Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

391–400 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#391

Earlier quoted context omitted.

Apple inspects every file on the local device Before its uploaded. It’s just pinky promise only matched with the on device database when an upload is intended.

That is the problem. CSAM is just smoke and mirrors paired with appeal to emotions to win approval more easily. I don't want anyone, neither Apple, nor Microsoft, Google and others to sneak into my files. Did anyone realize that in the 21st century our cellphone is essentially our wallet?

Microsoft and Google already scan all files uploaded to them regardless of your preferences.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#392
post #381

Earlier quoted context omitted.

There’s nothing stopping governments from banning E2EE, but in the absence of such bans, no one is under any obligation to build systems that empower them to spy on their users.

I wouldn’t be sure about that, the phone companies already have a legal obligation to allow wiretapping and the government is very happy to put gag orders on this stuff.

CALEA has a carve out for encryption. I’m sure when E2EE is about to be deployed to the masses the law will be updated to force key escrow.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#393

Earlier quoted context omitted.

There is no way to scan people’s content while “respecting their privacy.” The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it).

> The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it). There’s this bizarre notion that using end-to-end encryption can absolve you of responsibility, that the authorities will have to accept an answer of “we literally can’t access it”. That’s just not the case for centralised things: you’re deliberately facilitating some service, government will find you li…

When end-to-end encryption is done correctly, the answer is "we literally can't access it" as a matter of mathematics, whether the state accepts it or not.

A state that does not accept it might retaliate against the entity giving that answer or forbid future use of end-to-end encryption without backdoors, but the truth of the answer doesn't depend on anyone's acceptance.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#394

Earlier quoted context omitted.

The only thing Apple scans are files you upload to iCloud Photos. If you turn off iCloud Photos, nothing is scanned. Microsoft scans everything. >The system that scans cloud drives for illegal images was created by Microsoft and Dartmouth College and donated to NCMEC. The organization creates signatures of the worst known images of child pornography, approximately 16,000 files at present. These file signatures are gi…

I have no idea what I expected but 16,000 photos feels… disgustingly high and ridiculously low at the same time.

It's well known that there are also videos. So these criminals won't be caught watching them.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#395

Earlier quoted context omitted.

> The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it). There’s this bizarre notion that using end-to-end encryption can absolve you of responsibility, that the authorities will have to accept an answer of “we literally can’t access it”. That’s just not the case for centralised things: you’re deliberately facilitating some service, government will find you li…

There’s nothing stopping governments from banning E2EE, but in the absence of such bans, no one is under any obligation to build systems that empower them to spy on their users.

Courts can order them to collect data on users.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#396

Earlier quoted context omitted.

I mostly agree, though I will argue for the other side; child predators don't exactly have a track record for intelligence. Pedophiles still to this day get caught trading CP on Facebook of all places. I think engaging in that kind of activity requires a certain number of brain cells misfiring. Watch some old episodes of To Catch A Predator. Most of those guys were borderline retarded or had obvious personality disor…

This is not true and a harmful generalization. There are dumb people of every type. There are probably smart people you respect that engage in CSAM and are minor-attracted. This kind of privacy invasion will only net a tiny section of that population, as most know that lack of caution is life or death.

> This is not true and a harmful generalization. There are dumb people of every type.

That's purely specious, and you say it as if I ever asserted there aren't "dumb people of every type.", which I didn't say.

Yes, there are dumb people of every "type". Are there as many intelligent people as those of low intelligence who struggle to think abstractly, struggle to read and write, have poor motor control, rely heavily on dogma for a moral compass, or have trouble with impulse control?

If you think there are as many people with a high IQ as a low IQ with those traits, I don't think you're being honest.

Here's some data for you:

https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4478390/

https://pubmed.ncbi.nlm.nih.gov/14744183/

https://pubmed.ncbi.nlm.nih.gov/961457/

https://www.dw.com/en/scientists-find-brain-differences-in-p...

https://sci-hubtw.hkvisa.net/10.1023/a:1018754004962

https://www.livescience.com/4671-study-pedophiles-tend-short...

https://pubmed.ncbi.nlm.nih.gov/29625377/

Are most pedophiles of low intelligence overall? It's doubtful, but there's room for more study.

Are the pedophiles that are offenders of low intelligence? Significantly more offending pedophiles are of low intelligence than the general population. Yes, the factors at play may also apply to other forms of crime. But when you factor out non-offending pedophiles, those we aren't as concerned with in regards to CSAM, the ones that are caught aren't exactly the cream of the crop.

Furthermore, I've met a handful of pedophiles, both convicted and not. Every one of them either was clearly mentally retarded or bordering on retardedness, or they had a severe personality disorder. Yes, it's a small sample size, but the ones that were caught did so doing the dumbest of shit (putting aside the horrific nature of child exploitation in the first place). This even includes a female pedophile, who was both stupid and psychopathic, and I find it funny that one of those studies questions the very existence of female pedophiles.

There are many pedophiles that are of above-average intelligence. Most may not even be considered "dumb". But to imply that there's no difference in distribution of, frankly, dumb people to smart people between different behaviors is absurd in that it ignores any sort of relation implication that intelligence has on said behaviors.

As a group, the data does not suggest that pedophiles are exceptionally intelligent, but rather the opposite.

So yes, while I believe there is a privacy concern (I said earlier I would not want such software or hardware running on my own compuer), I stand by my conclusion that CSAM detection would catch a significant number of pedophiles and probably continue to do so for some time. The point of such systems isn't to be a superweapon to catch every pedophile. The ones that it might catch happen to be the ones who are most likely to offend. If you play the stupid game of uploading CSAM to Apple iCloud, you win the stupid prize of getting convicted, and it just so happens that a ton of pedophiles are likely to do something that boneheaded.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#397

Earlier quoted context omitted.

I mostly agree, though I will argue for the other side; child predators don't exactly have a track record for intelligence. Pedophiles still to this day get caught trading CP on Facebook of all places. I think engaging in that kind of activity requires a certain number of brain cells misfiring. Watch some old episodes of To Catch A Predator. Most of those guys were borderline retarded or had obvious personality disor…

You don't have to be intelligent to know that CSAM is super illegal and you probably don't want them to be co-mingled with pictures of your mum and last night's dinner.

Except intelligence is clustered with other pathologies such as poor impulse control. Knowledge of the law is not the end-all-be-all of human behavior. Both the intelligent and unintelligent are capable of poor impulse control, but the unintelligent are statistically much more likely to exhibit a lack of impulse control, among other things such as difficulty in long-term reasoning and connecting one's actions with adverse effects.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#398

Earlier quoted context omitted.

Take a look at this collision https://twitter.com/SarahJamieLewis/status/14280837442802565...

Those are two almost identical images based off each other. I know that that "think of the children" is a meme, but I think this illustrates the point for apple. If you have a croped or modified image of CSA the system will identify it. As long as your image is different enough from CSA, you are safe. The point here is that Apple is specifically looking for matches against known CSA material. If someone can demonstra…

> If someone can demonstrate that a legal NSFW image (eg. regular old-fashioned pornography), can be collided with a legal, completely 100% SFW image then I'll be concerned.

Look at this other collision: https://twitter.com/SarahJamieLewis/status/14282060881181491... An attacker can send you an innocent looking picture that embbed some CSA material and you get swatted the next day.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#399
post #188

Earlier quoted context omitted.

Because now Apple confirmed themselves that this promise is not kept.

What is "this promise"? Because I would consider it "we will only scan files that you upload to iCloud". That was true a month ago and that would be true under this new system. The only part that is changing is that the scanning happens on your device before upload rather than on an Apple server after upload. I don't view that as a material difference when Apple already controls the hardware and software on both ends…

Why is the scanning done on the device in the first place? Photos uploaded to Icloud are not encrypted (because the US government was apparently opposed to that idea), so why not do what Google and Facebook does and do the scanning once the image reaches their servers. What is the benefit in running the scan on the device?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#400
post #290

Earlier quoted context omitted.

Not if you have opted to have them uploaded.

Cloud backups are the default on iOS, so you rather have to opt out. And that doesn't even account for apps that can do the same.

iCloud backups are not scanned.

Also, what apps are you talking about?

Post reply on HN