Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

161–170 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#161
post #116

Earlier quoted context omitted.

I'm kinda amazed. I mentioned I was thinking of moving from an Android phone to Apple soon, somewhat privacy related. My friends lectured me on "they're scanning your photos" ... meanwhile they share their google photos albums with me and marvel about how easy they are to search ... Maybe we (humans) only get outraged based on more specific narratives and not so much the general topics / issues? I don't know but they…

Isn't there a small difference between these? A) They scan everything I have released to google photos B) They scan everything that exists on my device Psychologically, you'll feel a difference in what you accept between the two, I think

Google does everything they can to backup your photos ... and do it automatically.

I'm not sure there's a real difference unless you want to watch your settings all the time. In google land they tend to reset ... and really that happens a lot of places.

I think for most people if you use google, you're in their cloud.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#162

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar. Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people l…

I think the difference here is that it's ON YOUR DEVICE. I think there's a pretty clear understanding that if you upload stuff to a cloud provider they can do whatever they want with it. This is different. This is reaching into what has up until now mostly been considered a private place. Law enforcement often has to get warrants to search this kind of thing.

This is the difference between putting CSAM on a sign in your front yard (maybe not quite front yard but I can't come up with quite the same physical equivalent to a cloud provider) and keeping it in a password protected vault in your basement. One of those things is protected in the U.S. by laws against unlawful search and seizure. Cloud and on your device are two very different things and consumers are right to be alarmed.

I'll say it again, if you are concerned with this privacy violation, sell your Apple stock and categorically refuse to purchase Apple devices. Also go to https://www.nospyphone.com/ and make your voice heard there.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#163

Earlier quoted context omitted.

At least Google does. https://protectingchildren.google/intl/en/ > CSAI Match is our proprietary technology, developed by the YouTube team, for combating child sexual abuse imagery (CSAI) in video content online. It was the first technology to use hash-matching to identify known violative videos and allows us to identify this type of violative content amid a high volume of non-violative video content. When a match of…

No, that happens on Google's servers and isn't an agent in my pocket that runs on and invades my personal property. It's also only for videos.

[deleted]

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#164

Earlier quoted context omitted.

The other companies didn't advertise and pride themselves on being privacy focused. Part of the appeal of Apple was that you could avoid that issue and they touted it regularly. Now they're telling their customers to go fuck themselves (so long as they're 18 or older).

Conducting the scan on the user's device instead of on the companies server is more private. Apple can't decrypt the results of the scan until the ~30 image threshold is crossed and a human review is triggered. Given Google's reluctance to hire humans when a poorly performing algorithm is cheaper, are they turning over every single false positive without a human review?

[deleted]

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#165

Earlier quoted context omitted.

At least Google does. https://protectingchildren.google/intl/en/ > CSAI Match is our proprietary technology, developed by the YouTube team, for combating child sexual abuse imagery (CSAI) in video content online. It was the first technology to use hash-matching to identify known violative videos and allows us to identify this type of violative content amid a high volume of non-violative video content. When a match of…

No, that happens on Google's servers and isn't an agent in my pocket that runs on and invades my personal property. It's also only for videos.

When the scan is carried out on device, Apple can't read the results of the scan until the 30 image threshold is reached.

When Google scans on server, a single false positive result can be abused by anyone who can get a warrant.

>Innocent man, 23, sues Arizona police for $1.5million after being arrested for murder and jailed for six days when Google's GPS tracker wrongly placed him at the scene of the 2018 crime

https://www.dailymail.co.uk/news/article-7897319/Police-arre...

Apple's method is more private.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#166

Is no one going to talk about how Apple is implementing this? If Apple is training a neural network to detect this kind of imagery, I would imagine there to be thousands, if not millions of child pornography images on Apple's servers that are being used by their own engineers to train this system

> If Apple is training a neural network to detect this kind of imagery

NCMEC generate the hashes using their CSAM corpus.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#167
post #124

Would this work as an attack? 1. Get a pornographic picture involving young though legal actors and actresses. 2. Encode a nonce into the image. Hash it checking for CSAM collisions. If you've found a collision go on to the next step, if not update the nonce and try again. 3. You now have an image that, to visual inspection will appear plausibly like CSAM, and to automated detection will appear like CSAM. Though, pre…

How would you know if it's a CSAM collision? I don't believe that database is publicly available anywhere, for obvious reasons.

Good point. I can offer three possibilities to how you might know. First, a data leak of the material. Second, law enforcement presumably gives hashes of known CSAM to service operators so they can detect and report it. You could pose as or be the operator of such a service and get the hashes that way. Third, if you were a government operator you may have access to the hashes that way. (Although I guess corrupt government agents would have other easier ways of getting to you)

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#168
post #149

Earlier quoted context omitted.

Apple inspects every file on the local device Before its uploaded. It’s just pinky promise only matched with the on device database when an upload is intended.

Apple controls the hardware, software, and cloud service. It was always a pinky promise that they wouldn't look at your files. I don't know why we should doubt that pinky promise less today than we did a month ago.

Because now Apple confirmed themselves that this promise is not kept.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#169

Earlier quoted context omitted.

> B) They scan everything that exists on my device No ... They scan everything that I have released to apple photos that exists on my device. Same scan - different place.

The issue is that as soon as you set that precedent, it’s only a matter of time before it extends beyond iCloud. That’s the problem with doing any device-level scanning. This is dystopian and scary. And yes I understand the technology in its current iteration. The current form has problems (weaponizing collisions etc) but the real issue comes with future developments.

Was scanning server side not a precedent?
Post reply on HN