Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

91–100 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#91
post #66

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

Why are hash collisions relevent? There are atleast 2-3 further checks to account for this.

your trust in the system is charming

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#92

Earlier quoted context omitted.

No - the reporting is absolutely terrible here. 1) These are more share similar visual features than crypto hashes. 2) HN posters have been claiming that apple reviewing flagged photos is a felony -> because HN commentators are claiming flagged photos are somehow "known" CASM - this is also likely totally false. The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculo…

> The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculous. Agree, and I think this is backed up by real world experience. Has Facebook or anyone working on their behalf ever been charged for possession of CSAM? I guarantee they've seen some. Probably a lot, in fact. That's why we have recurring discussions about the workers and the compensation they get (or not) fo…

> Probably a lot, in fact.

> In 2020, FotoForensics received 931,466 pictures and submitted 523 reports to NCMEC; that's 0.056%. During the same year, Facebook submitted 20,307,216 reports to NCMEC

https://www.hackerfactor.com/blog/index.php?/archives/929-On....

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#93
post #62

Earlier quoted context omitted.

>> those opinions should have the name of a lawyer on them. Not going to happen. Lawyers in the US have issues with offering unsolicited advice, and other problems with issuing advice into states where they are not admitted. So likely none of the US lawyers (and the great many more law students) here will ever put their real name to a comment.

This. Also try contacting a lawyer who knows this area and asking to pay for a legal opinion brief so that you can post it online to be debated by legions of software developers. Lawyers I know would politely decline that.

No - this is actually done supposedly as part of biz dev.

So your own firm may cover some costs if you have something to say. If you found someone to pay for you to do an analysis or offer your thoughts - you'd be in heaven!

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#94
post #72

Earlier quoted context omitted.

Apple's management can also be prone to hubris. This is also very much a case where the engineers were left unbridled without any proper check from marketing and comms, I suspect because of the extreme complexity of the problem and the sheer impossibility of putting it into layman terms effectively.

Was this a pure engineering driven exercise? I hadn't heard that before and it doesn't match up with what I've heard about Apple's internal culture. The level of defensive pushback really makes me feel that they are very bought into the system. Definitely would appreciate a link to anything substantial indicating that this was a bunch of eng in over their heads.

Also have to agree: I don't see how this could originate from engineers. Every engineer I've spoken with at the company I work for has been mortified by this insanity.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#95

Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…

> Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. Why is that the alternative? How about everything is encrypted and nothing is scanned.

Realistically, because if they don't have something to scan for it, countries / EU are going to require them to provide a backdoor to scan it. There are already proposals in the EU to that affect.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#97

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

> I just don't understand how they acted this way at all.

There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of privacy. Apple found a way to preserve that privacy but still catch the bad people doing very bad things to children.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#98
post #5

> The system relies on a database of hashes—cryptographic representations of images—of known CSAM photos provided by National Center for Missing & Exploited Children (NCMEC) and other child protection organizations. “Cryptographic representations of images”. That’s not the case though right? These are “neuralhashes” afaik which are nowhere close to cryptographic hashes but rather locality sensitive hashes which is a…

In a certain sense it is cryptographic because the original CSAM images remains secret. While the hash is not useful for maintaining integrity it still provides confidentiality.

Edit: this is apparently not true as demonstrated by researchers.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#99

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

Apple's management can also be prone to hubris. This is also very much a case where the engineers were left unbridled without any proper check from marketing and comms, I suspect because of the extreme complexity of the problem and the sheer impossibility of putting it into layman terms effectively.

Maybe the implementation is difficult to put into layman’s terms, but the high level goals - scanning the devices for child porn - most definitely is not.

I’m not buying the “engineers were left unbridled” argument, I think there just have been a level of obliviousness in much wider a part of the organization for something like this to happen.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#100

Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…

Why prefer your owned device tattling on you to Apple looking at data you give them on their servers?

The reason people don't like this, as opposed to, for example, Dropbox scanning your synced files on their servers, is that a compute tool you ostensibly own is now turned completely against you. Today, that is for CSAM, tomorrow, what else?

Post reply on HN