Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

121–130 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#121
post #62

Earlier quoted context omitted.

In reality, the fact that they do the scanning on-device is actually better privacy-wise. But I can see how instinctually it “feels” wrong.

No it's not. Not scanning any content on device at all is better privacy wise.

Often, despite all its disadvantages, on-device scanning would at least let know see what was being scanned for.

But Apple have circumvented that with NeuralHash. There's no way for the user to verify that only CSAM is being detected - which could be partially accomplished by having iOS only accept hashes signed by multiple independent child protection organisations (with some outside of FVEY).

Re: Apple's child protection features spark concern within its own ranks: sources

#122
post #75

Earlier quoted context omitted.

It’s not a false sense of security, it’s a clear delimitation between theirs and mine; Debian package maintainers can also slip a scanner on your machine but that is a big line to cross on purpose and without notifying the user.

But with a debian package you can choose not to accept the upgrade and see any funny business in the release source code..

Somewhere along the line someone is producing and signing the binaries that find their way onto their computer, they could produce those binaries from different source code and I would be none the wiser.

Debian tries to be reproducible, so to avoid being caught they might need to control the mirror to so that they could send it to only me. I.e. if I'm lucky it would take a total of 2 people to put malicious binaries on my computer (1 with a signing key, 1 with access to the mirror I download things from).

Re: Apple's child protection features spark concern within its own ranks: sources

#123

There are two things that make me think this will be walked back. Firstly, and most importantly, this kind of backdoor is the kind of thing that makes big corps prohibit the use/purchases of devices. Secondly, it seems rife for abuse: dont like someone who uses an ios device, msg them some cp and destroy their entire life.

> Secondly, it seems rife for abuse: dont like someone who uses an ios device, msg them some cp and destroy their entire life.

I see this a lot. First of all, if you even have CP in the first place that seems quite bad and that you've made yourself vulnerable. Messaging someone will also reveal yourself as the sender. But my bigger question of this hypothetical issue is that Facebook, Google, Dropbox, Microsoft, etc etc have been scanning for CP all of this time on their servers. So it's not like this is somehow a new proposition. Thus wouldn't this already be a big issue through the many, many more people that use all of these other company's cloud products?

Re: Apple's child protection features spark concern within its own ranks: sources

#124
post #7

Can someone explain how Apple being coaxed or coerced into searching all of our personal devices for illegal files by federal law enforcement is not an unconstitutional warrantless search?

I am not a Lawyer, but my understanding is: The wording of the CSAM law is that content should be scanned when uploaded. That condition "upon upload" triggers the 3rd party doctrine. Apple has gone above and beyond here, not the actual US gov. So, the bill of rights doesn't apply to Apple's decision to scan content on device, just before it is uploaded.

There is no law that requires providers to scan users private documents, even uploaded.

However, if they do review the material and see child porn they're obligated to report it.

Re: Apple's child protection features spark concern within its own ranks: sources

#125

Regarding smartphones, I wonder if we’ve just lost a grip on what it means to have privacy. Even our expectations for privacy have degraded and eroded over time. We just carry this device with our life encoded in a flash chip with keys to cloud access. Life . Everything from emails to our walking gait, photos, text, history, health records, etc is stored on this one device. Dictators of the past would have a field da…

Why ham radio? That doesn’t make sense. There’s no privacy there by law. It is by nature a completely non anonymous medium. Not only that if a country shuts down its comms the hams are all on a nice list for their shit to be confiscated.

Im not a ham because of some romanticised dystopia avoidance. It’s just fun to make things that you can talk to people on :)

Re: Apple's child protection features spark concern within its own ranks: sources

#126
post #88

Earlier quoted context omitted.

They aren't being coaxed or coerced. If they were forced-- or even incentivized-- by the government to perform these searches than they'd be subject to the fourth amendment protecting against warrantless searches. Apple is engaging in this activity of their own free will for sake of their own commercial gain and are not being incentivized or coerced by the government in any way. As such, the warrantless search of the…

> Apple is engaging in this activity of their own free will for sake of their own commercial gain What's the commercial gain?

This will likely be paired with the rollout of full encryption for iCloud and they will sell the entire thing as a pro-privacy move.

Re: Apple's child protection features spark concern within its own ranks: sources

#127

Earlier quoted context omitted.

Just think of it as a form of lobbying.

What's the end-game here? I don't follow.

End game (being charitable to them here) is they can now start encrypting iCloud photos, and iCloud backups for that matter, with a key that they do not have any way to access, while getting the FBI off their backs on this one hot button issue.

That by itself makes it look ok.

Until you consider… there are a couple counterarguments.

One, Apple has not actually enabled such private encryption with the keys out of reach to Apple for iCloud backups.

Two, that child protection in other countries will sometimes be defined in such repugnant terms that it will compromise Apple fully to scan for the hashes provided by “child protection” organizations in those countries.

“Child protection” is in quotes not because I think countries will get away with shoehorning, say, terrorist content hashes in as purported child pornography hashes. It’s in quotes because the concept of child protection can be so wildly bizarrely corrupted in some countries for religious or ideological reasons. Who decides what is off limits for children, from having gay parents, to having friends of the opposite sex, to having an unislamic head covering? Well, each random government, of course, with Apple as the enabler, and individual and human rights be damned.

So while the most charitably viewed end game may be good, they seem to be papering over the real impacts this could have.

Re: Apple's child protection features spark concern within its own ranks: sources

#128
post #112

Earlier quoted context omitted.

The practical difference is that with on-device scanning, the system is just a few bit flips away from scanning every photo on your device, instead of just the ones that are about to be uploaded. With server-side scanning, the separation is clear—what's on Apple's server can be scanned, and what's only on your phone cannot. This all plays so perfectly into my long-time fears about the locked down nature of the iPhone…

There is also an argument that the cloud scanning is a few bit flips away from allowing random Apple employees from looking through all my photos while on device scanning means they have to be specifically looking for certain content. On device scanning is probably preferred if one's fear is someone stealing their nudes, which is one of the more common fears about photo privacy and one that Apple has already shown is…

Sure, but I don't particularly care because I don't upload sensitive photos to iCloud. As I'd recommend to everyone else. If it's on someone else's computer, it's not yours.

But, I suppose my iPhone was never really mine either. I knew that, I just never quite put two and two together...

Re: Apple's child protection features spark concern within its own ranks: sources

#129
So it boils down to companies make most of the OSs for devices.

Governments can compel companies to do stuff.

The only option for the truly privacy conscious is to not use a company provided OS. The future is in buying a phone and flashing the ROM you want.

Until even owning a non-standard phone becomes illegal.

Re: Apple's child protection features spark concern within its own ranks: sources

#130
post #9

In their attempt to make this extra private by scanning 'on device', I think they've managed to make it feel worse. If they scan my iCloud photos in iCloud, well lots of companies scan stuff when you upload it. It's on their servers, they're responsible for it. They don't want to be hosting CSAM. It feels much worse them turning your own, trusty iPhone against you. I know that isn't how you should look at it, but tha…

That is how you should look at it. They have no business scanning the phones for anything, period. I'll refer you to the poem beginning with "First they came for the Jews...".

"First they came for the pedophiles..."
Post reply on HN