Live data from Hacker News

Apple plans to scan US iPhones for child abuse imagery

ft.com

101–110 of 390 posts

Re: Apple plans to scan US iPhones for child abuse imagery

#101

> Apple intends to install software on American iPhones to scan for child abuse imagery > Apple’s neuralMatch algorithm will continuously scan photos that are stored on a US user’s iPhone and have also been uploaded to its iCloud back-up system Why is there any need for Apple to install software on the iPhone if they are isolating the algorithm to run only on cloud storage, not local images? Not a programmer, so mayb…

Doesn't really answer your question, but the article says this:

> According to people briefed on the plans, every photo uploaded to iCloud in the US will be given a “safety voucher” saying whether it is suspect or not. Once a certain number of photos are marked as suspect, Apple will enable all the suspect photos to be decrypted and, if apparently illegal, passed on to the relevant authorities.

Re: Apple plans to scan US iPhones for child abuse imagery

#102
post #23

I really don't see how this is going to end well, there could be perfectly innocent photos on someone's phone of their own children doing perfectly normal things that kids do. Like a kid running butt naked around the house, or a photo of something like a rash that is sent to a nurse friend for advice on what it is etc. I'm all for protecting children from being abused, but how are they going to filter what is normal…

What will happen is that criminals who actually had bad intent will move off of the platform and the ones who get the brunt of the blame are the innocent who had no ill intent.

The process is described above, but it’s very hard to “innocently” end up with one of those images that they are looking for from the database.

And the way it’s being done (hashes), a collision is highly unlikely. If it does occur it doesn’t mean it’s similar in nature (e.g. innocent picture of own child in bath). The hash isn’t looking at the image content in the sense of “what’s in the picture”, just the bits of the file. So it’s highly, highly unlikely, even if a collision occurs, that the collision would be an image that happens to be another child innocently bathing.

Re: Apple plans to scan US iPhones for child abuse imagery

#103

> Apple intends to install software on American iPhones to scan for child abuse imagery > Apple’s neuralMatch algorithm will continuously scan photos that are stored on a US user’s iPhone and have also been uploaded to its iCloud back-up system Why is there any need for Apple to install software on the iPhone if they are isolating the algorithm to run only on cloud storage, not local images? Not a programmer, so mayb…

They are scanning client and server-side photos.

Re: Apple plans to scan US iPhones for child abuse imagery

#104

I really don't see how this is going to end well, there could be perfectly innocent photos on someone's phone of their own children doing perfectly normal things that kids do. Like a kid running butt naked around the house, or a photo of something like a rash that is sent to a nurse friend for advice on what it is etc. I'm all for protecting children from being abused, but how are they going to filter what is normal…

Or when an internet troll gets your email address and/or phone number and starts spamming you with child porn pictures, which your phone immediately identifies and notifies authorities.

Re: Apple plans to scan US iPhones for child abuse imagery

#105

> Apple’s neuralMatch algorithm will continuously scan photos that are stored on a US user’s iPhone and have also been uploaded to its iCloud back-up system. Users’ photos, converted into a string of numbers through a process known as “hashing”, will be compared with those on a database of known images of child sexual abuse. This doesn't really make any sense. So it's not a Neural Engine thing but merely hash matchin…

The article is a mess, it could be anything. Locally? On iCloud? Hashed? Content detection? Who knows, the article has all of these keywords.

Re: Apple plans to scan US iPhones for child abuse imagery

#106

Imagine if Microsoft does this with Windows, lots of people would get arrested rightly so. But like some people say this can be dangerous because evidence can be planted on your device. I remember reading articles how through torrent clients files could be planted but I never actually saw it in the wild.

A good reminder to turn off AirDrop "Auto Accept from Everyone"

There is no such thing. AirDrop can "appear" to everyone, but not accept. At most you get a popup.

Re: Apple plans to scan US iPhones for child abuse imagery

#107

Earlier quoted context omitted.

> "The odds of This number is equivalent to generating 1 billion UUIDs per second for about 85 years." If we're talking about random files, sure. What if the files are intentionally created to match the desired hash? The malicious actor doing this could be a private party intending to disrupt your life, but it could also be law enforcement as a means of gaining access to your device when it would otherwise require a…

Couldn't someone that motivated come up with a dozen other ways to frame someone? This seems a little alarmist to me.

LEO have never, ever planted a baggie of weed in someone's car. Likewise, LEO would never, ever ensure that a picture that matched a known phash gets on a target's phone.

Re: Apple plans to scan US iPhones for child abuse imagery

#108
> The proposals are Apple’s attempt to find a compromise between its own promise to protect customers’ privacy and ongoing demands from governments, law enforcement agencies and child safety campaigners for more assistance in criminal investigations, including terrorism and child pornography.

The 1st and 4th amendments tell the fed to go pound sand, Apple should follow suit.

Re: Apple plans to scan US iPhones for child abuse imagery

#109
This article raises serious privacy concerns. Just building the infrastructure for on-device scanning and reporting is extremely troubling. A slippery slope, or a break in the dam, as others have said. My view is that we've been on that slope for a long time, and this changes little. We just have to trust Apple, as has always been the case.

When I look at the technical details, it seems to me to be a reasonable compromise. It allows Apple and government to do something about the worst offenders, whereas it has no impact on anyone else.

Two technical reasons for this:

- The "neuralMatch" algorithm suggests some sort of CV, whereas the article talks about matching against a hash of know images. My guess is that the actual technology is something like Microsoft's PhotoDNA (https://news.microsoft.com/on-the-issues/2018/09/12/how-phot...). Hash collisions aside, this should only produce matches against images that are already in a government database. It will match manipulated images (e.g., rotated or cropped), but it won't match new images.

- As described here, the scanning only applies to images also uploaded to iCloud ("[the] algorithm will continuously scan photos that are stored on a US user’s iPhone and have also been uploaded to its iCloud back-up system"). While we don't know whether this description is accurate, it suggests that if you don't back up images to iCloud your device won't do any scanning locally. Apple already has the keys to your iCloud backups, so if you value privacy you're probably not backing up to iCloud anyhow.

- It sounds like it doesn't flag a single image, but requires multiple hash hits.

So, if you want to feel better about this, understand that it is a system that will flag people who are downloading storing known child exploitation images on their devices and naively backing those up to iCloud.

This is the sort of privacy compromise that works in practice. Serious offenders are either caught or diverted to other channels. Minor offenders are probably not caught. The risk to non-offenders is zero or close to it.

Apple has the control to do all sorts of invasive things to our privacy. They could be scanning and reporting all kinds of things already, and we might not even know. Or they could start doing so tomorrow. From this point of view we're already trusting them to do right by us as their customers, and this feature doesn't change that.

Re: Apple plans to scan US iPhones for child abuse imagery

#110

If it matches, am I guilty until found innocent? I have no illicit images, but false positives are always going to be a problem and even at sub-1% rates if you're scanning literally every image stored on an iOS devices that could still be thousands of wrong matches. If I lose the false-positive lottery, am I going to have the police calling and have my mugshot in the evening news for "CP on their device" in particula…

In the United States, the process of reporting potential images of CSAM is defined by the government, and a technology company’s active responsibility ends with a report to the National Center for Missing and Exploited Children’s CyberTipline: https://www.missingkids.org/gethelpnow/cybertipline#whathapp...
Post reply on HN