Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

411–420 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#411
post #376

Earlier quoted context omitted.

There is no way to scan people’s content while “respecting their privacy.” The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it).

> The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it). You can still do secure backups of your phone without using iCloud, but there isn’t a way for Apple to do end to end encryption of backups transparently like you can with real time communication. The only way end to end encryption of backups works is to require people keep a separate secure key(s) to avo…

Mega.io (from the same people as MegaUpload) has e2e file encryption with just usernames and passwords.

There is no reason the password can't be the encryption key, with backup keys stored with a trusted third party (eg: your credit union or bank) without notation as to what these backup keys are tied to.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#412

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

Repeating myself from another thread but… China. Conjecture, admittedly: 1. Apple cannot lose the Chinese market. Huge and more important fastest growing geo for the company. 2. China is self deprecating elements of its own tech sector (aggressive crackdowns on both established companies like tencent and Alibaba as well as individual web sites). They are clearly cleaning house from a surveillance and control perspect…

If you use Apple devices, you are agreeing to their ToS which since 2019 give them the right to pre-screen your uploads for any potentially illegal (sic) content, not specifically CSAM imagery.

If Apple happens to use similar ToS in China (no idea if true), you bet CCP would be all over this clause.

A worst-case wild guess from the pessimist in me: they had to add this clause in 2019 to appease CCP, and then they got thinking if they could make use of it for the greater good (tm), too. Hopefully it’s very incorrect.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#413
post #400

Earlier quoted context omitted.

Cloud backups are the default on iOS, so you rather have to opt out. And that doesn't even account for apps that can do the same.

iCloud backups are not scanned. Also, what apps are you talking about?

Photos that are automatically uploaded to iCloud are not scanned?

As for apps - WhatsApp, for example, saves everything to Camera Roll by default. Which then gets auto-uploaded to iCloud.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#414

Earlier quoted context omitted.

Microsoft and Google already scan all files uploaded to them regardless of your preferences.

Exactly, and 100% Google and Microsoft have on device scanning as well. We are saying "Apple are bad for admitting it" what about the others that are not?

[deleted]

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#415

Earlier quoted context omitted.

I don't care. It's my device (at least that's how Apple used to advertise it) and I disagree with Apple's policy, full stop. I don't care about "think of the children" (especially since they will be scanning pictures of my own children), and furthermore I don't trust Apple not to change the policy in the future. They've created a backdoor and now the device is compromised and privacy is broken. If you want to trust A…

>I don't care If anything, you should be outraged that Google and Microsoft have been scanning much more of your data, and doing so in a much more intrusive way. Apple only scans iCloud Photos and they do so in a way that they can't see the results until they can be reasonably sure it's not just a false positive.

[deleted]

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#416
post #405

Earlier quoted context omitted.

Sure, but that's a case of "we're prohibited from providing end-to-end encryption and preserving user privacy so we can scan for prohibited content as mandated by authorities", not "we are keeping children safe while still preserving user privacy" Legal terms such as "murder", "fraud" and "rape" do change as effect of regulatory changes. "Encryption" and "privacy" do not. There's a limit to how much you can bend sema…

But if you're a company like apple, it'd be bad business to wait until large government bans your service/device before you respond to it. Much better to read the tea leaves and get a head of it.

Again, their double-speak and redefining words don't help with the reception.

They're deliberately misrepresenting what's happening, appearing surprised when people misunderstand, and bundling together legitimate criticism with misunderstandings.

I can draw some parallels to how Google went out with FLoC.

Honestly I can't tell where Hanlon's razor should cut here.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#417

Earlier quoted context omitted.

There is no way to scan people’s content while “respecting their privacy.” The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it).

> The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it). There’s this bizarre notion that using end-to-end encryption can absolve you of responsibility, that the authorities will have to accept an answer of “we literally can’t access it”. That’s just not the case for centralised things: you’re deliberately facilitating some service, government will find you li…

The law may say that government isn't allowed to spy on people. So no, the state cannot just come and demand anything it wants.

Problem is that the law is self-contradictory and it is up to the judicative institutions to fix it as soon as possible.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#418

Earlier quoted context omitted.

Repeating myself from another thread but… China. Conjecture, admittedly: 1. Apple cannot lose the Chinese market. Huge and more important fastest growing geo for the company. 2. China is self deprecating elements of its own tech sector (aggressive crackdowns on both established companies like tencent and Alibaba as well as individual web sites). They are clearly cleaning house from a surveillance and control perspect…

If you use Apple devices, you are agreeing to their ToS which since 2019 give them the right to pre-screen your uploads for any potentially illegal (sic) content, not specifically CSAM imagery. If Apple happens to use similar ToS in China (no idea if true), you bet CCP would be all over this clause. A worst-case wild guess from the pessimist in me: they had to add this clause in 2019 to appease CCP, and then they got…

Of course the CCP loves stuff like this. The big thing is will apple acquiesce to keeping mum about scanning everyone's stuff at the directive of the government. Also will that just be a "china" build or will it be in the USA code base but "flipped off"

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#419

Earlier quoted context omitted.

It's really interesting to see the mental gymnastics people are willing to go through to defend their favorite trillion dollar corporations. > other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of privacy. > Apple found a way to preserve that privacy ... So scanning for CSAM in a third-party cloud is "total invasion of privacy", while scanning your…

> defend their favorite trillion dollar corporations > is a short slippery slope away Obviously people who trust Apple aren't concerned about slippery slopes. What's the point of your post?

He's just commenting on how ludicrous it is for anyone to believe that apple is being honest about this and about spying for governments on its users.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#420

Earlier quoted context omitted.

That is the problem. CSAM is just smoke and mirrors paired with appeal to emotions to win approval more easily. I don't want anyone, neither Apple, nor Microsoft, Google and others to sneak into my files. Did anyone realize that in the 21st century our cellphone is essentially our wallet?

Microsoft and Google already scan all files uploaded to them regardless of your preferences.

No they don't, they scan them on the servers. If you have a source that says otherwise I'd love to see. I'm 99.99% sure you won't find any.
Post reply on HN