Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

71–80 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#71
Perhaps I have I missed this in all the discussions of Apple's latest move but has anyone considered the following questions.

Does Apple's solution only stop people from uploading illegal files to Apple's servers or does it stop them from uploading the files to any server.

If Apple intends to control the operation of a computer purchased from Apple after the owner begins using it, does Apple have a duty to report illegal files found on that computer and stop them from being shared (anywhere, not just through Apple's datacenters).

To me, this is why there is a serious distinction between a company detecting and policing what files are stored on their computers (i.e., how other companies approach this problem) and a company detecting and policing what files someone else's computer is storing and can transfer over the internet (in this case, unless I am mistaken, only to Apple's computers).

Mind you, I am not familiar with the details of exactly how Apple's solution works nor the applicable criminal laws so these questions might be irrelevant. However I was thinking that if Apple really wanted to prevent the trafficking of ostensibly illegal files then wouldn't Apple seek to prevent their transfer not only to Apple's computers but to any computer (and also report them to the proper authorities). What duty does Apple have if they can "see into the owner's computer" and they detect illegal activity. If Apple is in remote control of the computer, e.g., they can detect the presence/absence of files remotely and allow or disallow full user control through the OS, then does Apple have a duty to take action.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#72

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

Apple's management can also be prone to hubris. This is also very much a case where the engineers were left unbridled without any proper check from marketing and comms, I suspect because of the extreme complexity of the problem and the sheer impossibility of putting it into layman terms effectively.

Was this a pure engineering driven exercise? I hadn't heard that before and it doesn't match up with what I've heard about Apple's internal culture. The level of defensive pushback really makes me feel that they are very bought into the system.

Definitely would appreciate a link to anything substantial indicating that this was a bunch of eng in over their heads.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#73

Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…

> Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. Why is that the alternative? How about everything is encrypted and nothing is scanned.

This is already possible if you self host your stuff. I’m talking about iCloud specifically here - backups are not encrypted so it’s either scan in the backend or scan on the client.

If you don’t want to be scanned you can turn it off. I honestly don’t see the issue. It seems the only thing people can say are hypothetical situations here.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#74

Earlier quoted context omitted.

No - the reporting is absolutely terrible here. 1) These are more share similar visual features than crypto hashes. 2) HN posters have been claiming that apple reviewing flagged photos is a felony -> because HN commentators are claiming flagged photos are somehow "known" CASM - this is also likely totally false. The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculo…

> The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculous. Agree, and I think this is backed up by real world experience. Has Facebook or anyone working on their behalf ever been charged for possession of CSAM? I guarantee they've seen some. Probably a lot, in fact. That's why we have recurring discussions about the workers and the compensation they get (or not) fo…

From what I understand it's even more cut and dry than that. If you submit a report to the NCMEC you are generally required to (securely) keep a copy of the image(s) being reported and any related info for a period of time. That's part of the rules. You are also only compelled to report things that you know are bad, so verification before reporting makes sense. The idea that they would be charged with a crime for doing what is essentially required by law is flat out wrong. Unless they are storing the material insecurely once confirmed bad or otherwise mishandling the process, they seem to be following the law as I understand it. IANAL but I have an account with the NCMEC for a service I run, so I have looked through their documentation and relevant laws to try to understand the requirements placed on me as a service provider.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#75

Perhaps I have I missed this in all the discussions of Apple's latest move but has anyone considered the following questions. Does Apple's solution only stop people from uploading illegal files to Apple's servers or does it stop them from uploading the files to any server. If Apple intends to control the operation of a computer purchased from Apple after the owner begins using it, does Apple have a duty to report ill…

> does Apple have a duty to report illegal images found on that computer and stop them from being shared

Duty? No, that's the secondary question. The primary question is whether they have the right.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#76

Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…

Personally, I'd prefer no privacy intrusions at all.

The issue is that Apple previously was not intruding into their user's privacy (at least publicly), but now they are.

It sounds like your argument is that Apple could have been doing this all along and just not telling us. I find that unlikely mainly because they've marketed themselves as a privacy-focused company up until now.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#78

Perhaps I have I missed this in all the discussions of Apple's latest move but has anyone considered the following questions. Does Apple's solution only stop people from uploading illegal files to Apple's servers or does it stop them from uploading the files to any server. If Apple intends to control the operation of a computer purchased from Apple after the owner begins using it, does Apple have a duty to report ill…

> Does Apple's solution only stop people from uploading illegal images to Apple's servers or does it stop them from uploading the images to any server.

Only applies to iCloud Photos uploads, but the photos are still uploaded: when there's a match, the photo and a 'ticket' are uploaded and Apple's servers (after the servers themselves verify the match[0]) send the image to human reviewers to verify the CSAM before submitting it to police as evidence.

0: https://twitter.com/fayfiftynine/status/1427899951120490497 and https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#79

Earlier quoted context omitted.

No - the reporting is absolutely terrible here. 1) These are more share similar visual features than crypto hashes. 2) HN posters have been claiming that apple reviewing flagged photos is a felony -> because HN commentators are claiming flagged photos are somehow "known" CASM - this is also likely totally false. The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculo…

>> those opinions should have the name of a lawyer on them. Not going to happen. Lawyers in the US have issues with offering unsolicited advice, and other problems with issuing advice into states where they are not admitted. So likely none of the US lawyers (and the great many more law students) here will ever put their real name to a comment.

This is incorrectly applied. Offering a legal opinion is fundamentally different from offering legal advice. We publish legal opinions in academic and professional publications all the time. That doesn't mean we have an attorney-client relationship with anyone who reads those opinions, or that we would advise that someone act in accordance with such an opinion, particularly if no court has adopted our position yet.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#80

Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…

Personally, I'd prefer no privacy intrusions at all. The issue is that Apple previously was not intruding into their user's privacy (at least publicly), but now they are. It sounds like your argument is that Apple could have been doing this all along and just not telling us. I find that unlikely mainly because they've marketed themselves as a privacy-focused company up until now.

I’m your situation can’t you just turn off the scanning? What’s the issue?
Post reply on HN