Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

41–50 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#41
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

I agree that those statements are correct, however my reading of the proposed Apple implementation was that it struck a good balance between maximising the ability to discover CSAM, minimising the threat vectors, minimising false positives, and minimising the possibility that a malicious government could force Apple to implement bulk surveillance. I'm all for privacy, but those who put it above all else are already l…

But "the ability to discover CSAM" is by itself an excuse for mass surveillance, not a bona fide goal. It is certainly possible, instead, to investigate, then find likely pedophiles, and then get a search warrant.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#42
post #16

I’m not sure I understand Apple’s logic here. Are iCloud Photos in their data centers not scanned? Isn’t everything by default for iCloud users sent there automatically to begin with? Doesn’t the same logic around slippery slope also apply to cloud scans? This is not to say they should scan locally, but my understanding of CSAM was that it would only be scanned on its way to the cloud anyways, so users who didn’t use…

In my opinion their goal was to get stuff to a state where they could encrypt everything on iCloud so that even they can't access it.

To counter the "think of the children" -argument governments use to justify surveillance, Apple tried scanning stuff on-device but the internet got a collective hissy-fit of intentionally misunderstanding the feature and it was quickly scrapped.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#43

I haven't forgot about the guy that sent photos of his child to his doctor and was investigated for child pornography. With these systems, in my humble opinion, you are just one innocent photo at the beach away from your life turned upside down.

And Google to this day refuse to admit the mistake. They've even gone as far as to insinuate that he still is a pedo despite a police investigation clearing him.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#44
It's nice that Apple have clarified this. I think that the original intent was a misstep and possibly an internal political situation that they had to deal with. I can see that a number of people would be on each side of the debate with advocacy throughout the org.

There is only one correct answer though and that is what they have clarified.

I would immediately leave the platform if they progressed with this.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#45
post #34
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

[flagged]

This morality may not be so unusual outside the tech "filter bubble". And wherever someone, like the OP, appears to be serious, my own personal morality says the absolute least they deserve is an equally serious answer.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#46
post #19

Earlier quoted context omitted.

e2ee for iCloud is currently opt-in, without prompts/nudging. Most power users don't even have it turned on or are aware of its existence. The setting is buried/hidden in submenus. Approximately no one uses it. Hopefully Apple will begin promoting users to migrate in future updates.

> The setting is buried/hidden in submenus. Mind sharing where it is on an iPhone and Mac? I have not been able to find it.

How to turn on Advanced Data Protection for iCloud

https://support.apple.com/en-gb/HT212520

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#47

Earlier quoted context omitted.

I agree that those statements are correct, however my reading of the proposed Apple implementation was that it struck a good balance between maximising the ability to discover CSAM, minimising the threat vectors, minimising false positives, and minimising the possibility that a malicious government could force Apple to implement bulk surveillance. I'm all for privacy, but those who put it above all else are already l…

But "the ability to discover CSAM" is by itself an excuse for mass surveillance, not a bona fide goal. It is certainly possible, instead, to investigate, then find likely pedophiles, and then get a search warrant.

Discovering users sharing CSAM is a goal isn't it? That's why governments around the world require cloud storage providers to scan for it – because waiting until the police receive a report of someone is not really feasible. A proactive approach is necessary and mandated in many countries.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#48
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

The extreme hysteria created by anything related to children often seems to be carte blanche to destroy privacy and implement backdoors in applications. Most child abuse comes from family members (which must be solved at the source), and the ultra extreme cases simply make awful law (doing away with E2EE or instituting mass surveillance to catch an incredibly small minority is absurd). Much like other 'tough on crime…

> which must be solved at the source

Governments are not good at this type of thing. It requires careful analysis, planning and actual decisions.

But slap on a regulation and require private companies to do the hard work for you - now we are talking!

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#49

Earlier quoted context omitted.

Mass surveillance is never an appropriate solution, let's start with that. I don't belive tech has an over weighted responsibility to solve society's problems, and in fact it's generally better if we don't try and pretend more tech is the answer. Advocating for more money and more prioritization for this area of law enforcement is still the way to go if it's a priority area. Policing seems to be drifting towards "mal…

Mass surveillance is bad, but I think there are versions of it that are far less bad than others. Apple's proposed solution would have theoretically only reported cases that were much more than likely to be already known instances of CSAM (i.e. not pictures of your kids), and if nothing else is reported, can we say that they were really surveilled? In some very strict sense, yes, but in terms of outcomes, no.

[flagged]

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#50

Earlier quoted context omitted.

[flagged]

I honestly hadn't considered that when I asked someone to use Signal or Threema instead of Facebook Messenger that they would think I was a pedophile or drug addict. Food for thought.

For what it's worth, I don't think using Signal or Threema is enough to make you an E2EE enthusiast, and wanting to speak without your speech later used against you is maybe the purest reason for E2EE. I meant more so the type of people who are into Tor or I2P.
Post reply on HN