Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

241–250 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#241

Earlier quoted context omitted.

>> those opinions should have the name of a lawyer on them. Not going to happen. Lawyers in the US have issues with offering unsolicited advice, and other problems with issuing advice into states where they are not admitted. So likely none of the US lawyers (and the great many more law students) here will ever put their real name to a comment.

Sure - but if you are going to write blog posts / articles - and all you can say is based on the lawyers I talked to apple is committing child porn felonies, that is just unacceptable. At least HN should flag these and get these taken down. Over and over the legal analysis is either trash or it's clear the article author didn't understand something (so how can lawyer give good advice?). These conversations become so…

>> there are LOTS of legal articles online - with folks name on them

Articles are not legal advice. They are opinions on the law applicable generally, rather than fact-based advice to specific clients. Saying whether apple is doing something illegal or not in this case, with a lawyer's name stamped on that opinion, is very different.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#242

Earlier quoted context omitted.

No misconstrual needed. This technology is genuinely bad. It scans images against an arbitrary government-owned black-box database. There’s no guarantee that it’s only CSAM.

NECMEC isn’t owned by the government and the database of hashes is available from Apple.

That’s like saying the federal reserve is “private”. No, the NECMEC is not a private entity. Not only was it heavily funded/created by the gov, but more importantly it is granted special legal status. You and I can’t just spin up our own CSAM database. Nor do we have any laws that say that any companies aware of CSAM must send it to us and only us.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#243

Earlier quoted context omitted.

Correct. I'm not sure how that's a distinction from "you can't turn it off" though. I believe they've been doing this scan server-side for quite some time already.

Here's the distinction: I used to be able to use iCloud photos without having my photos scanned, and now I can't. So I have to make a choice of either dropping iCloud photos completely or submit to having all of my photos scanned. I don't think they have been doing server-side scanning until now, hence the publicity. Do you have any evidence that shows they've been doing this before?

https://www.dailymail.co.uk/sciencetech/article-7865979/Appl...

I wasn’t able to find the whole video though.

No time to watch, but. https://www.ces.tech/Videos/2020/Chief-Privacy-Officer-Round...

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#244

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

Consumers are probably in favor this, or don’t care.

The only people who are bothered are people claiming this is going to be misused by authoritarian governments.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#246
post #222

Earlier quoted context omitted.

NECMEC isn’t owned by the government and the database of hashes is available from Apple.

They're not owned by the federal government, but they do get a lot of federal government money. > The National Center for Missing & Exploited Children® was established in 1984 as a private, nonprofit 501(c)(3) organization. Today, NCMEC performs the following 15 specific programs of work, funded in part by federal grants (34 U.S.C. § 11293): Source: https://www.missingkids.org/footer/about US DOJ OJJDP lists recent g…

And don’t forget, it’s way more than just money:

https://www.law.cornell.edu/uscode/text/18/2258A

You must report to them and only them.

For the GP to claim they’re not government “owned” is a rhetorical trick at best and outright ignorant absurdity at worst.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#247
post #130

Earlier quoted context omitted.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

But who was complaining about google and microsoft doing the cloud scanning? I don’t mind my one drive being scanned for “bad stuff”, I very much mind my personally owned data stores being scanned, with no opt out.

That's the point: catching the bad guy foolish enough to keep known CSAM images on their phone, while not technically invading the privacy of any good guys. Anyway, if apple wanted to covertly invade their users' privacy, they'd have no technical problems to do so.

What it takes to accept is the "nothing to hide" mentality: your files are safe to scan (locally) because they can't be known CSAM files. You have to trust the scanner. You allow the scanner to touch your sensitive files because you're not the bad guy, and you want the bad guy be caught (or at least forced off the platform).

And this is, to my mind, the part Apple wasn't very successful at communicating. The whole thing should have started with an educational campaign well ahead of time. The privacy advantage should have been explained again and again: "unlike every other vendor, we won't siphon your files unecrypted for checking; we do everything locally and are unable to compromise your sensitive bits". Getting one's files scanned should have become a badge of honor among the users.

But, for some reason, they tried to do it in a low-key and somehow hasty manner.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#248
post #188

Earlier quoted context omitted.

What is "this promise"? Because I would consider it "we will only scan files that you upload to iCloud". That was true a month ago and that would be true under this new system. The only part that is changing is that the scanning happens on your device before upload rather than on an Apple server after upload. I don't view that as a material difference when Apple already controls the hardware and software on both ends…

> The only part that is changing is that the scanning happens on your device before upload This is the key point. 1. What if I change my mind and decide not to upload the picture? 2. This is a new mechanism for scanning private pictures on the device. What could go wrong? > If we can't trust Apple to follow their promise, their products should already have been considered compromised before this change was announced.…

> This is a new mechanism for scanning private pictures on the device.

No it isn’t. It’s a mechanism for scanning pictures as they are uploaded to iCloud Photo Library.

Private pictures on the device are not scanned.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#249
post #149

Earlier quoted context omitted.

Apple controls the hardware, software, and cloud service. It was always a pinky promise that they wouldn't look at your files. I don't know why we should doubt that pinky promise less today than we did a month ago.

They don't control the database used, any country can thru legal means attach additional hashes for search and reporting. Apple has already proven it will concede to China's demands. They are building the worlds most pervasive surveillance system and when the worlds governments come knocking to use it ... they will throw their hands up and feed you the "Apple complies with all local laws etc.."

> They don't control the database used

They control what goes into the on-device database that is used.

>The on-device encrypted child abuse database contains only data independently submitted by two or more child safety organizations, located in separate jurisdictions, and thus not under the control of the same government

https://www.techwarrant.com/apple-will-only-scan-abuse-image...

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#250

Earlier quoted context omitted.

As has been repeated over and over, apple only scans photos that are part if icloud photos (ie, uploaded). "for now" Which is the part most people have a problem with -- they say that they are only scanning iCloud uploads now, but it's simple extension of the scanner to scan all files. I don't care if Apple scans my iCloud uploads on iCloud servers, I don't want them scanning photos on my device.

I will believe them if they put their money where their mouth is: as a clause to iOS user agreement saying that if they ever use they ever use this functionality for anything other than CSAM or on anything other than iCloud photos, ever person who was subjected to this scan will be paid 100 million dollars by Apple. I will believe them if they put this clause in, and I know when they have changed their plans when the…

Until one day a box pops up. It says "We've updated our terms. See this 10,000 line document here. Please accept to continue using your device." Then your clause is gone.
Post reply on HN