Live data from Hacker News

EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

eff.org

101–110 of 215 posts

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#101
post #77

Earlier quoted context omitted.

They have to come from the intersection of two databases from two jurisdictions. So already that’s out as you suggest. Then you’d have to match _nearly exact photos_, which isn’t a vector for general photos of some random minority. Then you’d need 30 of such specific photos, a match with another secret hash, and then a human reviewer at Apple has to say yes it’s CP before anything else happens. I think there are plen…

Every step you've described is unfalsifyable: You just have to blindly trust that Apple is doing these things, and that e.g. authoritarian regemes haven't compromised Apple staff with access to the data. > They have to come from the intersection of two databases from two jurisdictions. My message directly answered that. A state actor can modify an apparent childporn image to match an arbitrarily hash and hand that im…

> A state actor can modify an apparent childporn image to match an arbitrarily hash and hand that image to other agencies who will dutifully include it in their database.

Even if a state actor constructs an image that is an NeuralHash collision for the material they wish to find, that only gets them through one of the three barriers Apple has erected between your device and the images being reported to a third party. They also need to cause 30 image matches in order to pass threshold secret sharing, and they need to pass human review of these 30 images.

Arguably investigation by NCMEC represents a fourth barrier, but I'll ignore that because it's beyond Apple's control.

> You just have to blindly trust that Apple

This has been true of all closed source operating systems since forever. Functionally, nothing has changed. And whatever you think of the decision Apple has made, you can't argue that they tried to do it in secret.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#102

Earlier quoted context omitted.

Why would you lie about something so easily disproven? "Instead of scanning images in the cloud, the system performs on-device matching..." https://www.apple.com/child-safety/

Lie? I don't take kindly to such words, because you're ascribing malicious intent where there is none. Please check your tone... HN comments are about assuming the best in everyone. This is only applying to photos uploaded to iCloud. Every single thing talks exactly about that, including the technical details: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni... The hash matching is occurring on device, bu…

> Lie? I don't take kindly to such words, because you're ascribing malicious intent where there is none.

Howdy partner, it seems my tone communicated the sentiment as intended. It is unreasonable to ascribe anything but malice in this case, because the rationale strains credulity. Do you know at what point Apple is determining your intent to sync photos? What processes, exactly, are they hooking into in order to trigger the local hash functionality? Is it the resource hogging Photos-Agent frequently complained about? Is this thresholding functionality restricted to cloud content, or is the local database mentioned involved? Does that local database only relate to images uploaded to the cloud, and how would the deletion of local and/or cloud content influence that?

These are all questions that are either unaddressed, provide no assurance beyond "trust us", or hint at logical conflicts between the stated purpose of local scanning and the actual implementation details. With all that in mind, granting Apple and its defenders the benefit of doubt is laughably foolish.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#103
post #77

Earlier quoted context omitted.

Every step you've described is unfalsifyable: You just have to blindly trust that Apple is doing these things, and that e.g. authoritarian regemes haven't compromised Apple staff with access to the data. > They have to come from the intersection of two databases from two jurisdictions. My message directly answered that. A state actor can modify an apparent childporn image to match an arbitrarily hash and hand that im…

> A state actor can modify an apparent childporn image to match an arbitrarily hash and hand that image to other agencies who will dutifully include it in their database. Even if a state actor constructs an image that is an NeuralHash collision for the material they wish to find, that only gets them through one of the three barriers Apple has erected between your device and the images being reported to a third party.…

The invocation of 30 images like it's a barrier confuses me. I created a bunch of preimages posted on github, I could easily create 30 or 3000 but at this point all I'd be doing is helping apple cover up their bad hash algorithm[1].

I pointed out above that the attacker could use legal pornography images selected to make it look like child porn. This isn't hard. Doing it 30 times is no particular challenge. I didn't use pornographic images in the examples I created out of good taste, not because it would be any harder.

[1] I've made a statement that I won't be posting any more preimages for now for that reason: https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX/issue...

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#104

Earlier quoted context omitted.

Why would you lie about something so easily disproven? "Instead of scanning images in the cloud, the system performs on-device matching..." https://www.apple.com/child-safety/

It is not a lie. The scanning is done on device, but photos are not scanned unless they are going to be uploaded to iCloud. Apple has explicitly stated this.

Oh, well if Apple says... I'm sure their statement somehow completely aligns with all the potentially conflicting interpretations one can draw from their PR, their stated objectives, and the implementation details observed, and it always will - forever.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#105

here is a quote from EFF complaint about Apple alerting parents to kids under 13 being sent porn: "The recipient’s parents will be informed of the content without the sender consenting to their involvement." Are parents really outraged by this? Are people sending porn upset about this? My own view is as a parent if you send porn to my kids, I shouldn't NEED your consent to be alerted to this. I paid for the device, s…

For ideological consistency, I can only hope the EFF has a lecture prepared about two party consent for kids who show their phones to their parents if they receive a dick pic.

I think they are coming at this from the view that because iMessage was one of the first actual E2E encrypted products, showing the pic to the parent (after picture has reached end user device and been decrypted and is ready to display) should require consent. Ie, the encryption has been "broken".

That said - I don't find it very compelling. Parent paid for device. Parent is responsible for child. Parent should be allowed to control device (including setting a kids account instead of adult which trigger this etc). So I want to preserve MY right to both the device and to take care of my child. EFF seems to be focusing oddly on the rights of someone who DIDN'T pay for device.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#106
post #93

Earlier quoted context omitted.

Apple have been pretty clear that a human will review things. That is (I hope) a feature of any system that leads to child porn charges. If not it should be - AI gets things wrong and can be tricked (as can humans but in different ways usually). But agreed, the technical bits may not be obvious (though apple released I thought a pretty darn complete paper on how it all works).

Sure - but who wants a human reviewing their private photos? I don’t. Unless you understand the technical bits you have know way of knowing how rarely this is likely to happen in practice.

Not me, but if they only review after a flag, that's best you can do I think? facebook works this way too. Users flag photos and someone looks and deals with them.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#107
post #98

Earlier quoted context omitted.

You are suggesting that another country could launder the request on behalf of the USA in order to circumvent the 4th Amendment. Okay then, let's play that out. Australia contacts Apple and demands they augment CSAM detection so that every iPhone in the USA is now scanning for image hashes supplied by Australia. Apple says no. End of hypothetical.

You haven't heard of how GCHQ would happily hand over intelligence they had on U.S. Citizens? I know for a fact there are efforts at creating fusion centers across national boundaries. The question you need to ask is not if but what will make you interesting enough to mobilize against. Thou shalt not build the effing Panopticon, nor it's predecessors. Is that so hard to not do.

I've no doubt that GCHQ would hand whatever they like to whomever they like. But why would Apple comply with a demand from the GCHQ to spy on US citizens?

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#108

Earlier quoted context omitted.

What did the EFF lie about? Missed that…

2/3rds of their original letter was spent describing a parental control over sensitive content detection in iMessage as an end to end encryption back door. At best, that is highly cynical. At worst, it is an intentional conflation of different features to raise false alarm.

It's not cynical at all. It's what EFF has been warning about since 2019 and before. (Disclosure: I worked at EFF during this period. We were extremely concerned about the potential role of client-side scanners and the concerted push being made at that time by the intelligence community to present this as a "solution" to end-to-end encryption's privacy features.) https://www.eff.org/deeplinks/2019/11/why-adding-client-side...

It's also the consensus position of a very large number of other digital rights groups and infosec experts. Do you believe they are also cynical and raising a false alarm?

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#109
post #103

Earlier quoted context omitted.

> A state actor can modify an apparent childporn image to match an arbitrarily hash and hand that image to other agencies who will dutifully include it in their database. Even if a state actor constructs an image that is an NeuralHash collision for the material they wish to find, that only gets them through one of the three barriers Apple has erected between your device and the images being reported to a third party.…

The invocation of 30 images like it's a barrier confuses me. I created a bunch of preimages posted on github, I could easily create 30 or 3000 but at this point all I'd be doing is helping apple cover up their bad hash algorithm[1]. I pointed out above that the attacker could use legal pornography images selected to make it look like child porn. This isn't hard. Doing it 30 times is no particular challenge. I didn't…

If someone is trying to frame a known individual, the 30 image threshold may not be a significant barrier, I'll grant you that. But if you're enlisting Apple's algorithm to perform a dragnet search of the citizenry (e.g. leaked state secrets) then this mechanism cannot be effective unless the material in question is comprised of at least 30 photographs.

Re: EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning

#110

Earlier quoted context omitted.

For ideological consistency, I can only hope the EFF has a lecture prepared about two party consent for kids who show their phones to their parents if they receive a dick pic.

I think they are coming at this from the view that because iMessage was one of the first actual E2E encrypted products, showing the pic to the parent (after picture has reached end user device and been decrypted and is ready to display) should require consent. Ie, the encryption has been "broken". That said - I don't find it very compelling. Parent paid for device. Parent is responsible for child. Parent should be al…

The picture is not sent to the parent. They are notified that the child viewed a sensitive photograph, after warning the child, and the parent can view the photograph on the child’s device.
Post reply on HN