Live data from Hacker News

Apple’s new abuse prevention system: an antritust/competition point of view

blog.quintarelli.it

211–220 of 318 posts

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#211
post #199

Say that you're an official with the Chinese Communist Party (CCP). You have huge stacks of brochures of anti-CCP materials. You've got them scanned and hashed. Next you call Apple and say, "Please alert us if similar imageries appears in your customers' devices. My assistants will send you weekly updates of the required hashes." Apple would say, "Sure, we're just following your law..." Hence when a Chinese photograp…

Yep, and now Apple can no longer say "Sorry, we can't put a backdoor into our devices" - one already publicly exists

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#212
post #185

Earlier quoted context omitted.

Thanks for the detailed explanation. I understand why that works for perceptual hashes if you make them really precise, however I doubt it would work with md5, which is why I asked.

The discussion I thought we were having was about false positives and not adversarially induced false positives. For the former the random collisions have a probability of 1/(2^64). To mitigate adversarial false positives one idea is to use the combination of a cryptographically strong hash along with a randomly selected perturbation of the file. Prior to hashing, perturb the file and submit both the hash and the sel…

I thought that the random collision for md5 was way higher than that. If it's that low, you're right, this would work. I'm not sure I understand the part about the pertubation.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#213
post #191

Earlier quoted context omitted.

They’re scanning for it as it enters their system. It’s only scanned if it’s set to go to iCloud.

Yes, but then there's a way to upload it in plaintext. That's the backdoor. That can, and will, eventually be used to exfiltrate any file, anytime, whether it would be going to the cloud or not.

It does set a terrible precedent, but it's possible this is a step towards E2E encryption on iCloud data; a way to comply with the law while preventing law enforcement from being able to subpoena other data.

Apple is being its usual cryptic self about this, which is once again breeding uncertainty, but I still have hope in the end this will work out.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#214

Can I just say that I'm fascinated that this is happening under Tim Apple - an openly gay man in his 60s? I mean this is someone who would know what being on the wrong side of law means - not only federally, but probably quite intimately since Alabama was not exactly known for its acceptance of homosexual people. Now just imagine if the US still had anti-homosexuality laws (like the majority of the world still does)…

Your last paragraph ruined an otherwise great comment.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#215
post #211
post #199

Say that you're an official with the Chinese Communist Party (CCP). You have huge stacks of brochures of anti-CCP materials. You've got them scanned and hashed. Next you call Apple and say, "Please alert us if similar imageries appears in your customers' devices. My assistants will send you weekly updates of the required hashes." Apple would say, "Sure, we're just following your law..." Hence when a Chinese photograp…

Yep, and now Apple can no longer say "Sorry, we can't put a backdoor into our devices" - one already publicly exists

Technically it's "front door" since it _publicly exists_.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#216

Earlier quoted context omitted.

Alternatively, and just as likely, is that the Republicans do the same evil things that you say the Democrats would do. Misusing tech isn't just for the "other" side, my friend.

Yeah that was particularly weird comment for GP to make just 6 months after Republicans stormed the Capitol on the command of a Republican President to hang government officials and overturn an election.

[deleted]

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#217
post #188

Earlier quoted context omitted.

> …your phone is constantly scanning your photos to check for signs of homosexual behaviour. Forgetfully take a selfie with your boyfriend, it gets flagged… Except that’s not what this is doing. For all intents and purposes, “scanning” is just hashing content before it’s uploaded and comparing that hash to a known database. So, unless your picture had been hashed and flagged before (And if you just took it how could…

The hash matching part of this is a red herring. The real issue is that if a hash matches, there's now a mechanism to upload the image in question from your phone, unencrypted, without your consent. What assurance is there that the hidden upload mechanism can't be used to upload other files on demand? If a mechanism is built into the OS that can exfiltrate files on demand, what's to say there even has to be a hash ma…

It’s not a “hidden upload mechanism”. It’s a hash-and-flag system on top of the extant “upload to iCloud” function.

Apple will already have the data. You’re already consenting to that when you enable iCloud Photo Library (the only place this is being implemented).

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#218

Earlier quoted context omitted.

The worst thing about it is that CP possession is a strict liability crime in most jurisdictions. Meaning that prosecution doesn't have to prove intent - if they can find it on your machine, you're guilty regardless of how it got there.

In criminal law you must be aware of an item for it to be under your possession. If someone plants illegal content on your computer, and you are unaware, you aren't legally in possession.

"Typically in criminal law, the defendant's awareness of what he is doing would not negate a strict liability mens rea (for example, being in possession of drugs will typically result in criminal liability, regardless of whether the defendant knows that he is in possession of the drugs)."

https://www.law.cornell.edu/wex/strict_liability

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#219
post #127

Earlier quoted context omitted.

is there really no fuzziness to it? If not, can’t this be defeated by simply reencoding the image?

I think it has gotten more sophisticated to detect cropped images and small changes now: https://inhope.org/EN/articles/what-is-image-hashing The example is somewhat contrived. If a 'friend' takes your phone and has access to it and then uses it to take images of CSAM similar enough to the original image that it triggers the hash match and does this enough times to go over Apple's threshold to flag the account after…

Or you know, anyone who wants to plant material on a device and has physical access. Say a disgruntled employee before leaving, or ex, or criminal or...

Or anyone who can just text you since imessage backs up to icloud automatically...

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#220

Earlier quoted context omitted.

Alternatively, and just as likely, is that the Republicans do the same evil things that you say the Democrats would do. Misusing tech isn't just for the "other" side, my friend.

Yeah that was particularly weird comment for GP to make just 6 months after Republicans stormed the Capitol on the command of a Republican President to hang government officials and overturn an election.

> on the command of a Republican President to hang government officials and overturn an election

Literally never happened. The fact that you're parroting this lie shows how deeply media bubbles have disconnected people from reality.

https://www.npr.org/2021/02/10/966396848/read-trumps-jan-6-s...

https://www.npr.org/sections/insurrection-at-the-capitol/202...

Post reply on HN