Live data from Hacker News

Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

wired.com

281–290 of 336 posts

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#281

Earlier quoted context omitted.

Don't forget this part: >(e) Failure To Report.—A provider that knowingly and willfully fails to make a report required under subsection (a)(1) shall be fined— (1) in the case of an initial knowing and willful failure to make a report, not more than $150,000; and (2) in the case of any second or subsequent knowing and willful failure to make a report, not more than $300,000. I find these clauses at odds with one anot…

> I find these clauses at odds with one another in that the Failure to Report clause created a tangible duty upon the provider, which, were I a judge, would satisfy me that the provider was, in fact, deputized. Absolutely not. That section requires a report under the circumstances where a provider has obtained “actual knowledge of facts and circumstances” of an “apparent violation” of various code sections (child por…

Except it does make you a state actor, and even children know it, as even the 9-11 year old demographic has literally disclosed to me, the "crazy uncle" in their life, that they are not comfortable being open with any type of guidance counselor or state licensed therapist due to knowledge of just such a dynamic.

A spade, is a spade by any other name. If the state will come down on you for not doing something (message generation), you are a deputy of the State. Period.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#282
post #52
post #16

I’m not sure I understand Apple’s logic here. Are iCloud Photos in their data centers not scanned? Isn’t everything by default for iCloud users sent there automatically to begin with? Doesn’t the same logic around slippery slope also apply to cloud scans? This is not to say they should scan locally, but my understanding of CSAM was that it would only be scanned on its way to the cloud anyways, so users who didn’t use…

> I’m not sure I understand apples logic here. Are iCloud Photos in their data centers not scanned? Isn’t everything by default for iCloud users sent there automatically to begin with? Doesn’t the same logic around slippery slope also apply to cloud scans? I don’t see the problem with this status quo. There is a clear demarcation between my device and their server. Each serving the interests of their owner. If I have…

Precisely! The software running on the phone should be representing the owner of the phone, period. We begrudgingly accept cloud scanning because that ship has already sailed, despite it being a violation of the analog of fiduciary duty. But setting the precedent that software on a user's device should be running actions that betray the user is from the same authoritarian vein as remote attestation. The option ignored by the "isn't this a good tradeoff" question is one where the device encrypts files before uploading them to iCloud, iCloud may scan the encrypted bits anyway to do their legal duty, and that's the end of the story. This is what we'd expect to be happening if device owners' interests were being represented by the software on the device, and so we should demand no less despite the software being proprietary.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#283

Earlier quoted context omitted.

Don't forget this part: >(e) Failure To Report.—A provider that knowingly and willfully fails to make a report required under subsection (a)(1) shall be fined— (1) in the case of an initial knowing and willful failure to make a report, not more than $150,000; and (2) in the case of any second or subsequent knowing and willful failure to make a report, not more than $300,000. I find these clauses at odds with one anot…

It’s because they wanted their cake and eat it too, get as close as possible to the 4th amendment without crossing the line. Put simply, if they have knowledge of it they have a duty to report, but they can’t be compelled to try and find out. In theory this means that if they happen to stumble upon it or are being alerted to it by a third party (e.g. user report) then they have to report it, in practice many voluntar…

I have no qualms with voluntary monitoring and reporting. However the inclusion of the penalty imposes a tangible duty. That tangible duty is enough to convince me this act is effectively a de facto deputization. The act of searching is, in essence "look out for, raise signal when found". This Act does everything it can to try to cast the process that happens after the search phase as "the search forbidden by the 4th Amendment" instead of the explicitly penalized activity, which is couched as "voluntary, and not State mandated despite a $150000 price tag assessed by... The State". Even going so far as creating a quasi-government entity, primarily funded by the State whose entire purpose is explocitly intended to act as a legal facade to create sufficient "abstract distance" through which the State can claim "it twas not I who did it, but a private organization, Constitional protections do not apply"

Words mean things, and we've gotten damned loose with it these days in my opinion when the want strikes. "Voluntary" anything with a $150000 fine for not doing it is no longer voluntary. It's now your job. If it's your job, and the State punishes you for not doing it, you are a deputy of the State. I do not care how many layers of legal fiction and indirection are between you and the State.

If you can't not comply without jeopardy, it ain't voluntary.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#284
post #264
post #23

> "Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit" > "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types." Yes, and it was patently obviou…

I want to be clear that I agree with you and I am not providing this explanation as an excuse for Apple, but merely as an explanation for what might have happened with the timeline: first they announced they were doing this, a bunch of us said "no this is the first step towards breaking e2e entirely", and THEN this year there was the high-profile issue--note that I am not saying it is a new issue, but merely that it…

being smartest person in the room is neutered by working in the dumbest room in the building.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#285

Earlier quoted context omitted.

This is what I was recalling, this method gives you a clever way to do it using the file itself as the key: > “Convergent encryption solves this problem in a very clever way: “The way to make sure that every unique user with the same file ends up with an encrypted version of that file that is also identical is to ensure they use the same key. However, you can’t share keys between users, because that defeats the entir…

This still suffers the same problems as the original proposal. Specifically, Apple could still be pressured or forced by governments to check for non-CSAM images. And using cryptographic hashing means they can’t detect altered files, while using perspective hashing leaves them open to false positives.

[deleted]

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#286
post #264
post #23

> "Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit" > "It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types." Yes, and it was patently obviou…

I want to be clear that I agree with you and I am not providing this explanation as an excuse for Apple, but merely as an explanation for what might have happened with the timeline: first they announced they were doing this, a bunch of us said "no this is the first step towards breaking e2e entirely", and THEN this year there was the high-profile issue--note that I am not saying it is a new issue, but merely that it…

> and THEN this year there was the high-profile issue with the laws in the UK and/or Australia or whatever that showed we were all correct

Do you have a link to that issue? I didn't heard about it (I'm from a third world country)

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#287
post #269

Earlier quoted context omitted.

Pointing out a few app vendors simply isn't impressive. Of course some app vendors can take a stand against mid-tier governments. It's great marketing for them, and the corporate risk isn't so high. It's the platform vendors which have much at stake. And of the three big platform vendors, two of them already scan private photos for CSAM right now — Google and Microsoft. Yet nobody is outraged because nobody actually…

Neither Google nor Microsoft operate a secure messaging platform that matters (email, yes, but email security is a lost cause), unlike WhatsApp (and Facebook Messenger), iMessage, Telegram or Signal. I'm not giving Google & Microsoft a pass, they're just irrelevant for the discussion at hand.

The CSAM scanning Apple abandoned, ie the topic at hand, was for the cloud, like the one operated by Google or Microsoft. You switched the topic to secure messaging platforms, which are irrelevant for the discussion at hand.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#288

Earlier quoted context omitted.

It would’ve been less likely, not impossible. Perceptive hashing absolutely has issues with false positives.

No, it would've been impossible. One photo match wouldn't have been enough to trigger any sort of response within Apple's system. And that's ignoring the fact that his photo wouldn't have matched anyway because it isn't in any CSAM database.

Apple’s proposal used perceptual hashing, which does have false positives, not cryptographic hashing, which does not.

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#289

Earlier quoted context omitted.

> There are also ways to detect matches even with e2ee By definition, encryption (with unique user keys) means you can't infer nor check what the content of the message is. Not without client cooperation, which is what this feature would have been.

This is what I was recalling, this method gives you a clever way to do it using the file itself as the key: > “Convergent encryption solves this problem in a very clever way: “The way to make sure that every unique user with the same file ends up with an encrypted version of that file that is also identical is to ensure they use the same key. However, you can’t share keys between users, because that defeats the entir…

That’s not what’s commonly understood to be a modern cipher. It would be trivial for a government to make a list of undesired messages/images and find everyone that has forwarded it.

https://en.wikipedia.org/wiki/Chosen-plaintext_attack

Re: Apple clarifies why it abandoned plan to detect CSAM in iCloud photos

#290

Earlier quoted context omitted.

This is what I was recalling, this method gives you a clever way to do it using the file itself as the key: > “Convergent encryption solves this problem in a very clever way: “The way to make sure that every unique user with the same file ends up with an encrypted version of that file that is also identical is to ensure they use the same key. However, you can’t share keys between users, because that defeats the entir…

Could one defeat this by changing a single byte in their file?

Bit, yes. Though on a moderately large file it would be easy to brute force all one-bit modifications, and then the effort grows exponentially (basically) in the number of bits flipped, so you’ll want to do more than a few.
Post reply on HN