Earlier quoted context omitted.
Why prefer your owned device tattling on you to Apple looking at data you give them on their servers? The reason people don't like this, as opposed to, for example, Dropbox scanning your synced files on their servers, is that a compute tool you ostensibly own is now turned completely against you. Today, that is for CSAM, tomorrow, what else?
There’s no difference - all cloud services that aren’t encrypting your data is subject to the same thing. Dropbox could do the same thing tomorrow. If we’re talking about hypotheticals any vendor that handles your unencrypted files can do this now.
Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
221–230 of 465 posts
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#222Earlier quoted context omitted.
No misconstrual needed. This technology is genuinely bad. It scans images against an arbitrary government-owned black-box database. There’s no guarantee that it’s only CSAM.
NECMEC isn’t owned by the government and the database of hashes is available from Apple.
> The National Center for Missing & Exploited Children® was established in 1984 as a private, nonprofit 501(c)(3) organization. Today, NCMEC performs the following 15 specific programs of work, funded in part by federal grants (34 U.S.C. § 11293): Source: https://www.missingkids.org/footer/about
US DOJ OJJDP lists recent grants totaling $84,446,366 in FY19 and FY20. Source: https://ojjdp.ojp.gov/funding/awards/list?awardee=NATIONAL%2...
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#223Earlier quoted context omitted.
> What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. Maybe because they underestimated people's ignorance. I think they saw (and still do see) it as a better, more privacy preserving technique than what everyone else is doing.
The thing is that this is a better and more privacy preserving technique. Their hubris is in not seeing or thinking that they will be able to stand up to all kinds of abuses of this system that its mere existence will invite; their hubris is also in thinking that they will be able to perfectly and without mistakes manage and overview a system making accusations so heinous that even the mere act of accusing destroy pe…
Since the announcement, I can think of a dozen ways Apple could be easily forced into scanning all the contents of your device by assembling features they’ve already shipped. Yet they haven’t. At some point, people need to produce evidence that Apple cannot hold the line they’ve said they will.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#224Earlier quoted context omitted.
No misconstrual needed. This technology is genuinely bad. It scans images against an arbitrary government-owned black-box database. There’s no guarantee that it’s only CSAM.
NECMEC isn’t owned by the government and the database of hashes is available from Apple.
Even though NCMEC describes itself as "private", it was established by and has been heavily funded by the U.S. government.
From an archive of NCMEC's own history page, cited on Wikipedia (https://web.archive.org/web/20121029010231/http://www.missin...):
> In 1984, the U.S. Congress passed the Missing Children’s Assistance Act which established a National Resource Center and Clearinghouse on Missing and Exploited Children. The National Center for Missing & Exploited Children was designated to fulfill this role.
> On June 13, 1984, the National Center for Missing & Exploited Children was opened by President Ronald Reagan in a White House Ceremony. The national 24-hour toll-free missing children’s hotline 1-800-THE-LOST opened as well.
$40 million/year of U.S. government funding from a 2013 bill (https://en.wikipedia.org/wiki/Missing_Children%27s_Assistanc...):
> The Missing Children's Assistance Reauthorization Act of 2013 (H.R. 3092) is a bill that was introduced into the United States House of Representatives during the 113th United States Congress. The Missing Children's Assistance Reauthorization Act of 2013 reauthorizes the Missing Children's Assistance Act and authorizes $40 million a year to fund the National Center for Missing and Exploited Children.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#225Earlier quoted context omitted.
In retrospect this makes sense to me. I don't like it, but I get it now. When Apple said "privacy" what they meant was "we don't like tracking cookies or hackers but everything else is fine".
Privacy means “you pay for the device so we don’t sell your attention to advertisers.” That’s it. There’s no protection against state level actors (Pegasus, CSAM scanning, etc.). If your threat model includes being the target of someone who will plant child pornography on your phone, you are already fucked. And no, Apple isn’t suddenly going to scan Chinese iPhones for Winnie the Pooh memes. They don’t have to. China…
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#226Earlier quoted context omitted.
>a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le... You don't consider the contents of your email account or the files you mirror to a cloud drive to be your own private data?
There are worlds between. One case is about pictures on your device. The other case is about pictures on Googles "devices" or network. You had to upload it to Google. EMail is also nothing like a letter anyway. It's a postcard. Everybody can read it.
>So if iCloud Photos is disabled, the system does not work, which is the public language in the FAQ. I just wanted to ask specifically, when you disable iCloud Photos, does this system continue to create hashes of your photos on device, or is it completely inactive at that point?
If users are not using iCloud Photos, NeuralHash will not run
https://techcrunch.com/2021/08/10/interview-apples-head-of-p...
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#227Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…
What is also possible: No scanning on your device and encrypted cloud storage. E.g. borg + rsync.net, mega, proton drive.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#228What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.
> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…
Saddened by the privacy-adverse functionality on handsets but Apple seems to be hitting the nail on the head that poor communication principally is driving outrage.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#229Earlier quoted context omitted.
What is "this promise"? Because I would consider it "we will only scan files that you upload to iCloud". That was true a month ago and that would be true under this new system. The only part that is changing is that the scanning happens on your device before upload rather than on an Apple server after upload. I don't view that as a material difference when Apple already controls the hardware and software on both ends…
> The only part that is changing is that the scanning happens on your device before upload This is the key point. 1. What if I change my mind and decide not to upload the picture? 2. This is a new mechanism for scanning private pictures on the device. What could go wrong? > If we can't trust Apple to follow their promise, their products should already have been considered compromised before this change was announced.…
>Many people did trust Apple to keep their files private until now.
And that was my original point. If a pinky promise from Apple is not enough to trust them, then Apple should have never been trusted.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#230> The system relies on a database of hashes—cryptographic representations of images—of known CSAM photos provided by National Center for Missing & Exploited Children (NCMEC) and other child protection organizations. “Cryptographic representations of images”. That’s not the case though right? These are “neuralhashes” afaik which are nowhere close to cryptographic hashes but rather locality sensitive hashes which is a…
Something to note here is that in the hash collision that was discovered, the two images look nothing alike. One is a picture of a dog, the other is blobby grey static.