Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

271–280 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#271
post #149

Earlier quoted context omitted.

Apple inspects every file on the local device Before its uploaded. It’s just pinky promise only matched with the on device database when an upload is intended.

Apple controls the hardware, software, and cloud service. It was always a pinky promise that they wouldn't look at your files. I don't know why we should doubt that pinky promise less today than we did a month ago.

Why do people expect anything different? Every corporate promise is subject to change. When you hand your belongings to someone else, those things are liable to be tampered with.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#272

Earlier quoted context omitted.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

It's really interesting to see the mental gymnastics people are willing to go through to defend their favorite trillion dollar corporations. > other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of privacy. > Apple found a way to preserve that privacy ... So scanning for CSAM in a third-party cloud is "total invasion of privacy", while scanning your…

> defend their favorite trillion dollar corporations

> is a short slippery slope away

Obviously people who trust Apple aren't concerned about slippery slopes. What's the point of your post?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#273

Earlier quoted context omitted.

Here's the reason for the sudden uproar: The scanning of things on third party servers was just barely tolerated by a lot of people, whether it's for advertising purposes or government intrusion. People accept it because it's considered reasonable for these third parties to scan data in exchange for providing a service for free (e.g. Google), or because they need to have some degree of accountability for what is on t…

When the scanning gets moved from the cloud to being on device, Apple itself cannot see the results of the scan until the risk that the result is only a false positive is greatly reduced. You would have to have 30 false positives before Apple can see anything, which is unlikely, but the next step is still a human review, since it's not impossible.

Whether or not Apple can see the results is completely irrelevant, to me at least. Automated surveillance is still surveillance.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#274
post #232

Earlier quoted context omitted.

A huge part of Apple’s value proposition is iCloud. If I have to turn that off to keep the spy out of my OS, it’s value to me is dramatically diminished.

Since you presumably don’t trust Apple to scan your photos, it sounds like Apple might not be for you, then. Who will you move to?

In the past I trusted Apple to resist government efforts to spy on me to the best the law allowed. Now they are innovating ways to help a government spy literally live in my pocket.

Trust is fragile and Apple has taken what in the past I believed it understood to be a strategic advantage and stomped it into little pieces.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#275

Earlier quoted context omitted.

PhotoDNA and NeuralHash are not the same thing.

Apple is using a private perceptual hash on the backend, likely to further filter out bad/spam tickets. https://twitter.com/fayfiftynine/status/1427899951120490497?... Given neuralhash is a hash of a hash, I imagine they’re running photodna and not some custom solution which would require Apple ingesting and hasing all of the images themselves using another custom perceptual hash system. > . Instead of scanning image…

My reading of that is NCMEC provides NeuralHash hashes of their CSAM library to Apple, and Apple encrypts and blinds that database before storing it on devices.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#276

Earlier quoted context omitted.

Edit: "The main purpose of the hash is to ensure that identical and visually similar images result in the same hash, and images that are different from one another result in different hashes."[1] Apple isn't using a "similar image, similar hash" system. They're using a "similar image, same hash" system. [1]: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

EDIT: Parent edited his comment to clarify. I understand the point now. I'm wrong about similar images needing to have "similar" hashes. Those hashes either need to match exactly, or else not be considered at all. IGNORE THIS: I think that's the parent comment's point. These are definitely not cryptographic hashes, since they—by design and necessity—need to mirror hash similarity to the perceptual similarity of the i…

[deleted]

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#277

Earlier quoted context omitted.

The other companies didn't advertise and pride themselves on being privacy focused. Part of the appeal of Apple was that you could avoid that issue and they touted it regularly. Now they're telling their customers to go fuck themselves (so long as they're 18 or older).

Conducting the scan on the user's device instead of on the companies server is more private. Apple can't decrypt the results of the scan until the ~30 image threshold is crossed and a human review is triggered. Given Google's reluctance to hire humans when a poorly performing algorithm is cheaper, are they turning over every single false positive without a human review?

I guess people had a sense of ownership of these devices and they feel that it’s doing some they they don’t want. If ownership means control, maybe in the digital age full ownership/control is not really possible on a managed device like the iPhone. There are other example like the John Deer tractor issues.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#278

Earlier quoted context omitted.

Edit: "The main purpose of the hash is to ensure that identical and visually similar images result in the same hash, and images that are different from one another result in different hashes."[1] Apple isn't using a "similar image, similar hash" system. They're using a "similar image, same hash" system. [1]: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

> There really is no sound concept of "the more similar the hash." Perceptual hashes are not cryptographic hashes. Perceptual hashing systems do compare hashes using a distance metric like the Hamming distance. If two images have similar hashes, then they look kind of similar to one another. That's the point of perceptual hashing.

This isn’t what Apple is doing, regardless of the fact they are using the same terminology. See my edit above.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#279

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

> catch the bad people doing very bad things to children

You may catch a few perverts looking at the stuff, but I'm not convinced this will lead to catching the producers. How would that happen?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#280

Earlier quoted context omitted.

This seems like a common deflection, but get back to me when either company puts programs in my pocket that scan my data for crimes and snitch on me to authorities.

>a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le... You don't consider the contents of your email account or the files you mirror to a cloud drive to be your own private data?

No, that happens on Google's servers and is not an agent in my pocket that scans and invades my personal property for evidence of crimes and snitches on me to authorities.
Post reply on HN