Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

201–210 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#201

Earlier quoted context omitted.

> one can be convicted of CSAM-related crimes related to paintings/drawings/created_art of fictional people. This isn't necessarily the case in the US, though I believe only for drawings. AI-generated CSAM probably wouldn't fly in a court of law. Regardless, it's a naive conception of a system of law to think of it as a utilitarian system of restitution in contexts of "this individual harmed this individual". In fact…

> The law is just as much about enforcing social mores and norms This shouldn't be the case in a society that supposedly values liberty.

There is no _society_ without _social_ mores and norms.

Re: Apple defeats liability for not scanning iCloud for CSAM

#202

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

I think it's similar with other liability issues, e.g., when a company happens to "lose" customer data through a breach. They will be on the hook for not having certain audits and certifications at regular intervals. Practically never will anyone be feeling any pain due to absolute disregard for basic common sense precautions to prevent issues in the first place. So usually, the pattern is that issues that can be outsourced to insurance will be handled by compliance departments - which don't care about the actual problems, just that the fallout from them is "managed" accordingly.

Re: Apple defeats liability for not scanning iCloud for CSAM

#203
post #141

Earlier quoted context omitted.

Clicking on a page linked in your article, the PROTECT Act of 2003[1] (passed a year later), I see: > The PROTECT Act includes prohibitions against obscene illustrations depicting child pornography, including computer-generated illustrations, also known as virtual child pornography. Previous provisions outlawing virtual child pornography... had been ruled unconstitutional... The PROTECT ACT attached an obscenity requ…

But crucially: > However, the court did not reverse its holding in Ashcroft v. Free Speech Coalition as to virtual child pornography which is not obscene under the Miller standard

> virtual child pornography which is not obscene

Does it surprise anyone else that this is a legal possibility?

Re: Apple defeats liability for not scanning iCloud for CSAM

#204

I am not a lawyer. There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example: * A: physical sexual abuse of children. B: possession or distribution of CSAM * A: drug trafficking or tax evasion. B: structured cash withdrawals The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A. It's my understanding that conv…

I don't think there's a particular connection between indirect enforcement mechanisms and inability to detect the crime, though:

- Structured transactions are illegal because we put a minimum on the amount of cash that has to move before government financial surveillance applies. The alternative (at least, one acceptable to the state) would be that the government knows every transaction you make[0] no matter the size. Since we don't want that, it has to be illegal to lie about the size of a transaction. Furthermore, the harder it is to get away with structuring your transactions, the more legible the financial system becomes and the easier it is to catch drug dealers.

- Pedophiles have not stopped possessing or distributing CSAM to reduce their legal liability. Actually, this argument ignores the main reason why pedophiles store and trade CSAM around in the first place: it's specifically to scare victims into silence and revictimize those who tell the cops. In fact, this is why we stopped calling it "child porn" and started calling it "child sexual abuse material" - because it is specifically material designed to sexually abuse children by way of it's mere existence.

If you're a "no touch" pedophile (they do exist!) that's still trading real CSAM around, well... Congratulations, Nobuhiro Watsuki, award-winning author of the hit samurai manga Rurouni Kenshin, you're still doing the dirty work for the full-contact pedo who recorded the damned thing.

As for drawn child porn, involving fictional characters (i.e. not CSAM), it is legal in certain jurisdictions. Notably, America, where the 1st Amendment errs on the side of creative expression[1]; and Japan, the thinking man's Epstein Island, where... I actually don't know why the fuck Japan is so weirdly tolerant of all this sick lolicon trash. Hell, Watsuki didn't even get cancelled when it came out he had 100 DVDs worth of actual CSAM.

There's an additional layer to this, though, in that for all the crimes you brought up, there's been a history of active state complicity in the crime:

- The CIA is a drug trafficking gang that happens to moonlight as a government intelligence agency

- A good chunk of elected officials and heads of state in multiple countries were compromised by notorious child trafficker Jeffrey Epstein

- The government doesn't pay taxes. I mean, obviously, they're the ones levying them.

We like to think of law enforcement as a cat-and-mouse game: criminals do a thing and law enforcement tries to hunt them down within the bounds of 4A/5A. The reality is more complicated. There are cases in which governments actively collaborate with organized crime, either because the government is corrupt as sin, or because the criminals are offering the state a way out.

[0] Fun fact: if you use Bitcoin, you're automatically opting into this.

[1] To be clear, while I agree with the American argument, you still shouldn't actually expose yourself to this kind of porn, because you're training yourself to get horny around kids. I shouldn't have to say this, but just because it's not illegal doesn't mean it's safe to use.

Re: Apple defeats liability for not scanning iCloud for CSAM

#205

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

One is far easier to prove. If the government could continuously monitor our actions "Is this CSA?" they might very well be pushing for that, too.

Re: Apple defeats liability for not scanning iCloud for CSAM

#206

Earlier quoted context omitted.

> The law is just as much about enforcing social mores and norms This shouldn't be the case in a society that supposedly values liberty.

There is no _society_ without _social_ mores and norms.

I'm not denying they exist, I'm saying a society that values liberty shouldn't enforce them by law.

Re: Apple defeats liability for not scanning iCloud for CSAM

#207
post #14

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

> It is crazy people think apple isnt on the side of privacy. > It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do. I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare qu…

The Pandora's box was already open and essentially no one noticed nor was there immense pushback that resulted in the features being removed. Photo scanning was already happening for both Android and Apple for the purpose of image search.

Re: Apple defeats liability for not scanning iCloud for CSAM

#208

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

I think it's similar with other liability issues, e.g., when a company happens to "lose" customer data through a breach. They will be on the hook for not having certain audits and certifications at regular intervals. Practically never will anyone be feeling any pain due to absolute disregard for basic common sense precautions to prevent issues in the first place. So usually, the pattern is that issues that can be out…

That's actually a little funny. I work in compliance and we regularly work with the teams to improve processes that enhance security. I will say though, that the outsourced work that we send to consultants has the same sort of result you describe.

Re: Apple defeats liability for not scanning iCloud for CSAM

#209

Earlier quoted context omitted.

Yes, this is an argument that exists. But it's not supported by evidence. It's the same as the old "video game violence should be outlawed because it might cause real violence", which is just as unsubstantiated.

Yeah, that old canard is ridiculous! I mean, if there were any truth to it, surely our nation would have seen an uptick, in the past 30–40 years, of new generations picking up guns and just mercilessly mowing down soft targets as if playing GTA. Thankfully, that is all confined to fantasy in cyberspace!

https://youtu.be/g7tII_3WXqo?is=MagnO5GswnVJJltM

Mother Shares How Video Games Radicalized Her Son to Run Around and Pick up Coins

Re: Apple defeats liability for not scanning iCloud for CSAM

#210

Earlier quoted context omitted.

Yes that's exactly his point. E2E is often sold as preventing the owners of the server from being able to read the messages at all, even if they are evil and misleading you. That's obviously only the case if they aren't also the sole providers of the "ends".

There are actual methods to do this though just not sure anyone does it yet. 1. 3rd party audit of a current repo hash 2. Public hosting of hash 3. Modern attested compute can check the current startup and running code hash and return to the user for their own checks. 4. User encrypts the last known hash they used or trust a 3rd party to perform the check like azure's methods. Another way is to open source it and rep…

How would that work for closed source apps like iMessage and WhatsApp?
Post reply on HN