Live data from Hacker News

One Bad Apple

hackerfactor.com

321–330 of 557 posts

Re: One Bad Apple

#321

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

> Nearly 1 in 10 children in the US will be sexually abused before the age of 18.

If you include non-therapeutic infant circumcision, which many believe to be medical battery and (infant) male genital mutilation, this number would be much higher.

Re: One Bad Apple

#322

I don't see many people pushing back on the child pornography laws themselves that are the cause of this. I'm stepping into a hornets nest by even bringing this up, because any criticism of the laws on the books makes one look they're a pedo, so I'll preface by saying, child pornography (filmed with actual kids) is vile and disgusting, but it is the production of it that is evil to be fought and suppressed, not the p…

[deleted]

Re: One Bad Apple

#323
post #188

Earlier quoted context omitted.

>Not only has communication become easier, so has surveillance. It is a devil's advocate response, but can you explain why this is a bad thing? If communication is scaling and becoming easier, why shouldn't surveillance?

Why shouldn't every Neuralink come with a mandated FBI module preinstalled? Where, if anywhere , is private life to remain, where citizens think and communicate freely? Is Xinjiang just the start for the whole world?

Do you see how this underlines my original point? I brought up real child abuse that is happening today and your response is about brain implants being mandated by the government. Most people are going prioritize the tangible problem over worrying about your sci-fi dystopia.

Re: One Bad Apple

#324
post #94

Earlier quoted context omitted.

The use of the detection algorithm is for iCloud only today . Now that the technology is on-board the device, how many lines of codes do you think it will take to scan the full photo-roll? Do you think that this ability will not tempt LEA, law makers, governments, to push for that ever-so-small change to the code, either for blanket monitoring (see if China is not tempted, using their own database of "illegal" conten…

>The use of the detection algorithm is for iCloud only today . Yes, which is what I was saying in my comment. If or when it comes to Apple changing this then I would agree it's a battle worth fighting, but that is not what is happening here and that is not what I was correcting in this article itself. >The main issue is that the wall has been breached: The wall was breached when we opted to run proprietary OS systems…

Yes, which is what I was saying in my comment. If or when it comes to Apple changing this then I would agree it's a battle worth fighting, but that is not what is happening here and that is not what I was correcting in this article itself.

Isn't it too late to fight the battle then? They've already built the infrastructure to make it trivial to scan any file on your device.

Re: One Bad Apple

#325
post #18

There are a lot of articles about Apples hadh algorithm and for me they are mostly irrelevant to the main problem. The main problem is that Apple has backdoored my device. More types of bad images or other files will be scanned since now apple does not have plausible deniablity to defend any of ghe government’x requests. In the future a false? positive that happened? to be of a political file that crept in the list c…

This is mainly where I come down on this. I care about what they’re doing not why they’re doing it. What they are doing is examining my private files, and that is simply unacceptable.

Re: One Bad Apple

#326

Earlier quoted context omitted.

Well there is a difference as stated on the article that they don't expect to see CP or CSAM and says "We are not 'knowingly' seeing it since it makes up less than 0.06% of the uploads ... We do not intentionally look for CP." Whereas Apple is moderating the suspected images so they intentionally look for CP (which, according to the author and his lawyer, is a crime).

Yeah, as usual I'm worried the people who claim that others don't read are the ones not reading (or being able to comprehend) what the author is trying to say. To me it seems like moderation in general is fine. What Apple is doing here is that after they receive a flag that a certain threshold is crossed, they manually review the material. The author states that no one should do that i.e., the law explicitly prohibit…

The whole thing rests on whether Apple knows that the content is CSAM or not. And they don’t. The author gets this fundamentally wrong. They do not know whether it is a match or not when the voucher is created. The process does, but they don’t. They know when the system detects a threshold number of matches in the account, and they can then verify the matches.

Additionally, we already know they consulted with NCMEC on this because of the internal memos that leaked the other day, both from Apple leadership and a letter NCMEC sent congratulating them on their new system. If you think they haven’t evaluated the legality of what they’re doing, you’re just wrong.

Re: One Bad Apple

#327

Earlier quoted context omitted.

I have no idea whether this statistic is true or not, but "nearly 1 in 10 children in the US will be sexually abused" is an incredibly high number. I have no doubt that some cases of sexually abused children must have also existed in the environment where I have grown up as a child, in Europe, but I am quite certain that such cases could not have been significantly more than 1 per thousand children. If the numbers wo…

What makes you quite certain about your 1-1000 number? It’s really easy to mistake our experience for something generalizable.

It's hard to say without data, but the number is so astonishingly high that, really, the first reaction is to call it into question.

It also seems to be the kind of thing that is hard to measure.

Re: One Bad Apple

#328

Good article, however- "Due to how Apple handles cryptography (for your privacy), it is very hard (if not impossible) for them to access content in your iCloud account. Your content is encrypted in their cloud, and they don't have access. If Apple wants to crack down on CSAM, then they have to do it on your Apple device" I do not believe this is true. Maybe one day it will be true and Apple is planning for it, but ri…

> why Apple needs to do this on device Presumably to implement E2E encryption, while at the same time helping the NCMEC to push for legislation to make it illegal to offer E2E encryption without this backdoor. Apple users would be slightly better off than the status quo, but worse off than if Apple simply implemented real E2E without backdoors, and everyone else's privacy will be impacted by the backdoors that the NC…

Whether users are worse off or not entirely depends on the rate of false positives. That's the biggest issue IMO and OP's article points out how there is zero published and trustworthy information on that.

Re: One Bad Apple

#329
post #121

I'm honestly shocked that Apple is buying into this because it's one of those well-intentioned ideas that is just incredibly bad. It also goes to show you can justify pretty much anything by saying it fights terrorism or child exploitation. We went through this 20+ years ago when US companies then couldn't export "strong" encryption (being stronger than 40 bits if you can believe that). Even at the time that was ridi…

>So these photos exist on Apple servers but what they're proposing, if I understand it correctly, is that that data will no longer be protected on their servers. That is, human review will be required in some cases. By definition that means the data can be decrypted. Of course it'll be by (or intended to be by) authorized individuals using a secured, audited system. Apple has always had the decryption keys for encryp…

OPs article cites the number of NCMEC reports from Apple vs. other tech giants (200 something vs 20 million something at Facebook). It is all a bit confusing and I expect most of us are learning more about iCloud than we ever planned on; Apple has been able to decrypt our iCloud photos all along but those reporting figures make it pretty clear that they haven’t been doing so en masse. This is a big shift.

Re: One Bad Apple

#330
post #288
post #280

Earlier quoted context omitted.

What seems naive? Adding hashes will only match images, not other files, and even then only if a group is matched, not just one.

Because people take and store images of huge numbers of different things? Like the things mentioned upthread, memes, documents? along with screenshots of a huge number of other things. And the details around matching (and groups, etc) are trivial to change in a later update.

> or other files will be scanned since now

Ok, so not other files at all then. Just photos of documents.

> And the details around matching (and groups, etc) are trivial to change in a later update.

Ok, so this mechanism can’t do more than us claimed, but they could add a new mechanism later?

Post reply on HN