Earlier quoted context omitted.
> The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it). There’s this bizarre notion that using end-to-end encryption can absolve you of responsibility, that the authorities will have to accept an answer of “we literally can’t access it”. That’s just not the case for centralised things: you’re deliberately facilitating some service, government will find you li…
There’s nothing stopping governments from banning E2EE, but in the absence of such bans, no one is under any obligation to build systems that empower them to spy on their users.
Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
381–390 of 465 posts
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#382Earlier quoted context omitted.
The only thing Apple scans are files you upload to iCloud Photos. If you turn off iCloud Photos, nothing is scanned. Microsoft scans everything. >The system that scans cloud drives for illegal images was created by Microsoft and Dartmouth College and donated to NCMEC. The organization creates signatures of the worst known images of child pornography, approximately 16,000 files at present. These file signatures are gi…
> If you turn off iCloud Photos, nothing is scanned. According to Apple. and For Now. Patriot Act was only for terrorists. Apple makes concessions for China. Creating this technology, makes it very easy for China to go, "Look at all photos, always". If they only want to scan stuff on iCloud Photos, no worries, just implement on it on their end. This tech does not need to exist in that case. > Microsoft scans everythi…
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#383Earlier quoted context omitted.
Something to note here is that in the hash collision that was discovered, the two images look nothing alike. One is a picture of a dog, the other is blobby grey static.
They actually do look alike to my eye, but in a “the way the algorithm sees it” kind of way. I can see the obvious similarity. But to your point it’s not like it’s two very slightly different photos of dogs.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#384Earlier quoted context omitted.
Apple keeps the scan results encrypted with a key they don't have until the device informs them that the threshold of 30 images that match known kiddie porn has been reached. After that, they get the decryption key and trigger a human review to make sure there haven't been 30 false positives at once. That is better, and more private, in a very meaningful way. False positive scan data sitting on the server is open to…
I do agree that it's more private, but I'm not sure it's better. I'm fine with the idea that if I upload stuff to someone else's server, they may take a look at it and maybe even punish me for what I've uploaded. Certainly if I encrypt the data before I upload it, they can't do that. But if I don't, then it's fine with me if they do. But my device should not be snitching on me. Yes, this device-side scanning is suppo…
Apple has the ability to upload literally any software to iPhones, so this argument applies equally to literally any conceivable bad thing that software could do on iPhones.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#385Earlier quoted context omitted.
Since you presumably don’t trust Apple to scan your photos, it sounds like Apple might not be for you, then. Who will you move to?
Motte and Bailey much? "Well you can turn it off" to "Well, but then you just don't trust Apple". Clearly these are users who did trust Apple. Apple betrayed their trust. Given that Apple bulk handed over iCloud data to China, I don't really believe their pinky promise that they are, by policy only, going to resist government use of this tech. They can cave to government cases _and_ the government can certainly force…
Therefore you must trust Apple. So if you still have issues then you don’t trust Apple.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#386Earlier quoted context omitted.
As has been repeated over and over, apple only scans photos that are part if icloud photos (ie, uploaded). Don't want your photo's scanned, don't sync them to icloud. Seriously! Please include the actual system when discussing this system, not your bogeyman system. "To help address this, new technology in iOS and iPadOS* will allow Apple to detect known CSAM images stored in iCloud Photos." To increase privacy - they…
As has been repeated over and over, apple only scans photos that are part if icloud photos (ie, uploaded). "for now" Which is the part most people have a problem with -- they say that they are only scanning iCloud uploads now, but it's simple extension of the scanner to scan all files. I don't care if Apple scans my iCloud uploads on iCloud servers, I don't want them scanning photos on my device.
I don't have a problem if it scans everything, but its not. Let's stick to what is doing. Android could do this as well, so talking about what companies like google could do is not so interesting - they could do almost anything.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#387Earlier quoted context omitted.
That's the point: catching the bad guy foolish enough to keep known CSAM images on their phone, while not technically invading the privacy of any good guys. Anyway, if apple wanted to covertly invade their users' privacy, they'd have no technical problems to do so. What it takes to accept is the "nothing to hide" mentality: your files are safe to scan (locally) because they can't be known CSAM files. You have to trus…
The "nothing to hide" mentality is exactly what's wrong about all this.
Everybody knows what goes on behind that door. And yet, everyone would much prefer to close it. Apple's method is equivalent to the toilet door being removed, so that you cannot do anything nefarious behind that door.
Your phone also (on average) have nothing to hide, but that's also why you need privacy on your devices.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#388Earlier quoted context omitted.
Something to note here is that in the hash collision that was discovered, the two images look nothing alike. One is a picture of a dog, the other is blobby grey static.
Take a look at this collision https://twitter.com/SarahJamieLewis/status/14280837442802565...
I know that that "think of the children" is a meme, but I think this illustrates the point for apple. If you have a croped or modified image of CSA the system will identify it. As long as your image is different enough from CSA, you are safe.
The point here is that Apple is specifically looking for matches against known CSA material.
If someone can demonstrate that a legal NSFW image (eg. regular old-fashioned pornography), can be collided with a legal, completely 100% SFW image then I'll be concerned.
But until then, this looks like a reasonable and supportable way for finding CSAM in real time.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#389Earlier quoted context omitted.
There’s nothing stopping governments from banning E2EE, but in the absence of such bans, no one is under any obligation to build systems that empower them to spy on their users.
I wouldn’t be sure about that, the phone companies already have a legal obligation to allow wiretapping and the government is very happy to put gag orders on this stuff.
Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’
#390Earlier quoted context omitted.
> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…
It's really interesting to see the mental gymnastics people are willing to go through to defend their favorite trillion dollar corporations. > other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of privacy. > Apple found a way to preserve that privacy ... So scanning for CSAM in a third-party cloud is "total invasion of privacy", while scanning your…