Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

231–240 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#231

Would this work as an attack? 1. Get a pornographic picture involving young though legal actors and actresses. 2. Encode a nonce into the image. Hash it checking for CSAM collisions. If you've found a collision go on to the next step, if not update the nonce and try again. 3. You now have an image that, to visual inspection will appear plausibly like CSAM, and to automated detection will appear like CSAM. Though, pre…

Your hash will match to say image 105 of the dataset. Upon visual inspection, your 'legal porn' is going to have to at least look passably like image 105 of the dataset to get anywhere.

So at this point we have an image that computers think is CSAM and people think is CSAM, and when held up next to the original verified horrific image everyone agrees is the same image. At this point, someone is going to ask, rightly so, where that came from.

In order to generate this attack, you have had to go out and procure, deliberately, known CSAM. Ignoring that it would be easier just to send that to the target, rather than hiring talent to recreate the pose of a specific piece of child porn (or 30 pieces to trigger the reporting levels), the most likely person by orders of magnitude to be prosecuted in this scenario is the attacker.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#232
post #147

Earlier quoted context omitted.

This is new for Apple's customers. And its new in that the device you bought and paid for is nosing through your files. Apple is introducing a reverse 'Little Snitch' where instead of the app warning you what apps are doing on the network, the OS is scanning your photos. Introducing a 5th columnist into a device that you've bought and paid for is a huge philosophical jump from Apple's previous stances on privacy, whe…

Luckily for their customers it can be turned off. So, what’s the issue?

A huge part of Apple’s value proposition is iCloud. If I have to turn that off to keep the spy out of my OS, it’s value to me is dramatically diminished.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#233

Earlier quoted context omitted.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar. Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people l…

Here's the reason for the sudden uproar: The scanning of things on third party servers was just barely tolerated by a lot of people, whether it's for advertising purposes or government intrusion. People accept it because it's considered reasonable for these third parties to scan data in exchange for providing a service for free (e.g. Google), or because they need to have some degree of accountability for what is on t…

When the scanning gets moved from the cloud to being on device, Apple itself cannot see the results of the scan until the risk that the result is only a false positive is greatly reduced.

You would have to have 30 false positives before Apple can see anything, which is unlikely, but the next step is still a human review, since it's not impossible.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#234
post #197
post #100

Earlier quoted context omitted.

Why prefer your owned device tattling on you to Apple looking at data you give them on their servers? The reason people don't like this, as opposed to, for example, Dropbox scanning your synced files on their servers, is that a compute tool you ostensibly own is now turned completely against you. Today, that is for CSAM, tomorrow, what else?

Why did you think you owned a closed source device?

Open Source fanatics are the worst. Even if all the software on your phone was Open Source, you wouldn’t have the mental bandwidth to ever verify you trust it. You’re just farming out your trust to a different set of people and hoping they’re more trustworthy than those with closed source. At best this MAY be reasonable because of incentive alignment but that’s super weak.

Not to mention the meaning of ownership is completely unrelated to ability to view the designs of a given object. I think I own the fan currently blowing air at me without ever having seen a schematic for its controls circuitry just fine and everyone for all of history has pretty much felt the same.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#235
post #232

Earlier quoted context omitted.

Luckily for their customers it can be turned off. So, what’s the issue?

A huge part of Apple’s value proposition is iCloud. If I have to turn that off to keep the spy out of my OS, it’s value to me is dramatically diminished.

Since you presumably don’t trust Apple to scan your photos, it sounds like Apple might not be for you, then. Who will you move to?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#236

Earlier quoted context omitted.

>> those opinions should have the name of a lawyer on them. Not going to happen. Lawyers in the US have issues with offering unsolicited advice, and other problems with issuing advice into states where they are not admitted. So likely none of the US lawyers (and the great many more law students) here will ever put their real name to a comment.

Right. That's why there's never been an amicus brief or a friends of the court type of document drafted and signed by lawyers.

Those are addressed to a court or government agency in a specific place. The advice offered isn't for a bunch of rando people on the internet across all number of jurisdictions. And it is only general advice about an area of law, normally at the appellate level, not specific fact-dependent advice to a real flesh-and-blood person. Amicus is also normally an opinion to sway the court on broad policy, not a determination of facts in a specific case.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#237

Apple does check it just before you upload it to icloud. How much money do they save it's is checked clientside? How much would it cost for Apple to do it on there own servers, like everybody else does it?

Iirc the rationale for doing it clientside isn't saving money, but maintaining encryption. If it's checked client side, Apple should never get unencrypted uploads unless they're suspected to be CSAM

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#238

Earlier quoted context omitted.

As has been repeated over and over, apple only scans photos that are part if icloud photos (ie, uploaded). Don't want your photo's scanned, don't sync them to icloud. Seriously! Please include the actual system when discussing this system, not your bogeyman system. "To help address this, new technology in iOS and iPadOS* will allow Apple to detect known CSAM images stored in iCloud Photos." To increase privacy - they…

As has been repeated over and over, apple only scans photos that are part if icloud photos (ie, uploaded). "for now" Which is the part most people have a problem with -- they say that they are only scanning iCloud uploads now, but it's simple extension of the scanner to scan all files. I don't care if Apple scans my iCloud uploads on iCloud servers, I don't want them scanning photos on my device.

I will believe them if they put their money where their mouth is: as a clause to iOS user agreement saying that if they ever use they ever use this functionality for anything other than CSAM or on anything other than iCloud photos, ever person who was subjected to this scan will be paid 100 million dollars by Apple. I will believe them if they put this clause in, and I know when they have changed their plans when they remove the clause. No more pinky swears, let's add some stakes for breaking the promise.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#239

Earlier quoted context omitted.

The issue is that as soon as you set that precedent, it’s only a matter of time before it extends beyond iCloud. That’s the problem with doing any device-level scanning. This is dystopian and scary. And yes I understand the technology in its current iteration. The current form has problems (weaponizing collisions etc) but the real issue comes with future developments.

Was scanning server side not a precedent?

It set the precedent for scanning server side. Which I don’t like but there’s really no way to avoid it anyway.

Now we have clientside scanning, and actually being led by the [note the scare quotes] “pro-privacy” two ton gorilla. It’s a whole different ballgame.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#240

Earlier quoted context omitted.

As has been repeated over and over, apple only scans photos that are part if icloud photos (ie, uploaded). "for now" Which is the part most people have a problem with -- they say that they are only scanning iCloud uploads now, but it's simple extension of the scanner to scan all files. I don't care if Apple scans my iCloud uploads on iCloud servers, I don't want them scanning photos on my device.

I will believe them if they put their money where their mouth is: as a clause to iOS user agreement saying that if they ever use they ever use this functionality for anything other than CSAM or on anything other than iCloud photos, ever person who was subjected to this scan will be paid 100 million dollars by Apple. I will believe them if they put this clause in, and I know when they have changed their plans when the…

I'd be satisfied with a money back guarantee -- if they change the policy then I can return the phone for a full refund.
Post reply on HN