Live data from Hacker News

Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

vice.com

311–320 of 465 posts

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#311

Earlier quoted context omitted.

> your sensitive data never leaves your device in order to be scanned. There can't be a crack in Apple servers that would expose files of millions of users uploaded for scanning. And yet photos that get scanned are still uploaded to iCloud Photos, so they do end up on Apple's servers.

Photos that users choose to upload to iCloud Photos do indeed get uploaded to iCloud Photos? I'm failing to see the issue.

I think you might be tilting at windmills here. The issue is that the post I'm replying to claims that data never ends up on Apple's servers even though it does. Thanks for confirming that it does, though.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#312

Earlier quoted context omitted.

https://www.dailymail.co.uk/sciencetech/article-7865979/Appl... I wasn’t able to find the whole video though. No time to watch, but. https://www.ces.tech/Videos/2020/Chief-Privacy-Officer-Round...

The article you linked makes a surprising claim, and it contradicts what the EFF said recently about this here - https://www.eff.org/deeplinks/2021/08/apples-plan-think-diff... > Currently, although Apple holds the keys to view Photos stored in iCloud Photos, it does not scan these images It also seems weird that the EFF wouldn't have complained about this before if Apple was known to be doing server-side scanning fo…

I can’t find any articles about eff complaining about gmail, onedrive, or discord doing similar scanning either. All of those services (and more) do similar scans.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#313

Earlier quoted context omitted.

The issue is that as soon as you set that precedent, it’s only a matter of time before it extends beyond iCloud. That’s the problem with doing any device-level scanning. This is dystopian and scary. And yes I understand the technology in its current iteration. The current form has problems (weaponizing collisions etc) but the real issue comes with future developments.

> They scan everything that exists on my device I get to select the issue and it was in response to the previous claim that 'they' are scanning everything that exists on the device right now. A year ago this was a possible 'future development'. 10 years from now I could be living on Mars. This is all hypothetical.

> This is all hypothetical.

Exactly. However, people don't seem to have an issue when hypothesizing that CSAM detection is good actually, because Apple might implement E2EE, despite no evidence of such intentions.

For some reason, though, people take issue when others hypothesize that CSAM detection is bad actually, because Apple might expand it further and violate users' privacy even more. And there's actually precedent for this hypothesis, given Apple's actions here and their own words[1]:

> This program is ambitious, and protecting children is an important responsibility. These efforts will evolve and expand over time.

[1] https://www.apple.com/child-safety/

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#314
post #288

Earlier quoted context omitted.

> I just don't understand how they acted this way at all. There's a simple answer to this right? Despite everyone's reaction, Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy. And if you look at it from Apple's point of view that's correct: other major cloud providers catch CSAM content on their platform by inspecting every file uploaded, i.e. total invasion of…

> Apple genuinely believe this is a novel and unique method to catch CSAM without invading people's privacy What’s novel about this? The technique and issues with it are fairly obvious to anyone with experience in computer vision. It seems not too different from research from 1993 https://proceedings.neurips.cc/paper/1993/file/288cc0ff02287... The issues are also well known and encompass the whole subfield of adversa…

Presumably the system is novel enough that a very similar proposal which lacked one important insight (using perceptual hashes to turn image similarity problems into set intersection problems) was accepted to USENIX this year: https://www.usenix.org/conference/usenixsecurity21/presentat...

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#315

Earlier quoted context omitted.

BigCos, take note: you’re better off doing nefarious shit without telling anyone. Because, if you come clean, you’ll only invite an endless parade of bloggers who will misconstrue your technology to make you look bad.

It's important to keep nefarious stuff on the server side because eventually someone will reverse engineer what's on the client side. Imagine if Apple had done this on the client side without telling anyone, and later it was discovered. I think things would be a whole worse for Apple in that case.

That being the case, why do it client side at all, when presumably every claim they make is verifiable?

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#316
post #54

Earlier quoted context omitted.

The problem isn't the idea of CASM, it's that what happens when they start scanning for "misinformation", or whatever else they want to come up with at that point.

Then why not wait until that actual issue comes up. The look is so bad / awkward with this big protest over something that many people are not going to find at all objectionable. Do you really think Apple's brand has been "destroyed" over this?

IMO the risk is that the reaction will be viewed amongst the general population as an overreaction, leading to it being ignored on the next go around. Many people are going to listen to what Apple says, look at their piles of technical documentation, see the word CSAM, and conclude that the opposing side is crazy.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#317
post #303

Earlier quoted context omitted.

I have a sense of ownership over my non-publicly-accessible data when it's backed up to a cloud drive. Apple isn't scanning that. Google and Microsoft are.

Sure, you own the data, but you don’t have any control on what’s happening to it. Just like iPhone users, we own the physical device but we only control certain aspects of what it’s doing, and the boundaries are not set by us, but by Apple.

If I back up my files to Apple's cloud server, I don't have to worry about them scanning my private files at all.

They don't cross that line like Google and Microsoft do.

With Apple, nothing but files you upload to iCloud Photos get scanned.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#318

Earlier quoted context omitted.

> You turn it off by turning off iCloud photos, I never claimed otherwise. I just have to point out the ridiculousness of this statement. With your logic any feature in any product can be "turned off" by not using the entire product at all. For example, the radio in my car sounds like shit, I guess I should just stop driving completely to avoid having to hear it. In reality, this new "feature" will be a requirement o…

> In reality, this new "feature" will be a requirement of using iCloud Photos. The feature itself cannot be turned off. If your answer is to stop using iCloud Photos, that is no help for the millions of people who currently use iCloud Photos. iCloud Photos can be used on Windows, for example. This scanning only applies to iOS devices. You could use iCloud Photos and not be subject to the scanning. > I've trusted Appl…

> iCloud Photos can be used on Windows, for example. This scanning only applies to iOS devices. You could use iCloud Photos and not be subject to the scanning.

That's great for the >Nothing about what they're doing is contradictory with privacy beyond what they're already doing. The only reason they're even implementing it this way is because they do care about privacy. They could just not encrypt and scan on the server like Google, Microsoft, Dropbox, Box.com and more.

False dichotomy. Apple doesn't have to do either of these things.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#319

Earlier quoted context omitted.

I don't care. It's my device (at least that's how Apple used to advertise it) and I disagree with Apple's policy, full stop. I don't care about "think of the children" (especially since they will be scanning pictures of my own children), and furthermore I don't trust Apple not to change the policy in the future. They've created a backdoor and now the device is compromised and privacy is broken. If you want to trust A…

>I don't care If anything, you should be outraged that Google and Microsoft have been scanning much more of your data, and doing so in a much more intrusive way. Apple only scans iCloud Photos and they do so in a way that they can't see the results until they can be reasonably sure it's not just a false positive.

You have clearly misunderstood my position as you have replied to 2 of my comments already. You seem to have an "Apple vs the world" mentality when my point is entirely about holding Apple accountable to their own marketing. You sound like a bizarre Apple apologist and I'm tired of trying to explain myself to you when all you want to do is explain to me why Apple is better than everybody when I do not care and also fundamentally disagree.

If you think Apple's approach is the best you're allowed to think that. I disagree.

Re: Apple defends anti-child abuse imagery tech after claims of ‘hash collisions’

#320

Earlier quoted context omitted.

> In reality, this new "feature" will be a requirement of using iCloud Photos. The feature itself cannot be turned off. If your answer is to stop using iCloud Photos, that is no help for the millions of people who currently use iCloud Photos. iCloud Photos can be used on Windows, for example. This scanning only applies to iOS devices. You could use iCloud Photos and not be subject to the scanning. > I've trusted Appl…

> iCloud Photos can be used on Windows, for example. This scanning only applies to iOS devices. You could use iCloud Photos and not be subject to the scanning. That's great for the >Nothing about what they're doing is contradictory with privacy beyond what they're already doing. The only reason they're even implementing it this way is because they do care about privacy. They could just not encrypt and scan on the ser…

NCMEC is an arm of the government. Either they share voluntarily or they get subpoenaed endlessly. Why do you think all of these companies even do this? lol

in any case I've given you the solution on how to use iCloud and not be scanned. Take your photos, sync your iDevice to your computer and manually upload to iCloud photos. there you go.

Post reply on HN