Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

251–260 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#251
post #142

Imagine taking a photo or have in your gallery a photo a dear leader doesn't want to spread. Ten minutes later you heard a knocking at your door. That's what I'm most worried about, how is this not creating the infrastructure to ensnare political dissidents.

I am profoundly disappointed that almost all of the discussion is about the minutiae of the implementation, and "Hmm.. Am I ok with the minutiae of Apple's specific implementation at rollout?" And almost nobody is discussing the basic general principle of whether they want their own device to scan itself for contraband, on society's behalf.

But Apple says, "You need several hash matches to trigger a review." See, that makes it OK!

Re: The deceptive PR behind Apple’s “expanded protections for children”

#252

>The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember) people really need to retire this meme. On the desktop in particular as a dev environment Linux is completely fine at this point. I can understand people not wanting to run a custom phone OS because that really is a ton of work but for working software de…

While I don't expect any Linux phone to become "mainstream" any time soon, it would be good if we had at least one "polished" alternative available.

PinePhone is still in beta and according to its own creators "aimed solely at early adopters"[1], while Librem 5 is experiencing supply chain issues with backorder shipping now scheduled to resume in October[2]

There is a version of the Librem 5 which is made in USA and it's in stock and shipping now, but unfortunately outside of my budget[3].

I was also considering getting something like Fairphone and installing an alternative OS but looking at compatibility charts there are some things that may not work with one OS or another.

So, right now I can't have a daily driver that is not iOS or Android, I will hold onto my very old smartphone and hope that things will change in the next year or so. I'm working from home for the foreseeable future so I can wait a bit.

[1] https://pine64.com/product/pinephone-beta-edition-linux-smar...

[2] https://shop.puri.sm/shop/librem-5/

[3] https://shop.puri.sm/shop/librem-5-usa/

Re: The deceptive PR behind Apple’s “expanded protections for children”

#253

Earlier quoted context omitted.

John Gruber is biased because his brand is closely tied to Apple’s brand. Ben Thompson wrote a better review on the topic: https://stratechery.com/2021/apples-mistake/ There’s also the Op-Ed by Matthew Green and Alex Stamos, cyber security researchers: https://www.nytimes.com/2021/08/11/opinion/apple-iphones-pri...

They have a podcast together called Dithering which is pretty good (but not free) - they're friends. I think John's article is better than Ben's, but they're both worth reading. Ben takes the view that unencrypted cloud is the better tradeoff - I'm not sure I agree. I'd rather have my stuff e2ee in the cloud. If the legal requirements around CSAM are the blocker then Apple's approach may be a way to thread the needle…

Is it really E2EE if there is an MITM application scanning and reporting everything?????

Seems like the existence of this scanning agent by default makes it not E2EE anymore

Re: The deceptive PR behind Apple’s “expanded protections for children”

#254
post #8

Earlier quoted context omitted.

Unless those pictures are also in the NCMEC database, there won’t be a match.* * As addressed in the comments below, this isn’t entirely true: the hash looks for visually similar picture and there may be false positives.

Absolutely not true. Apple is using a similarity based hash, so if the NCMEC database contains a picture that's similar to one that you have, it could produce a match even if it's not the same. Apple says this isn't an issue, because a person will look at your picture(yes, a random person somewhere will look at the pictures of your newborn) and judge whether they are pictures of child abuse or not. If this unknown pe…

> because a person will look at your picture(yes, a random person somewhere will look at the pictures of your newborn)

No. If the number of matches to known CSAM in your library exceeds a threshold, then a person will look at a "visual derivative" of only those pictures whose perceptual hatch match that of known CSAM.

Note that, if I understand correctly, pictures that Android users sync to Google have already been scanned for some time. Where are all those false positives?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#255

Earlier quoted context omitted.

That's the crux of it. Why bother with on-device identification, unless one of: a. Apple intends to E2E encrypt iCloud data. b. This is intended to extend to all photos on the device in the future. I'm hoping it's (a), but it's probably (b). And in either case it sets a bad precedent for other companies to follow. Edit: This also turns every jailbreak into a possible CSAM detection avoidance mechanism, giving the gov…

Where is this stance coming form that Apple needs to break E2E crypto to be "able" to "E2E encrypt iCloud data"? That makes absolutely no sense. There is nowhere such a requirement. They could just E2E encrypt iCloud data. Point.

It is curious that particular notion keeps getting repeated ad nauseam given it makes zero sense.

It's coming exclusively from Apple fans desperate to give them the benefit of the doubt on this rather epic implosion of Apple's brand when it comes to privacy.

So many people hooked themselves up to the Apple-is-pro-privacy wagon. They invested into the ecosystem across the board. They've been swimming in Apple's products & services pool for years or decades. Apple just went from hero to maybe villain on privacy. So now many of those people that are getting screwed over by Apple are going to be emotional about it, irrational about it, in denial about it.

It won't be used nefariously in the future. It won't be expansive, it'll remain the very limited program they say it is today. It won't be abused around the world by authoritarian governments. One of the greatest potential surveillance tools ever deployed and it won't be rampantly abused by the world's most powerful governments and agencies (all of which are hungry to spy on their citizens and or other nation's citizens). Yeah right.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#256

>The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember) people really need to retire this meme. On the desktop in particular as a dev environment Linux is completely fine at this point. I can understand people not wanting to run a custom phone OS because that really is a ton of work but for working software de…

I hate ubuntu from the bottom of my heart, for breaking stuff and changing stuff that used to "just work" all the time, but 99.999% of the time, that means "background stuff", "normal users" never mess around with, and for normal users, a "usb key -> install -> next, next, next -> finish -> reboot" just works.

I used to use Ubuntu for many years, but it became a such bloatware. So many things what you don’t really need.

Packages were sometimes also different compared to vanilla Debian. This caused issues in stability (talking more about feature set). Some advanced software just did not work, which worked on equivalent vanilla Debian.

I might recommend Ubuntu for very beginner developer, but not to stick with it longer time. It will give you headache. There are also more privacy-friendly distributions.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#257

There is something you can do about it: don’t use Apple products

That strategy will last ~15 minutes until Google is doing the same thing. Then what? I would argue that what Google is doing already is way more privacy-compromising than this.

Then don't use Google products either (or don't use for photography). Seems obvious.

"Dumb" phones and "dumb" cameras still exist.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#258
post #176

Earlier quoted context omitted.

Ahh - an "irrefutable" claim that apple is committing child porn felonies. This is sort of what I mean and a perfect example. People imagine that apple hasn't talked to the actual folks in charge NCMEC. People seem to imagine apple doesn't have lawyers? People go to the most sensationalist least good faith conclusion. Most mod systems at scale are using similar approaches. Facebook is doing 10's of MILLIONS of images…

Sorry under which of these other moderation regimes does the organisation in question transmit CSAM from a client device to their own servers? To my knowledge Apple is the only one doing so.

Almost every single one.

Facebook checks for potential CSAM when you upload from your client device (sometimes an iphone) to their servers or after it's on their system and a user flags it.

Instagram also check once you upload.

These are all transmissions.

Apple checks if you upload. If you don't upload or attempt to upload to their servers, no check.

All these are to flag potential CSAM. Some do more - nudity in general, harmful content filters etc. Some is auto blocked, some is forwarded for review and report etc.

In almost all cases flagging is part of or connected to uploading to a third parties servers. The flagging for CSAM is not a conviction - some do and some don't do a human review before submission. Most situations where folks can use flagging to hide content get a human review at some level to avoid abuse of the flagging system itself.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#259
This whole mess brought back a memory of when I was 4 to 5 years old (so probably 1971). During a summer vacation we were walking at a harbor in Tuscany with my parents and they told me suddenly I had to take a dump. Problem was that there was no bathroom nearby, well it probably was since the place was filled with restaurants, but we were like a hundred meters from the nearest one, which was incompatible with the sudden need of a baby like I was. So my parents quickly found an area with vegetation behind a building, helped me remove my clothes and sit down waiting for me to unload all that stuff. Then my father saw me doing an expression they later described as priceless, so he quickly shouted me to wait, then grabbed his Nikon and shot me a photo. That photo later that year won a prize.

Now imagine the same happening today with my dad shooting me a photo using his iPhone, only to trigger a CSAM alert somewhere an probably be investigated for child abuse. Just no thanks. Screw you Apple, and all those who pull your strings into creating this farce.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#260

Earlier quoted context omitted.

Comparing hashes reminds me of this announcement from a few years ago that Google had produced a SHA1 collision: https://security.googleblog.com/2017/02/announcing-first-sha... Can you imagine the chaos of a successful collision matching some explicit material being sent as a prank or targeted attack?

No chaos. The photos would be reported, reviewers would say "that's weird" since the false positive was obviously harmless and the industry would eventually switch to a different hash method while ignoring the false positives generated by the collision. If there were a flood of false positive images being produced the agencies would work faster to come up with a new solution, not perform mass arrests.

I thought the images were encrypted after the hashing was done locally. Reviewers can still view them?
Post reply on HN