Live data from Hacker News

One Bad Apple

hackerfactor.com

101–110 of 557 posts

Re: One Bad Apple

#101
post #76

I think Apple may have really screwed the pooch with this move. They're going to catch hell for being able to take images from your device without warning or consent, and, they'll catch hell if they remove it. Worse, they've also opened the door to government censorship of images and content and propped that door wide open.

Yes, they screwed the pooch with us, representing: 1. The few who care about privacy. 2. That's about it. Maybe 1% if you're being generous. ( And subtract the portion of that 1% on this site who DO care about privacy but are being compensated $400k/yr by Apple and with Bay Area rents being what they are, they shouldn't rock the boat, and they really need to make good on their Tesla Roadster reservation. ) But go ask…

I disagree. Ask anyone you listed if they'd be comfortable with Apple reviewing their photos and possibly sending them to another organization without any warning or recourse and I highly doubt any of them would be okay with it.

Re: One Bad Apple

#102
As a fan of this blog for longer than I can remember, it's refreshing to hear this particular author's take on this issue, especially considering their background.

I'm glad these issues were addressed in a much more elegant way than I would have put them:

> Apple's technical whitepaper is overly technical -- and yet doesn't give enough information for someone to confirm the implementation. (I cover this type of paper in my blog entry, "Oh Baby, Talk Technical To Me" under "Over-Talk".) In effect, it is a proof by cumbersome notation. This plays to a common fallacy: if it looks really technical, then it must be really good. Similarly, one of Apple's reviewers wrote an entire paper full of mathematical symbols and complex variables. (But the paper looks impressive. Remember kids: a mathematical proof is not the same as a code review.)

> Apple claims that there is a "one in one trillion chance per year of incorrectly flagging a given account". I'm calling bullshit on this.

Re: One Bad Apple

#103

There was parents arrested over bath time and playing in the yard sprinklers, photos being processed at photo mats, will the same thing happen by apple mistakenly reporting parents? When I worked telecom, we had md5sum database to check for this type of content. If you emailed/sms/uploaded a file with the same md5sum, your account was flagged and sent to legal to confirm it. Also if a police was involved, the account…

> There was parents arrested over bath time and playing in the yard sprinklers, photos being processed at photo mats, will the same thing happen by apple mistakenly reporting parents?

No, because they’re not identifying content, they’re matching it against a set of already-known CSAM that NCMEC maintains. As you go on to say, telecoms and other companies already do this. Apple just advanced the state of the art when it comes to the security and privacy guarantees involved.

Re: One Bad Apple

#104
post #56

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

>I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. Would it help anything? Apple isn't using PhotoDNA, so proving PhotoDNA is bad would just be met with "we don't use that".

I believe it would because other image systems will probably have to make similar implementations and trade offs that PhotoDNA did.

Re: One Bad Apple

#105
post #100

> To reiterate: scanning your device is not a privacy risk, but copying files from your device without any notice is definitely a privacy issue. I think the article is wrong about this. Or, right-but-situationally-irrelevant. As far as I can tell from Apple's statements, they're doing this only to photos which are being uploaded to iCloud Photos. So, any photo this is happening to is one that you've already asked App…

So.. how well does "human review" work with copyright on youtube?

This is basically fearmongering, and saying "if you're not a pedo, you have nothing to fear", installing the tech on all phones, and then using that tech to find the next wikileaks leaker (who was the first person with this photo), trump supporters (just add the trump-beats-cnn-gif to the hashes), anti-china protesters (winnie the pooh photos), etc.

This is basically like forcing everyone to "voluntarily" record inside of their houses, AI on that camera would then recognise drugs, and only those recordings will be sent to the police.

Re: One Bad Apple

#107
post #61
post #18

There are a lot of articles about Apples hadh algorithm and for me they are mostly irrelevant to the main problem. The main problem is that Apple has backdoored my device. More types of bad images or other files will be scanned since now apple does not have plausible deniablity to defend any of ghe government’x requests. In the future a false? positive that happened? to be of a political file that crept in the list c…

They could have done all that without telling you. And as long as the traffic was combined with normal traffic no one would ever notice (and in this case it would end up mixed with normal traffic since it only applies to images being uploaded to iCloud, so communication with Apples servers would be expected). What it looks like to me is that Apple is planning on releasing end-to-end encryption for iCloud. But they kn…

> What it looks like to me is that Apple is planning on releasing end-to-end encryption for iCloud

This is Gruber's optimistic take on it as well. If so, why not make both changes at once? Given that they've walked back E2EE on iCloud before, I'm not holding my breath.

Re: One Bad Apple

#108

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

It’s not enough to disband the NCMEC, I want jail time for these people.

This is literally conspiracy to undermine the privacy and security of over a billion devices (and their users) to catch a “small minority” of criminals.

These people deserve to lose their homes and freedom for this, along with every engineer and executive that participated.

Re: One Bad Apple

#109

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice Stopping to that level is what they want, CNN: “‘privacy activists’ have released a tool to allow the spread of CP”

If that’s how they play then the only winning move is to respond in kind.

>shadowy government affiliated agency abuses its role of protecting children to install malware on a billion devices

Re: One Bad Apple

#110
post #18

There are a lot of articles about Apples hadh algorithm and for me they are mostly irrelevant to the main problem. The main problem is that Apple has backdoored my device. More types of bad images or other files will be scanned since now apple does not have plausible deniablity to defend any of ghe government’x requests. In the future a false? positive that happened? to be of a political file that crept in the list c…

Exactly. The issue is that the iPhone is now a snitch AI for whatever purpose Apple deems fit.

Drug dogs have a 50~80% false positive rate, because after they've been certified as capable of detecting drugs, they get that trained out of them the field to instead indicate whatever the handler wants indicated.
Post reply on HN