Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

141–150 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#141

in "Photos" app, in the bottom right corner there is a "search" icon. When I click it, and entering "beach", I can see photos I've made on the beach (or in the sea, near the beach). What does it mean? My (and your) photos are scanned and analyzed. I've heard literally zero noise about this feature - nobody was complaining (at least not loud enough to let me notice it). So, why the hell all of that fuzz is being raise…

What are those cases where they might be checked by humans? To determine whether it's an innocent baby bath? If you have naked photos of a partner which happen to hit a statistical match for certain patterns that are similar to CSAM? These aren't far fetched scenarios, these are exactly the most likely types of photos that would be likely flagged. Are you okay with those photos being passed around Apple's security re…

I’m not even sure if it's a joke or you are serious.

It is a check against existing hashes in a big database of confirmed CSAM. What are the chances that photos of your partner are in that database? If your partner is older than 12 - it's 0%.

Who is taking more risk to be sued for the leakage of the photos, you or Apple?

The last part doesn't worth to be discussed because children in that DB are younger than 12.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#142

Imagine taking a photo or have in your gallery a photo a dear leader doesn't want to spread. Ten minutes later you heard a knocking at your door. That's what I'm most worried about, how is this not creating the infrastructure to ensnare political dissidents.

I am profoundly disappointed that almost all of the discussion is about the minutiae of the implementation, and "Hmm.. Am I ok with the minutiae of Apple's specific implementation at rollout?" And almost nobody is discussing the basic general principle of whether they want their own device to scan itself for contraband, on society's behalf.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#143

Earlier quoted context omitted.

Even HN reporting / article linking / comments have been surprisingly low quality and seem to fulminate and declaim with surprisingly little interesting conversation and tons of super big assertions. Linked articles and comments have said apple's brand is now destroyed, that apple is committing child porn felonies somehow with this (the logical jumps and twisting to get to these claims are very far from strong plausi…

From https://www.hackerfactor.com/blog/index.php?/archives/929-On... > The laws related to CSAM are very explicit. 18 U.S. Code § 2252 states that knowingly transferring CSAM material is a felony. (The only exception, in 2258A, is when it is reported to NCMEC.) In this case, Apple has a very strong reason to believe they are transferring CSAM material, and they are sending it to Apple -- not NCMEC. > It does not matt…

Ahh - an "irrefutable" claim that apple is committing child porn felonies.

This is sort of what I mean and a perfect example.

People imagine that apple hasn't talked to the actual folks in charge NCMEC.

People seem to imagine apple doesn't have lawyers?

People go to the most sensationalist least good faith conclusion.

Most mod systems at scale are using similar approaches. Facebook is doing 10's of MILLIONS of images to NCMEC, these get flagged by users and/or systems, and in most cases then facebook copies, checks through moderation queue and submits to NEC.

Reddit uses the sexualization of minors flags. In almost all cases, even though folks may have strong reasons to believe some of this flagged content is CSAM, it still gets a manual look. Once they know they act appropriately.

So the logic of this claim about apples late to party arrival of CSAM scanning is weird.

We are going to find out that instead of trying to charge apple with some kind of child porn charges, NCMEC and politicians are going to be THANKING apple, and may start requiring others with E2EE ideas to follow a similar approach.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#144
post #57

Earlier quoted context omitted.

Non-zero being technically true because of the subject matter, but I don’t see how Apple’s system increases the risk of authorities killing family or pets more than server-side scanning.

Their neural hashing is new, and they claim has a one in a trillion collision rate. There are 1.5 trillion images created in the US and something like 100 million photos in the compared database. That's a heck of a lot of collisions. And that's just a single year, Apple will be comparing everyone's back catalog. A lot of innocent people are going to get caught up in this.

I think you're wrong about the risk (the paper says per account), but even so you need to compare it to the alternatives.

Photos in iCloud are unencrypted and Apple checks for CSAM on the unencrypted photos server side, they know of all matches.

OR

Photo hashes are checked client side and only if a certain threshold of matches is passed does Apple get notified at all (at which point there's a sanity check for false positive by a person). This would allow all photos on iCloud to be able to be encrypted e2e.

Both only happen when iCloud photo backup is enabled.

The new method reduces the risk.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#145
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

[deleted]

Re: The deceptive PR behind Apple’s “expanded protections for children”

#146
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

No. The CSAM (Child Sexual Abuse Material) scanning is comparing hashes of photos about to be uploaded to iCloud against a specific set of images at NCMEC (National Center for Missing and Exploited Children) which are specific to missing and exploited children. It is not machine learning models looking for nudes or similar. It is not a generalized screening. If enough matched images are found, the images are flagged…

The correct answer is a well qualified "Maybe." The hashes are fuzzy AI generated weights. It's impossible to know what will cause a false-positive.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#147

Any idea why Apple didn’t just implement server side scanning like everyone else?

It's a good question. The only explanation that makes sense is that this now allows them to begin end-to-end encryption of iCloud photos. I see that many commentators are claiming that they could already have started e2e encryption without introducing this "backdoor." While this is true, Apple would then be creating a perfect environment for child abusers to house their CSAM content on Apple's own servers. You can understand why Apple might not want to do that.

This allows Apple to get to what is in their mind the best of both worlds: a truly private cloud for their valued users while not creating a safe haven for child abusers.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#148

Earlier quoted context omitted.

That's the crux of it. Why bother with on-device identification, unless one of: a. Apple intends to E2E encrypt iCloud data. b. This is intended to extend to all photos on the device in the future. I'm hoping it's (a), but it's probably (b). And in either case it sets a bad precedent for other companies to follow. Edit: This also turns every jailbreak into a possible CSAM detection avoidance mechanism, giving the gov…

Where is this stance coming form that Apple needs to break E2E crypto to be "able" to "E2E encrypt iCloud data"? That makes absolutely no sense. There is nowhere such a requirement. They could just E2E encrypt iCloud data. Point.

They could E2E iCloud, of course. Question is whether they could while still staying on the right side of the law.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#149
Dear tech users,

Associating with some of you has become a liability. One may be smart enough to avoid iPhone and Alexa et al. but what to do when one is surrounded by people who willingly expose themselves to nefarious technology?

In short, I don't want pictures of me being hoovered up along with your baby pics from your iPhone.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#150
post #7

Earlier quoted context omitted.

Arent the perceptual hashes based on a chunk of the image? I wonder what the false positive rates are for: - A random image against the DB of perceptual hashes - Images of a baby's skin against the DB of perceptual hashes It seems like the second would necessarily have a higher false positive rate: similar compositions (contains baby's skin) would more likely have similar chunks. Is it just a little higher or several…

According to https://rentafounder.com/the-problem-with-perceptual-hashes/ the false-positive rate will be likely high. Given the billions of pictures going through this system there are going to be a lot of false accusations of child porn possession likely (and alone such an accusation can ruin lives). HN discussion of that article from a few days ago: https://news.ycombinator.com/item?id=28091750

This is where the thresholding and manual review come in, but could be a bit scary for sure.
Post reply on HN