Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

261–270 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#262

Earlier quoted context omitted.

Yes, but to OP's point: this was patently obvious from the onset. Even here the comments at the time [1] pointed to all sorts of potential misuse, political or religious prosecution, dystopian cases of false positives, and that this would leave the door open to future government escalation beyond CSAM. How could they not see that they would have a giant backlash on their hands? Did they overestimate their ability to…

I think Apple was doing the exact opposite. They wanted to do the __least possible thing__ in order to stave away the far worse outcome of intelligence departments using the "it's for our children" excuse to pressure elected representatives to vote for back doors on consumer encryption. The ridiculous thing is that Apple's proposal was functionally identical to what other platform vendors (e.g. Google, Microsoft) wer…

Signal and Meta (WhatsApp) don’t scan your messages. Apple’s actions have shown they are untrustworthy, and even if they’ve reversed this particular decision, compromising on principle has put authoritarians on notice they are open to compromise in the future, like the UK’s horrific Online Safety Bill.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#263

Earlier quoted context omitted.

Apple was concerned about governments using the excuse of CSAM to pass laws which would force Apple to weaken encryption across the board. Whether this was the right response to such concern is something I’m not unsympathetic towards. Certainly I think it’s reasonable to say that Apple was trying to thread a needle in a way which was never going to please everyone, even if it somehow turns out to have been the least-…

Yes, but to OP's point: this was patently obvious from the onset. Even here the comments at the time [1] pointed to all sorts of potential misuse, political or religious prosecution, dystopian cases of false positives, and that this would leave the door open to future government escalation beyond CSAM. How could they not see that they would have a giant backlash on their hands? Did they overestimate their ability to…

> How could they not see that they would have a giant backlash on their hands? Did they overestimate their ability to get away with the "it's for our children" excuse this badly?"

I imagine it wasn't an environment where one could argue those concerns on fair grounds without it being seen as enabling CSAM and shot down. I also imagine it's enticing to call their competitors' products "pedo-phones".

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#264
post #23

> "Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit" > "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types." Yes, and it was patently obviou…

I want to be clear that I agree with you and I am not providing this explanation as an excuse for Apple, but merely as an explanation for what might have happened with the timeline: first they announced they were doing this, a bunch of us said "no this is the first step towards breaking e2e entirely", and THEN this year there was the high-profile issue--note that I am not saying it is a new issue, but merely that it was suddenly a high-profile one that actually caused a lot of press and backlash--with the laws in the UK and/or Australia or whatever that showed we were all correct, and so I'd guess even the most ardent "I am smarter than everyone" person at Apple finally went "ah damn I was wrong".

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#265
post #262

Earlier quoted context omitted.

I think Apple was doing the exact opposite. They wanted to do the __least possible thing__ in order to stave away the far worse outcome of intelligence departments using the "it's for our children" excuse to pressure elected representatives to vote for back doors on consumer encryption. The ridiculous thing is that Apple's proposal was functionally identical to what other platform vendors (e.g. Google, Microsoft) wer…

Signal and Meta (WhatsApp) don’t scan your messages. Apple’s actions have shown they are untrustworthy, and even if they’ve reversed this particular decision, compromising on principle has put authoritarians on notice they are open to compromise in the future, like the UK’s horrific Online Safety Bill.

Pointing out a few app vendors simply isn't impressive. Of course some app vendors can take a stand against mid-tier governments. It's great marketing for them, and the corporate risk isn't so high. It's the platform vendors which have much at stake.

And of the three big platform vendors, two of them already scan private photos for CSAM right now — Google and Microsoft. Yet nobody is outraged because nobody actually cares. There's no logical consistency. Google and Microsoft can implement scanning and there's no outrage. Apple went to great lengths to tell everyone exactly what they were proposing to do before they did it, and all the online people are outraged and calling Apple untrustworthy. Sure, whatever.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#266
post #193

I'm curious about the new parental control features they announced at the same time as the iCloud photo scanning. My recollection is that when they withdrew the iCloud scanning they also withdrew the new parental controls. I'm curious why they also withdrew those. For those who don't remember the parental control, which were largely overshadowed by the controversy over the cloud stuff, they were to work like this: 1.…

> if it reaches step 6 it violates the privacy of the person sending Let's say the parents are abusive, and someone wants to talk with the child about that (via chat, for some reason). Now, if the algorithms sometimes incorrectly flag private messages that were in fact safe -- could that be mitigated by letting the sender know: "Your message will be scanned and possibly shown to the parents of the recipient" before t…

introducing waze for predators

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#267
post #193

I'm curious about the new parental control features they announced at the same time as the iCloud photo scanning. My recollection is that when they withdrew the iCloud scanning they also withdrew the new parental controls. I'm curious why they also withdrew those. For those who don't remember the parental control, which were largely overshadowed by the controversy over the cloud stuff, they were to work like this: 1.…

I imagine they’d withdraw it because it’s a total PR nightmare. “Apple knew my 14 year old was receiving sexual material and did nothing about it?!”

It might’ve served the greater good of bringing home to parents that their kids are, in fact, old enough to be sexual beings and suppression of their sexuality just isn’t possible anymore. Maybe that would lead to fewer cases of kids like the one in my classroom yesterday, who had just learned at the ripe old age of 14 in the 9th grade that he was going to be a father. The proud mother will join him in high school next year, after she completes the 8th grade. If she completes it, I suppose.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#268
post #23

> "Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit" > "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types." Yes, and it was patently obviou…

>what's your actual problem here?

Post Steve Jobs Apple, especially after Scott Forstall and Katie Cotton left. ( Along with a few other top executives) Tim Cook's Apple were left with people of Harmony. These left aligning, DEI focus people have the same characteristic, their way is for the force of good, hence their way is the only way. Same as early Google in the 00s. ( Privacy is a fundamental human right? Actively securing and promoting Chinese components in their supply chains. )

I am sure CSAM started with good intention. As with most ideals do. But fundamentally they don't work in this complex world.

All roads to hell are paved with good intention.

I hope there are still enough of Steve Jobs' conviction left inside Apple.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#269
post #262

Earlier quoted context omitted.

Signal and Meta (WhatsApp) don’t scan your messages. Apple’s actions have shown they are untrustworthy, and even if they’ve reversed this particular decision, compromising on principle has put authoritarians on notice they are open to compromise in the future, like the UK’s horrific Online Safety Bill.

Pointing out a few app vendors simply isn't impressive. Of course some app vendors can take a stand against mid-tier governments. It's great marketing for them, and the corporate risk isn't so high. It's the platform vendors which have much at stake. And of the three big platform vendors, two of them already scan private photos for CSAM right now — Google and Microsoft. Yet nobody is outraged because nobody actually…

Neither Google nor Microsoft operate a secure messaging platform that matters (email, yes, but email security is a lost cause), unlike WhatsApp (and Facebook Messenger), iMessage, Telegram or Signal. I'm not giving Google & Microsoft a pass, they're just irrelevant for the discussion at hand.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#270

Earlier quoted context omitted.

I was looking for that! Great addition to provide more context.

Don't forget this part: >(e) Failure To Report.—A provider that knowingly and willfully fails to make a report required under subsection (a)(1) shall be fined— (1) in the case of an initial knowing and willful failure to make a report, not more than $150,000; and (2) in the case of any second or subsequent knowing and willful failure to make a report, not more than $300,000. I find these clauses at odds with one anot…

> I find these clauses at odds with one another in that the Failure to Report clause created a tangible duty upon the provider, which, were I a judge, would satisfy me that the provider was, in fact, deputized.

Absolutely not. That section requires a report under the circumstances where a provider has obtained “actual knowledge of facts and circumstances” of an “apparent violation” of various code sections (child porn among others). It doesn’t place on the provider the burden of seeking out that knowledge. In other words, it covers the cases where, for example, a provider receives a report that they are hosting a child porn video and are pointed to the link to it. Providers can’t jam their fingers in their ears and shout LALALA when they’re told they’re hosting (or whatever) CSAM and given the evidence to support it. They don’t have to do anything at all to proactively find it and report it, however.

Think of it like this. I, as a high school, teacher, am a mandated reporter of child abuse. It’s literally a crime (a misdemeanor) for me not to report suspected child abuse. But I don’t have to go out and suss out whether any of my students are being abused. That doesn’t make me a state actor for 4th Amendment purposes (although I am otherwise, because I am a public school teacher, but that’s a different issue).

Post reply on HN