Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

311–320 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#311
The problem is that, as much as this capability is disturbing, Apple chose it's first target well: It's difficult to be too vocal about this without the risk of getting labelled weak on underage sex trafficking and kiddie porn.

So, no matter the criticism, Apple won't seriously be pressured to reverse course, and after that the door is open on incremental increases in content monitoring.

(Not to mention the problems that could arise from false positives.)

Re: Apple's child protection features spark concern within its own ranks: sources

#312
post #305

Earlier quoted context omitted.

Because if (willBeUploaded) { scanPhoto(); } can become if (true) { scanPhoto(); } Obviously, this is stupidly oversimplified, I have no idea how Apple has structured their code. But the fact of the matter is, if the scanning routine is already on the phone, and the photos are on the phone, all anyone has to do is change which photos get scanned by the routine...

Right, but the CSAM scanning routine is absurdly narrow and difficult to use for detecting anything but CSAM, whereas a general purpose hash matching algorithm really is just a few lines of code. This whole ‘now that they have a scanner it’s easier’ reasoning doesn’t make sense. iOS already had numerous better matching algorithms if your goal is to do general spying.

Isn't the scanning routine searching for fingerprints? What happens if someone adds a fingerprint to the database, which matches something other than CSAM?

Re: Apple's child protection features spark concern within its own ranks: sources

#313

Earlier quoted context omitted.

That is, it seems like Apple really wanted to preserve "end-to-end" encryption,“ … except they still have not mentioned anything about E2E encryption… and they currently don’t encrypt icloud backups. You would think apple would get ahead of this story and mention … or maybe they don’t have any E2E plans at all.

CSAM scanning is probably the easiest thing they could do to satisfy this demand, and if you don't use iCloud Photos, you're not affected by it at all. As far as encrypted backups go, it's an open question whether they want to deal with the legal and support headaches that such a change would bring. If they continued to do nothing, Congress might force their hand by legislatively outlawing stronger encryption - they…

> For users, if you enable this feature, but then lose your password, you are entirely screwed and Apple can't help you.

Exactly the same with the phone if you forget your PIN/passcode. So they already do this.

Re: Apple's child protection features spark concern within its own ranks: sources

#314
post #300

Earlier quoted context omitted.

Exactly. They already analysed photos on your phone for search . They don’t in fact do CSAM detection on the photos on your phone. But why are people only objecting now when they were already doing on-device analysis? CSAM detection is a complete red herring. It is less of a general purpose scanning mechanism than the search function that was already there.

They're doing on device analysis, but there isn't any process by which an image of a hotdog will be sent to someone else without my knowledge.

Right, but neither is the CSAM code being used to detect anything but CSAM.

If a bit can be flipped to make the CSAM detector go evil, surely it can be flipped to make photo search go evil, or spotlight start reporting files that match keywords for that matter.

There is nothing special about this CSAM detector except that it’s narrower and harder to repurpose than most of the rest of the system.

Re: Apple's child protection features spark concern within its own ranks: sources

#315
post #269

Earlier quoted context omitted.

> But with Apple's CSAM proposal is NOT possible to have an iPhone that Apple isn't continuously scanning. As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone.

Woops, you're right, thanks for the correction. I think the issue is that, as Ben Thompson pointed out, the only thing preventing them from scanning other stuff now is just policy , not capability , and now that Pandora's box is open it's going to be much more difficult to resist when a government comes to them and says "we want you to scan messages for subversive content".

Yes, of course that is true. I use iCloud Photos and find this terribly creepy. If Apple must scan my photos, I'd rather they do it on their servers.

I could maybe understand the new implementation if Apple had announced they'd also be enabling E2E encryption of everything in iCloud, and explained it as "this is the only way we can prevent CSAM from being stored on our servers."

Re: Apple's child protection features spark concern within its own ranks: sources

#316
post #125

Regarding smartphones, I wonder if we’ve just lost a grip on what it means to have privacy. Even our expectations for privacy have degraded and eroded over time. We just carry this device with our life encoded in a flash chip with keys to cloud access. Life . Everything from emails to our walking gait, photos, text, history, health records, etc is stored on this one device. Dictators of the past would have a field da…

Why ham radio? That doesn’t make sense. There’s no privacy there by law. It is by nature a completely non anonymous medium. Not only that if a country shuts down its comms the hams are all on a nice list for their shit to be confiscated. Im not a ham because of some romanticised dystopia avoidance. It’s just fun to make things that you can talk to people on :)

Ham Radio does not depend on internet backbone. In the extreme, you can communicate across the world with a few basic electronic components which can be built at home. Sure, government can listen to it but it's trivial to encrypt (illegal on Ham bands) if you're oppressed by the government.

> nice list for their shit to be confiscated.

I am not sure if this would go well in the USA.

Re: Apple's child protection features spark concern within its own ranks: sources

#317

"The ark of the covenant is open and now all your faces are going to melt" - to paraphrase "The Thick of It". Prior to this when a government tapped Apple on the shoulder asking to scan for what they (the government) deem illicit material, Apple could have feasibly say "we cannot do this, the technology does not exist". Now the box is open, the technology does exist, publicly and on the record - Now we are but a nati…

> the technology does exist, publicly and on the record

And not only that, but with a little footnote saying "* Features available in the U.S." - in other words, publicly and on the record: this can be switched on and off on per jurisdiction. If another jurisdiction comes and says "here's my list of hashes of illegal images", how can Apple say "sorry, can't do..."?

Re: Apple's child protection features spark concern within its own ranks: sources

#318
post #269

Earlier quoted context omitted.

> But with Apple's CSAM proposal is NOT possible to have an iPhone that Apple isn't continuously scanning. As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone.

>As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone. Except for the "oops, due to an unexpected bug in our code, every image, document, and message on your device was being continuously scanned" mea culpa we will see a few months after this goes live.

The potential for this is overblown and I think a lot of people haven’t taken the time to understand how the system is set up. iOS is not scanning for hash matches and phoning home every time it sees one, it’s attaching a cryptographic voucher to every photo uploaded to iCloud that, if some number of photos represent hash matches (the fact of the match is not revealed until the threshold number is reached), then allow Apple to decrypt the photos that match. This is not something where “oops bug got non-iCloud photos too” or “court told us to flip the switch to scan the other photos” would make any sense, some significant modification would be required. Which I agree is a risk especially with governments like China/EU that like to set conditions for market access, just not a very immediate one.

Re: Apple's child protection features spark concern within its own ranks: sources

#319
post #253

I stopped my Apple Music subscription and downgraded iCloud to free, then donated a year of those fees to the EFF. $13/month is nothing to Apple, and I really regret it since photos in iCloud is really convenient, however it feels unethical to contribute to the Apple services system when it will inevitably be used to hurt people like dissidents and whistle blowers. It is arrogant to blow off security and human rights…

I totally agree that those actions individually are not much. However, with enough people doing those small actions, it will add up in the long run. Plus we’re going to be better off with open alternatives.

They just lost a few thousands from me alone not upgrading all my iDevices for next model year. Savings go to privacy advocacy organizations.

Re: Apple's child protection features spark concern within its own ranks: sources

#320
post #269

Earlier quoted context omitted.

> But with Apple's CSAM proposal is NOT possible to have an iPhone that Apple isn't continuously scanning. As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone.

Woops, you're right, thanks for the correction. I think the issue is that, as Ben Thompson pointed out, the only thing preventing them from scanning other stuff now is just policy , not capability , and now that Pandora's box is open it's going to be much more difficult to resist when a government comes to them and says "we want you to scan messages for subversive content".

Given that they obviously already have the capability to send software updates that add new on-device capability, this seems like a meaningless distinction. It’s already “just policy” preventing them from sending any conceivable software update to their phones.
Post reply on HN