Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

81–90 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#82

Perhaps I have I missed this in all the discussions of Apple's latest move but has anyone considered the following questions. Does Apple's solution only stop people from uploading illegal files to Apple's servers or does it stop them from uploading the files to any server. If Apple intends to control the operation of a computer purchased from Apple after the owner begins using it, does Apple have a duty to report ill…

What has been stated is that this all _only_ happens as photos are about to be uploaded to iCloud photos (not to be confused with iCloud backup, a totally separate thing). This is currently done server-side on iCloud photoes. This appears to move it client side.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#83

Perhaps I have I missed this in all the discussions of Apple's latest move but has anyone considered the following questions. Does Apple's solution only stop people from uploading illegal files to Apple's servers or does it stop them from uploading the files to any server. If Apple intends to control the operation of a computer purchased from Apple after the owner begins using it, does Apple have a duty to report ill…

> Does Apple's solution only stop people from uploading illegal files to Apple's servers or does it stop them from uploading the files to any server.

Perhaps they're trying to prevent being in "posession" of illegal images by having them on their own servers, rather than preventing copying to arbitrary destinations.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#84

it's kind of silly how this is treated like some deeply technical issue. Apple's 'one of a trillion' claim is either true and the software is useless, because I'm pretty sure pedophiles can figure out what a watermark or a gaussian blur in paint net is, or it's imprecise and actually detects things which is the very thing that makes it dangerous to the public. It's a direct trade-off and the error tolerance of any su…

Exactly right. The tech Apple uses can be one of two things: 1. It requires a perfect 1:1 match (their documentation says this is not the case); 2. Or it has some freedom in detecting a match, probably including a match with a certain percentage. If it's the former, it's completely useless. A watermark or a randomly chosen pixel with a slightly different hue and the hash would be completely different. So, it's not #1…

What? Why would memes be on the CSAM list?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#85

For everyone upset about Apple's CSAM scanning, I think we all forgot about the EARN IT Act. It was nearly passed last year but Congress was finished before it could be voted on. It had Bipartisan support and would've virtually banned E2E of any kind. And it would have required scanning everywhere according to the recommendations of a 19-member board of NGOs and unelected experts. The reason for this mandatory backdo…

>which would unilaterally banned E2E encryption in entirety It did not do this. The bill was essentially asking for search warrants to become a part of the protocol. If you're only solution to allowing for search warrants to work is to stop encrypting data I feel you are intentionally ignoring other options to make this seem worse than it is.

I am very intrigued about what you think the other options are that preserve E2E encryption. How do you make search warrants part of the process without some kind of escrow or third party involvement, at which point it is no longer "end to end"?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#86

Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…

> All of the slippery slope arguments have already been possible for nearly a decade now with the cloud.

Not only has it been possible for a decade, it’s been happening for a decade. Every major social media company already scans for and reports child pornography to the feds. Facebook submits millions of reports per year.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#87

Earlier quoted context omitted.

No - the reporting is absolutely terrible here. 1) These are more share similar visual features than crypto hashes. 2) HN posters have been claiming that apple reviewing flagged photos is a felony -> because HN commentators are claiming flagged photos are somehow "known" CASM - this is also likely totally false. The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculo…

>> those opinions should have the name of a lawyer on them. Not going to happen. Lawyers in the US have issues with offering unsolicited advice, and other problems with issuing advice into states where they are not admitted. So likely none of the US lawyers (and the great many more law students) here will ever put their real name to a comment.

Sure - but if you are going to write blog posts / articles - and all you can say is based on the lawyers I talked to apple is committing child porn felonies, that is just unacceptable.

At least HN should flag these and get these taken down. Over and over the legal analysis is either trash or it's clear the article author didn't understand something (so how can lawyer give good advice?).

These conversations become so uninteresting when people take these extreme type positions. Apple's brand is destroyed - apple is committing child porn felonies.

I would have rather just had a link to the apple technical paper and a discussion personally vs the over the top random article feed with all sorts of misunderstandings.

And in contract law there are LOTS of legal articles online - with folks name on them! They are useful! I read them and enjoy them. Can we ask for that here where it matters maybe more?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#88

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar.

Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people lose their minds.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#89

Earlier quoted context omitted.

No - the reporting is absolutely terrible here. 1) These are more share similar visual features than crypto hashes. 2) HN posters have been claiming that apple reviewing flagged photos is a felony -> because HN commentators are claiming flagged photos are somehow "known" CASM - this is also likely totally false. The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculo…

Or how about they just don't scan my phone at all.

feel free to go ahead and opt out.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#90
post #47

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

They are very likely aware of backlash but since this is a easily defendable hill with a very slippery slope down the way, it is of their interest to push for it IMHO.

Apple has declared in interviews that the slope shall not be slipped, but you're indicating that they chose this specifically because they can slip that slope.

How did you determine that their intentions contradict their words? Please share the framework for your belief, so that we're able to understand how you arrived at that belief and to evaluate your evidence with an open mind.

(Or, if your claim is unsupported conjecture, please don't misrepresent your opinions and beliefs as facts here at HN.)

Post reply on HN