Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

101–110 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#101
post #36

IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it. Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt…

This is based on a faulty understanding of the underlying systems. The risk with this sort of E2E encryption is not that the service provider pinky promises not to decrypt what they have, it's that they promise they will not insert a new key into your circle of trust to subsequently start decrypting things .

I think you've imagined this faulty understanding. There are many mechanisms by which Apple could actually decrypt the data despite pinky promises not to. You listed one. There are others.

Re: Apple defeats liability for not scanning iCloud for CSAM

#102

IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it. Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt…

Only if the company misleads and adds a backdoor to the front-end app (thus this entire discussion). If the company is misleading, any encryption technology is irrelevant anyway.

Yes that's exactly his point. E2E is often sold as preventing the owners of the server from being able to read the messages at all, even if they are evil and misleading you.

That's obviously only the case if they aren't also the sole providers of the "ends".

Re: Apple defeats liability for not scanning iCloud for CSAM

#103
post #14

Earlier quoted context omitted.

> It is crazy people think apple isnt on the side of privacy. > It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do. I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare qu…

> It proved that it was technically feasible, and was "privacy preserving". Didn't their paper disproved by reversing the perceptual hashes to reveal blurred version of the images being hashed, and Apple basically said "that's fair, it's not as robust as we wanted, let's visit this later"? If not, I'll happily stand corrected, but please share sources. Addenda: - Apple's original paper: https://web.archive.org/web/20…

> to reveal blurred version of the images being hashed

Skimmed your linked paper. It seems they were able to classify hashes up to ~8% top-1 accuracy and ~30% top-10. Not exactly a blurred version, or any images at all.

So for example, they can say that you probably have images of trees, or images of buildings, but without much other data & very low accuracy.

I'd still be a lot more concerned about them simply flagging political images rather than trying to get a broad understanding of what type of photos I have

Re: Apple defeats liability for not scanning iCloud for CSAM

#104
post #18
post #8

I know creating a throwaway to hide your name for an opinion is a bad manner, but this one is one I really don’t want linked back to me The VAST majority of “CSAM” is consensually created and exchanged by teens. Their future selves and their parents form this pressure group attacking everyone’s liberty and privacy to try to undo the downsides of choices they made themselves with full knowledge of what could happen. T…

Are there statistics backing up the "VAST" majority claim? While on statistics, I wonder, are there reliable statistics about child abuse of different types? Studying correlations with other social metrics, like sex education, liberal/conservative, policies regarding prostitution, and others can provide support for/against decisions. Not that I hope these will impact people's and governments' choices, but I want to c…

It's probably impossible to get reliable statistics about that given how both groups are trying to keep everything secret. But you can consider how many paedophiles there are vs how many horny teenagers there are. Based on that it would be extremely surprising if he was wrong.

The real question is what happens when a horny teenager sends another a nude. There definitely have been insane cases where they get stitched up for creating child porn. I don't know if that's the normal outcome today though.

Re: Apple defeats liability for not scanning iCloud for CSAM

#105
post #57

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

Apple is very much like WhatsApp. Yes you cant perfectly trust their E2EE against state actors, but both in fact put some effort into making world have little bit more privacy. At least on Desktop we have usable Linux, but on the phones there is literally nothing usable because thanks to Google efforts switching to GrapheneOS mean tons of apps either not working or break every few months. Yes its possible to make And…

> hanks to Google efforts switching to GrapheneOS mean tons of apps either not working or break every few months.

I've been using GrapheneOS for years and that hasn't been my experience. There are two financial apps that don't work for me, and that's it. Pretty much everything else I use is fine. But, to be fair, I'm very scrupulous about my apps and tend to avoid installing an app for every little thing that wants me to.

Re: Apple defeats liability for not scanning iCloud for CSAM

#106

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

Privacy is a natural fit for Apple in that they make money on discrete devices, but services have grown tremendously. That’s where the erosion of privacy happens.

So once there’s a profit motive for violating your privacy, the justification for eroding your privacy will proceed. It’s really the inertia of Apple starting out as privacy-compatible that makes them hesitant to throw that away.

Re: Apple defeats liability for not scanning iCloud for CSAM

#107
post #14

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

> It is crazy people think apple isnt on the side of privacy. > It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do. I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare qu…

I still also totally don't get their policy.

Trying to avoid false positives by not firing until a threshold was hit (was it 20 images?) seemed insane from a PR position... rightly or wrongly, all it would take would be the wrong court case and you can see the headlines:

"Apple says users can have up to 20 CSAM images on their phone before they'll tell police"

Re: Apple defeats liability for not scanning iCloud for CSAM

#108
post #14

Earlier quoted context omitted.

> It is crazy people think apple isnt on the side of privacy. > It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do. I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare qu…

> It proved that it was technically feasible, and was "privacy preserving". Didn't their paper disproved by reversing the perceptual hashes to reveal blurred version of the images being hashed, and Apple basically said "that's fair, it's not as robust as we wanted, let's visit this later"? If not, I'll happily stand corrected, but please share sources. Addenda: - Apple's original paper: https://web.archive.org/web/20…

The paper you linked doesn’t reveal blurred versions of the images being hashed. It does train a classifier to determine which of 1,000 ImageNet classes an image belongs to, which “achieved a top-1 test accuracy of 4.34%”.

Re: Apple defeats liability for not scanning iCloud for CSAM

#109
post #31

I simply don't trust services such as iCloud. The legal landscape is too volatile, and Apple's own "terms and conditions" are also subject to constant change. As far as I can tell, most people don't need cloud backups, and iCloud mostly shows up as an annoyance designed to extract more money from customers. In fact, most people probably don't know that Apple and Google vacuum up their files the moment they are create…

I gotta say handling my ever growing photo collection is a pain in the ass but I'm just not okay with uploading it to some server I don't control.

Re: Apple defeats liability for not scanning iCloud for CSAM

#110

Earlier quoted context omitted.

No matter how or why? That seems like a terrible mandate.

> No matter how or why? That seems like a terrible mandate. Honestly shocked that anyone would even say this, but even giving you the benefit of the doubt here -- the one case where I could imagine this might not happen would be if you're a police officer investigating such cases. But they also have their own therapists dedicated/trained in police-specific issues.

Even if someone went browsing for it, yes that's illegal but there's no benefit in their therapist reporting them for just visiting terrible websites.

But also there are definitely ways to get accidentally exposed. That's an absolutely awful thing to call the cops over.

Post reply on HN