Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

431–440 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#431

Earlier quoted context omitted.

I’m telling you what is going to happen in the future. What they write today is meaningless. In 2016 they fought the fbi in terms of unencrypting data. Then they decided to not encrypt iCloud backups. They didn’t mention in 2016 they wouldn’t encrypt iCloud backups just like they won’t say today that they won’t bend to the Chinese government tweaking their algorithm or their hash list in a few yearsnn

The only logical reason for Apple to implement such a complex system is to give them a defensive political tool to allow them to do things like encrypt iCloud backups and photos. “But CSAM” is a common political tool used against such encryption. I don’t see this move from Apple making any measurable difference in how well a government can scan your device for arbitrary data. If it happens it was going to happen anyw…

The difference is that Apple has built the infrastructure for _global_, continuous image scanning. No need to hack individual phones or know who your targets are, all you have to do is get some images added to list. If you think the Chinese (or most likely American) government wouldn't love to be able to find out everyone who had copies of certain images, say from protests or inside camps, you're far too optimistic.

This is Apple creating a mechanism for worldwide surveillance and declaring they'd never compromise because they're good people who we can trust. Note that they're not making any actual promises that might land them in court if the system is abuses, they're just repeating that they're good people who'd never cooperate with authoritarian regimes.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#432

Earlier quoted context omitted.

> Then where are the news reports or articles of these false positives that would have shown up within the past decade?... Is there even a single verifiable report of such a false positive? I feel that with the amount of attention brought to this issue, if there was such a report then it probably would have been brought up by now. Positives get reviewed by humans, at which point false positives are identified and dis…

The privacy violation here is smaller than the one we all used to have to go through to get photos developed at all.

Exactly why people avoided taking naughty pictures with film. Digital, on the other hand, is private. And should remain so.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#434
post #431

Earlier quoted context omitted.

The only logical reason for Apple to implement such a complex system is to give them a defensive political tool to allow them to do things like encrypt iCloud backups and photos. “But CSAM” is a common political tool used against such encryption. I don’t see this move from Apple making any measurable difference in how well a government can scan your device for arbitrary data. If it happens it was going to happen anyw…

The difference is that Apple has built the infrastructure for _global_, continuous image scanning. No need to hack individual phones or know who your targets are, all you have to do is get some images added to list. If you think the Chinese (or most likely American) government wouldn't love to be able to find out everyone who had copies of certain images, say from protests or inside camps, you're far too optimistic.…

All you have to do is:

- Get your image added to the list

- Order Apple to scan all images not just ones being uploaded to iCloud

- Order Apple to change the reporting threshold or remove the safety voucher system unless you only care about users with many matching images

- Compromise or order Apple to skip the human review and pass the reports directly to your government agency

Really you have to compromise or order Apple to change every step in the pipeline except “compare images to hashes” which is the part an intern could do in a weekend.

I’m sure governments would love to know which users have “undesirable” images on their device. I’m just saying instead of doing the above steps to take advantage of the CSAM system, they could just order Apple to scan for the images they want scanned for. Apple’s choice is the same, comply or risk participation in that market.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#435
post #257

Earlier quoted context omitted.

Then don't use Google products either (or don't use for photography). Seems obvious. "Dumb" phones and "dumb" cameras still exist.

That is not practical for many people who wish to be a part of society anymore. See: rollout of virtual vaccine passports, etc.

Virtual vaccine passports will be forgotten long before they affect even a small fraction of people on this planet.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#437

Earlier quoted context omitted.

In order for this system to work, Apple has to be able to compare the CSAM NeuralHash hashes against the NeuralHash hashes of the images to be synced with iCloud. How do they compare the hashes without decrypting?

They compare the encrypted forms of the hashes, the first step on the device and the second on the server.

How does one compare encrypted forms of hashes?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#438
post #68

Earlier quoted context omitted.

The end isn't really compromised with their described implementation. The only thing sent is the hash and signature and that's only if there are enough matches to pass some threshold. I don't really view that as 'permanently compromised' - at least not in any way more serious that Apple's current capabilities to compromise a device. I think e2ee still has meaning here - it'd prevent Apple from being able to see your…

> The only thing sent is the hash and signature and that's if there are enough matches to pass some threshold. Not true. If there are enough matches, someone at Apple will have a look at your pictures. Even if they are innocent.

How is anyone OK with Apple employees viewing their private pictures because their algorithm fucked up?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#439
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

> It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small.

What are you talking about? Ask anyone who has worked in this space: false positives are abound[1][2], especially when you're looking for fuzzy matches. And you have to look for fuzzy matches otherwise slight modifications to illegal images would bypass the detection system.

> Photos of your own kids won't trigger it, nude photos of adults won't trigger it;

This is also incorrect. In general, if two images kind of look like one another when you squint, they're going to have similar perceptual hashes. A lot of unrelated things look similar to one another when you squint, and a lot of unrelated things are going to have similar perceptual hashes. And, again, you'll be doing fuzzy matches on these hashes, so you're going to pick up those unrelated things even more so than when you just have hash collisions.

[1] https://news.ycombinator.com/item?id=28091750

[2] https://news.ycombinator.com/item?id=28110159

Re: The deceptive PR behind Apple’s “expanded protections for children”

#440

Earlier quoted context omitted.

If they were going to implement a government scanning tool it could be done much more simply. And they would if legally required, or turn down some of their largest markets. This is a step too far (on-device vs in cloud) but all of the “but what if the govt…” is ridiculous because that happens anyway if the govt wants it. Maybe we should change the government.

You point that it "could have" been done more simply is completely irrelevant. This "much more simply" mechanism is exactly what was created by Apple. It's done right now, and there's no need to worry about how much more simply they COULD HAVE. It's a fait-accompli. The government wanted it, and now they have it. Now they can scan individual phones for whatever they want.

You keep saying they can scan for whatever they want but that’s not true, today, by Apple’s description.(which is all we have to go by and is what you are mad about)

Yes the government could order them to change the system. They could also order Apple to create the system in the first place without all the indirection, safety vouchers, human review, etc which make it inefficient as a direct surveillance tool.

Post reply on HN