Live data from Hacker News

One Bad Apple

hackerfactor.com

311–320 of 557 posts

Re: One Bad Apple

#311

Earlier quoted context omitted.

He wrongly interpreted CSAM scanning. He said that Apple will scan your photos and if finds something, it will send photo to Apple. Which is absolutely not how it works. Photo is only scanned before uploading to iCloud Photos. Apple already confirmed it to iMore and it’s clearly stated in Apple papers from press-release.

You're very clearly missing the forest for the trees. Right before uploading to icloud, "Apple will scan your photos and if finds something, it will send photo to Apple." This process is automated and turned on on most iPhones. Most iPhones will have automatic photo upload to icloud enabled, and that's when this scanning takes place.

> Most iPhones will have automatic photo upload to icloud enabled,

I highly doubt that with how each photo is 10+MB and Apple only gives an abysmal 5GB of free iCloud storage, which includes everything else. My iphone 6s backups got to 4.5gb on their own years ago, turning off photo storage was the only way to avoid paying for iCloud storage outright.

Re: One Bad Apple

#312

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

> someone usually mocks "it's always about the kids, think about the kids." To those critics: They have not seen the scope of this problem or the long term impact.

This is making it worse : because people with an agenda use CP as an excuse to force immoral behavior into us, now child suffering is always associated with bullshit. Those action are hurting the children by supressong the social will to take it seriously.

Stop hurting the children!

Re: One Bad Apple

#313
post #146

Kim Dotcom did this and it lead to Riaa saying it obligated the file sharing service to look for all copyrighted materials. This opens pandoras box for Apple.

No, it didn't, at least not legally. There is no federal requirement to scan for copyrighted content (which is an impossible task without $MM in capital and a media library of copyrighted content) - YouTube only does it with Content ID to appease the rights holders and not have them remove all their content from YT outright. The only requirement is to respond to DMCA takedown notices, which they were obligated to do before Kim started scanning for CSAM (which I can't find a story for).

Re: One Bad Apple

#314
post #188

Earlier quoted context omitted.

>Not only has communication become easier, so has surveillance. It is a devil's advocate response, but can you explain why this is a bad thing? If communication is scaling and becoming easier, why shouldn't surveillance?

Why shouldn't every Neuralink come with a mandated FBI module preinstalled? Where, if anywhere , is private life to remain, where citizens think and communicate freely? Is Xinjiang just the start for the whole world?

Surely there is communication surrounding the child sexual abuse, making plans with other pedophiles and discussing strategies. Some of this may occur over text message. Maybe Apple’s next iteration of this technology can use my $1000 phone that I bought and that I own to surveil my E2EE private encrypted messages on my phone and generate a safety voucher for anything I say? The sky’s the limit!

Re: One Bad Apple

#315

The author of this article purports to have done a ton of research into this system, but appears to have missed basic information that I’ve acquired from a few podcasts. Namely the “1-in-a-trillion” false positives per account per year is based on the likelihood of multiple photos matching the database (Apple doesn’t say how many are required to trip their manual screening threshold).

Well, 3 photos or more are what puts you over the line for an affirmative defense against CSAM possession[0]. It's probably above that.

0: https://www.law.cornell.edu/uscode/text/18/2252A#:~:text=(d)...

Re: One Bad Apple

#316
post #215

Earlier quoted context omitted.

> A set of unverified hashes that you hope only came from NCMEC. Telecoms do this on their own devices - not yours. Yes, those are the main things we’re concerned about. > Apple just opened the door for constant searches of your digital devices. Specifically, it opens the door to them scanning content which is then end-to-end encrypted, which is the main problem. I think the jury is out on whether this capability wil…

Apple gave up in the face of China. Why not the US too?

Because they have legal avenues in the US that they don’t have in China? Easy.

Re: One Bad Apple

#317
post #103

Earlier quoted context omitted.

> There was parents arrested over bath time and playing in the yard sprinklers, photos being processed at photo mats, will the same thing happen by apple mistakenly reporting parents? No, because they’re not identifying content, they’re matching it against a set of already-known CSAM that NCMEC maintains. As you go on to say, telecoms and other companies already do this. Apple just advanced the state of the art when…

A set of unverified hashes that you hope only came from NCMEC. Telecoms do this on their own devices - not yours. Apple just opened the door for constant searches of your digital devices. If you think it will stop at CSAM you have never read a history book - the single biggest user of UKs camera system originally intended for serious crimes are housing councils checking to see who didn't clean up after their dog.

> the single biggest user of UKs camera system originally intended for serious crimes are housing councils checking to see who didn't clean up after their dog.

Which camera system? Do you have a citation for that?

Re: One Bad Apple

#319
post #282

Earlier quoted context omitted.

The implication -- and I think it's a valid one -- is that this client-side mechanism will be very quickly co-opted to also alert on non-CSAM material. For example, Winnie the Pooh memes in China.

I think it’s not valid to claim that it will be quickly used for that purpose. However I absolutely agree that it could be used to detect non-CSAM images if Apple colludes with that use case. My point is that this is immaterial to what is going on in China. China is already an authoritarian surveillance state. Even without this, the state has access to the iCloud photo servers in China, so who knows what they are doi…

You can label it collusion, but when Apple does it, it's going to call it _complying with local regulation_.

Re: One Bad Apple

#320
post #188

Earlier quoted context omitted.

In the past these people would have been developing the pictures themselves, and handing them between each other either personally or in some hidden manner using public systems. Not only has communication become easier, so has surveillance. The only difference now is that it's easier for people not to be aware when their very personal privacy is invaded, and that it can be done to the whole populace at once.

>Not only has communication become easier, so has surveillance. It is a devil's advocate response, but can you explain why this is a bad thing? If communication is scaling and becoming easier, why shouldn't surveillance?

To whom do you give the keys?
Post reply on HN