Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

361–370 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#361
post #130

Earlier quoted context omitted.

But who was complaining about google and microsoft doing the cloud scanning? I don’t mind my one drive being scanned for “bad stuff”, I very much mind my personally owned data stores being scanned, with no opt out.

The only thing Apple scans are files you upload to iCloud Photos. If you turn off iCloud Photos, nothing is scanned. Microsoft scans everything. >The system that scans cloud drives for illegal images was created by Microsoft and Dartmouth College and donated to NCMEC. The organization creates signatures of the worst known images of child pornography, approximately 16,000 files at present. These file signatures are gi…

If Microsoft's scan is a server-side scan, how do they scan "everything" if "everything" includes things that you do not upload?

By your definition of "everything", both Microsoft and Apple scan "everything". (Or Apple will, after this new system is rolled out.)

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#362
post #130

Earlier quoted context omitted.

But who was complaining about google and microsoft doing the cloud scanning? I don’t mind my one drive being scanned for “bad stuff”, I very much mind my personally owned data stores being scanned, with no opt out.

The only thing Apple scans are files you upload to iCloud Photos. If you turn off iCloud Photos, nothing is scanned. Microsoft scans everything. >The system that scans cloud drives for illegal images was created by Microsoft and Dartmouth College and donated to NCMEC. The organization creates signatures of the worst known images of child pornography, approximately 16,000 files at present. These file signatures are gi…

> If you turn off iCloud Photos, nothing is scanned.

According to Apple. and For Now. Patriot Act was only for terrorists. Apple makes concessions for China. Creating this technology, makes it very easy for China to go, "Look at all photos, always". If they only want to scan stuff on iCloud Photos, no worries, just implement on it on their end. This tech does not need to exist in that case.

> Microsoft scans everything.

Everything uploaded to the Cloud. The Cloud bit is fairly important here. That's me, willingly, putting information on their property. Perfectly acceptable and fine for them to ensure that it's nothing unethical.

However, someone else snooping through your drawers looking for something to pin on you is not private, nor the same as checking their own property.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#363
post #247

Earlier quoted context omitted.

That's the point: catching the bad guy foolish enough to keep known CSAM images on their phone, while not technically invading the privacy of any good guys. Anyway, if apple wanted to covertly invade their users' privacy, they'd have no technical problems to do so. What it takes to accept is the "nothing to hide" mentality: your files are safe to scan (locally) because they can't be known CSAM files. You have to trus…

I mostly agree, though I will argue for the other side; child predators don't exactly have a track record for intelligence. Pedophiles still to this day get caught trading CP on Facebook of all places. I think engaging in that kind of activity requires a certain number of brain cells misfiring. Watch some old episodes of To Catch A Predator. Most of those guys were borderline retarded or had obvious personality disor…

That sounds like survivorship bias. Of course the people who get caught for doing things the stupid way are going to be branded as stupid. How about the people who don't get caught, or the people who get caught despite doing a decent job of covering their tracks? What evidence do you have that most pedophiles are of the stupid sort?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#364

Earlier quoted context omitted.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

> catch the bad people doing very bad things to children You may catch a few perverts looking at the stuff, but I'm not convinced this will lead to catching the producers. How would that happen?

The theory is that if you make it too risky to possess CSAM, demand for it will drop, leading to less exploitation. I don't know if I buy that theory, but... there it is.

Compare this to the war on drugs. There is huge demand for drugs. Many drugs are highly illegal to possess, and a lot of people get jailed for possessing them. And yet most of us consider the war on drugs to be an abject failure that hasn't done much more than create inequity.

Why should something like CSAM possession be any different? I wish it was different, and these sorts of tactics would reduce this awful problem, but I'm just not convinced it does.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#365
post #247

Earlier quoted context omitted.

That's the point: catching the bad guy foolish enough to keep known CSAM images on their phone, while not technically invading the privacy of any good guys. Anyway, if apple wanted to covertly invade their users' privacy, they'd have no technical problems to do so. What it takes to accept is the "nothing to hide" mentality: your files are safe to scan (locally) because they can't be known CSAM files. You have to trus…

I mostly agree, though I will argue for the other side; child predators don't exactly have a track record for intelligence. Pedophiles still to this day get caught trading CP on Facebook of all places. I think engaging in that kind of activity requires a certain number of brain cells misfiring. Watch some old episodes of To Catch A Predator. Most of those guys were borderline retarded or had obvious personality disor…

You don't have to be intelligent to know that CSAM is super illegal and you probably don't want them to be co-mingled with pictures of your mum and last night's dinner.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#366

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

There is no way to scan people’s content while “respecting their privacy.” The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it).

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#367

Earlier quoted context omitted.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

Apple inspects every file on the local device Before its uploaded. It’s just pinky promise only matched with the on device database when an upload is intended.

That is the problem. CSAM is just smoke and mirrors paired with appeal to emotions to win approval more easily. I don't want anyone, neither Apple, nor Microsoft, Google and others to sneak into my files. Did anyone realize that in the 21st century our cellphone is essentially our wallet?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#368
post #247

Earlier quoted context omitted.

That's the point: catching the bad guy foolish enough to keep known CSAM images on their phone, while not technically invading the privacy of any good guys. Anyway, if apple wanted to covertly invade their users' privacy, they'd have no technical problems to do so. What it takes to accept is the "nothing to hide" mentality: your files are safe to scan (locally) because they can't be known CSAM files. You have to trus…

I mostly agree, though I will argue for the other side; child predators don't exactly have a track record for intelligence. Pedophiles still to this day get caught trading CP on Facebook of all places. I think engaging in that kind of activity requires a certain number of brain cells misfiring. Watch some old episodes of To Catch A Predator. Most of those guys were borderline retarded or had obvious personality disor…

> child predators don't exactly have a track record for intelligence

Maybe that's true of the ones that get caught, but if so there's a good chance that at least part of that is inverse survivorship bias. (Similar to “Why are most of the CIA covert missions you hear about failures?”)

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#369
post #260

Earlier quoted context omitted.

Maybe Apple was focused on keeping CSAM off a cloud resource that really is Apple's in both a practical and technical sense. Merely scanning after upload maybe doesn't accomplish that because the material already has arrived in an Apple resource and someone might define that as a failure. Viewed from a perspective of iCloud compliance it sorta makes sense. No one ought to feel a lot of (legal) security deploying a sy…

With the new system, it still arrives on the server, and they can't even know about it until some threshold has been passed - and then the servers still have to scan it. So it's not even accomplishing "keeping it off the servers."

Actually it'll do an excellent job of keeping it off their servers.

Apple's actions will be effective at making sure every CSAM aficionado will not trust their device. Or, if they're tech savvy, they will at least know not to co-mingle their deepest darkest secrets alongside photos of their mum and last night's dinner.

If you think Apple's very big, very public blow-up is making waves in the hacker/security/libertarian crowd, just imagine how big it's blowing up in the CSAM community right now. I dare say it's probably all they've been talking about for the past two weeks. Unlike places like Hacker News where there's plenty of people desperate to drag Apple through the coals, the CSAM community will be highly motivated to have a precise understanding of what Apple is doing. I dare say that they'll be extremely well informed about exactly what Apple's plans entail and how to work around them.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#370

Earlier quoted context omitted.

It’s really unpopular inside the fruit company. I’ve not spoken with a single engineer in Cupertino who thinks this is a good path. There has been radio silence from management on how to address this. It almost feels like they want this to fail. In the past management has given us resources and talking points we can use with our friends and family. Not this time.

> In the past management has given us resources and talking points we can use with our friends and family. Wow. That feels like an overreach. 'We don't just buy your labor, but also your private opinion and tell you how to talk to your family'.

Certainly people tow the official line, but it does help us to articulate the position of the company so that we aren’t so misinformed that we spread FUD.
Post reply on HN