Live data from Hacker News

One Bad Apple

hackerfactor.com

281–290 of 557 posts

Re: One Bad Apple

#281
post #231
post #225

Earlier quoted context omitted.

You're assuming that perceptual hashes are uniformly distributed, but that's not the case. If I post a picture of my kid at the beach I'm far, far more likely to generate perceptual hashes closer to the threshold. Not to mention intimate photos of/with my partner.

yep. what if i take a burst of 12 photos that all incorrectly fall as a false positive to NeuralHash (which is a ML black box), and an Apple reviewer is now invading my privacy by looking at my photo library?

The the technical paper Apple put out that is linked to in the post talks about the risk, but isn’t very helpful

“Several solutions to this were considered, but ultimately, this issue is addressed by a mechanism outside of the cryptographic protocol.”

Re: One Bad Apple

#282
post #224

Earlier quoted context omitted.

You can’t seriously be suffering that Apple not implementing these measures will somehow be good for privacy in China?

The implication -- and I think it's a valid one -- is that this client-side mechanism will be very quickly co-opted to also alert on non-CSAM material. For example, Winnie the Pooh memes in China.

I think it’s not valid to claim that it will be quickly used for that purpose.

However I absolutely agree that it could be used to detect non-CSAM images if Apple colludes with that use case.

My point is that this is immaterial to what is going on in China. China is already an authoritarian surveillance state. Even without this, the state has access to the iCloud photo servers in China, so who knows what they are doing, with or without Apple’s cooperation.

Re: One Bad Apple

#283
post #61
post #18

There are a lot of articles about Apples hadh algorithm and for me they are mostly irrelevant to the main problem. The main problem is that Apple has backdoored my device. More types of bad images or other files will be scanned since now apple does not have plausible deniablity to defend any of ghe government’x requests. In the future a false? positive that happened? to be of a political file that crept in the list c…

They could have done all that without telling you. And as long as the traffic was combined with normal traffic no one would ever notice (and in this case it would end up mixed with normal traffic since it only applies to images being uploaded to iCloud, so communication with Apples servers would be expected). What it looks like to me is that Apple is planning on releasing end-to-end encryption for iCloud. But they kn…

If this is a prelude to E2E encryption for iCloud they are going to be under TREMENDOUS pressure from law enforcement to expand the list of bad material way beyond just CSAM.

Re: One Bad Apple

#284

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

Not that I particularly care one way or the other, but doesn’t writing a ‘whitepaper’ (or calling your notes such) indicate an intention to release it?

Re: One Bad Apple

#285

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

>Why haven't I made my whitepaper about PhotoDNA public? In my view, who would it help? It would help bad guys avoid detection and it will help malcontents manufacture false-positives.

I would suggest that the people NCMEC are most enthusiastic to catch know better than to post CSAM in places using PhotoDNA, particularly in a manner that may implicate them. Perhaps I overestimate them.

Re: One Bad Apple

#286
post #12

> 18 U.S.C. § 2258A is specific: the data can only be sent to NCMEC. (With 2258A, it is illegal for a service provider to turn over CP photos to the police or the FBI; you can only send it to NCMEC. Then NCMEC will contact the police or FBI.) What Apple has detailed is the intentional distribution (to Apple), collection (at Apple), and access (viewing at Apple) of material that they strongly have reason to believe is…

[deleted]

Re: One Bad Apple

#287

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

Isn’t that an alleged memo from the NCMEC? I would sincerely doubt an official memo from any agency would use the term “shrieking minority”, it sounds like imaginative fiction of what a government agency would actually say.

9to5Mac published the full message that NCMEC sent to Apple:

https://9to5mac.com/2021/08/06/apple-internal-memo-icloud-ph...

It does say "We know that the days to come will be filled with the screeching voices of the minority."

Re: One Bad Apple

#288
post #280
post #277

Earlier quoted context omitted.

Literally Apple could just add a different set to the set of hashes they push? That seems very naive.

What seems naive? Adding hashes will only match images, not other files, and even then only if a group is matched, not just one.

Because people take and store images of huge numbers of different things? Like the things mentioned upthread, memes, documents? along with screenshots of a huge number of other things.

And the details around matching (and groups, etc) are trivial to change in a later update.

Re: One Bad Apple

#289

I don't see many people pushing back on the child pornography laws themselves that are the cause of this. I'm stepping into a hornets nest by even bringing this up, because any criticism of the laws on the books makes one look they're a pedo, so I'll preface by saying, child pornography (filmed with actual kids) is vile and disgusting, but it is the production of it that is evil to be fought and suppressed, not the p…

The reason possession is illegal is to try to prevent further production of it and to eliminate continuing abuse to children. The theory is that allowing even mere possession perpetuates a market of “buyers” that would further stimulate production. This is well covered in the Congressional findings associated with 18 U.S.C. 2251. See e.g. https://www.law.cornell.edu/uscode/text/18/2251 (click the notes tab).

Re: One Bad Apple

#290

Earlier quoted context omitted.

Yes, see Douglas v. Talk America.

Thanks for the link. ... but I'm not sure that would apply here, especially if Apple has a pop-up that the user dismissed a long time ago.

It’s unclear what the legal limits are, but I’ve seen some sites do a bold print summary of the changes. Certainly if one wants to be sure their TOS change is enforceable they’ll make sure a judge and jury will agree the changes were prominently advertised.
Post reply on HN