Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

441–450 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#441
post #376

Earlier quoted context omitted.

> The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it). You can still do secure backups of your phone without using iCloud, but there isn’t a way for Apple to do end to end encryption of backups transparently like you can with real time communication. The only way end to end encryption of backups works is to require people keep a separate secure key(s) to avo…

Mega.io (from the same people as MegaUpload) has e2e file encryption with just usernames and passwords. There is no reason the password can't be the encryption key, with backup keys stored with a trusted third party (eg: your credit union or bank) without notation as to what these backup keys are tied to.

Standard passwords don’t provide enough entropy to provide secure encryption.

Trusting third parties with the password in unencrypted form is either systematic in which case the FBI now just needs collect data from 2 different organizations, or on a case by case basis in which case users will mess it up. Apple etc would have no way to verify users actually did something to back up their keys.

Apple’s current approach is to let users setup their own backups if they want security which allows for privacy just fine without providing a service with fundamental issues.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#442
post #372

Earlier quoted context omitted.

I do agree that it's more private, but I'm not sure it's better. I'm fine with the idea that if I upload stuff to someone else's server, they may take a look at it and maybe even punish me for what I've uploaded. Certainly if I encrypt the data before I upload it, they can't do that. But if I don't, then it's fine with me if they do. But my device should not be snitching on me. Yes, this device-side scanning is suppo…

> And since Apple certainly has the capability, they are likely one secret court order away from being required to scan even photos that aren't being uploaded, at least on some targeted subset of devices. Apple has the ability to upload literally any software to iPhones, so this argument applies equally to literally any conceivable bad thing that software could do on iPhones.

As well as any conceivable bad thing that Google could be ordered to add to Android.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#443

Earlier quoted context omitted.

Only the safety tokens are generated on your device, the action triggering scan happens in the cloud (just like all the others) and then it goes to human review, so if it's a hash collision it'd be caught there when they review the images, and they can only review the images that matched CSAM. I honestly can't find the uproar here. Google devices can face match photos offline... so they are applying a neural net (sca…

One is matching a face--yes, concerning, and I don't like it but IMO Google has had a much worse privacy reputation for quite some time--and the other is reporting private data to law enforcement and potentially abusive parents. It's quite a bit different. The difference can also be seen from a customer service perspective. One is a feature that lets you sort according to which friends you were with. The other is a f…

No it reports you to Apple, Apple report you to police. Exactly like google, they will also report you to the police, just they search your library unencrypted.

Literally no difference.

If you have illegal stuff only on your phone neither google or Apple will be notified or notify anyone else.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#444
post #435

Earlier quoted context omitted.

What’s the double speak? It’s quite clear they are trying to maintain e2e encryption while also achieving CSAM scanning. Google/Facebook/Microsoft do this by scanning everything unencrypted. Apple do it while maintaining encryption and are being punished for it. It’s insane.

iCloud is not end-to-end encrypted, and Apple has not announced plans to add that option. Apple has the technical ability to scan images on the server.

Yes, they have the ability, but they found a way NOT to do that. Instead maintaining user privacy. And the world hates them for it, and would prefer they just unencrypted and scanned everything… doesn’t make sense.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#445

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

HN's Point of View doesn't represent the PoV of the 1 billion active iPhone owners.

Most people won't have any idea about the meaning of "hashes" and "databases". Not everyone is trying to actively fight the system and shit on everything, most people just want to live happily with their friends and family, they won't care that Apple scans their devices.

> "Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust."

Oh god ! How wasn't all of this obvious to the top Apple management, but so obvious to epistasis! Damn, thanks man for correcting and leading Apple to the right track !

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#446

Earlier quoted context omitted.

Right now, it seems like there are two specific groups of people that are upset with Apple: Freedom evangelists (e.g. EFF) and tech futurists (e.g. HN). They're saying, essentially: "Apple does not have my permission to use my device to scan my iCloud uploads for CSAM" and "This is a slippery slope that could result in Apple enforcing thoughtcrimes" Neither of these viewpoints are particularly agreeable to the genera…

You forgot the most important point of the last 24 hours: "Apple has created a system for detecting CSAM on local devices which has already proven vulnerable to cheap perceptual hash collision attacks. It's now highly inconceivable Apple will be able to deploy this technology as-is without having their users exploited." In other words it's not just about privacy or thoughtcrimes anymore but should be viewed as actual…

I would also warn you against owning any device with a radio. Carriers control the radio towers and can be compelled by government agencies and selfish corporate interests to exploit remote execution vulnerabilities in radio chips in order to plant CSAM content onto devices.

How dramatic is too dramatic? When does something that hasn’t happened to you or anyone you know become a risk you’re willing to sacrifice personal convenience to mitigate? Will you be divesting yourself of all wireless radio hardware? If not, then why would you be worried about users being exploited through a more clumsy and less effective process such as CSAM signature hacking?

The piece of information you’re taking for granted, that few in free/tech/lib are confronting, is the assumption that this process can be exploited at scale to harm millions of people.

So far as I can tell, there will probably be zero or one false positive CSAM matches that pass the known algo, the unknown algo, the human blurred comparison, and the human unblurred comparison — all steps that must occur before law enforcement is invoked to collect digital evidence - in the first year.

How many false positives (to the nearest 10^X) do you think the system will generate in the first year that result in law enforcement actions? Your words suggest that everyone is vulnerable, and there are 10^9 users, so do you believe there will be 10^9 false positives in the first year? Do you think only a thousand people will be affected, so 10^3? How do you judge which is more likely correct?

It is unlikely that this system will generate 10^9 false positives, or else it never would have passed QA. I encourage you to consider how you would personally quantify this risk, and then also look up the quantified risks for killing someone while driving a car or getting struck by lightning while indoors. I don’t know what the actual reality will be, but I don’t think it's a very large X.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#447

Earlier quoted context omitted.

Doing so would create a positive that still doesn't pass Apple's human visual check against the (blurred) CSAM content associated with that checksum, and if it somehow did, it would still then also have to occur at qty.30 or more, and they'd have to pass a human visual check against the (unblurred) CSAM content by one of the agencies in possession of it. It's not possible to spoof that final test unless you possess r…

At the point where it is submitted for a human visual check, your privacy has already been violated.

My privacy is violated every time I leave my home. Anyone can take a photo of me and look up the FBI Most Wanted and see if I’m there. If they think someone is me and they’re wrong, they can still summon law enforcement, and I’ll still be mistreated for their poor judgement.

Is this just as unacceptable as the CSAM scanning? Should all public photography be banned, in order to reduce the risk of false positive identifications of innocent people as criminals to zero? Or is that an acceptable degree of privacy impingement for the good of society?

Is Apple’s implementation an acceptable trade of impingement and risk, for good for society? We do live in a society, and so zero impingement upon privacies is never going to be acceptable (sorry, free/tech/libs). But instead of discussing whether Apple’s approach violates privacy minimally or not in order to get the job done, these discussions here just keep circling the drain of “putting my privacy at risk by any degree is never acceptable”, when that drain is cemented shut by the existence of society and will never lead to a valid outcome.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#448

Earlier quoted context omitted.

> All of the slippery slope arguments have already been possible for nearly a decade now with the cloud. Not only has it been possible for a decade, it’s been happening for a decade. Every major social media company already scans for and reports child pornography to the feds. Facebook submits millions of reports per year.

I really don’t understand how you can, with sound mind, compare a public facing ‘social media’ with my very personal and very private phone photos. These are two completely different things.

They are not scanning photos stored on your phone, their are scanning photos stored on iCloud

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#449

Earlier quoted context omitted.

Apple's reviewers are comparing blurred originals to blurred matches. It needs to look like the blurred original associated with the checksum that matched. It is irrelevant whether the blurred match looks pornographic or not.

This has already been demonstrated. https://twitter.com/SarahJamieLewis/status/14280837442802565...

At which point the image will be handed to the relevant CSAM group unblurred, who will do a visual comparison and find out immediately that it’s not a match, and then reject it without invoking law enforcement.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#450
post #47

Earlier quoted context omitted.

They are very likely aware of backlash but since this is a easily defendable hill with a very slippery slope down the way, it is of their interest to push for it IMHO.

Apple has declared in interviews that the slope shall not be slipped, but you're indicating that they chose this specifically because they can slip that slope. How did you determine that their intentions contradict their words? Please share the framework for your belief, so that we're able to understand how you arrived at that belief and to evaluate your evidence with an open mind. (Or, if your claim is unsupported c…

Words in interviews mean little to me. If it's impossible to hold a cooperation accountable when the verbal promise is broken, that promise, not word-by-word but in its spirit, is void from the beginning.

This is just my biased view but there _could_ be countless ways to slip the slope without violating the current framing. For example:

Q: What happens when other governments ask Apple to use this for other purposes.

A: We will inform them that we did not build the thing they’re thinking of.[1]

Note that the question could be interpreted as "use this exact implementation" (rather than use the algorithm in general), and the answer does not rule out the possibility of "but we can build the thing for them then" (rather than "we don't have it and we will never have it"). The reader is free to interprete the conversation as they see it.

[1] https://daringfireball.net/2021/08/apple_child_safety_initia... citing [2]

[2] https://www.nytimes.com/2021/08/05/technology/apple-iphones-...

Post reply on HN