Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

321–330 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#321
post #184

Earlier quoted context omitted.

Asking in earnest: are you speaking in absolute terms or relative terms? That is, does the percentage of funding (as compared to the rest of the budget) exceed most other countries’ military funding, or just the absolute amount?

Absolute. Today, the U.S. collectively spends $100 billion a year on policing and a further $80 billion on incarceration. Just the spending on policing is larger than what other countries spend on military. Actually, the only country that spends more on military is China [1], after taking in incarceration costs, it is 2.5 times the military expenditure of India. [1] https://www.sipri.org/publications/2021/sipri-fact-…

Thanks for the link, but have you read it?

"the only country that spends more on military is China"

1 1 United States 778 4.4 -10 3.7 4.8 39

2 2 China [252] 1.9 76 [1.7] [1.7] [13]

3 3 India 72.9 2.1 34 2.9 2.7 3.7

:facepalm:

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#322
post #125

Earlier quoted context omitted.

Yes, indeed, let's! Grownups recognize that strip searches are unwarranted in this and most other cases, be they physical OR digital... And certainly you've heard of software bugs. You do not think that a small one like "accidentally" "forgetting" to check that a photo had been synced cannot happen, and an "accidental" scan of ALL photos couldn't possibly happen in any situation no matter what bug/corruption/etc? Sur…

You must surely realise that there’s a fairly large difference between being strip-searched and having a hash computed on one of your photos that you’re uploading to iCloud.

Don't see any difference. In both cases your private property forcibly accessed without any reason to suspect you, but rather out of preventive reasons.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#323

Apple's new policy will have only one effect - pedophiles will stop using ios. For the rest of us, our privacy will remain compromised.

Pedophiles in the know would presumably just have to disable iCloud sync, and the hash scan would never happen.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#324

If you had the weights of the hashing neural network (NeuralHash) could it be reversible so that a hash could derive a similar photo to the original?

Neural networks are generally assumed to be non-invertible functions. That said, something like an auto-encoder can learn to decode the encoded data back to its original form, with loss.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#325

Horrible. Apple has every right not to facilitate child exploitation, your rights be damned. Don’t like it? Don’t buy an iPhone. end of story.

So we should sit still and wait while CCTV in every room would be a normal preventive measure against child abuse? No thanks, we will tear down this initiative, and will keep doing that in future. However, you can keep sending your private footage to the police station, if you like doing so.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#326

Earlier quoted context omitted.

The system is basically what you describe except the explicit report is precisely what Apple send to NCMEC. By the time it gets to the police, there will be an identified crime. This has been the case for many years. I don't have the numbers to hand but I believe NCMEC receives around the order of 100 million referrals a year. EDIT: it's 20 million according to https://www.missingkids.org/ourwork/ncmecdata https://ww…

But we've already established there is no public oversight over the contents of the NCMEC database and that there cannot ever be, by design. Furthermore, it's known to contain hashes of non-CSAE images simply because they were found in a CSAE-related context. So how can this system guarantee civil freedom? How can it be guaranteed that it won't be exploited by the small number of people in power to actually inspect i…

Have we established that? Certainly not a reality I recognize. The processes involved in CSAM databases like NCMEC/ICSE are many years old. If it leads to widespread civil rights abuses, where are they?

Google Drive has 1bn users. Google scans content for CSAM already. Shouldn't we be seeing these negative side effects already?

Proponents of these systems can point to thousands upon thousands of actual "wins" (such as identifying teachers, police officers, sports coaches, judges, child minders etc who are pedophiles) and detractors cannot provide actual evidence of their theoretical disadvantages.

No system is perfect, no system "guarantees civil freedom", this is not a fair test. The actual evidence suggests automated scanning for CSAM is a net win for society.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#327
Apple in the eyes of many had one redeeming feature over the competition: they appeared to value privacy. The problem is that the 'many' are still a small minority, and that the much larger contingent that Apple serves sees them more accurately for what they are: a consumer electronics manufacturer, where privacy is not an absolute concept but something malleable as long as it serves the bottom line.

The tech world seems to have a problem reconciling these two views.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#328
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

> a non-insignificant amount of people in tech take this seriously We're all here to make ourselves feel good saying we Took A Stand. In reality, four weeks from now, do you think anybody will still be talking about it? I made this same mistake. I was pretty convinced that people were taking Copilot seriously, and that there was possibly going to be ramifications for Microsoft. I wasn't particularly looking forward t…

Well, you can't save your friends, but you can save yourself: https://nixos.org/

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#329

Google Photos and Gmail openly and heavily scan server-side, and I'm sure a lot of us use them, how do we reconcile that?

If you don't like it, you can use Protonmail instead of Gmail, and Mega instead of Google Drive, and still being able use Android device. But I totally understand frustration of users, whose smartphone suddenly turned into spyware.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#330
post #79

Earlier quoted context omitted.

I think the point is that yes, they have always had the power to do these things - but they haven't thus far. We rely on entities with power (companies, governments, people) to exercise restraint in how they exercise it. Those that DO exercise restraint gain trust since exercising restraint demonstrates an understanding of the consequences of not doing so. What the Apple move is doing is showing that they are willing…

Yeah, but they are already doing this for pointless things. They already use facial recognition on all the photos on your phone. That’s what I don’t understand. The only new thing is what they are looking for and their willingness to alert the authorities. The slippery slope argument that this will eventually be used by China to arrest journalists is scare tactics. We have zero evidence that Apple would allow such a…

i think the remote execution with a remote hash database is the key part thay you need to focus. Checking for faces is something that doesn't need much information outside your phone itself.

What Apple is proposing is basically adding a feature to scan any user's phone for a collection of hashes. Even if they say they will only use this for CSAM this sends a strong message to all government agencies around the world that the capability is over there. Maybe for US citizens this doesn't sound dangerous but if I was a minority or a critic of the government on a more authoritarian country I would jump ship from Apple products right away.

Post reply on HN