Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

321–330 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#321

Earlier quoted context omitted.

While I knew that the "privacy" stance from Apple in prior years was always a marketing facade to sell more devices, I still continued to believe that they would keep sticking up for privacy as much as possible. It's kind of funny how I am very suspicious of governments and politicians but when it comes to a trillion dollar corporation, I was giving them more of benefit of doubt. I was wrong.

> I still continued to believe that they would keep sticking up for privacy as much as possible. Considering how often Apple gives up customer data without a fight when requested to by the government, I don't really believe that. According to Apple, they respond to government data requests with customers' data ~85% of the time, and 92% in cases of "emergencies"[1]. Apple gave customer data from over 31,000 users/acco…

I don’t know if the first half of 2020 is a good time frame for sampling as this is when the country had the largest amount of protests in history and the police are going to be making a lot of requests in retaliation.

Doesn’t make Apple look any better though. I’m curious about how often Google and Facebook hand over information.

Re: Apple's child protection features spark concern within its own ranks: sources

#322
States need to put a law on the books with fines to prevent faux encryption and scans without warrants which are unauthorized by the device owner, further consent may not be covered nor may electronic suppliers attempt to lease or license equipment to circumvent these protections.

Re: Apple's child protection features spark concern within its own ranks: sources

#323

Earlier quoted context omitted.

It’s silly to think the US government hasn’t been twisting their arm to do this for years.

My ears perk up whenever I hear a "Just think of the Children" argument because after Sandy Hook, I'm pretty certain the US could careless about children. There's a real reason behind this.

I feel like there’s a fallacy for this but I’m not sure. Either way doesn’t matter the logic here isn’t that the US could careless about children , it’s that the US cares more about Gun rights than it does children , but that doesn’t say anything about the minimum level of care they have , only the maximum.

Re: Apple's child protection features spark concern within its own ranks: sources

#324

Earlier quoted context omitted.

Woops, you're right, thanks for the correction. I think the issue is that, as Ben Thompson pointed out, the only thing preventing them from scanning other stuff now is just policy , not capability , and now that Pandora's box is open it's going to be much more difficult to resist when a government comes to them and says "we want you to scan messages for subversive content".

Given that they obviously already have the capability to send software updates that add new on-device capability, this seems like a meaningless distinction. It’s already “just policy” preventing them from sending any conceivable software update to their phones.

Making a custom OS update is pretty different from adding an entry into a database, and could also be mitigated against.

Re: Apple's child protection features spark concern within its own ranks: sources

#325

Earlier quoted context omitted.

Just think of it as a form of lobbying.

What's the end-game here? I don't follow.

I see it as Apple taking voluntary steps to prevent the Earn IT Act (or something similar) from becoming law in the US.

https://en.wikipedia.org/wiki/EARN_IT_Act_of_2020

Big tech companies are under a lot of US govt pressure right now to crack down on CSAM, most especially Apple because of their very low number of reports compared to most other tech giants. I think Apple saw this as a way to ease some of that government pressure while not jeopardizing their ability to use end-to-end encryption, which something like the EARN IT Act could effectively make illegal by requiring a government backdoor for all encrypted cloud services that operate in the US.

Apple probably saw the on-device CSAM scanning as a small, widely-acceptable concession to make that could prevent much bigger crackdowns, but maybe didn't anticipate the level of blowback from people seeing the CSAM scanning itself as an unacceptable government backdoor on their own device.

Re: Apple's child protection features spark concern within its own ranks: sources

#326
post #305

Earlier quoted context omitted.

Right, but the CSAM scanning routine is absurdly narrow and difficult to use for detecting anything but CSAM, whereas a general purpose hash matching algorithm really is just a few lines of code. This whole ‘now that they have a scanner it’s easier’ reasoning doesn’t make sense. iOS already had numerous better matching algorithms if your goal is to do general spying.

Isn't the scanning routine searching for fingerprints? What happens if someone adds a fingerprint to the database, which matches something other than CSAM?

No.

It’s way more complex than that, and has been engineered to prevent exactly that scenario.

I recommend you actually check out some of Apple’s material on this.

The idea that it’s just a list or fingerprints or hashes that can easily be repurposed is simply wrong, but is the root of almost all of the complaints.

Re: Apple's child protection features spark concern within its own ranks: sources

#327
I assume this is some sort of machine learning algorithm. How did they get the data set to train it on? That seems really strange. How did they test it? Seems like any engineers involved on this would come out with PTSD. Whatever they used to test it and train it with is illegal to possess and could only be used with some sort of massive government cooperation.

Re: Apple's child protection features spark concern within its own ranks: sources

#328
post #167

I just do not want Apple scanning my phone for the purpose of finding something they can send to the police. I’m not even talking about any “slippery slope” scenarios and I’ll never have any of the material they are looking for. And right or wrong, I don’t really fear a false identification, so this isn’t about a worry that they will actually turn me in. I just don’t want them scanning my phone for the purpose of tur…

I like this take. It shortcuts around all the "but people misunderstand the technology" back and forth and gets to the root of it. "Don't scan my phone for stuff you can send to the police."

Yup. We don't need to demand privacy as a means to an end, it is just respect I want from my belongings.

Re: Apple's child protection features spark concern within its own ranks: sources

#329

Earlier quoted context omitted.

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

That is, it seems like Apple really wanted to preserve "end-to-end" encryption,“ … except they still have not mentioned anything about E2E encryption… and they currently don’t encrypt icloud backups. You would think apple would get ahead of this story and mention … or maybe they don’t have any E2E plans at all.

Well, iCloud Photos are now ”kinda” E2E encrypted.

iOS 15 beta has new recovery option by secret (which is useful only on E2EE?)

And Child Safety was released most likely because the leaks. Motive of the leaks is unknown. They might be waiting for September now.

Re: Apple's child protection features spark concern within its own ranks: sources

#330
post #326

Earlier quoted context omitted.

Isn't the scanning routine searching for fingerprints? What happens if someone adds a fingerprint to the database, which matches something other than CSAM?

No. It’s way more complex than that, and has been engineered to prevent exactly that scenario. I recommend you actually check out some of Apple’s material on this. The idea that it’s just a list or fingerprints or hashes that can easily be repurposed is simply wrong, but is the root of almost all of the complaints.

I've looked through Apple's paper, what are you referring to?
Post reply on HN