Live data from Hacker News

Apple’s new abuse prevention system: an antritust/competition point of view

blog.quintarelli.it

251–260 of 318 posts

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#251

Earlier quoted context omitted.

It only scans images in your iCloud Photo Library. Not paying for iCloud? No scanning. Not in your photo library? No scanning. And even then, only for known content, not new content.

So the attacker only needs to get access to your iCloud. Your iPhone will happily sync down photos uploaded elsewhere. You don't have to be paying for iCloud, either. There's a free tier, so I'd imagine almost all iPhones are using some tier of it. iCloud account break-ins aren't exactly rare. An accusation, even if false, could ruin an innocent person's life.

If this was going to happen, it would have already happened on Android, Gmail, OneDrive, or any of dozens of services which already do what Apple is now doing.

Or are you saying that malicious activity is only interesting if it was on an Apple device?

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#252

Earlier quoted context omitted.

But for any serious charge you need indisputable evidence, and usually lots of it, usually the threshold is quite high.. But in the United States the system is insane so I could be wrong

All the evidence required is that it is there. Does not matter if someone else put it there without your knowledge. Or maybe it matters, but then it's on you (for all intents and purposes) to prove that it was without your knowledges.

The punishment for strict liability is much lower than for the same act with intent.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#253
post #238
post #113

Earlier quoted context omitted.

> Problem is that this scanning is necessarily fuzzy and there is going to be a false positive rate to it. And the way that you'll find out that you've tripped a false positive is that the SWAT team will knock your door down and kill your dog (at a minimum). Not true. Hash matches are to be human reviewed. So no, people won't get "swatted" accidentally as you allege. The other concerns people have been voicing are ce…

Reviewing potential matches sounds like an awful job. Retention might be even lower than in those FB abuse centers.

That's part of why possession is illegal. The material is toxic.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#254

Apple will release this in their desktop pcs. The major consequence of this is that, a year down the line, microsoft will also be compelled/forced to join this "coalition of the good". After all, they already scan all your files for viruses, it would be a shame if they didn't scan for anything that is deemed incriminating and also call the cops on you. Of course, the children are being used as a trojan horse again. W…

Of course, the next step after that is to make "non-authorised" operating systems -- which may include Linux (except for specially signed versions that will also include similar spyware) -- "deprecated" or "discouraged", then "suspicious", and perhaps even eventually illegal. Stallman predicted a similar outcome, and although he (and many others) thought the end of computing freedom would be due to copyright/DRM, I w…

> ...and as much as I'd like to see at least that amount of "watering the liberty tree" directed at Big Tech […]

I’m having a hard time finding a reading of this that isn’t advocating violence against tech workers. Is that what you intended?

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#255
post #139

Earlier quoted context omitted.

I can't find a widely accepted statistic but these numbers should illustrate the point: - A 2016 study by the Center for Court Innovation found that between 8,900 and 10,500 children, ages 13 to 17, are commercially exploited each year in the United States. (Center for Court Innovation, 2016) https://www.courtinnovation.org/sites/default/files/document... - The annual number of persons prosecuted for commercial sexua…

Thanks for the statistics. To me, these numbers are significant. Maybe Whole Foods or maybe some popular restaurants are better candidates for working on improving nutrition in public schools? Why don’t we let apple contribute where it thinks it can. Maybe with apple that number goes down from 10,000 to 2,000. Wouldn’t that be a celebrated outcome?

[deleted]

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#256
post #28

There is no such thing as a trustworthy third party and even trusting yourself is questionable at the best of times. We are constantly balancing a bunch of different considerations with regards to the way that we compute, purchase devices, and utilize services. Security and privacy are of course important, and Apple to date has had a fairly good (if shallow) track record in this regard, at least in the United States.…

> "As mentioned in the article, this does absolutely nothing towards protecting children other than directing all but the biggest idiots towards platforms that can't be linked to them, which I'd imagine, they already are." I suspect you're more wrong than you think about this. People share large volumes of CSAM through lots of different services - I knew someone who worked on the problem at Linked In (!). HN likes to…

[deleted]

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#257

Earlier quoted context omitted.

All the evidence required is that it is there. Does not matter if someone else put it there without your knowledge. Or maybe it matters, but then it's on you (for all intents and purposes) to prove that it was without your knowledges.

The punishment for strict liability is much lower than for the same act with intent.

It's still essentially a death sentence if you are innocent.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#258

So this new Apple stuff has made me decide not to buy an M1. I'm leaning Framework laptop. For my phone though... no idea. My iPhone is honestly such a solid piece of tech. I don't _want_ to go Google either... so what else do i have? I know lots of people run de-googled Androids, which i guess works, but i'd prefer to avoid them entirely. Is there anything that works? edit : I know of the Purism phone ( https://puri…

My MacBook Pro is overdue for an upgrade, and I literally ordered a Framework laptop (on which I plan to run Debian) partially in response to this announcement.

I am looking at Framework, but it still feels like a legacy tech. I have XPS 15 from 2019 and it feels slow and fans drive me crazy. I don't think Framework will be much different. I was looking at M1 for fanless experience and performance. I wish they at least considered ditching Intel and adding a good AMD option - then I will buy it.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#259
post #147
post #92

Earlier quoted context omitted.

One in one trillion chance per year, per the paper on the Apple site.

I see the 'one in one trillion' but it's a bit vague; I read it as '1 in trillion chance' per image. So when we have a billion iPhones in the wild taking 10 images a day...1 in a trillion chances happen every few months. Now, if that triggers some further review, maybe that's an acceptable false positive. If it triggers a SWAT team, I don't think it is.

They have also indicated that a single match won't be enough to trigger it, so an accidental match (being that 1 in a trillion person) is not enough.

Re: Apple’s new abuse prevention system: an antritust/competition point of view

#260

Earlier quoted context omitted.

I think it has gotten more sophisticated to detect cropped images and small changes now: https://inhope.org/EN/articles/what-is-image-hashing The example is somewhat contrived. If a 'friend' takes your phone and has access to it and then uses it to take images of CSAM similar enough to the original image that it triggers the hash match and does this enough times to go over Apple's threshold to flag the account after…

Or you know, anyone who wants to plant material on a device and has physical access. Say a disgruntled employee before leaving, or ex, or criminal or... Or anyone who can just text you since imessage backs up to icloud automatically...

While iMessage backups to iCloud, this measure is only for photos stored in the iCloud Photo Library. So sending a text with the photo is not enough.
Post reply on HN