Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

201–210 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#201
post #157

Earlier quoted context omitted.

That's not really better or different. In any meaningful way.

Then why the outrage if they're the same?

Because this is Apple and people are very passionate about both hating and liking Apple.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#202
post #188

Earlier quoted context omitted.

Because now Apple confirmed themselves that this promise is not kept.

What is "this promise"? Because I would consider it "we will only scan files that you upload to iCloud". That was true a month ago and that would be true under this new system. The only part that is changing is that the scanning happens on your device before upload rather than on an Apple server after upload. I don't view that as a material difference when Apple already controls the hardware and software on both ends…

> The only part that is changing is that the scanning happens on your device before upload

This is the key point.

1. What if I change my mind and decide not to upload the picture?

2. This is a new mechanism for scanning private pictures on the device. What could go wrong?

> If we can't trust Apple to follow their promise, their products should already have been considered compromised before this change was announced.

Many people did trust Apple to keep their files private until now.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#203
post #47

Earlier quoted context omitted.

They are very likely aware of backlash but since this is a easily defendable hill with a very slippery slope down the way, it is of their interest to push for it IMHO.

Apple has declared in interviews that the slope shall not be slipped, but you're indicating that they chose this specifically because they can slip that slope. How did you determine that their intentions contradict their words? Please share the framework for your belief, so that we're able to understand how you arrived at that belief and to evaluate your evidence with an open mind. (Or, if your claim is unsupported c…

“IMHO” means “in my humble opinion”

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#204

Earlier quoted context omitted.

This seems like a common deflection, but get back to me when either company puts programs in my pocket that scan my data for crimes and snitch on me to authorities.

>a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le... You don't consider the contents of your email account or the files you mirror to a cloud drive to be your own private data?

No OP, but yes. I expect that my emails can be read and that my files on a cloud service can be accessed. And I don’t even use Gmail.

I expect that my ISP tracks and stores my DNS resolutions (if I use their DNS) and has a good understanding of the websites I visit.

I expect that an app that I grant access to my contacts uploads as much data as it can to their servers.

I expect WhatsApp and similar apps to collect and upload meta data of my entire photo library such as GPS info the second I give them access.

Hence, I don’t give access. And hence, it’s a problem if there is no opt-out of local file scanning in the future.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#205

Earlier quoted context omitted.

Doing so would create a positive that still doesn't pass Apple's human visual check against the (blurred) CSAM content associated with that checksum, and if it somehow did, it would still then also have to occur at qty.30 or more, and they'd have to pass a human visual check against the (unblurred) CSAM content by one of the agencies in possession of it. It's not possible to spoof that final test unless you possess r…

And if you make the second image be actual, 18+ porn? Will Apple be able to tell the difference between that and CSAM after the blur is applied? Bonus points if you match poses, coloration, background, etc.

The only way to match poses, coloration, background, etc is to possess illegal CSAM content. If you do so successfully, you will result in your crafted image passing the blur check and reaching the agency that possesses the original image for final verification, where it will immediately fail because it is obviously a replica. You will then trigger that agency leading law enforcement to find the creator of the image, so that they can arrest whoever possesses CSAM content in order to model replicas after it.

I think that's a perfectly acceptable outcome, since anyone with the hubris to both possess CSAM content and create replicas of it especially deserves to be arrested. Do you see a more problematic outcome here?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#206

Earlier quoted context omitted.

Only if you disable iCloud photos completely. So no, you cannot turn off the feature unless you stop using iCloud photos.

Correct. I'm not sure how that's a distinction from "you can't turn it off" though. I believe they've been doing this scan server-side for quite some time already.

Here's the distinction: I used to be able to use iCloud photos without having my photos scanned, and now I can't. So I have to make a choice of either dropping iCloud photos completely or submit to having all of my photos scanned.

I don't think they have been doing server-side scanning until now, hence the publicity. Do you have any evidence that shows they've been doing this before?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#207

Earlier quoted context omitted.

Isn't there a small difference between these? A) They scan everything I have released to google photos B) They scan everything that exists on my device Psychologically, you'll feel a difference in what you accept between the two, I think

As has been repeated over and over, apple only scans photos that are part if icloud photos (ie, uploaded). Don't want your photo's scanned, don't sync them to icloud. Seriously! Please include the actual system when discussing this system, not your bogeyman system. "To help address this, new technology in iOS and iPadOS* will allow Apple to detect known CSAM images stored in iCloud Photos." To increase privacy - they…

As has been repeated over and over, apple only scans photos that are part if icloud photos (ie, uploaded).

"for now"

Which is the part most people have a problem with -- they say that they are only scanning iCloud uploads now, but it's simple extension of the scanner to scan all files.

I don't care if Apple scans my iCloud uploads on iCloud servers, I don't want them scanning photos on my device.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#208
post #72

Earlier quoted context omitted.

Was this a pure engineering driven exercise? I hadn't heard that before and it doesn't match up with what I've heard about Apple's internal culture. The level of defensive pushback really makes me feel that they are very bought into the system. Definitely would appreciate a link to anything substantial indicating that this was a bunch of eng in over their heads.

Also have to agree: I don't see how this could originate from engineers. Every engineer I've spoken with at the company I work for has been mortified by this insanity.

This doesn't hold much water. As a counter example, we have all of the engineers that designed Facebook, Google, etc. We have people working in ad tech. We have people working in lots of places that you and the people that you talk with directly would be moritified, but there are countless others that need a paycheck and do whatever pointy haired bosses tell them to do.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#210

Earlier quoted context omitted.

BigCos, take note: you’re better off doing nefarious shit without telling anyone. Because, if you come clean, you’ll only invite an endless parade of bloggers who will misconstrue your technology to make you look bad.

No misconstrual needed. This technology is genuinely bad. It scans images against an arbitrary government-owned black-box database. There’s no guarantee that it’s only CSAM.

I have a serious problem imagining that Apple will not be willing to redeploy this technology in a novel and nefarious means in exchange for continued market access when billions are on the line.

Mainland China will probably be the first chip to fall. Can't imagine the Ministry of State Security not actively licking their lips, waiting for this functionality to arrive.

Post reply on HN