Live data from Hacker News

Apple urged to drop plans to scan iMessages, images for sex abuse

aljazeera.com

81–90 of 129 posts

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#81

Im not sure if im missing something here, but from what I understand, what Apple is proposing is an enormous privacy boon that seems to be completely misunderstood. All cloud providers are required to, and do, make these scans. The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, excep…

There is no requirement to scan, only report when found.

There is NO end to end encryption being rolled out at the same time (so they can still decrypt and hand over your data in the cloud).

> This means they couldn't comply with a nation states demand to secretly decrypt your data, even if they were legally compelled too, unless they change how the cryptography at play here works.

Not only is this completely wrong (they can hand over your decrypted cloud data right now), it's wrong even going forwards with the assumption you made above about real E2EE (which we don't have...) - All they have to do is add a few hashes from that nation state to their catalog and your data is whisked away to apple for them to do with as they please (which right now is meaningless, since they currently have access to it anyways, but makes your point about E2EE a lot less compelling).

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#82
post #47

Im not sure if im missing something here, but from what I understand, what Apple is proposing is an enormous privacy boon that seems to be completely misunderstood. All cloud providers are required to, and do, make these scans. The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, excep…

The concern is that Apple is handing governments a new tool to go “give me a list of all users that have this photo”. It could track down dissidents based on this and combined with metadata is probably sufficient to pinpoint who took a particular picture. Think you shared that picture of police brutality anonymously? Think again.

Unless they change the system, no notification would happen without multiple matches.

Also, dissidents can just turn off iCloud sync and no scanning will happen.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#83
post #44

Earlier quoted context omitted.

iOS is closed source and builds are not reproducible by the public. You have zero control over what is running on the iPhone. It is also extremely challenging to go through each executable and firmware on the phone to probe for backdoors. Sophisticated backdoors won't be apparent even if you had the executable data dump for every iPhone system.

Right, I understand that. I guess my question was more of a general one on whether people think Apple in particular would cooperate with the government in that way? Obviously the San Bernardino shooter case comes to mind as an example of Apple not just folding to the government pressure.

Search "top secret ipod"

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#84

Earlier quoted context omitted.

You'd need 30 of them. And upload them iCloud. I guess the neural part is a bit of a blackbox, im not sure if theres a way for external parties to verify its legitimatcy. But again, any change to would go noticed.

You wouldn't need 30 of them or to upload them to iCloud. If a nation state can demand Apple uses their existing function to scan your phone for political images, then they can likewise demand that 1 hit would be enough, and that there's no requirement for it to be uploaded to iCloud before the scanning can start.

That’s bit how it works. They would need to have apple update iOS with the new hash, and then the photo uploaded to icloud.

If they change the system to just start scanning local photos globally there really is Nothing to stop them from pushing out an iOS update today that does the same thing.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#85
post #56

Earlier quoted context omitted.

No more frontend than running a basic subject recognition on a photo.

A bit like on-device machine learning features, like object detection in images and video, language analysis, and sound classification?

Yup. Apple made a recognition model around sexually explicit images and locally runs opted-in child accounts' images against it: https://developer.apple.com/documentation/vision/training_a_...

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#86
post #9

After seeing all these posts here and not hearing much about it outside of this space I’m starting to think that the cost benefit analysis that Apple did was that the profit from very likely convincing parents to spend a little more to get their children an iPhone as their first phone (and probably lock those children into their ecosystem) because of these features was greater than the amount of users who would switc…

I'm not sure we have an understanding of Apple's intentions. Given the massive backlash and the apparent maturity of their plans this must have been in the works for a while. They may have been under pressure from government actors to develop a program. Or they might see writing on the wall. Either way, I doubt they will ever share the total picture behind this move.

[deleted]

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#87

Earlier quoted context omitted.

No more frontend than running a basic subject recognition on a photo.

I don't think it reports those links back to big brother though. Keen difference.

but they're literally one if-statement away from doing so

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#88

Earlier quoted context omitted.

You'd need 30 of them. And upload them iCloud. I guess the neural part is a bit of a blackbox, im not sure if theres a way for external parties to verify its legitimatcy. But again, any change to would go noticed.

You wouldn't need 30 of them or to upload them to iCloud. If a nation state can demand Apple uses their existing function to scan your phone for political images, then they can likewise demand that 1 hit would be enough, and that there's no requirement for it to be uploaded to iCloud before the scanning can start.

A nation state would have to require Apple to change the algorithm on the device, requiring an OS level update.

Just by forcing Apple to add a bunch of image hashes they can't do anything, it'd still require multiple matches before Apple can see the images.

Oh and the OS sends fake encrypted "matches" at random to Apple's servers so that you can't use even that to fingerprint the user.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#89

Earlier quoted context omitted.

The more fear and confusion the EFF can spread, the more donations they get.

I agree, sadly. This prompted me to unsubscribe from them. In some ways it reminds me of the ACLU. Similar fixation on donations above all else, to the point of dark patterns. I still haven't managed to fully extricate myself from their pleas.

I’m in the same boat. Unfortunately, I don’t see myself continuing to donate to them, given the terrible job they’ve done on this topic. I trusted them to bring nuance and clarity —- really liked what they did in response to the cash bail discussion in California —- but this was too much of a miss for me.

I’m still a fan of the ACLU, even with their spotty record on gay rights, but it might just be a matter of time.

Re: Apple urged to drop plans to scan iMessages, images for sex abuse

#90

So, what parts of my phone are actually being scanned by this system? It seems like it's rummaging through any images that are touch iCloud, which would include: - iMessage - WhatsApp - Camera - Matrix (?) - Any other application that you give 'photo' permission to?

Photos in Photos.app will get scanned if you have iCloud enabled (required to download the CSAM hash database). Messages will be scanned for CSAM content if you are a child, then parents will get notified that they received a dickpick.

To be clear, the content being scanned in messages is not a hash check against a database. It’s a plain old nudity detection algorithm similar to what Facebook has.
Post reply on HN