Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

121–130 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#121
post #93

Seems like the kids miss their chance at justice because of section 230 allowing platforms the freedom to remove whatever they want but not be responsible for what they keep or amplify. That is the problem with 230. Censorship is permitted and punishing the censor isn't. Twitter and Tiktok are literally microblog platforms that get away with removing good stuff and leaving evil because they "are not a publisher" whil…

You're conflating "what's illegal" with "what a private entity doesn't want". I don't like it any more than you do, but the first is very clear, the second is a bit harder to "solve".

[deleted]

Re: Apple defeats liability for not scanning iCloud for CSAM

#122

I am not a lawyer. There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example: * A: physical sexual abuse of children. B: possession or distribution of CSAM * A: drug trafficking or tax evasion. B: structured cash withdrawals The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A. It's my understanding that conv…

> one can be convicted of CSAM-related crimes related to paintings/drawings/created_art of fictional people. This isn't necessarily the case in the US, though I believe only for drawings. AI-generated CSAM probably wouldn't fly in a court of law. Regardless, it's a naive conception of a system of law to think of it as a utilitarian system of restitution in contexts of "this individual harmed this individual". In fact…

> The law is just as much about enforcing social mores and norms

This shouldn't be the case in a society that supposedly values liberty.

Re: Apple defeats liability for not scanning iCloud for CSAM

#123
post #14

Earlier quoted context omitted.

> It is crazy people think apple isnt on the side of privacy. > It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do. I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare qu…

I still also totally don't get their policy. Trying to avoid false positives by not firing until a threshold was hit (was it 20 images?) seemed insane from a PR position... rightly or wrongly, all it would take would be the wrong court case and you can see the headlines: "Apple says users can have up to 20 CSAM images on their phone before they'll tell police"

Imagine you have pictures of someones baptism and the kid was nude. Is it CSAM? I think the program would have to say use but morally I'd say no. The issue with client scanning is it has to assume the worst, or they are than liable. If its the person has 20+ different baptism of nude babys well huh that actually might be CSAM because the context of how that concentrated photos implies but even than its hard what if that person actually has 20 God Children its less crazy than one thinks... Especially if they have multiply phones from a single baptism.

You might not like pictures that way but honestly I think more important in procescuting CSAM is to go after the large sources of CSAM generation. Its trafficing in East Asia, and in Europe. I think weirdly America actually produces less CSAM in general because Americans are lot more off put by Sex than most other cultures. Abuse definitely happens in the US but making policy decisions like this produces bad policy.

Does iCloud rehost the photos to other people I don't really know because I use andriod tbh. If they are being rehosted (I assume to members of your contacts) that can be problematic but I think honestly the issue a lot more complex than just protect the children which the source of critic is a lot attacks against apples are coming from

Re: Apple defeats liability for not scanning iCloud for CSAM

#124
post #91

Earlier quoted context omitted.

> end to end encryption means no CSAM scanning Not true. There is the option of scanning on the device.

Owning your device (instead of the manufacturer, a set of unlisted governments, big software corporations, etc.) means no scanning.

It also means no banking app will work

Re: Apple defeats liability for not scanning iCloud for CSAM

#125
post #26

Earlier quoted context omitted.

I wonder if the judge would be in favor of companies proactively going into people's houses at random to check on their belongings, if they don't have inappropriate photos somewhere, or whatever. It's harder to do, but conceptually the same. So sad it's not being done. Very disturbing. They could do it when people are not at home. There'd no problem, nobody would even notice.

Kind of a bad analogy (not service related, no associated liability). A better one: what about rental property, like a business? Can the landlord randomly check for criminal behavior?

> Can the landlord randomly check for criminal behavior?

Absolutely not.

Re: Apple defeats liability for not scanning iCloud for CSAM

#126
post #14

Earlier quoted context omitted.

> It is crazy people think apple isnt on the side of privacy. > It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do. I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare qu…

I still also totally don't get their policy. Trying to avoid false positives by not firing until a threshold was hit (was it 20 images?) seemed insane from a PR position... rightly or wrongly, all it would take would be the wrong court case and you can see the headlines: "Apple says users can have up to 20 CSAM images on their phone before they'll tell police"

The practical problem is, without a threshold, they'd have an order of magnitude more false positives than 'real' detections, making the system useless.

Re: Apple defeats liability for not scanning iCloud for CSAM

#127

Earlier quoted context omitted.

> No matter how or why? That seems like a terrible mandate. Honestly shocked that anyone would even say this, but even giving you the benefit of the doubt here -- the one case where I could imagine this might not happen would be if you're a police officer investigating such cases. But they also have their own therapists dedicated/trained in police-specific issues.

Even if someone went browsing for it, yes that's illegal but there's no benefit in their therapist reporting them for just visiting terrible websites. But also there are definitely ways to get accidentally exposed. That's an absolutely awful thing to call the cops over.

I think you're demonstrating incredibly poor judgment here. CSAM is a crime with real victims. Even if your patient came across it innocently, someone is out there intentionally distributing it and that needs to be investigated.

Re: Apple defeats liability for not scanning iCloud for CSAM

#128
post #90

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

Apple is on the side of privacy if it serves their marketing. Which is why they would rather build and normalize CLIENT SIDE CONTENT SCANNING so they can continue to market iCloud as "secure and private". If Apple's interests sometimes align with ours then great. I'll take it. But don't attribute to this ~5 trillion dollar company some kind of altruism.

[deleted]

Re: Apple defeats liability for not scanning iCloud for CSAM

#129
post #14

Earlier quoted context omitted.

> It is crazy people think apple isnt on the side of privacy. > It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do. I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare qu…

I thought the client side scanning was to protect children? If it suspects an image is bad, it blurs it and pops up a warning including a link to resources to go to for help. Very different than trying to narc out users to the authorities.

There were two different technologies. One was client-side scanning for known CSAM, which created a huge backlash and is described here: https://educatedguesswork.org/posts/apple-csam-intro/

The other is detection of images that may contain nudity, whether sent or received, when the owner/admin/parent enables the feature. It is relatively uncontroversial and is described here: https://support.apple.com/en-us/105069

Re: Apple defeats liability for not scanning iCloud for CSAM

#130

Earlier quoted context omitted.

There's also the argument that CSAM can act as a gateway leading people from just being a pedophile in their head, to going out and doing something to some child.

Yes, it’s an argument but there’s zero data to support it, in fact the opposite. If this were true then widespread availability of pornography on the internet would have resulted in a massive increase in rape of adult females. When in fact, assault numbers have been on a steady decline for decades.

Why would general pornography lead to rape? Most pornography is not rape pornography. Would people watching a bunch of rape pornography lead to more rapes? I don't know, but that seems more likely than general pornography leading to rapes.

60% of respondents who were found looking for CSAM on the dark web stated that they were fearful that consuming CSAM would lead them to do something to a child in real life: https://doi.org/10.54501/jots.v1i2.29

Post reply on HN