Live data from Hacker News

One Bad Apple

hackerfactor.com

191–200 of 557 posts

Re: One Bad Apple

#191
post #150

There was parents arrested over bath time and playing in the yard sprinklers, photos being processed at photo mats, will the same thing happen by apple mistakenly reporting parents? When I worked telecom, we had md5sum database to check for this type of content. If you emailed/sms/uploaded a file with the same md5sum, your account was flagged and sent to legal to confirm it. Also if a police was involved, the account…

You can read a bit more about how it would work here: https://daringfireball.net/2021/08/apple_child_safety_initia... (No, not arresting parents over bath time.)

I want to draw attention to one point in this

> Will Apple actually flatly refuse any and all such demands? If they do, it’s all good. If they don’t, and these features creep into surveillance for things like political dissent, copyright infringement, LGBT imagery, or adult pornography — anything at all beyond irrefutable CSAM — it’ll prove disastrous to Apple’s reputation for privacy protection. The EFF seems to see such slipping down the slope as inevitable.

What seems to be missing from this discussion is that Apple is already doing these scans on the iCloud photos they store. Therefore, the slippery slope scenario is already a threat today. What’s stopping Apple from acquiescing to a government request to scan for political content right now, or in any of the past years iCloud photos has existed? The answer is they claim not to and their customers believe them. Nothing changes when the scanning moves on device, though, as the blog mentions, I suspect this is a precursor to allowing more private data in iCloud backups that Apple cannot decrypt even when ordered to.

Re: One Bad Apple

#192
post #148

Earlier quoted context omitted.

> Too often the tech community's response is that the intangible concept of privacy is more important than the tangible issue of child abuse. Is it intangible? 18% of the world lives in China alone. That's more people than the "1/10 who are victims of child abuse*", and I'm sure that 18% will only grow as other authoritarian countries get more technologically advanced. I think "Think of the kids" applies very well to…

>Is it intangible? 18% of the world lives in China alone. That's more people than the "1/10 who are victims of child abuse*", and I'm sure that 18% will only grow as other authoritarian countries get more technologically advanced. You didn't mention any tangible results here. How would this system by Apple make my life worse? Can you answer that without a slippery slope argument? >I think "Think of the kids" applies…

> How would this system by Apple make my life worse? Can you answer that without a slippery slope argument?

“With the first link, the chain is forged. The first speech censured, the first thought forbidden, the first freedom denied, chains us all irrevocably. The first time any man's freedom is trodden on we're all damaged...."

Re: One Bad Apple

#193
post #142

Earlier quoted context omitted.

It's a lossy hash match though. If it wasn't, then subtly re-encoding the image would hide it. So they're definitely going to be mistakingly matching images.

And any mistakes would be caught by the manual review.

So now Apple gets to paw through your images without a warrant or consent?

Re: One Bad Apple

#194

Earlier quoted context omitted.

Any reach into privacy, even while "thinking of the kids" is an overreach. Police can't open your mail or search your house without a warrant. The same should apply to your packets and your devices. Why not police these groups with.. you know.. regular policing? Infiltrate, gather evidence, arrest. This strategy has worked for centuries to combat all manner of organized crime. I don't see why it's any different here.

Devil's advocate: It may not be mostly big organized crime. It may be hard to fight, because it's not groups. It mostly comes from people close to the families, or the families themselves. Here's a relevant extract sourced from Wikipedia: "Most sexual abuse offenders are acquainted with their victims; approximately 30% are relatives of the child, most often brothers, sisters, fathers, mothers, uncles or cousins; arou…

Sure, but the people sharing these images do so in organized groups, often referred to as "rings". I agree it would be very hard to catch a solitary perpetrator abusing children and not sharing the images. However since they would be creating novel images with new hashes, Apple's system wouldn't do much to help catch them would it?

Re: One Bad Apple

#195
post #150

Earlier quoted context omitted.

You can read a bit more about how it would work here: https://daringfireball.net/2021/08/apple_child_safety_initia... (No, not arresting parents over bath time.)

I want to draw attention to one point in this > Will Apple actually flatly refuse any and all such demands? If they do, it’s all good. If they don’t, and these features creep into surveillance for things like political dissent, copyright infringement, LGBT imagery, or adult pornography — anything at all beyond irrefutable CSAM — it’ll prove disastrous to Apple’s reputation for privacy protection. The EFF seems to see…

The slippery slope has already been slid down for every iCloud user in China.

Re: One Bad Apple

#196

As a fan of this blog for longer than I can remember, it's refreshing to hear this particular author's take on this issue, especially considering their background. I'm glad these issues were addressed in a much more elegant way than I would have put them: > Apple's technical whitepaper is overly technical -- and yet doesn't give enough information for someone to confirm the implementation. (I cover this type of paper…

Reading carefully through the paper, an important part of their calculation for the "one in a trillion" claim seems to rest on the cryptographic threshold approach they are using. In particular, it seems likely to me that the number matches required for your account to be flagged is relatively high (perhaps a dozen). If that is the case, their hash collision likelihood could be "only" 1 in a million, but it would still be vanishingly unlikely for a typical iCloud user to get a dozen false positives. 1e-6 is _much_ more testable than 1e-12 for the perceptual hashing, and the cryptographic parts of the secret sharing are easy to analyze mathematically.

As a disclaimer, I haven't done the actual math here. This also implies that the risk of your account getting flagged falsely is tightly related to how many images you upload.

Re: One Bad Apple

#197
post #148

Earlier quoted context omitted.

> Too often the tech community's response is that the intangible concept of privacy is more important than the tangible issue of child abuse. Is it intangible? 18% of the world lives in China alone. That's more people than the "1/10 who are victims of child abuse*", and I'm sure that 18% will only grow as other authoritarian countries get more technologically advanced. I think "Think of the kids" applies very well to…

>Is it intangible? 18% of the world lives in China alone. That's more people than the "1/10 who are victims of child abuse*", and I'm sure that 18% will only grow as other authoritarian countries get more technologically advanced. You didn't mention any tangible results here. How would this system by Apple make my life worse? Can you answer that without a slippery slope argument? >I think "Think of the kids" applies…

> Can you answer that without a slippery slope argument?

So far any defense of this whole fiasco can be boiled down to what you are trying to imply in part. When you say "The possibility of abusing this system is a slippery slope argument", as if identifying a (possible) slippery slope element in an argument would somehow automatically make it invalid?

The other way around if all that can be said in defense is that the dangers are part of slippery slope thinking, then you are effectively saying that the only defense is "trust them, let's wait and see, they might not do something bad with it" or "it sure doesn't affect me" (sounds pretty similar to "I've got nothing to hide"). This might work for other areas, not so much when it comes to backdooring your device/backups for arbitrary database checks.

And since "oh the children" or "but the terrorists" has become the vanilla excuse for many many things I'm unsure why we are supposed to believe in a truly noble intent down the road here. "No no this time it's REALLY about the kids, the people at work here mean it" just doesn't cut it anymore. So no, I'm not convinced the people at Apple working on this actually do it because they care.

When "but the children" becomes a favourite excuse to push whatever, the problem are very much the people abusing this very excuse to this level, not the ones becoming wary of it.

> some of the tech community has begun to think we should do absolutely nothing about this problem

I don't believe that people think that, I believe that people rather think that the ones in power simply aren't actually mainly interested in this problem. The trust is (rightfully) heavily damaged.

Re: One Bad Apple

#198

I haven’t read all the details, articles, and comments. My personal thoughts on the whole situation are the following. If you are a parent and lose a child then you would want every possible avenue taken to find your child. You would be going mad wanting to find them. If there is a way to match photos to known missing children then I say it should be at least tried. I equate this to Ring cameras. They are everywhere.…

> It’s all an invasion of privacy until you’re sitting on the other side of the table where you have a vested interest in getting access to the information. That’s the thing about privacy that so many don’t want to admit. “Everyone deserves it, until they don’t”. All of society’s privacy is more important than your single child, sorry. Meanwhile I created this great new technology. It runs in the background super eff…

> "All of society’s privacy is more important than your single child, sorry." "which might include audio of you making love to your wife."

You and your wife bumping uglies just isn't that special, your embarassment about it is way out of proportion to the amount necessary. The fact that you would rather people die in house fires than a small chance that a stranger hears you breathing heavily and talking dirty should cause you a lot more concern than it seems to be causing you.

Re: One Bad Apple

#199

Earlier quoted context omitted.

Devil's advocate: It may not be mostly big organized crime. It may be hard to fight, because it's not groups. It mostly comes from people close to the families, or the families themselves. Here's a relevant extract sourced from Wikipedia: "Most sexual abuse offenders are acquainted with their victims; approximately 30% are relatives of the child, most often brothers, sisters, fathers, mothers, uncles or cousins; arou…

Sure, but the people sharing these images do so in organized groups, often referred to as "rings". I agree it would be very hard to catch a solitary perpetrator abusing children and not sharing the images. However since they would be creating novel images with new hashes, Apple's system wouldn't do much to help catch them would it?

Let me respond to the "novel images with new hashes" part. Apple's system doesn't use only cryptographic hashes, it seems designed to catch novel images too.

There is concern that it will be inaccurate and have a much higher rate of false positive than the 1 in a trillion reported by Apple (as described in the, very thorough, article).

Re: One Bad Apple

#200
post #184

Earlier quoted context omitted.

>> You didn't mention any tangible results here. How would this system by Apple make my life worse? Can you answer that without a slippery slope argument? That's a weird goal-post. >> Why does the causality matter? A correlation is enough that cracking down on this content will result in less abusers on the streets. Obviously of the people who look at cp, a higher percentage of those will be actual child abusers. The…

>Well you didn't cite anything at all, and were off by a shockingly large number. Sorry, I am just baffled by your last point here. How can I be off by a shockingly large number when I didn't even cite a number?

My B, I see now that was in a section where you were quoting hackerfactor. I guess I should direct that question to him.
Post reply on HN