Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

301–310 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#301

Earlier quoted context omitted.

No, these hashes can’t be reversed to an image. They’re not CSAM and therefore not illegal. That blog is not very good, either from a tech standpoint or a legal one.

They are perceptual hashes of CSAM images no? Sure, just because they are perceptual hashes, doesn't mean they can be reversed to an image, but it seems to be true PhotoDNA, a similar perceptual hashing algorithm, can be reversed to an image. For this reason, I believe it is possible Apple's perceptual hashes can be reversed as well, though, maybe they did it in a different way and it's not possible

PhotoDNA is Microsoft’s algorithm. Apple’s new one is NeuralHash. Plus the hashes are encrypted and blinded before being stored on the phone. They can’t be reversed.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#302

Earlier quoted context omitted.

For #2 actions are taken in the cloud, authorities are contacted, and all of the photos are unencrypted. Option #1 doesn’t really breach the ‘sanctity of device ownership’ because it only occurs if you’ve enabled iCloud photos on the device. Option #1 seems better to me in its current implementation. I understand the fear of abusing the hash matching. I just think that’s a separate thing.

>Option #1 doesn’t really breach the ‘sanctity of device ownership’ because it only occurs if you’ve enabled iCloud photos on the device. I'm done. You'll rationalize anything.

To be fair - I think reasonable people can disagree on this.

I don't think it's a rationalization to point out that it only occurs when the same baseline conditions are met (using the cloud). I think those constraints/specifics matter. I wouldn't be in favor of the policy if they were different (and I'm not even sure I'm in favor of it now).

My personally preferred outcome would be e2ee by default for everything without any of this, but I also understand the concerns of NCMEC and the general tradeoffs/laws around this stuff (and future regulatory risk of CSAM) - and just the general issue of reducing child sexual abuse.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#303
post #188

Earlier quoted context omitted.

Yes, if they wind up part of a child porn investigation. Your cloud account gets hacked. Some perv gets your images. He is then arrested and his "collection" added to the hash database... including your family photos. Context often matters more than the nature of the actual content. Police aquire thousands of images with little hope of ever knowing where they originated. If they are collected by pervs, and could be c…

Actually, we don’t know yet whether you can access your photos from the web anymore after this update, because E2EE ”like” implementation. Protocol is rather device specific (while allowing multi-device), so it might not be enough to access or hack iCloud account to access the photos. So, things get complicated.

> because E2EE ”like” implementation.

Did apple actually say photos would be e2ee or are we just assuming?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#304
post #300
post #243

Earlier quoted context omitted.

Yes, but that has always been the case. It can upload to iCloud, it could also upload to the CIA. What has changed?

Policy-wise Apple have just said "yes, we are going to use our super-admin powers to push updates to turn your phone against you". Sure, a suitably powerful authoritarian org could do lots of secret things, but that isn't what happens in real life: in real life you publicly change policy in increments and get everyone to go along with it. "Apple was actually scanning all users photos for CSAM regardless of iCloud usa…

> is a headline that is guaranteed in the future

Care to put a date on your guarantee?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#305

Earlier quoted context omitted.

They are perceptual hashes of CSAM images no? Sure, just because they are perceptual hashes, doesn't mean they can be reversed to an image, but it seems to be true PhotoDNA, a similar perceptual hashing algorithm, can be reversed to an image. For this reason, I believe it is possible Apple's perceptual hashes can be reversed as well, though, maybe they did it in a different way and it's not possible

PhotoDNA is Microsoft’s algorithm. Apple’s new one is NeuralHash. Plus the hashes are encrypted and blinded before being stored on the phone. They can’t be reversed.

In order for this system to work, Apple has to be able to compare the CSAM NeuralHash hashes against the NeuralHash hashes of the images to be synced with iCloud. How do they compare the hashes without decrypting?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#306
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Yes, if they wind up part of a child porn investigation. Your cloud account gets hacked. Some perv gets your images. He is then arrested and his "collection" added to the hash database... including your family photos. Context often matters more than the nature of the actual content. Police aquire thousands of images with little hope of ever knowing where they originated. If they are collected by pervs, and could be c…

if your cloud account gets hacked you have other things to worry about than someone stealing your child's photos (which for whatever reason are explicit enough for apple to report the detections to authorities), spreading them on a honeypot forum and you ending up in court where the judge doesn't believe that the minor on the image is your child

Re: The deceptive PR behind Apple’s “expanded protections for children”

#307

>The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember) people really need to retire this meme. On the desktop in particular as a dev environment Linux is completely fine at this point. I can understand people not wanting to run a custom phone OS because that really is a ton of work but for working software de…

While I don't expect any Linux phone to become "mainstream" any time soon, it would be good if we had at least one "polished" alternative available. PinePhone is still in beta and according to its own creators "aimed solely at early adopters"[1], while Librem 5 is experiencing supply chain issues with backorder shipping now scheduled to resume in October[2] There is a version of the Librem 5 which is made in USA and…

Problem will always be the hardware. Until we get some 80's IBM style architecture on mobile, there is no viable Linux for smartphone.

I have 4 phones. None of them support lineage os.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#308
post #166
post #164

Earlier quoted context omitted.

It all depends on what perceptual hashes you use. If Apple can institute a process whereby those are tied to the OS version, but not to the region, then it would be impossible to impose jurisdiction-specific exceptions.

> It all depends on what perceptual hashes you use. I’m talking about the mechanism as described, not a hypothetical. > If Apple can institute a process whereby those are tied to the OS version, but not to the region, then it would be impossible to impose jurisdiction-specific exceptions. As it is the mechanism they have built only works in the US jurisdiction.

> As it is the mechanism they have built only works in the US jurisdiction.

That is very worrisome. How do they want to withstand political pressure then to make the database of "bad hashes" dependent on the jurisdiction if they've already made the feature dependent on the jurisdiction?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#309

Earlier quoted context omitted.

I think the thumbnail is only when the threshold is passed and there's a hash match. The reason for that is an extra check to make sure there is no false positive match based on hatch match (they claim one trillion to one, but even ignoring that probably pretty rare and strictly better than everything unencrypted on iCloud anyway). > Nope, E2EE without compromises is preferable. Well that's not an option on offer and…

>Well that's not an option on offer and even that has real tradeoffs - it would result in less CSAM getting detected. Maybe you think that's the acceptable tradeoff, but unless government legislatures also think so it doesn't really matter. It should and can be an option. Who cares what they offer us. Do it yourself.

That's just a separate topic.

If you do it yourself none of this policy stuff matters.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#310

Earlier quoted context omitted.

Even HN reporting / article linking / comments have been surprisingly low quality and seem to fulminate and declaim with surprisingly little interesting conversation and tons of super big assertions. Linked articles and comments have said apple's brand is now destroyed, that apple is committing child porn felonies somehow with this (the logical jumps and twisting to get to these claims are very far from strong plausi…

From https://www.hackerfactor.com/blog/index.php?/archives/929-On... > The laws related to CSAM are very explicit. 18 U.S. Code § 2252 states that knowingly transferring CSAM material is a felony. (The only exception, in 2258A, is when it is reported to NCMEC.) In this case, Apple has a very strong reason to believe they are transferring CSAM material, and they are sending it to Apple -- not NCMEC. > It does not matt…

That’s amusing, but your source is completely wrong about (1) What 18 USC § 2252 says in general (notably, it leaves out the “knowingly” requirement, which is critical given the wait being given to post-auto-flag, pre-verification transfer), (2) What exceptions are in § 2252, and (3) the entire reference to § 2258A, which is a separate reporting requitement, not an exception to § 2252. Really, one should read all of the chapter those sections are part of, but the whole argument is based on either fantasy or distortion of the text.

https://www.law.cornell.edu/uscode/text/18/part-I/chapter-11...

Post reply on HN