Live data from Hacker News

Is macOS Look Up Destined for CSAM?

eclecticlight.co

121–130 of 143 posts

Re: Is macOS Look Up Destined for CSAM?

#121

Earlier quoted context omitted.

This isn't combatting abuse because producing CSAM != consuming CSAM. It's far better that 10 people beat off to children than have one innocent person come under suspicion.

I disagree. Suspicion is not the same as prosecuted, and every time someone "beats off" to an image of child sexual abuse, that child is re-victimised; every time. You'd rather 10 children be victimised than 1 person falls under suspicion? Ok...

> You'd rather 10 children be [re-]victimised than 1 person falls under suspicion? Ok...

Well yeah, mostly because I don't understand what you mean be "revictimization", but I can easily imagine what it's like to have such suspicions leaked to the angry mob.

Re: Is macOS Look Up Destined for CSAM?

#122

Earlier quoted context omitted.

No, I am not. I haven't gotten into an accident, nor have I witnessed one that resulted in a fatality or any major injury. The distribution of skills amongst drivers isn't geographically even , nor is it static.

What makes you think it’s not geographically even (at least in a country like the US)?

Because I haven't seen it proven in any domain, it sounds too naive to believe that people have equal abilities and skills by geography (or any other random metric). Population centers will have greater access to training, also in this example more cars on the road will co-relate to more opportunity to practice driving skills, but also more opportunity for accidents, etc, etc. In any case, if you look at outcomes in terms of car crashes/fatalities, the data also shows what you would expect -

https://worldpopulationreview.com/state-rankings/fatal-car-a...

Re: Is macOS Look Up Destined for CSAM?

#123

Earlier quoted context omitted.

>There is lots of information about the safety of human driven cars, it is not a high bar to improve upon, and can be verified. That doesn't make sense. The 'average' driver gets into millions of accidents. I don't want a slight above average driver driving my family around, and I don't want slightly above average drivers around me - especially those who I can't communicate with - by honking, by shouting to get their…

What measure are you using for "slightly above average" that also equals "unproven dangerous"? If the above average technology is dangerous, surely the average driver is even more dangerous. Otherwise it's not really above average, no? I.e., how can you make fewer errors and be a measurably better driver but still be worse than the thing that you're measurably better than? Either you're making this argument in bad fa…

Where are the self-driving cars that respond to honking, respond to someone yelling the driver to watch out, where you can make eye contact and they wave you over so you feel safer while crossing, etc, etc?

Re: Is macOS Look Up Destined for CSAM?

#124
I am using Little Snitch since version 2. Practically all my connections form MacOS to the mothership are stopped by default. I turn off the filter only for updates. I avoid in general Apple software (Preview, Photos, etc.). Macs are used only for work. My personal information or browsing is done only on Linux with Open Snitch and minimalistic install. In the new information landscape blind trust can be harmful.

Re: Is macOS Look Up Destined for CSAM?

#125

Earlier quoted context omitted.

They almost certainly do. Every major provider does, and even some enterprises. The whole point of the CSAM stuff was that it would allow for end to end encryption while not turning Apple’s ecosystem into preferred tool of child pornographers. Apple poorly communicated the feature, then the EFF put out a deliberately misguided written hitpiece that conflated parental controls with CSAM, and started an online freak ou…

I think that's a pretty bad summary of the concerns that were raised. Sure they are scanning your files on icloud, but there is a 100% reliable way to prevent that: just don't upload them. In their proposal they would scan your files on device, which is fundamentally different. Initially they would not run the scanning when icloud upload was disabled but how long would that last for?

No. The proposal was to generate the perceptual hash on device at the time of uploading to iCloud. It would not be doing any scanning on-device. The comparison to the CSAM database would still happen on Apple's servers.

Re: Is macOS Look Up Destined for CSAM?

#126
post #101
post #18

Earlier quoted context omitted.

CSAM is, by definition, photography or videography of something that has already happened. Therefore, quite literally, doing absolutely nothing about CSAM itself would result in no harm to any child, as the harm has already occurred. Now you're probably going to then cry about incentivising or normalising CSAM - but that's a different argument. And if you then try to argue that the normalisation of CSAM would somehow…

> Therefore, quite literally, doing absolutely nothing about CSAM itself would result in no harm to any child, as the harm has already occurred. By this "moral" reasoning you're also fully supportive of revenge porn.

I don't think possession of revenge porn by third parties should be illegal. However, I do think a victim of revenge porn should have causes of action against the ex or whomever recorded and distributed it. In some countries, like Australia at least, recording and distributing revenge porn has resulted in claims in equity for breach of confidence - so something like that already works.

But prosecuting third parties for having it is asinine, IMO.

Re: Is macOS Look Up Destined for CSAM?

#127

Earlier quoted context omitted.

Self-driving cars are unproven tech. Just pointing to the harm that humans contribute towards doesn't mean much. Soldiers also accidentally kill innocent civilians - are you in favor of AI-drones and AI-soldiers??

Not the guy you are talking to, but I would 100% be in favour of AI-drones if it was shown they made fewer mistakes than human operators.

I’d be in favor of self-driving cars by the same criteria, but sadly a lot of people are ready to skip that step.

Let’s be clear, there is ZERO empirical evidence that self-driving car technologies available to humanity today are safer than human drivers. Zero.

There are lots of theoretical advantages like “computers don’t get sleepy or drunk,” which elide the many other ways that computers still dramatically underperform people (like recognizing objects).

Re: Is macOS Look Up Destined for CSAM?

#128
post #10

What's the right number of lives to destroy over false positives from an algorithm? Is it some number other than zero? Why or why not?

I'm more concerned with the fact that framing someone for real CSAM is nearly the perfect crime. Contract killers have to be up close and personal in meatspace and leave an actual homicide investigation in their wake. Someone half way around the world could be contracted to spearfish you, take over your phone/laptop then cause it to download actual CSAM. The first thing you'd know about it is when you were arrested,…

> It is a button that someone (without any morals and willing to take a certain degree of risk) can push to ruin your life remotely, leaving virtually no trace, and allowing virtually no defense

There are many such buttons. So many it’s horrifying.

Re: Is macOS Look Up Destined for CSAM?

#129
post #124

I am using Little Snitch since version 2. Practically all my connections form MacOS to the mothership are stopped by default. I turn off the filter only for updates. I avoid in general Apple software (Preview, Photos, etc.). Macs are used only for work. My personal information or browsing is done only on Linux with Open Snitch and minimalistic install. In the new information landscape blind trust can be harmful.

I couldn’t find a way to black hole CIDR blocks on Little Snitch which is necessary to completely silence macOS. However if you do this at the router you break stuff like iMessage on phones running on the wifi and so forth.

Re: Is macOS Look Up Destined for CSAM?

#130
post #125

Earlier quoted context omitted.

I think that's a pretty bad summary of the concerns that were raised. Sure they are scanning your files on icloud, but there is a 100% reliable way to prevent that: just don't upload them. In their proposal they would scan your files on device, which is fundamentally different. Initially they would not run the scanning when icloud upload was disabled but how long would that last for?

No. The proposal was to generate the perceptual hash on device at the time of uploading to iCloud. It would not be doing any scanning on-device. The comparison to the CSAM database would still happen on Apple's servers.

The device would download an encrypted database. It would compute a hash on the device. It would compute a value (“voucher”) from this hash and the database and upload that value to iCloud, which could decrypt it iff there were a sufficient number of matches. The voucher is independent of the plaintext file uploaded to iCloud: hence you could upload only the voucher and not the file and the system would still alert.

Phrases like “it would not be doing any scanning on-device” don’t have any precise meaning. Scanning is a series of operations including hashing and cryptographic calculations plus a voucher upload and decryption. All of the former operations are happening on the device, only the latter happens on the server. So in fact a significant fraction of the scanning is indeed happening on your device. And this two-computer design isn’t being used to preserve your privacy: it’s designed this way solely to prevent you (the device owner) from knowing whether your files match the database. Without that requirement, the system would be much simpler: it would download a hash database and simply send a notification to iCloud whenever (a sufficient number of) local files hash to values matching the database.

Post reply on HN