Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

151–160 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#151
post #116

Earlier quoted context omitted.

I'm kinda amazed. I mentioned I was thinking of moving from an Android phone to Apple soon, somewhat privacy related. My friends lectured me on "they're scanning your photos" ... meanwhile they share their google photos albums with me and marvel about how easy they are to search ... Maybe we (humans) only get outraged based on more specific narratives and not so much the general topics / issues? I don't know but they…

Isn't there a small difference between these? A) They scan everything I have released to google photos B) They scan everything that exists on my device Psychologically, you'll feel a difference in what you accept between the two, I think

Isn't the default on Android these days that all images get uploaded ("backed up") to Photos? And how many users are actually altering defaults?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#152
post #116

Earlier quoted context omitted.

I'm kinda amazed. I mentioned I was thinking of moving from an Android phone to Apple soon, somewhat privacy related. My friends lectured me on "they're scanning your photos" ... meanwhile they share their google photos albums with me and marvel about how easy they are to search ... Maybe we (humans) only get outraged based on more specific narratives and not so much the general topics / issues? I don't know but they…

Isn't there a small difference between these? A) They scan everything I have released to google photos B) They scan everything that exists on my device Psychologically, you'll feel a difference in what you accept between the two, I think

As has been repeated over and over, apple only scans photos that are part if icloud photos (ie, uploaded).

Don't want your photo's scanned, don't sync them to icloud. Seriously! Please include the actual system when discussing this system, not your bogeyman system.

"To help address this, new technology in iOS and iPadOS* will allow Apple to detect known CSAM images stored in iCloud Photos."

To increase privacy - they perform the scan on device prior to upload.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#153
post #130

Earlier quoted context omitted.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

But who was complaining about google and microsoft doing the cloud scanning? I don’t mind my one drive being scanned for “bad stuff”, I very much mind my personally owned data stores being scanned, with no opt out.

The only thing Apple scans are files you upload to iCloud Photos.

If you turn off iCloud Photos, nothing is scanned.

Microsoft scans everything.

>The system that scans cloud drives for illegal images was created by Microsoft and Dartmouth College and donated to NCMEC. The organization creates signatures of the worst known images of child pornography, approximately 16,000 files at present. These file signatures are given to service providers who then try to match them to user files in order to prevent further distribution of the images themselves, a Microsoft spokesperson told NBC News. (Microsoft implemented image-matching technology in its own services, such as Bing and SkyDrive.)

https://www.nbcnews.com/technolog/your-cloud-drive-really-pr...

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#154
post #130

Earlier quoted context omitted.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

But who was complaining about google and microsoft doing the cloud scanning? I don’t mind my one drive being scanned for “bad stuff”, I very much mind my personally owned data stores being scanned, with no opt out.

Where's the line though? Would you be upset that the Dropbox client scanned things before uploadng it? What about the Google Drive client JS?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#155

What's shocking to me is how little Apple management understood of what their actions looked like. Really stunning. For a company that marketed itself as one of the few digital service providers that consumers could trust, I just don't understand how they acted this way at all. Either there will be heads rolling at management, or Apple takes a permanent hit to consumer trust.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar. Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people l…

Here's the reason for the sudden uproar: The scanning of things on third party servers was just barely tolerated by a lot of people, whether it's for advertising purposes or government intrusion. People accept it because it's considered reasonable for these third parties to scan data in exchange for providing a service for free (e.g. Google), or because they need to have some degree of accountability for what is on their servers.

When that scanning gets moved from the cloud to being on your device, a boundary is violated.

When that boundary is violated by a company who makes extreme privacy claims like saying that privacy is a "fundamental human right"[1], yes, people will "lose their minds" over it. This shouldn't be shocking at all.

[1] https://apple.com/privacy

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#156

Earlier quoted context omitted.

The thing that's shocking to me is that Google, Microsoft and all the big names in tech have been scanning everything in your account (email, cloud drive, photos, etc) for the past decade, without any noticeable uproar. Apple announces that it is going to start scanning iCloud Photos only, and that their system is set to ignore anything below a threshold of ~30 positives before triggering a human review, and people l…

BigCos, take note: you’re better off doing nefarious shit without telling anyone. Because, if you come clean, you’ll only invite an endless parade of bloggers who will misconstrue your technology to make you look bad.

No misconstrual needed. This technology is genuinely bad. It scans images against an arbitrary government-owned black-box database. There’s no guarantee that it’s only CSAM.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#157
post #131

Earlier quoted context omitted.

That's what they're saying, the key difference is Apples happens on your device, not theirs.

That's not really better or different. In any meaningful way.

Then why the outrage if they're the same?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#158
post #124

Would this work as an attack? 1. Get a pornographic picture involving young though legal actors and actresses. 2. Encode a nonce into the image. Hash it checking for CSAM collisions. If you've found a collision go on to the next step, if not update the nonce and try again. 3. You now have an image that, to visual inspection will appear plausibly like CSAM, and to automated detection will appear like CSAM. Though, pre…

How would you know if it's a CSAM collision? I don't believe that database is publicly available anywhere, for obvious reasons.

Apple's client clearly has some revealing information on that...

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#159

Earlier quoted context omitted.

BigCos, take note: you’re better off doing nefarious shit without telling anyone. Because, if you come clean, you’ll only invite an endless parade of bloggers who will misconstrue your technology to make you look bad.

No misconstrual needed. This technology is genuinely bad. It scans images against an arbitrary government-owned black-box database. There’s no guarantee that it’s only CSAM.

NECMEC isn’t owned by the government and the database of hashes is available from Apple.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#160

Earlier quoted context omitted.

Isn't there a small difference between these? A) They scan everything I have released to google photos B) They scan everything that exists on my device Psychologically, you'll feel a difference in what you accept between the two, I think

> B) They scan everything that exists on my device No ... They scan everything that I have released to apple photos that exists on my device. Same scan - different place.

The issue is that as soon as you set that precedent, it’s only a matter of time before it extends beyond iCloud. That’s the problem with doing any device-level scanning. This is dystopian and scary. And yes I understand the technology in its current iteration. The current form has problems (weaponizing collisions etc) but the real issue comes with future developments.
Post reply on HN