Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

321–330 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#321

Earlier quoted context omitted.

This status quo is that a lot of countries want to use the CSAM argument to push privacy-invasive technology (cough UK) like e.g. forcing companies to allow the government to break E2EE to catch CSAM distributors. Apple made this feature while planning to move iCloud Photos to E2EE so that they could argue "look, we still catch x CSAM distributors with n < 0.x% false positive rate, even with E2EE photos. therefore yo…

I know "give them an inch, they take a mile" is a reductive comparison but I really can't see this way of thinking going any other way in the long term.

It isn't reductive. At the end of the day, that's exactly what it comes down to.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#322
post #219

Earlier quoted context omitted.

The extreme hysteria created by anything related to children often seems to be carte blanche to destroy privacy and implement backdoors in applications. Most child abuse comes from family members (which must be solved at the source), and the ultra extreme cases simply make awful law (doing away with E2EE or instituting mass surveillance to catch an incredibly small minority is absurd). Much like other 'tough on crime…

> The extreme hysteria created by anything related to children often seems to be carte blanche to destroy privacy and implement backdoors in applications. Yes, and you can tell because the proposed solutions attack privacy when alternative solutions exist. For example, simply deleting CSAM material from devices locally without involving any other parties could have achieved the goals without privacy violations. It ma…

Ah... But you see, now you're arguing in "bad faith" because you're trying to protect the kiddie diddlers!

...Understand I don't see it that way and applaud you for your way of thinking. I too have had to wrestle with the very uncomfortable "bed fellows" as it were that adhering to consistent application of principles inevitably results in.

The fact remains though that in a large swathe of the population, the ripping off and sacrifice of personal privacy is considered a small price to pay to inflict harm on that subpopulation. My issue comes in in that once you make the exception for one subpopulation, the slope is set.

Though even your "just delete it" has dystopian ramifications. Imagine that were implemented like Tianenmen Square? Recordings that are not blessed? You're still leaving in somebody's hands essentially executive control over what information can be allowed to exist, which is an unconscionably powerful lever to build.

This is one of those rare circumstances where "do nothing and clean up the mess" may be the most wise course of action.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#323

Earlier quoted context omitted.

ALL cloud providers are actively scanning all of your content right now, unless you specifically encrypt it yourself. It's a cost of doing business pretty much, you need to give the authorites access to customers data or they can go "but think of the children, there might be child abuse material in there!" and that's really damn hard to argue against. Thus: checking stuff on-device and keeping the cloud locked so tha…

> you need to give the authorites access to customers data At least some cloud providers require a warrant before doing so.

Of course they need a warrant. Officer Johnson from Randomtown Alabama can't just call up Google and tell they want access to everything in GDrive :D

But the point is that if the data is fully encrypted, no warrant will help against pure mathematics. A cloud provider cannot give something they have no access to.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#324
post #43

I haven't forgot about the guy that sent photos of his child to his doctor and was investigated for child pornography. With these systems, in my humble opinion, you are just one innocent photo at the beach away from your life turned upside down.

And Google to this day refuse to admit the mistake. They've even gone as far as to insinuate that he still is a pedo despite a police investigation clearing him.

Do you have a reference on that?

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#325

Earlier quoted context omitted.

> Most child abuse comes from family members (which must be solved at the source) Yes. Since becoming an abuser is a process and not a moment, part of the solution must be making access to CSAM much harder. > And no, we are not 'condoning' it when we declare E2EE an overall good thing. Agreed. I'm sorry if I worded things in a way that caused you to see an implication which was not intended. To be clear: E2EE is a go…

That position says that to achieve privacy, I must tolerate CSAM. I want both privacy and for us not to tolerate CSAM. Not true, you can have privacy and at the same time not tolerate child pornography, those are two perfectly compatible positions and arguably the current state. What you can not have - by definition - is privacy on the one hand and on the other hand no privacy in order to look for child pornography.…

...Now that, is a well conceived viewpoint, but I still argue policy-wise, that no penalties can conscionably be assessed for failure to engage in said activity without spreading the taint of deputization, which de-facto unmakes your stance. As a government deputy, you don't have that privacy. If you are not compelled to act as a deputy of the State, I can accept you escalating to NCMEC, but we also have to accept there is no recourse for providers who turn a blind eye to the whole thing.

Failure to recognize this perpetuates the fundamental inconsistency.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#326

Earlier quoted context omitted.

> you need to give the authorites access to customers data At least some cloud providers require a warrant before doing so.

Of course they need a warrant. Officer Johnson from Randomtown Alabama can't just call up Google and tell they want access to everything in GDrive :D But the point is that if the data is fully encrypted, no warrant will help against pure mathematics. A cloud provider cannot give something they have no access to.

> Of course they need a warrant.

Right, but your post kind of made it seem like they didn't. And with the CSASM stuff, they didn't need anything to match hashes. So what happens when that gets expanded to other types of content that they still don't need a warrant for? Like torrent files?

> But the point is that if the data is fully encrypted, no warrant will help against pure mathematics. A cloud provider cannot give something they have no access to.

Agreed, but most don't use encryption, and should still have privacy rights for their data.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#327

Earlier quoted context omitted.

Of course they need a warrant. Officer Johnson from Randomtown Alabama can't just call up Google and tell they want access to everything in GDrive :D But the point is that if the data is fully encrypted, no warrant will help against pure mathematics. A cloud provider cannot give something they have no access to.

> Of course they need a warrant. Right, but your post kind of made it seem like they didn't. And with the CSASM stuff, they didn't need anything to match hashes. So what happens when that gets expanded to other types of content that they still don't need a warrant for? Like torrent files? > But the point is that if the data is fully encrypted, no warrant will help against pure mathematics. A cloud provider cannot giv…

If they would have expanded it beyond CSAM, in that instance I would have joined the rest of the internet on the picket lines protesting against the system.

The point of the system would've been that EVERYONE'S content would've been encrypted in the cloud without them needing to do anything.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#328
post #144

Earlier quoted context omitted.

The hashes can not have collisions anymore, because modern forensics hash with both md5 and sha512, and both hashes must be together for use in any legal case. The odds of both of them having a collision is big enough to flat out say it's not going to happen. But even if there was an md5 hash collision back when md5 was the only one hash use, it still doesn't matter because upon viewing the image that matched, if it'…

I don't think it's an MD5 or SHA512 hash, since just changing one pixel would be enough to evade the scanner. My understanding is that it's heuristic similarity detection, which has a much wider footprint for collisions.

It was a hashing technique that would output similar outputs with similar inputs, maximizing collisions rather than minimizing it

That's why people were initially all up in arms about

But they didn't need to do that.

A regular hash where "just changing one pixel would be enough to evade the scanner" is already good enough

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#329
post #144

Earlier quoted context omitted.

>Both of these arguments are absolutely, unambiguously, correct. Oh, please. As if we couldn't just compare the hashes of the pictures people are storing against a CSAM database of hashes that gets regularly updated When this was proposed people would respond "But they could just mirror the pictures or cut a pixel off!" Who cares? You got that picture from some place in the dark web, and eventually someone will stumb…

The hashes can not have collisions anymore, because modern forensics hash with both md5 and sha512, and both hashes must be together for use in any legal case. The odds of both of them having a collision is big enough to flat out say it's not going to happen. But even if there was an md5 hash collision back when md5 was the only one hash use, it still doesn't matter because upon viewing the image that matched, if it'…

You just said yourself that hash collisions don't matter as "because upon viewing the image that matched, if it's not csam, it doesn't matter"

So when you say "a hash alone is meaningless, since in court there must be a presentation of evidence", you'd just present the image to court.

The hash is the trigger to call the authorities they handle the rest

And with a userbase the size of apple and people as pissy as reddit, you want to completely exclude a possibility of collisions or you'll get a repeat of the scenario we got in 2021

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#330
post #249

Earlier quoted context omitted.

Then how would they respond to warrants asking for all user identities that upload image x? "Sorry, no"? I don't think so. If they are served a valid warrant that isn't overbroad and they have the data, they are legally compelled to provide it. Whatever they said, it was probably worded to give you this impression, without actually saying that. Apple is extremely careful and goes to great pains to actively mislead an…

They confirmed here: https://9to5mac.com/2021/08/23/apple-scans-icloud-mail-for-c... Apple clearly has very limited ongoing scanning because they report on the order of hundreds of instances of CSAM to NCMEC every year whereas other services with pervasive scanning report on the order of tens of millions of instances. It’s ok, you are one of the vast majority of people commenting on this topic while reasoning from fa…

Nothing in this article from Apple says that they don't scan iCloud Photos, and many things strongly suggest that they do.

The headline says they don't scan iCloud Photos, but I don't see the statements from Apple saying that. The media often misreports on Apple's comments because Apple's expert at inducing the media to misreport in ways that are favorable to Apple.

Post reply on HN