Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

111–120 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#111
post #100

Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…

Why prefer your owned device tattling on you to Apple looking at data you give them on their servers? The reason people don't like this, as opposed to, for example, Dropbox scanning your synced files on their servers, is that a compute tool you ostensibly own is now turned completely against you. Today, that is for CSAM, tomorrow, what else?

There’s no difference - all cloud services that aren’t encrypting your data is subject to the same thing. Dropbox could do the same thing tomorrow. If we’re talking about hypotheticals any vendor that handles your unencrypted files can do this now.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#112

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

> What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning.

Maybe because they underestimated people's ignorance.

I think they saw (and still do see) it as a better, more privacy preserving technique than what everyone else is doing.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#113
post #5

> The system relies on a database of hashes—cryptographic representations of images—of known CSAM photos provided by National Center for Missing & Exploited Children (NCMEC) and other child protection organizations. “Cryptographic representations of images”. That’s not the case though right? These are “neuralhashes” afaik which are nowhere close to cryptographic hashes but rather locality sensitive hashes which is a…

In a certain sense it is cryptographic because the original CSAM images remains secret. While the hash is not useful for maintaining integrity it still provides confidentiality. Edit: this is apparently not true as demonstrated by researchers.

This has technically been proven false:

> Microsoft says that the "PhotoDNA hash is not reversible". That's not true. PhotoDNA hashes can be projected into a 26x26 grayscale image that is only a little blurry. 26x26 is larger than most desktop icons; it's enough detail to recognize people and objects. Reversing a PhotoDNA hash is no more complicated than solving a 26x26 Sudoku puzzle; a task well-suited for computers.

https://www.hackerfactor.com/blog/index.php?/archives/929-On...

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#114

Is no one going to talk about how Apple is implementing this? If Apple is training a neural network to detect this kind of imagery, I would imagine there to be thousands, if not millions of child pornography images on Apple's servers that are being used by their own engineers to train this system

It's not a neural network. It's not AI. It's not trying to interpret image content. It's trying to identify known specific images, but is using a fuzzy fingerprinting match.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#115

Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…

> All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Not only has it been possible for a decade, it’s been happening for a decade. Every major social media company already scans for and reports child pornography to the feds. Facebook submits millions of reports per year.

Yes, exactly. This is honestly nothing new.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#116

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

I'm kinda amazed.

I mentioned I was thinking of moving from an Android phone to Apple soon, somewhat privacy related.

My friends lectured me on "they're scanning your photos" ... meanwhile they share their google photos albums with me and marvel about how easy they are to search ...

Maybe we (humans) only get outraged based on more specific narratives and not so much the general topics / issues?

I don't know but they didn't seem to notice the conflict.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#117

it's kind of silly how this is treated like some deeply technical issue. Apple's 'one of a trillion' claim is either true and the software is useless, because I'm pretty sure pedophiles can figure out what a watermark or a gaussian blur in paint net is, or it's imprecise and actually detects things which is the very thing that makes it dangerous to the public. It's a direct trade-off and the error tolerance of any su…

> I'm pretty sure pedophiles can figure out what a watermark or a gaussian blur in paint net is, or it's imprecise and actually detects things which is the very thing that makes it dangerous to the public

Or better yet, they can just not store their stuff on an iPhone. While meanwhile, millions of innocent people are have their photos scanned and risking being reported as a pedophile.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#118

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar. Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people l…

The other companies didn't advertise and pride themselves on being privacy focused. Part of the appeal of Apple was that you could avoid that issue and they touted it regularly. Now they're telling their customers to go fuck themselves (so long as they're 18 or older).

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#119
Something just occurred to me. If this goes forward, and then Microsoft and/or Google copy it, then we might see lawmakers expecting it. If that becomes the case, then it'd be yet another barrier to entry (in addition to a cop on every phone.)

Isn't that where we already with things like Article 17 of the EU's Copyright Directive?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#120

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar. Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people l…

This seems like a common deflection, but get back to me when either company puts programs in my pocket that scan my data for crimes and snitch on me to authorities.
Post reply on HN