Live data from Hacker News

Apple’s device surveillance plan is a threat to user privacy – and press freedom

freedom.press

121–130 of 145 posts

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#121
post #83

Earlier quoted context omitted.

> It's not their role to judge the contents, only whether the match is correct or not. Which is what they would be doing. Some government gives Apple a purported CSAM hash database, which Apple only accepts because it is a CSAM database. An image gets a match. Apple looks at it and it is not CSAM. Therefore, unless the government lied to them about the database, it must be a false positive and gets rejected as an inc…

My point was, what if you have content in there that is CSAM in some places but isn't in others(for instance - drawings). If apple employees report it to authorities in a state where it isn't illegal, they just suspended your account and reported you to authorities without any reason. So like I said, then you get into this trap of - do apple employees start judging whether the match "should" count? What if a picture…

My point was, what if you have content in there that is CSAM in some places but isn't in others(for instance - drawings). If apple employees report it to authorities in a state where it isn't illegal, they just suspended your account and reported you to authorities without any reason.

The only CSAM Apple will flag has to come from multiple organizations in different jurisdictions; otherwise, those hashes are ignored.

And since no credible child welfare organization is going to have CSAM that matches stuff from the worst places, there's no simple or obvious way to get them to match.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#122

Earlier quoted context omitted.

My point was, what if you have content in there that is CSAM in some places but isn't in others(for instance - drawings). If apple employees report it to authorities in a state where it isn't illegal, they just suspended your account and reported you to authorities without any reason. So like I said, then you get into this trap of - do apple employees start judging whether the match "should" count? What if a picture…

My point was, what if you have content in there that is CSAM in some places but isn't in others(for instance - drawings). If apple employees report it to authorities in a state where it isn't illegal, they just suspended your account and reported you to authorities without any reason. The only CSAM Apple will flag has to come from multiple organizations in different jurisdictions; otherwise, those hashes are ignored.…

>>The only CSAM Apple will flag has to come from multiple organizations in different jurisdictions; otherwise, those hashes are ignored.

Have they actually said they would do that? I was under the impression that they just use the database of hashes provided by the American authority on prevention of child abuse.

>>And since no credible child welfare organization is going to have CSAM that matches stuff from the worst places

I'm not sure I understand what you mean, can you expand?

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#123

This technology will soon be out of Apple’s control. Higgins correctly highlights the immense pressure Apple will get from governments and other actors to bend the technology and use it for something else than csam. It will happen, people are probably already thinking how to apply such pressure. Sooner or later Apple will cave in and they will have only themselves to blame when freedom supports in Sudan or LGBTQ acti…

Ten years from now we will read a leaked document stating that US authorities requested FISA Courts warrants (or similar) and made Apple scan for things other than csam. It already happened. Court orders are easier than hacks once you iron out the legal opinions.

10 years seems a little too much for US gov's patience

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#124

There business model has always been a threat to user privacy and press freedom, many people were just okay with it cause Apple told them otherwise. Open source is the only model where you can verify though, and so Apple was about blind trust and never about privacy.

I agree, this is what's to be expected when people rely on proprietary and other people's computers. Stallman's essays, among others, depicted scenarios like this for ages. But people don't like to miss the latest shiny, the convenience of the smart phone tech, so, here we are. They also don't like a told-you-so.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#125

Earlier quoted context omitted.

My point was, what if you have content in there that is CSAM in some places but isn't in others(for instance - drawings). If apple employees report it to authorities in a state where it isn't illegal, they just suspended your account and reported you to authorities without any reason. The only CSAM Apple will flag has to come from multiple organizations in different jurisdictions; otherwise, those hashes are ignored.…

>>The only CSAM Apple will flag has to come from multiple organizations in different jurisdictions; otherwise, those hashes are ignored. Have they actually said they would do that? I was under the impression that they just use the database of hashes provided by the American authority on prevention of child abuse. >>And since no credible child welfare organization is going to have CSAM that matches stuff from the wors…

> Have they actually said they would do that?

In [1], "That includes a rule to only flag images found in multiple child safety databases with different government affiliations — theoretically stopping one country from adding non-CSAM content to the system."

[1] https://www.theverge.com/2021/8/13/22623859/apple-icloud-pho...

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#126

This technology will soon be out of Apple’s control. Higgins correctly highlights the immense pressure Apple will get from governments and other actors to bend the technology and use it for something else than csam. It will happen, people are probably already thinking how to apply such pressure. Sooner or later Apple will cave in and they will have only themselves to blame when freedom supports in Sudan or LGBTQ acti…

Western governments had enough room to select a different way. Instead we are captured by a destructive war on terror surveillance ambitions. Do you think those defense and security contractors will ever go away? That they won't summon dangers if they have nothing else to do?

Here governments could have opted for a contrast but they neglected these opportunities.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#127
post #28

Earlier quoted context omitted.

How a human looking at low res CSAM matching collision picture that looks "innocent" will be able to tell for sure it is a false positive? Can they know with certainty that it is a false positive and not a manipulated real image? It seems to me that they would have to report these anyway.

Is your argument "a human review step is fundamentally a rubber-stamp that won't reject a false-positive?" Because I don't personally think that's how it'd work out, but I'll acknowledge that I might just be an optimist. (I mean, assuming that you need ~30 matches to trigger the review phase of the process, I'd think it'd be weird to a reviewer looking for child porn if you got 30 pictures of apparently-random politi…

Police often rubber-stamp computer-generated evidence of infractions (facial-recognition that does not visually match is one very-applicable example), and content moderators are probably paid less.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#128

Earlier quoted context omitted.

Constantly flagging my account to Apple is an attack of its own. I don't need Apple to be complicit, just make a mistake by erring on the side of caution when reporting.

I don't see how there's a "side of caution" when it comes to images classified as "A1" of prepubescent minors ("A") engaged in sex acts ("1"). What does it take to have 30 or more images in your photo library that have been all been manipulated to be a perceptual hash match to 30 or more A1-classified images, while also being able to pass human review ("erring on the side of caution") with respect to them being maybe…

The content reviewer isn't going to see an image in enough detail to determine that it is obviously A1 material, so yes, the content reviewer will err on the side of caution.

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#129

Earlier quoted context omitted.

I don't see how there's a "side of caution" when it comes to images classified as "A1" of prepubescent minors ("A") engaged in sex acts ("1"). What does it take to have 30 or more images in your photo library that have been all been manipulated to be a perceptual hash match to 30 or more A1-classified images, while also being able to pass human review ("erring on the side of caution") with respect to them being maybe…

The content reviewer isn't going to see an image in enough detail to determine that it is obviously A1 material, so yes, the content reviewer will err on the side of caution.

You seem to be fairly certain about exactly how much detail is in the visual derivative contained within the safety token. Care to share your source?

Re: Apple’s device surveillance plan is a threat to user privacy – and press freedom

#130

Earlier quoted context omitted.

1) The DB must be updated on both the server and the client. Apple's solution requires the DBs to match, essentially. So you can't update the DB without everyone knowing it was changed. 2) Apple has trillions of dollars to lose by selling out to a shitty change like that. Do those things mean nothing bad can come of it? Hell no. But, right now we have FISA courts and silent warrants sucking in data without anyone kno…

> 2) Apple has trillions of dollars to lose by selling out to a shitty change like that. Apple has trillions to lose by building this system in the first place. All it takes is one court order to do non-CP scanning with the existing system .

It really doesn’t have much to lose. None of the non-tech people I have spoken to think of this as a bad thing.
Post reply on HN