Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

431–440 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#431

Earlier quoted context omitted.

Exactly, and 100% Google and Microsoft have on device scanning as well. We are saying "Apple are bad for admitting it" what about the others that are not?

You have 0 proof of that other than conjecture. They are not scanning stuff and uploading it to government organizations to come and arrest you.

A literal feature of Google Photos is to find photos on your device.

Apple are not uploading anything to government organisations, in fact they are uploading less than google, by their own(and googles admission).

You have 0 proof that they are uploading to gov orgs… right?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#432
post #416

Earlier quoted context omitted.

But if you're a company like apple, it'd be bad business to wait until large government bans your service/device before you respond to it. Much better to read the tea leaves and get a head of it.

Again, their double-speak and redefining words don't help with the reception. They're deliberately misrepresenting what's happening, appearing surprised when people misunderstand, and bundling together legitimate criticism with misunderstandings. I can draw some parallels to how Google went out with FLoC. Honestly I can't tell where Hanlon's razor should cut here.

What’s the double speak? It’s quite clear they are trying to maintain e2e encryption while also achieving CSAM scanning. Google/Facebook/Microsoft do this by scanning everything unencrypted. Apple do it while maintaining encryption and are being punished for it. It’s insane.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#433

Earlier quoted context omitted.

I think the difference here is that it's ON YOUR DEVICE. I think there's a pretty clear understanding that if you upload stuff to a cloud provider they can do whatever they want with it. This is different. This is reaching into what has up until now mostly been considered a private place. Law enforcement often has to get warrants to search this kind of thing. This is the difference between putting CSAM on a sign in y…

Only the safety tokens are generated on your device, the action triggering scan happens in the cloud (just like all the others) and then it goes to human review, so if it's a hash collision it'd be caught there when they review the images, and they can only review the images that matched CSAM. I honestly can't find the uproar here. Google devices can face match photos offline... so they are applying a neural net (sca…

One is matching a face--yes, concerning, and I don't like it but IMO Google has had a much worse privacy reputation for quite some time--and the other is reporting private data to law enforcement and potentially abusive parents. It's quite a bit different.

The difference can also be seen from a customer service perspective. One is a feature that lets you sort according to which friends you were with. The other is a feature that puts you in jail. No thanks. Not gonna pay money for that.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#434
post #332

Earlier quoted context omitted.

This is the same company that saved the disk encryption password as the password hint. You really trust them to not screw this up when the stakes are that it could ruin your life and/or land you in jail? I'm simply not ok with that.

How exactly do you imagine a bug in this will land you in jail?

Ever heard of planted evidence?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#435
post #416

Earlier quoted context omitted.

Again, their double-speak and redefining words don't help with the reception. They're deliberately misrepresenting what's happening, appearing surprised when people misunderstand, and bundling together legitimate criticism with misunderstandings. I can draw some parallels to how Google went out with FLoC. Honestly I can't tell where Hanlon's razor should cut here.

What’s the double speak? It’s quite clear they are trying to maintain e2e encryption while also achieving CSAM scanning. Google/Facebook/Microsoft do this by scanning everything unencrypted. Apple do it while maintaining encryption and are being punished for it. It’s insane.

iCloud is not end-to-end encrypted, and Apple has not announced plans to add that option. Apple has the technical ability to scan images on the server.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#436
Honest question - as far as I could find out the files will be scanned on device but before upload to iCloud. Before they were scanned in the cloud after upload. That's the change as far as I understand it. But if it's scanned before upload then what is the difference? A few seconds? It would be scanned either way, before or after upload. Is that it?

What I'm basically getting at is: are the files scanned after the user has expressed the intention of uploading them? That's what I understood. Am I wrong? Are the files scanned the moment they appear on your device, regardless of you iCloud status (even if you have disabled iCloud somehow)?

Edit: typo

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#437
post #321

Earlier quoted context omitted.

> to whom apple would refer hash matching images that pass human verification I am under the impression that Apple's scheme allows them only to verify the output of the matching algorithm (the "safety vouchers"), and not the image content itself. So in the hypothetical situation described in the thread, it won't be possible for Apple to detect the false positive, and they could pass on the report to NCMEC. I fear tha…

Happy to provide citation of how the apple scheme works [1]. You should also point out that the NCMEC themselves are not law enforcment. [1] https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

Right, and what in there suggests to you that Apple can view an image after a sufficient number of images match? I see the opposite: "Apple can’t access metadata or visual derivatives for matched CSAM images until a threshold of matches is exceeded for an iCloud Photos account."

That suggests that Apple can't access the actual matched CSAM images at all.

> You should also point out that the NCMEC themselves are not law enforcment.

I don't think the distinction is relevant. The point is that they will get passed on for enforcement purposes, and at that point, innocent parties will find themselves raided and their devices seized without any human actually manually verifying that it is CSAM first.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#438

Earlier quoted context omitted.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

There is no way to scan people’s content while “respecting their privacy.” The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it).

In this case, the state does demand it. Running a major cloud photo storage and sharing platform without checking for this material isn't an option in the US.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#439
post #149

Earlier quoted context omitted.

Apple controls the hardware, software, and cloud service. It was always a pinky promise that they wouldn't look at your files. I don't know why we should doubt that pinky promise less today than we did a month ago.

Should they even be doing that though? It seems like a matter of time before it's possible to SWAT somebody by sending them a series of hash colliding image files given how not cryptographically secure the hash algorithm is. I think I'm not the only one who'd rather not have my devices call the cops on me in a country where the cops are already way too violent.

You could already just send them CSAM. That is a lot easier than finding a hash collision that also appears to be illegal content when downscaled and viewed by a human.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#440

Earlier quoted context omitted.

Exactly, and 100% Google and Microsoft have on device scanning as well. We are saying "Apple are bad for admitting it" what about the others that are not?

You have 0 proof of that other than conjecture. They are not scanning stuff and uploading it to government organizations to come and arrest you.

The point is that until devices and all their software/firmware become fully auditable, there's no way to be 100% safe, and we must resort to trust.

That wouldn't be a problem in an ideal world, but the one in which we live is far from even resembling one. Mining data is already a huge business, and governments everywhere would love tools to use to get advantage over people they don't like. There's huge motivation and demand for those tools at all levels, and at least governments have the resources to buy them and the power to force whoever implements them to stay silent. I'm not implying that spyware tools exist in any phone, PC, smart TV, car, etc. because we can't prove they don't; that's the argument used for UFOs, witches and unicorns, no thanks, but we better think like they do because technology, resources and demand for their adoption are real, and the rest is probability.

Post reply on HN