Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

221–230 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#222
The intention to prevent child sexual abuse material is indeed laudable. But the "solution" is not. For those wondering what's wrong with this, two hard-earned rights in a democracy go for a toss here:

    1. The law presumes we are all innocent until proven guilty.
    2. We have the right against self-incrimination.
Pervasive surveillance like this starts with the presumption that we are all guilty of something ("if you are innocent, why are you scared of such surveillance?"). The right against self-incrimination is linked to the first doctrine because compelling an accused to testify transfers the burden of proving innocence to the accused, instead of requiring the government to prove his guilt.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#223
post #9
post #4

I recently listened to a Darknet Diaries episode on messaging app Kik. This app is apparently being used by many people to trade child pornography. In this episode, there was some criticism expressed on how Kik doesn't scan all the images on their platform for child pornography. I would really like to hear from people who sign this open letter, how they think about this. Should the internet be a free for all place wi…

I think there is a very deep and troublesome philosophical issue here. Ceci n'est pas une pipe. A picture of child abuse /is not/ child abuse. Let me ask you a counter-question. If I am able to draw child pornography so realistically that you couldn't easily tell, am I committing a crime by drawing?

> A picture of child abuse /is not/ child abuse.

Yes, exactly.

It may even help prevent child abuse, because it may help pedophiles overcome their urges and not act upon it.

I'm not aware of any data regarding this issue exactly, but there are studies that show that general pornography use and sexual abuse are inversely correlated.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#224
post #209

US Government: We suspect the person in this photo of committing a crime. Here is your subpoena, Apple. You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them. Chinese Government: Here is the NeuralHash for Tienanmen square. Delete all photos you find matching this or we will bar you from China. Apple has at this point already admitted thi…

Have they? The whitepaper made it sound like the encrypted security voucher is created from the database of known cp on the device at the time the image is uploaded, and the only way for Apple to decrypt something is if it matched something in that database. It did not sound like they could retroactively add additional hashes and decrypt something that already was uploaded. They could theoretically add something to t…

Directly from the link:

> ...the system performs on-device matching using a database of known CSAM image hashes provided by NCMEC and other child safety organizations. Apple further transforms this database into an unreadable set of hashes that is securely stored on users’ devices.

>... The device creates a cryptographic safety voucher that encodes the match result along with additional encrypted data about the image. This voucher is uploaded to iCloud Photos along with the image.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#225
post #50

Fixed: Chinese Government: Here is the NeuralHash for some child abuse imagery, please scan this user's phone and tell us if it's found. Apple: Sure we found it. Chinese Government: this user has unpermitted winnie the pooh memes. Send them to an internment camp.

Fixed further: Chinese Government: Here is the NeuralHash for some child abuse imagery, please scan this user's phone and tell us if it's found. Apple: Sure we found it. Chinese Government to some western company/instititution: We have detected unacceptable behavior from your employee/student/client/vendor. Please cancel them, or we will stop funding you.

Not too far from reality [1].

PhD student at Swiss University posts something critical on Twitter. Chinese intervene at his professor.

Promotion gone with mildly interesting reasoning.

Link to Swiss newspaper in German language.

[1]: https://www.nzz.ch/schweiz/hsg-und-china-kritik-auf-twitter-...

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#226
post #107

https://www.apple.com/customer-letter/ A stark change since Apple/FBI.

And what happened since then, I wonder?

They were probably strong-armed into this. Perhaps the CCP and the FBI talked, and Apple was told they'd be cut off from their suppliers if they didn't introduce this.

It doesn't matter. This is the wrong choice, and everyone should rebuke and abandon Apple for this.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#227
post #194
post #158

Earlier quoted context omitted.

The Chinese government already has direct access to everyone's data and messages. There is no encryption. This is mandated. [0]: https://www.nytimes.com/2021/05/17/technology/apple-china-ce...

> direct access to everyone's data and messages. From what I understand, only to Chinese customers 's data and messages (bad enough, sure, but not as bad as you say).

Depends on the company. If it’s a Chinese company like TikTok, data is stored in China and therefore property of the state. Things are about to get worse and they crack down on private companies in China.

And it’s not just Americans who worry about this. When word got out that Line was storing user data in China servers, it blew up in the news in Japan and Taiwan and went into immediate investigation. Line ended up moving Japanese user data to South Korea. Chinese aggression and Xi’s obsession with power is not just something Americans spout off in Reddit and YouTube comments. They’re a legit threat to Taiwan, Japan, Australia and India.

https://asia.nikkei.com/Business/Technology/Line-cuts-off-ac...

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#228
post #121

Earlier quoted context omitted.

Thanks for the link, I had assumed that Apple was already doing it on servers (like all other online services providers), which makes the announcement even more terrible. Moving it on device will show 0 improvement to the original goal, while opening a door that quite frankly I never expected Apple to be the one to open (I would have bet on Microsoft).

> Moving it on device will show 0 improvement to the original goal, while opening a door that quite frankly I never expected Apple to be the one to open (I would have bet on Microsoft). The CSAM scan is only for photos that are to be uploaded to iCloud Photos. Turning off iCloud Photos will disable this.

Sorry if my point wasn't clear, I do understand this yes.

My point is that to my knowledge, this is the first time that an on device "content check" is being done (even if it's just for photos that will end up in iCloud). This is the precedent (the on device check) that makes me and some others uneasy, as pointed out in the linked letter. The fact that it applies only to photos going to the cloud is an implementation detail of the demonstrated technology.

Legislators around the world now have a precedent and may (legitimately) want it extended to comply with their existing or upcoming laws. This is not a particularly far fetched scenario if you consider that Apple has already accommodated how they run their services locally (as they should, they have to comply with local laws around the world in order to be able to operate).

That's the crux of the issue most of the people quoted in the letter have, one can argue it's just a slippery slope argument, I personally think that one can be legitimately concerned of the precedent being set.

Keeping doing it on server, in my opinion, was a much better option for users (with the same compliance to local laws and effectiveness to the stated goal as far as we know, there's no improvement on that front, or none that couldn't have been brought to the existing server check), and ultimately also a safer option in the long run for Apple.

They've opened themselves, for little reason, to a large amount of trouble on an international scale and at this point rolling it back (to server checks) might not make a difference anyway.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#229
post #130
post #116

You guys can get outraged all you want. It's pretty clear that Apple debated this internally and decided that the backlash was worth whatever they got from this deal... By today, it's pretty clear than privacy is not the top priority of most people. See how much data people are giving fb/google every second...

This defeatist attitude is not helpful. The louder people are about this, the more it hurts and the more likely the policy is reversed. if the policy is not reversed, then at least the community has been loud enough that people took notice and understood that this is happening, giving them a chance to vote with their wallet; for most people what happens on a computer or a phone is a complete mystery.

[deleted]

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#230
post #204

Earlier quoted context omitted.

Hasn’t Google been parsing Google Photos images, email content, and pretty much everything else since forever? Do you just stay off of smartphones and cloud platforms entirely?

Microsoft and Google have been doing that in their online services for ages, but not on your personal devices.

So if I don’t backup with Google Photos or Google Drive, would they be safe for now?
Post reply on HN