Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

751–757 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#751

Earlier quoted context omitted.

You can’t do a byte-for-byte hash on images because a slight resize or minor edit will dramatically change the hash, without really modifying the image in a meaningful way. But image hashes are “perceptual” in the sense that the hash changes proportionally with the image. This is how reverse image searching works, and why it works so well.

Sure, I get how it works, but I feel like false positives are inevitable with this approach. That wouldn't necessarily be an issue under normal police circumstances where they have a warrant and a real person reviews things, but it feels really dangerous here. As I mentioned, any accusations along these lines have a habit of sticking, regardless of reality - indeed, irrational FUD around the Big Three (terrorism, pae…

There is also a number of flagged pictures to reach before an individual is actually classified as a "positive" match.

It is claimed that the chance of being a false-positive for a positive match is one out of a trillion.

> Apple says this process is more privacy mindful than scanning files in the cloud as NeuralHash only searches for known and not new child abuse imagery. Apple said that there is a one in one trillion chance of a false positive.

https://techcrunch.com/2021/08/05/apple-icloud-photos-scanni...

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#752

Earlier quoted context omitted.

> And then take what actions, exactly? Don’t buy or use their products.

And perhaps more importantly: don't develop for their products.

but... but the app revenue from all the same iSheeple who are given up their privacy...

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#753
post #690

Earlier quoted context omitted.

Linux kernel AFAIK has less security issues than Apple. Qubes even less. Not sure what the reason for your insult is.

No insult. You actually don’t know that the Linux kernel has less security issues than Apple’s kernel. But the kernel is only a tiny fraction of the system. There simply is no Linux system that even attempts to solve the problems Apple solves. There could be, but there isn’t - this is what we mean by the term ‘wishful thinking’.

> You actually don’t know that the Linux kernel has less security issues than Apple’s kernel.

You are speaking as if you know the opposite. Any links?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#754

Earlier quoted context omitted.

The NCMEC hash list is private, and adversarial attacks require running gradient descent and being able to generate a hash value for arbitrary input.

At least one of these two things must be true: either Apple is going to upload hashes of every image on your device to someone else's server, or the database of hashes will be available somehow to your device.

Turns out there's a third option I wasn't thinking about: private set intersection.

https://news.ycombinator.com/item?id=28097683

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#755

Earlier quoted context omitted.

No one here has a problem with the worst criminals being taken out. The problem is the scope creep that always comes after. In 2021 and 2020 we saw people being arrested for planning/promoting anti lockdown protests. Not for actually participating but for simply posting about it. The scope of what "harmful content" is is infinite. You might agree that police do need to take action against these people but surely you…

We also saw HN shadow banning entire IP CIDR blocks because they didn’t like argument against fleeting CDC guidance that was put forth or the Chinese lab origin theory in 2020. You can’t register from these CIDR blocks. If you had an account before the comments would just end up in a black hole. Dang can explain.

That is false. So was your other false claim that I replied to (https://news.ycombinator.com/item?id=28093879).

Please stop creating accounts to break HN's rules with.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#756
post #748
post #570

Earlier quoted context omitted.

The first ( and only ) way to solve any problem is to first admit it is a problem. It doesn't even need to be an "action". You will have to be at least conscious of what is happening. That is not what is happening, right now ( or before that ) many are defending Apple, and also an attitude of not "my problem". Writing off any warning as either pessimistic or conspiracy. Having some healthy dose of skepticism is somew…

Yeah I think a lot of us are conscious of the problem but you're right, the scale/critical mass isn't quite there yet hmm. BTW I think one of the roots of our problem is that we seem to end up in these really weird "winner take all" distributions with only 2-3 main winners and rarely any serious alternatives. It happens with operating systems, browsers, it also happens within programming language communities, like Ja…

Well that's because the more people use the thing, the easier it is to find solutions for issues with said thing. Looking up a way to do routing in react is way easier than looking it up for a framework with a 100 users.

Issues are also being found way faster simply due to a bigger user base.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#757
post #624

Earlier quoted context omitted.

Or maybe the web is getting too bloated? https://idlewords.com/talks/website_obesity.htm

Those two things aren't mutually exclusive.

But only one of those things is relevant to the discussion.

Hint: the relevant thing wasn't to do with my laptop.

Post reply on HN