Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

201–210 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#201
post #109

Earlier quoted context omitted.

>The hashes are hard coded into each iOS release Do you have a source on that? Since it is illegal to share those hashes in any way or form. Even people working with photo forensic and big photo sharing sites cannot get access to them. I very much doubt Apple can incorporate them into the iOS release without breaking multiple laws. The hashes themselves can easily be reversed to (bad quality) pictures so having the h…

From the interview I linked, Apple Privacy head Erik Neuenschwander said, “The hash list is built into the operating system, we have one global operating system and don’t have the ability to target updates to individual users and so hash lists will be shared by all users when the system is enabled.” Where did you hear sharing hashes is illegal? How would anybody determine whether CASM at scale without those hashes? Y…

NCMEC will share MD5 but not the hashes used for perceptual matching.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#202

Any idea why Apple didn’t just implement server side scanning like everyone else?

It's a good question. The only explanation that makes sense is that this now allows them to begin end-to-end encryption of iCloud photos. I see that many commentators are claiming that they could already have started e2e encryption without introducing this "backdoor." While this is true, Apple would then be creating a perfect environment for child abusers to house their CSAM content on Apple's own servers. You can un…

Lawyerly word games. The e in e2e is the user, or a device loyal to them; malware on the user's device has always been understood as a subversion of e2e.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#203
post #112
post #6

Earlier quoted context omitted.

It's worth reading this, which is basically the only good reporting I've seen on this topic: https://daringfireball.net/2021/08/apple_child_safety_initia... There are legitimate things to be concerned about, but 99% of internet discussion on this topic is junk.

I still don't understand how this is allowed. If the police want to see the photos on my device, then they need to get a warrant to do so. Full stop. This type of active scanning should never be allowed. I hope that someone files a lawsuit over this.

You agreed to the EULA :)

Re: The deceptive PR behind Apple’s “expanded protections for children”

#204

Earlier quoted context omitted.

Yeah I found the EFF's piece to be really disappointing, coming from an organization I'm otherwise aligned with nearly 100% of the time.

EFF today is really not the organisation it was just a few years ago. I dont know who they hired badly, but the reasoned takedowns have been replaced with hysterical screaming.

> hysterical screaming

Given the political/societal climate, it probably gets them more donations.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#205
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

No, this will never be caught.

This only catches ownership of illegal photos.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#206
"The hypothesis that I have is that Apple wishes to distance itself from checking users' data. They've been fighting with the FBI and the federal government for years, they've been struggling with not reporting CSAM content to the NCMEC, they don't want to be involved in any of this anymore."

However there is close to zero evidence to support this idea. I was just reading something the other day that directly contradicted this; it suggested the relationship has been excellent save for a single, well-publicised dispute over unlocking an iPhone. In other words, the publicly aired dispute was an anomaly, not representative of the underlying relationship.

Even more, unless the pontificator works for Apple or the government, she is not a good position to summarise the relationship. Plainly put, it is not public information.

What does such baseless speculation achieve. Is it like spreading a meme. I dont get it.

"The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember), debugging wifi drivers and tirelessly trying to make resume-from-suspend work? Am I getting a Pixel and putting GrapheneOS on it like a total nerd? FUCK."

Is having a computer with closed source wifi drivers and proper ACPI support more important than having a computer with an open OS that does not include an intentional backdoor.

Maybe the problem is not how to put your money where your mouth is, its how to put your mouth where your money is. What does GrapheneOS cost. Maybe this is not about money.

Options like GrapheneOS, even the mere idea of GrapheneOS, i.e., that there can be alternatives to BigTech's offerings, get buried underneath Apple marketing. Much of that marketing Apple gets for free. It comes from people who do not work for Apple.

Bloggers and others who discuss computers can help change that. They can also help Apple sail through any criticism (and they do).

Re: The deceptive PR behind Apple’s “expanded protections for children”

#207
post #185

Earlier quoted context omitted.

IMHO, what Apple is doing is not _knowingly_ transferring CSAM material. Very strong reason to believe is not the same as knowing. Of course it's up to courts to decide and IANAL.

Go ahead and click on some google results after searching for child porn and see if that defence holds up.

Can you elaborate how your reply relates to Apple's case and my comment?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#208
post #68

Earlier quoted context omitted.

> The only thing sent is the hash and signature and that's if there are enough matches to pass some threshold. Not true. If there are enough matches, someone at Apple will have a look at your pictures. Even if they are innocent.

I think the one thumbnail of the matching hash? Just to make sure there isn't a (they argue one in a trillion, but I don't know if I buy that) false positive. That's if there is enough matches to trigger the threshold in the first place, otherwise nothing is sent (even if there are matches below that threshold). Alternatively this is running on all unencrypted photos you have in iCloud and all matches are known immed…

I really don't understand how you're arguing as if you don't see the bigger picture. Is this is a subtle troll?

They are now scanning on the device. Regardless of how limited it is in its current capabilities, those capabilities are only prevented from being expanded by Apple's current policies. The policies enacted by the next incoming exec who isn't beholden to the promises of the previous can easily erode whatever 'guarantees' we've been given when they're being pressured for KPIs or impact or government requests or promotion season or whatever. This has happened time and again. It's been documented.

I really am at a loss how you can even attempt to be fair to Apple. This is a black and white issue. They need to keep scanning for crimes off our devices.

So to your answer your question, yes it is preferable to have them be able to scan all of the unencrypted photos on iCloud. We can encrypt things beforehand if need be. It is lunacy to have crime detecting software on the device in any fashion because it opens up the possibility for them to do more. The people in positions to ask for these things always want more information, more control. Always.

The above reads like conspiracy theory but over the past couple of decades it has been proven correct. It's honestly infuriating to see people defend what's going on in any way shape or form.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#209
post #112

Earlier quoted context omitted.

I still don't understand how this is allowed. If the police want to see the photos on my device, then they need to get a warrant to do so. Full stop. This type of active scanning should never be allowed. I hope that someone files a lawsuit over this.

You agreed to the EULA :)

I'm not sure EULA's can effectively bargain away US constitutional protections.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#210

Earlier quoted context omitted.

No. The CSAM (Child Sexual Abuse Material) scanning is comparing hashes of photos about to be uploaded to iCloud against a specific set of images at NCMEC (National Center for Missing and Exploited Children) which are specific to missing and exploited children. It is not machine learning models looking for nudes or similar. It is not a generalized screening. If enough matched images are found, the images are flagged…

I am not sure the right questions are being asked. 1. Who is adding these photos to NCMEC? 2. How often are these photos added? 3. How many people have access to these photos - both adding and viewing? Everyone is focused on Apple and no one is looking at MCMEC. If I wanted to plant a Trojan horse, I would point everyone towards Apple and perform all of the dirty work on the NCMEC end of things.

Exactly. An unknown mechanism adds hashes to a NGO subject to exactly what conditions?

This initiative makes me extremely leery of black boxes, to the extent that any algorithm between subject and accusation had damned well better be explainable outside the algorithm; else I as a jury member am bound to render a "not guilty" verdict.

Post reply on HN