Live data from Hacker News

One Bad Apple

hackerfactor.com

341–350 of 557 posts

Re: One Bad Apple

#341
post #294

Earlier quoted context omitted.

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

> Why haven't I made my whitepaper about PhotoDNA public? In my view, who would it help? It would help bad guys avoid detection and it will help malcontents manufacture false-positives. The paper won't help NCMEC, ICACs, or related law enforcement. It won't help victims. Making it public would allow the public to scrutinize it, attack it, if you will, so that we can get to the bottom of how bad this technology is. Ul…

PhotoDNA is a very simple algorithm. Reproducing what OP did to "reverse engineer" is not hard. If you really have the guts to try this go ahead and you'll be surprised. I'm living in the US with a greencard so I'm not touching the problem even with a laser pointer.

The techno-legal framework is worse than just "reversing the hashes is possible". You could brute force creation of matching images using a cloud service or online chat as an "oracle".

Re: One Bad Apple

#342
post #9
post #5

Earlier quoted context omitted.

What does "manual review" mean then and how are those images reported?

Before: you would upload images to iCloud Photos. Apple can access your images in iCloud Photos, but it does not. Now: You upload images to iCloud Photos. When doing so, your device also uploads a separate safety voucher for the image. If there are enough vouchers for CSAM matched images in your library, Apple gains the ability to access the data in the vouchers for images matching CSAM. One of the data elements in t…

> access the data in the vouchers for images matching CSAM. One of the data elements in the voucher is an “image derivative” (probably a thumbnail)

So the author of the article is technically correct: Apple intentionally uploads CP to their servers for manual review which is explicitly forbidden by law.

He even describes the issue with thumbnails

Re: One Bad Apple

#343

Earlier quoted context omitted.

Why shouldn't every Neuralink come with a mandated FBI module preinstalled? Where, if anywhere , is private life to remain, where citizens think and communicate freely? Is Xinjiang just the start for the whole world?

Surely there is communication surrounding the child sexual abuse, making plans with other pedophiles and discussing strategies. Some of this may occur over text message. Maybe Apple’s next iteration of this technology can use my $1000 phone that I bought and that I own to surveil my E2EE private encrypted messages on my phone and generate a safety voucher for anything I say? The sky’s the limit!

Good point: neural nets are getting better at natural language every year.

Re: One Bad Apple

#344

I don't see many people pushing back on the child pornography laws themselves that are the cause of this. I'm stepping into a hornets nest by even bringing this up, because any criticism of the laws on the books makes one look they're a pedo, so I'll preface by saying, child pornography (filmed with actual kids) is vile and disgusting, but it is the production of it that is evil to be fought and suppressed, not the p…

Relatedly, I don't see much discussion around the nuances of what counts as cp. In my experience, the vast majority of cp people are likely to come into contact with is "consensual" (the definition of consent gets weird here) images taken by teenagers of themselves, not old men raping little kids. So what happens if a 17 year old girl takes pictures of herself, sends them to her partner, they break up, he posts them…

Sure there’s probably orders of magnitudes more of that content. But that’s not what most people are targeting I think with these laws and tech. I believe when I read some of NYT (Gabriel J.X. Dance?) on this a while back it was explicitly about child abuse not “oops older teens”.

Re: One Bad Apple

#345

Earlier quoted context omitted.

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

> About this time, someone usually mocks "it's always about the kids, think about the kids." To those critics: They have not seen the scope of this problem or the long term impact. The problem is people use this perfectly legitimate problem to justify anything. They think it's okay to surveil the entire world because children are suffering. There are no limits they won't exceed, no lines they won't cross in the name…

Yeah, and none of these assholes (pardon the language) is willing to spend a penny to provide for millions of children suffering of poverty: free education, food, health, parental support. Nothing, zero, zilch. And these millions are suffering right now, this second, with life-long physical and psychological traumas that will perpetuate this poverty spiral forever.

Re: One Bad Apple

#346

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

How feasible is it to change the algorithm to flag police uniforms? The Tank Man?

Re: One Bad Apple

#347
post #61

Earlier quoted context omitted.

They could have done all that without telling you. And as long as the traffic was combined with normal traffic no one would ever notice (and in this case it would end up mixed with normal traffic since it only applies to images being uploaded to iCloud, so communication with Apples servers would be expected). What it looks like to me is that Apple is planning on releasing end-to-end encryption for iCloud. But they kn…

If this is a prelude to E2E encryption for iCloud they are going to be under TREMENDOUS pressure from law enforcement to expand the list of bad material way beyond just CSAM.

Not if it's only E2EE for photos

Re: One Bad Apple

#348
post #332

Earlier quoted context omitted.

You can label it collusion, but when Apple does it, it's going to call it _complying with local regulation_.

It doesn’t matter what you label it. Hand wringing over making things worse in China is not a valid concern.

I'm old enough to remember when the revelation that NSA is spying on everyone was a shock.

Now people are seriously arguing that continuous searching through your entire life without any warrant or justification by opaque algorithms is fine.

It only took what, 10 years?

Re: One Bad Apple

#350

Earlier quoted context omitted.

A set of unverified hashes that you hope only came from NCMEC. Telecoms do this on their own devices - not yours. Apple just opened the door for constant searches of your digital devices. If you think it will stop at CSAM you have never read a history book - the single biggest user of UKs camera system originally intended for serious crimes are housing councils checking to see who didn't clean up after their dog.

> the single biggest user of UKs camera system originally intended for serious crimes are housing councils checking to see who didn't clean up after their dog. Which camera system? Do you have a citation for that?

That's absolute nonsense but it's one of those things where I'd be interested to try and unpick the provenance of how someone could believe something so ridiculous.
Post reply on HN