Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

151–160 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#151

Earlier quoted context omitted.

It has already be announced, this is not only iOS, but all Apple devices.

Great. I recently invested $3800 in an excellent, new iMac. Now I'm starting to wonder if I should have spent a couple thousand less for a barebones PC and installed my favorite Linux distro. It would have done 75% of what I needed, and the other 25% (music and video work)... well, that's the tradeoff. If anyone in my circle of family, friends, and social network asks my advice, the formerly easy answer "Get a Mac, g…

The CSAM detection technical summary [1] only mentions iOS and iPadOS.

If it does come to macOS it will be part of Photos.app, as that's the only way to interact with iCloud Photos. I would recommend you to avoid that app and cloud in general if you care about privacy.

[1] https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

Re: Apple's child protection features spark concern within its own ranks: sources

#152

Earlier quoted context omitted.

> Secondly, it seems rife for abuse: dont like someone who uses an ios device, msg them some cp and destroy their entire life. I see this a lot. First of all, if you even have CP in the first place that seems quite bad and that you've made yourself vulnerable. Messaging someone will also reveal yourself as the sender. But my bigger question of this hypothetical issue is that Facebook, Google, Dropbox, Microsoft, etc…

>Messaging someone will also reveal yourself as the sender Sending a link to 4chan /b would probably be enough. Or a hidden iFrame in a forum post. Its very very easy to get images onto someones device without their consent, getting them to upload them to a 3rd party is completely different.

So again, how is this different from Google Photos, Facebook messenger, etc etc?

If this really was such an issue we would have hit it long ago. CSAM scanning is going occurring for photos that would be uploaded to iCloud.

Re: Apple's child protection features spark concern within its own ranks: sources

#153
post #131

Earlier quoted context omitted.

But with a debian package you can choose not to accept the upgrade and see any funny business in the release source code..

That is technically true but in a real very practical sense everyone here using OSS absolutely is trusting a third party because they are not auditing every bit of code they run. For less technical people there is effectively zero difference between open and closed software. It’s really disingenuous to suggest that open source isn’t dependent on trust, you just change who you are trusting. Even if the case is someone…

Thinking about this.. I guess my trust, is that someone smarter than I will notice it, cause a fuss, and the community will raise pitch forks and.. git forks. My trust is in the community, I hope it can stay healthy and diverse for all time.

Re: Apple's child protection features spark concern within its own ranks: sources

#154
post #6

Don't use cloud services or closed-source services if you want your stuff to be safe and you want your privacy to be maintained.

Er, do you have a recommendation for non-cloud services that provide me with automatic backups of everything I do if something happens to my apartment, or open-source services that are free of all security flaws allowing hackers to compromise your privacy? Like I wholeheartedly get where you're coming from, but I'm not sure what realistic alternatives look like.

Since we're on HN. Use something like restic and a cron job backing up to something like blackblaze.

Yes, it's the cloud, but they don't control the backup software (it's open source, not developed by them, using public APIs) or the encryption keys (protected by a passphrase client side, use a good one).

There may be less programmery equivalents of that, which have scheduling built into the backup tool and so on. Just recommending what I've used.

(This advice applies to general purpose computers, not sure if there's an equivalent for android or iOS)

Re: Apple's child protection features spark concern within its own ranks: sources

#155
post #143

Earlier quoted context omitted.

>Sure, but I don't particularly care because I don't upload sensitive photos to iCloud So you are saying you have nothing to fear because you aren't hiding anything? Is this a tacit admission that you don't want them scanning your phone for CSAM because they will find something? I'm obviously not seriously accusing you of anything, just pointing out how your line of argument applies equally to privacy whether on the…

> So you are saying you have nothing to fear because you aren't hiding anything? No, I'm saying that if you're hiding something, maybe don't give it to someone else.

"I'm not giving my photos to anyone. I am just taking photos on my phone and Apple is automatically backing them up to iCloud. I have no idea how that feature was turned on or how to turn it off." ~ most normal people.

People here too often only think of these issues from the perspective of the type of person who browses HN. Apple is thinking of this from the perspective of an average iPhone users.

Re: Apple's child protection features spark concern within its own ranks: sources

#156

In their attempt to make this extra private by scanning 'on device', I think they've managed to make it feel worse. If they scan my iCloud photos in iCloud, well lots of companies scan stuff when you upload it. It's on their servers, they're responsible for it. They don't want to be hosting CSAM. It feels much worse them turning your own, trusty iPhone against you. I know that isn't how you should look at it, but tha…

In a few years, all the pedophiles will stop using iPhone, and then only innocent people will be scanned in perpetuity. Remember, if someone makes new CSAM, it won't match any hashes so even "new" pedophiles won't get caught by this.

So really, the steady state is just us regular folks getting scanned. As the years go on, what is defined as CSAM will morph into "objectionable material", and will then include "misinformation" like today. They say they won't right now, but where will things be in a few years?

Re: Apple's child protection features spark concern within its own ranks: sources

#157

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

Hey it's still private... unless you have content that matches an opaque, government controlled list of forbidden content... what could go wrong?

Re: Apple's child protection features spark concern within its own ranks: sources

#158
> It's a complete change of narrative and there's no easy way to explain it and still defend Apple's Privacy narrative, wihout doing extreme mental gymnastics.

Everyone who took Apple at their word was already doing extreme mental gymnastics because Apple's privacy stance was a farce on borrowed time to begin with. Now it's just blatantly obvious to everyone.

Re: Apple's child protection features spark concern within its own ranks: sources

#159
post #83
post #32

Earlier quoted context omitted.

Simple - our laws haven't evolved with technology. That's why your mail has about a million times more protection than your email.

This cuts both ways. Our laws not evolving with technology is also the reason why tapping and intercepting secured digital communication is orders of magnitude more difficult than tapping someone's analog phone line, or why decrypting a hard drive is far more difficult for the police than sawing apart a safe.

Agreed. Technology has allowed abusive images to thrive and reach new consumers. Any pressure to "evolve laws with technology" will surely lead to more draconian anti-privacy measures.

Re: Apple's child protection features spark concern within its own ranks: sources

#160
post #111
post #62

Earlier quoted context omitted.

In reality, the fact that they do the scanning on-device is actually better privacy-wise. But I can see how instinctually it “feels” wrong.

Can you explain how it is better? If they only scanned icloud I can choose to not use that. If they scan on my iphone my choice would be to stop using that and get a gphone instead.

It only runs if you have iCloud photos enabled.

Then it only runs client side and alerts if there are matches to CSAM hashes above some threshold.

The other way is it runs against unencrypted images in iCloud and they'd know of any match.

The new method also paves the way for the iCloud photos to be encrypted (they're currently not).

Post reply on HN