Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

71–80 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#71
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

> criminals are using E2EE communication systems to share sexual abuse material

Blah blah blah, the same old argument given by the "think of the children" people.

There are many ways to counter that old chestnut, but really, we only need to remember the most basic fundamental facts:

1) Encryption is mathematics 2) Criminals are criminals

Can you ban mathematics ? No. Can you stop criminals being criminals ? No.

So, let's imagine you are able to successfully backdoor E2EE globally, on all devices and all platforms.

Sure, the "think of the children" people will rejoice and start singing "Hallelujah". And the governments will rub their hands with glee with all the new data they have access to.

But the criminals ? Do you honestly think they'll think "oh no, game over" ?

No of course not. They'll pay some cryptographer in need of some money to develop a new E2EE tool and carry on. Business as usual.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#72
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

I don't like how these sentiments are written as if (C)SAM sharing is only type of crimes to ever be committed, which is devastating and PTSD inducing and life crippling, but say, not a murder. It could be one, or it could be major financial crimes, terrorism conspiracy, et cetera.

Yet, the only justification around for mass surveillance for camera pictures, the important societal matter to rest literally on "the other side of the coin", is "some minority of people could be sharing naked photos of young members of society for highly unethical acts of viewing".

wtf.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#73
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

How are individuals re-victimized with every share? That makes no sense. Your LinkedIn profile photo could be on a billboard in rural China, what would it be to you?

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#74

Earlier quoted context omitted.

Mass surveillance is never an appropriate solution, let's start with that. I don't belive tech has an over weighted responsibility to solve society's problems, and in fact it's generally better if we don't try and pretend more tech is the answer. Advocating for more money and more prioritization for this area of law enforcement is still the way to go if it's a priority area. Policing seems to be drifting towards "mal…

When tech creates problems should tech tried to solve it or should tech be limited? We deceive ourselves honestly by pretending like we have not created new realities which are problematic at scale. We have. They are plentiful. And if people aren’t willing that we walk back tech to reduce the problems and people aren’t willing to accept technical solutions which are invasive then what are we to do? Are we just to acc…

“Tech”? What do you mean by “tech?” Do you expect Apple to remove the camera, storage, and networking capabilities of all their devices? That’s the “tech” that enables this.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#75
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

> Is is bad for the individuals who are re-victimised on every share.

Absolutely.

> It is also bad for the fabric of society at large, in the sense that if we don't clearly take a stand against abhorrent behaviour then we are in some sense condoning it.

Much less clear. There's always been the argument: does it provide an outlet with no _new_ (emphasis on "new" so people don't skim that word) victims, or does it encourage people to act out their desires for real?

I don't have any answer to this question; but the answer matters. I do have a guess, which is "both at the same time in different people", because humans don't have one-size-fits-all responses.

Even beyond photographs, this was already a question with drawings; now we also have AI, creating new problems with both deepfakes of real people and ex-nihilo (victimless?) images.

> Does the tech industry have any alternate solutions that could functionally mitigate this abuse?

Yes.

We can build it into the display devices, or use a variation of Van Eck phreaking to the same effect.

We can modify WiFi to act as wall-penetrating radar with the capacity to infer pose, heart rate, and breathing of multiple people nearby even if they're next door, so that if they act out their desires beyond the screen, they'll be caught immediately.

We can put CCTV cameras everywhere, watch remotely what's on the screens, and also through a combination of eye tracking and (infrared or just noticing a change in geometry) who is aroused while looking at a forbidden subject and require such people to be on suppressants.

Note however that I have not said which acts or images: this is because the options are symmetrical under replacement for every other act and image, including (depending on the option) non-sexual ones.

There are places in the world where being gay has the death penalty. And if I remember my internet meme history right, whichever state Mr Hands was in, accidentally decriminalised his sex when the Federal courts decided states couldn't outlaw being gay and because that state had only one word in law for everything they deemed "unnatural".

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#76
post #24
post #10

Earlier quoted context omitted.

> So despite looking a bit fishy at first, this doesn't seem to come from a christofascist group. Why would you assume this in the first place?

The main impetus behind "child safety" advocacy nowadays seem to be by cells of extremist right-wing Christian / QAnon types who believe in conspiracy theories like Pizzagate and the "gay groomer" panic. It's a reasonable assumption to make about any such group mentioned in the media that doesn't have an established history at least prior to 2016.

It sounds like an entirely unreasonable assumption to me. Advocating for child safety is something that transcends political differences, and generally unifies people across the political spectrum.

I mean, there aren't many people who want paedophiles to be able to amass huge collections of child abuse imagery from other paedophiles online. And pretty much every parent wants their child to be kept safe from predators both online and offline.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#77
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

Mass surveillance is never an appropriate solution, let's start with that. I don't belive tech has an over weighted responsibility to solve society's problems, and in fact it's generally better if we don't try and pretend more tech is the answer. Advocating for more money and more prioritization for this area of law enforcement is still the way to go if it's a priority area. Policing seems to be drifting towards "mal…

Every other aspect of life has been impacted by the computer's ability to process lots of information at speed. To say "no, policing must not use these tools but everyone else can" seems - well, quixotic, maybe?

If illegal data (CP) is being transferred on the net, wiretapping that traffic and bringing hits to the attention of a human seems like a proportional response.

(Yes, I know, it's not going to be 100% effective, encryption etc, but neither is actual detective work.)

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#78

Earlier quoted context omitted.

It's an incredibly bad thing. It's also an incredibly poor excuse to justify backdooring phones. Cops need to investigate the same way they always have, look for clues, go undercover, infiltrate, find where this stuff is actually being made, etc. Scanning everyone's phones would make their jobs significantly easier, no doubt, but it simply isn't worth the cost to us as a society and there is simply no good counter-ar…

Let's take a step back here and bring in some facts. "Apple" wasn't scanning your phone, neither was there a "backdoor". If you would've had iCloud upload enabled (you'd be uploading all your photos to Apple's server, a place where they could scan ALL of your media anyway), the phone would've downloaded a set of hashes of KNOWN and HUMAN VERIFIED photos and videos of sexual abuse material. [1] After THREE matches of…

i thought they can't scan the media in icloud, since media is encrypted, no?

also: If it was someone sending you hashbombs of intentional false matches or an innocuous pic that matched because some mathematical anomaly, the actual human would notice this instantly and no action would've been taken. - if someone is doing this, imagine the scale- thousands of pics that should be human-evaluated, scaled to thousands of people, it'll be just plain ignored, meaning system loses it's purpose. also, you say that it'll be enabled only if icloud bck is enabled, but it's not guaranteed, this assumption can later change... and it doesn't make sense, for me your 2 statements contradict themselves:

- if apple can scan your photos in icloud AND for this feature to be enabled, you must enable icloud, why they should send hashes to you? they can scan the photos anyway in icloud, since all your photos are backed up there. Unless... they can't scan photos in icloud since these are encrypted, meaning scanning can be done only locally before photos are sent, meaning icloud enabling is not mandatory and it could work without it.

Either way the csam scanning is imo pointless, on one hand bc of privacy reasons(and we've seen that if state is able to use a backdoor, it'll use it when needed) and on the other hand, because of generative algorithms: photos can be manipulated to trigger csam even if human eye can see another thing (aka hashbomb) OR a sick/ill intentioned person can generate a legit csam like photo just by using target ppl's face(or description of their face), in this case I don't even know if they are breaking the law or not, since the image is totally generated but is looking totally illegal

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#79
post #73
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

How are individuals re-victimized with every share? That makes no sense. Your LinkedIn profile photo could be on a billboard in rural China, what would it be to you?

There are several cases of victims being harassed and haunted by photos and video of them as a child being sexually abused. This is one of the reasons for Masha's law.

https://www.nbcphiladelphia.com/news/local/child-porn-victim...

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#80
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

It is also bad for the fabric of society at large, in the sense that if we don't clearly take a stand against abhorrent behaviour then we are in some sense condoning it. Does the tech industry have any alternate solutions that could functionally mitigate this abuse?

I'd suggest there's a lot the not-tech industry could do to stop condoning abhorrent behavior that stops short of installing scanners on billions of computing devices. It's become a bit of a trope at this point, but it's bizarre to see a guy who is/was spokesman for a "minor attracted persons" (i.e. pedos) advocacy group getting published negatively reviewing the controversial new sex trafficking movie ... in Bloomberg:

https://www.bloomberg.com/opinion/articles/2023-07-15/qanon-...

For some background:

https://www.opindia.com/2021/08/meet-noah-berlatsky-prostasi...

His 501(c)(3) non-profit also advocates in favor of pedophilic dolls and has a "No Children Harmed certification seal" program for pedophilic dolls/etc:

https://prostasia.org/blog/dolls-prevent-child-sexual-abuse/

https://prostasia.org/no-children-harmed/

I'm not sure you can criminalize stuff like this, but it sets off my alarm bells when pedophile advocates are being published in mainstream news at the same time there's a moral panic around the need to scan everyone's hard drives. Is society actually trying to solve this problem, or is this more like renewing the Patriot Act to record every American's phone calls at the same time we're allied with al Qaeda offshoots in Syria? Interesting how terrorism has been the primary other argument for banning/backdooring all encryption.

----

As an aside I couldn't find ~anything about this group "Heat Initiative" Apple is responding to? Other than a TEDx talk by the founder a couple years ago which again seems very focused on "encrypted platforms" as the primary problem that needs solving: https://www.ted.com/talks/sarah_gardner_searching_for_a_chil...

Post reply on HN