Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

151–160 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#151
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

No, no, no.

There is no parallel to be drawn between better encryption and worse outcomes for kids. Should we also outlaw high-performance cars because these sometimes serve as effective getaway vehicles for criminals?

CSAM producers and consumers should be found and punished via old-fashioned methods. How was this done in the past? Did we just never catch any human traffickers / rapists? No, we had detectives who went around detecting and presumably kicking down doors.

To outlaw large sections of mathematics because of this is absurd. And from the amount of power it would give big governments / big businesses, the fabric of society doesn't stand a chance.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#152
post #134

Earlier quoted context omitted.

> only the most competent criminal organisations will do this correctly. All it takes is for one criminal to write a one-page guide to using GPG and circulate it to the group .... I know I mentioned paying a cryptographer earlier, but in reality downloading and using GPG is a crude and effective way of defeating an E2EE backdoor. Are the GPG devs going to backdoor GPG to satisfy governments ? Probably not.

> All it takes is for one criminal to write a one-page guide to using GPG and circulate it to the group If cybersecurity was that easy, we wouldn't have so many examples of businesses getting it wrong. Just because everyone here can follow instructions like that, doesn't make it common knowledge for anyone else.

> If cybersecurity was that easy, we wouldn't have so many examples of businesses getting it wrong.

There are almost no consequences for anyone working at a business that gets it wrong.

The consequences for being a nonce are quite severe so the motivation to get it right will be quite high.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#153

Earlier quoted context omitted.

ok, and in theory, with new generative algorithms, do you think it's still ok? Suppose apple implements this, suppose someone finds a way to generate meme images that can trigger apple's algorithm(but human can't see anything wrong), suppose that someone wants to harm you and sends you a bunch of memes and you save them. What will happen? Or what does happen if somebody is using generative algorithm to create csam li…

These criticisms are reasonable criticisms of a system in general, but Apple's design featured ways to mitigate these issues. I agree that the basic idea of scanning on device for CSAM has a lot of issues and should not be implemented. What I think was missing from the discourse was an actual look at what Apple were suggesting, in terms of technical specifics, and why that would be well designed to not suffer from th…

Apple's mitigations and their inadequacy were discussed.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#154
post #13

The vast majority (99%+) of iCloud Photos are not e2ee and are readable to Apple. You can rest assured that they are scanning all of it serverside for illegal images presently. The kerfuffle was around clientside scanning, something that it has been reported that they dropped. I have thus far seen no statements from Apple that they actually intended to stop the deployment of clientside scanning. Serverside scanning h…

Apple has full control over their customers devices, so they can access all encryption keys and device local files anyway. That e2ee setting seems pretty pointless to me...

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#155
post #73

Earlier quoted context omitted.

How are individuals re-victimized with every share? That makes no sense. Your LinkedIn profile photo could be on a billboard in rural China, what would it be to you?

There are several cases of victims being harassed and haunted by photos and video of them as a child being sexually abused. This is one of the reasons for Masha's law. https://www.nbcphiladelphia.com/news/local/child-porn-victim...

This makes no mention of direct harassment. How easy is it to connect random pictures of children with actual living adults? She's suing people she's never had any direct contact with. The government itself notifies her each time someone is arrested and in possession of an image of her, why, it does not say, but none of this sounds like a necessary healthy resolution to the underlying problem.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#156
post #33

Pretty ridiculous idea. Bad actors simply won't use their platform if this was in place. It would only be scanning private data from all people who aren't comitting crimes.

You'd be surprised. Lots of offenders are very low sophistication. If you read news articles about how a particular offender was caught with illegal material, so so often it's because they uploaded it to a cloud provider. It's not a one-sided tradeoff here.

What percentage of offenders victimize children and never record it in any way? If that's the overwhelming majority of abuse cases, what are we even doing here?

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#158
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

> Both of these arguments are absolutely, unambiguously, correct.

I don't really buy any "slippery slope" arguments for this stuff. Apple already can push any conceivable software it wants to all of its phones, so the slope is already as slippery as it can possibly be.

It just doesn't make sense to say "Apple shouldn't implement this minimal version of photo-scanning now even though I don't think it's bad, because that's a slippery slope for them to implement some future version of scanning that I do think is bad." They already have the capability to push any software to their phones at any time! They could just skip directly to the version you think is bad!

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#159
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

>>and at rates which they were not previously able to.

your source for proof of that?

>> in the sense that if we don't clearly take a stand against abhorrent behaviour then we are in some sense condoning it.

No. this narrative of "silence is violence" and "no action is support" etc is 100% wrong.

You started out great, but i can not get behind this type of thinking...

>>Does the tech industry have any alternate solutions that could functionally mitigate this abuse?

Why is it a "tech industry" problem

>>Or do we all just shout "yay, individual freedom wins again!"

For me the answer is simple... Yes individual freedom is more important that everything. I will never support curbing individual freedom on the alter of any kind proclaimed government solution to a social safety problem. Largely because I know enough about history to understand that not only will they no solve that social safety problem, many in government are probably participating in the problem and have the power to exempt themselves, while abusing the very tools and powers we give them to fight X, for completely unrelated purposes.

Very quickly any tool we would give them to fight CSAM would be used for Drug Enforcement, Terrorism, etc. It would not be long before the AI based phashes detect some old lady's Tomato plants as weed and we have an entire DEA paramilitary unit raiding her home...

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#160
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

> Both of these arguments are absolutely, unambiguously, correct. I don't really buy any "slippery slope" arguments for this stuff. Apple already can push any conceivable software it wants to all of its phones, so the slope is already as slippery as it can possibly be. It just doesn't make sense to say "Apple shouldn't implement this minimal version of photo-scanning now even though I don't think it's bad, because th…

Your comment confused me. Isn't Apple still scanning iPhones for CSAM just not the iCloud? I don't see any additional threat vectors by doing it locally.
Post reply on HN