Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

271–280 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#271
post #129

Earlier quoted context omitted.

I thought the client side scanning was to protect children? If it suspects an image is bad, it blurs it and pops up a warning including a link to resources to go to for help. Very different than trying to narc out users to the authorities.

There were two different technologies. One was client-side scanning for known CSAM, which created a huge backlash and is described here: https://educatedguesswork.org/posts/apple-csam-intro/ The other is detection of images that may contain nudity, whether sent or received, when the owner/admin/parent enables the feature. It is relatively uncontroversial and is described here: https://support.apple.com/en-us/105069

> The other is detection of images that may contain nudity, whether sent or received, when the owner/admin/parent enables the feature. It is relatively uncontroversial [...]

That's a new version. The one that as announced the same time as client side scanning to block uploading CSAM to iCloud worked like this.

1. It could be enabled on a child's device by the parents. It was not on be default.

2. If the child received a sexual image (not necessarily just CSAM...if an adult sends a dick pic to a child that is not CSAM but would have been flagged) the image is blocked, the child is notified, told their parents are worried the image may harm them, and asked if they still want to see it.

3. If the child says no, they do not want to see it, that is the end of the matter.

4. If the child says that they do want to see it and they are at least 13 they are shown the image and that is the end of the matter.

5. If the child says that they do want to see it and they are under 13, they are again told that they parents are concerned, and that if they view it their parents will be notified, and asked if they still want to view it.

6. If they say no that is the end of the matter.

7. If they say yes they see it but the parents also are notified and will be able to see it.

This should have been pretty uncontroversial, but there were objections on the grounds that if someone say sends their dick pic to your under 13 child and the child goes all the way through to step 7 and decides to view it, that is a violation of the sender's privacy because that message was only intended for the child.

Re: Apple defeats liability for not scanning iCloud for CSAM

#272
post #236

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

Because it isn't about CSAM, IMO. You see this with plenty of social issues, notably firearms ownership. The claim is we will restrict/license/outlaw xyz for the kids, but really, a data-drive approach would have focused on different things entirely (eg additional behavioral health services for kids, suicide prevention etc) The same technology/access used for CSAM identification can find copyrighted files, materials…

> The claim is we will restrict/license/outlaw xyz for the kids, but really, a data-drive approach would have focused on different things entirely (eg additional behavioral health services for kids, suicide prevention etc)

Well, most of Europe simply has banned guns in the hands of civilians instead, so that's some data as well.

The only reason why the US is so extremely lax on firearms is because people keep blathering on about how guns are the last line of defense against a tyrannical government - and yet, what do the most rabid of these people do? Vote in and defend a literal tyrant.

Re: Apple defeats liability for not scanning iCloud for CSAM

#273
post #81

Earlier quoted context omitted.

For drawings it has to additionally be "obscene" (since obscenity isn't protected by the first amendment). And there is also a specific law that criminalizes even non-obscene realistic computer generated imagery.

Not quite. There can be more restrictions on the distribution or promotion of obscene material, but mere possession of obscene material is protected by the first Amendment: https://en.wikipedia.org/wiki/Stanley_v._Georgia The reason why the Supreme Court upheld bans on possessing CSAM is not because it's obscene, but because it incentivizes abuse of children to produce it.

This is an extremely important point to understand. At face value, it can feel like CSAM should be protected speech, however repulsive. There are no laws against gore videos, though one might argue that death is worse than SA. However, we have substantial empirical evidence that CSAM directly contributes to offending behavior.

We also acknowledge that participating in pornography requires consent, and that the continued distribution of nonconsensual pornography constitutes a continuing crime against the unwilling subject. Because children have zero legal capacity to consent, CSAM is de facto illegal.

It misses the point to think that CSAM is illegal because it is "obscene". It isn't illegal because it's disgusting; it's illegal because it's egregiously harmful to children. It's like thinking the bad thing a murderer did was make a mess.

Re: Apple defeats liability for not scanning iCloud for CSAM

#274

Earlier quoted context omitted.

Somehow, even something as simple as "age-appropriate sex education going right down to kindergarten" would tend to end up "special interests education from vocal minority groups."

To be clear, I recognize that there is zero chance of genuine effective age-appropriate sex education being mandated in the foreseeable future in the US, nor has there been any such chance at any time in the past. I'm merely noting some of the things that would actually be helpful measures in combating CSA if it were possible to implement them. You're absolutely right that, even if such a mandate had already existed,…

Yep, will end up right-wing groups, or same-sex groups.

Re: Apple defeats liability for not scanning iCloud for CSAM

#275
post #8

I know creating a throwaway to hide your name for an opinion is a bad manner, but this one is one I really don’t want linked back to me The VAST majority of “CSAM” is consensually created and exchanged by teens. Their future selves and their parents form this pressure group attacking everyone’s liberty and privacy to try to undo the downsides of choices they made themselves with full knowledge of what could happen. T…

Just by casually glancing at KMP or VoL, you'd find that even the darknet pedo community itself strongly vilifies actual child abuse (known as "hurtcore"). There's truly no place for people who rape children. They are scum of the earth even in the eyes of the scum of the earth itself.

Re: Apple defeats liability for not scanning iCloud for CSAM

#276

Earlier quoted context omitted.

Side channel is academic at best. Watching memory changing on a complex code base without having said code base is near impossible. 1. Run code 2. Watch memory changes 3. Correlate those to real data If your code is doing anything complicated that's an intense thing to determine. If you're deep enough for a side channel there's likely a lot easier way of getting in.

Brainfart on my part. I was referring to what @majorchord was worrying about, the unencrypted messages in the client get exfiltrated and get sent to the spooks using steganography on some benign request, edited my comment. My mental model is that most competent intelligence agencies have a PRISM 3.0 deal with FAANG, including on E2E products or at least have devs on the payroll. I imagine that any backdoor is only us…

Yeah Cletus and Chud aren't getting many secrets but I get the feeling Apple's incentives here are against this.

What financial gain do they get from this?

A: risk billions in stock value and customer purchases for basically a "thanks" from the gov? One whistleblower would also have the real ability of becoming world famous for "exposing" apple.

B: Get publicity actually resisting the gov and not lying, what is the gov gonna do? I imagine it has and does happen but I also imagine there's a crying tim apple being dragged through it painfully.

Unlike google I just don't see the financial positives for them to do it beyond massive arm twisting. For many companies the risk of destroying their entire value to customers is just not worth it.

The only money in it is mass scale data collection for training data and ads, if they aren't doing that any other method is the opposite of valuable it's a massive liability.

Re: Apple defeats liability for not scanning iCloud for CSAM

#278

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

> There doesn't seem to be any real push for educating and protecting kids before it happens.

Before abstinence and birth control, CSA prevention should be the primary goal of sex ed in schools, especially before high school. (Though on birth control [1] and probably STIs as well the US is not doing well.)

[1] https://www.plannedparenthoodaction.org/issues/sex-education...

Re: Apple defeats liability for not scanning iCloud for CSAM

#279

Earlier quoted context omitted.

I thought the client side scanning was to protect children? If it suspects an image is bad, it blurs it and pops up a warning including a link to resources to go to for help. Very different than trying to narc out users to the authorities.

The original proposal was to use a visual hash designed to identify known bad CSAM images even if cropped or otherwise edited. Your computer would scan all your stuff for these images and report you to apple who would report you to the cops. This presented a number of issues. Accidental false positives could lead to horrific outcomes up to and including oh look bob got shot by the cops for resisting. It was possible…

> Apple could be forced to scan for ANYTHING by repressive regimes including America and China.

Including Europe. Europe is ruled by people who think 1984 was an instruction manual.

Re: Apple defeats liability for not scanning iCloud for CSAM

#280
post #236

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

Because it isn't about CSAM, IMO. You see this with plenty of social issues, notably firearms ownership. The claim is we will restrict/license/outlaw xyz for the kids, but really, a data-drive approach would have focused on different things entirely (eg additional behavioral health services for kids, suicide prevention etc) The same technology/access used for CSAM identification can find copyrighted files, materials…

epsteins case tells you how much the US political class cares about SA and CSA happening in the US.
Post reply on HN