Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

581–590 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#581

Earlier quoted context omitted.

> The hash database is regulated and used worldwide. To get the hashes of what you mention into the database requires numerous people signing off on it. So, it's correct. What you're describing is a policy, not a technical limitation. The technical infrastructure allows exactly that. Policies can and will be changed and bypassed. > It is also a 1:1 match, not a "dissident said X" type meme match. So you can maintain…

> Policies can and will be changed and bypassed. You should take the time to see how it works. No singular country can put information in that wouldn't be picked up straight away by other countries. There are 70 countries signed up to it. > So you can maintain a list of dissident memes just like you can maintain a list of CSAM. Using hashes as a way to match doesn't scale in the way you describe. So it wouldn't be fe…

> No singular country can put information in that wouldn't be picked up straight away by other countries. There are 70 countries signed up to it.

Once that is in place it's just a tiny change to switch to a national database. Granted, that's not a purely technological argument, but the main point is, you are not in control of what your images are scanned for and you cannot even verify it because it's hashes.

> Using hashes as a way to match doesn't scale in the way you describe. So it wouldn't be feasible to do that.

Why wouldn't it? If it scales for CSAM why wouldn't it scale for other types of content? If it doesn't scale for CSAM why are we even arguing about it? There is no technological difference between the two. It's all just images or videos.

> All major companies (for about 10 years) scan everyone's images/files for CSAM. That is happening now.

They scan the images on there servers. They do not scan my images, for example.

> It would have dramatically reduced server costs and meant that your files were 100% safe on the cloud from the government, instead of what they are now. Everyone lost their mind over it, but were taking news stories as facts when it didn't match the research paper.

It would have reduced server costs for Apple at the expense of energy costs and battery life for their customers. I fail to see how that is a win.

I don't care if my files are safe in "the cloud" when they are not safe on my device before being uploaded to the cloud. Also Apple introduced E2EE later anyway and there are other E2EE cloud storage options that have been available before. You are painting a false dilemma. We can have E2EE without surveillance scanning.

>>> if your government is determined to spy on its population there are much easier and less intrusive methods of doing so.

What are those methods? It is always about the children and terrorism when the government wants to extend mass surveillance.

Btw, when I follow your link I only get en error page stating "Access to this site was denied for security reasons. Please contact your network or system administrator."

Re: Apple defeats liability for not scanning iCloud for CSAM

#582
post #575

Earlier quoted context omitted.

I think that product people are very much doing development with these tools; and trusting, deploying and maintaining them. The vast majority won’t even know the trust, deployment and maintenance challenges that technical people know and so they won’t worry about them and probably never will need to. Anything very risky will be eventually protected by exposure in the training data. Not unlike how you see in lovable l…

Even just by narrowing to some definition of "product people," you've cut out the vast majority of the population. > Why does someone who says “I pay -$x for Google Drive, how much can we make our own clone for?” need to know what a server is? The natural language doesn’t necessitate the technical jargon. My point wasn't specifically that they need to know what servers are. Rather, the point is that the average perso…

Yes I get that. And yes I did narrow it in by saying Product people. My point is why would anyone bother to know what goes into building x (a backup solution for example) if building it doesn't require that?

Using me as an example, or my non-technical client now doing app development using lovable, we don't care to know how the things being built but just that it works and its reliable and consistent enough.

Less than a year ago I'd never built iOS or Mac apps, and now I'm building those - I come from an HTML and frontend world, not the Mac or iOS screen layout world and I still know nothing about that and don't want to either.

Re: Apple defeats liability for not scanning iCloud for CSAM

#583

Earlier quoted context omitted.

There is a distinction between teaching tolerance, celebrating diversity, vocal promotion of special interests and recruitment.

"Recruitment"? Do you think that queer people are "recruited"? Do you think that queer people are a "special interest", like corn farmers? No; that type of attitude is just run-of-the-mill queerphobia. Young children need to be taught what gender identities are so that they will know if they are trans/nonbinary, so that they don't have to suffer for years or decades from gender dysphoria. Slightly-older children need…

[flagged]

Re: Apple defeats liability for not scanning iCloud for CSAM

#584
post #575

Earlier quoted context omitted.

Even just by narrowing to some definition of "product people," you've cut out the vast majority of the population. > Why does someone who says “I pay -$x for Google Drive, how much can we make our own clone for?” need to know what a server is? The natural language doesn’t necessitate the technical jargon. My point wasn't specifically that they need to know what servers are. Rather, the point is that the average perso…

Yes I get that. And yes I did narrow it in by saying Product people. My point is why would anyone bother to know what goes into building x (a backup solution for example) if building it doesn't require that? Using me as an example, or my non-technical client now doing app development using lovable, we don't care to know how the things being built but just that it works and its reliable and consistent enough. Less tha…

And I'm glad that works well for you! But this is the context of the thread:

>> most people don't need cloud backups

> What world do you live in?

As put by another commenter:

> Most People™ do not have the technical knowledge to set up a self-owned backup system, and/or will not realize how badly their future selves will wish they had backups if the setup friction for a self-owned solution is too high to conveniently do it right this second.

So, okay, if you're just saying Some Small Percentage of People™ can vibe up a long-term backup solution, then, sure, I grant that.

I just don't think it's a useful or interesting point in the context of this thread, even if it's true.

Re: Apple defeats liability for not scanning iCloud for CSAM

#585
post #584

Earlier quoted context omitted.

Yes I get that. And yes I did narrow it in by saying Product people. My point is why would anyone bother to know what goes into building x (a backup solution for example) if building it doesn't require that? Using me as an example, or my non-technical client now doing app development using lovable, we don't care to know how the things being built but just that it works and its reliable and consistent enough. Less tha…

And I'm glad that works well for you! But this is the context of the thread: >> most people don't need cloud backups > What world do you live in? As put by another commenter: > Most People™ do not have the technical knowledge to set up a self-owned backup system, and/or will not realize how badly their future selves will wish they had backups if the setup friction for a self-owned solution is too high to conveniently…

No I think we are taking about similar things, but the core of it is this:

- you and other guy believe non-technical people can't build technical things because its still too hard and you need to know the technical things

- I'm saying you don't now, and some the samples I showed are that we are moving in that direction and its possible now, even if most people aren't doing it now. that they could. and its an awareness and comfort problem.

is this right or am I still missing your point?

Re: Apple defeats liability for not scanning iCloud for CSAM

#586

Earlier quoted context omitted.

I have an ancestor who was born there, it's now my country.

I am Swedish yes. Why should we take in the world? We took in most per capita in the Syrian crisis. Where do you live and how many refugees did you take in? I am seeing my country destroyed in real time so YES I am upset.

But since my ancestor is from there also I'm allowed to determine who is allowed to be there right?

Re: Apple defeats liability for not scanning iCloud for CSAM

#587

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

The CSAM issue is both very real and abused by politicians. When I did some work with a police agency, it was explained to me that there’s a pattern of escalation with people and they tend to accumulate collections and many escalate to actual behavior. The detectives assigned to this work tend to not last long, and the horrific nature of the crime affects them. Like all rape, it’s a combo of control and dopamine. The…

> it was explained to me

Or as the Dothraki put it, “it is known”.

Re: Apple defeats liability for not scanning iCloud for CSAM

#588

Earlier quoted context omitted.

Not to get too off track, but it's actually an interesting case in that it's one of those where weighting for prevalence of ownership wouldn't matter for the purpose of discovering the more effective measure. If you did something to restrict handguns you would prevent more death than restricting other firearms. Also, not that it has any bearing on what I said, but I'm decidedly pro-gun for any repliers who want to fo…

If it's weighted by ownership then banning one type of gun would increase the ownership of other types of guns, maybe not solving the problem.

Certainly anyone promoting this as a policy goal would brush over the fact that you stated, and exagerate the benefits. However I doubt everybody owning a handgun would go out and buy a rifle. There is also the likelihood that many situations involving the use of handguns would not eventuate if the person in question had a rifle instead.

But again, I'm not actually in favour of this anyway.

Re: Apple defeats liability for not scanning iCloud for CSAM

#589
post #584

Earlier quoted context omitted.

And I'm glad that works well for you! But this is the context of the thread: >> most people don't need cloud backups > What world do you live in? As put by another commenter: > Most People™ do not have the technical knowledge to set up a self-owned backup system, and/or will not realize how badly their future selves will wish they had backups if the setup friction for a self-owned solution is too high to conveniently…

No I think we are taking about similar things, but the core of it is this: - you and other guy believe non-technical people can't build technical things because its still too hard and you need to know the technical things - I'm saying you don't now, and some the samples I showed are that we are moving in that direction and its possible now, even if most people aren't doing it now. that they could. and its an awarenes…

Thanks for trying to summarize.

> - you and other guy believe non-technical people can't build technical things because its still too hard and you need to know the technical things

Pretty much. Though maybe I should more softly phrase it as "you still need to have some idea about technical things." Even more importantly, you still need to have some idea about decomposing problems in a technical way.

What you said:

> the samples I showed are that we are moving in that direction

> and its possible now...its an awareness and comfort problem

So which is it? Are we there, or are we only moving in that direction? Core to my position is the idea that there is a long tail of competences that technical and "product" people have or can fill in the gaps with. Other people don't have these things that are needed to smooth out what AI misses.

Said another way, even if AI has made it 90% of the way there, that still leaves the remaining 90%[0]. Long tails are long, and smoothing everything out such that a truly average person would feasibly whip up a bespoke, reliable backup solution really relies conquering so many edges that technical and product people would never even notice.

[0] https://en.wikipedia.org/wiki/Ninety%E2%80%93ninety_rule

Re: Apple defeats liability for not scanning iCloud for CSAM

#590

sigh Once again, someone (in this case, the judge of this case) asks if we can meet in the middle on whether or not private communications are actually private. To be clear: this is not a limitation of nerds' imagination. This is a limitation of physics . A person is either party to a communication (and thus can decrypt it) or is not (and thus cannot). If you demand Apple scan encrypted photos for CSAM, what you are…

[dead]
Post reply on HN