Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

291–300 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#291

Earlier quoted context omitted.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

> catch the bad people doing very bad things to children You may catch a few perverts looking at the stuff, but I'm not convinced this will lead to catching the producers. How would that happen?

Known CSAM detection was one of three features they announced under the banner of child safety. Certainly they understand it is by itself an incomplete intervention for a much larger problem.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#292

Earlier quoted context omitted.

When the scanning gets moved from the cloud to being on device, Apple itself cannot see the results of the scan until the risk that the result is only a false positive is greatly reduced. You would have to have 30 false positives before Apple can see anything, which is unlikely, but the next step is still a human review, since it's not impossible.

I don't care. It's my device (at least that's how Apple used to advertise it) and I disagree with Apple's policy, full stop. I don't care about "think of the children" (especially since they will be scanning pictures of my own children), and furthermore I don't trust Apple not to change the policy in the future. They've created a backdoor and now the device is compromised and privacy is broken. If you want to trust A…

>I don't care

If anything, you should be outraged that Google and Microsoft have been scanning much more of your data, and doing so in a much more intrusive way.

Apple only scans iCloud Photos and they do so in a way that they can't see the results until they can be reasonably sure it's not just a false positive.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#293
post #220

Earlier quoted context omitted.

Should they even be doing that though? It seems like a matter of time before it's possible to SWAT somebody by sending them a series of hash colliding image files given how not cryptographically secure the hash algorithm is. I think I'm not the only one who'd rather not have my devices call the cops on me in a country where the cops are already way too violent.

But this doesn't change any of that. It only changes whether the scanning happens on your device as part of the upload process instead of on the server after the upload.

Yeah that’s right and I don’t think either method is ethical.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#294
post #174

Earlier quoted context omitted.

I just don't get this. Say you're given two options when going through the TSA. 1. The TSA agent opens your luggage and searches everything for banned items. 2. The TSA agent hands you a scanner for you to wave over your luggage in private, it prints out a receipt of banned items it saw, and you present that receipt to the agent. Which one is more invasive?

Apple’s solution more like the TSA agent shows up at your house and inspects your luggage before you even leave for the airport and he pinky promises not to report on anything else he might see while in your home.

This version is incorrect because Apple’s solution by design does not reveal the non-suspect contents of your luggage.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#295
post #277

Earlier quoted context omitted.

Conducting the scan on the user's device instead of on the companies server is more private. Apple can't decrypt the results of the scan until the ~30 image threshold is crossed and a human review is triggered. Given Google's reluctance to hire humans when a poorly performing algorithm is cheaper, are they turning over every single false positive without a human review?

I guess people had a sense of ownership of these devices and they feel that it’s doing some they they don’t want. If ownership means control, maybe in the digital age full ownership/control is not really possible on a managed device like the iPhone. There are other example like the John Deer tractor issues.

I have a sense of ownership over my non-publicly-accessible data when it's backed up to a cloud drive.

Apple isn't scanning that.

Google and Microsoft are.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#296
post #252

Earlier quoted context omitted.

> Apple found a way to preserve that privacy but still catch the bad people doing very bad things to children. They're not going to find predators, all they are going to find is people incompetent enough to have years old (otherwise how would it end up at NCMEC?) CSAM on their iPhones and dumb enough to have iCloud backup turned on. To catch actual predators they would need to run AI scanning on phones for all photos…

> people incompetent enough to have years old (otherwise how would it end up at NCMEC?) CSAM on their iPhones Who do you think has 30 or more CSAM images on their phone?

Let's be real, of course many of those people will be child abusers.

But let's also be real about something else. Think of the Venn diagram of child abusers and people who share CSAM online. Those circles are not identical. Not everybody with CSAM is necessarily a child abuser. Worse, how many child abusers don't share CSAM online? Those can't ever be found by Apple-style invasions of privacy, so one has to wonder if we're being asked to give up significant privacy for a crime fighting strategy that may not even be all that effective.

The cynic in me is also wondering what fraction of people working at places like NCMEC are pedophiles. It'd be a rather convenient job for them. And after all, there's a long history of ostensibly child-serving institutions harboring the worst kind of offenders.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#297

Earlier quoted context omitted.

Please show evidence where the feature can be turned off (without having to completely disable iCloud photos).

You turn it off by turning off iCloud photos, I never claimed otherwise. If you don’t trust Apple why would you use iCloud anyway? Makes no sense.

> You turn it off by turning off iCloud photos, I never claimed otherwise.

I just have to point out the ridiculousness of this statement. With your logic any feature in any product can be "turned off" by not using the entire product at all. For example, the radio in my car sounds like shit, I guess I should just stop driving completely to avoid having to hear it.

In reality, this new "feature" will be a requirement of using iCloud Photos. The feature itself cannot be turned off. If your answer is to stop using iCloud Photos, that is no help for the millions of people who currently use iCloud Photos.

> If you don’t trust Apple why would you use iCloud anyway? Makes no sense.

I've trusted Apple for a long time because I felt like they were one of the only companies that cared about consumer privacy. After these actions I am less convinced of that. I'm not sure why that stance is so surprising.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#298
post #261

Earlier quoted context omitted.

That's not really better or different. In any meaningful way.

It is indeed meaningfully different: your sensitive data never leaves your device in order to be scanned. There can't be a crack in Apple servers that would expose files of millions of users uploaded for scanning. Eventually it could lead to Apple platform not having any CSAM content, or any known legally objectionable content, because any sane perpetrator would migrate to other platforms, and less sane, caught. This…

> your sensitive data never leaves your device in order to be scanned. There can't be a crack in Apple servers that would expose files of millions of users uploaded for scanning.

And yet photos that get scanned are still uploaded to iCloud Photos, so they do end up on Apple's servers.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#299

Earlier quoted context omitted.

Here's the distinction: I used to be able to use iCloud photos without having my photos scanned, and now I can't. So I have to make a choice of either dropping iCloud photos completely or submit to having all of my photos scanned. I don't think they have been doing server-side scanning until now, hence the publicity. Do you have any evidence that shows they've been doing this before?

https://www.dailymail.co.uk/sciencetech/article-7865979/Appl... I wasn’t able to find the whole video though. No time to watch, but. https://www.ces.tech/Videos/2020/Chief-Privacy-Officer-Round...

The article you linked makes a surprising claim, and it contradicts what the EFF said recently about this here - https://www.eff.org/deeplinks/2021/08/apples-plan-think-diff...

> Currently, although Apple holds the keys to view Photos stored in iCloud Photos, it does not scan these images

It also seems weird that the EFF wouldn't have complained about this before if Apple was known to be doing server-side scanning for some time now.

I also am not going to watch through an hour video, but I scanned the transcript and I didn't see anything that said that Apple currently (at that time) scanned content.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#300
post #252

Earlier quoted context omitted.

> people incompetent enough to have years old (otherwise how would it end up at NCMEC?) CSAM on their iPhones Who do you think has 30 or more CSAM images on their phone?

Let's be real, of course many of those people will be child abusers. But let's also be real about something else. Think of the Venn diagram of child abusers and people who share CSAM online. Those circles are not identical. Not everybody with CSAM is necessarily a child abuser. Worse, how many child abusers don't share CSAM online? Those can't ever be found by Apple-style invasions of privacy, so one has to wonder if…

All CSAM is produced by child abuse. Everyone who shares 30 images online is a participant in child abuse, even if only by creating a demand for images.

> a crime fighting strategy

Is it a crime fighting strategy? I thought it was just about not making their devices and services into aids for these crimes.

> The cynic in me is also wondering what fraction of people working at places like NCMEC are pedophiles.

Good question. What has that to do with this?

Post reply on HN