Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

251–260 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#251
You wouldn't hold the postal service accountable for delivering CSAM or a bank for offering storing it a lock box would you? So why should cloud storage services be different? Stop clutching your pearls and welcoming big brother over imagined threats while a real rapist sits in the oval office!

Re: Apple defeats liability for not scanning iCloud for CSAM

#252

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

Apple has degraded privacy online through Safari's cookie-preferential storage partitioning (i.e. site capabilities are penalized for using private localStorage instead of cookies), requiring sites to occasionally leak data over the network for multi-subdomain same-site web applications. These applications can privately share local state offline in Firefox and Chrome but usually serve the lowest common denominator, so many webapps use cookies to support Safari.

They're pro-privacy when it serves them financially.

Re: Apple defeats liability for not scanning iCloud for CSAM

#253
post #155

Earlier quoted context omitted.

But you still need backups right? For most people "the cloud" is where you backup stuff. If you have a personal backup strategy that doesn't involve the cloud, you are not "most people". Doing backups the right way take some skill and investment if you want to do it by yourself. It may involve setting up a NAS, and some discipline with physical media. You have to do your own security too. Most people don't want to do…

> But you still need backups right? I back up files to my own cloud with a Nextcloud integration for Android. That being said, a monthly or so backup of devices via USB/Ethernet, like we used to in the pre-cloud area, would be enough for all intents and purposes. It's not like what people have on their phones is generally very valuable.

- People don't need cloud backups

- People's files aren't valuable

You're making a lot of claims that are so blatantly false from what I see on my side that I don't know what to make of it. Are you projecting your own needs onto "people"? Or am I the one who's disconnected, and people truly don't care about losing all their photos?

Re: Apple defeats liability for not scanning iCloud for CSAM

#254

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

CSAM is the perfect trojan horse to undermine privacy everywhere. No politician and no company can oppose it on the grounds of protecting privacy before having the reputation ruined.

Meanwhile the real pedos are rich people vacationing in well known places.

Re: Apple defeats liability for not scanning iCloud for CSAM

#255

I am not a lawyer. There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example: * A: physical sexual abuse of children. B: possession or distribution of CSAM * A: drug trafficking or tax evasion. B: structured cash withdrawals The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A. It's my understanding that conv…

> CSAM (“see-sam”) refers to any visual content—photos, videos, livestreams, or AI-generated images —that shows a child being sexually abused or exploited. Child sexual abuse material (CSAM) is not “child pornography.” It’s evidence of child sexual abuse [1] I can't wrap my head around how AI-generated imagery is evidence of child sexual abuse (CAS). How are you abusing a real child by generating an image of a fake o…

what about an AI generated image using the real face of a minor? That can (I would argue will) cause real damage to the real child.

Re: Apple defeats liability for not scanning iCloud for CSAM

#256

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

In Sweden we're going to literally have Minority Report style pre-crime registries for potential child molesters. We already have one for potential domestic abusers. Fuck this country. I need to get out of here before it gets worse.

Say what now? What criteria do they use to scan the populace and create a pre-crime registry of any kind?

Re: Apple defeats liability for not scanning iCloud for CSAM

#257

Earlier quoted context omitted.

You're suggesting they purposely put a backdoor into all their custom methods? Why? From a liability standpoint that implies a security breach could result in massive loss of customer data and if it did occur would destroy their privacy image to their customers. I agree with the point that what you actually trust is the company to not insert maliscous code or keys into your protected path but modern systems actually…

> You're suggesting they purposely put a backdoor into all their custom methods? Why? I'm not sure what you mean by "custom methods", but I'm not saying they have bypassed the e2e encryption - I'm just saying that they technically could . And as for why they would do that, they might get compelled by a government to do it secretly. As far as I know that hasn't happened yet but I see no reason it couldn't and it would…

They are not lying when they say that they cannot read your messages at rest or in transit without actively changing the code so that you start trusting a new key. The keys sync between devices in ways that Apple cannot read.

This is not bulletproof, because they can potentially change the code to do this - this is what the FBI vs Apple thing was a few years ago was all about.

Re: Apple defeats liability for not scanning iCloud for CSAM

#258

Earlier quoted context omitted.

Circumventing encryption with client side scanning is on par with requiring encryption backdoors, and goes against the purpose of having end to end encryption.

> on par with requiring encryption backdoors There is no back door if nothing leaves your device > goes against the purpose of having end to end encryption Most people would consider the "purpose" is to avoid 3rd parties listening in

If nothing leaves the device so why to scan it at all? This is what proves your statement about compatibility of scanning and e2ee to be wrong.

Re: Apple defeats liability for not scanning iCloud for CSAM

#259

Earlier quoted context omitted.

I think you’re right, but from another angle. In the state where I lived way back when, a state representative put forth a bill to explicitly make e-CSAM illegal. I guess it was already illegal for print media and this covered a gap in the law about cell phone pics, etc. Thing is, it had no allowance for the age of the picture taker, or even whether the picture taker was the photo subject. If a 16 year old girl took…

> I still don’t want to throw kids in prison or remove all traces of a right to privacy in our haste to sun-yeet them. The one messy corner of this is the "strict liability" for this type of material. An underage kid can take a nude photo, send it to an adult, and then the adult can criminally liable for just having it, even if he deleted it as soon as he saw it. Either both parties involved in handing something for…

> has to be changed so a person isn't liable if he deletes or reports the material as soon as he first becomes aware of it

AFAIK that's more or less how it works today as a practical matter. The law recognizes this situation as an affirmative defense, but does not make it impossible to be charged.

To be an affirmative defense it has to be reported immediately or destroyed, constitute three images or less, and not be sent to anyone [other than law enforcement]. Interestingly, NCMEC doesn't necessarily count for that -- if you find yourself in this situation and you want to report something, call your local police.

Re: Apple defeats liability for not scanning iCloud for CSAM

#260

Earlier quoted context omitted.

The problem is, the things that would actually prevent CSA require things like "giving children rights", "widely mandating effective age-appropriate sex education even for young children", and "admitting that it's mostly not scary strangers doing it." These are utterly anathema to huge chunks of society, especially American society. It's more and more clear, from the scope of the Epstein Files, just how much of Ameri…

Somehow, even something as simple as "age-appropriate sex education going right down to kindergarten" would tend to end up "special interests education from vocal minority groups."

To be clear, I recognize that there is zero chance of genuine effective age-appropriate sex education being mandated in the foreseeable future in the US, nor has there been any such chance at any time in the past. I'm merely noting some of the things that would actually be helpful measures in combating CSA if it were possible to implement them.

You're absolutely right that, even if such a mandate had already existed, it would've been erased or co-opted by right-wing groups by now.

Post reply on HN