Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

281–290 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#281

There is a great deal of misinformation and confusion on this topic. Here is a good interview with Apple's head of Privacy. https://techcrunch.com/2021/08/10/interview-apples-head-of-p...

What part exactly do you think people are confused about?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#282
post #109

Earlier quoted context omitted.

>The hashes are hard coded into each iOS release Do you have a source on that? Since it is illegal to share those hashes in any way or form. Even people working with photo forensic and big photo sharing sites cannot get access to them. I very much doubt Apple can incorporate them into the iOS release without breaking multiple laws. The hashes themselves can easily be reversed to (bad quality) pictures so having the h…

No, these hashes can’t be reversed to an image. They’re not CSAM and therefore not illegal. That blog is not very good, either from a tech standpoint or a legal one.

They are perceptual hashes of CSAM images no? Sure, just because they are perceptual hashes, doesn't mean they can be reversed to an image, but it seems to be true PhotoDNA, a similar perceptual hashing algorithm, can be reversed to an image. For this reason, I believe it is possible Apple's perceptual hashes can be reversed as well, though, maybe they did it in a different way and it's not possible

Re: The deceptive PR behind Apple’s “expanded protections for children”

#283

Earlier quoted context omitted.

How do new hashes get added to this database? How do we know that all the hashes are of CSAM? Who is validating it and is there an audit trail? Or can bad actors inject their own hashes into the database and make innocent people get reported as pedophiles?

Apple has stated point-blank that the only source of CSAM content to generate the hash list will be NCMEC and other child safety organizations. While I fully admit that NCMEC could do a better job with transparency and auditing, they are currently being used by several other platforms right now (Facebook, Google, Microsoft) without issue. Could bad actors inject hashes of non-CSAM content into the database somehow? W…

Wait a second.

You’re telling me that you believe a low-wage worker reviewing the worst of the worst human depravity, is going to stand up on a soap box and defend another nameless and faceless denizen of the Earth, when the crux of the argument is basically this:

“Yeah I know the person tripped the safety threshold for CSAM, but these images aren’t that bad!”

It’s not reasonable to trust the human reviewer. They put themselves at risk by going against the automated system. I’d bet 95% of people in this circumstance would pass the buck to the FBI to make their determination, at which point “your” life is already ruined.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#284

Earlier quoted context omitted.

Frankly the distinction seems arbitrary to me. This is a policy issue in both cases - policy can change (for the worse) in both cases. The comparison is about unencrypted photos in iCloud or this other method that reveals less user information by running some parts of it client side (only if iCloud photos are enabled) and could allow for e2e encryption on the server. The argument of "but they could change it to be wo…

They've given you two options: 1. Encrypt everything in the cloud but upload the hashes of these items as well on the device. Also notify us so we can notify law enforcement if they're doing some illegal stuff. 2. Everything is unencrypted in the cloud. No actions are taken on the device. No notifications to authorities. With option one the sanctity of the device ownership is breached. With option two it's maintained…

For #2 actions are taken in the cloud, authorities are contacted, and all of the photos are unencrypted.

Option #1 doesn’t really breach the ‘sanctity of device ownership’ because it only occurs if you’ve enabled iCloud photos on the device.

Option #1 seems better to me in its current implementation. I understand the fear of abusing the hash matching. I just think that’s a separate thing.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#285

Earlier quoted context omitted.

Even HN reporting / article linking / comments have been surprisingly low quality and seem to fulminate and declaim with surprisingly little interesting conversation and tons of super big assertions. Linked articles and comments have said apple's brand is now destroyed, that apple is committing child porn felonies somehow with this (the logical jumps and twisting to get to these claims are very far from strong plausi…

From https://www.hackerfactor.com/blog/index.php?/archives/929-On... > The laws related to CSAM are very explicit. 18 U.S. Code § 2252 states that knowingly transferring CSAM material is a felony. (The only exception, in 2258A, is when it is reported to NCMEC.) In this case, Apple has a very strong reason to believe they are transferring CSAM material, and they are sending it to Apple -- not NCMEC. > It does not matt…

It’s good to know that if I use the “section” glyph in an otherwise completely false analysis born of extending my experience past where I’m competent, readers will quickly repeat whatever it is I said as factual and “quite irrefutable”. The power of one blog post is quite something. You’re the third person I’ve seen quote that very post and go “welp, sure is a smoking gun” despite it being completely, utterly, demonstrably false. It’s make believe. That entire blog post is so incorrect that it’s barely useful as toilet paper, friend.

If the author were correct Facebook and others would have been charged with felonies already. Verification happens in good faith and requires transmission despite the exact letter of the law. The people doing it regularly talk to NCMEC. There are evidentiary and chain of custody procedures to follow that also transmit the material. Guess we should charge computers with felonies!

It’s also fucking hysterical that the armchairs who didn’t know what CSAM stood for a week ago think that one of the most litigiously sensitive systems ever built by a corporation somehow missed criminal legal liability. You know, it’s pretty easy to overlook criminal liability when you’re building a system that is used to establish criminal liability. Totally passes the smell test. Irrefutable indeed.

You guys are off your rockers and should move on to another topic. Seriously. Every day this is discussed is another harsh reminder of (a) how few fucks the industry gives about abuse of children and (b) how everyone here digests blogs and considers themselves authoritative on horrors they’ve never once experienced. Every day this is argued on HN, particularly last night when someone said the privacy situation is “the actual abuse” and “much worse” than the rape of children, is another day I’m ashamed to have chosen this profession and work alongside you. This community welcomes the people who have built surveillance systems for every consumer activity imaginable and kids getting molested is where you draw the privacy line, huh? Can’t look for that? I’m genuinely out. Keep your industry. I’d rather manage a Taco Bell if this is the perspective of this industry, because brother, I’ve seen what they’re trying to tackle and I’m still in therapy.

There is a hypocrisy at the core of the “privacy” argument here that is fundamentally indicting not only this community, but everyone discussing this up to and including EFF. I’ve never been so disappointed in people who I used to look up to and think of as good, smart folks.

Source: I’ve built CSAM handling systems for a FAANG and written the policy for using it. The author has misinterpreted the very law he cites and overlooked two subparagraphs. But that isn’t what you want to hear.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#286

Earlier quoted context omitted.

Apple is attaching a ticket to images as the user uploads to iCloud. If enough of these tickets think CSAM and allow an unlock key to be built, they will unlock and get checked. It's still the user who has turned on iCloud and uploaded the images.

Correct. The one odd thing I don't get. It would be a lot EASIER to just scan everything when its in the cloud itself. Why go to this trouble to avoid looking at users photos in the cloud, set these thresholds etc. You'd only need to scan on device if for some reason you blocked your own ability to scan in cloud (ie, for E2E photos - which I don't think users actually want).

Something like all of iCloud getting E2EE would be a big feature and likely only be announced at an event. I agree, if the CSAM on device scanning isn’t followed on by something else, it seems like a lot of work and PR flak for little gain.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#287

Earlier quoted context omitted.

Wait are you saying you get ads based on things you converse about out loud in the real world because your phone is listening to everything in your pocket? You know that is a myth and isn't true, right?

You saying one conspiracy is 100% true but another one is laugh out loud impossible?

Wait, what conspiracy am I saying is 100% true?

If your phone was listening to everything you do all the time then you'd need a lot of processing to analyze it on-device and exfiltrate the critical pieces of info (which would be pretty obvious when looking at CPU usage and battery life), or you'd be sending an insane amount of data off over the internet all the time.

I'm not saying it's technically impossible - I'm just saying that the ol "Facebook is listening to everything and that's why you get ads for something after you talk about it in real life" is almost certainly a myth with zero actual data to support it other than some anecdotes online.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#288

Earlier quoted context omitted.

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

Who looks at the photos in that database? How do we know it is a trustworthy source? That it doesn’t contain photos of let’s say activists or other people of interest unrelated to its projected use?

How do we know that the people who look at the photos are not child molesters, pedophiles, psychopaths themselves?

--

Seriously. The people who worked in the abuse department at facebook when I was there were an odd group of people with whom I would not trust my kids to be around unattended.

Zuck had some weird fucking bodyguards as well...

---

Cool - I'll expect that child abusers are downvoting this.

When did you stop abusing your kids?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#289

Earlier quoted context omitted.

How do new hashes get added to this database? How do we know that all the hashes are of CSAM? Who is validating it and is there an audit trail? Or can bad actors inject their own hashes into the database and make innocent people get reported as pedophiles?

Apple has stated point-blank that the only source of CSAM content to generate the hash list will be NCMEC and other child safety organizations. While I fully admit that NCMEC could do a better job with transparency and auditing, they are currently being used by several other platforms right now (Facebook, Google, Microsoft) without issue. Could bad actors inject hashes of non-CSAM content into the database somehow? W…

You are incredibly naive.

Apple started out saying that they can't decrypt data from anyone's phone. They fought a lawsuit from the FBI over the San Bernadino terrorist phones. This is one of the reasons why I went all-in on Apple, because they were willing to fight the government over our privacy.

Now, years later, they don't encrypt iCloud backups because the FBI told them not to.

Google used to human review all copyright violations on Youtube. Fast forward a few years later, and all copyright violations are demonstrably shown to be approved and the content generator needs to prove that they didn't violate copyright. Look at the violations over white noice. Google doesn't even care anymore, they just let the copyright violations go through and affect the content creators with no review.

To believe that Apple employees will review CSAM-flagged photos 5 years from now is so incredibly naive, it's actually funny. You can bet they are working on AI that will handle this for them right now in Cupertino.

And then, it will be random chance whether or not we are flagged and labelled as pedophiles, or if a government wants to tag us as "problematic" and wants access to our phones because we are journalists and they want to see our anonymous sources.

It's naive to think that it won't go in this direction.

If you're a pedophile, after this announcement you will delete all the photos off your iPhone and never use it again. After the first few rounds of arrests and cleansing, it will be well knowing within the pedophile community not to use iPhones. And then the only ones who will be getting their photos scanned will be innocent people. So the entire feature doesn't make sense at all. It's a ruse.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#290
post #109
post #47

Earlier quoted context omitted.

In this TechCrunch interview, Apple believes it is less invasive since no one can be individually targeted. The hashes are hard coded into each iOS release which is the same for all iOS devices. The database is not vulnerable to server side changes. Additionally, FWIW, they do not want to start analyzing entire iCloud photo libraries so this system only analyzes new uploads. https://techcrunch.com/2021/08/10/intervie…

>The hashes are hard coded into each iOS release Do you have a source on that? Since it is illegal to share those hashes in any way or form. Even people working with photo forensic and big photo sharing sites cannot get access to them. I very much doubt Apple can incorporate them into the iOS release without breaking multiple laws. The hashes themselves can easily be reversed to (bad quality) pictures so having the h…

I think you're forgetting that Apple isn't using PhotoDNA. Just because PhotoDNA hashes can be reversed into images, doesn't mean Apple's perceptual hashes can be reversed into images. I think there's a good chance they can be though.
Post reply on HN