Live data from Hacker News

WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

theverge.com

181–190 of 372 posts

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#181
post #105
post #42

Earlier quoted context omitted.

Apple doesn’t scan iCloud for CSAM and refuses to do it. Which is why they researched intensively on differential privacy.

But they could, as iCloud Photos is not e2e (Apple can read all of it) and they turn over the user data on over 30,000 users per year to the USG without even a warrant. This is just farce.

> But they could, as iCloud Photos is not e2e

Client side scanning is a prerequsite to making it e2e if you also want countermeasures against CSAM.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#182

Earlier quoted context omitted.

"Fairphone" It is nice the the fairphone trys to be nice and fair, but I would rather have a focus of a actual open phone under my control and they do not deliver this (not to blame them, the issue is hard). Fixing the global exploitive economy is a different issue and trying to solve everything at once is not working usually. "Librem 5" How useful is a microphone killswitch, if there is no killswitch for the speaker…

>phone with facebook app preinstalled and unremovable I've never used a phone like this, but are you also forced to provide FB credentials during initial setup? If not, then is the FB app just being installed a privacy threat if it is never used? Is it still accessing information on the phone without being tied directly to you?

I have had a phone that had a Facebook application preinstalled, and prevented removal of said application. Setting up the phone did not require FB credentials.

I would be worried that even without logging into Facebook or giving it my credentials, my FB-ized phone would help FB's efforts in creating and maintaining shadow profiles. As far as I'm concerned, since the FB app is tied into the OS so tightly that it cannot be removed, it poisons the phone and makes it an adversarial surveillance device.

This type of poison, of course, is not limited to Facebook.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#183
post #40
post #35

So I was ignorant on the issue and completely against the approach of Apple. Then HN taught me that any company storing images on their infrastructure in the US must report pedophilic images to the US government. At this point, the approach taken by Apple seems like the best one to me, if you don't want to store pictures in clear on your servers. What other technical approach are people advocating for? Another point…

> any company storing images on their infrastructure in the US must report pedophilic images to the US government Ones they know of… > What other technical approach are people advocating for? Apple already has a technical solution, encryption.

> Apple already has a technical solution, encryption.

How does encryption help prevent porn being sent to pre-teens?

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#184
post #161

does anyone know if there has been studies showing rise in child sexual exploitation that would warrant something so drastic? I would have imagined it would be lower as society progresses but i do not know. I dont see enough people asking if giving up our personal privacy is really warranted or if we are being mislead. People should be asking for hard proof.

Child porn was, as far as I remember, made illegal because 2 million children was used in it's production. Now that number is 5 million.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#185

Earlier quoted context omitted.

I find it laughable whenever someone says "this is the last straw" because it just shows how incredibly misinformed they are. Yes, backdooring E2E encryption in general is a bad idea. However, consider two things: * iCloud Photos was never E2E encrypted in the first place. They already can scan your photos all they want server-side, and they have been scanning for CSAM since 2019, while Google has been scanning for i…

> It does NOT scan photos that are not uploaded to the cloud, despite being on-device. Yet. Once it's on the device, it's a MUCH smaller step to use it in other ways. It's certainly easier fro governments to argue that they should be able to force it to be used arbitrarily... you know, for the children/terrorists/etc. > And it's important to note the threshold and manual human review system put in place before the au…

> Yet. Once it's on the device, it's a MUCH smaller step to use it in other ways

We crossed this bridge a long time ago. Apple already has on device Neural Nets processing everyone one of your on device photos. That’s what powers spotlight search and “photo memories”.

Simple fact of the matter is that this isn’t the top of some slippery slope, it’s half way down one. A slope we started down when we figured out how to put powerful Neural Nets on mobile devices in people’s pockets.

> Until it's not. Once again, once it's in place, it's a lot easier for malevolent actors (governments) to force it to be used other ways.

Which is why Apples current solution makes it cryptography impossible to decrypt photos until a large enough number of suspect photos have been uploaded.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#186

Earlier quoted context omitted.

Everything sold in China, already has that. Remember ICloud is operated by Chinese company in china.

And we all now that these governments stop carrying about their citizens at the border. Not.

Are you claiming that China will force Apple to scan the phones of US citizens now?

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#187
post #176
post #35

So I was ignorant on the issue and completely against the approach of Apple. Then HN taught me that any company storing images on their infrastructure in the US must report pedophilic images to the US government. At this point, the approach taken by Apple seems like the best one to me, if you don't want to store pictures in clear on your servers. What other technical approach are people advocating for? Another point…

>if you don't want to store pictures in clear on your servers Reading https://support.apple.com/en-us/HT202303 , it seems that Apple may encrypt pictures on their servers, but they have the key. The list of what's actually end-to-end encrypted doesn't include photos. So, they may be scanning on your phone, but they can scan on their servers if they wanted to.

I believe the want this update exactly to enable E2E encryption.

In this way the can get rid of the keys on their servers and still find pedo pictures.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#188
post #171

Earlier quoted context omitted.

> You don't build this and take the PR flack for something you can already do server side That’s exactly what you do if you plan to enable E2E.

Yep. That certainly is the next step. And then, once you are scanning encrypted data, iMessage is next whether you want it or not.

> And then, once you are scanning encrypted data,

They aren’t.

> iMessage is next whether you want it or not.

Is there some evidence you have of this plan? Sounds like this is just a fear you have.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#189
post #35

So I was ignorant on the issue and completely against the approach of Apple. Then HN taught me that any company storing images on their infrastructure in the US must report pedophilic images to the US government. At this point, the approach taken by Apple seems like the best one to me, if you don't want to store pictures in clear on your servers. What other technical approach are people advocating for? Another point…

The problem I have with this approach is that it introduces on-device scan for images. All what is needed to adopt it to scan for different kind of images is to connect it to different database, say, Winnie the Pooh memes featuring CCP chairman, and boom, jailed dissenters. And ability to scan all images is but a minor firmware update away. Server scanning makes it clear that the company running the servers has acces…

> All what is needed to adopt it to scan for different kind of images is to connect it to different database, say, Winnie the Pooh memes featuring CCP chairman, and boom, jailed dissenters.

The CCP have already throughly demonstrated that they don’t need manufactures consent to build these systems.

Look at the Uyghur population in China. They already have their phones scanned on device for dissident material, not by coercing manufacturers, but by forcing the population to install a surveillance app. Then making it illegal to use a phone without it.

Being caught at checkpoint without the app installed and working is grounds for immediate arrest and re-education.

Re: WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan

#190
post #179

Earlier quoted context omitted.

Tarsnap exists so either it is legal when done right or tarsnap is a walking dead and I haven't heard anything to that effect from any credible source.

I guess that service slightly goes out of the scope for active scanning, because it is for general backup, not a cloud especially for photo sharing and storing.

And that is my point: by tying oneself to the mast, denying oneself the access to navigate after the sweet sweet sound of user data, it becomes possible to sail straight past the sirens.

Today this is less about physically tying management and physically putting wax in the crews ears and more about technically and legally making oneself unable to touch the juicy juicy customer data.

Post reply on HN