> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…
Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
141–150 of 336 posts
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#142Earlier quoted context omitted.
> Is being against child sexual abuse really an unusual opinion in the tech industry? Nobody said that. You are being manipulative an trying to make it look that people who disagree with you are somehow pro-child abuse. In saying "Does the tech industry have any alternate solutions that could functionally mitigate this abuse?" you are trying to pain a picture in which child abuse is somehow "tech industry" fault. You…
This thread is tending towards flamewar so I'll try to dial back, but I do want to respond. > You are being manipulative an trying to make it look that people who disagree with you are somehow pro-child abuse. I am not doing that. You described my position as an "alien morality", to which another poster seemed to agree. I was responding to that by clarifying the actual moral point I was making. For the avoidance of d…
I understand that most information on how the state fights organised crime will be classfied, but if there is any publicly available evidence for this claim that you can share, I would be interested in reading it (and I hope others on this thread would be too). I'm not saying I doubt you - you give the impression you know what you're talking about - please take this in the spirit it's intended, as one of my former supervisors once said "In academia, asking for citations/references is an expression of interest, not of doubt".
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#143Earlier quoted context omitted.
i thought they can't scan the media in icloud, since media is encrypted, no? also: If it was someone sending you hashbombs of intentional false matches or an innocuous pic that matched because some mathematical anomaly, the actual human would notice this instantly and no action would've been taken. - if someone is doing this, imagine the scale- thousands of pics that should be human-evaluated, scaled to thousands of…
You do know that we currently have "thousands of people" watching for and tagging the most heinous shit people upload to social media, right? There are multiple sources for this how we use outsourced people from Africa and Asia to weed through all of the filth people upload on FB alone. "Looking illegal" isn't enough to trigger a CSAM check in this case. It's perfectly normal to take pictures of your own kids without…
Outsourcing work for this(afaik) isn't possible since it's private data, not public and only specific organisations can have full access to potential triggers
But in the end it also doesn't matter because there are other problems too, like how to make the final list easily checkable so that we are sure governments/ companies do not alter the list to target specific ppl/groups for their own interest. Or how algorithm isn't modified under the hood to check not just images but also text/files
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#144> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…
>Both of these arguments are absolutely, unambiguously, correct. Oh, please. As if we couldn't just compare the hashes of the pictures people are storing against a CSAM database of hashes that gets regularly updated When this was proposed people would respond "But they could just mirror the pictures or cut a pixel off!" Who cares? You got that picture from some place in the dark web, and eventually someone will stumb…
But even if there was an md5 hash collision back when md5 was the only one hash use, it still doesn't matter because upon viewing the image that matched, if it's not csam, it doesn't matter. Having said that, the chance of dozens of images matching hashes known to be associated to csam is also so unlikely as to be unthinkable. Where there is smoke, there is fire.
And further, a hash alone is meaningless, since in court there must be a presentation of evidence. If the image that set off the csam alarm by hash collision is say, an automobile, there is no case to be had. So all this talk about hash issues is absolutely moot.
Source: I have worked as an expert witness and presented for cases involving csam (back when we called it Child Pornography, because the CSAM moniker hadn't come about yet), so the requirements are well known to me.
Having said all that, I am an EFF member, and I prefer cryptography to work, and spying on users to be illegal.
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#145I’m not sure I understand Apple’s logic here. Are iCloud Photos in their data centers not scanned? Isn’t everything by default for iCloud users sent there automatically to begin with? Doesn’t the same logic around slippery slope also apply to cloud scans? This is not to say they should scan locally, but my understanding of CSAM was that it would only be scanned on its way to the cloud anyways, so users who didn’t use…
No outright statement confirming or denying this has ever made to my knowledge, but the implication, based both on Apple's statements and the statement of stakeholders, is that this isn't currently the case.
This might come as a surprise to some, because many companies scan for CSAM, but that's done voluntarily because the government can't force companies to scan for CSAM.
This is because based on case law, companies forced to scan for CSAM would be considered deputized and thus subsequently it would be a breach of the 4th amendments safeguards against "unreasonable search and seizure".
The best the government can do is to force companies to report "apparent violations" of CSAM laws, this seems like a distinction without a difference, but the difference is between required to actively search for it (and thus becoming deputized) v. reporting when you come across it.
Even then, the reporting requirement is constructed in such a way as to avoid any possible 4th amendment issues. Companies aren't required to report it to the DOJ, but rather to the NCMEC.
The NCMEC is a semi-government organization, autonomous from the DOJ, albeit almost wholly funded by the DOJ, and they are the ones that subsequently report CSAM violations to the DOJ.
The NCMEC is also the organization that maintains the CSAM database and provides the hashes that companies, who voluntarily scan for CSAM, use.
This construction has proven to be pretty solid against 4th amendment concerns, as courts have historically found that this separation between companies and the DOJ and the fact that only confirmed CSAM making its way to the DOJ after review by the NCMEC, creates enough of a distance between the DOJ and the act of searching through a person's data, that there aren't any 4th amendment concerns.
The Congressional Research Service did a write up on this last year for the ones that are interested in it[0].
Circling back to Apple, as it stands there's nothing indicating that they already scan for CSAM server-side and most comments both by Apple and child safety organizations seem to imply that this in fact is currently not happening.
Apple's main concerns however, as stated in the letter by Apple, echo the same concerns by security experts back when this was being discussed. Namely that it creates a target for malicious actors, that it is technically not feasible to create a system that can never be reconfigured to scan for non-CSAM material and that governments could pressure/regulate it to reconfigure it for other materials as well (and place a gag order on them, prohibiting them to inform users of this).
At the time, some of these arguments were brushed off as slippery slope FUD, and then the UK started considering something that would defy the limits of even the most cynical security researcher's nightmare, namely a de facto ban on security updates if it just so happens that the UK's intelligence services and law enforcement services are currently exploiting the security flaw that the update aims to patch.
Which is what Apple references in their response.
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#146Earlier quoted context omitted.
This thread is tending towards flamewar so I'll try to dial back, but I do want to respond. > You are being manipulative an trying to make it look that people who disagree with you are somehow pro-child abuse. I am not doing that. You described my position as an "alien morality", to which another poster seemed to agree. I was responding to that by clarifying the actual moral point I was making. For the avoidance of d…
> I am stating that the problem has been massively exacerbated by the adoption of E2EE by the tech industry I understand that most information on how the state fights organised crime will be classfied, but if there is any publicly available evidence for this claim that you can share, I would be interested in reading it (and I hope others on this thread would be too). I'm not saying I doubt you - you give the impressi…
I'm not part of any state, and I don't have access to any special knowledge that you can't find on the internet.
I'm also not aware of any study that provides the very direct link you're asking for. Because of the nature of E2EE, I don't know if it would be possible to produce one. What I can do is link to evidence such as https://www.weprotect.org/global-threat-assessment-21/#repor..., which has (to me) some fairly compelling data showing that the magnitude of the problem is increasing.
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#147Earlier quoted context omitted.
>Both of these arguments are absolutely, unambiguously, correct. Oh, please. As if we couldn't just compare the hashes of the pictures people are storing against a CSAM database of hashes that gets regularly updated When this was proposed people would respond "But they could just mirror the pictures or cut a pixel off!" Who cares? You got that picture from some place in the dark web, and eventually someone will stumb…
The hashes can not have collisions anymore, because modern forensics hash with both md5 and sha512, and both hashes must be together for use in any legal case. The odds of both of them having a collision is big enough to flat out say it's not going to happen. But even if there was an md5 hash collision back when md5 was the only one hash use, it still doesn't matter because upon viewing the image that matched, if it'…
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#148Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#149Earlier quoted context omitted.
The extreme hysteria created by anything related to children often seems to be carte blanche to destroy privacy and implement backdoors in applications. Most child abuse comes from family members (which must be solved at the source), and the ultra extreme cases simply make awful law (doing away with E2EE or instituting mass surveillance to catch an incredibly small minority is absurd). Much like other 'tough on crime…
> Most child abuse comes from family members (which must be solved at the source) Yes. Since becoming an abuser is a process and not a moment, part of the solution must be making access to CSAM much harder. > And no, we are not 'condoning' it when we declare E2EE an overall good thing. Agreed. I'm sorry if I worded things in a way that caused you to see an implication which was not intended. To be clear: E2EE is a go…
[1] https://en.wikipedia.org/wiki/Relationship_between_child_por...
Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos
#150Earlier quoted context omitted.
That's just an axiom for me, no justification needed. My life is my life and it is not the business of the state to watch every step I do as long as I am not affecting others in any relevant way. You convince me that I or society as a whole would be better off if I allowed the state to constantly keep an eye on me, then I might change my opinion and grant the state the permission to violate my privacy.
> That's just an axiom for me, no justification needed Congrats, you've got a religion.