Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

221–230 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#221
post #198

Earlier quoted context omitted.

> Are iCloud Photos in their data centers not scanned? No outright statement confirming or denying this has ever made to my knowledge, but the implication, based both on Apple's statements and the statement of stakeholders, is that this isn't currently the case. This might come as a surprise to some, because many companies scan for CSAM, but that's done voluntarily because the government can't force companies to scan…

To add a bit more color, 18 U.S. Code § 2258A specifically states: > Nothing in this section shall be construed to require a provider to— > (1) monitor any user, subscriber, or customer of that provider; > (2) monitor the content of any communication of any person described in paragraph (1); or > (3) affirmatively search, screen, or scan for facts or circumstances described in sections (a) and (b). The core of 18 U.S…

I was looking for that!

Great addition to provide more context.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#222
post #217

Earlier quoted context omitted.

> Are iCloud Photos in their data centers not scanned? No outright statement confirming or denying this has ever made to my knowledge, but the implication, based both on Apple's statements and the statement of stakeholders, is that this isn't currently the case. This might come as a surprise to some, because many companies scan for CSAM, but that's done voluntarily because the government can't force companies to scan…

It WASN’T the case. Photos are listed on their page of stuff that’s not end to end encrypted. Since it all went down they added the advanced security option that encrypts photos, messages, and even more. But that option is opt-in since if you mess it up they can’t help you recover.

Non-encryption ≠ CSAM scanning

That said, I could be wrong about them not scanning currently, I simply don’t have anything authoritative saying either way.

Only statements that imply that they currently don’t, nothing more.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#223

Earlier quoted context omitted.

There are also ways to detect matches even with e2ee iirc and I suspect they found doing that instead easier than dealing with the previous approach. At the time I also thought it was obvious it was in preparation for e2ee (despite loud people on HN who disagreed). I do wonder if they had intended to have it be default on though, maybe not since probably better for most users to have a recovery option.

> There are also ways to detect matches even with e2ee By definition, encryption (with unique user keys) means you can't infer nor check what the content of the message is. Not without client cooperation, which is what this feature would have been.

This is what I was recalling, this method gives you a clever way to do it using the file itself as the key:

> “Convergent encryption solves this problem in a very clever way:

“The way to make sure that every unique user with the same file ends up with an encrypted version of that file that is also identical is to ensure they use the same key. However, you can’t share keys between users, because that defeats the entire point; you need a common reference point between users that is unknown to anyone but those users.

“The answer is to use the file itself: the system creates a hash of the file’s content, and that hash (a long string of characters derived from a known algorithm) is the key that is used to encrypt said file.

“If every iCloud user uses this technique — and given that Apple implements the system, they do — then every iCloud user with the same file will produce the same encrypted file, given that they are using the same key (which is derived from the file itself); that means that Apple only needs to store one version of that file even as it makes said file available to everyone who “uploaded” it (in truth, because iCloud integration goes down to the device, the file is probably never actually uploaded at all — Apple just includes a reference to the file that already exists on its servers, thus saving a huge amount of money on both storage costs and bandwidth).

“There is one huge flaw in convergent encryption, however, called “confirmation of file”: if you know the original file you by definition can identify the encrypted version of that file (because the key is derived from the file itself). When it comes to CSAM, though, this flaw is a feature: because Apple uses convergent encryption for its end-to-end encryption it can by definition do server-side scanning of files and exploit the “confirmation of file” flaw to confirm if CSAM exists, and, by extension, who “uploaded” it. Apple’s extremely low rates of CSAM reporting suggest that the company is not currently pursuing this approach, but it is the most obvious way to scan for CSAM given it has abandoned its on-device plan.”

https://stratechery.com/2022/apple-icloud-encryption-csam-sc...

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#224
post #11

False positives would constitute a huge invasion of privacy. Even actual positives would be, a mom taking a private picture of her naked baby, how can you report that. They did well dropping this insane plan. The slippery slope argument is also a solid one.

The apple one was only matching against known images, not trying to detect new ones. The google one actually does try to detect new ones and there are reported instances of Google sending the police on normal parents for photos they took for the doctor.

I feel this neatly captures the overarching corporate philosophies and attitudes of Apple and Google in a single example.

Pick your favourite other example of when Apple and Google have faced roughly the same problem as each other, and hold up their respective solutions next to those in the example of CSAM scanning above. I bet they'll look similar.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#225

Earlier quoted context omitted.

> There are also ways to detect matches even with e2ee By definition, encryption (with unique user keys) means you can't infer nor check what the content of the message is. Not without client cooperation, which is what this feature would have been.

This is what I was recalling, this method gives you a clever way to do it using the file itself as the key: > “Convergent encryption solves this problem in a very clever way: “The way to make sure that every unique user with the same file ends up with an encrypted version of that file that is also identical is to ensure they use the same key. However, you can’t share keys between users, because that defeats the entir…

> that hash is the key that is used to encrypt said file.

So every file has a unique key? So thousands or 10,000s of keys would need need to be in the keychain, mapped to the file name.

And if one person's keys are leaked, they can be used prove that other people had the same file

No, this doesn't sound well thought out

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#226
post #196
post #193

I'm curious about the new parental control features they announced at the same time as the iCloud photo scanning. My recollection is that when they withdrew the iCloud scanning they also withdrew the new parental controls. I'm curious why they also withdrew those. For those who don't remember the parental control, which were largely overshadowed by the controversy over the cloud stuff, they were to work like this: 1.…

The issue is that it’s predicated on an age field that can be set separately. It’s easy to use parental controls to control non-children by setting a lower age internally. Think victims of human trafficking or adults in odd relationship situations. Not quite the same but see: https://www.forbes.com/sites/thomasbrewster/2023/04/06/sex-t... Apple’s updated system allows children to ask for help from an adult using the…

> to control non-children[...] Think victims of human trafficking or adults in odd relationship situations.

uh, by preventing them from seeing sexual content?

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#227
post #193

I'm curious about the new parental control features they announced at the same time as the iCloud photo scanning. My recollection is that when they withdrew the iCloud scanning they also withdrew the new parental controls. I'm curious why they also withdrew those. For those who don't remember the parental control, which were largely overshadowed by the controversy over the cloud stuff, they were to work like this: 1.…

> if it reaches step 6 it violates the privacy of the person sending

Let's say the parents are abusive, and someone wants to talk with the child about that (via chat, for some reason).

Now, if the algorithms sometimes incorrectly flag private messages that were in fact safe -- could that be mitigated by letting the sender know: "Your message will be scanned and possibly shown to the parents of the recipient" before they hit Send?

(O.t.o.h. that leaks info about the age of the recipient.)

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#228

Earlier quoted context omitted.

If your ex-spouse was a contractor for a government agency with access to the mass surveillance machine, would you still feel comfortable "that only a miniscule fraction of the data collected in bulk ever reaches human eyes?" What if you were a candidate for political office, pushing opinions that angered large swaths of the Intelligence Comminity? The "minuscule fraction" of content is not surfaced by some random ro…

What leads you to believe that access to search these datasets is some sort of unregulated, unmonitored free-for-all for anyone allowed to wander into an intelligence agency building? The scenarios you invented sound very far-fetched to me, if these did happen I very much doubt the perpetrator would be able to get away with it.

> In 2021 alone, the FBI conducted up to 3.4 million warrantless searches of Section 702 data to find Americans’ communications

https://www.eff.org/deeplinks/2023/04/internal-documents-sho...

> At least a dozen U.S. National Security Agency employees have been caught using secret government surveillance tools to spy on the emails or phone calls of their current or former spouses and lovers in the past decade, according to the intelligence agency’s internal watchdog.

https://www.reuters.com/article/us-usa-surveillance-watchdog...

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#229
post #184

The article keeps saying that Apple has responded or that Apple has clarified and then linking other Wired articles. Is there an Apple press release somewhere? If so, I'd rather read that. ETA: looks like they directly provide documents from Apple at the bottom of the article

Here's the link: https://s3.documentcloud.org/documents/23933180/apple-letter...

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#230
post #198

Earlier quoted context omitted.

To add a bit more color, 18 U.S. Code § 2258A specifically states: > Nothing in this section shall be construed to require a provider to— > (1) monitor any user, subscriber, or customer of that provider; > (2) monitor the content of any communication of any person described in paragraph (1); or > (3) affirmatively search, screen, or scan for facts or circumstances described in sections (a) and (b). The core of 18 U.S…

I was looking for that! Great addition to provide more context.

Don't forget this part:

>(e) Failure To Report.—A provider that knowingly and willfully fails to make a report required under subsection (a)(1) shall be fined— (1) in the case of an initial knowing and willful failure to make a report, not more than $150,000; and (2) in the case of any second or subsequent knowing and willful failure to make a report, not more than $300,000.

I find these clauses at odds with one another in that the Failure to Report clause created a tangible duty upon the provider, which, were I a judge, would satisfy me that rhe provider was, in fact, deputized.

Does nobody actually read the legislation that is passed and realize that oops, I just passed am unconstitutional law.

That they include the construed... clause just solidifies for me that the legislators in question were trying to pull a fast one.

Post reply on HN