Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

371–380 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#371

Earlier quoted context omitted.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

There is no way to scan people’s content while “respecting their privacy.” The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it).

> The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it).

There’s this bizarre notion that using end-to-end encryption can absolve you of responsibility, that the authorities will have to accept an answer of “we literally can’t access it”.

That’s just not the case for centralised things: you’re deliberately facilitating some service, government will find you liable for some things in its operation, and if you don’t comply, they’ll fine or shut you down. E2EE doesn’t absolve you from law; law is all about saying you’re not allowed to do things that are physically possible.

(Decentralised things, now they can be banned but not truly stopped because there’s no central party to shut down.)

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#372

Earlier quoted context omitted.

That's not really better or different. In any meaningful way.

Apple keeps the scan results encrypted with a key they don't have until the device informs them that the threshold of 30 images that match known kiddie porn has been reached. After that, they get the decryption key and trigger a human review to make sure there haven't been 30 false positives at once. That is better, and more private, in a very meaningful way. False positive scan data sitting on the server is open to…

I do agree that it's more private, but I'm not sure it's better.

I'm fine with the idea that if I upload stuff to someone else's server, they may take a look at it and maybe even punish me for what I've uploaded. Certainly if I encrypt the data before I upload it, they can't do that. But if I don't, then it's fine with me if they do.

But my device should not be snitching on me. Yes, this device-side scanning is supposedly gated on enabling uploads to iCloud, but that doesn't really make for much of a distinction to me. And since Apple certainly has the capability, they are likely one secret court order away from being required to scan even photos that aren't being uploaded, at least on some targeted subset of devices.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#373

Earlier quoted context omitted.

They don't control the database used, any country can thru legal means attach additional hashes for search and reporting. Apple has already proven it will concede to China's demands. They are building the worlds most pervasive surveillance system and when the worlds governments come knocking to use it ... they will throw their hands up and feed you the "Apple complies with all local laws etc.."

Then simply disable iCloud Photos sync. It's bizarre to me that people are freaking out about governments adding client side hashes but no concern that they could be doing server side checks.

Have you tried disabling various iCloud features? Disabling iCloud is incredibly buggy.

I tried disabling iCloud keychain and it just flips back on. Sometimes it asks for a login first. Sometimes it shows a cancel/continue modal. Either way, it magically flips back on. No error message.

I tried backing up my device to my hard drive (with Photos already on iCloud) and it kept complaining that there wasn’t enough space. It throws error message after warning message that your content will be deleted. It created additional copies of my photos each time my phone synced.

To properly back up, I had to copy the photos directory to an external hard drive, delete the original, mark the external hard drive one as the system one and then finally free up enough space to back up. iCloud and the device backup weren’t smart enough to free up space for my backup. In fact, I first backed up all my photos to iCloud first because they said that it would free up space on my hard drive as necessary. LOL.

BTW, iCloud keychain is still on for me. Fuck Apple.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#374

Earlier quoted context omitted.

There is no way to scan people’s content while “respecting their privacy.” The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it).

> The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it). There’s this bizarre notion that using end-to-end encryption can absolve you of responsibility, that the authorities will have to accept an answer of “we literally can’t access it”. That’s just not the case for centralised things: you’re deliberately facilitating some service, government will find you li…

There’s nothing stopping governments from banning E2EE, but in the absence of such bans, no one is under any obligation to build systems that empower them to spy on their users.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#375
post #174

Earlier quoted context omitted.

Making it obviously and unquestionably more invasive.

I just don't get this. Say you're given two options when going through the TSA. 1. The TSA agent opens your luggage and searches everything for banned items. 2. The TSA agent hands you a scanner for you to wave over your luggage in private, it prints out a receipt of banned items it saw, and you present that receipt to the agent. Which one is more invasive?

The scenario is far more like this

3. The home builder installs a TSA scanner in all newly built homes. The scanners will scan all items as they are put away into drawers and cupboards, attempting to detect the presence of banned items.

Then the TSA Agents say they won't report you until at least 30 banned items are detected, even though you haven't flown in 10 years and don't have banned materials. As the TSA Agents walk back to their car, you overhear words like warrant, trouble, and tap amidst their chuckles. What could go wrong with that?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#376

Earlier quoted context omitted.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

There is no way to scan people’s content while “respecting their privacy.” The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it).

> The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it).

You can still do secure backups of your phone without using iCloud, but there isn’t a way for Apple to do end to end encryption of backups transparently like you can with real time communication. The only way end to end encryption of backups works is to require people keep a separate secure key(s) to avoid losing their data, which means a universal implementation has real direct risk for users.

As long as Apple has access to these files the FBI can legally require them to do these searches. From a pure PR perspective they should have communicated what was already going on before releasing this system because people assume something significant changed.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#377
post #373

Earlier quoted context omitted.

Then simply disable iCloud Photos sync. It's bizarre to me that people are freaking out about governments adding client side hashes but no concern that they could be doing server side checks.

Have you tried disabling various iCloud features? Disabling iCloud is incredibly buggy. I tried disabling iCloud keychain and it just flips back on. Sometimes it asks for a login first. Sometimes it shows a cancel/continue modal. Either way, it magically flips back on. No error message. I tried backing up my device to my hard drive (with Photos already on iCloud) and it kept complaining that there wasn’t enough space…

I just tried disabling iCloud for Game Center. It flips itself back on. No error message. Fuck Apple.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#378
post #149

Earlier quoted context omitted.

Apple controls the hardware, software, and cloud service. It was always a pinky promise that they wouldn't look at your files. I don't know why we should doubt that pinky promise less today than we did a month ago.

They don't control the database used, any country can thru legal means attach additional hashes for search and reporting. Apple has already proven it will concede to China's demands. They are building the worlds most pervasive surveillance system and when the worlds governments come knocking to use it ... they will throw their hands up and feed you the "Apple complies with all local laws etc.."

They can upload any software to iPhones that they want. They may not create the database of hashes, but they can choose whether their software uses that database.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#379

Earlier quoted context omitted.

I think the difference here is that it's ON YOUR DEVICE. I think there's a pretty clear understanding that if you upload stuff to a cloud provider they can do whatever they want with it. This is different. This is reaching into what has up until now mostly been considered a private place. Law enforcement often has to get warrants to search this kind of thing. This is the difference between putting CSAM on a sign in y…

ON YOUR DEVICE (where it's encrypted in a way that Apple can't read until the 30 image threshold is crossed) is more private than doing the same scan on server where a single false positive can be misused by anyone who can get a subpoena.

A poster upthread made an analogy that I really like. Sure, like all analogies, it's imperfect, but I think it strikes at why many people are uneasy about this.

Let's say the TSA were to install air-travel-contraband scanners in everyone's homes, but promise only to scan things that are being put into your luggage as you prepare to go to the airport. And let's say that this became a requirement if you want to board a plane.

That's what this feels like. I'm fine with Google scanning through everything in my GMail account, or everything I've uploaded to GDrive, or created in GDocs. That stuff is on their servers, unencrypted, and I explicitly put it there.

But I'm sure as hell not going to let Google install something on my laptop (or phone!) that lets them look at my stuff, even if they pinky-promise that they'll only scan stuff that I intend to upload.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#380
post #250

Earlier quoted context omitted.

Until one day a box pops up. It says "We've updated our terms. See this 10,000 line document here. Please accept to continue using your device." Then your clause is gone.

I'm fine with that. Apple is a big company and changing its TOS will be instantly reported on. It will act as a canary of sorts to know when they turn evil and we know to stop using their products.

Isn't the design of this system enough of a canary?
Post reply on HN