Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

171–180 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#171

Earlier quoted context omitted.

Yes, it’s an argument but there’s zero data to support it, in fact the opposite. If this were true then widespread availability of pornography on the internet would have resulted in a massive increase in rape of adult females. When in fact, assault numbers have been on a steady decline for decades.

Why would general pornography lead to rape? Most pornography is not rape pornography. Would people watching a bunch of rape pornography lead to more rapes? I don't know, but that seems more likely than general pornography leading to rapes. 60% of respondents who were found looking for CSAM on the dark web stated that they were fearful that consuming CSAM would lead them to do something to a child in real life: https:…

Does it need to be said that by making all pornography easier to access the internet obviously makes rape pornography more prevalent and easier to access as well?

Hence your theory should be easily visible in rape statistics, yet it’s the opposite.

Re: Apple defeats liability for not scanning iCloud for CSAM

#172

Earlier quoted context omitted.

It also means no banking app will work

Banks are probably the most Orwellian surveillance apparatus of all. Almost every time I read an arrest warrant there is a whole section where banking records are used to damn someone. The equivalent level of banking privacy to graphene is roughly walking in to the teller to withdraw a few thousand cash once a month and then paying literally everything with that (or an anonymized crypto).

I don't think you understand banking

https://www.ncontracts.com/nsight-blog/risk-management-strat...

Re: Apple defeats liability for not scanning iCloud for CSAM

#173

Earlier quoted context omitted.

Have you considered the implications of what you're saying? A whistleblower goes to a therapist, stressed out over their pending decision to reveal official misconduct. They've been investigating ways to post something on the internet that can't be immediately taken down by the corrupt government officials they want to expose. They express their discomfort, in confidence, to their therapist, about using something the…

I used to have a good friend that was a stripper (I promise, I wasn't the client...). Some of her biggest customers were people that wanted therapy without the paper trail of going to a licensed therapist. This is a big thing for pilots as well, since their health records and mental care are intensely scrutinized. A stripper will provide comfort, verbal relief, and physical love for $100 hour you can tell them anythi…

Makes you wonder if there's a strip-joint where they're all licensed therapists, but non-practicing.

Re: Apple defeats liability for not scanning iCloud for CSAM

#174

Earlier quoted context omitted.

Why would general pornography lead to rape? Most pornography is not rape pornography. Would people watching a bunch of rape pornography lead to more rapes? I don't know, but that seems more likely than general pornography leading to rapes. 60% of respondents who were found looking for CSAM on the dark web stated that they were fearful that consuming CSAM would lead them to do something to a child in real life: https:…

Does it need to be said that by making all pornography easier to access the internet obviously makes rape pornography more prevalent and easier to access as well? Hence your theory should be easily visible in rape statistics, yet it’s the opposite.

It would be easily visible or not visible in the rape statistics if the world had a single variable. In any case, even if the world was extremely simple, 'rape porn' could increase rapes, and we could still observe a decrease in rapes if 'general porn' decreased the odds of rape to a larger degree than rape porn increased them relative to the population that consumed each.

Re: Apple defeats liability for not scanning iCloud for CSAM

#175
post #79

I am not a lawyer. There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example: * A: physical sexual abuse of children. B: possession or distribution of CSAM * A: drug trafficking or tax evasion. B: structured cash withdrawals The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A. It's my understanding that conv…

No. In short, in US law, CSAM is a visual depiction of a real-world act of child sexual abuse. Visual depictions like you're describing are covered under a different law, and I'm not aware of it having a short name. There's a good expert thread on this with links to the relevant federal laws here: https://bsky.app/profile/rahaeli.bsky.social/post/3lbt7zkvlq...

Currently it is explicitly against the law[0]:

  (a)In General.—Any person who, in a circumstance described in subsection (d), knowingly produces, distributes, receives, or possesses with intent to distribute, a visual depiction of any kind, including a drawing, cartoon, sculpture, or painting, that—
    (1)
      (A)depicts a minor engaging in sexually explicit conduct; and
      (B)is obscene; or ...
  (b)...
  (c)Nonrequired Element of Offense.—
  It is not a required element of any offense under this section that the minor depicted actually exist.

It is not a required element of any offense under this section that the minor depicted actually exist.

[0]https://www.law.cornell.edu/uscode/text/18/1466A

Re: Apple defeats liability for not scanning iCloud for CSAM

#176

Earlier quoted context omitted.

Yes, in the sense that you have a legal doctor-patient privilege that binds what they can share with whom. There's not really an Apple cloud user privilege. No, in the sense that your therapist is still required to report you to the police in various situations where you pose an immediate threat to yourself or others, etc.

A better analogy is a storage locker. AFAIK police need a warrant to search "your" storage locker even though it's on someone else's property. I don't see why data in the cloud should be any different. Pre-emptively scanning everyone's data is equivalent to officers rummaging through all the storage lockers in a facility "just in case" they find something illegal.

It’s a bit more like requiring you to submit to a weapons pat down before you go to your locker I think.

Re: Apple defeats liability for not scanning iCloud for CSAM

#177

Earlier quoted context omitted.

No matter how or why? That seems like a terrible mandate.

They are mandated to report child abuse. It is the same story with doctors, if an abusive parent brings in a child for care they learn never to give the kid healthcare again after the doctor reports it. It is rooted in good intentions but the effect is it means abused children never get to see doctors, therapists, get a half-ass minimal homeschool instead of going to school, etc so that mandated reporters never enter…

Reporting abuse the client was involved in has a compelling reason. That's different from hearing their client saw a picture of the abuse of a total stranger.

Re: Apple defeats liability for not scanning iCloud for CSAM

#178

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

> It is crazy people think apple isnt on the side of privacy.

Apple is on the side of making money, and the privacy claims are mostly marketing. The entire stack is closed source, which means it is difficult and expensive to independently verify any of the claims made. What's more, the "auto update" universal backdoor means that Apple can forcibly push a user-hostile "feature" like client-side scanning when it wants or is compelled to by a state actor.

Re: Apple defeats liability for not scanning iCloud for CSAM

#179
post #123

Earlier quoted context omitted.

I still also totally don't get their policy. Trying to avoid false positives by not firing until a threshold was hit (was it 20 images?) seemed insane from a PR position... rightly or wrongly, all it would take would be the wrong court case and you can see the headlines: "Apple says users can have up to 20 CSAM images on their phone before they'll tell police"

Imagine you have pictures of someones baptism and the kid was nude. Is it CSAM? I think the program would have to say use but morally I'd say no. The issue with client scanning is it has to assume the worst, or they are than liable. If its the person has 20+ different baptism of nude babys well huh that actually might be CSAM because the context of how that concentrated photos implies but even than its hard what if t…

The proposed mechanism was hash matching against known CSAM images, so the baptism photos would not trip the filter because they wouldn’t be hash matches.

Re: Apple defeats liability for not scanning iCloud for CSAM

#180

IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it. Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt…

> IMO "end-to-end encryption" simply isn't possible

In a technical sense it's absolutely possible. Owning the servers != transferring keys to the servers. Most E2E apps run both client and servers, it's about if they ever had key access.

Post reply on HN