Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

31–40 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#31
I simply don't trust services such as iCloud. The legal landscape is too volatile, and Apple's own "terms and conditions" are also subject to constant change. As far as I can tell, most people don't need cloud backups, and iCloud mostly shows up as an annoyance designed to extract more money from customers. In fact, most people probably don't know that Apple and Google vacuum up their files the moment they are created, for their own good, of course.

Re: Apple defeats liability for not scanning iCloud for CSAM

#32
post #26
post #7

The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections. As sad as this is, end to end encryption means no CSAM scanning. As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too. This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

I wonder if the judge would be in favor of companies proactively going into people's houses at random to check on their belongings, if they don't have inappropriate photos somewhere, or whatever. It's harder to do, but conceptually the same. So sad it's not being done. Very disturbing. They could do it when people are not at home. There'd no problem, nobody would even notice.

[flagged]

Re: Apple defeats liability for not scanning iCloud for CSAM

#33
post #14

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

> It is crazy people think apple isnt on the side of privacy. > It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do. I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare qu…

Is it different than telling your therapist something in confidence and then finding police waiting for you in the lobby.

Re: Apple defeats liability for not scanning iCloud for CSAM

#34

Earlier quoted context omitted.

> As sad as this is, end to end encryption means no CSAM scanning. I think it depends on your definition of e2ee and where the "end"s are. If the locally running application can decrypt the data, it could always do whatever it wanted. Is that really how you define e2ee?

The locally running application is one of the 'ends' of the end to end encryption.

Then in that case I think the previous statement of "end to end encryption means no CSAM scanning" would be false.

Re: Apple defeats liability for not scanning iCloud for CSAM

#35
post #14

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

> It is crazy people think apple isnt on the side of privacy. > It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do. I feel that Apple open pandora's box with the client-side scanning. It proved that it was technically feasible, and was "privacy preserving". I use scare qu…

> It proved that it was technically feasible, and was "privacy preserving".

Didn't their paper disproved by reversing the perceptual hashes to reveal blurred version of the images being hashed, and Apple basically said "that's fair, it's not as robust as we wanted, let's visit this later"?

If not, I'll happily stand corrected, but please share sources.

Addenda:

- Apple's original paper: https://web.archive.org/web/20210807165030/https://www.apple...

- Paper breaking the hash: https://arxiv.org/abs/2111.06628

Edit: The second one is the wrong paper. I’ll find and link the correct one tomorrow. Keeping the link for transparency.

Re: Apple defeats liability for not scanning iCloud for CSAM

#36

IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it. Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt…

This is based on a faulty understanding of the underlying systems. The risk with this sort of E2E encryption is not that the service provider pinky promises not to decrypt what they have, it's that they promise they will not insert a new key into your circle of trust to subsequently start decrypting things.

Re: Apple defeats liability for not scanning iCloud for CSAM

#37
post #7

The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections. As sad as this is, end to end encryption means no CSAM scanning. As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too. This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

People can also distribute heinous things through snail mail, but we are not yet at the point where the government reads all letters looking for wrongthink.

Just because we technically can make a privacy destroying drag net does not mean we should. Had phones existed 250 years ago, I have no doubt the founders would have thought it obvious that a cellphone’s contents were your personal papers which could not be freely searched.

Re: Apple defeats liability for not scanning iCloud for CSAM

#38
post #7

The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections. As sad as this is, end to end encryption means no CSAM scanning. As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too. This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

-

The judge’s dicta about protecting children in her pro-privacy ruling upholding existing law “tips their hand” that they are somehow part of a global conspiracy to eliminate privacy?

I think your conspiracy theory needs work, to be perfectly honest with you.

Re: Apple defeats liability for not scanning iCloud for CSAM

#39
post #9

If these judges are so righteous, they should go further and mandate the OS to do mandatory scanning of personal hd.

It's still a shade of gray to me. If I offered some homegrown cloud storage to my friends, and one of them uploaded CSAM to it, you can bet your ass that I would be arrested for it.

Does Sundar get arrested if someone uploaded CSAM to GDrive?

Re: Apple defeats liability for not scanning iCloud for CSAM

#40
post #8

I know creating a throwaway to hide your name for an opinion is a bad manner, but this one is one I really don’t want linked back to me The VAST majority of “CSAM” is consensually created and exchanged by teens. Their future selves and their parents form this pressure group attacking everyone’s liberty and privacy to try to undo the downsides of choices they made themselves with full knowledge of what could happen. T…

[deleted]
Post reply on HN