Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

451–460 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#451

Earlier quoted context omitted.

It's really interesting to see the mental gymnastics people are willing to go through to defend their favorite trillion dollar corporations. > other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of privacy. > Apple found a way to preserve that privacy ... So scanning for CSAM in a third-party cloud is "total invasion of privacy", while scanning your…

They are scanning files that are being uploaded. So, yes.

As I mentioned, it is (by definition) impossible for the cloud to have access to something that does not exist in the cloud - only the content that is explicitly uploaded/shared by the user can be scanned.

While local, on-device content access has no such guarantees - it's a question of policy rather than technical infeasibility.

And policies change.

> They are scanning files that are being uploaded. So, yes.

Even considering the situation as it is today, the cloud providers (as well as Apple) are scanning just the files that are being uploaded. So I'm still not sure how one is "total invasion of privacy" and the other "preserving privacy".

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#452

Earlier quoted context omitted.

At the point where it is submitted for a human visual check, your privacy has already been violated.

My privacy is violated every time I leave my home. Anyone can take a photo of me and look up the FBI Most Wanted and see if I’m there. If they think someone is me and they’re wrong, they can still summon law enforcement, and I’ll still be mistreated for their poor judgement. Is this just as unacceptable as the CSAM scanning? Should all public photography be banned, in order to reduce the risk of false positive identi…

By leaving your home and going out in public, you are implicitly consenting to being observed. So, no, that's not a violation of your privacy.

Apple's implementation is more like a stranger sneaking into your house if they suspect you're up to something bad. That would be equally unacceptable - we have warrants for a reason.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#453

Earlier quoted context omitted.

Microsoft and Google already scan all files uploaded to them regardless of your preferences.

No they don't, they scan them on the servers. If you have a source that says otherwise I'd love to see. I'm 99.99% sure you won't find any.

If they are "uploaded to them", they are on their servers. They just do it there instead of before they are uploaded.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#454

Earlier quoted context omitted.

They are scanning files that are being uploaded. So, yes.

As I mentioned, it is (by definition) impossible for the cloud to have access to something that does not exist in the cloud - only the content that is explicitly uploaded/shared by the user can be scanned. While local, on-device content access has no such guarantees - it's a question of policy rather than technical infeasibility . And policies change. > They are scanning files that are being uploaded. So, yes. Even c…

It has always been technically feasible for them to have software on the phone that scans everything on the phone. I don't see how this changes anything. Apple is trying to avoid scanning in the cloud so that the data can be E2EE and not subject to being stolen by someone that gets access to their servers somehow.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#455

Earlier quoted context omitted.

> And since Apple certainly has the capability, they are likely one secret court order away from being required to scan even photos that aren't being uploaded, at least on some targeted subset of devices. Apple has the ability to upload literally any software to iPhones, so this argument applies equally to literally any conceivable bad thing that software could do on iPhones.

As well as any conceivable bad thing that Google could be ordered to add to Android.

Or Google with Chrome (way more reach than Android), or Microsoft with Windows, etc. This is why I reject slippery slope arguments for software updates to auto-updating platforms. They already have the ability to ship literally any conceivable software to millions of people, so the "slippery slope" already exists trivially for the evilest software you can imagine.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#456

Earlier quoted context omitted.

As I mentioned, it is (by definition) impossible for the cloud to have access to something that does not exist in the cloud - only the content that is explicitly uploaded/shared by the user can be scanned. While local, on-device content access has no such guarantees - it's a question of policy rather than technical infeasibility . And policies change. > They are scanning files that are being uploaded. So, yes. Even c…

It has always been technically feasible for them to have software on the phone that scans everything on the phone. I don't see how this changes anything. Apple is trying to avoid scanning in the cloud so that the data can be E2EE and not subject to being stolen by someone that gets access to their servers somehow.

> It has always been technically feasible for them to have software on the phone that scans everything on the phone.

No, the OS can limit access to local content. E.g. Mac has https://support.apple.com/guide/mac-help/control-access-to-f..., and ios has its own permissions system.

It also requires installing third-party software on the device. While if Apple's policy regarding local content changes in the future, there is no way to avoid the OS itself (other than jailbreaking I suppose).

> Apple is trying to avoid scanning in the cloud so that the data can be E2EE

Citation needed.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#457
post #332

Earlier quoted context omitted.

How exactly do you imagine a bug in this will land you in jail?

Ever heard of planted evidence?

You haven’t explained how evidence could be planted. That is what you are being asked.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#458

Earlier quoted context omitted.

I really don’t understand how you can, with sound mind, compare a public facing ‘social media’ with my very personal and very private phone photos. These are two completely different things.

They are not scanning photos stored on your phone, their are scanning photos stored on iCloud

My iCloud is not accessible to all my friends, family, work associates, and the public. Facebook/Twitter/insta is. (Depending on your privacy settings)

Scanning publicly accessible material makes a lot of sense and is within the boundaries of section 230, tech companies are responsible for policing removing illegal or threatening material. For private or encrypted information, section 230 does not apply.

The purposes these services were designed for matters. iCloud is meant to be private, facebook would prefer everything you post is public as it’s built in to benefit their business model. Facebook should scan, iCloud shouldn’t. You are purposely obfuscating that detail.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#459

Earlier quoted context omitted.

You forgot the most important point of the last 24 hours: "Apple has created a system for detecting CSAM on local devices which has already proven vulnerable to cheap perceptual hash collision attacks. It's now highly inconceivable Apple will be able to deploy this technology as-is without having their users exploited." In other words it's not just about privacy or thoughtcrimes anymore but should be viewed as actual…

I would also warn you against owning any device with a radio. Carriers control the radio towers and can be compelled by government agencies and selfish corporate interests to exploit remote execution vulnerabilities in radio chips in order to plant CSAM content onto devices. How dramatic is too dramatic? When does something that hasn’t happened to you or anyone you know become a risk you’re willing to sacrifice perso…

Thank you for your comments. And I think you are probably correct about the true risk/X entailed here. As well as the risk of simply using anything with a radio - I can't think of a single device I own that hasn't had a radio attack of some sort published (including all Apple devices, of course).

If I'm honest what makes me feel bad about this is probably just that- a feeling based on what I consider to be an algorithm designed around the presumption of guilt. It's much the same way I feel about taking my shoes off in line at airport security. It's an act which I've largely come to ignore but which still produces that vague feeling of discomfort that somehow feels like the opposite of security.

That this is occurring on my Apple devices - my favorite devices - is also just depressing.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#460

Earlier quoted context omitted.

This is not true and a harmful generalization. There are dumb people of every type. There are probably smart people you respect that engage in CSAM and are minor-attracted. This kind of privacy invasion will only net a tiny section of that population, as most know that lack of caution is life or death.

> This is not true and a harmful generalization. There are dumb people of every type. That's purely specious, and you say it as if I ever asserted there aren't "dumb people of every type.", which I didn't say. Yes , there are dumb people of every "type". Are there as many intelligent people as those of low intelligence who struggle to think abstractly, struggle to read and write, have poor motor control, rely heavily…

I think your response is emotionally-charged and mixes feelings with data and anecdotes, which is unhelpful in a complex discussion of a sensitive topic, so I hesitate to engage further, but…

I’ve reviewed much of the existing data on minor-attracted persons (which is scant). The problem is that the samples are heavily biased towards including individuals who are caught or self-admit for care, which is not a very good representative sample. As a few of the studies and articles you posted mention, there was little study done until very recently. You also make the leap without supporting data that this system would catch those most likely to offend. Generally I would say the data is insufficient to conclude in any direction other than dumber people get caught doing crimes at a higher rate than smarter people.

Lastly, I have some serious doubts about your expertise in mental health and the study thereof from your use of “mentally retarded” and “retardedness”. You should know for future discussions that the clinical terminology has shifted to “intellectually disability”.

Post reply on HN