Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

281–290 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#281

Its a terrible move for their business, I am already looking for an alternative.

Nice, what have you found so far? I just started a Nextcloud today, 2GB free from most providers listed here: http://nextcloud.com

Re: Apple's child protection features spark concern within its own ranks: sources

#282

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

[deleted]

Re: Apple's child protection features spark concern within its own ranks: sources

#283
post #269

Earlier quoted context omitted.

This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…

> But with Apple's CSAM proposal is NOT possible to have an iPhone that Apple isn't continuously scanning. As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone.

Woops, you're right, thanks for the correction.

I think the issue is that, as Ben Thompson pointed out, the only thing preventing them from scanning other stuff now is just policy, not capability, and now that Pandora's box is open it's going to be much more difficult to resist when a government comes to them and says "we want you to scan messages for subversive content".

Re: Apple's child protection features spark concern within its own ranks: sources

#284

Personally I don't see on device scanning as significantly different than cloud scanning. I think the widespread acceptance of scanning personal data stored on the cloud is a serious mistake. Cloud storage services are acting as agents of the user and so should not be doing any scanning or interpreting of data not explicitly for providing the service to the end user. Scanning/interpreting should only happen when data…

Would you like to have a landlord coming to your flat as they please to look for drugs? It's the same thing. They make you a suspect by default.

Heck, this is worse.

More like do you want the bank coming into your house to look for drugs because you have your loan with them.

Re: Apple's child protection features spark concern within its own ranks: sources

#285

Earlier quoted context omitted.

>Messaging someone will also reveal yourself as the sender Sending a link to 4chan /b would probably be enough. Or a hidden iFrame in a forum post. Its very very easy to get images onto someones device without their consent, getting them to upload them to a 3rd party is completely different.

Currently it would not catch that 4chan thing as they only scan things that are uploaded to icloud photos. So you'd have to click on it and save to photos. This is the current implementation. I would guess that once they have their hooks in though all files with an image extension/header will be scanned and reported.

Send it via WhatsApp where it gets added to photos and later iCloud by default if I recall correctly

Re: Apple's child protection features spark concern within its own ranks: sources

#286
post #269

Earlier quoted context omitted.

This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…

> But with Apple's CSAM proposal is NOT possible to have an iPhone that Apple isn't continuously scanning. As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone.

>As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone.

Except for the "oops, due to an unexpected bug in our code, every image, document, and message on your device was being continuously scanned" mea culpa we will see a few months after this goes live.

Re: Apple's child protection features spark concern within its own ranks: sources

#287
post #269

Earlier quoted context omitted.

This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…

> But with Apple's CSAM proposal is NOT possible to have an iPhone that Apple isn't continuously scanning. As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone.

That’s wrong. They are also enabling on-device detection for Messages.

Re: Apple's child protection features spark concern within its own ranks: sources

#288
post #273

Earlier quoted context omitted.

Because if (willBeUploaded) { scanPhoto(); } can become if (true) { scanPhoto(); } Obviously, this is stupidly oversimplified, I have no idea how Apple has structured their code. But the fact of the matter is, if the scanning routine is already on the phone, and the photos are on the phone, all anyone has to do is change which photos get scanned by the routine...

By the way they already scan photos that aren’t uploaded to iCloud. I’ve never used iCloud and I can go on the photos app and search for food for example

Right, the difference is that now, you can be reported to the authorities for a photo that the CSAM algorithm mistook for child pornography, whereas before the image classifying was purely for your own use.

Re: Apple's child protection features spark concern within its own ranks: sources

#290

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

If I were to speculate, I’ve seen lots of references as to how Apple reports way less of this to the appropriate authority than the rest of their competition. It does kinda sound to me like this is the consequence of external pressure. I cannot prove this but speculate, of course.

I just don’t think the messaging they had around this is reassuring at all. While they had all sorts of technical explanations as to how trustworthy this will all be because they are in charge, the whole thing quickly went from “this is only for iCloud photos” and only in the US to “3rd party integration can happen” and “we’re expanding it to other countries”. Which I guess is a logical next step but it is a hint at expansion.

The walled garden becomes much less tempting after all of this, especially right after a scandal like the Pegasus one.

Post reply on HN