Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

421–430 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#421

Earlier quoted context omitted.

Microsoft and Google already scan all files uploaded to them regardless of your preferences.

Exactly, and 100% Google and Microsoft have on device scanning as well. We are saying "Apple are bad for admitting it" what about the others that are not?

You have 0 proof of that other than conjecture. They are not scanning stuff and uploading it to government organizations to come and arrest you.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#422

Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…

If it's in the cloud you can choose not to use the cloud service. If it's on device - a device you'e spent over $1000 on and already own - you don't have a choice (unless you want to forgo all updates, including security patches).

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#423
post #328

Earlier quoted context omitted.

This is a great answer but that’s not actually the GP’s contention. Their argument is essentially “so what if there’s a collision, the human review will catch it”. And to that I’d say that the same is supposed to occur for the no-fly list and we all know how that works in practice. The mere accusal itself of possessing CSAM can be life ruining if it gets to that stage. More importantly, a collision will effectively a…

That’s one check. There are other system checks to make the client side hash collision meaningless.

Do you understand that anyone can take absolutely legal porn and make it match CSAM hash? And no one except NCMEC can know the difference because they all only compare hashes and not actual images.

And whoever going to check images for Apple will see that yeah, there is porn on picture. Flag it. Then you'll have unlimited amount of time to explain to FBI why some porn on your device match CSAM hash.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#424
post #237

Apple does check it just before you upload it to icloud. How much money do they save it's is checked clientside? How much would it cost for Apple to do it on there own servers, like everybody else does it?

Iirc the rationale for doing it clientside isn't saving money, but maintaining encryption. If it's checked client side, Apple should never get unencrypted uploads unless they're suspected to be CSAM

Yes thats the official version. I still wonder what would be the cost difference. In this scale it is not just for free.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#425

Earlier quoted context omitted.

And if you make the second image be actual, 18+ porn? Will Apple be able to tell the difference between that and CSAM after the blur is applied? Bonus points if you match poses, coloration, background, etc.

The only way to match poses, coloration, background, etc is to possess illegal CSAM content. If you do so successfully, you will result in your crafted image passing the blur check and reaching the agency that possesses the original image for final verification, where it will immediately fail because it is obviously a replica. You will then trigger that agency leading law enforcement to find the creator of the image,…

Why would attacker need to create anything from scratch? If you want to build a dataset of images with people with specific skin and hair color, body types, etc in very specific poses it's can be quite hard and expensive to do so. Because even photo stocks have limited number of such photos. Unless...

Unless you're looking to build a porn dataset and you're don't care about copyright. Porn is industry where exabytes of material are produced and published on internet almost every week.

Who will agency come to? To some OnlyFans creators?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#426

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

> Apple found a way to preserve that privacy

This is Orwellian doublespeak.

You don't preserver someone's privacy by snooping on their devices.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#427
post #321

Earlier quoted context omitted.

No, probably wouldnt even get to the desk of the police. End of the road would be NCMEC, to whom apple would refer hash matching images that pass human verification that are close enough to porn. If your 30 or so hash matching images matched their corresponding known CSAM then that goes on to the police and then they knock on your door.

> to whom apple would refer hash matching images that pass human verification I am under the impression that Apple's scheme allows them only to verify the output of the matching algorithm (the "safety vouchers"), and not the image content itself. So in the hypothetical situation described in the thread, it won't be possible for Apple to detect the false positive, and they could pass on the report to NCMEC. I fear tha…

Happy to provide citation of how the apple scheme works [1].

You should also point out that the NCMEC themselves are not law enforcment.

[1] https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#428

Am I the only one who finds no issue with this? Personally I’d prefer this than no encryption and scanning in the cloud, which is already possible. All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Can someone illustrate something wrong with this that’s not already possible today. Fundamentally unless you audited the client and the server yourself either (client or…

> All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Not only has it been possible for a decade, it’s been happening for a decade. Every major social media company already scans for and reports child pornography to the feds. Facebook submits millions of reports per year.

I really don’t understand how you can, with sound mind, compare a public facing ‘social media’ with my very personal and very private phone photos. These are two completely different things.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#429
post #221

Earlier quoted context omitted.

There’s no difference - all cloud services that aren’t encrypting your data is subject to the same thing. Dropbox could do the same thing tomorrow. If we’re talking about hypotheticals any vendor that handles your unencrypted files can do this now.

You’re not understanding. Dropbox already does scan your files and I’m comparing Apples actions explicitly to that fact. I’m pointing out that people don’t care about that because you’re literally, voluntarily, giving Dropbox your files. Here, Apple is controlling your phone to tattle on you at an OS level (yes, I know, Apple says you need to turn on iCloud Photos for this to run but the precedent is the problem).

> Dropbox already does scan your files

> people don’t care about that because you’re literally, voluntarily, giving Dropbox your files.

Correct and I agree. I don’t upload my most personal photos to Dropbox for this very specific reason. In fact I stopped using Dropbox when Condi Rice joined the board because she lacks good sense and doesn’t respect civil rights. See ‘The Patriot Act’ and ‘the Invasion of Afghanistan’. It was easy to stop using Dropbox because the alternatives were vast. Apple has me very purposely locked in to this scheme to where the alternatives are a huge transition and compromise on privacy no matter where I turn.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#430
post #261

Earlier quoted context omitted.

It is indeed meaningfully different: your sensitive data never leaves your device in order to be scanned. There can't be a crack in Apple servers that would expose files of millions of users uploaded for scanning. Eventually it could lead to Apple platform not having any CSAM content, or any known legally objectionable content, because any sane perpetrator would migrate to other platforms, and less sane, caught. This…

> your sensitive data never leaves your device in order to be scanned. There can't be a crack in Apple servers that would expose files of millions of users uploaded for scanning. And yet photos that get scanned are still uploaded to iCloud Photos, so they do end up on Apple's servers.

You can disable iCloud backup.

Doing so right while activating a new iDevice is the way to prevent its private keys from ending up in iCloud, and so preventing Apple, or law enforcement, or some malicious hackers from cracking into your device.

Post reply on HN