Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

101–110 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#101
post #36

Earlier quoted context omitted.

Apple isn’t the government.

They are acting on behalf of the government.

If they are acting on behalf of the government there is a massive secret conspiracy to illegally violate the constitutional rights of hundreds of millions of Americans.

It wouldn't be the first time... but it shouldn't be our first assumption.

Instead, in litigation caused by this scanning the companies of testified that they conduct the scanning out of their own free will with no coercion or incentive of the government, simply because they don't want their brand being connected to the distribution of child porn.

Implicitly, they'd rather be associated with unaccountable mass surveillance-- with products that violate human rights, and with a push of a button could be used to enable genocide.

They aren't stupid, so you have to assume that they think that the latter is less of a hit on their bottom line than the former. Lets prove them wrong.

Re: Apple's child protection features spark concern within its own ranks: sources

#102
post #66

Question for Android users: do you have Google Photos backup enabled? I’d say most people have iCloud Photos enabled, so I’m trying to gauge whether that’s true of Google Photos too. Google Photos also does CSAM scanning, I believe

It's not about CSAM scanning its about where the scanning is done!

> I’d say most people have iCloud Photos enabled, so I’m trying to gauge whether that’s true of Google Photos too.

I'd say most people don't have CSAM eitherway.

Re: Apple's child protection features spark concern within its own ranks: sources

#103

In their attempt to make this extra private by scanning 'on device', I think they've managed to make it feel worse. If they scan my iCloud photos in iCloud, well lots of companies scan stuff when you upload it. It's on their servers, they're responsible for it. They don't want to be hosting CSAM. It feels much worse them turning your own, trusty iPhone against you. I know that isn't how you should look at it, but tha…

They didn’t do themselves any favors by blurring the line between apps and the OS. If it’s just Apple’s Photos app doing this, you can install a different app and not use that one.

Re: Apple's child protection features spark concern within its own ranks: sources

#104
post #7

Can someone explain how Apple being coaxed or coerced into searching all of our personal devices for illegal files by federal law enforcement is not an unconstitutional warrantless search?

Technically it's not apple searching, it's your phone searching itself. Sadly, they'll probably put it somewhere on page 89 of their ToS.

If you do not understand what the software on your phone is doing; you cannot control it; you do not own it. Apple owns it.

Re: Apple's child protection features spark concern within its own ranks: sources

#105

There are two things that make me think this will be walked back. Firstly, and most importantly, this kind of backdoor is the kind of thing that makes big corps prohibit the use/purchases of devices. Secondly, it seems rife for abuse: dont like someone who uses an ios device, msg them some cp and destroy their entire life.

It seems easy as hell for them to just change the system to do server-side scanning instead of client-side scanning and it would probably be enough to calm the horde. I think people can understand, Apple can't have certain content on their servers. People have a much harder time understanding that Apple needs to make sure you don't have certain content on your phone.

My understanding is they already do server-side. But relying on server-side alone means trying to end-to-end encrypt your data on the server would put them in political/legal crosshairs.

Re: Apple's child protection features spark concern within its own ranks: sources

#106
post #71

Earlier quoted context omitted.

you can self-host NextCloud on your laptop or desktop. you can use whichever flavor of Android you'd like - a lot of people like GrapheneOS

So, lemme preface this by saying I also use my own NAS at home and wholly support your push for self-hosting. That said, I'm gonna play devil's advocate here, because this is an area I admittedly haven't put much thought into. GP said: >... non-cloud services that provide me with automatic backups of everything I do if something happens to my apartment... And my first concern is that a laptop or desktop (or my NAS) w…

How about whole disk encryption with Duplicati backing up to Sia[1]? This will let you do automatic backups to a decentralized version of S3 where you pay cryptocurrency (Siacoin) for the storage.

That way here's what you need to protect:

- Your whole-disk encryption keys / passwords

- Your Sia key

- Your password for Duplicati backups

[1] https://duplicati.readthedocs.io/en/latest/05-storage-provid...

Re: Apple's child protection features spark concern within its own ranks: sources

#107
post #100

Earlier quoted context omitted.

That is a distinction without a difference. I’m sure you could put together quite a good tank man classifier (proof: Google Reverse Image Search works quite well), and it’d catch variations which a perceptual hash wouldn’t. The only difference is intent. The technical risk has not changed at all.

That is to say face scanning is equally insidious as the new feature?

The technical risk to user privacy - if your threat model is a coerced Apple building surveillance features for nation state actors - is exactly the same between CSAM detection and Photos intelligence which sync results through iCloud. In fact, the latter is more generalizable, has no threshold protections, and so is likely worse.

Re: Apple's child protection features spark concern within its own ranks: sources

#108
post #95

Earlier quoted context omitted.

Yes, thats exactly how i feel. I'd still hate it if my iCloud uploads are scanned but I'm already assuming that anyway. But the fact that my iOS device can potentially report me to any authorities, for whatever reason, is crossing a line that makes it impossible to ever own an iPhone again. I bought my first one in 2007 so I'm not saying this lightly.. Does anybody know if this policy will extend to macOS too?

It has already be announced, this is not only iOS, but all Apple devices.

Great. I recently invested $3800 in an excellent, new iMac. Now I'm starting to wonder if I should have spent a couple thousand less for a barebones PC and installed my favorite Linux distro. It would have done 75% of what I needed, and the other 25% (music and video work)... well, that's the tradeoff.

If anyone in my circle of family, friends, and social network asks my advice, the formerly easy answer "Get a Mac, get an iPhone; you won't regret it!" is probably going to be replaced with something more nuanced ("Buy Apple, but know what you're getting into; here's a few articles on privacy....").

Re: Apple's child protection features spark concern within its own ranks: sources

#109
post #6

Don't use cloud services or closed-source services if you want your stuff to be safe and you want your privacy to be maintained.

Er, do you have a recommendation for non-cloud services that provide me with automatic backups of everything I do if something happens to my apartment, or open-source services that are free of all security flaws allowing hackers to compromise your privacy? Like I wholeheartedly get where you're coming from, but I'm not sure what realistic alternatives look like.

What I wouldn't recommend is using a cloud service like Flickr if you value the integrity of your data. Recently they charged me with a "Community Guideline Warning" because I accidentally included a folder filled with non-photo images, and threatened to delete my account within three days. There is no way to appeal or know which content is specifically in violation. All they left was a curt, automated email. You can request all your data from Flickr to save everything, but they state that the process can take up to several weeks before you're given a download link, longer than the three days it takes for them to arbitrarily terminate your account.

Even with services like MEGA that tout keywords like "encryption" and "privacy" without end, look at their Terms of Service and there will be a clause stating that they will still give all your data to any law enforcement agency that puts in a request, including encrypted files. And they have no choice but to do so, because of the very same issue that's forcing the personal privacy debate with Apple into the spotlight - hosting any kind of illegal data, which is for all intents and purposes synonymous with CSAM, makes your service criminally liable in dozens of different jurisdictions. A public cloud provider that allows arbitrary file uploads and has absolute privacy cannot exist because of the necessity to allow law enforcement to investigate reports of the illegal hosting of CSAM in dozens of different countries.

Any expectation of privacy is a facade when dealing with the cloud. Even beyond the issue of privacy, you're still at the whims of the cloud provider in the end. Fail to play by their rules, and you're done for.

Re: Apple's child protection features spark concern within its own ranks: sources

#110
post #75
post #56

Earlier quoted context omitted.

I feel like this is a false sense of security. Even before this change, they can easily access and scan photos on your device. If they do any post-processing of the image on device, they already do.

It’s not a false sense of security, it’s a clear delimitation between theirs and mine; Debian package maintainers can also slip a scanner on your machine but that is a big line to cross on purpose and without notifying the user.

But with a debian package you can choose not to accept the upgrade and see any funny business in the release source code..
Post reply on HN