Live data from Hacker News

After criticism, Apple to only seek abuse images flagged in multiple nations

mobile.reuters.com

241–250 of 255 posts

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#241

Earlier quoted context omitted.

Because this is likely not about making money, it's about expanding surveillance. Once this becomes accepted they can ratchet it up bit-by-bit. Each the the outrage will be less and less. For example imagine creating a new tax for 1% of purchases. People would be outraged. Now imagine raising sales tax instead by 1% (ex 7% to 8%.) Sure some people would be upset, but it would be a smaller number than the "new" tax. T…

The reason Apple actually cares about the feature though is probably to maintain sales in China (which will require this kind of surveillance soon).

I love how people will jump through hoops to land on China even when discussing something that was conceptualized and first (only, as of now) implemented in the US.

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#242

Earlier quoted context omitted.

hearin the number of CSAM reports apple made (265) vs facebook (10 million) changed my perspective. i don't like it but they are going to have to start scanning icloud photos sometime

I don’t think anybody has a problem with iCloud scanning (don’t they do it already?). Apple owns their servers, so I don’t care if they scan them. It’s the on-device scanning that is the massive overreach. It’s like being forced to allow a government employee to live in your home and watch your behavior 24/7 for anything they don’t like. “Oh but John is only looking for specific bad behavior like drug use, you don’t…

> I don’t think anybody has a problem with iCloud scanning

The large number of people here who want iCloud to be E2E have a problem with it.

> (don’t they do it already?).

Apparently not for files and photos. They may well do it for email.

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#243

Earlier quoted context omitted.

from ptrotecting children to global ip dmca takedowns. we all know this is gonna be dmca 2.0

Yep. And you know who that gun is aimed at first? Apple employees. Even if you trust Apple and NCMEC to not add out of scope hashes that some government or law enforcement or intelligence agency “asks” them to, does anybody who’s ever worked for Apple have any doubt at all they they’d use this to check employee’s personal devices for Apple IP? Especially if a big spectacular leak hits the media? Apple’s IP enforcemen…

Apple employees can be subject to all kinds of employer installed management tools and builds, that’s nowhere near the same page of concern.

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#244
I wonder if anyone would've really cared (or at least cared this much) if they just nixed the possible plans to do end to end on the entire iCloud and just did the scanning server-side. I probably wouldn't have started looking at other options, personally.

It's somewhat funny to me that switching to a Mac and eventually to multiple Macs is what had me thinking that I could probably be fine just using Linux for my day-to-day computing that doesn't involve gaming (I've a Windows desktop for that) and now this has me thinking "yeah, I can pretty much make the switch and realistically not feel like I'm missing out on too much, anyway.".

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#245
post #28

And... Apple misses the point of the criticism completely. This problem is the capability, not what it's used for. Any such capability will be abused by new use cases be it terrorism, drug trafficking, human trafficking or whatever. Plus there will inevitably be unauthorized access. The only way to prevent all this is for the system not to exist. I don't buy into theories that Apple is being pressured or coerced on a…

They didn't miss the point. They get the point.

Their point is that they don't care about that other point.

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#246

Earlier quoted context omitted.

You need to read what they are doing. Yes it is on device But it is only done to photos uploaded to the cloud.

If they only intended to scan iCloud photos, then they would’ve done it on the server (since they have encryption keys) instead of installing spyware on everybody’s iPhone. If they had done that then there would’ve been little to no outrage since people wouldn’t need to worry as they could just turn off iCloud. What do you think will happen when e.g. the Chinese government demand that they scan all photos for hashes…

Or they are trying to get rid of having encryption keys…

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#247
post #210

Earlier quoted context omitted.

>>>In a legal context where detecting CSAM is a strong requirement, what’s preferable to this approach? It's not a strong requirement though? Only if the company sees it (unencrypted) do they need to report it, detecting it on-device is wholly different. It would honestly be better if they adjusted their TOS and started scanning the files on upload (on server side). They have the encryption keys already. Apple is pla…

Even if scanning for the content is not explicitly required by law, what happens when a pedophile ring hoarding thousands of images of CSAM on iCloud is busted, and the news gets out? The article at [1] makes it sound like Apple choosing not to scan any of its users' videos in iCloud was seen as evidence of Apple lagging behind the status quo of companies like Facebook that were proactively reporting CSAM. According…

>>>If a company is found to allow criminals to store CSAM on their servers

I'd bet dollars to doughnuts that AWS, GCP, Azure, et al. have terabytes of CSAM stored within their data centers - because users have uploaded encrypted files and the companies (rightly) don't have the keys. I'll also bet there are many WD hard drives full of CSAM, many Linux servers hosting it, many nginx or apache installs serving it up, etc. Should we mandate that all hard drives scan files as they're written to see if it's CSAM? Or maybe nginx should alert law enforcement anytime a CSAM image is served.

Apple should have actually let their users have E2EE or given up on that and just scanned stuff server-side.

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#249

Earlier quoted context omitted.

That’s a smart plan. Apple didn’t misunderstand the criticism, they just have ulterior motives. It’s the only rational explanation.

“It’s the only rational explanation.” Or, perhaps they feel really strongly about child exploitation?

As another commentator stated, if they actually cared about this issue, they would have done what all the other cloud providers have been doing for many years, and what everyone opposed to this wants them to do - just scan the cloud. That's all they're effectively doing right now, only with the scanning happening on a person's private device.

Re: After criticism, Apple to only seek abuse images flagged in multiple nations

#250
post #202

Earlier quoted context omitted.

There is another option - don’t put anything sensitive on your phone and basically treat it as an adversary already has root access. This pretty much what I do for a long time. All the sensitive information (e.g. banking) is on Linux desktop and there are no logins or apps on iPhone or work laptop (hn is not sensitive ;) ).

> hn is not sensitive In literally 30s looking at your comments it shows that you're an HR and an amateur pilot. Seeing the number of comments, with slightly more time, your place of residence and political leaning would probably become apparent.

Missed 100% ;)
Post reply on HN