Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

241–250 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#241

Earlier quoted context omitted.

> There are also ways to detect matches even with e2ee By definition, encryption (with unique user keys) means you can't infer nor check what the content of the message is. Not without client cooperation, which is what this feature would have been.

This is what I was recalling, this method gives you a clever way to do it using the file itself as the key: > “Convergent encryption solves this problem in a very clever way: “The way to make sure that every unique user with the same file ends up with an encrypted version of that file that is also identical is to ensure they use the same key. However, you can’t share keys between users, because that defeats the entir…

Could one defeat this by changing a single byte in their file?

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#242

Earlier quoted context omitted.

> There are also ways to detect matches even with e2ee By definition, encryption (with unique user keys) means you can't infer nor check what the content of the message is. Not without client cooperation, which is what this feature would have been.

This is what I was recalling, this method gives you a clever way to do it using the file itself as the key: > “Convergent encryption solves this problem in a very clever way: “The way to make sure that every unique user with the same file ends up with an encrypted version of that file that is also identical is to ensure they use the same key. However, you can’t share keys between users, because that defeats the entir…

This still suffers the same problems as the original proposal. Specifically, Apple could still be pressured or forced by governments to check for non-CSAM images. And using cryptographic hashing means they can’t detect altered files, while using perspective hashing leaves them open to false positives.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#243

I haven't forgot about the guy that sent photos of his child to his doctor and was investigated for child pornography. With these systems, in my humble opinion, you are just one innocent photo at the beach away from your life turned upside down.

That scenario would've been impossible with Apple's system.

It would’ve been less likely, not impossible. Perceptive hashing absolutely has issues with false positives.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#244
post #23

> "Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit" > "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types." Yes, and it was patently obviou…

This is truly mind-boggling because it’s Apple and such an important topic. We are right to expect better from these bright people.

It worries me that Sarah Gardner seems to be truthful when she hints at that no one at Apple reached out to her after Apple killed the plan in December 2022. She must have also missed articles like the one at The Verge [1].

Gardner’s message to Tim is dated 2023-08-30 03:24:37 (CEST).

Erik Neuenschwander's reply was printed out 2023-08-31 14:41:00 (probably PDT).

So that’s a period of about 44 hours that the print out [0] represents.

It would be helpful to know the time when Apple’s reply was sent to deduce whether Apple had time for additional deliberations before writing the email to Gardner.

Regardless, as reported by The Verge they obviously had deliberations shortly after the public outcry, killed the plan in December 2022, and then presumably failed to inform Gardner about the reasons.

If that’s the case, far smaller companies have checks and balances in place to keep that from happening.

[0]: https://s3.documentcloud.org/documents/23933180/apple-letter...

[1]: https://www.theverge.com/2022/12/9/23500838/apple-csam-plans...

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#245

Earlier quoted context omitted.

No, no, no. There is no parallel to be drawn between better encryption and worse outcomes for kids. Should we also outlaw high-performance cars because these sometimes serve as effective getaway vehicles for criminals? CSAM producers and consumers should be found and punished via old-fashioned methods. How was this done in the past? Did we just never catch any human traffickers / rapists? No, we had detectives who we…

> Should we also outlaw high performance cars Yes. If consumer cars’ speed was capped to 100 mph it would affect a very small percentage of people and zero legitimate use. The difference with encryption is that while it protects criminals from the police, it also protects legitimate users from criminals.

Plenty of people who own performance cars take them to racetracks where driving above 100mph is entirely legitimate. So doing this wouldn't affect zero legitimate use.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#246

Earlier quoted context omitted.

Because the idea is that the iCloud data would be encrypted so their servers couldn’t scan it. With the plan being they would do on device scanning of photos that were marked as being stored on iCloud. It’s objectively better than what google does but I’m glad we somehow ended up with no scanning at all.

that sounds strange, I mean i'm not sure what's the big difference. If data is scanned on icloud, this means it's not encrypted, got it, if scanned on devices, data is fully encrypted on icloud, but apple has access by scanning it on devices and can send unencrypted matches, so it behaves as an unencrypted system, that can be altered at apple's will, just like icloud... but still, why scanning locally only if icloud…

> Since policy is meant to 'catch bad ppl', why limit to icloud option and not scan all the time

The policy is meant to ensure Apple's servers are not storing and distributing CSAM, not that Apple wants to become a police investigative force.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#247

Earlier quoted context omitted.

That scenario would've been impossible with Apple's system.

It would’ve been less likely, not impossible. Perceptive hashing absolutely has issues with false positives.

No, it would've been impossible. One photo match wouldn't have been enough to trigger any sort of response within Apple's system.

And that's ignoring the fact that his photo wouldn't have matched anyway because it isn't in any CSAM database.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#248

Earlier quoted context omitted.

> Should we also outlaw high performance cars Yes. If consumer cars’ speed was capped to 100 mph it would affect a very small percentage of people and zero legitimate use. The difference with encryption is that while it protects criminals from the police, it also protects legitimate users from criminals.

Plenty of people who own performance cars take them to racetracks where driving above 100mph is entirely legitimate. So doing this wouldn't affect zero legitimate use.

Not to distract from the topic but vehicles cost orders of magnitude more could be geofenced like $500 rental scooters so the engine computer would recognize the handful of high-speed tracks in the region.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#249
post #13

The vast majority (99%+) of iCloud Photos are not e2ee and are readable to Apple. You can rest assured that they are scanning all of it serverside for illegal images presently. The kerfuffle was around clientside scanning, something that it has been reported that they dropped. I have thus far seen no statements from Apple that they actually intended to stop the deployment of clientside scanning. Serverside scanning h…

To be clear, they positively stated that they do not perform any server side scanning when this feature was first announced.

Then how would they respond to warrants asking for all user identities that upload image x? "Sorry, no"? I don't think so. If they are served a valid warrant that isn't overbroad and they have the data, they are legally compelled to provide it.

Whatever they said, it was probably worded to give you this impression, without actually saying that. Apple is extremely careful and goes to great pains to actively mislead and deceive whilst avoiding actual lies.

Could you please link to or quote these statements from Apple? I would bet any money they say something different than what you claim, a "not wittingly"-style hedge.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#250

Earlier quoted context omitted.

> There are also ways to detect matches even with e2ee By definition, encryption (with unique user keys) means you can't infer nor check what the content of the message is. Not without client cooperation, which is what this feature would have been.

This is what I was recalling, this method gives you a clever way to do it using the file itself as the key: > “Convergent encryption solves this problem in a very clever way: “The way to make sure that every unique user with the same file ends up with an encrypted version of that file that is also identical is to ensure they use the same key. However, you can’t share keys between users, because that defeats the entir…

That makes me happy, because 12 years ago here on HN I posted a comment [1] outlining how a Dropbox-like service could be implemented that stored user files encrypted, with the service not having the keys, yet allow for full deduplication when different users were storing the same file, while still supporting the normal Dropbox sharing features.

The file encryption part was based on using a hash of the file as the key.

It's always nice to later find out that one's quick amateur idea turns out to be an independent rediscovery of something legit. Now that I've learned it is called "convergent encryption" Googling tells me it it goes back to 1995 and a Stac patent.

[1] https://news.ycombinator.com/item?id=2461713

Post reply on HN