Live data from Hacker News

One Bad Apple

hackerfactor.com

201–210 of 557 posts

Re: One Bad Apple

#201
post #89

Earlier quoted context omitted.

This made me come up with a thought experiment. If you sampled a thousand parents and asked them if they think sex offenders deserve a fair and just trial, what do you think the result would be?

That question is framed wrong. What you should be asking is "Should people accused of such crimes get a fair and just trial?". This makes it clear that it takes me one sentence to put you in that very position. And that's exactly the problem. Your formulation erases any question of guilt, which makes the discussion nearly impossible to win for the privacy side.

No, what they’re saying is that most people already presume guilt, even if it’s just an accusation. Further, most would be willing to engage in mob justice. I feel like you’re doing a lot of work to miss that point.

Re: One Bad Apple

#203

Earlier quoted context omitted.

I know of no messaging app the “automatically” uploads to iCloud. And what sort of idiot would try and send CP using a messenger app (almost all of which CASM detection). That’s like trying to smuggle drugs past the TSA so you can put them in someone’s house to frame them.

The app doesn’t. The iOS camera roll uploads newly captured or saved images when it connects to Wi-Fi.

If you choose to save it, then you no longer a “victim”. But someone else can’t force a save to iCloud on your device.

Re: One Bad Apple

#204
> As it was explained to me by my attorney, that is a felony.

Apple could argue they were already going to receive the photo (since this algorithm only affects Photos destined for iCloud Photos) and thus "when in the upload process it was classified" is simply technological semantics.

> This was followed by a memo leak, allegedly from NCMEC to Apple:

Well, we certainly are the minority. If a majority of people knew and were mad we'd have protests in major cities.

Re: One Bad Apple

#205
post #188

Earlier quoted context omitted.

In the past these people would have been developing the pictures themselves, and handing them between each other either personally or in some hidden manner using public systems. Not only has communication become easier, so has surveillance. The only difference now is that it's easier for people not to be aware when their very personal privacy is invaded, and that it can be done to the whole populace at once.

>Not only has communication become easier, so has surveillance. It is a devil's advocate response, but can you explain why this is a bad thing? If communication is scaling and becoming easier, why shouldn't surveillance?

Post your passwords.

Re: One Bad Apple

#206
post #151

Earlier quoted context omitted.

He wrongly interpreted CSAM scanning. He said that Apple will scan your photos and if finds something, it will send photo to Apple. Which is absolutely not how it works. Photo is only scanned before uploading to iCloud Photos. Apple already confirmed it to iMore and it’s clearly stated in Apple papers from press-release.

Please stop spreading misinformation. Apple has built the system to scan your entire phone, their claims about its limited scope are suspect.

[deleted]

Re: One Bad Apple

#207

Good article, however- "Due to how Apple handles cryptography (for your privacy), it is very hard (if not impossible) for them to access content in your iCloud account. Your content is encrypted in their cloud, and they don't have access. If Apple wants to crack down on CSAM, then they have to do it on your Apple device" I do not believe this is true. Maybe one day it will be true and Apple is planning for it, but ri…

> Thus far there has been no compelling answer as to why Apple needs to do this on device.

"You scratch my back and I scratch yours". Apple doesn't want to go through an antitrust lawsuit that will kill their money printer so they kowtow with these favors.

Re: One Bad Apple

#208

Earlier quoted context omitted.

They want to move to e2e for photos so they don't have to keep those keys. That's what this is part of — a way to prevent their service from being used for CSAM, yet still provide e2e encryption. I feel very ambivalent about this.

That was never mentioned by Apple. If that was their intention then I suspect they would have mentioned it alongside this announcement to provide a justification and quell the (justified) outrage. I also question the value of e2e there’s an arbitrary scanner that can send back the unencrypted files if it finds a match. If apple’s servers controls the db with “hashes” to match then is it all that different from apple’…

> If that was their intention then I suspect they would have mentioned it alongside this announcement to provide a justification and quell the (justified) outrage.

It’s August. New iPhones and iOS / macOS are released in September. If they want to introduce E2E encryption for photos and need this in place to do it, then it makes sense to announce this ahead of time and get the backlash out of the way so that they can announce the headline feature during the main event without it being overshadowed.

Re: One Bad Apple

#209

Earlier quoted context omitted.

The app doesn’t. The iOS camera roll uploads newly captured or saved images when it connects to Wi-Fi.

If you choose to save it, then you no longer a “victim”. But someone else can’t force a save to iCloud on your device.

Sure, but some apps allow you to choose once and henceforth save all photos sent to you. That provides a vector for someone to inject things into your iCloud.

However, I find this risk exaggerated because if someone actually does this, you can just block the app’s ability to access your camera roll in the privacy settings or stop using the app. And report the user to the service, of course.

Re: One Bad Apple

#210
post #188

Earlier quoted context omitted.

In the past these people would have been developing the pictures themselves, and handing them between each other either personally or in some hidden manner using public systems. Not only has communication become easier, so has surveillance. The only difference now is that it's easier for people not to be aware when their very personal privacy is invaded, and that it can be done to the whole populace at once.

>Not only has communication become easier, so has surveillance. It is a devil's advocate response, but can you explain why this is a bad thing? If communication is scaling and becoming easier, why shouldn't surveillance?

> It is a devil's advocate response, but can you explain why this is a bad thing?

I didn't state it as a bad thing, I stated it as a counter to your argument that encrypted communication is more common, and therefore maybe we should assess whether additional capabilities are warranted. Those capabilities already exist, and expanded before the increased encrypted communication (they happened during the analog phone line era). I would hazard that increasingly encrypted communication is really just people responding to that change in the status quo (or overreach, depending on how you view it) brought about by the major powers (whether they be governmental or corporate).

Post reply on HN