Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

81–90 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#81
post #65

Earlier quoted context omitted.

It's an incredibly bad thing. It's also an incredibly poor excuse to justify backdooring phones. Cops need to investigate the same way they always have, look for clues, go undercover, infiltrate, find where this stuff is actually being made, etc. Scanning everyone's phones would make their jobs significantly easier, no doubt, but it simply isn't worth the cost to us as a society and there is simply no good counter-ar…

If CSAM was still done the way it "always has been", then "cops" relying on the methods they always had would be a valid answer. But since tech has enabled the distribution of CSAM at unprecedented scales, I think the requests by law enforcement to also make their job a bit easier have some merit...

I don't.

They can find those materials the same way abusers work their way into communities to have access to them in the first place.

The increased scale only means they need more people working on it.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#82
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

[deleted]

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#83
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

> criminals are using E2EE communication systems to share sexual abuse material Blah blah blah, the same old argument given by the "think of the children" people. There are many ways to counter that old chestnut, but really, we only need to remember the most basic fundamental facts: 1) Encryption is mathematics 2) Criminals are criminals Can you ban mathematics ? No. Can you stop criminals being criminals ? No. So, l…

> But the criminals ? Do you honestly think they'll think "oh no, game over" ?

> No of course not. They'll pay some cryptographer in need of some money to develop a new E2EE tool and carry on. Business as usual.

I used to think this, I changed my mind: just as it's difficult to do security correctly even when it's a legal requirement, only the most competent criminal organisations will do this correctly.

Unfortunately, the other issue:

> And the governments will rub their hands with glee with all the new data they have access to.

Is 100% still the case, and almost impossible to get anyone to care about.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#84

Earlier quoted context omitted.

Mass surveillance is never an appropriate solution, let's start with that. I don't belive tech has an over weighted responsibility to solve society's problems, and in fact it's generally better if we don't try and pretend more tech is the answer. Advocating for more money and more prioritization for this area of law enforcement is still the way to go if it's a priority area. Policing seems to be drifting towards "mal…

Mass surveillance is bad, but I think there are versions of it that are far less bad than others. Apple's proposed solution would have theoretically only reported cases that were much more than likely to be already known instances of CSAM (i.e. not pictures of your kids), and if nothing else is reported, can we say that they were really surveilled? In some very strict sense, yes, but in terms of outcomes, no.

Mass surveillance isn't necessarily bad. It depends how it's implemented. The solution you describe is basically how it works with the intelligence agencies, in that only a miniscule fraction of the data collected in bulk ever reaches human eyes. The rest ends up being discarded after the retention period.

In terms of outcomes, almost nobody is actually surveilled, as the overall effect is the same as no data having been collected on them in the first place.

That said, I am personally more comfortable with my country's intelligence agencies hoovering up all my online activity than I am with the likes of Apple. The former is much more accountable than the latter.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#85
post #74

Earlier quoted context omitted.

When tech creates problems should tech tried to solve it or should tech be limited? We deceive ourselves honestly by pretending like we have not created new realities which are problematic at scale. We have. They are plentiful. And if people aren’t willing that we walk back tech to reduce the problems and people aren’t willing to accept technical solutions which are invasive then what are we to do? Are we just to acc…

“Tech”? What do you mean by “tech?” Do you expect Apple to remove the camera, storage, and networking capabilities of all their devices? That’s the “tech” that enables this.

I mean "tech" did a lot of messed up things - there is a reason why "what is your favorite big tech innovation: 1) illegal cab company 2) illegal hotel company 3) fake money for criminals 4) plagiarism machine" is a funny joke.

Enabling people to talk to each other without all their communication being wiretapped and archived forever is not one of those, I would say.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#86
post #76
post #24

Earlier quoted context omitted.

The main impetus behind "child safety" advocacy nowadays seem to be by cells of extremist right-wing Christian / QAnon types who believe in conspiracy theories like Pizzagate and the "gay groomer" panic. It's a reasonable assumption to make about any such group mentioned in the media that doesn't have an established history at least prior to 2016.

It sounds like an entirely unreasonable assumption to me. Advocating for child safety is something that transcends political differences, and generally unifies people across the political spectrum. I mean, there aren't many people who want paedophiles to be able to amass huge collections of child abuse imagery from other paedophiles online. And pretty much every parent wants their child to be kept safe from predators…

I didn't claim otherwise. The fact remains that a specific subset of a specific political party has been using "advocating for child safety" as a pretext to accelerate fear of and harassment against the LGBT community and "the left" in general for years now, and they put a lot of effort into appearing legitimate.

And yes, because their politics are becoming normalized within American culture, it is necessary to be skeptical about references to any such group. Assuming good faith is a rule on HN but elsewhere, where bad faith is what gets visibility, it's naive.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#87

Earlier quoted context omitted.

It's an incredibly bad thing. It's also an incredibly poor excuse to justify backdooring phones. Cops need to investigate the same way they always have, look for clues, go undercover, infiltrate, find where this stuff is actually being made, etc. Scanning everyone's phones would make their jobs significantly easier, no doubt, but it simply isn't worth the cost to us as a society and there is simply no good counter-ar…

Let's take a step back here and bring in some facts. "Apple" wasn't scanning your phone, neither was there a "backdoor". If you would've had iCloud upload enabled (you'd be uploading all your photos to Apple's server, a place where they could scan ALL of your media anyway), the phone would've downloaded a set of hashes of KNOWN and HUMAN VERIFIED photos and videos of sexual abuse material. [1] After THREE matches of…

You might've read the spec but you're missing the point and your approach is naive. For me it's about crossing the line. If you want to be snooping around my phone or my house, you need a warrant and go to official channels provides by my gov officials. And you really think it's as simple as picking apples from oranges? I mean come on. Yes, it's easy to implement hash check to see if u have some known child porn in your cloud. But was that the use case for the advocates? No. Their use case was to try finding abuse and that would need a more thorough scanning. And once we're there, we have to make hard decisions on what is porn or abuse. If u think it's easy, then you need to it through harder. Think of some picture from sauna where there are naked family, might be harmful? But normal here in Finland. What about a stick figure cartoon what depicts a some shady sexual positions with a smaller child-like figure in it? Or what about grooming, asking for naked pics? How is this system going to prevent that? I mean, I get why ppl would want something like this. But it isn't the right solution imho.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#88
post #19
post #14

Earlier quoted context omitted.

Where do you get this number?

e2ee for iCloud is currently opt-in, without prompts/nudging. Most power users don't even have it turned on or are aware of its existence. The setting is buried/hidden in submenus. Approximately no one uses it. Hopefully Apple will begin promoting users to migrate in future updates.

Indeed. After looking at the documentation, photos are not e2ee by default.

https://support.apple.com/en-us/HT202303

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#89

Earlier quoted context omitted.

But "the ability to discover CSAM" is by itself an excuse for mass surveillance, not a bona fide goal. It is certainly possible, instead, to investigate, then find likely pedophiles, and then get a search warrant.

Discovering users sharing CSAM is a goal isn't it? That's why governments around the world require cloud storage providers to scan for it – because waiting until the police receive a report of someone is not really feasible. A proactive approach is necessary and mandated in many countries.

imo diminishing ppl's privacy is a goal. Apple's csam could be tricked in different ways, esp with generative algorithms, like an malicious person will send you an album with 100+ normal looking photos(to the eye) but altered to trigger csam, now govt needs to check 100+ photos per person per send and dismiss the false positives. Since this can be replicated, imagine gov't will need to scan 100k similar usecases just for 1k ppl? that's insane, they'll either not check them, so system became obsolete(bc in this case ill intentioned ppl can just send an album of 5k photos, all triggering csam and only a bunch will be real csam. multiplied by nr of these ill ppl, you understand system is easy to game, or they spend thousands of hours checking all this photos and checking each person. Another vector of attack is generation of legit looking csam, bc, generating algorithms are too good now, but in this case(afaik) it's not a crime, since image is fully generated(either by only using ppl's face as starting point or using the description of their face tweaked enough to look realistic). So what we get is: - a system that can be gamed in different ways - a system that's not proved to be effective before releasing - a system that may potentially drive those ppl to other platforms with e2ee that don't have the csam scan(i assume since they know what e2ee is, they can find a platform without csam), so again obsolete AND: - a system that can't be verified by users (like is the csam list legit, can it trigger other things, is the implementation safe?) - a system that can be altered by govt by altering the csam list to target specific ppl (idk snowden or some journalist that found something sketchy) - a system that can be altered by apple/other company by altering csam list for ad targeting purposes

Idk, maybe i'm overreacting, but I've seen what a repressive gov can do, and with such an instrument it's frightening what surveillance vectors can be opened

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#90
post #16

I’m not sure I understand Apple’s logic here. Are iCloud Photos in their data centers not scanned? Isn’t everything by default for iCloud users sent there automatically to begin with? Doesn’t the same logic around slippery slope also apply to cloud scans? This is not to say they should scan locally, but my understanding of CSAM was that it would only be scanned on its way to the cloud anyways, so users who didn’t use…

so users who didn’t use iCloud would’ve never been scanned to begin with. - so why not implement csam for icloud only without local scanning?
Post reply on HN