Live data from Hacker News

One Bad Apple

hackerfactor.com

151–160 of 557 posts

Re: One Bad Apple

#151

Really nice explanation from someone who knows a thing or two about images/photos (Dr. Neal Krawetz is the creator of https://fotoforensics.com and specializes in computer forensics).

He wrongly interpreted CSAM scanning. He said that Apple will scan your photos and if finds something, it will send photo to Apple. Which is absolutely not how it works. Photo is only scanned before uploading to iCloud Photos. Apple already confirmed it to iMore and it’s clearly stated in Apple papers from press-release.

Please stop spreading misinformation.

Apple has built the system to scan your entire phone, their claims about its limited scope are suspect.

Re: One Bad Apple

#152
post #132

Earlier quoted context omitted.

>About this time, someone usually mocks "it's always about the kids, think about the kids." To those critics: They have not seen the scope of this problem or the long term impact. There is nearly a 1-to-1 relationship between people who deal in CP and people who abuse children. And they rarely victimize just one child. Nearly 1 in 10 children in the US will be sexually abused before the age of 18. I think we have see…

> Too often the tech community's response is that the intangible concept of privacy is more important than the tangible issue of child abuse. Is it intangible? 18% of the world lives in China alone. That's more people than the "1/10 who are victims of child abuse*", and I'm sure that 18% will only grow as other authoritarian countries get more technologically advanced. I think "Think of the kids" applies very well to…

> I think "Think of the kids" applies very well to the CREATORS of pornography. Per wikipedia, there isn't any conclusive causal relationship between viewing CP and assaulting children.

“Think of the Kids” damn well applies to the consumers of this content - by definition, there is a kid (or baby in some instances) involved in the CP. As a society, the United States draws the line at age 18 as the age of consent [the line has to be drawn somewhere and this is a fairly settled argument]. So by definition, in the United States, these are not consenting victims in the pictures.

Demand drives creation. Getting rid of it on one of the largest potential viewing and sharing platforms is a move in the right direction in addressing the problem.

What I haven’t seen from the tech community is the idea that this will be shut down if it goes too far or beyond this limited scope. Which I think it would be - people would get rid of iPhones if some of the other cases privacy advocates are talking about occur. And at that point they would have to scrap the program - so Apple is motivated to keep it limited in scope to something everyone can agree is abhorrent.

Re: One Bad Apple

#153
post #61
post #18

There are a lot of articles about Apples hadh algorithm and for me they are mostly irrelevant to the main problem. The main problem is that Apple has backdoored my device. More types of bad images or other files will be scanned since now apple does not have plausible deniablity to defend any of ghe government’x requests. In the future a false? positive that happened? to be of a political file that crept in the list c…

They could have done all that without telling you. And as long as the traffic was combined with normal traffic no one would ever notice (and in this case it would end up mixed with normal traffic since it only applies to images being uploaded to iCloud, so communication with Apples servers would be expected). What it looks like to me is that Apple is planning on releasing end-to-end encryption for iCloud. But they kn…

> They could have done all that without telling you.

But in that case it would much more likely be a crime, it would certainly cost them a tremendous amount of good will.

Your personal computing device is a trusted agent. You cannot use the internet without it, and esp. in lockdown you likely can't realistically live your life without use of the internet. You share with it your most private information, more so even than you do with your other trusted agents like your doctor or lawyers (whom you likely communicate with using the device). Its operation is opaque to you: you're just forced to trust it. As such your device ethically owes you a duty to act in your best interest, to the greatest extent allowed by the law. -- not unlike your lawyers obligation to act in your interest.

Apple is reprogramming customer devices, against the will of many users (presumably at the cost of receiving necessary fixes and security updates if you decline) to make it betray that trust and compromise the confidentiality of the device's user/owner.

The fact that Apple is doing it openly makes it worse in the sense that it undermines your legal recourse for the betrayal. The only recourse people have is the one you see them exercising in this thread: Complaining about it in public and encouraging people to abandon apple products.

E2EE should have been standard a decade ago, certainly since the Snowden revelations. No doubt apple seeks to gain a commercial advantage by simultaneously improving their service while providing some pretextual dismissal of child abuse concerns. But this gain comes at the cost of deploying and normalizing an automated surveillance infrastructure, one which undermines their product's ethical duty to their customers, and one that could be undetectable retasked to enable genocide by being switched to match on images associated with various religions, ethniticities, or political ideologies.

Re: One Bad Apple

#154
post #121

I'm honestly shocked that Apple is buying into this because it's one of those well-intentioned ideas that is just incredibly bad. It also goes to show you can justify pretty much anything by saying it fights terrorism or child exploitation. We went through this 20+ years ago when US companies then couldn't export "strong" encryption (being stronger than 40 bits if you can believe that). Even at the time that was ridi…

I don't know how I feel about all of this yet (still trying to understand better), but your post implies that you've made a lot of incorrect assumptions about how this system works. For example, the main system in discussion never sends the image to Apple, only a "visual proxy", and furthermore, it only aims to identify known (previously cataloged) CSAM. There's a [good primer of this on Daring Fireball]( https://dar…

Legally, a visual proxy of CP is CP

Re: One Bad Apple

#155
post #18

There are a lot of articles about Apples hadh algorithm and for me they are mostly irrelevant to the main problem. The main problem is that Apple has backdoored my device. More types of bad images or other files will be scanned since now apple does not have plausible deniablity to defend any of ghe government’x requests. In the future a false? positive that happened? to be of a political file that crept in the list c…

> The main problem is that Apple has backdoored my device.

Isn't that the shtick with Apple though? That they own the devices you rent and you don't have to worry too much about it. They always had the backdoor in place, they used it for software updates. Now they will also use it for another thing.

Re: One Bad Apple

#156
post #132

Earlier quoted context omitted.

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

>About this time, someone usually mocks "it's always about the kids, think about the kids." To those critics: They have not seen the scope of this problem or the long term impact. There is nearly a 1-to-1 relationship between people who deal in CP and people who abuse children. And they rarely victimize just one child. Nearly 1 in 10 children in the US will be sexually abused before the age of 18. I think we have see…

It’s not just thinking of the victims when they are kids - if they aren’t killed after the material is made, then they have issues for the rest of their life with a real cost to society.

We’re talking a life-long impact from being abused in that stuff…

Re: One Bad Apple

#157
post #109

Earlier quoted context omitted.

> I'm surprised, and honestly disappointed, that the author seems to still play nice Stopping to that level is what they want, CNN: “‘privacy activists’ have released a tool to allow the spread of CP”

If that’s how they play then the only winning move is to respond in kind. >shadowy government affiliated agency abuses its role of protecting children to install malware on a billion devices

That's not even news at this point. Privacy invading laws have been pushed for years under the guise of either CP or terrorism.

Re: One Bad Apple

#158
post #109

Earlier quoted context omitted.

> I'm surprised, and honestly disappointed, that the author seems to still play nice Stopping to that level is what they want, CNN: “‘privacy activists’ have released a tool to allow the spread of CP”

If that’s how they play then the only winning move is to respond in kind. >shadowy government affiliated agency abuses its role of protecting children to install malware on a billion devices

That's a PR fight you will lose.

Re: One Bad Apple

#159

The "legal" section talks about local scanning, and possible transmission of CSAM from devices to Apple, in pursuit of verification, however Apple have made clear that the scanning happens only for files that have been uploaded to iCloud Photo Library -- in which case they are not deliberately transmitting the CSAM but rather flagging something which the user already sent them. Likewise the copyright issue; The user…

This is a short sighted and naive viewpoint.

Apple did not build this entire system to only scan uploads hah.

This was built to scan the entire file system.

Re: One Bad Apple

#160

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

> I built the initial FotoForensics service in a few days.

Why did you specify "In a few days"?

Post reply on HN