Live data from Hacker News

After criticism, Apple to only seek abuse images flagged in multiple nations

mobile.reuters.com

221–230 of 255 posts

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#222
post #213

Earlier quoted context omitted.

Sooner or later the copyright enforcement companies will find a judge whose willing to rule that since Apple has the capability they have to use it even though this system is aimed at still images only, no sound or video. Then Apple will end up fighting it for years if they're lucky and it doesn't get a quick trip up to Supreme Court that's drastically Hollywood-friendly. The legal difference between mandating that a…

Apple doesn't have that capabilty though. There are countless ways to get copyrighted material on your phone that are perfectly legal. Apple would have to be able to decide if you're legally owning your files. With how the IP system works currently that's impossible. For CSAM this isn't a problem because we assume that there is no legitimate way to have CSAM files on your phone.

> we assume that there is no legitimate way to have CSAM files on your phone

WhatsApp has "Save pictures to camera roll" on by default. Someone can send you a bunch of CSAM via WhatsApp and now you are in trouble.

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#223

Earlier quoted context omitted.

Apple doesn't have that capabilty though. There are countless ways to get copyrighted material on your phone that are perfectly legal. Apple would have to be able to decide if you're legally owning your files. With how the IP system works currently that's impossible. For CSAM this isn't a problem because we assume that there is no legitimate way to have CSAM files on your phone.

> we assume that there is no legitimate way to have CSAM files on your phone WhatsApp has "Save pictures to camera roll" on by default. Someone can send you a bunch of CSAM via WhatsApp and now you are in trouble.

Or take a photo of CSAM on display on another device or printout using your iPhone camera, which is often accessible from the lock screen without a PIN.

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#224
post #202

Earlier quoted context omitted.

I can't wait until /child-safety 404s or redirects to /safety and there's a wall of marketing blurb (possibly only in Chinese at first) that explains how 'national security' concerns are reported to the CCP. This has totally pushed me over the edge, though I'll admit I was oblivious to begin with. My plan is to replace the MacBooks with a Thinkpad P15 gen 2 running Ubuntu and replace the iPhone with something running…

There is another option - don’t put anything sensitive on your phone and basically treat it as an adversary already has root access. This pretty much what I do for a long time. All the sensitive information (e.g. banking) is on Linux desktop and there are no logins or apps on iPhone or work laptop (hn is not sensitive ;) ).

> don’t put anything sensitive on your phone and basically treat it as an adversary already has root access

Why am I paying 100s of $$$ to own a device that is adversarial?

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#225
> The implications of the government’s demands are chilling. If the government can use the All Writs Act to make it easier to unlock your iPhone, it would have the power to reach into anyone’s device to capture their data. The government could extend this breach of privacy and demand that Apple build surveillance software to intercept your messages, access your health records or financial data, track your location, or even access your phone’s microphone or camera without your knowledge.[1]

[1]: https://www.apple.com/customer-letter/

Chilling indeed, Tim, chilling indeed.

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#226
post #224
post #202

Earlier quoted context omitted.

There is another option - don’t put anything sensitive on your phone and basically treat it as an adversary already has root access. This pretty much what I do for a long time. All the sensitive information (e.g. banking) is on Linux desktop and there are no logins or apps on iPhone or work laptop (hn is not sensitive ;) ).

> don’t put anything sensitive on your phone and basically treat it as an adversary already has root access Why am I paying 100s of $$$ to own a device that is adversarial?

For fun. Why do people pay to run with the bulls or to own a tiger? We pay because we love the thrill that comes from a pocket adversary.

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#227

Since hearing about this whole affair, one potential scenario popped up in my mind... Currently, bad actors are randomly sharing illegal content in an unsolicited way to people who did not ask for it (1). Let's imagine this happens to you. Suddenly, you have illegal content on your device you didn't ask for. Maybe you are busy when the message with the content is received and you don't even know about it, or you thin…

Well, to be factually accurate, in this case with Apple, nothing will happen. Apple only reports when it matches 30 instances of this content. They have said they plan to reduce it from 30 as they improve their algorithm.

> Well, to be factually accurate, in this case with Apple, nothing will happen.

To be factually accurate, the commenter didn’t mention a number. Sending 30+ images of anything to someone’s number is trivial.

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#228
post #210
post #192

Earlier quoted context omitted.

Having read the coverage and the documents that Apple has been putting out to manage the … what, crisis? Backlash? … I’ve been thinking about the design of the system and how I would want CSAM to be detected, if different than this. Honestly, I’m pretty impressed by what this approach accomplishes. Your comment says this obviously isn’t the way to do it— what’s better than this? In a legal context where detecting CSA…

>>>In a legal context where detecting CSAM is a strong requirement, what’s preferable to this approach? It's not a strong requirement though? Only if the company sees it (unencrypted) do they need to report it, detecting it on-device is wholly different. It would honestly be better if they adjusted their TOS and started scanning the files on upload (on server side). They have the encryption keys already. Apple is pla…

Even if scanning for the content is not explicitly required by law, what happens when a pedophile ring hoarding thousands of images of CSAM on iCloud is busted, and the news gets out? The article at [1] makes it sound like Apple choosing not to scan any of its users' videos in iCloud was seen as evidence of Apple lagging behind the status quo of companies like Facebook that were proactively reporting CSAM.

According to that article, in the last year Apple only submitted 265 reports to the NCEMC while Facebook submitted 20 million. Would law enforcement believe they'd be missing out on catching abusers after seeing this disparity?

If a company is found to allow criminals to store CSAM on their servers for extended periods of time, the law is going to want to know why they let it pass, irrespective of the extent the company chose to scan for it. Apple probably doesn't want to deal with that fallout, so maybe they figured that being proactive about scanning for CSAM in a way that could enable the use of E2EE wouldn't hurt, and that pushing the privacy narrative would satisfy enough people - which it didn't.

[1] https://www.nytimes.com/2021/08/05/technology/apple-iphones-...

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#229

Earlier quoted context omitted.

That’s a smart plan. Apple didn’t misunderstand the criticism, they just have ulterior motives. It’s the only rational explanation.

“It’s the only rational explanation.” Or, perhaps they feel really strongly about child exploitation?

If they did, they would have done this much sooner.

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#230
post #28

And... Apple misses the point of the criticism completely. This problem is the capability, not what it's used for. Any such capability will be abused by new use cases be it terrorism, drug trafficking, human trafficking or whatever. Plus there will inevitably be unauthorized access. The only way to prevent all this is for the system not to exist. I don't buy into theories that Apple is being pressured or coerced on a…

Their promise is completely childishly unrealistic, the person who said it should feel ashamed. Does anybody believe they will refuse to use this in if the government demands when it’s a few button clicks of work to do it? When market access is at risk, and with apple’s track record? Or that two countries can’t collaborate to save face while doing this? This promise is so unrealistic that it’s just a lie
Post reply on HN