Live data from Hacker News

One Bad Apple

hackerfactor.com

21–30 of 557 posts

Re: One Bad Apple

#21
The author of this article purports to have done a ton of research into this system, but appears to have missed basic information that I’ve acquired from a few podcasts.

Namely the “1-in-a-trillion” false positives per account per year is based on the likelihood of multiple photos matching the database (Apple doesn’t say how many are required to trip their manual screening threshold).

Re: One Bad Apple

#22

Really nice explanation from someone who knows a thing or two about images/photos (Dr. Neal Krawetz is the creator of https://fotoforensics.com and specializes in computer forensics).

He wrongly interpreted CSAM scanning. He said that Apple will scan your photos and if finds something, it will send photo to Apple. Which is absolutely not how it works. Photo is only scanned before uploading to iCloud Photos. Apple already confirmed it to iMore and it’s clearly stated in Apple papers from press-release.

Re: One Bad Apple

#23
Question: who is or will be making money on this deal? Answer that ("follow the money") and then I think we'll have a handle on what's really going on.

Re: One Bad Apple

#24

To help fight back against false positives, why not just repeatedly trigger the code that sends the data to NCMEC (per the article's claimed legal requirements) and create a DoS attack?

[deleted]

Re: One Bad Apple

#25
> However, nothing in the iCloud terms of service grants Apple access to your pictures for use in research projects, such as developing a CSAM scanner. (Apple can deploy new beta features, but Apple cannot arbitrarily use your data.) In effect, they don't have access to your content for testing their CSAM system.

> If Apple wants to crack down on CSAM, then they have to do it on your Apple device.

I don’t understand… Apple can’t change their TOS but they can install this scanning service on your device?

Re: One Bad Apple

#26

Earlier quoted context omitted.

This basic implementation fact has been misrepresented over and over and over again. Does anyone read anymore? I’m starting to get really concerned. The hacker community is where I’ve turned to be more informed, away from the clickbait. But I’m being let down.

Agreed - so dissapointing. The idea that standard moderation steps are a felony is such a stretch. Almost all the major players have folks doing content screening and management - and yes, this may invovle the provider transmitting / copying etc images that are then flagged and moderated away. The idea that this is a felony is rediculous. The other piece is that folks are making a lot of assumptions about how this wo…

Does the law have a moderation carve out? There are plenty of laws that have what's called 'strict liability' where your intent doesn't matter.

I'm not suggesting that this is absolutely positively a situation where strict liability exists and that moderation isn't allowed. But the idea that "hey we're trying to do the right thing here" will be honored in court is....not obvious.

Re: One Bad Apple

#27

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice

Stopping to that level is what they want, CNN: “‘privacy activists’ have released a tool to allow the spread of CP”

Re: One Bad Apple

#28
post #2

This reads like a failure of the NCMEC, and the legal system surrounding it. It is insane that using perceptual hashes is likely illegal. As the hashes are actually somewhat reversible and so possession of the hash is a criminal offence. It just shows how twisted up in itself the law is in this area. One independent image analysis service should not be beating reporting rates of major service providers. And NCMEC sho…

Doesn’t seem like it was an accident, rather protectionism written long ago to make sure they were the only “game” in town.

Re: One Bad Apple

#29

The author of this article purports to have done a ton of research into this system, but appears to have missed basic information that I’ve acquired from a few podcasts. Namely the “1-in-a-trillion” false positives per account per year is based on the likelihood of multiple photos matching the database (Apple doesn’t say how many are required to trip their manual screening threshold).

So they are assuming that the photos are independent. Common error with probabilistic reasoning. What if the same photo (or photos of the same scene taken seconds apart) gets uploaded more than once? The likelihood no longer multiplies. I don't believe the "one in a trillion" claim.

Re: One Bad Apple

#30
The engineers that worked on this should honestly be ashamed of themselves. We need some sort of oath of ethics in computer science.
Post reply on HN