Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

141–150 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#141

I am not a lawyer. There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example: * A: physical sexual abuse of children. B: possession or distribution of CSAM * A: drug trafficking or tax evasion. B: structured cash withdrawals The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A. It's my understanding that conv…

At least in the US, fictional content is legal even if it depicts minors sexually: https://en.wikipedia.org/wiki/Ashcroft_v._Free_Speech_Coalit... There have been a handful of convictions based on fictional content, but usually the defendants also possessed real CSAM so there wasn't much point in contesting the charges over fictional images.

Clicking on a page linked in your article, the PROTECT Act of 2003[1] (passed a year later), I see:

> The PROTECT Act includes prohibitions against obscene illustrations depicting child pornography, including computer-generated illustrations, also known as virtual child pornography. Previous provisions outlawing virtual child pornography... had been ruled unconstitutional... The PROTECT ACT attached an obscenity requirement under the Miller test or the variant test noted above to overcome this limitation.

Which, if I'm reading it right, means that GP was correct in saying "conviction of CSAM-related crimes do not require any physical act to have ever occurred to any real person"

[1] https://en.wikipedia.org/wiki/PROTECT_Act_of_2003

Re: Apple defeats liability for not scanning iCloud for CSAM

#142
post #8

I know creating a throwaway to hide your name for an opinion is a bad manner, but this one is one I really don’t want linked back to me The VAST majority of “CSAM” is consensually created and exchanged by teens. Their future selves and their parents form this pressure group attacking everyone’s liberty and privacy to try to undo the downsides of choices they made themselves with full knowledge of what could happen. T…

I completely agree with you, but I do think that these teens do not have good opsec around these photos. It’s like the revenge porn problem but way worse. A teenager sending a nude selfie to a friend who then later shared these images non-consensually is a much bigger problem than if the same thing happened to adults.

I don’t have any ideas for a solution, but I suspect that the heightened focus on CSAM is really compensating for the fact that we don’t have solutions for revenge porn.

Re: Apple defeats liability for not scanning iCloud for CSAM

#143
post #8

I know creating a throwaway to hide your name for an opinion is a bad manner, but this one is one I really don’t want linked back to me The VAST majority of “CSAM” is consensually created and exchanged by teens. Their future selves and their parents form this pressure group attacking everyone’s liberty and privacy to try to undo the downsides of choices they made themselves with full knowledge of what could happen. T…

I think you’re right, but from another angle. In the state where I lived way back when, a state representative put forth a bill to explicitly make e-CSAM illegal. I guess it was already illegal for print media and this covered a gap in the law about cell phone pics, etc. Thing is, it had no allowance for the age of the picture taker, or even whether the picture taker was the photo subject. If a 16 year old girl took…

> I still don’t want to throw kids in prison or remove all traces of a right to privacy in our haste to sun-yeet them.

The one messy corner of this is the "strict liability" for this type of material. An underage kid can take a nude photo, send it to an adult, and then the adult can criminally liable for just having it, even if he deleted it as soon as he saw it. Either both parties involved in handing something for which there is "strict liability' need to be held accountable, or "strict liability" has to be changed so a person isn't liable if he deletes or reports the material as soon as he first becomes aware of it. And this isn't likely to happen because it would provide a plausible defense for every one criminally charged.

Re: Apple defeats liability for not scanning iCloud for CSAM

#144

I am not a lawyer. There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example: * A: physical sexual abuse of children. B: possession or distribution of CSAM * A: drug trafficking or tax evasion. B: structured cash withdrawals The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A. It's my understanding that conv…

A: cyber crimes or other digital crimes. probably applies to many of the other crimes you mentioned too. B: privacy

Re: Apple defeats liability for not scanning iCloud for CSAM

#145
sigh

Once again, someone (in this case, the judge of this case) asks if we can meet in the middle on whether or not private communications are actually private.

To be clear: this is not a limitation of nerds' imagination. This is a limitation of physics. A person is either party to a communication (and thus can decrypt it) or is not (and thus cannot). If you demand Apple scan encrypted photos for CSAM, what you are demanding is that Apple be party to every communication done with an iPhone. There is no middle ground on encryption, there will never be a middle ground on encryption, and I will hold this truth on my deathbed.

There is no "encrypted but crackable" - if the CIA can crack it at all, we're only a few years away from some kid's gaming rig doing the same thing. There is no "secure golden key" - if there was, you could buy it in the same section of Amazon that sells copies of the TSA master key that opens all luggage locks.

Personally, the next time a government demands decryption keys, I think Apple should just set all iCloud photo libraries in that country to public and say "Sorry, your politicians made private photos illegal, take it up with them". Obviously, telegraph this far in advance and give users time to actually delete their cloud-hosted photos first. But definitely do not pretend like you can keep a secret with a government bureaucracy of hundreds of thousands of people.

But then again, Apple also capitulated (good meaning) to the EU on third-party app distribution, so Apple has a lot less of a spine than they let on. At least Google actually stayed out of China.

Re: Apple defeats liability for not scanning iCloud for CSAM

#146

Earlier quoted context omitted.

Only if the company misleads and adds a backdoor to the front-end app (thus this entire discussion). If the company is misleading, any encryption technology is irrelevant anyway.

Yes that's exactly his point. E2E is often sold as preventing the owners of the server from being able to read the messages at all, even if they are evil and misleading you. That's obviously only the case if they aren't also the sole providers of the "ends".

There are actual methods to do this though just not sure anyone does it yet.

1. 3rd party audit of a current repo hash 2. Public hosting of hash 3. Modern attested compute can check the current startup and running code hash and return to the user for their own checks. 4. User encrypts the last known hash they used or trust a 3rd party to perform the check like azure's methods.

Another way is to open source it and repeat 2/3/4

The way around that requires either a backdoor in attested hardware which would be wild if discovered because it's the same tech protecting companies and governments most sensitive info so they're all incentivised to audit that.

Re: Apple defeats liability for not scanning iCloud for CSAM

#147

I am not a lawyer. There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example: * A: physical sexual abuse of children. B: possession or distribution of CSAM * A: drug trafficking or tax evasion. B: structured cash withdrawals The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A. It's my understanding that conv…

> CSAM (“see-sam”) refers to any visual content—photos, videos, livestreams, or AI-generated images—that shows a child being sexually abused or exploited. Child sexual abuse material (CSAM) is not “child pornography.” It’s evidence of child sexual abuse [1]

I can't wrap my head around how AI-generated imagery is evidence of child sexual abuse (CAS). How are you abusing a real child by generating an image of a fake one?

[1] https://rainn.org/get-the-facts-about-csam-child-sexual-abus...

Re: Apple defeats liability for not scanning iCloud for CSAM

#148

IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it. Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt…

Beyond the privacy marketing angle, e2e allows companies with global exposure to sidestep any unpleasantness when they get a subpoena from Bumfuck, Nowhere. Sure, the NSA, GCHQ and Mossad have a way to exfiltrate the unencrypted data but proprietary e2e is a good thing for most people IMO. Shifts the risk from "my messages are theoretically available to most law enforcement in the globe" to "YOU’RE STILL GONNA BE MOS…

Side channel is academic at best.

Watching memory changing on a complex code base without having said code base is near impossible.

1. Run code 2. Watch memory changes 3. Correlate those to real data

If your code is doing anything complicated that's an intense thing to determine. If you're deep enough for a side channel there's likely a lot easier way of getting in.

Re: Apple defeats liability for not scanning iCloud for CSAM

#149
post #108

Earlier quoted context omitted.

> It proved that it was technically feasible, and was "privacy preserving". Didn't their paper disproved by reversing the perceptual hashes to reveal blurred version of the images being hashed, and Apple basically said "that's fair, it's not as robust as we wanted, let's visit this later"? If not, I'll happily stand corrected, but please share sources. Addenda: - Apple's original paper: https://web.archive.org/web/20…

The paper you linked doesn’t reveal blurred versions of the images being hashed. It does train a classifier to determine which of 1,000 ImageNet classes an image belongs to, which “achieved a top-1 test accuracy of 4.34%”.

Then, that’s the wrong paper. I’ll find it and link it as a reply to this comment. Probably tomorrow morning.

Re: Apple defeats liability for not scanning iCloud for CSAM

#150

Earlier quoted context omitted.

Yes, in the sense that you have a legal doctor-patient privilege that binds what they can share with whom. There's not really an Apple cloud user privilege. No, in the sense that your therapist is still required to report you to the police in various situations where you pose an immediate threat to yourself or others, etc.

> No, in the sense that your therapist is still required to report you to the police in various situations where you pose an immediate threat to yourself or others, etc. And therapists are legally mandated to report you if you told them you viewed or possessed CSAM.

That's not generally true. From [0]

> Across most states, viewing CSEM alone is generally not a mandated-reporting trigger; reporting becomes obligatory when disclosures involve an identifiable child being abused or used to produce material.

> California’s CANRA imposes a distinct duty to report electronic access (download/stream) with identifying patient information, upheld against privacy challenges based on compelling state interest.

[0] https://www.psychiatrictimes.com/view/mandatory-reporting-ch...

Post reply on HN