Earlier quoted context omitted.
> This is a new mechanism for scanning private pictures on the device. No it isn’t. It’s a mechanism for scanning pictures as they are uploaded to iCloud Photo Library. Private pictures on the device are not scanned.
Pictures not uploaded yet are private.
Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
351–360 of 465 posts
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#352Earlier quoted context omitted.
Apple controls the hardware, software, and cloud service. It was always a pinky promise that they wouldn't look at your files. I don't know why we should doubt that pinky promise less today than we did a month ago.
Should they even be doing that though? It seems like a matter of time before it's possible to SWAT somebody by sending them a series of hash colliding image files given how not cryptographically secure the hash algorithm is. I think I'm not the only one who'd rather not have my devices call the cops on me in a country where the cops are already way too violent.
Further, this is step 1 of a process they have explicitly said they are looking to expand on [1], even going as far to state it in bold font with a standout color.
So theres no telling that they wont expand it by simply scanning everything, regardless of icloud usage, or pivot it to other combat "domestic terrorism" or "gun violence epidemics" or whatever else they feel like.
Its an erosion of trust, even if not a full stop erosion, its something they intend to expand upon and wont be taking back.
[1] https://www.apple.com/child-safety/pdf/Expanded_Protections_...
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#353Earlier quoted context omitted.
That's the point: catching the bad guy foolish enough to keep known CSAM images on their phone, while not technically invading the privacy of any good guys. Anyway, if apple wanted to covertly invade their users' privacy, they'd have no technical problems to do so. What it takes to accept is the "nothing to hide" mentality: your files are safe to scan (locally) because they can't be known CSAM files. You have to trus…
I mostly agree, though I will argue for the other side; child predators don't exactly have a track record for intelligence. Pedophiles still to this day get caught trading CP on Facebook of all places. I think engaging in that kind of activity requires a certain number of brain cells misfiring. Watch some old episodes of To Catch A Predator. Most of those guys were borderline retarded or had obvious personality disor…
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#354Earlier quoted context omitted.
They don't control the database used, any country can thru legal means attach additional hashes for search and reporting. Apple has already proven it will concede to China's demands. They are building the worlds most pervasive surveillance system and when the worlds governments come knocking to use it ... they will throw their hands up and feed you the "Apple complies with all local laws etc.."
> They don't control the database used They control what goes into the on-device database that is used. >The on-device encrypted child abuse database contains only data independently submitted by two or more child safety organizations, located in separate jurisdictions, and thus not under the control of the same government https://www.techwarrant.com/apple-will-only-scan-abuse-image...
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#355Earlier quoted context omitted.
A huge part of Apple’s value proposition is iCloud. If I have to turn that off to keep the spy out of my OS, it’s value to me is dramatically diminished.
Since you presumably don’t trust Apple to scan your photos, it sounds like Apple might not be for you, then. Who will you move to?
"Well you can turn it off" to "Well, but then you just don't trust Apple".
Clearly these are users who did trust Apple. Apple betrayed their trust. Given that Apple bulk handed over iCloud data to China, I don't really believe their pinky promise that they are, by policy only, going to resist government use of this tech. They can cave to government cases _and_ the government can certainly force them to.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#356Earlier quoted context omitted.
I think you might be tilting at windmills here. The issue is that the post I'm replying to claims that data never ends up on Apple's servers even though it does. Thanks for confirming that it does, though.
Am I supposed to be shocked that photos the user uploads to iCloud are on iCloud? The results of the scan looking for kiddie porn cannot be read by Apple until the device finds 30 examples of photos that match known kiddie porn, whereupon Apple gets the decryption key so they can see which images on their server need review, and a human review is triggered to make sure there haven't been 30 false positives.
I implore you to read the comment I originally replied in order to understand the context of my replies. Personally, I don't care what you're shocked about or not, as my OP wasn't directed at you at all.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#357Earlier quoted context omitted.
The thing is that this is a better and more privacy preserving technique. Their hubris is in not seeing or thinking that they will be able to stand up to all kinds of abuses of this system that its mere existence will invite; their hubris is also in thinking that they will be able to perfectly and without mistakes manage and overview a system making accusations so heinous that even the mere act of accusing destroy pe…
What abuses apply to CSAM scanning in this hybrid pipeline which don’t apply to iCloud Backup? If they scanned on the server, why couldn’t governments “slippery slope” abuse the system by requiring that all files on iOS end up in iCloud Backup, where they can be scanned by the system? Since the announcement, I can think of a dozen ways Apple could be easily forced into scanning all the contents of your device by asse…
What we have now is Apple, with its "strong privacy" record, normalizing this. If it succeeds, it would be that much easier for the governments to tackle other stuff onto it. Or, say, lower the threshold needed to submit images for review. I can easily picture some senator ranting about how unacceptable it is that somebody with only 20 CSAM photos won't be flagged, and won't somebody please think of the children?
And yes, if it comes to that, Apple definitely cannot hold the line. After all, they already didn't hold it on encrypted cloud storage - and that wasn't even legally forced on them, merely "not recommended".
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#358We are just one stupid terrorist attack from full surveillance of everybody.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#359Earlier quoted context omitted.
How are those two examples different than before? You can't unupload a photo under either the old or new system. I don't know why we would expect that the scanning feature will be more prone to accidentally scan too many photos compared to the uploading feature accidentally uploading too many photos. >Many people did trust Apple to keep their files private until now. And that was my original point. If a pinky promise…
> You can't unupload a photo under either the old or new system. You can choose to upload many pictures. They will start uploading. Then, you change your mind. Some pictures were not uploaded yet. But they were scanned by the new algorithm.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#360Earlier quoted context omitted.
BigCos, take note: you’re better off doing nefarious shit without telling anyone. Because, if you come clean, you’ll only invite an endless parade of bloggers who will misconstrue your technology to make you look bad.
It's important to keep nefarious stuff on the server side because eventually someone will reverse engineer what's on the client side. Imagine if Apple had done this on the client side without telling anyone, and later it was discovered. I think things would be a whole worse for Apple in that case.