Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

161–170 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#161
post #109
post #47

Earlier quoted context omitted.

In this TechCrunch interview, Apple believes it is less invasive since no one can be individually targeted. The hashes are hard coded into each iOS release which is the same for all iOS devices. The database is not vulnerable to server side changes. Additionally, FWIW, they do not want to start analyzing entire iCloud photo libraries so this system only analyzes new uploads. https://techcrunch.com/2021/08/10/intervie…

>The hashes are hard coded into each iOS release Do you have a source on that? Since it is illegal to share those hashes in any way or form. Even people working with photo forensic and big photo sharing sites cannot get access to them. I very much doubt Apple can incorporate them into the iOS release without breaking multiple laws. The hashes themselves can easily be reversed to (bad quality) pictures so having the h…

From the interview I linked, Apple Privacy head Erik Neuenschwander said, “The hash list is built into the operating system, we have one global operating system and don’t have the ability to target updates to individual users and so hash lists will be shared by all users when the system is enabled.”

Where did you hear sharing hashes is illegal? How would anybody determine whether CASM at scale without those hashes?

Your hackerfactor source states, “In 2014 and 2015, NCMEC stated that they would give MD5 hashes of known CP to service providers for detecting known-bad files.”

Re: The deceptive PR behind Apple’s “expanded protections for children”

#162
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

[deleted]

Re: The deceptive PR behind Apple’s “expanded protections for children”

#163
post #112
post #6

Earlier quoted context omitted.

It's worth reading this, which is basically the only good reporting I've seen on this topic: https://daringfireball.net/2021/08/apple_child_safety_initia... There are legitimate things to be concerned about, but 99% of internet discussion on this topic is junk.

I still don't understand how this is allowed. If the police want to see the photos on my device, then they need to get a warrant to do so. Full stop. This type of active scanning should never be allowed. I hope that someone files a lawsuit over this.

Speculating (IANAL) - it's only when iCloud photos is enabled. I'd guess this is akin to third party hosting the files, I think the rules around that are more complex.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#164
post #132
post #65

Earlier quoted context omitted.

The design more plausible enables total device surveillance than questionable iCloud Backups. (I refuse to call a backdoored setup E2EE)

That’s silly. The design is so narrowly tailored to scan for CSAM that nobody can use it for anything else.

It all depends on what perceptual hashes you use. If Apple can institute a process whereby those are tied to the OS version, but not to the region, then it would be impossible to impose jurisdiction-specific exceptions.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#165

Earlier quoted context omitted.

"But look, I've re-compressed it with JPEG 80%. It's not THAT picture!". It would be interesting to hear what a court has to say if a child porn consumer would try to defend him/her with this "argument".

Love 'em or hate 'em, it is hard to believe Apple's lawyers haven't very carefully figured out what kind of derivative image will be useful to catch false positives but not also itself illegal CP. I assume they have in fact had detailed conversations on this exact issue with NCMEC.

Firstly, the NCMEC doesn't make the the laws. They can't therefore give any exceptional allowance to Apple.

Secondly, any derivatives that are clear enough to enable a definitive judgment whether something's CP or not by an Apple employee would be subject to my argument above. Also just collecting such material is an felony.

I don't see any way around that. Only that promising some checks before stuff gets reported for real is just a PR move to smoothen the first wave of pushback. PR promises aren't truly binding…

Re: The deceptive PR behind Apple’s “expanded protections for children”

#166
post #164
post #132

Earlier quoted context omitted.

That’s silly. The design is so narrowly tailored to scan for CSAM that nobody can use it for anything else.

It all depends on what perceptual hashes you use. If Apple can institute a process whereby those are tied to the OS version, but not to the region, then it would be impossible to impose jurisdiction-specific exceptions.

> It all depends on what perceptual hashes you use.

I’m talking about the mechanism as described, not a hypothetical.

> If Apple can institute a process whereby those are tied to the OS version, but not to the region, then it would be impossible to impose jurisdiction-specific exceptions.

As it is the mechanism they have built only works in the US jurisdiction.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#167

What would prevent someone from, for instance, printing off an illegal photo, “borrowing” a disliked co-workers iCloud enabled phone, and snapping a picture of the illegal picture with their camera? On iOS the camera can be accessed before unlocking the phone, and wouldn’t this effectively put illegal image(s) in the targets possession without their knowledge?

These illegal photos are not trivial to obtain. Possessing (and here, the printing step necessitates possession) these illegal photos is in and of itself a crime in most relevant jurisdictions.

But OK, let's say that you've found a way to get the photos and you're comfortable with the criminal implications of that. At that point why don't you just hide the printed photos in your coworker's desk? My point is that if you have a disgruntled coworker who's willing to resort to heinous crimes in order to screw you over, there's many different things they could do that are less convoluted.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#170
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Wait until someone manages to create an image (white noise) that's a hash collision for anything in that database. And then starts spamming random strangers via airdrop.

Enjoy explaining why your mugshot and arrest record had these charges attached to it!

(Actually, in this case the prosecution would probably use the other pictures on the phone that were not detected by the scanning tool as a way to get a guilty plea deal!)

Post reply on HN