Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

291–300 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#291
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

> 1. Vote with your feet - Put your money in the pockets of the people aligned to your values. The sad reality right now is that we're actively suggesting that peoples stop buying smart phones, and I think that would mean that any argument will fall on deaf ears. Yes, projects like the PinePhone exists, but they aren't ready for the general public. As much as I agree with your comment, the sad reality is that I have…

That's not the only choice at all.

Pixel phones + GrapheneOS/CalyxOS. Various phones + LineageOS. Various devices + SailfishOS. Librem 5. PinePhone. Fairphone. /e/. F(x)Tec Pro1.

You're greatly underestimating the ability of people to adapt when suggiciently motivated, especially when so many devices can be bought fully set up and most people use only a few apps anyway.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#292
post #60
post #50

Related but slightly off-topic: am I the only one that thinks more technology is not the answer to catching crooks? Can’t the police do good old fashioned police work to catch people doing these things? Why does EVERYONE need to be surveilled for the 0.01% (or less?) who don’t behave properly. To further this point: why do we need cameras on every street, facial recognition systems and 3-letter orgs storing huge data…

>One thought: is it because over 10, 20, 30+ years the police have been de-funded everywhere Police funding has shot up in America. It's everything else thats been cut. >what’s the problem. There's no problem. It's just a drawn out power grab with a weak pretext.

>There's no problem. It's just a drawn out power grab with a weak pretext.

In 2018 tech companies reported over 45 million images of CSAM, which was double the amount that was reported the year before.[0] The next year the number of reports went up to 60 million.[1] I wouldn't expect everyone to agree on the proper response to the rapid growth of child-abuse imagery online, but I don't think the problem itself should be dismissed.

[0] https://www.nytimes.com/interactive/2019/09/28/us/child-sex-... or https://web.archive.org/web/https://www.nytimes.com/interact...

[1] https://www.nytimes.com/2020/02/19/podcasts/the-daily/child-...

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#293
post #249

Earlier quoted context omitted.

The empowerment at the time was a honest and professional assessment of using MacOS X vs Windows. Apple embraced PC vs Mac marketing as I can remember. The empowerment today is the same professional stance. Explaining the technical facts to my customers. Nobody will like the idea that their phone or personal computer will actively police on the behalf of big brother. Serious business people don't have to "follow" tec…

Your professionalism is admirable. In this context, perhaps that's all it counts for.

Thanks. Smart one. :)

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#294
post #269

Notice, for example, that Thunderbird is sending file names and SHA-256 hashes when you open most (e.g. .pdf) attachments, in the clear, to Google. This seems worse to me (in the Apple case, the information is revealed only if enough files from one device match against a predefined hash list) and nobody really cares... I have just tested with a fresh profile with a freshly downloaded thunderbird-78.12.0.tar.bz2 (x64…

I suspect that if they were strictly bitstream hashes and not perceptual hashes, people would be less concerned.

No, i'm sure people would still make a fuss. Perceptual hashes are required to prevent criminals from slightly changing pixels within CSAM photos to avoid detection.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#295

Earlier quoted context omitted.

I apologise if you you genuinely felt my questions were assuming bad faith. It was not my intention. > "does the CP protection end justify any means?" It's a style of argumentation. Not personal. When trying to find where to draw a line in the sand, one way is to draw a line that almost certainly encompasses us both. We are obliged to consider: if not this line (obviously) then what line? My intent was to find your l…

How are you expecting me to describe this limit? I think it's legitimate for companies to implement automated systems, such as CSAM and spam filtering, to limit the amount of unwanted material on their networks. I don't have any problem with Apple, Google, and Microsoft, checking the hashes of files I upload (or attempt to upload, in Apple's case) to their servers against ICSE. I would have an issue if employees of t…

It's probably timing that is limiting your responses. AFAIK downvotes won't do that. And I didn't down-vote you.

I accept your answer, and acknowledge that different perspectives are valuable.

My own opinion is far less relevant as I probably will not be implementing or executing systems that target information from large swathes of a population for inspection by my organisation.

Nevertheless, let me give it a shot. I asked you about the social cost of false-positives. You reciprocated by asking me about false-negatives. It's tough - on both sides of the equation.

I try to apply weighting. If the dragnet would be targeted to a limited number (say 100) then it could easily be justified, since the relative horror of one over the other is surely in that ball park. Maybe even 1,000.

The problem for me is that mass surveillance such as the subject of this discussion is not numerically constrained. It's trawling the entire ocean floor for the one or two species that may be legally caught.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#296
post #50

Related but slightly off-topic: am I the only one that thinks more technology is not the answer to catching crooks? Can’t the police do good old fashioned police work to catch people doing these things? Why does EVERYONE need to be surveilled for the 0.01% (or less?) who don’t behave properly. To further this point: why do we need cameras on every street, facial recognition systems and 3-letter orgs storing huge data…

We hire, and train, terrible cops in America. They are basically Reveune Collectors. I would like to see all cops under federal jurisdiction. Let the FBI train them. I know in my county of Marin we have way to many just looking for any slight moving violation. I have felt for awhile that we also need complete bans in certain kinds of tech. With the exception of always on cop cameras.

Exactly, there's a reason the FBI takes over real criminal cases when they occur - the police are just there to settle petty, inconsequential local disputes.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#297
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

> a non-insignificant amount of people in tech take this seriously We're all here to make ourselves feel good saying we Took A Stand. In reality, four weeks from now, do you think anybody will still be talking about it? I made this same mistake. I was pretty convinced that people were taking Copilot seriously, and that there was possibly going to be ramifications for Microsoft. I wasn't particularly looking forward t…

I can't have a phone or a computer that snoops on me to this degree. So for me I definitely won't change or forget in a week. Unless they solve it, there's no more Mac or iPhone for me.

(This may actually be a Good Thing)

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#298
post #148

Earlier quoted context omitted.

> I am currently planning the migration away from the Apple ecosystem Me too. I told my wife today that I'll be looking at a feature phone as I'm not sure I can be bothered with jumping through all the hoops required to de-Google an Android phone. I remember a time before mobile phones, I was just fine without one - smartphones aren't that good, just convenient.

Are you in North America? Which feature phone would you suggest? The Nokia 3310 was likely the only phone I was considering, but it’s ancient and 3G and doesn’t seem very future proof.

The Nokia 3310 does not support 3G. It’s a 2G (GSM or TDMA) device.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#299
post #144

Apple is forgetting the network effect of professionals that made them billionaires. I personally evangelized my clients in the past for years to switch to Apple ecosystem. In my view this is weaponization of personal devices on a mass scale with clear intent of normalization of surveillance state on a global level. The fact that this comes after NSO spyware investigation speaks volumes. They don't care about privacy…

As a fellow professional, I think this is kind of nonsense.

Apple (and all these companies) also operate in a world with a populace that WANTS surveillance for these areas, does not agree that it is a slippery slope, and has voted in governments where that eventually will force Apple to install an even worse back door.

The Linux and FOSS movement have never been up to the end user device challenge, and they too operate in a world with a populace that WANTS surveillance for this stuff.

The solution to true privacy is never going to be “switch to FOSS” for most users, as that’s sort of like saying “get a degree in math”. It will work for some, but it will be an unstable experience.

The solution has to be to a) ensuring democracy survives and b) convincing most people that the right to privacy is more important than finding child pornographers, and c) to vote for representatives that will uphold that right.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#300
post #269

Notice, for example, that Thunderbird is sending file names and SHA-256 hashes when you open most (e.g. .pdf) attachments, in the clear, to Google. This seems worse to me (in the Apple case, the information is revealed only if enough files from one device match against a predefined hash list) and nobody really cares... I have just tested with a fresh profile with a freshly downloaded thunderbird-78.12.0.tar.bz2 (x64…

Do you produce most email attachment in your inbox yourself? Do you produce most photos on your iCloud yourself? The point is anti-virus (purposed) hash upload is different from your private iCloud content hash upload.
Post reply on HN