Live data from Hacker News

Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

crypto.stackexchange.com

81–86 of 86 posts

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#81
post #46

Earlier quoted context omitted.

It’s very muddy, though. The number of pictures on one’s hard drive is irrelevant to the fact that a child has been abused or not. In your example, none of the children would have been abused. Also, who gets to define how much “a lot” is? We can’t say that it’s ok if it’s your children (or grand-children’s, or nephews, etc), because most of child abuse cases involve close family members or close friends. We definitel…

That is correct. The children within the images that are classified as CSAM don't necessarily have (though frequently are) to be abused. For example, the NCMEC database contains hashes for Nirvana's Nevermind cover. Completely innocent to possess within it's original and intended context. I have not said whether I agree with this, because I do see problems when automating the process. However, the precedent for it be…

> I have not said whether I agree with this, because I do see problems when automating the process.

The process will never be fully automated, regardless of what they say. Cases will need to be reviewed. Things will need to be checked at some point.

They are trying to play the cog in the machine, that mechanically transmits information to law enforcement. But if we’ve learnt anything the last decade is that cogs are not impartial and can be very dangerous, if only because of the scale at which they operate. I can see several ways a user can face a kafkaesque uphill battle to prove their innocence. In several countries, just a child pornography case can be a social death sentence. And even a fraction of a percent of mistakes will mean millions of people might be dragged in this (let’s not kid ourselves: this is never going to stay in the US).

Personally I think (what Apple is doing) is misguided and ripe for abuse. I am very disappointed that they, of all companies, are pushing this nightmare.

> As to who decides what constitutes significance? That is where you'll hit the most problems, and reasonable discussion of it will be quickly shut down with the same arguments used for automating a flagging system. The conversation requires nuance, but those currently calling for such systems aren't interested in a good faith discussion.

Ultimately, a tech company has no business making this sort of decisions. This is something that needs to be sorted out by law.

Unfortunately, a nuanced discussion is very unlikely these days. Anyone looking not agressive enough will be pilloried.

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#82
post #66
post #7

Earlier quoted context omitted.

What is the difference between CP and CSAM and why is everyone suddenly using the term CSAM instead of CP?

CSAM indicates you think the material, and the practice of making it, is abhorrent. "Child porn" is something some (severely deranged) people might actually want to see. The upshot of this is, if you put "ios child porn detection features" into Google, Google will see "child porn" and may think that's what you're searching for, put up warning banners reminding you that child porn is super illegal and that you should…

What stops google from monitoring for “CSAM” as well? Security through obscurity (“if Google doesn’t know about the term, they won’t report us!”)

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#83
post #66

Earlier quoted context omitted.

CSAM indicates you think the material, and the practice of making it, is abhorrent. "Child porn" is something some (severely deranged) people might actually want to see. The upshot of this is, if you put "ios child porn detection features" into Google, Google will see "child porn" and may think that's what you're searching for, put up warning banners reminding you that child porn is super illegal and that you should…

What stops google from monitoring for “CSAM” as well? Security through obscurity (“if Google doesn’t know about the term, they won’t report us!”)

Social dynamics. The kind of person who calls CSAM CSAM is unlikely to favor it, let alone distribute it, so people interested in it are unlikely to search for it by that name.

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#84

Earlier quoted context omitted.

That does seem like an interesting protest vector, though. Generate a bunch of images that match CSAM images but are mundane. Then have everyone download them and send them to their cloud. Someone then needs to spend resources determining that the images are _not_ actual matches. Basically, a DDOS attack on the functionality.

Indeed, that thought occurred to me as well. It's a risky bet, though: if somehow that intermediate layer fails and you find yourself locked up and accused of storing/disseminating CSAM material, it's not like the civil rights era when your friends and neighbors (and hopefully employers) will understand you've been arrested for a peaceful protest.

The smarter, if potentially less ethical solution is to encode such images and make memes with them. One of them going viral is likely to flag an enormous number of people along the way.

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#85
post #47

Earlier quoted context omitted.

Much of the discussion is about how trivial it would be for Apple to start scanning any photos on the phone at a later date. Right now they are able to bill this as doing what they currently do server side, but client side. Later, they can say they are simply applying the same "protections" to all photos instead of merely the ones being uploaded to iCloud.

They can do it already. System is full black box, and all we have is their word. So, saying that adding something might enable something else, is not strong argument.

By that logic we may as well never question anything any of these companies - or even governments really - do because they might just find a way to do it secretly and maybe nobody would ever figure it out.

Re: Apple's New CSAM Protections May Make iCloud Photos Bruteforceable

#86
post #7

Earlier quoted context omitted.

What is the difference between CP and CSAM and why is everyone suddenly using the term CSAM instead of CP?

Good link to explain why "CSAM" is being used in lieu of "CP" https://www.adfsolutions.com/news/what-is-csam > However, the phrase “child pornography” is almost too sterile and generic to properly exemplify the horrors of what is being created. That is why many advocates, including the National Center for Missing and Exploited Children (NCMEC), believe this phrase to be outdated. > NCMEC refers to these kinds of mate…

>Furthermore, children are re-victimized every time a file is shared, sustaining the abuse in a continuous loop.

I've seen this argument many times, and I agree that initial act is horrendous of course, but I believe this is overstating the ongoing damage.

Post reply on HN