Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

131–140 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#131
post #10

Earlier quoted context omitted.

> So despite looking a bit fishy at first, this doesn't seem to come from a christofascist group. Why would you assume this in the first place?

Because when they couldn't win the war on porn, some right Christians decided to cloak their attack in "concerns" of "abuse". See project Excedus. Of course it has nothing to do with abuse and everything to do with their attempts to keep people from seeing pixels of other people having sex. Backpage was shut down despite being good at removing underage and trafficed women - which meant that sex workers had to find ot…

But being critical of pornography and considering it to be abuse isn't a view limited to right-wing Christians. For example, here's what Noam Chomsky has to say about it:

> Pornography is humiliation and degradation of women. It's a disgraceful activity. I don't want to be associated with it. Just take a look at the pictures. I mean, women are degraded as vulgar sex objects. That's not what human beings are. I don't even see anything to discuss.

> Interviewer: But didn't performers choose to do the job and get paid?

> The fact that people agree to it and are paid, is about as convincing as the fact that we should be in favour of sweatshops in China, where women are locked into a factory and work fifteen hours a day, and then the factory burns down and they all die. Yeah, they were paid and they consented, but it doesn't make me in favour of it, so that argument we can't even talk about.

> As for the fact that it's some people's erotica, well you know that's their problem, doesn't mean I have to contribute to it. If they get enjoyment out of humiliation of women, they have a problem, but it's nothing I want to contribute to.

> Interviewer: How should we improve the production conditions of pornography?

> By eliminating degradation of women, that would improve it. Just like child abuse, you don't want to make it better child abuse, you want to stop child abuse.

> Suppose there's a starving child in the slums, and you say "well, I'll give you food if you'll let me abuse you." Suppose - well, there happen to be laws against child abuse, fortunately - but suppose someone were to give you an argument. Well, you know, after all a child's starving otherwise, so you're taking away their chance to get some food if you ban abuse. I mean, is that an argument?

> The answer to that is stop the conditions in which the child is starving, and the same is true here. Eliminate the conditions in which women can't get decent jobs, not permit abusive and destructive behaviour.

(Source of the above is this interview: https://youtube.com/watch?v=SNlRoaFTHuE)

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#132

Earlier quoted context omitted.

In my opinion their goal was to get stuff to a state where they could encrypt everything on iCloud so that even they can't access it. To counter the "think of the children" -argument governments use to justify surveillance, Apple tried scanning stuff on-device but the internet got a collective hissy-fit of intentionally misunderstanding the feature and it was quickly scrapped.

> so that even they can't access it. > scanning stuff on-device What do you think they were going to do once the scanning turned up a hit? Access the photos? Well that negates the first statement.

Who is this "they" who will access the photos on-device?

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#133

Earlier quoted context omitted.

Let's take a step back here and bring in some facts. "Apple" wasn't scanning your phone, neither was there a "backdoor". If you would've had iCloud upload enabled (you'd be uploading all your photos to Apple's server, a place where they could scan ALL of your media anyway), the phone would've downloaded a set of hashes of KNOWN and HUMAN VERIFIED photos and videos of sexual abuse material. [1] After THREE matches of…

i thought they can't scan the media in icloud, since media is encrypted, no? also: If it was someone sending you hashbombs of intentional false matches or an innocuous pic that matched because some mathematical anomaly, the actual human would notice this instantly and no action would've been taken. - if someone is doing this, imagine the scale- thousands of pics that should be human-evaluated, scaled to thousands of…

You do know that we currently have "thousands of people" watching for and tagging the most heinous shit people upload to social media, right? There are multiple sources for this how we use outsourced people from Africa and Asia to weed through all of the filth people upload on FB alone.

"Looking illegal" isn't enough to trigger a CSAM check in this case. It's perfectly normal to take pictures of your own kids without clothes in most of Europe for example. Nothing illegal.

That's why the checks would've been explicitly done on known and confirmed CSAM images. It wasn't some kind of check_if_penis() -algorigthm, or one of the shitty ones that trigger if there's too much (white) skin colour in an image.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#134
post #83

Earlier quoted context omitted.

> But the criminals ? Do you honestly think they'll think "oh no, game over" ? > No of course not. They'll pay some cryptographer in need of some money to develop a new E2EE tool and carry on. Business as usual. I used to think this, I changed my mind: just as it's difficult to do security correctly even when it's a legal requirement, only the most competent criminal organisations will do this correctly. Unfortunatel…

> only the most competent criminal organisations will do this correctly. All it takes is for one criminal to write a one-page guide to using GPG and circulate it to the group .... I know I mentioned paying a cryptographer earlier, but in reality downloading and using GPG is a crude and effective way of defeating an E2EE backdoor. Are the GPG devs going to backdoor GPG to satisfy governments ? Probably not.

> All it takes is for one criminal to write a one-page guide to using GPG and circulate it to the group

If cybersecurity was that easy, we wouldn't have so many examples of businesses getting it wrong.

Just because everyone here can follow instructions like that, doesn't make it common knowledge for anyone else.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#135
I think they likely also considered the lawsuit exposure. If just 0.0001% of users sued over false positives, Apple would be in serious trouble.

And there's another dynamic where telling your customers you're going to scan their content for child porn is the same as saying you suspect your customers of having child porn. And your average non-criminal customer's reaction to that is not positive for multiple reasons.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#136
post #134

Earlier quoted context omitted.

> only the most competent criminal organisations will do this correctly. All it takes is for one criminal to write a one-page guide to using GPG and circulate it to the group .... I know I mentioned paying a cryptographer earlier, but in reality downloading and using GPG is a crude and effective way of defeating an E2EE backdoor. Are the GPG devs going to backdoor GPG to satisfy governments ? Probably not.

> All it takes is for one criminal to write a one-page guide to using GPG and circulate it to the group If cybersecurity was that easy, we wouldn't have so many examples of businesses getting it wrong. Just because everyone here can follow instructions like that, doesn't make it common knowledge for anyone else.

> If cybersecurity was that easy, we wouldn't have so many examples of businesses getting it wrong.

I can only partially agree with this point. Businesses getting cybersecurity wrong has almost no material and significant consequences. At best, they get a tiny slap on the wrist or asked to answer some questions. Nobody in said businesses goes to jail for it or personally pays any fines. Compare that to criminals who have a lot more to lose if they get caught — jail time, fines they have to pay, not having freedom for quite sometime, life not being the same after they’ve served their sentence, and more. Businesses have it extremely easy compared to this. No wonder cybersecurity is so poor among all businesses, including very large ones (like Microsoft, as a recent example).

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#137

Earlier quoted context omitted.

If you have reasonable evidence, wiretapping a suspect to gain more evidence is fine. On the other hand wiretapping everyone in hope of finding some initial evidence, that is not okay at all.

Why is it not okay at all? That's what our intelligence agencies do with their bulk data collection capabilities, and they have an immense positive impact on society.

s/positive/negative/

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#138
post #134

Earlier quoted context omitted.

> All it takes is for one criminal to write a one-page guide to using GPG and circulate it to the group If cybersecurity was that easy, we wouldn't have so many examples of businesses getting it wrong. Just because everyone here can follow instructions like that, doesn't make it common knowledge for anyone else.

> If cybersecurity was that easy, we wouldn't have so many examples of businesses getting it wrong. I can only partially agree with this point. Businesses getting cybersecurity wrong has almost no material and significant consequences. At best, they get a tiny slap on the wrist or asked to answer some questions. Nobody in said businesses goes to jail for it or personally pays any fines. Compare that to criminals who…

> jail time, fines they have to pay

Fear of these is the reason for the (maliciously compliant) GDPR popups, and that despite discussion about extra-territoriality and relativity limited capacity-to-websites ratio.

The law and threats of punishment are clearly not hugely significant to anyone involved in the specific topic of this thread regardless; in the UK at least, it's the kind of thing where if someone is lynched for it, the vigilantes have to be extremely stupid (like attacking a paediatrician because they can't tell the difference, which happened) to not get public sympathy.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#139
post #94

Earlier quoted context omitted.

> they can just use/switch to unpatched devices with some opensource e2ee without big effort. Assuming no new zero-days, and that they were even doing best practices in the first place. How many legit companies do best practices?

zero days are irrelevant imo, zero days are for targeted attacks(assuming it's from gov), exploiting all zerodays for all devices is not that productive, csam scan on the other hand can handle both untargeted and targeted surveilance: untargeted by spotting bad actors from a generic csam list, targeted - by adding to that list target's face/specific things to locate it and monitor it. That's the point, bad actors can…

I don't buy your argument, but as for:

> I've seen how an authoritarian gov in my country is targeting ppl bc they are uncomfortable for the system and this algorithm opens another potential vector of attack.

As per my last sentence in my initial comment in this chain:

--

> And the governments will rub their hands with glee with all the new data they have access to.

Is 100% still the case, and almost impossible to get anyone to care about.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#140

Earlier quoted context omitted.

This morality may not be so unusual outside the tech "filter bubble". And wherever someone, like the OP, appears to be serious, my own personal morality says the absolute least they deserve is an equally serious answer.

I'm confused by what you mean by "morality" here. The only moral position that I am communicating is that child sexual abuse is a real thing that really happens, and it is bad for both the individual and for society. That's it. There's no subtext. There is explicitly no refutation of the arguments against client-side CSAM scanning which, I will say again, are unambiguously correct. Is being against child sexual abuse…

I don't think anyone would disagree with you that child abuse exists - and if they did, that's an empirical question, and it resolves to you being correct.

The moral part is whether and how much society / the state / the tech industry should invest in combating it, and how the advantages and disadvantages of mandating government access to E2E encrypted communications or people's cloud storage weigh up.

For what it's worth, my own position is that the state should do more about it, and should in principle have more resources allocated to do so. I would support higher taxes in exchange for more police (and better trained police), who could do more about many kinds of crime including child abuse. I wouldn't mind more resources being allocated to policing specifically for fighting child abuse, too. But I could think of a lot of other places besides legislating access to people's messenger apps where such resources could be invested.

I'm still undecided on whether legally mandated backdoors in E2E encrypted storage and communications would be _effective_ in fighting child abuse, which is a question I would need more technical knowledge on before I could take an informed position (I know a fair bit about cryptography but less about how organised crime operates). If it turns out that this would be an ineffective measure (maybe criminals fall back on other means of communication such as TOR relays) then it would be hard to justify such a measure morally, especially as it could have a lot of disadvantages in other areas.

Post reply on HN