Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

261–270 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#261

Personally I don't see on device scanning as significantly different than cloud scanning. I think the widespread acceptance of scanning personal data stored on the cloud is a serious mistake. Cloud storage services are acting as agents of the user and so should not be doing any scanning or interpreting of data not explicitly for providing the service to the end user. Scanning/interpreting should only happen when data…

Can you expand upon what you mean by "feels different because you supposedly own the device"? Just want to get a clearer idea of what you're saying. How does it feel?

Re: Apple's child protection features spark concern within its own ranks: sources

#262

Earlier quoted context omitted.

With server-side scanning, the separation is clear In all these threads everyone is coming close to the crux of the issue, but I want to restate it in clearer terms: There is a sacrosanct line between "public" and "private," "mine" and "yours." That line cannot be crossed by Western governments without a warrant. Cloud computing has deliberately blurred this line over time. This on-device scanning implementation blow…

> There is a sacrosanct line between "public" and "private," "mine" and "yours." That line cannot be crossed by Western governments without a warrant. This is a self-delusion, I am afraid. The line has been crossed more than once, and it will be crossed again. UK and Australian governments are just two prime examples of waving terrorism and pedobear banners as a pretext to get invasive with each new legislation, and…

And all the while:

Sir James Wilson Vincent Savile OBE KCSG (/ˈsævɪl/; 31 October 1926 – 29 October 2011) was an English DJ, television and radio personality who hosted BBC shows including Top of the Pops and Jim'll Fix It. He raised an estimated £40 million for charities and, during his lifetime, was widely praised for his personal qualities and as a fund-raiser. After his death, hundreds of allegations of sexual abuse were made against him, leading the police to conclude that Savile had been a predatory sex offender—possibly one of Britain's most prolific. There had been allegations during his lifetime, but they were dismissed and accusers ignored or disbelieved; Savile took legal action against some accusers.

https://en.wikipedia.org/wiki/Jimmy_Savile

Re: Apple's child protection features spark concern within its own ranks: sources

#263

> It's a complete change of narrative and there's no easy way to explain it and still defend Apple's Privacy narrative, wihout doing extreme mental gymnastics. Everyone who took Apple at their word was already doing extreme mental gymnastics because Apple's privacy stance was a farce on borrowed time to begin with. Now it's just blatantly obvious to everyone.

It’s only a “farce on borrowed time” because you have the benefit of hindsight.

No, this is obvious to anyone that understands that companies one master: profit. The soon as it becomes convenient to discard a "principled" stand, a company will do it. Apple was using privacy as a wedge to attack the Android consumer base or because they wanted their customers to believe they were special to reinforce their velben brand, not because they have some deeply held belief. In this case, perhaps Apple saw a way to do a favor for the government in exchange for some policy that will advantage it.

Re: Apple's child protection features spark concern within its own ranks: sources

#264
Has someone built a guide to self host on iOS/MacOS so the CSAM issue is moot? Or what are the other platform options, like on Android?

I’m concerned that Apple’s stance on security has been compromised and it is time to dump the platform or find an acceptable modification.

I’m surprised there’s no gist being linked on HN about to get people bootstrapped for secure device backups as an alternative to iCloud (and without a jailbreak).

Re: Apple's child protection features spark concern within its own ranks: sources

#265

This is the ultimate lock-in strategy. If you switch from iPhone now, everyone will suspect you of being a pedo and you'll have to endure the social consequences.

People switch back and forth between iphone and android all the time.

Re: Apple's child protection features spark concern within its own ranks: sources

#266

Earlier quoted context omitted.

Please stop insulting people because they chose less privacy than you. Don't act superior. I would posit that just about everyone who reads hackernews knows that privacy and security are on a spectrum. People complaining about this as the last straw have every right to do so and this is a huge leap from Apple's previous position. No one thinks you're any smarter by saying "I told you so".

Important adjustment -- privacy and surveillance are what's on a spectrum. Security is not the inverse of privacy.

I was going to say; I'm aware security is always a compromise (vs speed or ease of use or budget etc), but I've never seen that privacy and security are the natural opposites / inverses in same spectrum.

Re: Apple's child protection features spark concern within its own ranks: sources

#267

> It's a complete change of narrative and there's no easy way to explain it and still defend Apple's Privacy narrative, wihout doing extreme mental gymnastics. Everyone who took Apple at their word was already doing extreme mental gymnastics because Apple's privacy stance was a farce on borrowed time to begin with. Now it's just blatantly obvious to everyone.

Please stop insulting people because they chose less privacy than you. Don't act superior. I would posit that just about everyone who reads hackernews knows that privacy and security are on a spectrum. People complaining about this as the last straw have every right to do so and this is a huge leap from Apple's previous position. No one thinks you're any smarter by saying "I told you so".

My daily drivers are an Android and an iPhone while my PinePhone gathers dust, so I don't understand what this has to do with my privacy choices. Nor did I say it to act superior or imply that no one had a right to complain.

This is merely a reminder that Apple was founded in and most HN readers live in the United States, a nation founded on the idea that, without checks and balances, any power that can be abused will be abused. Without something legally binding and someone holding Apple to their word, their privacy stance was never going to be anything more than a temporary ploy in their ultimate goal: to make more money.

Re: Apple's child protection features spark concern within its own ranks: sources

#268

Earlier quoted context omitted.

>the system is just a few bit flips away from scanning every photo on your device I prefer to think of it as being just one national security letter away from that happening. Which is of course a schroedinger's cat kinda thing. It's already been sent. Or it hasn't. But why would the national security apparatus not take advantage of this obvious opportunity? Anyone giving benefit of the doubt to this kind of stuff now…

How would the agency issuing an NSL be able to generate a hash of a photo they’re looking for? Presumably if they already had a photo to derive the hash they’d already have whatever it is they’re searching for.

I think you already got one great reply, I have just one thing to add to it: your post literally presupposes a 1.0 version of this software that never has its feature set expanded. I don't think that's a reasonable assumption. After all, with 1.0 the goal of catching this class of person is barely achieved. They'll likely arrest people, 99% of whom are just CSAM jpeg collectors who get an extra kick out of viewing a class of image that is super illegal. And nothing more.

Then for version 2.0, they'll realize the INTERPOL, FBI, whatever can provide them a combo hash plus one string of text that can nail a known active producer. The holy grail. This small feature add to get so much closer to the original "moral goal" will prove too appealing to pass up. Now all the code is in place for the govt to pass over requests for data pinpointing mere common criminals.

Re: Apple's child protection features spark concern within its own ranks: sources

#269

Earlier quoted context omitted.

That is, it seems like Apple really wanted to preserve "end-to-end" encryption,“ … except they still have not mentioned anything about E2E encryption… and they currently don’t encrypt icloud backups. You would think apple would get ahead of this story and mention … or maybe they don’t have any E2E plans at all.

This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…

> But with Apple's CSAM proposal is NOT possible to have an iPhone that Apple isn't continuously scanning.

As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone.

Re: Apple's child protection features spark concern within its own ranks: sources

#270
post #124

Earlier quoted context omitted.

I am not a Lawyer, but my understanding is: The wording of the CSAM law is that content should be scanned when uploaded. That condition "upon upload" triggers the 3rd party doctrine. Apple has gone above and beyond here, not the actual US gov. So, the bill of rights doesn't apply to Apple's decision to scan content on device, just before it is uploaded.

There is no law that requires providers to scan users private documents, even uploaded. However, if they do review the material and see child porn they're obligated to report it.

Any chance you have a good link explaining this? I saw the parent comment earlier and wanted to add this. But I only recently learned that the US federal government cannot require or incentivize providers to scan user's private documents, so didn't want to post without clear sources.
Post reply on HN