Live data from Hacker News

Messaging and chat control

patrick-breyer.de

291–300 of 336 posts

Re: Messaging and chat control

#291

Earlier quoted context omitted.

But the point is there’s an existing database. Either you have a photo in that database, or you don’t. So your kids naked photos don’t get triggered. And even if that photo is legal, not only is there human verification and minimum quantities required, it would be very strange for you to have in your iCloud photos that were part of CP collection sets regardless of content.

Their point was CSAM means especially bad CP. Your points were different. It's a perceptual hash. Matches don't have to be exact. And people have engineered collisions for other perceptual hash algorithms. What a computer sees and what a person sees can be very different. People have said the human verification just involves the visual derivative of the suspect image. Apple didn't explain what that is really. And hum…

Sorry. Either the posts got updated or I got the thread confused as others were trying to say that (re: hash versus classifier).

Re hashing, Apple claims 1:1 trillion likelihood of a collision. These kinds of systems are not rolled out lightly, and even if that number is wrong, it’s feels unlikely to me that it’s too far off. If it is and it has too many false positives, this will get noticed and the system pulled until it’s fixed and at the required false positive rate.

Ultimately beyond Apple if you’re getting arrested and confront a judge, you’d expect humans at that point to look at the evidence. In fact, I’d expect the DA or whomever to similarly look at the photos at that point. You can’t be sentenced without evidence in the US legally (how all of this works in another country is another matter).

If there is legit porn that’s 18+ mixed in this database, and someone ends up being charged because of it, fights, and wins, I’d expect a number of counter lawsuits to follow. To me it seems incredibly unlikely that non-CP is not only going to be a significant part of that database (including 17 year olds versus the more likely 7 year olds), but you’ll be saving it to your iCloud photo roll. There’s so much legal porn out there, in such vast quantities, this hypothetical situation you describe I’m not sure will ever actually occur.

Re: Messaging and chat control

#292

Earlier quoted context omitted.

Yes it's absolutely hyperbole to compare the racist policy of apartheid to reasonable restrictions on people who voluntarily choose to avoid vaccines for mostly-nonsense reasons. Do you also oppose driver's license restrictions? Or existing pre-covid vaccine requirements? I struggle to see how these new restrictions are so onerous.

Equating drivers licenses to vaccine passports is a false equivalency.

Why? Drivers' licensing makes people safer on the roads, vaccines make people safer in crowded indoor spaces.

Re: Messaging and chat control

#293
post #254

Earlier quoted context omitted.

Whenever a politician invokes "think of the children", ask them about their funding of Child Protection Services. Any political action that's said to be under the umbrella of "think of the children" that doesn't provide additional funding to existing Child Protection Services is for reasons other than child protection. Additionally, it's actively working against helping children because the funds for "this new thing"…

> Of course, removing children from danger is often removing them from their parents / legal guardians, which comes with its own set of risks. What number of false positives would you tolerate?

I genuinely do not know the answer. But also, what would you define as false positive?

It's blurry definitions all the way down, and that's part of the reason politics doesn't like this problem and would rather argue technology and punishment after-the-fact than actual protection / prevention.

Nuance is expensive and doesn't play well to the crowd.

Re: Messaging and chat control

#294
post #98

The scary thing about this is that many people have images that look like child porn at home: Family photos of naked grandchildren playing at the sea or in the mud, as well as sexting between consenting teenagers. There is no way automatic classification can distinguish these from real child porn, because they look almost identical and thus many private pictures will be shared with the government. This not only infri…

"Child porn" is a smokescreen. It's what every privacy advocate saw coming: find the worst, most repugnant thing possible and use it to backdoor encryption. It's not a dream, and it's really happening, right now.

CSAM is still problematic, though. The consensus is that creates a market that incentivizes the abuse of children, because you cannot produce CSAM without CSA. It seems to be the one of the few classes of data that is an exception to the standard of privacy that is applied to almost all other data, to the point that Apple took action against it. Dozens of other countries besides the US also agree, and outlaw that class of data as well. Finding actual CSAM (and not just any kind of pornography involving minors, hence the shift in terminology) is supposedly directly tied to finding child abusers, thus preventing future child abuse from taking place.

There appear to be few to no studies that give statistical evidence for the market hypothesis or that the spread of CSAM causes CSA. But even if they existed, I still think the argument would ultimately become "letting one more child abuser get away because we preserved our privacy instead." How can such an argument be challenged, given that the prevention of CSA is a legitimate problem on a global scale? Even so much as mentioning an argument that takes into consideration the nature of CSA appears to be taboo - and for good reason, as it carries a risk of being labeled many kinds of terrible things oneself. That seems to be why a lot of threads here are reducing the issue to "think of the children" or lambasting the potential slippery slope of authoritarian surveillance, instead of discussing why CSAM is outlawed to begin with, and thus the reasons why Apple came to this decision in the first place.

Another thing that nobody seems to talk about is that Apple doesn't want to be held liable for CSAM stored on their servers, either. Within that context, this change is Apple's way of addressing that issue, which also happens to erode individual privacy. Apple's values appear to dictate that the tradeoff is worth it in the end. About the only people that have pushed back on this change come from technology or privacy-conscious circles. Nobody else seems to care. That is the status quo, and I'm not sure how it's going to change with general public sentiment the way it is surrounding CSA.

Re: Messaging and chat control

#295

Earlier quoted context omitted.

"Child porn" is a smokescreen. It's what every privacy advocate saw coming: find the worst, most repugnant thing possible and use it to backdoor encryption. It's not a dream, and it's really happening, right now.

CSAM is still problematic, though. The consensus is that creates a market that incentivizes the abuse of children, because you cannot produce CSAM without CSA. It seems to be the one of the few classes of data that is an exception to the standard of privacy that is applied to almost all other data, to the point that Apple took action against it. Dozens of other countries besides the US also agree, and outlaw that cla…

UnaDavidsonVKw@yahoo.com

Re: Messaging and chat control

#296
post #254

Earlier quoted context omitted.

> Of course, removing children from danger is often removing them from their parents / legal guardians, which comes with its own set of risks. What number of false positives would you tolerate?

I genuinely do not know the answer. But also, what would you define as false positive? It's blurry definitions all the way down, and that's part of the reason politics doesn't like this problem and would rather argue technology and punishment after-the-fact than actual protection / prevention. Nuance is expensive and doesn't play well to the crowd.

If I take a picture of my adorable toddler playing naked in a sprinkler in the backyard and CPS calls that child porn and takes him away from me, that's a false positive.

I don't know much about abusers, but my hunch is that they know they are abusers and will more-or-less accept being caught. But what I know about non-abusive parents is if you take their kids away, it's war.

Re: Messaging and chat control

#297
post #261
post #98

The scary thing about this is that many people have images that look like child porn at home: Family photos of naked grandchildren playing at the sea or in the mud, as well as sexting between consenting teenagers. There is no way automatic classification can distinguish these from real child porn, because they look almost identical and thus many private pictures will be shared with the government. This not only infri…

Not a lawyer, but my understanding is that in the States, sending naked pictures of teens is illegal, even if it's a picture of yourself. If you send naked selfies to someone, you could be charged with distribution of child pornography if you are a teenager. I'm also fairly sure I heard that even possessing naked selfies is considered illegal, at least in some states, e.g. this article about a teenager facing 10 year…

> A Fayetteville, North Carolina teenager has reached a plea deal to avoid being charged with multiple sexual exploitation counts after his cell phone was found to contain nude selfies of himself. Seventeen-year-old Cormega Copening, who took the photos of himself when he was 16, agreed to the deal in order to avoid possible jail time and being registered as a sex offender. As part of the plea, the teen agreed to random police searches without warrant for one year as well as other penalties, Fusion reports. The teenager was listed as both the victim and the perpetrator on the sexual exploitation charges.

This is quite possibly the most kafkaesque "justice" story I have ever heard coming out of America and that really says something.

Re: Messaging and chat control

#298
post #285
post #277

Earlier quoted context omitted.

Please keep name-calling and personal attacks out of your comments here. https://news.ycombinator.com/newsguidelines.html

Exactly where is this name calling? Please unflag this so we can continue the discussion.

"Hold your horses" and "put down the pitchforks" count as name-calling in the sense that the HN guidelines use that term, because they are swipes that don't reply to the actual argument. Ultimately they're just putdowns. Please omit those from your posts to HN.

https://news.ycombinator.com/newsguidelines.html

Re: Messaging and chat control

#299
post #231

Earlier quoted context omitted.

That experiment shows that whatever is stored on ProtonMail's servers plus your password is sufficient to decrypt your emails. This could be explained by the private key being derived from or encrypted with your password. ProtonMail's documentation says it's the latter ( https://protonmail.com/support/knowledge-base/how-is-the-pri... ): > Your ProtonMail private key is generated in your browser. Before sending the pr…

The most likely attacker against proton mail are various law enforcement or intelligence agencies. Such agency can force PM to modify login process to derive password from submitted form, or to just switch private keys for non-encrypred ones, because the user won't even notice it. Truly secure entity just wouldn't have private keys on a server at all . Users would have to go through an an uncomfortable process of gen…

> Truly secure entity just wouldn't have private keys on a server at all.

They don't. They have your encrypted private key, but there's no need to keep that secret. (The decryption key is derived from your password, so the password needs to be strong and secret.)

> Such agency can force PM to modify login process to derive password from submitted form, or to just switch private keys for non-encrypred ones, because the user won't even notice it.

Yes, definitely. It's hard to trust self-updating software (like JavaScript in the browser), particularly if you're concerned about targeted attacks. But creating your own private keys and then entering them in the browser wouldn't help you at all against that sort of attack. You would instead need a different type of client that could be trusted somehow not to leak your private key.

It's not uncommon for services like this to offer a downloadable version of the web client so you can pin a version and audit the code as needed. I think maybe https://github.com/ProtonMail/WebClient is that for ProtonMail? If so, you should be able to verify that code and then use that. The fact that an encrypted copy of your private key will live on ProtonMail's servers shouldn't bother you.

Re: Messaging and chat control

#300

I voted Remain in the EU referendum here in the UK but, in 2021, a few things have happened that have caused me to question whether that was the right choice and whether, with Brexit, we have the right outcome (albeit for very much the wrong reasons seen through 2016 eyes): 1. Ursula von der Leyen and the EU Commission bullying companies and non-EU countries about vaccine production and provision. A wider point here…

Also, one wonders if EU states would have been better at closing their borders at the start of the pandemic (like Australia or New Zealand did) if it wasn't for the EU. Maybe not, because there are always big trade networks on a landmass on this size, but I do think that the 'free movement' ideology played a part as well. (Free movement is wonderful in general, but why in a pandemic??)

> Also, one wonders if EU states would have been better at closing their borders at the start of the pandemic (like Australia or New Zealand did) if it wasn't for the EU.

It's a fair question. OTOH, here in the UK, we were extremely slow to close our borders (in fact we've never closed our borders fully in the way that say Australia or NZ did, nor anything close), with the justification being that the UK is an international hub.

The real reason, of course, is that our government is too spineless and inept to take such decisive action, and has the collective intellect of a colony of woodlice.

I don't know enough about the EU decision making process around closing borders to know if their bureaucracy was a problem. I know Italy introduced restrictions fairly early on (back in February, or maybe early March 2020), but I do remember being surprised that people were still allowed to cross the border between Switzerland and Italy for work purposes even whilst the pandemic was raging in Italy. (Switzerland isn't in the EU, obviously.) I also remember being surprised that ski resorts such as Aprica, in Italy, were still open as late as the beginning of the second week of March in 2020.

The UK is very densely populated, particularly in south east England, compared to many countries, so risk of accelerated transmission is and always has been considerably higher. We also have an ageing population with a history (at a population level) of making poor lifestyle choices who have accrued a significant burden of pre-existing medical conditions (not unlike the USA), with the distribution across the whole of the country not entirely mirroring population density. Again, this increases the severity of COVID for those who fall into affected demographics.

With that being said, I have no doubt that more decisive measures earlier in the pandemic, more consistently applied throughout the pandemic, would have led to a significant reduction in both the human and economic costs of the pandemic in our country.

I would like to see Boris Johnson and his cadre of fawning, useless imbeciles stripped of their citizenships and banished to a frozen wasteland to endure an existence of hard labour for the rest of their natural lives. Their abject failure to step up and lead in the face of the greatest challenge we have faced since WWII - to discharge their most basic responsibilities to the people of this country - absolutely disgusts me.

I accept that I am likely to be disappointed.

Post reply on HN