Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

101–110 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#101

Earlier quoted context omitted.

The extreme hysteria created by anything related to children often seems to be carte blanche to destroy privacy and implement backdoors in applications. Most child abuse comes from family members (which must be solved at the source), and the ultra extreme cases simply make awful law (doing away with E2EE or instituting mass surveillance to catch an incredibly small minority is absurd). Much like other 'tough on crime…

> Most child abuse comes from family members (which must be solved at the source) Yes. Since becoming an abuser is a process and not a moment, part of the solution must be making access to CSAM much harder. > And no, we are not 'condoning' it when we declare E2EE an overall good thing. Agreed. I'm sorry if I worded things in a way that caused you to see an implication which was not intended. To be clear: E2EE is a go…

That position says that to achieve privacy, I must tolerate CSAM. I want both privacy and for us not to tolerate CSAM.

Not true, you can have privacy and at the same time not tolerate child pornography, those are two perfectly compatible positions and arguably the current state. What you can not have - by definition - is privacy on the one hand and on the other hand no privacy in order to look for child pornography. You can still fight child pornography in any other way, but when it comes to privacy, you have to make a choice - give people their privacy or look through their stuff for illegal content, you can not have both. If you have enough evidence, a judge might even grant law enforcement the permission for privacy violating measures, it should just not be the default position that your privacy gets violated.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#102
post #16

I’m not sure I understand Apple’s logic here. Are iCloud Photos in their data centers not scanned? Isn’t everything by default for iCloud users sent there automatically to begin with? Doesn’t the same logic around slippery slope also apply to cloud scans? This is not to say they should scan locally, but my understanding of CSAM was that it would only be scanned on its way to the cloud anyways, so users who didn’t use…

so users who didn’t use iCloud would’ve never been scanned to begin with. - so why not implement csam for icloud only without local scanning?

Because the idea is that the iCloud data would be encrypted so their servers couldn’t scan it. With the plan being they would do on device scanning of photos that were marked as being stored on iCloud.

It’s objectively better than what google does but I’m glad we somehow ended up with no scanning at all.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#103
post #85
post #74

Earlier quoted context omitted.

“Tech”? What do you mean by “tech?” Do you expect Apple to remove the camera, storage, and networking capabilities of all their devices? That’s the “tech” that enables this.

I mean "tech" did a lot of messed up things - there is a reason why "what is your favorite big tech innovation: 1) illegal cab company 2) illegal hotel company 3) fake money for criminals 4) plagiarism machine" is a funny joke. Enabling people to talk to each other without all their communication being wiretapped and archived forever is not one of those, I would say.

Those aren't really "tech innovations", though, aside from maybe the plagiarism machine.

Uber and AirBnB are just using very-widely-available technology—that some taxi services and hotels are also using!—and claiming that they're completely different when the main difference is that they're just ignoring the laws and regulations around their industries.

Cryptocurrencies are using a tech innovation as a front for what's 99.9999% a financial "innovation"...which is really just a Ponzi scheme and/or related scams in sheep's clothing.

LLMs are genuinely a tech innovation, but the primary problem they bring to the fore is really a conversation we've needed to have for a while about copying in the digital age. The signs have been there for some time that such a shift was coming; the only question was exactly when.

In none of these cases is technology actually doing anything "messed up". Companies that denote themselves as being "in the tech industry" do bad things all the time, but blaming the technology for the corporate (and otherwise human) malfeasance is very unhelpful. In particular, trying to limit technological progress, or ban widely useful technological innovations because a small minority of people use them for ill, is horrifically counterproductive.

Enforce the laws we have better, be more willing to turn the screws on people even if they have lots of money, and where necessary put new regulations on human and corporate behavior in place (eg, requiring informed consent to have works you created included in the training set of an LLM or similar model).

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#104
post #19
post #14

Earlier quoted context omitted.

Where do you get this number?

e2ee for iCloud is currently opt-in, without prompts/nudging. Most power users don't even have it turned on or are aware of its existence. The setting is buried/hidden in submenus. Approximately no one uses it. Hopefully Apple will begin promoting users to migrate in future updates.

It only just came out this year and it comes with some pretty serious UX issues around potentially getting locked out of your data.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#105
post #11

False positives would constitute a huge invasion of privacy. Even actual positives would be, a mom taking a private picture of her naked baby, how can you report that. They did well dropping this insane plan. The slippery slope argument is also a solid one.

The apple one was only matching against known images, not trying to detect new ones.

The google one actually does try to detect new ones and there are reported instances of Google sending the police on normal parents for photos they took for the doctor.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#106
post #77

Earlier quoted context omitted.

Mass surveillance is never an appropriate solution, let's start with that. I don't belive tech has an over weighted responsibility to solve society's problems, and in fact it's generally better if we don't try and pretend more tech is the answer. Advocating for more money and more prioritization for this area of law enforcement is still the way to go if it's a priority area. Policing seems to be drifting towards "mal…

Every other aspect of life has been impacted by the computer's ability to process lots of information at speed. To say "no, policing must not use these tools but everyone else can" seems - well, quixotic, maybe? If illegal data (CP) is being transferred on the net, wiretapping that traffic and bringing hits to the attention of a human seems like a proportional response. (Yes, I know, it's not going to be 100% effecti…

If you have reasonable evidence, wiretapping a suspect to gain more evidence is fine. On the other hand wiretapping everyone in hope of finding some initial evidence, that is not okay at all.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#107
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

> criminals are using E2EE communication systems to share sexual abuse material Blah blah blah, the same old argument given by the "think of the children" people. There are many ways to counter that old chestnut, but really, we only need to remember the most basic fundamental facts: 1) Encryption is mathematics 2) Criminals are criminals Can you ban mathematics ? No. Can you stop criminals being criminals ? No. So, l…

> Can you stop criminals being criminals ? No.

[Citation needed]

This mindset—that assigns people into immutable categories, "criminal" and "not criminal"—is actually one of the biggest things that needs to change.

We absolutely can stop criminals from being criminals. We just can't do so by pointing at them and saying "Stop! Bad!" We have to change the incentives, remove the reasons they became criminal in the first place (usually poverty), and make it easier, safer, and more acceptable to go from being a criminal to being a not-criminal again.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#108

Earlier quoted context omitted.

so users who didn’t use iCloud would’ve never been scanned to begin with. - so why not implement csam for icloud only without local scanning?

Because the idea is that the iCloud data would be encrypted so their servers couldn’t scan it. With the plan being they would do on device scanning of photos that were marked as being stored on iCloud. It’s objectively better than what google does but I’m glad we somehow ended up with no scanning at all.

that sounds strange, I mean i'm not sure what's the big difference. If data is scanned on icloud, this means it's not encrypted, got it, if scanned on devices, data is fully encrypted on icloud, but apple has access by scanning it on devices and can send unencrypted matches, so it behaves as an unencrypted system, that can be altered at apple's will, just like icloud... but still, why scanning locally only if icloud is enabled? why not scan regardless? Since policy is meant to 'catch bad ppl', why limit to icloud option and not scan all the time

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#109
post #77

Earlier quoted context omitted.

Every other aspect of life has been impacted by the computer's ability to process lots of information at speed. To say "no, policing must not use these tools but everyone else can" seems - well, quixotic, maybe? If illegal data (CP) is being transferred on the net, wiretapping that traffic and bringing hits to the attention of a human seems like a proportional response. (Yes, I know, it's not going to be 100% effecti…

If you have reasonable evidence, wiretapping a suspect to gain more evidence is fine. On the other hand wiretapping everyone in hope of finding some initial evidence, that is not okay at all.

Why is it not okay at all? That's what our intelligence agencies do with their bulk data collection capabilities, and they have an immense positive impact on society.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#110
post #77

Earlier quoted context omitted.

Every other aspect of life has been impacted by the computer's ability to process lots of information at speed. To say "no, policing must not use these tools but everyone else can" seems - well, quixotic, maybe? If illegal data (CP) is being transferred on the net, wiretapping that traffic and bringing hits to the attention of a human seems like a proportional response. (Yes, I know, it's not going to be 100% effecti…

If you have reasonable evidence, wiretapping a suspect to gain more evidence is fine. On the other hand wiretapping everyone in hope of finding some initial evidence, that is not okay at all.

But that's just a restatement of the OP's position ("Mass surveillance is never an appropriate solution"). You're not attempting to justify that position.
Post reply on HN