Live data from Hacker News

Apple plans to scan US iPhones for child abuse imagery

ft.com

141–150 of 390 posts

Re: Apple plans to scan US iPhones for child abuse imagery

#141

I really don't see how this is going to end well, there could be perfectly innocent photos on someone's phone of their own children doing perfectly normal things that kids do. Like a kid running butt naked around the house, or a photo of something like a rash that is sent to a nurse friend for advice on what it is etc. I'm all for protecting children from being abused, but how are they going to filter what is normal…

If the photo of your kid running around the house ends up in a CP database, you messed up before Apple did.

Re: Apple plans to scan US iPhones for child abuse imagery

#142

When it comes to Apple and privacy, it's important to differentiate two different types of privacy: (1) privacy against snooping by the state, and (2) privacy against snooping by all others. As we had seen with Apple and China, it's only the second type of privacy that Apple cares about. Sharing your information with the state is not out of character for Apple. In fact, had they done the opposite, it would have been…

Apple cares about #1 when they feel the requests are not legal. https://en.wikipedia.org/wiki/FBI–Apple_encryption_dispute

Apple has to comply with the law, however.

Re: Apple plans to scan US iPhones for child abuse imagery

#143
post #102
post #23

Earlier quoted context omitted.

What will happen is that criminals who actually had bad intent will move off of the platform and the ones who get the brunt of the blame are the innocent who had no ill intent.

The process is described above, but it’s very hard to “innocently” end up with one of those images that they are looking for from the database. And the way it’s being done (hashes), a collision is highly unlikely. If it does occur it doesn’t mean it’s similar in nature (e.g. innocent picture of own child in bath). The hash isn’t looking at the image content in the sense of “what’s in the picture”, just the bits of th…

What happens if someone spams CP via iMessage to their enemies?

Additionally, this isn't just a hash of the file but a perceptual hash on the image content. So e.g. changing a single bit in the image would create a different cryptographic hash, but generally not a different perceptual hash.

Re: Apple plans to scan US iPhones for child abuse imagery

#144
post #129

Earlier quoted context omitted.

I actually do want a feature where I will get a notification on my phone if someone nearby has snagged a picture of me or my kids. A creepy shopper at Costco once took a pic of my 2-year-old. They pretended to be working up a conversation with my little kid meanwhile they had their phone at hip-level to snag a shot. I even confronted them about it. The Costco employees couldn't do a thing. Phones with cameras are use…

That's silly. You're in public. Your photo (and your kids') are being taken all the time.

It's not the case when you're inside Costco. I'd also argue that it's not open to the public because you're required to have a membership to go in.

Re: Apple plans to scan US iPhones for child abuse imagery

#145
post #124

Earlier quoted context omitted.

Don't worry, AI is very good at these things and never makes mistakes. It is so advanced it even understands nuance and complex communication mechanisms like sarcasm in text, even if it's only a single sentence to contrast! It will be able to know exactly the context of each image and it will affect only the sickos. We're also working on watching your face through the camera to see your true expression when viewing t…

Yep. And if you dont like it, build your own iPhone.

And be immediately labelled by society as a CP holder

Re: Apple plans to scan US iPhones for child abuse imagery

#146
post #139

Earlier quoted context omitted.

This is how every single cloud service has worked for a decade. You’ll need to elaborate on how, exactly, you believe it’s dystopian. The article is clearly wrong, because Apple cannot know which jurisdiction to forward a report to. That is NCMEC’s responsibility.

This is on your device, not hosted by a third party (and therefore not a third party liability). Kind of like if your microwave was checking that there wasn't any illegal activity happening in your home and phoning home if it has a suspicion. As others mentioned, privacy erosion only goes one way. This is a frontier being breached, i.e. searching your physical device without a warrant, and as usual in the name of CP…

No it’s not. Read the article: the proposed mechanism is implemented as part of photo upload to iCloud.

Re: Apple plans to scan US iPhones for child abuse imagery

#147
post #115
post #67

Earlier quoted context omitted.

I see it as an unwarranted search, which makes me feel like the state views me as inherently guilty until innocence is proven by sifting through my photos.

It’s not the state, it’s Apple. And they are making the decision that they do not want to put out a product that makes it easy for CP to be shared or viewed. As a huge player in the market this is great. This also limits the possible avenues for future exposure - if one has less ways to distribute or get CP or the overall amount of it is reduced, they may never get into it in the first place and the market for it wil…

According to the article, Apple is responding to government and law enforcement pressure to implement the scanning. The state is just laundering its desires through private corporations; there must be a word for this type of system.

Re: Apple plans to scan US iPhones for child abuse imagery

#148
post #115
post #67

Earlier quoted context omitted.

I see it as an unwarranted search, which makes me feel like the state views me as inherently guilty until innocence is proven by sifting through my photos.

It’s not the state, it’s Apple. And they are making the decision that they do not want to put out a product that makes it easy for CP to be shared or viewed. As a huge player in the market this is great. This also limits the possible avenues for future exposure - if one has less ways to distribute or get CP or the overall amount of it is reduced, they may never get into it in the first place and the market for it wil…

Today they say it’s for CP, tomorrow they will say it’s for pirated content, or anything deemed illegal by the government.

Re: Apple plans to scan US iPhones for child abuse imagery

#149
post #102
post #23

Earlier quoted context omitted.

What will happen is that criminals who actually had bad intent will move off of the platform and the ones who get the brunt of the blame are the innocent who had no ill intent.

The process is described above, but it’s very hard to “innocently” end up with one of those images that they are looking for from the database. And the way it’s being done (hashes), a collision is highly unlikely. If it does occur it doesn’t mean it’s similar in nature (e.g. innocent picture of own child in bath). The hash isn’t looking at the image content in the sense of “what’s in the picture”, just the bits of th…

> but it’s very hard to “innocently” end up with one of those images that they are looking for from the database.

Are you sure, given how many iPhone takeover/jailbreak bugs regularly exist, including the recent 0-click iMessage bug? Would you like to dare a hacking group, domestic or foreign, to land a single verboten image on your iPhone?

> And the way it’s being done (hashes), a collision is highly unlikely.

The limited details so far are suggestive that its using perceptual hashes, which are more susceptible to collision-engineering/false-positives than cryptographically-secure hashes.

Re: Apple plans to scan US iPhones for child abuse imagery

#150
post #3

https://towardsdatascience.com/black-box-attacks-on-perceptu... I mean, who's to say that my hash is actually what they think it is... ...and if it's not uploaded to iCloud for someone to manually review what the image is, is that going to be enough to get a search warrant for my phone? "AUSA SOMEONE: But, Your Honor, The Defendant's phone has an image that matched a hash of a CSAM picture!" "DEFENDANT: I'm not going…

I have always been concerned that this system could be weaponized as a way gain access to someone's account. For example:

- Add the hash of a non-pornographic image to the database

- Using a burner email address, email the non-pornographic image to the target's Gmail address. The target wouldn't think anything of it.

- The innocent image would trigger a CP alert, giving law enforcement the pretense it needs to access the account

Post reply on HN