Live data from Hacker News

One Bad Apple

hackerfactor.com

181–190 of 557 posts

Re: One Bad Apple

#181
post #174

Earlier quoted context omitted.

> I built the initial FotoForensics service in a few days. Why did you specify "In a few days"?

It does make one wonder--careless work, trivial problem, reuse of existing projects, writer portrays self as extremely productive, or some combination?

I think you're assuming bad faith from someone who has proven very competent, technical, and coherent.

It might simply be truthful. And if the author is proud of that, it is both irrelevant and perfectly okay. Let's focus on the facts and arguments relevant to the article, not personal attacks.

Re: One Bad Apple

#182

There is one particular thing I don’t understand about this Apple policy: You can buy a SIM card and send images to your enemies/competitors through WhatsApp, and these images automatically gets downloaded to iPhone and potentially uploaded to iCloud. What precautions are Apple taking against such actions? Or will it be some kind of exploitable implementation where you can easily swat any person you want and let them…

I know of no messaging app the “automatically” uploads to iCloud. And what sort of idiot would try and send CP using a messenger app (almost all of which CASM detection). That’s like trying to smuggle drugs past the TSA so you can put them in someone’s house to frame them.

The app doesn’t. The iOS camera roll uploads newly captured or saved images when it connects to Wi-Fi.

Re: One Bad Apple

#183
post #132

Earlier quoted context omitted.

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

>About this time, someone usually mocks "it's always about the kids, think about the kids." To those critics: They have not seen the scope of this problem or the long term impact. There is nearly a 1-to-1 relationship between people who deal in CP and people who abuse children. And they rarely victimize just one child. Nearly 1 in 10 children in the US will be sexually abused before the age of 18. I think we have see…

Any reach into privacy, even while "thinking of the kids" is an overreach. Police can't open your mail or search your house without a warrant. The same should apply to your packets and your devices.

Why not police these groups with.. you know.. regular policing? Infiltrate, gather evidence, arrest. This strategy has worked for centuries to combat all manner of organized crime. I don't see why it's any different here.

Re: One Bad Apple

#184
post #148

Earlier quoted context omitted.

>Is it intangible? 18% of the world lives in China alone. That's more people than the "1/10 who are victims of child abuse*", and I'm sure that 18% will only grow as other authoritarian countries get more technologically advanced. You didn't mention any tangible results here. How would this system by Apple make my life worse? Can you answer that without a slippery slope argument? >I think "Think of the kids" applies…

>> You didn't mention any tangible results here. How would this system by Apple make my life worse? Can you answer that without a slippery slope argument? That's a weird goal-post. >> Why does the causality matter? A correlation is enough that cracking down on this content will result in less abusers on the streets. Obviously of the people who look at cp, a higher percentage of those will be actual child abusers. The…

>Well you didn't cite anything at all, and were off by a shockingly large number.

Sorry, I am just baffled by your last point here. How can I be off by a shockingly large number when I didn't even cite a number?

Re: One Bad Apple

#185

Earlier quoted context omitted.

> Apple can’t change their TOS Why not... has anyone actually successfully sued a company for changing their ToS from under them?

Yes, see Douglas v. Talk America.

Thanks for the link.

... but I'm not sure that would apply here, especially if Apple has a pop-up that the user dismissed a long time ago.

Re: One Bad Apple

#186
post #154

Earlier quoted context omitted.

I don't know how I feel about all of this yet (still trying to understand better), but your post implies that you've made a lot of incorrect assumptions about how this system works. For example, the main system in discussion never sends the image to Apple, only a "visual proxy", and furthermore, it only aims to identify known (previously cataloged) CSAM. There's a [good primer of this on Daring Fireball]( https://dar…

Legally, a visual proxy of CP is CP

And?

My point about visual proxies was in reference to the OP's point:

> Also, what controls exist on those who have to review the material? What if it's a nude photo of an adult celebrity? How confident are we that someone can't take a snap of that on their own phone and sell it or distribute it online? It doesn't have to be a celebrity either of course.

I never said that a visual proxy/derivitive wasn't CSAM.

I assume your point had something to do with the legality of sending this data to Apple for review?

I'm not a lawyer, and I have read that NCMEC is the only entity with a legal carve out for possessing CSAM, but if FB and Google already have teams of reviewers for this type of material and other abuse images, I imagine there must be a legal way for this type of review to take place. I mean, these were all images that were being uploaded to iCloud anyway.

Re: One Bad Apple

#187
post #132

Earlier quoted context omitted.

>About this time, someone usually mocks "it's always about the kids, think about the kids." To those critics: They have not seen the scope of this problem or the long term impact. There is nearly a 1-to-1 relationship between people who deal in CP and people who abuse children. And they rarely victimize just one child. Nearly 1 in 10 children in the US will be sexually abused before the age of 18. I think we have see…

Any reach into privacy, even while "thinking of the kids" is an overreach. Police can't open your mail or search your house without a warrant. The same should apply to your packets and your devices. Why not police these groups with.. you know.. regular policing? Infiltrate, gather evidence, arrest. This strategy has worked for centuries to combat all manner of organized crime. I don't see why it's any different here.

Devil's advocate: It may not be mostly big organized crime. It may be hard to fight, because it's not groups. It mostly comes from people close to the families, or the families themselves.

Here's a relevant extract sourced from Wikipedia:

"Most sexual abuse offenders are acquainted with their victims; approximately 30% are relatives of the child, most often brothers, sisters, fathers, mothers, uncles or cousins; around 60% are other acquaintances such as friends of the family, babysitters, or neighbours; strangers are the offenders in approximately 10% of child sexual abuse cases.[53] In over one-third of cases, the perpetrator is also a minor.[56]"

Content warning: The WP article contains pictures of abused children.

Re: One Bad Apple

#188
post #161

Earlier quoted context omitted.

>I think the actual idea, which the nuance is often lost (and let's be honest, some people aren't really aware of and are just jumping on the bandwagon), is that privacy is a right, and erosion of rights is extremely important because it has been shown many times in the past to have far reaching and poorly understood future effects. The encryption everywhere mindset of a lot of the tech community is changing the natu…

In the past these people would have been developing the pictures themselves, and handing them between each other either personally or in some hidden manner using public systems. Not only has communication become easier, so has surveillance. The only difference now is that it's easier for people not to be aware when their very personal privacy is invaded, and that it can be done to the whole populace at once.

>Not only has communication become easier, so has surveillance.

It is a devil's advocate response, but can you explain why this is a bad thing? If communication is scaling and becoming easier, why shouldn't surveillance?

Re: One Bad Apple

#189
post #142
post #103

Earlier quoted context omitted.

> There was parents arrested over bath time and playing in the yard sprinklers, photos being processed at photo mats, will the same thing happen by apple mistakenly reporting parents? No, because they’re not identifying content, they’re matching it against a set of already-known CSAM that NCMEC maintains. As you go on to say, telecoms and other companies already do this. Apple just advanced the state of the art when…

It's a lossy hash match though. If it wasn't, then subtly re-encoding the image would hide it. So they're definitely going to be mistakingly matching images.

And any mistakes would be caught by the manual review.

Re: One Bad Apple

#190
post #103

There was parents arrested over bath time and playing in the yard sprinklers, photos being processed at photo mats, will the same thing happen by apple mistakenly reporting parents? When I worked telecom, we had md5sum database to check for this type of content. If you emailed/sms/uploaded a file with the same md5sum, your account was flagged and sent to legal to confirm it. Also if a police was involved, the account…

> There was parents arrested over bath time and playing in the yard sprinklers, photos being processed at photo mats, will the same thing happen by apple mistakenly reporting parents? No, because they’re not identifying content, they’re matching it against a set of already-known CSAM that NCMEC maintains. As you go on to say, telecoms and other companies already do this. Apple just advanced the state of the art when…

A set of unverified hashes that you hope only came from NCMEC. Telecoms do this on their own devices - not yours.

Apple just opened the door for constant searches of your digital devices. If you think it will stop at CSAM you have never read a history book - the single biggest user of UKs camera system originally intended for serious crimes are housing councils checking to see who didn't clean up after their dog.

Post reply on HN