Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

931–940 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#931

Earlier quoted context omitted.

I can't believe how uninformed, angry, and still willing to argue about it people were over this. The whole point was a very reasonable compromise between a legal requirement to scan photos and keeping photos end-to-end encrypted for the user. You can say the scanning requirement is wrong, there's plenty of arguments for that. But Apple went so above and beyond to try to keep photo content private and provide E2E enc…

> a legal requirement to scan photos Can you provide documentation demonstrating this requirement in the United States? It is widely understood that no such requirement exists. There's no need to compromise with any requirement, this was entirely voluntary on Apple's part. That's why people were upset. > I can't believe how uninformed Oh the irony.

> Can you provide documentation demonstrating this requirement in the United States?

PROTECT Act of 2003 - Details CSAM materials as being illegal which is enforced by FBI + ICE.

Also NCMEC which is a non-profit created by the US government that actively works in this area.

Re: Apple Photos phones home on iOS 18 and macOS 15

#932

Earlier quoted context omitted.

From my understanding, it didn't scan all of the files on the device, just the files that were getting uploaded to Apple's iCloud. It was set up to scan the photos on the device because the files were encrypted before they were sent to the cloud and Apple couldn't access the contents but still wanted to try to make sure that their cloud wasn't storing anything that matched various hashes for bad content. If you never…

Your understanding is correct, as was/is the understanding of people critical of the feature. People simply don't want their device's default state to be "silently working against you, unless you are hyperaware of everything that needs to be disabled". Attacks on this desire were felt particularly strongly due to Apple having no legal requirement to implement that functionality. One also can't make the moral argument…

> People simply don't want their device's default state to be "silently working against you

That was the misconception of what was happening though.

Nothing happens on your device. Only when it gets to the cloud. It just puts a flag on the picture in question to have the cloud scan it.

Which is exactly what happens before Apple suggested it and happens now. Except it does it for all your files.

> One also can't make the moral argument that the "bad content" list only included CSAM material, as that list was deliberately made opaque. It was a "just trust me bro" situation.

CSAM database is run by Interpol. What evidence do you have that they are not being honest?

Re: Apple Photos phones home on iOS 18 and macOS 15

#933

Earlier quoted context omitted.

That whole incident was so misinformed. CSAM scanning takes place on the cloud with all the major players. It only has hashes for the worst of the worst stuff out there. What Apple (and others do) is allow the file to be scanned unencrypted on the server. What the feature Apple wanted to add was scan the files on the device and flag anything that gets a match. That file in question would be able to be decrypted on th…

> What the feature Apple wanted to add was scan the files on the device and flag anything that gets a match. This is not the revelation you think it is. Critics understood this perfectly. People simply did not want their devices scanning their content against some opaque uninspectable government-controlled list that might send you to jail in the case of a match. More generally, people usually want their devices worki…

> People simply did not want their devices scanning their content against some opaque uninspectable government-controlled list that might send you to jail in the case of a match.

Again I feel like many people just didn't read/understand the paper.

As it stands now all your files/videos are scanned on all major Cloud companies.

Even if you get a hit on the database the hash doesn't put you in jail. The illegal materials do and a human reviews that before making a case.

Re: Apple Photos phones home on iOS 18 and macOS 15

#934
Don't be too worried about what they collect per se they all do and you mostly won't know. Let's worry about how they manage and use it. When it comes to Apple specifically - homomorphic encryption is "common" and well done - it how do they use this encrypted data is the key...

Re: Apple Photos phones home on iOS 18 and macOS 15

#935
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

So you don't want a browser?

Re: Apple Photos phones home on iOS 18 and macOS 15

#936
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

So you don't want a browser?

A browser (without telemetry) is surely a good definition of something that doesn't initiate network calls before user intent

Re: Apple Photos phones home on iOS 18 and macOS 15

#937

Earlier quoted context omitted.

That technology of perceptional hashes could have failed in numerous ways, ruining lives of law-abiding users along the way.

The chance of a hash colliding is near 0%. The hashes are for some of the worst content out there, its not trying to detect anything else. Even so a human is in the loop to review what got a hit. Which is exactly currently happens now.

> The chance of a hash colliding is near 0%

Until someone finds a successful collision attack.

> Even so a human is in the loop to review what got a hit.

Until shareholder/growth pressure causes them to replace that human with an AI.

Re: Apple Photos phones home on iOS 18 and macOS 15

#938
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

So you don't want a browser?

Browsing the Internet is explicit intent! Some of the stuff enabled by JavaScript definitely tows the line but at the very least that's not really the direct fault of the browser.

Re: Apple Photos phones home on iOS 18 and macOS 15

#939
post #292

What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first . All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in. Trust in software will continue to erode until software stops treating end users and their data…

The shorter answer is that it's your data, but it's their service. If you want privacy, you should use your own service.

And for how cheap and trivial syncing photos is, any mandatory or exclusive integration of services between app/platform/device vendors needs to be scrutinized heavily by the FTC.

Re: Apple Photos phones home on iOS 18 and macOS 15

#940

Earlier quoted context omitted.

"All it takes is for 50% of the internet users to stop visiting web sites with them..." You've written that like it's a plausible and likely scenario.

I think it's very unlikely. "All it takes" was tongue in cheek. (If it was likely, it would have already happened)

Apologies, I read your comment like you'd written it, not like you've retro-actively decided you'd written it.
Post reply on HN