Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

271–280 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#271

Earlier quoted context omitted.

I really don't understand how you're arguing as if you don't see the bigger picture. Is this is a subtle troll? They are now scanning on the device. Regardless of how limited it is in its current capabilities, those capabilities are only prevented from being expanded by Apple's current policies. The policies enacted by the next incoming exec who isn't beholden to the promises of the previous can easily erode whatever…

Frankly the distinction seems arbitrary to me. This is a policy issue in both cases - policy can change (for the worse) in both cases. The comparison is about unencrypted photos in iCloud or this other method that reveals less user information by running some parts of it client side (only if iCloud photos are enabled) and could allow for e2e encryption on the server. The argument of "but they could change it to be wo…

They've given you two options:

1. Encrypt everything in the cloud but upload the hashes of these items as well on the device. Also notify us so we can notify law enforcement if they're doing some illegal stuff.

2. Everything is unencrypted in the cloud. No actions are taken on the device. No notifications to authorities.

With option one the sanctity of the device ownership is breached. With option two it's maintained. Maintaining that stark distinction is hugely important for what future actions can be taken in the public eye. Normalizing on device actions that work against the user must be fought at every instance they occur.

Your line of thinking dangerous because you're ignoring the public perception of a device you own actively working against you. Apple's behavior cannot be allowed to be considered normal.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#272
post #254

Earlier quoted context omitted.

Absolutely not true. Apple is using a similarity based hash, so if the NCMEC database contains a picture that's similar to one that you have, it could produce a match even if it's not the same. Apple says this isn't an issue, because a person will look at your picture(yes, a random person somewhere will look at the pictures of your newborn) and judge whether they are pictures of child abuse or not. If this unknown pe…

> because a person will look at your picture(yes, a random person somewhere will look at the pictures of your newborn) No. If the number of matches to known CSAM in your library exceeds a threshold, then a person will look at a "visual derivative" of only those pictures whose perceptual hatch match that of known CSAM. Note that, if I understand correctly, pictures that Android users sync to Google have already been s…

>>the number of matches to known CSAM in your library exceeds a threshold, then a person will look at a "visual derivative" of only those pictures whose perceptual hatch match that of known CSAM

Apple very specifically said that their employees will look at the suspected picture before sending it through to authorities. Where do you see the bit about visual derivatives? What would that even mean or look like?

Also what is this threshold? As others have pointed out, us parents have literally hundreds of pictures of our newborns, toddlers and kids - having to trigger some detector "multiple" times doesn't give me any peace of mind at all.

>>Where are all those false positives?

Google doesn't use perceptual hashing, or at least haven't said they do.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#273
post #178

Question: Would Apple report CSAM matches worldwide to one specific US NGO? That's a bit weird, but ok. Presumably they know which national government agencies to contact. Opinion: If Apple can make it so that a) the list of CSAM hashes is globally the same, independent of the region (ideally verifiably so!), and b) all the reports go only to that specific US NGO (which presumably doesn't care about pictures of Winni…

NCMEC is not exactly a normal NGO; it was opened with Reagan present and Congress frequently gives it funding. It also works with other government organizations on a frequent basis.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#274
post #109

Earlier quoted context omitted.

>The hashes are hard coded into each iOS release Do you have a source on that? Since it is illegal to share those hashes in any way or form. Even people working with photo forensic and big photo sharing sites cannot get access to them. I very much doubt Apple can incorporate them into the iOS release without breaking multiple laws. The hashes themselves can easily be reversed to (bad quality) pictures so having the h…

No, these hashes can’t be reversed to an image. They’re not CSAM and therefore not illegal. That blog is not very good, either from a tech standpoint or a legal one.

[deleted]

Re: The deceptive PR behind Apple’s “expanded protections for children”

#276

Earlier quoted context omitted.

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

How do new hashes get added to this database? How do we know that all the hashes are of CSAM? Who is validating it and is there an audit trail? Or can bad actors inject their own hashes into the database and make innocent people get reported as pedophiles?

There is a manual review step by Apple.

You have to first get a “significant” number of photos flagged, then they have to pass Apple’s manual review (ie looking at photo thumbnails), and only then does Apple report the account.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#277
post #270

This whole mess brought back a memory of when I was 4 to 5 years old (so probably 1971). During a summer vacation we were walking at a harbor in Tuscany with my parents and they told me suddenly I had to take a dump. Problem was that there was no bathroom nearby, well it probably was since the place was filled with restaurants, but we were like a hundred meters from the nearest one, which was incompatible with the su…

There will only be an alert if that photo is extremely similar to an image in the NCMEC database, AND there are numerous other such photos on the account that match. The threshold number of matches to trigger an alert is tuned for a 1/trillion chance of false positive. Furthermore, if you were using say Google Photos to store your images, then you were already subject to this vulnerability.

[deleted]

Re: The deceptive PR behind Apple’s “expanded protections for children”

#278

Earlier quoted context omitted.

This is all behind a huge, neon-flashing-lights asterisk of "for now." How long until they try to machine-learn based on that database? The door's open.

Apple previously stored photo backups in their cloud in cleartext. The door was always open. At some point if you are providing your personal images for Apple to store, you have to exercise a modicum of trust in the company. If you don't trust Apple, I suggest you don't use an iPhone.

I don’t even use iCloud but what you suggest is exactly what I’m going to do.

I no longer trust Apple, and I’m going to get rid of my iPhone.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#279
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

Explain to me how photos get into the NCMEC database to begin with

Re: The deceptive PR behind Apple’s “expanded protections for children”

#280
post #193
post #157

Earlier quoted context omitted.

And in the process hand over more user data to tyrants. Surely they know this will be abused to check user data before it is uploaded to iCloud. All it takes is a willing government.

How is that different from how things work now?

Before, Apple would only scan data already in the cloud.

Now the pandora box has been opened. They are adding capability to scan files on iPhones before it hits the cloud.

Any technical or financial excuse they might have used in the past to not scan files locally is now rendered null.

Governments can just say: "you know what? scan these arbitrary sets of hashes as well, they are illegal in my jurisdiction and since you've shown that you can, scan them regardless if the user is sending to iCloud or not."

Post reply on HN