Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

171–180 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#171
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

I’m sorry that there are victims, and it’s a horrible crime but no matter what I don’t believe my privacy and my freedoms should be sacrificed for this.

A small percentage of people are involved in this crime and subjecting every single person to illegal searches and possibly getting wrongly identified or nation states using this to imprison its enemies is wrong.

Sometimes there is no solution that satisfies everyone and sometimes the only good solution is the least shittiest solution but still a shitty solution. In this case, I believe that my and everyone else’s freedoms and privacy are worth it and we should instead spend much money time and effort trying to catch these criminals instead of scanning everyone’s phones which won’t ultimately work.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#172
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

No, no, no. There is no parallel to be drawn between better encryption and worse outcomes for kids. Should we also outlaw high-performance cars because these sometimes serve as effective getaway vehicles for criminals? CSAM producers and consumers should be found and punished via old-fashioned methods. How was this done in the past? Did we just never catch any human traffickers / rapists? No, we had detectives who we…

> How was this done in the past? Did we just never catch any human traffickers / rapists?

Recently invented encrypted chat rooms allow people to coordinate and transfer CSAM without any government official being able to infiltrate it. And just being able to freely discuss has been shown to make the problem worse as it facilitates knowledge transfer.

This is all completely different to in the past where this would have been done in person. So the argument that we should just do what we did in the past makes no sense. As technology advances we need to develop new techniques in order to keep up.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#173
post #80
post #9

> “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit," Neuenschwander wrote. "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.” Both of th…

It is also bad for the fabric of society at large, in the sense that if we don't clearly take a stand against abhorrent behaviour then we are in some sense condoning it. Does the tech industry have any alternate solutions that could functionally mitigate this abuse? I'd suggest there's a lot the not-tech industry could do to stop condoning abhorrent behavior that stops short of installing scanners on billions of comp…

Can't solve social problems with technology, as they say. And as mentioned elsewhere, most child abuse is perpetrated by family members and other close connections.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#174

Earlier quoted context omitted.

Mass surveillance is never an appropriate solution, let's start with that. I don't belive tech has an over weighted responsibility to solve society's problems, and in fact it's generally better if we don't try and pretend more tech is the answer. Advocating for more money and more prioritization for this area of law enforcement is still the way to go if it's a priority area. Policing seems to be drifting towards "mal…

When tech creates problems should tech tried to solve it or should tech be limited? We deceive ourselves honestly by pretending like we have not created new realities which are problematic at scale. We have. They are plentiful. And if people aren’t willing that we walk back tech to reduce the problems and people aren’t willing to accept technical solutions which are invasive then what are we to do? Are we just to acc…

> When tech creates problems should tech tried to solve it or should tech be limited?

You haven't explained the problem 'tech' has created, I'm confused as to what your point is?

CSAM isn't a problem caused by 'tech' unless you're going back to the invention of the camera, and I think that toothpaste is well out of the tube.

Additionally, and this is where a whole of arguments about this go wrong, the important part: the actual literal abuse, is human to human. There is no technology involved whatsoever.

Technological involvement may be an escalation of offense, but it's vanishingly secondary.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#175

Earlier quoted context omitted.

This morality may not be so unusual outside the tech "filter bubble". And wherever someone, like the OP, appears to be serious, my own personal morality says the absolute least they deserve is an equally serious answer.

I'm confused by what you mean by "morality" here. The only moral position that I am communicating is that child sexual abuse is a real thing that really happens, and it is bad for both the individual and for society. That's it. There's no subtext. There is explicitly no refutation of the arguments against client-side CSAM scanning which, I will say again, are unambiguously correct. Is being against child sexual abuse…

Most child abuse is perpetrated by family members and close connections. While that may not be true in the future, I think there are better avenues of action than jumping to completely backdooring an extremely valuable tool that allows people to exercise their rights more effectively.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#176
post #144

Earlier quoted context omitted.

>Both of these arguments are absolutely, unambiguously, correct. Oh, please. As if we couldn't just compare the hashes of the pictures people are storing against a CSAM database of hashes that gets regularly updated When this was proposed people would respond "But they could just mirror the pictures or cut a pixel off!" Who cares? You got that picture from some place in the dark web, and eventually someone will stumb…

The hashes can not have collisions anymore, because modern forensics hash with both md5 and sha512, and both hashes must be together for use in any legal case. The odds of both of them having a collision is big enough to flat out say it's not going to happen. But even if there was an md5 hash collision back when md5 was the only one hash use, it still doesn't matter because upon viewing the image that matched, if it'…

I don't think it's an MD5 or SHA512 hash, since just changing one pixel would be enough to evade the scanner. My understanding is that it's heuristic similarity detection, which has a much wider footprint for collisions.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#177

Earlier quoted context omitted.

No, no, no. There is no parallel to be drawn between better encryption and worse outcomes for kids. Should we also outlaw high-performance cars because these sometimes serve as effective getaway vehicles for criminals? CSAM producers and consumers should be found and punished via old-fashioned methods. How was this done in the past? Did we just never catch any human traffickers / rapists? No, we had detectives who we…

> How was this done in the past? Did we just never catch any human traffickers / rapists? Recently invented encrypted chat rooms allow people to coordinate and transfer CSAM without any government official being able to infiltrate it. And just being able to freely discuss has been shown to make the problem worse as it facilitates knowledge transfer. This is all completely different to in the past where this would hav…

Absolutely true. If there are new ways to commit crimes, there must be new ways to fight crimes. Child abuse has been accelerated greatly by technology and we are fighting it with sticks and stones because we don't want to accept that the terribleness of these crimes is worth giving up some of our privacy to stop.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#178

Earlier quoted context omitted.

> How was this done in the past? Did we just never catch any human traffickers / rapists? Recently invented encrypted chat rooms allow people to coordinate and transfer CSAM without any government official being able to infiltrate it. And just being able to freely discuss has been shown to make the problem worse as it facilitates knowledge transfer. This is all completely different to in the past where this would hav…

Absolutely true. If there are new ways to commit crimes, there must be new ways to fight crimes. Child abuse has been accelerated greatly by technology and we are fighting it with sticks and stones because we don't want to accept that the terribleness of these crimes is worth giving up some of our privacy to stop.

[flagged]

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#179
post #160

Earlier quoted context omitted.

> Both of these arguments are absolutely, unambiguously, correct. I don't really buy any "slippery slope" arguments for this stuff. Apple already can push any conceivable software it wants to all of its phones, so the slope is already as slippery as it can possibly be. It just doesn't make sense to say "Apple shouldn't implement this minimal version of photo-scanning now even though I don't think it's bad, because th…

Your comment confused me. Isn't Apple still scanning iPhones for CSAM just not the iCloud? I don't see any additional threat vectors by doing it locally.

Other way around-they’re scanning iCloud but not photos stored on iPhones, except in iMessage.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#180
post #13

The vast majority (99%+) of iCloud Photos are not e2ee and are readable to Apple. You can rest assured that they are scanning all of it serverside for illegal images presently. The kerfuffle was around clientside scanning, something that it has been reported that they dropped. I have thus far seen no statements from Apple that they actually intended to stop the deployment of clientside scanning. Serverside scanning h…

[deleted]
Post reply on HN