Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

261–270 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#261

Earlier quoted context omitted.

Does the school work to cover it up to the same extent? Are people across the school in on it? Are the rates of abuse higher on a per capita basis? Why are you making apologies for (Catholic) church sex abuse? Because you are a member and you took a training? Yikes.

Where did you see apologies? I read it basically as “schools are even worse than churches and scouts yet are overlooked,” nothing apologizing for the churches.

HN is very anti-religion. It turns off their brain when they see it and leads to these kinds of responses.

Re: Apple defeats liability for not scanning iCloud for CSAM

#262
post #14

Earlier quoted context omitted.

> It is crazy people think apple isnt on the side of privacy. > It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do. I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare qu…

> I feel that Apple open pandora's box with the client-side scanning. That box has been open for years now. Big brother is already watching what you do on your Android device. > A Dad Took Photos of His Naked Toddler for the Doctor. Google Flagged Him as a Criminal. https://www.nytimes.com/2022/08/21/technology/google-surveil...

I'm pretty sure this article if from after Apple introduced (floated the idea of?) client-side scanning. I'm not sure it really bolsters the idea that it's been open for years.

Re: Apple defeats liability for not scanning iCloud for CSAM

#263
post #142
post #8

I know creating a throwaway to hide your name for an opinion is a bad manner, but this one is one I really don’t want linked back to me The VAST majority of “CSAM” is consensually created and exchanged by teens. Their future selves and their parents form this pressure group attacking everyone’s liberty and privacy to try to undo the downsides of choices they made themselves with full knowledge of what could happen. T…

I completely agree with you, but I do think that these teens do not have good opsec around these photos. It’s like the revenge porn problem but way worse. A teenager sending a nude selfie to a friend who then later shared these images non-consensually is a much bigger problem than if the same thing happened to adults. I don’t have any ideas for a solution, but I suspect that the heightened focus on CSAM is really com…

There is no good solution to revenge porn. It is impossible to enforce that only a single person has access to an image (physical or digital), and that the person doesn’t redistribute the image.

The only way I can see this working is that people in explicit images need to publicly declare their intent for who can see the images (maybe a hash of the image content and the name of the person who can see that content) and then when the courts prosecute revenge porn the intent can be referenced to see if it was meant to be shared or not. There are still issues in that there is no proof that the person being accused of revenge porn actually distributed the images vs the defendant actually sending the images to other, or the image was leaked by a hack.

I think the best thing we can do is try and educate teens on the dangers of revenge porn like we do on the consequences of having sex. We cannot stop teens from having sex or taking nudes, but we can at least try to educate them as best we can.

Re: Apple defeats liability for not scanning iCloud for CSAM

#264

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

The CSAM issue is both very real and abused by politicians. When I did some work with a police agency, it was explained to me that there’s a pattern of escalation with people and they tend to accumulate collections and many escalate to actual behavior.

The detectives assigned to this work tend to not last long, and the horrific nature of the crime affects them.

Like all rape, it’s a combo of control and dopamine. The church and Boy Scout leaders leveraged their societial influence and power to compel compliance and even loyalty from their victims. Boy Scouts as an organization inserted itself into existing power structures like church, police and other institutions. It’s difficult for a 11 year old victim to make an accusation about a beloved community figure. They also tend to find ways to make their victims feel complicit. Even if people come forward, they are hard cases to try and exposes young victims to public shame. Many of these people plea to lesser crimes to protect the victim.

I wasn’t a victim thank god, but a Boy Scout leader at my parish was a serial molester who abused dozens or hundreds of children. I learned about it years later and realized that some of my friends were almost certainly victims — in his case everyone in authority just blew it off

Re: Apple defeats liability for not scanning iCloud for CSAM

#265

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

> On the CSA side, you rarely hear about arrests (they happen but less than CSAM).

Because it is nearly always someone we know. Someone who we just cannot imagine would ever do such a thing, even when the evidence is glaringly obvious. And I suspect that the fraction of the population diddling kids in real life is breathtaking, and nobody really wants to face that head on. Too uncomfortable.

I could just be overly cynical today. But given my own experiences and other people I've known throughout my life, I really believe it is very common.

Re: Apple defeats liability for not scanning iCloud for CSAM

#266
post #214

Earlier quoted context omitted.

Google Photos does ask you for consent when you run it. (It is, granted, a bit pushy about it and will ask multiple times when you run it with an intrusive dialog.)

Informed consent would require Google to inform you that their AI server will scan every photo you take with your device and report you to the police if it should detect (or hallucinate) something it doesn't like.

On page 83 of subsection 14 of paragraph 3 of the consent document you agree to by using "google" as a verb, or by viewing any website they have a tracking pixel on there is a link to a policy which mentions that they retain the right to scan any and all of your photos for advertising targeting purposes, and further, if you read page 27 of the sub agreement mentioned in upside down white on white text in the main TOS they describe advertising purposes as: "Anything we want to do, in perpetuity, for any reason, and without any right of redress".

It's right there plain as day in the TOS. I don't know how people can use these products without understanding the contract they locked themselves into. /s

Re: Apple defeats liability for not scanning iCloud for CSAM

#267

Earlier quoted context omitted.

Only if the company misleads and adds a backdoor to the front-end app (thus this entire discussion). If the company is misleading, any encryption technology is irrelevant anyway.

The company can provide secure enclave and allow the architecture to be audited by third parties. Which apple does. It's largely academic though, as almost nobody opts-in to escalated e2e posture in apple services unless they're a high risk person (journalist, dissident, etc). The headaches that come from e2e everything are too great for most people.

[deleted]

Re: Apple defeats liability for not scanning iCloud for CSAM

#268

Earlier quoted context omitted.

There is no _society_ without _social_ mores and norms.

I'm not denying they exist, I'm saying a society that values liberty shouldn't enforce them by law.

This is an argument I find myself making depressingly frequently to people I thought knew better...

Re: Apple defeats liability for not scanning iCloud for CSAM

#269

Earlier quoted context omitted.

You're suggesting they purposely put a backdoor into all their custom methods? Why? From a liability standpoint that implies a security breach could result in massive loss of customer data and if it did occur would destroy their privacy image to their customers. I agree with the point that what you actually trust is the company to not insert maliscous code or keys into your protected path but modern systems actually…

> You're suggesting they purposely put a backdoor into all their custom methods? Why? I'm not sure what you mean by "custom methods", but I'm not saying they have bypassed the e2e encryption - I'm just saying that they technically could . And as for why they would do that, they might get compelled by a government to do it secretly. As far as I know that hasn't happened yet but I see no reason it couldn't and it would…

I disagree because these systems are amoungst the most abused in the world. The only way a backdoor realistically exists is if they have code that is prebuilt backdoor that they serve to inviduals upon request.

As a company you'd be asking for an internal implosion of your company if everything had an additional backdoor in it.

Any backdoor added is a backdoor the thousands to tens of thousands of advanced hackers are always actively trying to breach. So if they do it they'd be doing it very selectively via special served code.

It's also the only way they'd stop whistle blowers.

Now that I say it. That's 100% what they would do. But again it's a crazy high risk almost zero reward action for them. Is the CIA paying apple a bajillion dollars for phones? No so why unless their arm is twisted would they risk billions of dollars for basically no gain?

Re: Apple defeats liability for not scanning iCloud for CSAM

#270

Earlier quoted context omitted.

There are actual methods to do this though just not sure anyone does it yet. 1. 3rd party audit of a current repo hash 2. Public hosting of hash 3. Modern attested compute can check the current startup and running code hash and return to the user for their own checks. 4. User encrypts the last known hash they used or trust a 3rd party to perform the check like azure's methods. Another way is to open source it and rep…

How would that work for closed source apps like iMessage and WhatsApp?

"3rd party audit"
Post reply on HN