Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

121–130 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#121

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

> For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Because privacy stance is mostly PR to differentiate from Google. And while there're invalid reasons to get users data, there're also valid ones (at least from legal requirement point of view - let's not get into weeds about personal freedom here and if t…

It was obvious from the beginning that the privacy nonsense was a convenient excuse to cover for their poor (especially at the time) cloud offerings compared to competitors like Google.

I assumed they pivoted to focus on privacy, but clearly it was just a marketing department innovation rather than a core value (as their marketing department claimed).

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#122

Earlier quoted context omitted.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar. Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people l…

BigCos, take note: you’re better off doing nefarious shit without telling anyone. Because, if you come clean, you’ll only invite an endless parade of bloggers who will misconstrue your technology to make you look bad.

It's important to keep nefarious stuff on the server side because eventually someone will reverse engineer what's on the client side.

Imagine if Apple had done this on the client side without telling anyone, and later it was discovered. I think things would be a whole worse for Apple in that case.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#123

Earlier quoted context omitted.

I’m your situation can’t you just turn off the scanning? What’s the issue?

There are two different "features" being implemented - Messages scanning for minors on a family plan (which can be turned off) and iCloud Photo scanning (which can't be turned off, as far as I know). So no, you can't just turn it off.

Yes, it can be turned off. https://www.macrumors.com/2021/08/05/apple-csam-detection-di...

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#124

Would this work as an attack? 1. Get a pornographic picture involving young though legal actors and actresses. 2. Encode a nonce into the image. Hash it checking for CSAM collisions. If you've found a collision go on to the next step, if not update the nonce and try again. 3. You now have an image that, to visual inspection will appear plausibly like CSAM, and to automated detection will appear like CSAM. Though, pre…

How would you know if it's a CSAM collision? I don't believe that database is publicly available anywhere, for obvious reasons.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#125

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

> other major cloud providers catch CSAM content on their platform by inspecting every file uploaded

That is very unlikely. Most likely they compare some hash against a database - just like apple.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#126

Earlier quoted context omitted.

I’m your situation can’t you just turn off the scanning? What’s the issue?

There are two different "features" being implemented - Messages scanning for minors on a family plan (which can be turned off) and iCloud Photo scanning (which can't be turned off, as far as I know). So no, you can't just turn it off.

But you can tho…

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#127
post #72

Earlier quoted context omitted.

Was this a pure engineering driven exercise? I hadn't heard that before and it doesn't match up with what I've heard about Apple's internal culture. The level of defensive pushback really makes me feel that they are very bought into the system. Definitely would appreciate a link to anything substantial indicating that this was a bunch of eng in over their heads.

Also have to agree: I don't see how this could originate from engineers. Every engineer I've spoken with at the company I work for has been mortified by this insanity.

It’s really unpopular inside the fruit company. I’ve not spoken with a single engineer in Cupertino who thinks this is a good path. There has been radio silence from management on how to address this. It almost feels like they want this to fail. In the past management has given us resources and talking points we can use with our friends and family. Not this time.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#128

Earlier quoted context omitted.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar. Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people l…

This seems like a common deflection, but get back to me when either company puts programs in my pocket that scan my data for crimes and snitch on me to authorities.

At least Google does.

https://protectingchildren.google/intl/en/

> CSAI Match is our proprietary technology, developed by the YouTube team, for combating child sexual abuse imagery (CSAI) in video content online. It was the first technology to use hash-matching to identify known violative videos and allows us to identify this type of violative content amid a high volume of non-violative video content. When a match of violative content is found, it is then flagged to partners to responsibly report in accordance to local laws and regulations. Through YouTube, we make CSAI Match available for free to NGOs and industry partners like Adobe, Reddit, and Tumblr, who use it to counter the spread of online child exploitation videos on their platforms as well.

> We devote significant resources—technology, people, and time—to detecting, deterring, removing, and reporting child sexual exploitation content and behavior. Since 2008, we’ve used “hashing” technology, which creates a unique digital ID for each known child sexual abuse image, to identify copies of images on our services that may exist elsewhere.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#129

Earlier quoted context omitted.

> For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Because privacy stance is mostly PR to differentiate from Google. And while there're invalid reasons to get users data, there're also valid ones (at least from legal requirement point of view - let's not get into weeds about personal freedom here and if t…

In retrospect this makes sense to me. I don't like it, but I get it now. When Apple said "privacy" what they meant was "we don't like tracking cookies or hackers but everything else is fine".

Privacy means “you pay for the device so we don’t sell your attention to advertisers.” That’s it. There’s no protection against state level actors (Pegasus, CSAM scanning, etc.).

If your threat model includes being the target of someone who will plant child pornography on your phone, you are already fucked. And no, Apple isn’t suddenly going to scan Chinese iPhones for Winnie the Pooh memes. They don’t have to. China already has the 50 cent party to do that for them, on WeChat.

Basically everything everyone seems to think is just around the corner has already been possible for years.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#130

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

But who was complaining about google and microsoft doing the cloud scanning?

I don’t mind my one drive being scanned for “bad stuff”, I very much mind my personally owned data stores being scanned, with no opt out.

Post reply on HN