Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

261–270 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#261

What would prevent someone from, for instance, printing off an illegal photo, “borrowing” a disliked co-workers iCloud enabled phone, and snapping a picture of the illegal picture with their camera? On iOS the camera can be accessed before unlocking the phone, and wouldn’t this effectively put illegal image(s) in the targets possession without their knowledge?

These illegal photos are not trivial to obtain. Possessing (and here, the printing step necessitates possession) these illegal photos is in and of itself a crime in most relevant jurisdictions. But OK, let's say that you've found a way to get the photos and you're comfortable with the criminal implications of that. At that point why don't you just hide the printed photos in your coworker's desk? My point is that if y…

An “interesting” part of this is, up until now these photos had little technical exposure. But now that millions of phones can be affected, creating unrelated pictures that purposefully match these hashes becomes a shinny target.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#262

Earlier quoted context omitted.

No chaos. The photos would be reported, reviewers would say "that's weird" since the false positive was obviously harmless and the industry would eventually switch to a different hash method while ignoring the false positives generated by the collision. If there were a flood of false positive images being produced the agencies would work faster to come up with a new solution, not perform mass arrests.

Right. Kind of like how copyright violations on YouTube are double checked and the humans say “that’s weird” and deny the request. Or maybe they will just report everything and let the law work everything out. If they’re innocent they have nothing to worry about, right?

I don't understand how most people are still willing to "trust the system" when it's evident that this type of mechanism keeps failing time and time again.

And in the example you gave we are talking about Google, not some early-stage understaffed startup.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#263
post #77

Earlier quoted context omitted.

No, it doesn't work like that.

Yes it does, it uses fuzzy perceptual hashes not crypto hashes. So if your innocent baby pic looks similar enough to a previously tagged child abuse image then YES, it will flag you and send a copy to the feds. And before you correct me, the Apple employee will see a picture of your naked baby and hit “forward to NCMEC”, which… upon investigation is actually just the feds

Perceptual hashes are extremly accurate. You might need a twin and top of that somehow identical environment almost in pixel level.

Are news filled with false-positive accusations by PhotoDNA, flagging wrong images in Google, Facebook, Instagram etc.?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#265
post #176

Earlier quoted context omitted.

Sorry under which of these other moderation regimes does the organisation in question transmit CSAM from a client device to their own servers? To my knowledge Apple is the only one doing so.

Apple is attaching a ticket to images as the user uploads to iCloud. If enough of these tickets think CSAM and allow an unlock key to be built, they will unlock and get checked. It's still the user who has turned on iCloud and uploaded the images.

Correct.

The one odd thing I don't get. It would be a lot EASIER to just scan everything when its in the cloud itself.

Why go to this trouble to avoid looking at users photos in the cloud, set these thresholds etc. You'd only need to scan on device if for some reason you blocked your own ability to scan in cloud (ie, for E2E photos - which I don't think users actually want).

Re: The deceptive PR behind Apple’s “expanded protections for children”

#266

Earlier quoted context omitted.

Where is this stance coming form that Apple needs to break E2E crypto to be "able" to "E2E encrypt iCloud data"? That makes absolutely no sense. There is nowhere such a requirement. They could just E2E encrypt iCloud data. Point.

There is no requirement right now, but you only need to look at what's happening in the US, UK, and EU to see the battle setting up around E2EE. Apple may see this feature as a way to quiet critics of E2EE. Hard to know if it will be enough. But, I think it's safe to say if Apple did turn on E2EE w/o any provision for things like CSAM, it would help drive legislation that is likely more heavy handed.

Even if that were true, that Apple might accelerate attempted government overreach by encrypting data end to end, the obvious better solution would be to hold the line on the status quo for as long as possible (including legally duking it out with governments around the world to hold the line to the extent they can), not to do what they're doing now.

If they were badly losing on that front (such that all hope were lost so to speak), then they could attempt this new approach at that time, they could offer that up as a middle ground, and their seeming capitulation then would buy them a lot of slack. Instead, they're supposedly pre-capitulating (if you buy into that premise).

Doing what they're doing now, it looks like one of a few possibilities: they're just that stupid (I'm skeptical), they're groveling for points (hey, if we give you this, maybe you'll leave us alone on anti-trust, as our size and quasi-monopolistic position is beneficial to your surveillance aims), or they're already being compelled (as they were with PRISM) and are not publicly able to reveal that.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#267
post #257

Earlier quoted context omitted.

That strategy will last ~15 minutes until Google is doing the same thing. Then what? I would argue that what Google is doing already is way more privacy-compromising than this.

Then don't use Google products either (or don't use for photography). Seems obvious. "Dumb" phones and "dumb" cameras still exist.

That is not practical for many people who wish to be a part of society anymore. See: rollout of virtual vaccine passports, etc.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#268
post #93

Earlier quoted context omitted.

And you think this will be the ultimate implementation? Let the devil in, and he'll treat himself to tea and biscuits.

I think it's possible to have nuanced policy in difficult areas where some things are okay and others are not.

Did we learn nothing from the Snowden revelation?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#269

There is something you can do about it: don’t use Apple products

That strategy will last ~15 minutes until Google is doing the same thing. Then what? I would argue that what Google is doing already is way more privacy-compromising than this.

Google couldn’t do it, not effectively anyway because android vendors and variants are decentralised. They could do it for the pixels but that represents less thats half a percent of the market - not to mention that everyone on a pixel could just move to lineageOS if they didn’t like it.

That freedom and decentralisation doesn’t exist on Apple (at least yet, maybe the DOJ or congress will regulate them).

Re: The deceptive PR behind Apple’s “expanded protections for children”

#270

This whole mess brought back a memory of when I was 4 to 5 years old (so probably 1971). During a summer vacation we were walking at a harbor in Tuscany with my parents and they told me suddenly I had to take a dump. Problem was that there was no bathroom nearby, well it probably was since the place was filled with restaurants, but we were like a hundred meters from the nearest one, which was incompatible with the su…

There will only be an alert if that photo is extremely similar to an image in the NCMEC database, AND there are numerous other such photos on the account that match. The threshold number of matches to trigger an alert is tuned for a 1/trillion chance of false positive.

Furthermore, if you were using say Google Photos to store your images, then you were already subject to this vulnerability.

Post reply on HN