Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

191–200 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#191

What would prevent someone from, for instance, printing off an illegal photo, “borrowing” a disliked co-workers iCloud enabled phone, and snapping a picture of the illegal picture with their camera? On iOS the camera can be accessed before unlocking the phone, and wouldn’t this effectively put illegal image(s) in the targets possession without their knowledge?

[deleted]

Re: The deceptive PR behind Apple’s “expanded protections for children”

#192
post #153

As much as the tech and security community has concerns and objections to this policy change on the part of Apple, I’m skeptical there will be any notable impact to Apple’s revenue and future sales.

I remember people were saying same thing about Linux on Desktop, yet we have viable alternatives to proprietary OSes.

Yes, someone will have to struggle to get us there, but will have alternative if we don’t give up.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#193
post #157

> The hypothesis that I have is that Apple wishes to distance itself from checking users’ data. This is best explanation of the whole situation I have read.

And in the process hand over more user data to tyrants. Surely they know this will be abused to check user data before it is uploaded to iCloud. All it takes is a willing government.

How is that different from how things work now?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#194
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

Probability of a false positive for a given image = p

Probability of N false positives (assuming independence) = p^N

Threshold N is chosen by Apple such that p^N -12 log(10)/log(p) [since log(p) ETA: Suppose, just for the sake of the argument, that p = 10^-3 (one false positive in 1000, so really quite bad).

Then log(p) = -3 log(10), so N > -12 log(10)/(-3 log(10)) = 12/3 = 4.

Similarly, if p is one in a million (10^6), then N would be required to be > 12/6 = 2.

In practice, I'd expect N to be larger than 4, in other words, Apple being very conservative here.

ETA: The above doesn't take into account how many images M you have. The analysis gets more complicated, but N needs to be way larger than 4. I'll think about it some more.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#195
post #176

Earlier quoted context omitted.

Ahh - an "irrefutable" claim that apple is committing child porn felonies. This is sort of what I mean and a perfect example. People imagine that apple hasn't talked to the actual folks in charge NCMEC. People seem to imagine apple doesn't have lawyers? People go to the most sensationalist least good faith conclusion. Most mod systems at scale are using similar approaches. Facebook is doing 10's of MILLIONS of images…

Sorry under which of these other moderation regimes does the organisation in question transmit CSAM from a client device to their own servers? To my knowledge Apple is the only one doing so.

Apple is attaching a ticket to images as the user uploads to iCloud. If enough of these tickets think CSAM and allow an unlock key to be built, they will unlock and get checked. It's still the user who has turned on iCloud and uploaded the images.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#196

What would prevent someone from, for instance, printing off an illegal photo, “borrowing” a disliked co-workers iCloud enabled phone, and snapping a picture of the illegal picture with their camera? On iOS the camera can be accessed before unlocking the phone, and wouldn’t this effectively put illegal image(s) in the targets possession without their knowledge?

yes

Re: The deceptive PR behind Apple’s “expanded protections for children”

#197
post #178

Question: Would Apple report CSAM matches worldwide to one specific US NGO? That's a bit weird, but ok. Presumably they know which national government agencies to contact. Opinion: If Apple can make it so that a) the list of CSAM hashes is globally the same, independent of the region (ideally verifiably so!), and b) all the reports go only to that specific US NGO (which presumably doesn't care about pictures of Winni…

Apple said they're only enabling it in the US for now.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#198
post #68

Earlier quoted context omitted.

The end isn't really compromised with their described implementation. The only thing sent is the hash and signature and that's only if there are enough matches to pass some threshold. I don't really view that as 'permanently compromised' - at least not in any way more serious that Apple's current capabilities to compromise a device. I think e2ee still has meaning here - it'd prevent Apple from being able to see your…

> The only thing sent is the hash and signature and that's if there are enough matches to pass some threshold. Not true. If there are enough matches, someone at Apple will have a look at your pictures. Even if they are innocent.

> someone at Apple will have a look at your pictures

No, but at a "visual derivative"

Re: The deceptive PR behind Apple’s “expanded protections for children”

#199
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

[deleted]

Re: The deceptive PR behind Apple’s “expanded protections for children”

#200
post #87

Eh, I completely agree that this is a step too far, but the solution is so simple. Stop using Apple devices - luckily I switched from iOS to CalyxOS when my iPhone 7 broke earlier this year. Honestly, it wasn't so bad.

This is throwing the baby (pictures) out with the bathwater. I am for better or worse deeply rooted in the Apple tree (phone, laptop, tablet, and, recently, watch); for all its occasionally infuriating and arguably stupidly designed warts, the fact that so many features disappear and Just Work is something you can nary say for other ecosystems.

That’s the thing, for years I had to tolerate those silly issues from people who are supposed to be best in the industry. There is still no default calculator installed on iPad in 2021!

For some people, it’s simply no worth it anymore, after primary commitment is gone..

Post reply on HN