Live data from Hacker News

Ask HN: What are you using to replace shared iCloud Photos albums?

news.ycombinator.com

41–50 of 111 posts

Re: Ask HN: What are you using to replace shared iCloud Photos albums?

#42
post #8

I have always used Mega[0]. It's real end to end encryption. I would argue it also has a superior user experience across all the others. [0] https://mega.nz/

Mega and Stingle are the only options I'm aware of that are "truly" private, and every other major cloud storage provider will scan your files for CSAM. The best way forward for truly privacy conscious people would be to roll their own NextCloud instance, because any public service that allows you to store E2EE images will get hunted by the Government for allowing CSAM if they reach any significant userbase. Case in point, even good ol' MegaUpload scanned for CSAM, because that's a bigger risk than getting sued by the MPAA.

Re: Ask HN: What are you using to replace shared iCloud Photos albums?

#44
post #37

I would be classified as a pedo if my pictures were on iCloud... even if some of the naked kid is me... I also have pictures of my kids playing in the bath.

No? The scanner only checks for matches against images in NCMEC's database, so you can take as many pictures of your kids as you want, it won't trip the scanner.

Considering it's a perceptual hash match, some difference is accepted. Such confidence in the infallibility of these methods usually precedes the method being used to go jail some poor innocent bastard. After all, if he wasn't guilty, it wouldn't have tripped the scanner.

Re: Ask HN: What are you using to replace shared iCloud Photos albums?

#47
post #8

I have always used Mega[0]. It's real end to end encryption. I would argue it also has a superior user experience across all the others. [0] https://mega.nz/

Mega and Stingle are the only options I'm aware of that are "truly" private, and every other major cloud storage provider will scan your files for CSAM. The best way forward for truly privacy conscious people would be to roll their own NextCloud instance, because any public service that allows you to store E2EE images will get hunted by the Government for allowing CSAM if they reach any significant userbase. Case in…

Dumb question but would an S3 bucket be scanned by CSAM?

Ehh idk seems like a dumb concern/losing battle. My thing is about IP. I picked up this e-ink tablet and it syncs to their cloud service for example. Which you can stop but still... Ahh. Just feels like going in circles, ISP knows your content, VPN, is your device actually secure, etc... Do you have anything to hide anyway.

I'm probably just paranoid ha I question using Trello putting "new IP" into it which they say is encrypted at rest so yeah. Gmail too like everything goes through that.

Anyway I'm average intelligence not developing cold fusion or something on my spare time so I don't really have IP anyway.

Here's an idea, a piece of paper and a pencil.

Re: Ask HN: What are you using to replace shared iCloud Photos albums?

#49
post #8

I have always used Mega[0]. It's real end to end encryption. I would argue it also has a superior user experience across all the others. [0] https://mega.nz/

What we need is transparent encryption at rest, where only you have the keys.

Re: Ask HN: What are you using to replace shared iCloud Photos albums?

#50

Earlier quoted context omitted.

Apple’s system design does not easily extend to checking vague subject matter. Every step of the process is tied to hashes of specific photographs. And do you seriously think they didn’t check the legality of what they built? Really?

> specific photographs That's the catch. Nothing in the system design prevents them from adding hashes of other types of photographs to that database. > And do you seriously think they didn’t check the legality of what they built? IANAL, but the law clearly states that transmitting CSAM to any party other than NCMEC is a felony. Apple != NCMEC. More info: https://www.hackerfactor.com/blog/index.php?/archives/929-On..…

“IANAL” is used to avoid liability for offering legal advice in settings where it’s not permitted. It’s not used to hand wave away that you don’t know what you’re talking about.

The very same law you’re citing describes, in detail, the good faith diligence process that requires the service provider to verify the suspected material before transmission to NCMEC. But no, some random blog and you, you two have a handle on legal analysis that the most litigiously sensitive entity on Earth must have missed while designing one of the most litigiously sensitive systems ever fielded by humans. How’d they miss felony criminal liability, right? It’s just too easy to overlook while designing a system whose sole purpose is to gather legally actionable evidence against other people.

As someone who’s built these systems for over a decade, it’s remarkable how one Apple press release can make everyone so hopelessly uninformed and confident that they know the score. Nobody used the acronym CSAM until a week ago except for people like me, those of us haunted by (actual) nightmares of this shit while HN distantly pontificates on the apparent sacrilege of MD5ing your photos of a family vacation to Barbados to see if you happen to be sharing images of children being raped.

Nobody commenting on this has ever seen child pornography. I’d take that to the bank. Did you know the organized outfits design well-polished sites like PornHub, complete with React and a design palette? 35 thumbnails of different seven year olds right on the front page, filterable by sexual situation. Filterable by how many adults are involved. With a comment section, even!, and God help you if you even begin to imagine what is said there. You’re right, though, let’s think about your privacy and the criminal liability for Apple for taking action on something that clearly doesn’t matter to anyone except those stuck with dealing with it.

Get real. Sometimes the lack of perspective among otherwise smart people really worries me, and this conversation about Apple’s motives for the last week or so has worried me the most yet.

Post reply on HN