Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

381–390 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#381

Earlier quoted context omitted.

> The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it). There’s this bizarre notion that using end-to-end encryption can absolve you of responsibility, that the authorities will have to accept an answer of “we literally can’t access it”. That’s just not the case for centralised things: you’re deliberately facilitating some service, government will find you li…

There’s nothing stopping governments from banning E2EE, but in the absence of such bans, no one is under any obligation to build systems that empower them to spy on their users.

I wouldn’t be sure about that, the phone companies already have a legal obligation to allow wiretapping and the government is very happy to put gag orders on this stuff.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#382
post #362

Earlier quoted context omitted.

The only thing Apple scans are files you upload to iCloud Photos. If you turn off iCloud Photos, nothing is scanned. Microsoft scans everything. >The system that scans cloud drives for illegal images was created by Microsoft and Dartmouth College and donated to NCMEC. The organization creates signatures of the worst known images of child pornography, approximately 16,000 files at present. These file signatures are gi…

> If you turn off iCloud Photos, nothing is scanned. According to Apple. and For Now. Patriot Act was only for terrorists. Apple makes concessions for China. Creating this technology, makes it very easy for China to go, "Look at all photos, always". If they only want to scan stuff on iCloud Photos, no worries, just implement on it on their end. This tech does not need to exist in that case. > Microsoft scans everythi…

“And for now” is not a particularly strong argument because it applies to literally anything that software could ever conceivably do on an iPhone, because Apple has the ability to release any software updates they want.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#383

Earlier quoted context omitted.

Something to note here is that in the hash collision that was discovered, the two images look nothing alike. One is a picture of a dog, the other is blobby grey static.

They actually do look alike to my eye, but in a “the way the algorithm sees it” kind of way. I can see the obvious similarity. But to your point it’s not like it’s two very slightly different photos of dogs.

You must be a champion CAPTCHA solver.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#384
post #372

Earlier quoted context omitted.

Apple keeps the scan results encrypted with a key they don't have until the device informs them that the threshold of 30 images that match known kiddie porn has been reached. After that, they get the decryption key and trigger a human review to make sure there haven't been 30 false positives at once. That is better, and more private, in a very meaningful way. False positive scan data sitting on the server is open to…

I do agree that it's more private, but I'm not sure it's better. I'm fine with the idea that if I upload stuff to someone else's server, they may take a look at it and maybe even punish me for what I've uploaded. Certainly if I encrypt the data before I upload it, they can't do that. But if I don't, then it's fine with me if they do. But my device should not be snitching on me. Yes, this device-side scanning is suppo…

> And since Apple certainly has the capability, they are likely one secret court order away from being required to scan even photos that aren't being uploaded, at least on some targeted subset of devices.

Apple has the ability to upload literally any software to iPhones, so this argument applies equally to literally any conceivable bad thing that software could do on iPhones.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#385

Earlier quoted context omitted.

Since you presumably don’t trust Apple to scan your photos, it sounds like Apple might not be for you, then. Who will you move to?

Motte and Bailey much? "Well you can turn it off" to "Well, but then you just don't trust Apple". Clearly these are users who did trust Apple. Apple betrayed their trust. Given that Apple bulk handed over iCloud data to China, I don't really believe their pinky promise that they are, by policy only, going to resist government use of this tech. They can cave to government cases _and_ the government can certainly force…

The point is that turning it off resolves the issue, but if someone refuses to turn it off because they want to use iCloud there’s clearly a contradiction.

Therefore you must trust Apple. So if you still have issues then you don’t trust Apple.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#386

Earlier quoted context omitted.

As has been repeated over and over, apple only scans photos that are part if icloud photos (ie, uploaded). Don't want your photo's scanned, don't sync them to icloud. Seriously! Please include the actual system when discussing this system, not your bogeyman system. "To help address this, new technology in iOS and iPadOS* will allow Apple to detect known CSAM images stored in iCloud Photos." To increase privacy - they…

As has been repeated over and over, apple only scans photos that are part if icloud photos (ie, uploaded). "for now" Which is the part most people have a problem with -- they say that they are only scanning iCloud uploads now, but it's simple extension of the scanner to scan all files. I don't care if Apple scans my iCloud uploads on iCloud servers, I don't want them scanning photos on my device.

People are pretending it scans everything on your device. This conversation is already bad enough without adding additional confusion over what this does.

I don't have a problem if it scans everything, but its not. Let's stick to what is doing. Android could do this as well, so talking about what companies like google could do is not so interesting - they could do almost anything.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#387
post #247

Earlier quoted context omitted.

That's the point: catching the bad guy foolish enough to keep known CSAM images on their phone, while not technically invading the privacy of any good guys. Anyway, if apple wanted to covertly invade their users' privacy, they'd have no technical problems to do so. What it takes to accept is the "nothing to hide" mentality: your files are safe to scan (locally) because they can't be known CSAM files. You have to trus…

The "nothing to hide" mentality is exactly what's wrong about all this.

Yes. You don't leave the toilet doors open, not because you don't "have nothing to hide", but because privacy is a right.

Everybody knows what goes on behind that door. And yet, everyone would much prefer to close it. Apple's method is equivalent to the toilet door being removed, so that you cannot do anything nefarious behind that door.

Your phone also (on average) have nothing to hide, but that's also why you need privacy on your devices.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#388

Earlier quoted context omitted.

Something to note here is that in the hash collision that was discovered, the two images look nothing alike. One is a picture of a dog, the other is blobby grey static.

Take a look at this collision https://twitter.com/SarahJamieLewis/status/14280837442802565...

Those are two almost identical images based off each other.

I know that that "think of the children" is a meme, but I think this illustrates the point for apple. If you have a croped or modified image of CSA the system will identify it. As long as your image is different enough from CSA, you are safe.

The point here is that Apple is specifically looking for matches against known CSA material.

If someone can demonstrate that a legal NSFW image (eg. regular old-fashioned pornography), can be collided with a legal, completely 100% SFW image then I'll be concerned.

But until then, this looks like a reasonable and supportable way for finding CSAM in real time.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#389
post #381

Earlier quoted context omitted.

There’s nothing stopping governments from banning E2EE, but in the absence of such bans, no one is under any obligation to build systems that empower them to spy on their users.

I wouldn’t be sure about that, the phone companies already have a legal obligation to allow wiretapping and the government is very happy to put gag orders on this stuff.

Shouldn't the E2EE apple walled-garden app equivalent of wiretapping be pushing an app update to the suspect's phone with a sidechannel added for law enforcement to snoop, with warrant in hand?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#390

Earlier quoted context omitted.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

It's really interesting to see the mental gymnastics people are willing to go through to defend their favorite trillion dollar corporations. > other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of privacy. > Apple found a way to preserve that privacy ... So scanning for CSAM in a third-party cloud is "total invasion of privacy", while scanning your…

They are scanning files that are being uploaded. So, yes.
Post reply on HN