Live data from Hacker News

One Bad Apple

hackerfactor.com

301–310 of 557 posts

Re: One Bad Apple

#301
post #270

Earlier quoted context omitted.

They do not provide e2e for iCloud photos (or iCloud backups, etc.) and did not specify that they were planning to. They do not provide more privacy than the competition (in this regard at least), and yes, people can just disable iCloud services. That argument that "you can just not use it" is a pretty weak one for defending poor privacy practices. The same could be said for any website or server with poor privacy pr…

i dunno, reading this thing sure does make it sound like it's only for photos stored in icloud. and the existence of such an elaborate system sure does seem to indicate that photos are end to end encrypted on their servers, otherwise they could just hash them there. it does the matching client side, so the hashes never leave the client. what it does send with the photos is this threshold thing where if enough of them…

okay, so according to this [1], icloud photos are not e2e encrypted. point still stands, this is a system that is designed to flag the images without looking at them server side. assuming that it is successful, it paves the way for when they could turn on e2e encryption for icloud photos.

[1] https://support.apple.com/en-us/HT202303

Re: One Bad Apple

#302

Earlier quoted context omitted.

>Demand drives creation. Getting rid of it on one of the largest potential viewing and sharing platforms is a move in the right direction in addressing the problem. Yeah, that focus has worked really well in the "war on some drugs," hasn't it? I don't pretend to have all (or any good ones for that matter) the answers, but we know interdiction doesn't work. Those who are going to engage in non-consensual behavior (wit…

> Were that to happen today, I would be sitting in a jail cell, looking at a lengthy prison sentence. No you would not, I was ready to somewhat agree with you but this is just false and has nothing to do with what you were talking about before. The law does not say that naked photos of (your or anyone else's) kids are inherently illegal, they have to actually be sexual in nature. And while the line is certainly not a…

> The law does not say that naked photos of (your or anyone else's) kids are inherently illegal, they have to actually be sexual in nature.

But that depends on who looks at it.

People have been arrested and (at least temporary) lost custody over their children because someone called the police over perfectly normal family photos. I remember one case a few years ago where someone had gotten into trouble because one photo included a toddler wearing nothing (even facing away from the camera if my memory serves me correctly) playing at the beach. When police realized this wasn't an offense, instead of apologizing they got hung up on another photo were kids were playing with an empty beer can.

Recently this was also linked https://jonathanturley.org/2009/09/18/arizona-couple-sues-wa...

which further links to a couple of previous cases.

I'd say we get police or health care to talk to people who think perfectly normal images are sexual in nature, but until we get laws changed at least then keep us safe.

> I mean let's be clear here, do you believe the law considers to much stuff to be CSAM, and if so why? How would you prefer we redefine it?

Another thing that comes up is that a lot of things that are legal might be in that database because criminal might have a somewhat varied history.

Personally I am a practicing conservative Christian so this doesn't bother me personally at the moment since for obvious reasons I don't collect these kinds of images.

The reason I care is because every such capability will be abused, and below I present in two easy steps how it will go from todays well intended system to a powerful tool for oppression:

1. today it is pictures but if getting around it is as simple as putting it in a pdf then obviously pdfs must be screened too. Same with zip files. Because otherwise this so simple to circumvent that is worthless.

2. once you have such a system in place it would be a shame not to use it for every other evil thing. Dependending on where you live this might be anything: Muslim scriptures, Atheist books or videos, Christian scriptures, Winnie the Pooh drawings - you name it and someone wants to censor it.

Re: One Bad Apple

#303

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

I think there is a trend across the world of power centers becoming more authoritarian and punitive. It is en vogue to see it in China and point them out for it.

It is harder to look in the mirror and see something similar happening in the US. In the US, we superficially see government doing it (Snowden disclosures) and then we see corporations doing it separately (Facebook, Google ad tracking, etc...). However, I think government and tech giants are working closely together to act like China. This feels like another bud of this trend.

- Social credit system

- Loss of financial services (PayPal)

- Loss of access to social media (Facebook, Google, Apple, YouTube)

- Loss of access to travel related services (AirBnB, travel ban)

- Banning of material (Amazon)

- Control of media (owned by just a few major corporations who don't have to make money from the media... Comcast basically has a monopoly on land line Internet, AT&T has a very strong position on mobile, Disney has a strong position in films... they own CNN, NBC, and ABC)... EDIT: And let's not forget Fox

You can say all you want about freedom of association, but the effect is similar in China and the US. You are ostracized from the system.

Tech has lost its neutral carrier status and now is connected into a system that enforces consent. I wonder why? Are we being prepared for an economic war? Is this the natural evolution of power seeking power? Is this just a cycle of authoritarianism and liberalism?

P.S. I don't think groundswell upcry leading to cancellation means much. I am much more concerned when corporations do it. I just think they are much, much more powerful.

Re: One Bad Apple

#304
post #272

There is so much focus on the technical aspects such as probability of mismatch etc. For me the risk is much more that through some mechanism outside my control real CSAM material becomes present on my device. Whether its a dodgy web site, a spam email, a successful hack attempt or something else like that, I feel like there's a significant chance some day I'll end up with this stuff injected onto my phone without me…

The reason everyone is focusing on the technical aspects is because most people will evaluate it as it is planned to be, and not as what it could become. This is probably because, at any time, users can switch from Apple to Android in an upgrade cycle - so while perhaps 99% of users are fine with this CSAM scanner in its current state, if they expand its usage to something bad then those 99% that stayed can once again evaluate if they still value the hardware enough to keep it with the new status quo; therefore, evaluating it as it is in its current state will help people reading make the best personal decisions and the details will help with context if/when they do expand usage of this system.

Re: One Bad Apple

#306
post #273

Earlier quoted context omitted.

One way to interpret the macaque photo is that the database has already been subverted for uses other than catching CP.

Or it’s one of many test images, like EICAR, so people can test and validate the system without using abhorrent images.

Sure. Though, it’s not of much use if it is not documented.

Re: One Bad Apple

#307
post #98

I don't see many people pushing back on the child pornography laws themselves that are the cause of this. I'm stepping into a hornets nest by even bringing this up, because any criticism of the laws on the books makes one look they're a pedo, so I'll preface by saying, child pornography (filmed with actual kids) is vile and disgusting, but it is the production of it that is evil to be fought and suppressed, not the p…

Something else I haven’t heard anyone bring up: when child abusers are caught, sentences are often a joke. They often spend less time in prison than low to mid level drug offenders. CP is rape porn. People who produce or knowingly distribute actual rape porn (of children or adults) should be going to jail for 25+ years. I would not rule out life for extreme cases that also involve other forms of abuse. Yet as far as…

Indeed. A case in particular was Benjamin Levin who was the Minister of Education in Ontario

> Levin was ultimately nabbed conversing with police officers posing as single moms. He encouraged them to sexually abuse their kids and in some cases shared photos. [1]

> In one case, Levin sent photographs to a New Zealand police officer, one showing a “close-up of the face of a crying child, her face smeared with black makeup.” Levin suggested to her the image was “hot,” according to parole board documents. Another photo he sent showed a young female bound and leashed, with a gag in her mouth and Levin commented, “Mmm, so hot to imagine a mother doing that to her girl to please her lover.” [1]

> On May 29, 2015, he was sentenced to three years in prison. He only spent 3 months of his sentence in jail before being paroled [2]

[1] https://torontosun.com/2017/10/07/ex-deputy-education-minist... [2] https://en.wikipedia.org/wiki/Benjamin_Levin_(academic)

Re: One Bad Apple

#308
post #47

Earlier quoted context omitted.

Why do elected officials act as fake representatives to the people that elected them in the first place? Has it always been this way? It doesn’t matter left or right. The governing bodies should obey the people not the other way around.

If the people had their way, those suspected of child sex crimes wouldn’t even get trials. Things like privacy and due process only exist to the extent that a ruling class has the power to impose their own values, contrary to popular will.

These cases of people actually claiming to want people locked up without due process are pushed by a vocal minority (same with us - even hacker news posts with maybe a million views mean than 1% of U.S. adults read it) - almost everyone wants due process since we want the truth to come out in the most verifiable way, and the court system provides that, even if it involves humans that can be bribed, persuaded, and manipulated by rich & powerful people.

Re: One Bad Apple

#309
post #94
post #57

I appreciate just about everything about this post, but this part keeps getting lost in everything I see written about it: >As noted, Apple says that they will scan your Apple device for CSAM material. If they find something that they think matches, then they will send it to Apple. The problem is that you don't know which pictures will be sent to Apple. It's iCloud Photos. Apple has explicitly said it's iCloud photos…

The use of the detection algorithm is for iCloud only today . Now that the technology is on-board the device, how many lines of codes do you think it will take to scan the full photo-roll? Do you think that this ability will not tempt LEA, law makers, governments, to push for that ever-so-small change to the code, either for blanket monitoring (see if China is not tempted, using their own database of "illegal" conten…

Based on this article (and my first rebuttal[0]) I actually think the whole "only photos syncing to icloud photos" part of it is the defining factor making it legal - if Apple specifically only sent themselves photos that were detected as CSAM, it would likely be a felony, while the planned system can use the reasoning I laid out to likely not be charged with such felony.

0: https://news.ycombinator.com/item?id=28112312

Re: One Bad Apple

#310
post #151

Earlier quoted context omitted.

He wrongly interpreted CSAM scanning. He said that Apple will scan your photos and if finds something, it will send photo to Apple. Which is absolutely not how it works. Photo is only scanned before uploading to iCloud Photos. Apple already confirmed it to iMore and it’s clearly stated in Apple papers from press-release.

Please stop spreading misinformation. Apple has built the system to scan your entire phone, their claims about its limited scope are suspect.

https://news.ycombinator.com/item?id=28112982
Post reply on HN