Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

271–280 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#271

Earlier quoted context omitted.

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

That is, it seems like Apple really wanted to preserve "end-to-end" encryption,“ … except they still have not mentioned anything about E2E encryption… and they currently don’t encrypt icloud backups. You would think apple would get ahead of this story and mention … or maybe they don’t have any E2E plans at all.

CSAM scanning is probably the easiest thing they could do to satisfy this demand, and if you don't use iCloud Photos, you're not affected by it at all.

As far as encrypted backups go, it's an open question whether they want to deal with the legal and support headaches that such a change would bring. If they continued to do nothing, Congress might force their hand by legislatively outlawing stronger encryption - they had to shit or get off the pot.

For users, if you enable this feature, but then lose your password, you are entirely screwed and Apple can't help you. Encrypting "In-transit" as a middle ground is likely good enough for most people, until researchers manage to come up with a better solution.

Re: Apple's child protection features spark concern within its own ranks: sources

#272
post #262

Earlier quoted context omitted.

> There is a sacrosanct line between "public" and "private," "mine" and "yours." That line cannot be crossed by Western governments without a warrant. This is a self-delusion, I am afraid. The line has been crossed more than once, and it will be crossed again. UK and Australian governments are just two prime examples of waving terrorism and pedobear banners as a pretext to get invasive with each new legislation, and…

And all the while: Sir James Wilson Vincent Savile OBE KCSG (/ˈsævɪl/; 31 October 1926 – 29 October 2011) was an English DJ, television and radio personality who hosted BBC shows including Top of the Pops and Jim'll Fix It. He raised an estimated £40 million for charities and, during his lifetime, was widely praised for his personal qualities and as a fund-raiser. After his death, hundreds of allegations of sexual ab…

Respectfully, I don't understand where you're going with this at all. I could point to it and say, "Wow, we need to make sure nothing like that ever happens again, no matter what the cost to personal liberty!"

Re: Apple's child protection features spark concern within its own ranks: sources

#273
post #205

Earlier quoted context omitted.

How is it any more ‘bit flips’ away from scanning every photo on your device than it was before?

Because if (willBeUploaded) { scanPhoto(); } can become if (true) { scanPhoto(); } Obviously, this is stupidly oversimplified, I have no idea how Apple has structured their code. But the fact of the matter is, if the scanning routine is already on the phone, and the photos are on the phone, all anyone has to do is change which photos get scanned by the routine...

By the way they already scan photos that aren’t uploaded to iCloud. I’ve never used iCloud and I can go on the photos app and search for food for example

Re: Apple's child protection features spark concern within its own ranks: sources

#274
post #14

Earlier quoted context omitted.

Probably the same way people say that when Twitter moderates speech on their platform it’s not censorship.

Or when the NSA feeds your texts through their ML and into their DB it's not a "search" because humans haven't gone looking for it.

Ooh the copilot defence

Re: Apple's child protection features spark concern within its own ranks: sources

#275

> It's a complete change of narrative and there's no easy way to explain it and still defend Apple's Privacy narrative, wihout doing extreme mental gymnastics. Everyone who took Apple at their word was already doing extreme mental gymnastics because Apple's privacy stance was a farce on borrowed time to begin with. Now it's just blatantly obvious to everyone.

It’s only a “farce on borrowed time” because you have the benefit of hindsight.

Not true, unless by "having the benefit of hindsight" you mean "having watched Apple's actions for the last few years".

Yes, they do a lot for privacy. But when it comes to their bottom line, they also have a record of compromising on privacy (and consumer rights in general) to preserve business with less than freedom-loving countries such as China, the UAE, Russia.

It is sometimes difficult to criticize them for this because the financial loss to them would be huge if, say, China kicked them out of their market (and utterly devastating if they kicked them out of manufacturing in China), and because people like to make the argument that iOS is (probably) "still the the bets option for privacy in China" - but it doesn't change the fact that in Apple's hierarchy of priorities privacy ranks lower than making money.

To give a concrete example: if Apple allowed sideloading of apps as Android does, Apple would no longer be in the position to remove VPN apps on behest of China - but at the cost of opening up app distribution outside their own store, which means no free rent-seeking income from that anymore. They'd now actually need to compete on providing the best store for developers, which is obviously going to be more work and cost for them. So, instead they choose the "lesser evil" of putting themselves in a position where they are the only thing that stands (or rather: drops dead lie a wet sack) between an authoritarian state and people trying to circumvent that state's surveillance.

It's a good thing Apple shows more Courage(TM) when it truly counts, for instance when it comes to ridding us all of that terrible scourge of human existence, the 3.5mm jack.

Re: Apple's child protection features spark concern within its own ranks: sources

#276
post #131

Earlier quoted context omitted.

But with a debian package you can choose not to accept the upgrade and see any funny business in the release source code..

That is technically true but in a real very practical sense everyone here using OSS absolutely is trusting a third party because they are not auditing every bit of code they run. For less technical people there is effectively zero difference between open and closed software. It’s really disingenuous to suggest that open source isn’t dependent on trust, you just change who you are trusting. Even if the case is someone…

> Even if the case is someone else is auditing that code, you’re trusting that person instead of the repository owners.

Suppose Debian's dev process happened at monthly in-person meetings where minutes were taken and a new snapshot of the OS (without any specific attribution) released.

If that were the case, I'd rankly speculate that Debian devs would have misrepresented what happened in the openssl debacle. A claim would have been made that some openssl dev was present and signed off on the change. That dev would have then made a counterclaim that regular procedure wasn't followed, to which another dev would claim it was the openssl representative's responsibility to call for a review of relevant changes in the breakout session of day three before the second vote for the fourth day's schedule of changes to be finalized.

Instead, there is a very public history of events that led up to the debacle that anyone can consult. That distinction is important-- it means that once trust is in question, anyone-- including me-- can pile on and view a museum of the debacle to determine exactly how awful Debian's policy was wrt security-related changes.

There is no such museum for proprietary software, and that is a big deal.

Re: Apple's child protection features spark concern within its own ranks: sources

#277

Earlier quoted context omitted.

because its scanning the content of the device, not what you did on the device. An iFrame full of CP downloaded from 4chan that fills the browser cache with CP just by visiting a harmless site would not go anywhere near Google Photos, Facebook messenger, etc etc It would trigger a scanner checking the browser cache for CP images. Those are just the obvious ways, by "rife" I mean there is any number of ways to get CP…

But that’s not the proposed design. Browser cache isn’t getting advanced. It’s photos for iCloud. I’m not asking if people do bad things, I’m saying over and over again this is getting coverage on Hn and people are pointing to this hypothetical issue — yet this hypothetical issue has been possible for years on many more devices.

As far as I have read its scanning any images and messages on the device, as well as text entered into Siri.

So accidentally stick a w in your siri teen porn search and you'll be seeing https://www.apple.com/v/child-safety/a/images/guidance-img__...

If it was photos taken on the device there would be no existing hash for the image to match.

Re: Apple's child protection features spark concern within its own ranks: sources

#278

Cancelled my Apple TV+, iCloud. In the process of selling my iPhone and Apple watch. I know it seems crazy but I feel betrayed and this is the only way I can protest this. Will I have less privacy on android? Yes.

Taking action ftw. Any alternatives you're purchasing or thinking about? I'm quite interested in http://puri.sm. Just setup a NextCloud today, they have free 2GB of hosting plans: http://nextcloud.com

Re: Apple's child protection features spark concern within its own ranks: sources

#280

Cancelled my Apple TV+, iCloud. In the process of selling my iPhone and Apple watch. I know it seems crazy but I feel betrayed and this is the only way I can protest this. Will I have less privacy on android? Yes.

Taking action ftw. Any alternatives you're purchasing or thinking about? I'm quite interested in http://puri.sm . Just setup a NextCloud today, they have free 2GB of hosting plans: http://nextcloud.com

I have a synology, so I think they have an app to push photos directly to my home nas.
Post reply on HN