Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

301–310 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#301
post #131

Earlier quoted context omitted.

That's what they're saying, the key difference is Apples happens on your device, not theirs.

That's not really better or different. In any meaningful way.

Apple keeps the scan results encrypted with a key they don't have until the device informs them that the threshold of 30 images that match known kiddie porn has been reached.

After that, they get the decryption key and trigger a human review to make sure there haven't been 30 false positives at once.

That is better, and more private, in a very meaningful way.

False positive scan data sitting on the server is open to malicious misuse by anyone who can get a warrant.

>Innocent man, 23, sues Arizona police for $1.5million after being arrested for murder and jailed for six days when Google's GPS tracker wrongly placed him at the scene of the 2018 crime

https://www.dailymail.co.uk/news/article-7897319/Police-arre...

Also, I sincerely doubt that Google has ended it's practice of refusing to hire a human being to check for false positives when a poorly performing algorithm is cheaper.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#302
post #261

Earlier quoted context omitted.

It is indeed meaningfully different: your sensitive data never leaves your device in order to be scanned. There can't be a crack in Apple servers that would expose files of millions of users uploaded for scanning. Eventually it could lead to Apple platform not having any CSAM content, or any known legally objectionable content, because any sane perpetrator would migrate to other platforms, and less sane, caught. This…

> your sensitive data never leaves your device in order to be scanned. There can't be a crack in Apple servers that would expose files of millions of users uploaded for scanning. And yet photos that get scanned are still uploaded to iCloud Photos, so they do end up on Apple's servers.

Photos that users choose to upload to iCloud Photos do indeed get uploaded to iCloud Photos?

I'm failing to see the issue.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#303
post #277

Earlier quoted context omitted.

I guess people had a sense of ownership of these devices and they feel that it’s doing some they they don’t want. If ownership means control, maybe in the digital age full ownership/control is not really possible on a managed device like the iPhone. There are other example like the John Deer tractor issues.

I have a sense of ownership over my non-publicly-accessible data when it's backed up to a cloud drive. Apple isn't scanning that. Google and Microsoft are.

Sure, you own the data, but you don’t have any control on what’s happening to it. Just like iPhone users, we own the physical device but we only control certain aspects of what it’s doing, and the boundaries are not set by us, but by Apple.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#304
post #253

Earlier quoted context omitted.

what kind of encryption can't be decrypted until some threshold has been crossed? maybe you mean to say that apple says they won't read it until that threshold has been crossed.

> what kind of encryption can't be decrypted until some threshold has been crossed? The kind Apple has built. You should read the docs. This is literally how it works.

This is the same company that saved the disk encryption password as the password hint. You really trust them to not screw this up when the stakes are that it could ruin your life and/or land you in jail? I'm simply not ok with that.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#305

Earlier quoted context omitted.

I think the difference here is that it's ON YOUR DEVICE. I think there's a pretty clear understanding that if you upload stuff to a cloud provider they can do whatever they want with it. This is different. This is reaching into what has up until now mostly been considered a private place. Law enforcement often has to get warrants to search this kind of thing. This is the difference between putting CSAM on a sign in y…

ON YOUR DEVICE (where it's encrypted in a way that Apple can't read until the 30 image threshold is crossed) is more private than doing the same scan on server where a single false positive can be misused by anyone who can get a subpoena.

> ON YOUR DEVICE (where it's encrypted in a way that Apple can't read until the 30 image threshold is crossed)

First of all, you have to be able to read it to do the comparison that can increment the counter to 30. So regardless of whether it is or is not encrypted there, they're accessing the unencrypted plaintext to calculate the hash.

And yes, on my device is definitively more private than on someone else's server--just like in my bedside drawer is more private than in an office I rent in a co-working space.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#306

Earlier quoted context omitted.

You turn it off by turning off iCloud photos, I never claimed otherwise. If you don’t trust Apple why would you use iCloud anyway? Makes no sense.

> You turn it off by turning off iCloud photos, I never claimed otherwise. I just have to point out the ridiculousness of this statement. With your logic any feature in any product can be "turned off" by not using the entire product at all. For example, the radio in my car sounds like shit, I guess I should just stop driving completely to avoid having to hear it. In reality, this new "feature" will be a requirement o…

> In reality, this new "feature" will be a requirement of using iCloud Photos. The feature itself cannot be turned off. If your answer is to stop using iCloud Photos, that is no help for the millions of people who currently use iCloud Photos.

iCloud Photos can be used on Windows, for example. This scanning only applies to iOS devices. You could use iCloud Photos and not be subject to the scanning.

> I've trusted Apple for a long time because I felt like they were one of the only companies that cared about consumer privacy. After these actions I am less convinced of that. I'm not sure why that stance is so surprising.

Nothing about what they're doing is contradictory with privacy beyond what they're already doing. The only reason they're even implementing it this way is because they do care about privacy. They could just not encrypt and scan on the server like Google, Microsoft, Dropbox, Box.com and more.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#307

Earlier quoted context omitted.

The only way to match poses, coloration, background, etc is to possess illegal CSAM content. If you do so successfully, you will result in your crafted image passing the blur check and reaching the agency that possesses the original image for final verification, where it will immediately fail because it is obviously a replica. You will then trigger that agency leading law enforcement to find the creator of the image,…

This assumes that it's impossible to reverse the perceptual hashes used here in such a way that you could determine poses and coloration, for one. And in retrospect, you don't need to match that - you just need it to appear obviously pornographic after the blur is applied in order to get past Apple's reviewers. After that, the lucky individual's life is in the hands of the police/prosecutors. (I have to imagine that…

Apple's reviewers are comparing blurred originals to blurred matches. It needs to look like the blurred original associated with the checksum that matched. It is irrelevant whether the blurred match looks pornographic or not.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#308
post #300

Earlier quoted context omitted.

Let's be real, of course many of those people will be child abusers. But let's also be real about something else. Think of the Venn diagram of child abusers and people who share CSAM online. Those circles are not identical. Not everybody with CSAM is necessarily a child abuser. Worse, how many child abusers don't share CSAM online? Those can't ever be found by Apple-style invasions of privacy, so one has to wonder if…

All CSAM is produced by child abuse. Everyone who shares 30 images online is a participant in child abuse, even if only by creating a demand for images. > a crime fighting strategy Is it a crime fighting strategy? I thought it was just about not making their devices and services into aids for these crimes. > The cynic in me is also wondering what fraction of people working at places like NCMEC are pedophiles. Good qu…

That's a tedious debate that has been rehashed to death. Finding somebody who has CSAM without being a child abuser doesn't save even a single child. Finding everybody who has CSAM without being a child abuser would likely save some children (drying out commercial operations, perhaps?), but is also basically impossible.

And how many children can really be helped in this way? Surely the majority of child abuse happens independently of the online sharing of CSAM.

And is that really worth the suspension of important civil rights? That is really what this discussion is about. Nobody is arguing against fighting child abuse, the question is about how, and about what means can be justified.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#309

Earlier quoted context omitted.

No - the reporting is absolutely terrible here. 1) These are more share similar visual features than crypto hashes. 2) HN posters have been claiming that apple reviewing flagged photos is a felony -> because HN commentators are claiming flagged photos are somehow "known" CASM - this is also likely totally false. The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculo…

> The images may not be CASM and the idea that a moderation queue results in felony charges is near ridiculous. Agree, and I think this is backed up by real world experience. Has Facebook or anyone working on their behalf ever been charged for possession of CSAM? I guarantee they've seen some. Probably a lot, in fact. That's why we have recurring discussions about the workers and the compensation they get (or not) fo…

More of an anecdote, but our software allows users to upload files, documents, images and such. This in turn means, technically speaking, our platform could be used to distribute malware or other illegal content. I've asked: Well what happens if that occurs and we as a company becomes aware?

Overall, we're advised to take about these steps there. First off, report it. Second, remove all access for the customer, terminate the accounts, lock them out asap. Third, prevent access to the content without touching it. For example, if it sits on a file system and a web server could serve it, blacklist URLs on a loadbalancer. Fourth, if necessary, begin archiving and securing evidence. But if possible in any way, disable content deletion mechanisms and wait for legal advice, or the law enforcement to tell you how to gather the data.

But overall, you're not immediately guilty for someone abusing your service, and no one is instantly guilty for detecting someone is abusing your service.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#310

Earlier quoted context omitted.

Privacy means “you pay for the device so we don’t sell your attention to advertisers.” That’s it. There’s no protection against state level actors (Pegasus, CSAM scanning, etc.). If your threat model includes being the target of someone who will plant child pornography on your phone, you are already fucked. And no, Apple isn’t suddenly going to scan Chinese iPhones for Winnie the Pooh memes. They don’t have to. China…

Is there a consumer computing device that’s more secure than iPhone against state actors? A Chromebook, maybe?

There is no consumer grade device that is secure against state actors.
Post reply on HN