Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

341–350 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#341

Earlier quoted context omitted.

> NCMEC is an arm of the government. Either they share voluntarily or they get subpoenaed endlessly. A subpoena is a lot different than scanning every single photo on every user's device automatically. > Why do you think all of these companies even do this? lol Because most companies don't give a shit about privacy? And they will cave at even the slightest government pressure to do so. Honestly it's probably easier f…

If Apple really didn’t care about privacy they’d end e2ee and scan on the server side like Google and Microsoft. > Because most companies don't give a shit about privacy? And they will cave at even the slightest government pressure to do so. Honestly it's probably easier for them that way (but worse for the consumer). Most people don’t care. I’m giving you solutions and you’re taking about convenience how hard it is.…

> If Apple really didn’t care about privacy they’d end e2ee and scan on the server side like Google and Microsoft.

It's not black or white. Clearly Apple does care more about privacy than most other tech companies. That doesn't mean we shouldn't be critical of them when they make a mistake.

Also, Apple doesn't use e2ee now. AFAIK it's possible for them to decrypt the contents of your iCloud content, and they will do so and forward your data if legally required to.

> Most people don’t care. I’m giving you solutions and you’re taking about convenience how hard it is. Plugging in your phone is trivial.

I don't see what is so hard for you to understand about this - because of Apple's decision, I gain nothing and lose privacy. I shouldn't have to jump through extra hoops to avoid that, and it's reasonable to dislike Apple's position on this. In order to replicate the same functionality I would have to remember to sync my phone every night, and if I ever forgot and my phone died, I just lost data. Yours is an indefensible position when a MUCH easier solution exists today.

> I assume you’re going to stick with iCloud even despite this “privacy” issue? If not, what are you switching to?

That's a bold assumption. I haven't decided yet, for a couple reasons. One is that it's a pain in the ass to switch providers, so I'm going to wait and see if Apple actually follows through with it. Two is that it's possible that Apple is only implementing this so that they can in fact implement full e2ee and then tell law enforcement to kick rocks when they ask for user data (only allowing them to see the CSAM results before they are uploaded to the cloud). I might be willing to accept that compromise, but it's not clear that that is what their plan is.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#342

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar. Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people l…

> all the big names in tech have been scanning everything in your account [...] without any noticeable uproar

In part because people didn't know.

And if you were one of innocent people caught by them, you wouldn't want people to know.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#343

Earlier quoted context omitted.

Photos that users choose to upload to iCloud Photos do indeed get uploaded to iCloud Photos? I'm failing to see the issue.

I think you might be tilting at windmills here. The issue is that the post I'm replying to claims that data never ends up on Apple's servers even though it does. Thanks for confirming that it does, though.

Am I supposed to be shocked that photos the user uploads to iCloud are on iCloud?

The results of the scan looking for kiddie porn cannot be read by Apple until the device finds 30 examples of photos that match known kiddie porn, whereupon Apple gets the decryption key so they can see which images on their server need review, and a human review is triggered to make sure there haven't been 30 false positives.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#344

Earlier quoted context omitted.

ON YOUR DEVICE (where it's encrypted in a way that Apple can't read until the 30 image threshold is crossed) is more private than doing the same scan on server where a single false positive can be misused by anyone who can get a subpoena.

> where it's encrypted in a way that Apple can't read This doesn't matter because Apple can read iCloud data, including iCloud Photos. They hold the encryption keys, and they hand over customers' data for about 150,000 users/accounts a year in response to requests from the government[1]. [1] https://www.apple.com/legal/transparency/us.html

Of course Apple can read iCloud data.

How do you think Google and Microsoft scan everything in your account? They all have the capability to read your cloud data.

What Apple cannot read are the results of your device scanning your iCloud Photos. Those results are encrypted and stay that way until your device finds 30 matches for known kiddie porn.

Once you pass the threshhold, Apple gets the decryption key and a human review is triggered to make sure there weren't just 30 false positives.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#345
post #130

Earlier quoted context omitted.

But who was complaining about google and microsoft doing the cloud scanning? I don’t mind my one drive being scanned for “bad stuff”, I very much mind my personally owned data stores being scanned, with no opt out.

The only thing Apple scans are files you upload to iCloud Photos. If you turn off iCloud Photos, nothing is scanned. Microsoft scans everything. >The system that scans cloud drives for illegal images was created by Microsoft and Dartmouth College and donated to NCMEC. The organization creates signatures of the worst known images of child pornography, approximately 16,000 files at present. These file signatures are gi…

I have no idea what I expected but 16,000 photos feels… disgustingly high and ridiculously low at the same time.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#346
post #290

Earlier quoted context omitted.

Pictures not uploaded yet are private.

Not if you have opted to have them uploaded.

Cloud backups are the default on iOS, so you rather have to opt out. And that doesn't even account for apps that can do the same.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#347
post #220

Earlier quoted context omitted.

But this doesn't change any of that. It only changes whether the scanning happens on your device as part of the upload process instead of on the server after the upload.

Yeah that’s right and I don’t think either method is ethical.

Ethics aside, on-device scanning has the benefit of Constitutional protection, at least in the USA. Any attempt by the Government to compel Apple to expand the on-device searching of privately owned devices to find other things would be a clear-cut 4th Amendment violation.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#348
post #149

Earlier quoted context omitted.

Apple controls the hardware, software, and cloud service. It was always a pinky promise that they wouldn't look at your files. I don't know why we should doubt that pinky promise less today than we did a month ago.

They don't control the database used, any country can thru legal means attach additional hashes for search and reporting. Apple has already proven it will concede to China's demands. They are building the worlds most pervasive surveillance system and when the worlds governments come knocking to use it ... they will throw their hands up and feed you the "Apple complies with all local laws etc.."

Then simply disable iCloud Photos sync.

It's bizarre to me that people are freaking out about governments adding client side hashes but no concern that they could be doing server side checks.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#349

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

I have a feeling they already did a test of this with some small sample of people who did not know they were test subjects. I think that in the future it will come out that what they found was disturbing enough that they thought doing it network wide was a worth while endeavor.

This is not me agreeing or disagreeing.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#350

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

> other major cloud providers catch CSAM content on their platform by inspecting every file uploaded

So does Apple.

EDIT: some people don’t like that answer, but “inspecting” in this context clearly means “digitally inspecting” (Google does not physically look at every file) and Apple does this with files that are uploaded. They do it in device, but it’s still inspected. That’s the whole point of this controversy, that there’s not much difference to people WHERE apple inspects and on device is actually arguably worse. Your sentence does not in any way distinguish what Apple does from what others do.

Post reply on HN