Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

171–180 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#171
post #148

Earlier quoted context omitted.

Where is this stance coming form that Apple needs to break E2E crypto to be "able" to "E2E encrypt iCloud data"? That makes absolutely no sense. There is nowhere such a requirement. They could just E2E encrypt iCloud data. Point.

They could E2E iCloud, of course. Question is whether they could while still staying on the right side of the law.

Is there a law requiring device manufactures to search (without any warrant!) the devices of all their customers?

How do for example hard drive manufacturers comply?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#173
Unless Apple can demonstrate that the techniques they are using are intrinsically specific to CSAM and to CSAM only--the techniques do not work for any other kinds of photo or text--slippery slope arguments are perfectly valid and cannot be denied.

Apple is a private company and as such its actions amount to vigilantism.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#174

Earlier quoted context omitted.

No. The CSAM (Child Sexual Abuse Material) scanning is comparing hashes of photos about to be uploaded to iCloud against a specific set of images at NCMEC (National Center for Missing and Exploited Children) which are specific to missing and exploited children. It is not machine learning models looking for nudes or similar. It is not a generalized screening. If enough matched images are found, the images are flagged…

Comparing hashes reminds me of this announcement from a few years ago that Google had produced a SHA1 collision: https://security.googleblog.com/2017/02/announcing-first-sha... Can you imagine the chaos of a successful collision matching some explicit material being sent as a prank or targeted attack?

No chaos. The photos would be reported, reviewers would say "that's weird" since the false positive was obviously harmless and the industry would eventually switch to a different hash method while ignoring the false positives generated by the collision. If there were a flood of false positive images being produced the agencies would work faster to come up with a new solution, not perform mass arrests.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#175
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

The 1 trillion figure is only after factoring in that you would need multiple false positives to trigger the feature. It's not descriptive of the actual false positive rate of the hashing itself.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#176

Earlier quoted context omitted.

From https://www.hackerfactor.com/blog/index.php?/archives/929-On... > The laws related to CSAM are very explicit. 18 U.S. Code § 2252 states that knowingly transferring CSAM material is a felony. (The only exception, in 2258A, is when it is reported to NCMEC.) In this case, Apple has a very strong reason to believe they are transferring CSAM material, and they are sending it to Apple -- not NCMEC. > It does not matt…

Ahh - an "irrefutable" claim that apple is committing child porn felonies. This is sort of what I mean and a perfect example. People imagine that apple hasn't talked to the actual folks in charge NCMEC. People seem to imagine apple doesn't have lawyers? People go to the most sensationalist least good faith conclusion. Most mod systems at scale are using similar approaches. Facebook is doing 10's of MILLIONS of images…

Sorry under which of these other moderation regimes does the organisation in question transmit CSAM from a client device to their own servers? To my knowledge Apple is the only one doing so.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#177
post #59

Earlier quoted context omitted.

Yeah, and as argued in one of the blog posts - that's just a policy decision - not a capability decision - malleable to authoritarian countries' requests.

Yes - and I agree that that's where the risk lies. Though I'd argue the risk has kind of always lied there given companies can ship updates to phones. You could maybe argue it'd be harder to legally compel them to do so, but I'm not sure there's much to that. The modern 'megacorp' centralized software and distribution we have is dependent on policy for the most part.

That's the problem I had with Ben's post - it's always been policy since Apple controls and distributes iOS.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#178
Question:

Would Apple report CSAM matches worldwide to one specific US NGO? That's a bit weird, but ok. Presumably they know which national government agencies to contact.

Opinion:

If Apple can make it so that

a) the list of CSAM hashes is globally the same, independent of the region (ideally verifiably so!), and

b) all the reports go only to that specific US NGO (which presumably doesn't care about pictures of Winnie the Pooh or adult gay sex or dissident pamphlets)

then a lot of potential for political abuse vanishes.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#179

Earlier quoted context omitted.

It turns out people liked it when their phone scanned their photos for 'selfie' or 'beach' for them. Apparently tagging 'child porn' on your photos for searching isnt the killer feature someone thought it might be.

So what you’re saying is if Apple had a 5 year plan to help China disappear minorities, they should’ve just kept improving photos search? Maybe this child safety effort isn’t aimed at satisfying some authoritarian wet dream after all!

[deleted]

Re: The deceptive PR behind Apple’s “expanded protections for children”

#180
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Yes, if they wind up part of a child porn investigation. Your cloud account gets hacked. Some perv gets your images. He is then arrested and his "collection" added to the hash database... including your family photos. Context often matters more than the nature of the actual content. Police aquire thousands of images with little hope of ever knowing where they originated. If they are collected by pervs, and could be c…

It’s worth pointing out that this could happen with any Internet-attached photo storage, and pre-dates Apple’s announcement.

What Apple announced is a new system for reading the existing hash lists of known CSAM images and doing the comparison on the device as part of the iCloud upload, rather than on the server after upload.

Post reply on HN