an unm…

> It'll start with protecting children. We all want to protect children, don't we? Why do you want children abused? Are you a child abuser, what do you have to hide? To be clear, this is continued enforcement for years-old regulation. The feature is only enabled in the US where it is required. The implementation is changing from cloud-based matching (which requires photos to be readable by their cloud infrastructure)…

“ which would allow them potentially to be in compliance while making the system E2E encrypted …”

Apples system is not E2E encrypted if a local program scans files prior to upload.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#296
post #289
post #287

Earlier quoted context omitted.

> Under no circumstances is it justifiable to essentially enlist people's devices to police their owners, while using the electricity that you pay for, the internet service you pay for, and the device itself that you pay for to perform a function that is to absolutely no benefit to the user and in fact can only ever be harmful to them. This is an obvious misrepresentation. An opt-in system to detect when adults are t…

It's not a misrepresentation whatsoever. If Apple wishes to scan what's on their servers, that is their prerogative. They can use their compute resources and energy to do so. You needn't install spyware on a person's device that is of no benefit to the user. I'll reiterate, this can only ever be harmful to the user. Its utility right now is at its absolute best and most altruistic and it is still a violation of peopl…

> stealing computing resources from the device owner.

No, it is opt-in. Nothing is being stolen.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#297
post #148
post #131

Earlier quoted context omitted.

No. A registered charity called The National Center for Missing and Exploited Children controls the hash list. Yes, they are partly government funded, but I highly doubt they'd let their mission be compromised by allowing the government to inject non-CP hashes. Doing so would compromise all the work they've performed over the last four decades. These people are (rightfully) very passionate about their work and can't…

> by allowing the government to inject non-CP hashes I don't think "allowing" is the concern here, because I highly doubt they get to generate the hashes themselves.

Since they are the only ones legally allowed to possess the images, one can surmise that they must be the ones to create the hashes.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#298

Earlier quoted context omitted.

You need to stop assuming everyone is commenting out of ignorance and read up on how perceptual hashing works. It’s about as far as you can get from zero false positives, if configured otherwise it becomes just a poor version of SHA or whatever and can only detect exact matches.

At the time of my comments people weren’t discussing the fuzziness of perceptual hashing - they weren’t discussing implementation details at all. I don’t know enough about the specific implementation or perceptual hashing details and probably pushed back too hard as a result of the other comments at the time (which were comments out of ignorance). The level of downvotes I received is disproportionate to what I wrote…

Apple is obviously already scanning for CSAM for whatever non-E2E content hits their servers. With this, they offload some of the cost of computation to the end nodes but that can’t be the only reason for pushing this tech, so it’s only natural to ask why and look for avenues of exploitation. The Trojan horse/foot-in-the-door hypothesis is basically Occam’s razor.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#299
post #289

Earlier quoted context omitted.

It's not a misrepresentation whatsoever. If Apple wishes to scan what's on their servers, that is their prerogative. They can use their compute resources and energy to do so. You needn't install spyware on a person's device that is of no benefit to the user. I'll reiterate, this can only ever be harmful to the user. Its utility right now is at its absolute best and most altruistic and it is still a violation of peopl…

Maybe they want to turn iCloud fully e2e, so cannot actually scan anymore on their servers. They have to scan for CSAM by US law.

[deleted]

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#300

Earlier quoted context omitted.

I suspect that's why they have some threshold that moves the false positive rate to one in one trillion. The iMessage bit is different - it's only on device, only on child accounts, and only alerts parents. It's more akin to a parental control feature than anything else.

> I suspect that's why they have some threshold that moves the false positive rate to one in one trillion. So now instead of sending just one nice innocent very high resolution images of "Tokyo City" or something with something horrific hidden somewhere you have to send a few such images. That is reassuring. I can never believe anyone except me will think about that. (If the system is too dumb to detect this it is wo…

This would require multiple hash collisions.
Post reply on HN