Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

191–200 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#191
post #122

Earlier quoted context omitted.

In my opinion their goal was to get stuff to a state where they could encrypt everything on iCloud so that even they can't access it. To counter the "think of the children" -argument governments use to justify surveillance, Apple tried scanning stuff on-device but the internet got a collective hissy-fit of intentionally misunderstanding the feature and it was quickly scrapped.

> In my opinion their goal was to get stuff to a state where they could encrypt everything on iCloud so that even they can't access it. They basically did. If you turn on Advanced Data Protection, you get all of the encryption benefits, sans scanning. The interesting thing is that if you turn on ADP though, binary file hashes are unencrypted on iCloud, which would theoretically allow someone to ask for those hashes i…

Nice! TIL this exists.

For anyone else wondering, to enable it just go to iOS Settings -> iCloud and you'll see "Advanced Data Protection." Toggle it to enabled to create a recovery key, which you'll then be prompted to input correctly after saving it somewhere safe, and then return to the iCloud Settings page, toggle it one more time and enter your recovery key again to confirm.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#192
post #52
post #16

I’m not sure I understand Apple’s logic here. Are iCloud Photos in their data centers not scanned? Isn’t everything by default for iCloud users sent there automatically to begin with? Doesn’t the same logic around slippery slope also apply to cloud scans? This is not to say they should scan locally, but my understanding of CSAM was that it would only be scanned on its way to the cloud anyways, so users who didn’t use…

> I’m not sure I understand apples logic here. Are iCloud Photos in their data centers not scanned? Isn’t everything by default for iCloud users sent there automatically to begin with? Doesn’t the same logic around slippery slope also apply to cloud scans? I don’t see the problem with this status quo. There is a clear demarcation between my device and their server. Each serving the interests of their owner. If I have…

> the data storage space has heaps of competitive options

The generic space does, yes. But if you want native integration with iOS, your only choice is iCloud. It would certainly be nice if this was an open protocol where you could choose your own storage backend. But I think the chances of that ever happening are pretty much zero.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#193
I'm curious about the new parental control features they announced at the same time as the iCloud photo scanning. My recollection is that when they withdrew the iCloud scanning they also withdrew the new parental controls.

I'm curious why they also withdrew those. For those who don't remember the parental control, which were largely overshadowed by the controversy over the cloud stuff, they were to work like this:

1. If parents had enabled them on their child's device, they would scan incoming messages for sexual material. The scan would be entirely on-device. If such material was found the material would be blocked, the child would be notified that the the message contained material that their parents thought might be harmful, and asked if they wanted to see it anyway.

2. If the child said no, the material would be dropped and that would be the end of it. If the child said yes what happened next depended on the age of the child.

3. If the was at least 13 years old the material would be unblocked and that would be the end of it.

4. If the while was not yet 13 they would be given another warning that their parents think the material might be harmful, and again asked if they want to go ahead and see it. They would be told that if they say "yes" their parents will be notified that they viewed the material.

5. If they say no the material remains blocked and that is the end of it.

6. If they say yes it is unblocked, but their parents are told.

There wasn't a lot of discussion of this, and I only recall seeing one major privacy group object (the EFF, on the grounds that if it reaches step 6 it violates the privacy of the person sending sex stuff to your pre-teen because they probably did not intend for the parents to know).

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#194

Earlier quoted context omitted.

The extreme hysteria created by anything related to children often seems to be carte blanche to destroy privacy and implement backdoors in applications. Most child abuse comes from family members (which must be solved at the source), and the ultra extreme cases simply make awful law (doing away with E2EE or instituting mass surveillance to catch an incredibly small minority is absurd). Much like other 'tough on crime…

> which must be solved at the source Governments are not good at this type of thing. It requires careful analysis, planning and actual decisions. But slap on a regulation and require private companies to do the hard work for you - now we are talking!

Don't worry, we fill our homes and pockets with enough cameras and microphones from private companies that the government can require the monitoring of everyone in every family 24/7 to make sure we're finally safe!

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#195

Earlier quoted context omitted.

No, no, no. There is no parallel to be drawn between better encryption and worse outcomes for kids. Should we also outlaw high-performance cars because these sometimes serve as effective getaway vehicles for criminals? CSAM producers and consumers should be found and punished via old-fashioned methods. How was this done in the past? Did we just never catch any human traffickers / rapists? No, we had detectives who we…

> Should we also outlaw high-performance cars because these sometimes serve as effective getaway vehicles for criminals? What if we change the last bit after the "because" to "these sometimes are used at unsafe speeds and, intentionally or not, kill people who are not in cars?" Because, at least for me, the answer is an unambiguous yes. I agree that privacy and security should be available to everyone. But we also sh…

>But we also shouldn't count on being able to find people ... because the person messed up their opsec.

How is this different from how police find anybody else who commits a crime? Like if they're trying to solve a murder, they're looking for DNA, clues, etc... They're literally looking for where the person who committed the crime "messed up their opsec" to use your wording.

Governments and law enforcement agencies have access to more information than they've ever had before. They have more cameras, location data, tons of data compiled by data brokers. But it's not enough - of course they have to have this too.

On top of that, there's a long history now of governments buying zero day vulnerabilities or even technology from firms like NSO and guess what? It's not being used to catch pedophiles (cue shocked Pikachu face) but it is being used to target political dissidents.

This is so frustrating, because it feels like a siege on a city. Collectively, people have to fight against bad legislation in various countries constantly. But the other side only has to "win" once.

I'd say that "we" as an industry should be putting out brains to trying to figure out ways to make it even harder for these people to legislate encryption out of existence, than trying to find ways to appease geriatric lawmakers.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#196
post #193

I'm curious about the new parental control features they announced at the same time as the iCloud photo scanning. My recollection is that when they withdrew the iCloud scanning they also withdrew the new parental controls. I'm curious why they also withdrew those. For those who don't remember the parental control, which were largely overshadowed by the controversy over the cloud stuff, they were to work like this: 1.…

The issue is that it’s predicated on an age field that can be set separately. It’s easy to use parental controls to control non-children by setting a lower age internally. Think victims of human trafficking or adults in odd relationship situations.

Not quite the same but see: https://www.forbes.com/sites/thomasbrewster/2023/04/06/sex-t...

Apple’s updated system allows children to ask for help from an adult using the Communication Safety features, which strikes a good balance to me.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#197

Earlier quoted context omitted.

> Most child abuse comes from family members (which must be solved at the source) Yes. Since becoming an abuser is a process and not a moment, part of the solution must be making access to CSAM much harder. > And no, we are not 'condoning' it when we declare E2EE an overall good thing. Agreed. I'm sorry if I worded things in a way that caused you to see an implication which was not intended. To be clear: E2EE is a go…

It is not clear if access to child pornography increases, decreases, or has no significant effect on child sex abuse.[1] [1] https://en.wikipedia.org/wiki/Relationship_between_child_por...

We have all this AI now, maybe give the people who want that stuff realistic enough victimless content and we can see if cases drop? It seems like we're approaching a time when the technology makes it possible to test the theory and get an answer anyway.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#198
post #16

I’m not sure I understand Apple’s logic here. Are iCloud Photos in their data centers not scanned? Isn’t everything by default for iCloud users sent there automatically to begin with? Doesn’t the same logic around slippery slope also apply to cloud scans? This is not to say they should scan locally, but my understanding of CSAM was that it would only be scanned on its way to the cloud anyways, so users who didn’t use…

> Are iCloud Photos in their data centers not scanned? No outright statement confirming or denying this has ever made to my knowledge, but the implication, based both on Apple's statements and the statement of stakeholders, is that this isn't currently the case. This might come as a surprise to some, because many companies scan for CSAM, but that's done voluntarily because the government can't force companies to scan…

To add a bit more color, 18 U.S. Code § 2258A specifically states:

> Nothing in this section shall be construed to require a provider to—

> (1) monitor any user, subscriber, or customer of that provider;

> (2) monitor the content of any communication of any person described in paragraph (1); or

> (3) affirmatively search, screen, or scan for facts or circumstances described in sections (a) and (b).

The core of 18 U.S. Code § 2258A - Reporting requirements of providers is available at https://www.law.cornell.edu/uscode/text/18/2258A.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#199
post #84

Earlier quoted context omitted.

Mass surveillance is bad, but I think there are versions of it that are far less bad than others. Apple's proposed solution would have theoretically only reported cases that were much more than likely to be already known instances of CSAM (i.e. not pictures of your kids), and if nothing else is reported, can we say that they were really surveilled? In some very strict sense, yes, but in terms of outcomes, no.

Mass surveillance isn't necessarily bad. It depends how it's implemented. The solution you describe is basically how it works with the intelligence agencies, in that only a miniscule fraction of the data collected in bulk ever reaches human eyes. The rest ends up being discarded after the retention period. In terms of outcomes, almost nobody is actually surveilled, as the overall effect is the same as no data having…

If your ex-spouse was a contractor for a government agency with access to the mass surveillance machine, would you still feel comfortable "that only a miniscule fraction of the data collected in bulk ever reaches human eyes?"

What if you were a candidate for political office, pushing opinions that angered large swaths of the Intelligence Comminity?

The "minuscule fraction" of content is not surfaced by some random roll of the dice - it's the definitionally most interesting content, in the sense that some human went specifically looking for it in the heap of content caught in the dragnet. And it only needs to be interesting to at least one person with the clearance to search for it.

Maybe that means it's a video of a child being abused, and some morally upstanding federal officer is searching for it because anyone possessing it is ethically and legally culpable for the abuse of that child... Or maybe it's a PDF containing evidence of FBI kidnapping and torturing innocent civilians, and some morally corrupt federal officer is searching for it because anyone possessing it is a liability who needs to be silenced... Or maybe it's a JSON file containing the GPS locations of an individual for the past year, and some emotionally scorned federal contractor is searching for it because that individual is their ex-spouse who's moved onto a new partner.

Are you really prepared to put your faith in the trustworthiness and moral clarity of the population of 100k+ people with federal security clearances?

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#200

Earlier quoted context omitted.

No, no, no. There is no parallel to be drawn between better encryption and worse outcomes for kids. Should we also outlaw high-performance cars because these sometimes serve as effective getaway vehicles for criminals? CSAM producers and consumers should be found and punished via old-fashioned methods. How was this done in the past? Did we just never catch any human traffickers / rapists? No, we had detectives who we…

> How was this done in the past? Did we just never catch any human traffickers / rapists? Recently invented encrypted chat rooms allow people to coordinate and transfer CSAM without any government official being able to infiltrate it. And just being able to freely discuss has been shown to make the problem worse as it facilitates knowledge transfer. This is all completely different to in the past where this would hav…

So these people who are coordinating and transferring CSAM are presumably bringing others into the fold to more effectively distribute things. Otherwise digital technology would not make distribution and coordination easier. So law enforcement just needs to infiltrate these groups exactly the same way that they did in the past. The only difference is they don't even need to meet these creeps face to face until they arrest them.
Post reply on HN