Live data from Hacker News

One Bad Apple

hackerfactor.com

31–40 of 557 posts

Re: One Bad Apple

#31
post #9
post #5

Earlier quoted context omitted.

What does "manual review" mean then and how are those images reported?

Before: you would upload images to iCloud Photos. Apple can access your images in iCloud Photos, but it does not. Now: You upload images to iCloud Photos. When doing so, your device also uploads a separate safety voucher for the image. If there are enough vouchers for CSAM matched images in your library, Apple gains the ability to access the data in the vouchers for images matching CSAM. One of the data elements in t…

Not sure your before is entirely correct. Apple has admitted to scanning iCloud photos, so they are already accessing them at some point.

https://digit.fyi/apple-admits-scanning-photos-uploaded-to-i...

Re: One Bad Apple

#32

Good article, however- "Due to how Apple handles cryptography (for your privacy), it is very hard (if not impossible) for them to access content in your iCloud account. Your content is encrypted in their cloud, and they don't have access. If Apple wants to crack down on CSAM, then they have to do it on your Apple device" I do not believe this is true. Maybe one day it will be true and Apple is planning for it, but ri…

They want to move to e2e for photos so they don't have to keep those keys. That's what this is part of — a way to prevent their service from being used for CSAM, yet still provide e2e encryption. I feel very ambivalent about this.

Re: One Bad Apple

#33
post #31
post #9

Earlier quoted context omitted.

Before: you would upload images to iCloud Photos. Apple can access your images in iCloud Photos, but it does not. Now: You upload images to iCloud Photos. When doing so, your device also uploads a separate safety voucher for the image. If there are enough vouchers for CSAM matched images in your library, Apple gains the ability to access the data in the vouchers for images matching CSAM. One of the data elements in t…

Not sure your before is entirely correct. Apple has admitted to scanning iCloud photos, so they are already accessing them at some point. https://digit.fyi/apple-admits-scanning-photos-uploaded-to-i...

The before is entirely correct. Only iCloud Mail was previously scanned for CSAM. As a sanity check: it's not plausible that Apple only generated O(100) referrals to CyberTip annually if it were scanning all iCloud Photos. Other services of similar scale generate O(1M) referrals.

Re: One Bad Apple

#34
post #12

> 18 U.S.C. § 2258A is specific: the data can only be sent to NCMEC. (With 2258A, it is illegal for a service provider to turn over CP photos to the police or the FBI; you can only send it to NCMEC. Then NCMEC will contact the police or FBI.) What Apple has detailed is the intentional distribution (to Apple), collection (at Apple), and access (viewing at Apple) of material that they strongly have reason to believe is…

This is the part that also caught my eye.

Surely Apple's lawyers have also reviewed the same law, and if it's that clearly defined, how did they justify/explain their approach?

Re: One Bad Apple

#35
This feels like missing the forest from the trees — Steve Jobs said many times to the effect ‘it doesn’t matter how any of this stuff happens, GigaHertz, Ram, Speeds, it only matters that the user gets what they want.’

Right now Apple’s biggest unhappy user is the DOJ. As it stands with the legislation coming down the pipe and both previous administrations building on a keenness to ‘get something done’ about big tech, Apple will do as they’ve done in China and ‘obey the laws in each jurisdiction.’

Right now there are a lot of unwritten laws that say Apple better play right or lose quite a bit more —

So, how it’s getting done is a side show.

That said, it wasn’t long ago that they stood toe to toe with the FBI —- but there also weren’t wonderfully strong ‘sanctions’ on the horizon.

Re: One Bad Apple

#36

> However, nothing in the iCloud terms of service grants Apple access to your pictures for use in research projects, such as developing a CSAM scanner. (Apple can deploy new beta features, but Apple cannot arbitrarily use your data.) In effect, they don't have access to your content for testing their CSAM system. > If Apple wants to crack down on CSAM, then they have to do it on your Apple device. I don’t understand……

> Apple can’t change their TOS

Why not... has anyone actually successfully sued a company for changing their ToS from under them?

Re: One Bad Apple

#37
> Apple then manually reviews each report to confirm there is a match,

This is always the terrifying part for me. They will access your personal photos or data without telling you. I’m surprised how is that even legal given all the law that are already available. Are they immune to those laws stated in thd blog?

Also what happens when they launch this in EU, AU, etc with different privacy laws?

Re: One Bad Apple

#38

> However, nothing in the iCloud terms of service grants Apple access to your pictures for use in research projects, such as developing a CSAM scanner. (Apple can deploy new beta features, but Apple cannot arbitrarily use your data.) In effect, they don't have access to your content for testing their CSAM system. > If Apple wants to crack down on CSAM, then they have to do it on your Apple device. I don’t understand……

> Apple can’t change their TOS Why not... has anyone actually successfully sued a company for changing their ToS from under them?

That’s what I don’t understand about that paragraph.

Re: One Bad Apple

#39
Somewhat tangential, but people like this author amaze me in their deep knowledge AND ability to communicate it well.

Also, none of this topic is something I would want to deal with.

Post reply on HN