Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

261–270 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#261
post #131

Earlier quoted context omitted.

That's what they're saying, the key difference is Apples happens on your device, not theirs.

That's not really better or different. In any meaningful way.

It is indeed meaningfully different: your sensitive data never leaves your device in order to be scanned. There can't be a crack in Apple servers that would expose files of millions of users uploaded for scanning.

Eventually it could lead to Apple platform not having any CSAM content, or any known legally objectionable content, because any sane perpetrator would migrate to other platforms, and less sane, caught.

This, of course, takes the user base to overwhelmingly agree that keeping legally objectionable content is a bad thing and should be exposed to police, and to trust the whatever body which defines the hashes of objectionable content. I'm afraid this order is not as tall as we could imagine.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#262

Earlier quoted context omitted.

The issue is that as soon as you set that precedent, it’s only a matter of time before it extends beyond iCloud. That’s the problem with doing any device-level scanning. This is dystopian and scary. And yes I understand the technology in its current iteration. The current form has problems (weaponizing collisions etc) but the real issue comes with future developments.

Was scanning server side not a precedent?

Furthermore, was uploading (backing up) the entire contents of your phone to a server to be freely scaned and distributed (with warrant of course) server side not also a precedent?

Must have been absloutely nuts round here back in 2011 when they announced the particular slippery slope that is iCloud backup.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#263

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

Nah, their stock is up which means they'll continue on this trajectory.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#264

Earlier quoted context omitted.

Also have to agree: I don't see how this could originate from engineers. Every engineer I've spoken with at the company I work for has been mortified by this insanity.

It’s really unpopular inside the fruit company. I’ve not spoken with a single engineer in Cupertino who thinks this is a good path. There has been radio silence from management on how to address this. It almost feels like they want this to fail. In the past management has given us resources and talking points we can use with our friends and family. Not this time.

> In the past management has given us resources and talking points we can use with our friends and family.

Wow. That feels like an overreach. 'We don't just buy your labor, but also your private opinion and tell you how to talk to your family'.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#265

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

It's really interesting to see the mental gymnastics people are willing to go through to defend their favorite trillion dollar corporations.

> other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of privacy.

> Apple found a way to preserve that privacy ...

So scanning for CSAM in a third-party cloud is "total invasion of privacy", while scanning your own personal device is "preserving privacy"?

The third-party clouds can only scan what one explicitly chooses to share with the third-party, while on-device scanning is a short slippery slope away from have its scope significantly expanded (to include non-shared and non-CSAM content).

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#266

Earlier quoted context omitted.

Here's the reason for the sudden uproar: The scanning of things on third party servers was just barely tolerated by a lot of people, whether it's for advertising purposes or government intrusion. People accept it because it's considered reasonable for these third parties to scan data in exchange for providing a service for free (e.g. Google), or because they need to have some degree of accountability for what is on t…

When the scanning gets moved from the cloud to being on device, Apple itself cannot see the results of the scan until the risk that the result is only a false positive is greatly reduced. You would have to have 30 false positives before Apple can see anything, which is unlikely, but the next step is still a human review, since it's not impossible.

I don't care. It's my device (at least that's how Apple used to advertise it) and I disagree with Apple's policy, full stop. I don't care about "think of the children" (especially since they will be scanning pictures of my own children), and furthermore I don't trust Apple not to change the policy in the future. They've created a backdoor and now the device is compromised and privacy is broken. If you want to trust Apple go ahead. They have eroded my trust and I doubt they could regain it within a decade.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#267
post #214
post #174

Earlier quoted context omitted.

I just don't get this. Say you're given two options when going through the TSA. 1. The TSA agent opens your luggage and searches everything for banned items. 2. The TSA agent hands you a scanner for you to wave over your luggage in private, it prints out a receipt of banned items it saw, and you present that receipt to the agent. Which one is more invasive?

The TSA installs this scanner in your house so it can detect before you even get to the airport. They give a pinky promise they will only run it when you book your ticket and intend on going to the airport where you would be expected to be scanned anyway. The scanner technology can also be used for detecting dissident journalism, but they say it won't be, it is just for preventing terrorism, but still they say, they…

> The scanner technology can also be used for detecting dissident journalism, but they say it won't be, it is just for preventing terrorism

This has always been possible with server side scanning. Yeah we have to trust Apple to not enable it for users who don’t use iCloud photos but we’ve always had to trust Apple given their closed source system.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#268
post #247
post #130

Earlier quoted context omitted.

But who was complaining about google and microsoft doing the cloud scanning? I don’t mind my one drive being scanned for “bad stuff”, I very much mind my personally owned data stores being scanned, with no opt out.

That's the point: catching the bad guy foolish enough to keep known CSAM images on their phone, while not technically invading the privacy of any good guys. Anyway, if apple wanted to covertly invade their users' privacy, they'd have no technical problems to do so. What it takes to accept is the "nothing to hide" mentality: your files are safe to scan (locally) because they can't be known CSAM files. You have to trus…

I mostly agree, though I will argue for the other side; child predators don't exactly have a track record for intelligence. Pedophiles still to this day get caught trading CP on Facebook of all places. I think engaging in that kind of activity requires a certain number of brain cells misfiring. Watch some old episodes of To Catch A Predator. Most of those guys were borderline retarded or had obvious personality disorders.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#269
post #248

Earlier quoted context omitted.

> The only part that is changing is that the scanning happens on your device before upload This is the key point. 1. What if I change my mind and decide not to upload the picture? 2. This is a new mechanism for scanning private pictures on the device. What could go wrong? > If we can't trust Apple to follow their promise, their products should already have been considered compromised before this change was announced.…

> This is a new mechanism for scanning private pictures on the device. No it isn’t. It’s a mechanism for scanning pictures as they are uploaded to iCloud Photo Library. Private pictures on the device are not scanned.

Pictures not uploaded yet are private.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#270
post #229

Earlier quoted context omitted.

> The only part that is changing is that the scanning happens on your device before upload This is the key point. 1. What if I change my mind and decide not to upload the picture? 2. This is a new mechanism for scanning private pictures on the device. What could go wrong? > If we can't trust Apple to follow their promise, their products should already have been considered compromised before this change was announced.…

How are those two examples different than before? You can't unupload a photo under either the old or new system. I don't know why we would expect that the scanning feature will be more prone to accidentally scan too many photos compared to the uploading feature accidentally uploading too many photos. >Many people did trust Apple to keep their files private until now. And that was my original point. If a pinky promise…

> You can't unupload a photo under either the old or new system.

You can choose to upload many pictures. They will start uploading. Then, you change your mind. Some pictures were not uploaded yet. But they were scanned by the new algorithm.

Post reply on HN