Live data from Hacker News

Apple urged to drop plans to scan iMessages, images for sex abuse

aljazeera.com

51–60 of 129 posts

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#51
post #10

I want to ignore most of this article to complain about an inaccuracy that keeps coming up. > More broadly, they said the change will break end-to-end encryption for iMessage, which Apple has staunchly defended in other contexts. But... it wouldn't. The iMessage feature doesn't expose the contents of your message to anyone else under any circumstance. If you're a child under 13 and your parents have opted in to this…

Let's also not pretend that some of this confusion done is 100% willfully by some of the news organizations reporting on this because it benefits them to conflate the two. We even see it a little from places like EFF who appear to believe their ends justify the means.

There are plenty of comments on HN that claim there are no details of what has been proposed while simultaneously claiming to have read the white paper.

This is rapidly becoming a topic not worth reading more about due to the misinformation and shilling from all sides.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#52
post #9

After seeing all these posts here and not hearing much about it outside of this space I’m starting to think that the cost benefit analysis that Apple did was that the profit from very likely convincing parents to spend a little more to get their children an iPhone as their first phone (and probably lock those children into their ecosystem) because of these features was greater than the amount of users who would switc…

> convincing parents to spend a little more to get their children an iPhone as their first phone

What do you mean here: I don't think makes things any safer for child _users_ of iPhones, does it? It's scanning for images of child sexual abuse.

(To anyone inclined to respond without reading the context, I'm not suggesting that there's no privacy concern if you're not sharing CP. I'm addressing OP's hypothetical that some parents will see owning an iPhone as safer for their child)

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#53
post #33
post #26

Earlier quoted context omitted.

I’m not interested in Apple’s newspeak definition of “E2EE” (where they are between the ends) or “Privacy” (terms and restrictions may apply). I want the real thing.

In this case, they wouldn't be "between" the ends, no? They'd be _at_ the ends, just as sending a message on Signal doesn't prevent someone from stealing your phone and reading your messages. I'm not in agreement with this being ok, but if it truly is on device, it still technically can be E2EE

> but if it truly is on device, it still technically can be E2EE

What do you think this software does when it finds a matching hash entry? Toss a notification to ask you nicely to pop round your nearest FBI office?

What meaning does 'end-to-end' have anymore if this applies? If Apple wrote software on-device to forward a copy of all messages prior to encryption to iCloud for 'backup', would it still be end-to-end? What if they sent it to an AdTech firm to index for interesting terms that match products you should be pitched? The software in this case is still Apple's, running on-device.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#54
post #15

Earlier quoted context omitted.

How is it not still E2EE?

If a copy of your messages (even if it is only low resolution jpgs) get auto forwarded to Apple/FBI under certain circumstances it is not securely E2E encrypted

It’s not forwarded to Apple/FBI though, under any circumstances.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#55

So, what parts of my phone are actually being scanned by this system? It seems like it's rummaging through any images that are touch iCloud, which would include: - iMessage - WhatsApp - Camera - Matrix (?) - Any other application that you give 'photo' permission to?

There are two different CSAM related features. One scans photos before they get uploaded to iCloud, other looks for indications of nudity and only works on minors' phones if their parents enabled this detection.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#56

Earlier quoted context omitted.

I don't think so, it doesn't really need to "analyze" your messages to do preview urls, show videos... Those are more like frontend stuff IMO

No more frontend than running a basic subject recognition on a photo.

A bit like on-device machine learning features, like object detection in images and video, language analysis, and sound classification?

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#57
post #10

I want to ignore most of this article to complain about an inaccuracy that keeps coming up. > More broadly, they said the change will break end-to-end encryption for iMessage, which Apple has staunchly defended in other contexts. But... it wouldn't. The iMessage feature doesn't expose the contents of your message to anyone else under any circumstance. If you're a child under 13 and your parents have opted in to this…

Let's also not pretend that some of this confusion done is 100% willfully by some of the news organizations reporting on this because it benefits them to conflate the two. We even see it a little from places like EFF who appear to believe their ends justify the means.

The more fear and confusion the EFF can spread, the more donations they get.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#58

Earlier quoted context omitted.

Honestly, this is deeply concerning. Apple shouldn't be in a position to be able to police what photos we take. If I'm a teen and I sext with a partner, does that mean that in the near future, our messages/photos will be flagged and reviewed for "child porn" and forwarded to police enforcement? That's horrifying and incredibly unfair to young people exploring their sexuality in a completely consensual and normal way.…

> If I'm a teen and I sext with a partner, does that mean that in the near future, our messages/photos will be flagged and reviewed for "child porn" and forwarded to police enforcement? No. The system looks for files that are similar to known illegal content. It is not a general purpose underage nude photograph detector.

> does that mean that in the near future

I think the parent comment is in reference not to the current system, but to potential future functionality, enabled by opening the Pandora's Box of client-side scanning.

Though I agree that underage nudity detection in particular is a little fanciful

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#59
post #47

Im not sure if im missing something here, but from what I understand, what Apple is proposing is an enormous privacy boon that seems to be completely misunderstood. All cloud providers are required to, and do, make these scans. The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, excep…

The concern is that Apple is handing governments a new tool to go “give me a list of all users that have this photo”. It could track down dissidents based on this and combined with metadata is probably sufficient to pinpoint who took a particular picture. Think you shared that picture of police brutality anonymously? Think again.

Apple can already decrypt your iCloud photos, same with google etc. I don’t get this argument as they can already do that.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#60

Pretty clear cut for me: iMessage either offers robust end-to-end encryption , or it doesn’t. (Intentional backdoors place it in the latter ofcourse). I want true end to end enc.

> I want true end to end enc. People who say things like this rarely also want the hassle that comes with it. Key exchanges, re-keying: all a big PITA. But iMessage (and WhatsApp) do key exchanges facilitated by a trusted broker. If you didn't trust the broker, you would have to do more work when making an initial exchange with a peer and more work if they lost their phone/keys. iMessage has always been a compromise…

Key exchange would be easy in real life, just bump phones when you meet someone. It's only difficult on IRC.
Post reply on HN