Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

241–250 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#241

Whoever controls the hash list controls your phone from now on. Period. End of sentence. Apple has not disclosed who gets to add new hashes to the list of CSAM hashes or what the process is to add new hashes. Do different countries have different hash lists? Because if the FBI or CIA or CCCP or KSA wants to arrest you, all they need to do is inject the hash of one of your photos into the “list” and you will be flagge…

There are numerous incorrect statements in your comment. First: Apple has disclosed who gets to curate the hash list. The answer is NCMEC and other child safety organizations. https://twitter.com/AlexMartin/status/1424703642913935374/ph... Apple states point-blank that they will refuse any demands to add non-CSAM content to the lists. Second: Why can't the FBI / CCCP inject a hash into the list. Here's a tweet thread…

How do you know there aren’t bad actors working at the NCMEC? If I know that adding a hash to a list will get it flagged, and I could conveniently arrest or discredit anyone I wanted, I would certainly send people to work there.

How will Apple know whether a hash is for non-CSAM content? Spoiler alert: they won’t.

And Apple claims it will be reviewed by a human. Sure, just like YouTube copyright claims? Or will it get automated in the near future? And what about in China? Or Saudi Arabia or other countries with less human rights?

The point is that it is completely an easy way to get tagged by a government or bad actors as a pedophile. It’s sickening that Apple would let this “technology” into their products.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#242

What would prevent someone from, for instance, printing off an illegal photo, “borrowing” a disliked co-workers iCloud enabled phone, and snapping a picture of the illegal picture with their camera? On iOS the camera can be accessed before unlocking the phone, and wouldn’t this effectively put illegal image(s) in the targets possession without their knowledge?

These illegal photos are not trivial to obtain. Possessing (and here, the printing step necessitates possession) these illegal photos is in and of itself a crime in most relevant jurisdictions. But OK, let's say that you've found a way to get the photos and you're comfortable with the criminal implications of that. At that point why don't you just hide the printed photos in your coworker's desk? My point is that if y…

It takes 1 minutes on TOR to find enough to get anyone thrown in jail don't make it sound harder than it really is. As for photos vs printing taking a photo reports it for you so you're never involved.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#243
post #33

Earlier quoted context omitted.

> Gruber practically (no, perhaps actually) worships Apple. He'd welcome Big Brother into his house if it came with an Apple logo, and he'd tell us how we were all wrong for distrusting it. You mean the same Gruber who described the situation as “justifiably, receiving intense scrutiny from privacy advocates.”? The one who said “this slippery-slope argument is a legitimate concern”? I'm having a hard time reconciling…

If icloud backup works as advertised - it backs up your device. However, if we consider the slipery slope, under pressure from a shaddow government, the contents of your phone could have been uploaded to the CIA every day, including live recordings 24 hours a day.

Yes, but that has always been the case. It can upload to iCloud, it could also upload to the CIA. What has changed?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#244
post #109
post #47

Earlier quoted context omitted.

In this TechCrunch interview, Apple believes it is less invasive since no one can be individually targeted. The hashes are hard coded into each iOS release which is the same for all iOS devices. The database is not vulnerable to server side changes. Additionally, FWIW, they do not want to start analyzing entire iCloud photo libraries so this system only analyzes new uploads. https://techcrunch.com/2021/08/10/intervie…

>The hashes are hard coded into each iOS release Do you have a source on that? Since it is illegal to share those hashes in any way or form. Even people working with photo forensic and big photo sharing sites cannot get access to them. I very much doubt Apple can incorporate them into the iOS release without breaking multiple laws. The hashes themselves can easily be reversed to (bad quality) pictures so having the h…

No, these hashes can’t be reversed to an image. They’re not CSAM and therefore not illegal. That blog is not very good, either from a tech standpoint or a legal one.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#245
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

How do we know the database itself does not have any false positives?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#246

Earlier quoted context omitted.

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

How do new hashes get added to this database? How do we know that all the hashes are of CSAM? Who is validating it and is there an audit trail? Or can bad actors inject their own hashes into the database and make innocent people get reported as pedophiles?

Apple has stated point-blank that the only source of CSAM content to generate the hash list will be NCMEC and other child safety organizations.

While I fully admit that NCMEC could do a better job with transparency and auditing, they are currently being used by several other platforms right now (Facebook, Google, Microsoft) without issue.

Could bad actors inject hashes of non-CSAM content into the database somehow? Well even if they could do this, Apple employes human reviewers who must visually confirm that the flagged photo contains actual CSAM before they report the image. If the image does not contain CSAM, Apple is under no legal obligation to report it.

More information here: https://twitter.com/AlexMartin/status/1424703642913935374/ph...

Re: The deceptive PR behind Apple’s “expanded protections for children”

#247

in "Photos" app, in the bottom right corner there is a "search" icon. When I click it, and entering "beach", I can see photos I've made on the beach (or in the sea, near the beach). What does it mean? My (and your) photos are scanned and analyzed. I've heard literally zero noise about this feature - nobody was complaining (at least not loud enough to let me notice it). So, why the hell all of that fuzz is being raise…

It turns out people liked it when their phone scanned their photos for 'selfie' or 'beach' for them. Apparently tagging 'child porn' on your photos for searching isnt the killer feature someone thought it might be.

Your photos aren’t being tagged as child porn.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#248
post #23
post #8

Earlier quoted context omitted.

Unless those pictures are also in the NCMEC database, there won’t be a match.* * As addressed in the comments below, this isn’t entirely true: the hash looks for visually similar picture and there may be false positives.

As far as I understand they use some kind of hash. I suspect their paper on avoiding hash collisions is right next to the Nobel price wining description of the worlds first working perpetuum mobile.

They have accounted for the possibility of false positives.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#249
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

I don’t want it done on my device. Might as well let the police in my home whenever they want to rummage through my papers.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#250

in "Photos" app, in the bottom right corner there is a "search" icon. When I click it, and entering "beach", I can see photos I've made on the beach (or in the sea, near the beach). What does it mean? My (and your) photos are scanned and analyzed. I've heard literally zero noise about this feature - nobody was complaining (at least not loud enough to let me notice it). So, why the hell all of that fuzz is being raise…

What are those cases where they might be checked by humans? To determine whether it's an innocent baby bath? If you have naked photos of a partner which happen to hit a statistical match for certain patterns that are similar to CSAM? These aren't far fetched scenarios, these are exactly the most likely types of photos that would be likely flagged. Are you okay with those photos being passed around Apple's security re…

It is very far fetched. The system matches copies of specific photos, not subject matter like “baby taking a bath”.
Post reply on HN