Live data from Hacker News

In internal memo, Apple addresses concerns around new Photo scanning features

9to5mac.com

101–110 of 430 posts

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#101
post #17
post #16

Earlier quoted context omitted.

How is this system, where Apple sees far less photos, worse? You can't audit anything Apple does on their servers.

Now that a fully built system for breaking end-to-end encryption is shipped directly in the OS, we're one configuration change away from massive scope creep. First terrorist content, then "misinformation", then political speech. Apple will be unable to resist government demands to use this preexisting backdoor with a different set of perceptual hashes.

This doesn't break end-to-end encryption.

If you're going to comment on this topic you need to be technically aware of how it works. You're just spreading nonsense.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#102
post #64

Earlier quoted context omitted.

Hopefully so they can remove their current ability to decrypt user photos for whatever reason they want. The current state is they can decrypt any user photos on iCloud. Doing client side scanning and this CSAM detection implementation could allow them to remove their ability to decrypt EXCEPT in very specific situations. It's not true end-to-end encryption since in some cases the content can be decrypted without the…

If they can decrypt in a “specialized” situation, then they can decrypt in any situation. All that has to be done is to broaden the classifier step by step. Or someone else gets access to the back door. That’s why there can be zero allowed back doors.

They can decrypt iCloud content currently, so it wouldn't be a step back.

On the topic of backdoors, automatic update systems could be used as backdoors.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#103
Recommended reading prior to this one is the 2016 public letter from Apple [1] where Apple makes a similar slippery-slope argument on FBI's request.

1. https://www.apple.com/customer-letter/

Regarding the slippery-slope argument in this context though, it isn't the same. if Apple really wanted to silently transition from CP to Gov/Politics surveillance, they could have just released this feature without any announcement. I mean, if they wanted to be evil. Shouldn't we have thought about this eventuality before putting all our pictures in the cloud?

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#104
post #100

Earlier quoted context omitted.

Add hashes of police uniforms and now you cannot take pictures of law enforcement. Add hashes of politicians. Businessmen in suits. Army uniforms. At the end you have a weapon that can only shoot civilians.

Do you know how discovery works in court? I'm guessing not. Once a hash matches, law enforcement would need a subpoena to access the raw image. If a person were to be arrested, that evidence would be turned over to the defense. It would be very obvious that a picture of a police officer was not child pornography. Are you under the impression people are jailed for hash collisions? Because that's not the case at all...…

Have you heard of the chilling effect?

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#105
If we pretend for a minute, which may not be hard, that Apple isn't trying to "think of the children" - this feature seems like a good step to protect themselves from the legal implications of having CP on their servers. I don't know what all the ramifications would be, but I imagine that if a CP ring was discovered using iCloud as a storage medium, Apple could get in a some big trouble.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#106
post #95

> Today marks the official public unveiling of Expanded Protections for China, and I wanted to take a moment to thank each and every one of you for all of your hard work over the last few years. We would not have reached this milestone without your tireless dedication and resiliency. > Keeping China safe is such an important mission. In true Apple fashion, pursuing this goal has required deep cross-functional commitm…

This isn't the argument you think it is. If you need to replace words and change the context of the discussion, I'm going to assume you don't have any valid criticism. I would refrain from posting, as arguments like this only trivialize the problem.

[deleted]

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#107

If we pretend for a minute, which may not be hard, that Apple isn't trying to "think of the children" - this feature seems like a good step to protect themselves from the legal implications of having CP on their servers. I don't know what all the ramifications would be, but I imagine that if a CP ring was discovered using iCloud as a storage medium, Apple could get in a some big trouble.

>Apple could get in a some big trouble.

On what basis? Is there precedence for this?

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#108
post #81

I don't understand the claim that this system improves their ability to detect anything. If it's really true that the system only works on data uploaded to icloud then apple could have easily just done all the scanning in the cloud, because icloud is not end-to-end encrypted. In that case, all this feature does is move the computational cost of scanning from Apple's datacenters to Apple's users, saving Apple money an…

Respectfully you've missed what this is. This has nothing to do with data sent up to iCloud - at that point not only can those photos be checked via hash they can be further reviewed if there is a positive/high degree match The issue is that this mechanism applies to photos (/data) on the local device that wouldn't otherwise make its way up to iCloud.

Do you have a source that this is being used on all photos on the device?

The EFF posts says it applies to 2 cases: photos being uploaded to iCloud, and photos through iMessage if the account holder is a child and the feature hasn't been disabled.

https://www.eff.org/deeplinks/2021/08/apples-plan-think-diff...

You're right that only scanning photos uploaded to iCloud is currently pointless. But maybe Apple plans to do semi-end-to-end encryption on iCloud photos in the future, and then this feature would be useful.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#109
post #100

Earlier quoted context omitted.

Do you know how discovery works in court? I'm guessing not. Once a hash matches, law enforcement would need a subpoena to access the raw image. If a person were to be arrested, that evidence would be turned over to the defense. It would be very obvious that a picture of a police officer was not child pornography. Are you under the impression people are jailed for hash collisions? Because that's not the case at all...…

Have you heard of the chilling effect?

Yeah, which is irrelevant to the discussion. This thread is about photos of law enforcement and politicians used to convict people on CP charges.

Let's stick to the topic of discovery and how courts work.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#110
post #97

Apple's mistake is that they seemingly believe there is pushback because people misunderstand how it works. The reality is more nuanced: People understand exactly how it works, and how it works is that it is turn-key onboard spyware, that Apple pinky-swears isn't being used wrong today . For example if the scope/mission expands (e.g. foreign governments), suddenly you've created a drag-net for whatever "badness" is o…

> people misunderstand how it works You can literally read any thread on HN or Reddit to see this is the case. Thousands of comments about facial recognition and AI, completely misunderstanding how it works. The EFF article itself was FUD. The EFF article starts right off claiming a backdoor, which is completely incorrect. Taking hashes of client-side content is not a backdoor, and the EFF should be embarrassed for n…

This client side scanning of local files can be easily extended to scan the whole device. That's why the eff was calling it a backdoor. All it takes is for the right govt to put the right preassure on apple. In a way it's kinda worse than a backdoor since your phone is actively reporting any suspicious looking files to the authority all the time on its own. The govt dosent need to actively look for it. Just add the appropriate has of what it wants discovered to the db and wait
Post reply on HN