Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

221–230 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#222

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

[deleted]

Re: Apple defeats liability for not scanning iCloud for CSAM

#223

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

One is far easier to prove. If the government could continuously monitor our actions "Is this CSA?" they might very well be pushing for that, too.

if you wear red glasses...

Re: Apple defeats liability for not scanning iCloud for CSAM

#224
post #129

Earlier quoted context omitted.

I thought the client side scanning was to protect children? If it suspects an image is bad, it blurs it and pops up a warning including a link to resources to go to for help. Very different than trying to narc out users to the authorities.

There were two different technologies. One was client-side scanning for known CSAM, which created a huge backlash and is described here: https://educatedguesswork.org/posts/apple-csam-intro/ The other is detection of images that may contain nudity, whether sent or received, when the owner/admin/parent enables the feature. It is relatively uncontroversial and is described here: https://support.apple.com/en-us/105069

The controversial part is having the system enabled by default with age verification required to turn it off, and having the system impact non-Apple/Google apps. The UK for example wants Apple and Google to forcibly enable nudity blocking on all devices in the UK, and they want the system to bypass app/DRM security to scan all content visible on a device.

Re: Apple defeats liability for not scanning iCloud for CSAM

#225

Earlier quoted context omitted.

Have you considered the implications of what you're saying? A whistleblower goes to a therapist, stressed out over their pending decision to reveal official misconduct. They've been investigating ways to post something on the internet that can't be immediately taken down by the corrupt government officials they want to expose. They express their discomfort, in confidence, to their therapist, about using something the…

Well, in the jurisdictions that I care about the courts and lawmakers have already decided this and the legal requirement is to report. If its your license to practice on the line you know what choice you're going to make.

Therapy will become progressively more useless as people avoid it because therapists are required to report anything they hear which might be a crime.

Re: Apple defeats liability for not scanning iCloud for CSAM

#226
post #7

The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections. As sad as this is, end to end encryption means no CSAM scanning. As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too. This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

The judge's comments are extremely disturbing, as she seems to want legislation passed that requires companies to violate user privacy.

And client side scanning is just as bad as encryption backdoors. There's a good reason Apple was attacked for even considering it: https://arxiv.org/abs/2110.07450

Re: Apple defeats liability for not scanning iCloud for CSAM

#227
post #7

The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections. As sad as this is, end to end encryption means no CSAM scanning. As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too. This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

> end to end encryption means no CSAM scanning Not true. There is the option of scanning on the device.

Circumventing encryption with client side scanning is on par with requiring encryption backdoors, and goes against the purpose of having end to end encryption.

Re: Apple defeats liability for not scanning iCloud for CSAM

#228

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

> ones who have been involved in abuse scandals in the past (Churches, Scouts, etc)

And those groups still have lower rates of abuse than Schools which do a lot less training and enforcement of youth protection policies.

Children are still safer in Scouts and churches than in schools.

Just about every kid goes to school though, so people just prefer to sweep that under the rug and focus on targeting organizations they are not a part of or disagree with because they're easier to demonize and make fun of.

I work with kids, and I've had to take the Scouts and Catholic Church's youth protection training. They are both free to take online if anyone wants to check it out.

Re: Apple defeats liability for not scanning iCloud for CSAM

#229

Earlier quoted context omitted.

They are mandated to report child abuse. It is the same story with doctors, if an abusive parent brings in a child for care they learn never to give the kid healthcare again after the doctor reports it. It is rooted in good intentions but the effect is it means abused children never get to see doctors, therapists, get a half-ass minimal homeschool instead of going to school, etc so that mandated reporters never enter…

Reporting abuse the client was involved in has a compelling reason. That's different from hearing their client saw a picture of the abuse of a total stranger.

> That's different from hearing their client saw a picture of the abuse of a total stranger.

I get it, actually. It's totally possible the picture in question was not known to authorities prior. That's called due diligence to look into it.

Adults not looking into things or following up on things are how the system fails children if you read some accounts of people who were abused by their guardians. Horrifying stuff.

Re: Apple defeats liability for not scanning iCloud for CSAM

#230

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

I said this in another thread a while ago, and one of these people who thinks Apple isn’t on the side of privacy cited a lawsuit they settled around Siri listened to conversations: https://www.scientificamerican.com/article/apple-settles-cla... People understood this settlement to mean Apple was spying on their conversations and selling them to advertisers, when it seems to have more to do with people accidentally tr…

This is also a misunderstanding of the case, though. The suit wasn't filed because of accidental Siri triggers, it was filed because Apple never informed users that third-party contractors would be listening to retained recordings of accidental invocations. From the original Guardian report:

> Although Apple does not explicitly disclose it in its consumer-facing privacy documentation, a small proportion of Siri recordings are passed on to contractors working for the company around the world. https://www.theguardian.com/technology/2019/jul/26/apple-con...

Regardless of how you feel towards Apple, this sort of data should be siloed in a way that makes it impossible to share with undisclosed third-parties. It also should not be shared anywhere until Apple can confirm that PII and other sensitive information was redacted from the data, which they did not. It generally points to a laissez-faire attitude towards personal data that is hard to abdicate without seeing the Siri server-side code or retention architecture, which is why Apple settled to avoid revealing the extent to which they retain and share data in a class-action discovery process. The settlement is a mea-culpa without admitting to wrongdoing or proving fundamental security.

The lawsuit was entirely avoidable if Apple didn't play fast-and-loose with production databases. It'll be a black eye for anyone that points to Apple's whitepapers as an example of their commitment to security - some retention simply doesn't get documented by Apple.

Post reply on HN