Live data from Hacker News

One Bad Apple

hackerfactor.com

231–240 of 557 posts

Re: One Bad Apple

#231
post #225

Earlier quoted context omitted.

Reading carefully through the paper, an important part of their calculation for the "one in a trillion" claim seems to rest on the cryptographic threshold approach they are using. In particular, it seems likely to me that the number matches required for your account to be flagged is relatively high (perhaps a dozen). If that is the case, their hash collision likelihood could be "only" 1 in a million, but it would sti…

You're assuming that perceptual hashes are uniformly distributed, but that's not the case. If I post a picture of my kid at the beach I'm far, far more likely to generate perceptual hashes closer to the threshold. Not to mention intimate photos of/with my partner.

yep. what if i take a burst of 12 photos that all incorrectly fall as a false positive to NeuralHash (which is a ML black box), and an Apple reviewer is now invading my privacy by looking at my photo library?

Re: One Bad Apple

#232

Good article, however- "Due to how Apple handles cryptography (for your privacy), it is very hard (if not impossible) for them to access content in your iCloud account. Your content is encrypted in their cloud, and they don't have access. If Apple wants to crack down on CSAM, then they have to do it on your Apple device" I do not believe this is true. Maybe one day it will be true and Apple is planning for it, but ri…

> why Apple needs to do this on device Presumably to implement E2E encryption, while at the same time helping the NCMEC to push for legislation to make it illegal to offer E2E encryption without this backdoor. Apple users would be slightly better off than the status quo, but worse off than if Apple simply implemented real E2E without backdoors, and everyone else's privacy will be impacted by the backdoors that the NC…

> make it illegal to offer E2E encryption without this backdoor.

It isn’t a back door to E2E encryption. It can’t even be used to search for a specific image on a person’s device.

It could be used possibly to find a collection of images that are not CSAM but are disliked by the state, assuming Apple is willing to enter into a conspiracy with NCMEC.

Re: One Bad Apple

#233
post #18

There are a lot of articles about Apples hadh algorithm and for me they are mostly irrelevant to the main problem. The main problem is that Apple has backdoored my device. More types of bad images or other files will be scanned since now apple does not have plausible deniablity to defend any of ghe government’x requests. In the future a false? positive that happened? to be of a political file that crept in the list c…

> More types of bad images or other files will be scanned since now apple does not have plausible deniablity to defend any of ghe government’x requests.

The mechanism doesn’t scan anything except images, and won’t trigger on a single bad image - only a set.

Yes, that set could be something other than child porn, assuming Apple and NCMEC conspire, but this is not a general purpose backdoor.

Re: One Bad Apple

#234

Earlier quoted context omitted.

I don't know how I feel about all of this yet (still trying to understand better), but your post implies that you've made a lot of incorrect assumptions about how this system works. For example, the main system in discussion never sends the image to Apple, only a "visual proxy", and furthermore, it only aims to identify known (previously cataloged) CSAM. There's a [good primer of this on Daring Fireball]( https://dar…

If the visual proxy is enough to determine CSAM from non-CSAM, it's a significant invasion of privacy. Sure a thumbnail is less information than full-res but not that much less.

FWIW I'm not defending this, but it's important to get the facts correct.

1) Someone can't just randomly review one of your images. The implementation is built on threshold secret sharing, so the visual derivative can't be reviewed (is cryptographically secure) unless you hit the threshold of matched content.

2) You're uploading these files to iCloud, which is currently not end-to-end encrypted. So these photos can be reviewed in the current iCloud regime.

Re: One Bad Apple

#236

Earlier quoted context omitted.

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

> I built the initial FotoForensics service in a few days. Why did you specify "In a few days"?

My guess is to establish the approximate amount of collaboration. He didn't work there full time for years, that collaboration has been small and limited.

Re: One Bad Apple

#237

Earlier quoted context omitted.

That question is framed wrong. What you should be asking is "Should people accused of such crimes get a fair and just trial?". This makes it clear that it takes me one sentence to put you in that very position. And that's exactly the problem. Your formulation erases any question of guilt, which makes the discussion nearly impossible to win for the privacy side.

No, what they’re saying is that most people already presume guilt, even if it’s just an accusation. Further, most would be willing to engage in mob justice. I feel like you’re doing a lot of work to miss that point.

The thread parent stated:

> If the people had their way, those suspected of child sex crimes wouldn’t even get trials.

Emphasis on suspected.

I agree that the question, as phrased, would be interesting and you'd probably be right that a lot of people would condone or even engage in mob justice. Given this thread, however, it seems that the actual question posed is the one I formulated.

As a side note, my formulation would also be the one to find out how likely people are to presume guilt, as the original formulation confirms guilt directly in the prompt.

Re: One Bad Apple

#238
post #174

Earlier quoted context omitted.

It does make one wonder--careless work, trivial problem, reuse of existing projects, writer portrays self as extremely productive, or some combination?

Ya, it's hard to interpret it differently, so was curious. Don't know why I'm being downvoted for a question about rhetorical intention.

I didn’t downvote, but it comes across as a nitpick on a thoughtful and reasonable piece.

Re: One Bad Apple

#239
post #132

Earlier quoted context omitted.

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

>About this time, someone usually mocks "it's always about the kids, think about the kids." To those critics: They have not seen the scope of this problem or the long term impact. There is nearly a 1-to-1 relationship between people who deal in CP and people who abuse children. And they rarely victimize just one child. Nearly 1 in 10 children in the US will be sexually abused before the age of 18. I think we have see…

The laws regarding CSAM/CSA are not the problem, they are fine. The problem is that we are expected to give up our rights in the vague notion of 'protecting children' while the same authorities actively ignore ongoing CSA. The Sophie Long case is an excellent example where the police has no interest in investigating allegations of CSA. Why is it that resources are spent policing CSAM but not CSA? It is because it is about control and eroding our right to privacy.

Re: One Bad Apple

#240
post #109

Earlier quoted context omitted.

If that’s how they play then the only winning move is to respond in kind. >shadowy government affiliated agency abuses its role of protecting children to install malware on a billion devices

That's a PR fight you will lose.

I'm not so sure, I think it may be a lose-lose scenario, with both the government and the companies who's products have become compromised taking a big hit.

The people merely avoiding the tainted products aren't on blast here.

Post reply on HN