Live data from Hacker News

Apple Photos phones home on iOS 18 and macOS 15

lapcatsoftware.com

941–950 of 1001 posts

Re: Apple Photos phones home on iOS 18 and macOS 15

#941
post #736

Earlier quoted context omitted.

Yeah, this is an insane proposal. I know GP may be imagining a smart populace walking away from Big Evil Facebook and X with heads held high, but the other 99% of sites are also doing the same cookie banner stupidity because it is roughly mandatory due to useless EU law (unless you’re not engaging at all in advertising even as an advertiser ). So, no more accessing your bank, power utility, doctor, college, etc. That…

I am happy to learn what I may have been imagining: thanks for that! The law has turned out to be useless, agreed — or at least, it has driven hard-to-navigate UX that we live through today. The intent could have taken us in a different direction with some care (i.e. mandating a clear, no-dark-pattern opt-out/opt-in ahead-of-time option a la DoNotTrack header that similarly failed): if web clients (browsers) were req…

That's precisely what https://en.wikipedia.org/wiki/EPrivacy_Regulation was supposed to be! As you can imagine, there are strong incentives to lobby against it, so it's almost a decade late already.

Whoever came up with an idea to attach CSAM scanning provision to it is an evil genius, what an incredible way to make sure it's not going to pass any time soon.

Re: Apple Photos phones home on iOS 18 and macOS 15

#942
post #643

Earlier quoted context omitted.

> This mindset is how we got those awful cookie banners. The only thing I've found awful is the mindset of the people implementing the banners. That you feel frustration over that every company has a cookie banner, is exactly the goal. The companies could decide that it isn't worth frustrating the user over something trivial like website analytics, as they could get that without having to show a cookie banner at all.…

[flagged]

Do you feel like your comment is responding to mine in good faith and using the strongest plausible interpretation? Because it sure feels like you intentionally "misunderstood" it.

Obviously the intention is not "to not improve user privacy at all" but to give companies and users the agency to make their own choices. Many companies seems to chose "user inconvenience" over "user privacy", and it now makes it clear what companies made that choice. This is the intention of the directive.

Re: Apple Photos phones home on iOS 18 and macOS 15

#943
post #465

Earlier quoted context omitted.

> Everyone lost their mind yet it was clearly laid out in the papers Apple released on it. And people working with CSAM and databases of CSAM have said it was a very bad idea.

Citation needed. As the latest news suggests the opposite.

> Citation needed.

The best one I remember is this one: https://www.hackerfactor.com/blog/index.php?/archives/929-On...

> As the latest news suggests the opposite.

What news?

Re: Apple Photos phones home on iOS 18 and macOS 15

#944
post #942

Earlier quoted context omitted.

[flagged]

Do you feel like your comment is responding to mine in good faith and using the strongest plausible interpretation? Because it sure feels like you intentionally "misunderstood" it. Obviously the intention is not "to not improve user privacy at all" but to give companies and users the agency to make their own choices. Many companies seems to chose "user inconvenience" over "user privacy", and it now makes it clear wha…

I didn't intend to criticize your description of the situation. My intent was to criticize the people who (allegedly) had that goal, because it has become clear that the result of the policy was not to cause user frustration and have that lead to companies improving their privacy practices. Instead, the result of the policy was simply to increase user frustration without improving privacy practies.

Re: Apple Photos phones home on iOS 18 and macOS 15

#945

Earlier quoted context omitted.

Once upon a time, I worked for a pretty big company (fortune 500ish) and had access to production data. When a colleague didn't show up at work as they were expected, I looked up their location in our tracking database. They were in the wrong country -- but I can't finish this story here. Needless to say, if an Apple employee wanted to stalk someone (say an abusive partner, creep, whatever), the fact that this stuff…

Your first story sounds like a good outcome. I doubt Apple employees could deduce location from the uploaded data. Having worked at FB I know that doing something like that would very quickly get you fired post 2016

It depends on your position.

Re: Apple Photos phones home on iOS 18 and macOS 15

#946
post #643

Earlier quoted context omitted.

> This mindset is how we got those awful cookie banners. The only thing I've found awful is the mindset of the people implementing the banners. That you feel frustration over that every company has a cookie banner, is exactly the goal. The companies could decide that it isn't worth frustrating the user over something trivial like website analytics, as they could get that without having to show a cookie banner at all.…

[flagged]

Not the goal of the regulations. The goal of the companies.

Re: Apple Photos phones home on iOS 18 and macOS 15

#947

Earlier quoted context omitted.

Consent is the key issue binding all. There is complete lack of consent when there is no opt-out and great degradation when the default is opt-out. Trust is the only means to consent. 1) Opt-in, Opt-survey, Opt-out is the only ternary to build trust. Survey is an active validator of trust and assists in low-bandwith communication. Question should be presented to the end user the first time using it or the next time t…

Yes - I understand but in many (or even most) cases, opt-in makes the data worthless. There's literally no point collecting it.

Building and growing trust makes the data less worthless to the point of being useful. More people will opt-in when they trust the company / the developer(s). Opt-in without a push, universally trust building in the community, keeps leading to this worthless data.

The only way I see moving forward would be community driven effort to build the trust through said means and or other ideas. This not an easy problem to solve and would take time.

*Even the USA agencies like the CDC and FBI must utilize bias data for the decision making since not all states and organizations self-report.

Re: Apple Photos phones home on iOS 18 and macOS 15

#948

Earlier quoted context omitted.

That whole incident was so misinformed. CSAM scanning takes place on the cloud with all the major players. It only has hashes for the worst of the worst stuff out there. What Apple (and others do) is allow the file to be scanned unencrypted on the server. What the feature Apple wanted to add was scan the files on the device and flag anything that gets a match. That file in question would be able to be decrypted on th…

I can't believe how uninformed, angry, and still willing to argue about it people were over this. The whole point was a very reasonable compromise between a legal requirement to scan photos and keeping photos end-to-end encrypted for the user. You can say the scanning requirement is wrong, there's plenty of arguments for that. But Apple went so above and beyond to try to keep photo content private and provide E2E enc…

> a legal requirement to scan photos

There is absolutely no such legal requirement. If there were one it would constitute an unlawful search.

The reason the provider scanning is lawful at all is because the provider has inspected material voluntarily handed over to them, and through their own lawful access to the customer material has independently and without the direction of the government discovered what they believe to be unlawful material.

The cryptographic functionality in Apple's system was not there to protect the user's prviacy, the cryptographic function instead protected apple and their datasources from accountability by concealing the fingerprints that would cause user's private data to be exposed.

Re: Apple Photos phones home on iOS 18 and macOS 15

#949

Earlier quoted context omitted.

The chance of a hash colliding is near 0%. The hashes are for some of the worst content out there, its not trying to detect anything else. Even so a human is in the loop to review what got a hit. Which is exactly currently happens now.

> The chance of a hash colliding is near 0% Until someone finds a successful collision attack. > Even so a human is in the loop to review what got a hit. Until shareholder/growth pressure causes them to replace that human with an AI.

> Until someone finds a successful collision attack.

Indeed, and within hours of the hash function being made available to me I developed a second preimage attack (strictly stronger than a collision attack)... allowing me to modify images in a visually non-objectionable way to match an arbitrary hash value.

> Until shareholder/growth pressure causes them to replace that human with an AI.

Indeed, but more than that:

The "human" is still a dire privacy loss. Perhaps Apple's review might have protected you from some erroneous reports to law enforcement, but does it protect you from an apple-employed stalker ex? does it protect you from paparazzi? Does it protect you from the double thinking ("do I photograph my kids playing in the sprinklers? do I take a nude photo of my spouse?") due knowing that your private activity is being watched?

One could easily argue that some AI second level review is an "improvement", which is another reason why your assumption that even that backstop would eventually be removed is a reasonable one.

Re: Apple Photos phones home on iOS 18 and macOS 15

#950

Earlier quoted context omitted.

That technology of perceptional hashes could have failed in numerous ways, ruining lives of law-abiding users along the way.

The chance of a hash colliding is near 0%. The hashes are for some of the worst content out there, its not trying to detect anything else. Even so a human is in the loop to review what got a hit. Which is exactly currently happens now.

> The chance of a hash colliding is near 0%.

The 'chance' is 100% -- collisions and even arbitrary second preimages have been constructed.

> The hashes are for some of the worst content out there, its not trying to detect anything else.

You don't know that because apple developed powerful new cryptographic techniques to protect themselves and their data providers from accountability.

Post reply on HN