Live data from Hacker News

Ask HN: What are you using to replace shared iCloud Photos albums?

news.ycombinator.com

81–90 of 111 posts

Re: Ask HN: What are you using to replace shared iCloud Photos albums?

#82

Personally I don't trust anything that I don't self-host. With Hetzner I chose full-metal instead of VPS. I pay €40 for 4 TB (2x4 TB mirrored to be precise) shared among a large number of services, including Minecraft servers for kids. The load is very low and the maintenance is a pleasure. Plus I love tinkering with and learning new things, so this part of mine is fully satisfied. I learned with Hetzner that every 3…

Thanks. Some nice options. https://www.hetzner.com/dedicated-rootserver

Re: Ask HN: What are you using to replace shared iCloud Photos albums?

#84

Personally I don't trust anything that I don't self-host. With Hetzner I chose full-metal instead of VPS. I pay €40 for 4 TB (2x4 TB mirrored to be precise) shared among a large number of services, including Minecraft servers for kids. The load is very low and the maintenance is a pleasure. Plus I love tinkering with and learning new things, so this part of mine is fully satisfied. I learned with Hetzner that every 3…

Hetzner is cool unless you are in the US. Latency sucks across the Atlantic.

Depends on what you’re using it for. I set up a Matrix homeserver on a hetzner box in Finland for primarily North American users. Latency hasn’t been a perceptible problem for that.

Re: Ask HN: What are you using to replace shared iCloud Photos albums?

#85
post #27
post #8

I have always used Mega[0]. It's real end to end encryption. I would argue it also has a superior user experience across all the others. [0] https://mega.nz/

I remember meeting with KimDotCom lawyer a few years ago in SF. A very flamboyant-person. One of those guys who makes a big impression on you from the first sight. While KimDotCom is an impressive hacker, I am not sure that I would love to be the target of the FEDs around the world as he is still in the eye of the US. Fun story about MegaUpload. I once lived in Argentina back in the MegaUpload days. At the time, pira…

> Old days…

Here in New Zealand we are only just finishing tidying up the fallout from the Dotcom fiasco now. Shame on us.

https://en.m.wikipedia.org/wiki/Kim_Dotcom

Re: Ask HN: What are you using to replace shared iCloud Photos albums?

#86
post #28

Earlier quoted context omitted.

They couldn't even if they wanted. Due to the encryption

They could on device.

except if the key to its encrypted-at-rest hard drive is not used to do encrypting/decrypting on same CPU as it’s hard drive (that being, done remotely)

Re: Ask HN: What are you using to replace shared iCloud Photos albums?

#87
post #50

Earlier quoted context omitted.

> specific photographs That's the catch. Nothing in the system design prevents them from adding hashes of other types of photographs to that database. > And do you seriously think they didn’t check the legality of what they built? IANAL, but the law clearly states that transmitting CSAM to any party other than NCMEC is a felony. Apple != NCMEC. More info: https://www.hackerfactor.com/blog/index.php?/archives/929-On..…

“IANAL” is used to avoid liability for offering legal advice in settings where it’s not permitted. It’s not used to hand wave away that you don’t know what you’re talking about. The very same law you’re citing describes, in detail, the good faith diligence process that requires the service provider to verify the suspected material before transmission to NCMEC. But no, some random blog and you, you two have a handle o…

> “IANAL” is used to avoid liability for offering legal advice in settings where it’s not permitted. It’s not used to hand wave away that you don’t know what you’re talking about.

It's exactly and only the latter, actually. Consider how useful an obscure-to-normies Web-forum acronym consisting mostly of "anal" is going to be at deflecting liability—should such even be possible—if it comes up in court. Not a bit, right? So how could it be intended for that? If that were the purpose, people would write out the words.

Re: Ask HN: What are you using to replace shared iCloud Photos albums?

#89
post #68

Earlier quoted context omitted.

Checking for CSAM isn't the issue. The issue is that Apple's system design easily extends to checking all sorts of other things - political dissidents, journalists, etc. Not only that, it commits a felony when it transmits found CSAM to a party other than NCMEC (i.e. Apple itself).

> For the conspiracy to work, it'd need Apple, NCMEC and DOJ working together to pull it off voluntarily and it to never leak. If that's your threat model, OK, but that's a huge conspiracy with enormous risk to all participants. Worth reading: https://pingthread.com/thread/1424873629003702273

My threat model right now is to trust no one except (1) people I know personally, (2) people they know and trust personally, (3) people who have proved their reputation for integrity publicly, and (4) well-designed systems built by either (1), (2), or (3).

I know someone at Apple who knows their head of privacy... so #2 may be in question, given the design of this system and its capability of further compromising the privacy of millions of Chinese citizens on the Chinese government's whim (and any other strongly-authoritarian government).

Re: Ask HN: What are you using to replace shared iCloud Photos albums?

#90

Earlier quoted context omitted.

“Resemble”, in the same way that a cropped photo resembles the uncropped original.

And in the same way a human resembles a butterfly. didn't you learn from the case where algorithms matched white noise with some copyright material? There are many iPhones and many images in each iPhones, there will be false matches. Add on top of that that the database of hashes is secret, that it can be updated in secret, that the algorithm is secret and the "threshold" is also secret and you have a lot of suspicio…

No, not in the way a human resembles a butterfly. But for the sake of argument, fine: some pictures of you look exactly like pictures of a butterfly, enough to trigger the flagging threshold. These false positives would easily be caught during the review and nothing would happen.
Post reply on HN