Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

101–110 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#101
From the article;

> You could of course say that it’s “a slippery slope” sort of argument, and that we should trust Apple that it won’t use the functionality for anything else. Setting aside the absurdity of trusting a giant, for-profit corporation over a democratically-elected government,

And then later it reads

> and has previously cancelled their plans for iCloud backups encryption under the pressure of FBI.

Isn't the FBI in place because of the democratically elected government? It seems like the for profit organisation is trying to do the right thing, and the government is stopping them.

This is the fundamental problem with arguments based on "trust" - the government seems to be doing the wrong thing.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#102
I used to always get the latest and greatest iphone but with the politics and everything that's going on why would I want to spend more than the absolute minimum on my cellphone? There are plenty of wholesome things to spend money on other than tech.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#103

I really don't see why the scanning would ever be done on the phone instead of on iCloud if it only affects iCloud images. But I do have guesses why.

That's the crux of it. Why bother with on-device identification, unless one of: a. Apple intends to E2E encrypt iCloud data. b. This is intended to extend to all photos on the device in the future. I'm hoping it's (a), but it's probably (b). And in either case it sets a bad precedent for other companies to follow. Edit: This also turns every jailbreak into a possible CSAM detection avoidance mechanism, giving the gov…

Where is this stance coming form that Apple needs to break E2E crypto to be "able" to "E2E encrypt iCloud data"?

That makes absolutely no sense. There is nowhere such a requirement.

They could just E2E encrypt iCloud data. Point.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#104
post #50

Earlier quoted context omitted.

If you don't choose upload to icloud, no upload to apple at all. If you do choose icloud upload (most do), they were being uploaded already and stored and may be available to law enforcement. If you do upload to icloud, NOW they will be screened for matches with "known" images in a database, and if you have more than a threshold number of hits, you may be reported. This will happen on device. Apple will also scan pho…

Disabling iCloud does not remove the scanning system or it’s database from your phone.

Not syncing your contacts to icloud does not remove the uploading system and its components from your phone.

Disabling iCloud does not remove the uploading system from your phone.

Pressing end recording on a video does not remove the video capture system from your phone.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#105
post #80

Earlier quoted context omitted.

I think the one thumbnail of the matching hash? Just to make sure there isn't a (they argue one in a trillion, but I don't know if I buy that) false positive. That's if there is enough matches to trigger the threshold in the first place, otherwise nothing is sent (even if there are matches below that threshold). Alternatively this is running on all unencrypted photos you have in iCloud and all matches are known immed…

> I think the one thumbnail of the matching hash? So it is sending pictures? That makes your argument quite a bit weaker. > Is that preferable? Nope, E2EE without compromises is preferable.

I think the thumbnail is only when the threshold is passed and there's a hash match. The reason for that is an extra check to make sure there is no false positive match based on hatch match (they claim one trillion to one, but even ignoring that probably pretty rare and strictly better than everything unencrypted on iCloud anyway).

> Nope, E2EE without compromises is preferable.

Well that's not an option on offer and even that has real tradeoffs - it would result in less CSAM getting detected. Maybe you think that's the acceptable tradeoff, but unless government legislatures also think so it doesn't really matter.

This isn't the clipper chip, this is more about enabling more security and more encryption by default but still handling CSAM.

The CSAM issue is a real problem: https://www.nytimes.com/interactive/2019/09/28/us/child-sex-...

Re: The deceptive PR behind Apple’s “expanded protections for children”

#106

Earlier quoted context omitted.

99% of internet discussion on this topic is junk. And how is that? It seems like the Gruber article follows a common formula for justifying controversial approaches. First, "most of what you hear is junk", then "here's a bunch of technical points everyone gets wrong"(but where the wrongness might not change the basic situation), then go over the non-controversial and then finally go to the controversial parts and giv…

But some of those technical points are important. Parent comment was concerned that photos of their own kids will get them in trouble - it appears the system was designed to explicitly to prevent that.

The Daring Fireball article actually is a little deceptive here. It goes over a bunch of that won't get parents in trouble and gives a further couched justification of the finger printing example.

The question is whether an ordinary baby photo is likely to collide with the one of the CSAM hashes Apple will be scanning for. I don't think Apple can give a definite no here (Edit: how could give a guarantee that a system that finds any disguised/distorted CSAM won't tag a random baby picture with a similar appearance. And given such collision, the picture might be looked at by Apple and maybe law enforcement).

Separately, Apple does promise only to scan things going to iCloud for now. But their credibility no long appears high given they're suddenly scanning users' photos on the users' own machines.

Edited for clarity.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#108
I really don't get all the hype. This is not a backdoor as it's called in TFA. It's not Apple "reaching into your device". It is literally checking for specific images and reporting their presence to Apply if found. It's not using AI to analyze your photos or anything like that. It's looking for specific images, and only prior to uploading them to iCloud. It won't even flag your own nasty images because the hash won't match.

Note: The above assume we're talking about a typical hash of data and not an image-analysis "hash" of what it thinks the content it. This is supported by the language they use.

Yes, it's a bit big-brother. But I already assume the authorities can fairly easily get ALL your iCloud data if they ask Apple the right way.

You know what's creepy AF? Having a private conversation and getting facebook ads the next day relating to the topic. Talk about an acquaintance acting schizophrenic and get ads about medications and treatment for that? Creepy as fuck. And that was on the wifes iPhone - I have Android and didn't get that stuff, but I seem to remember similar incidents where I got ads for stuff talked about. That's serious voice analysis, not just checking a file hash, and it happens when your phone is in your pocket.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#109
post #47

Any idea why Apple didn’t just implement server side scanning like everyone else?

In this TechCrunch interview, Apple believes it is less invasive since no one can be individually targeted. The hashes are hard coded into each iOS release which is the same for all iOS devices. The database is not vulnerable to server side changes. Additionally, FWIW, they do not want to start analyzing entire iCloud photo libraries so this system only analyzes new uploads. https://techcrunch.com/2021/08/10/intervie…

>The hashes are hard coded into each iOS release

Do you have a source on that? Since it is illegal to share those hashes in any way or form. Even people working with photo forensic and big photo sharing sites cannot get access to them. I very much doubt Apple can incorporate them into the iOS release without breaking multiple laws. The hashes themselves can easily be reversed to (bad quality) pictures so having the hashes equals having child pornography.

Edit:

https://www.hackerfactor.com/blog/index.php?/archives/929-On...

Post reply on HN