Earlier quoted context omitted.
Correct. The one odd thing I don't get. It would be a lot EASIER to just scan everything when its in the cloud itself. Why go to this trouble to avoid looking at users photos in the cloud, set these thresholds etc. You'd only need to scan on device if for some reason you blocked your own ability to scan in cloud (ie, for E2E photos - which I don't think users actually want).
Something like all of iCloud getting E2EE would be a big feature and likely only be announced at an event. I agree, if the CSAM on device scanning isn’t followed on by something else, it seems like a lot of work and PR flak for little gain.
The deceptive PR behind Apple’s “expanded protections for children”
341–350 of 595 posts
Re: The deceptive PR behind Apple’s “expanded protections for children”
#342Earlier quoted context omitted.
These illegal photos are not trivial to obtain. Possessing (and here, the printing step necessitates possession) these illegal photos is in and of itself a crime in most relevant jurisdictions. But OK, let's say that you've found a way to get the photos and you're comfortable with the criminal implications of that. At that point why don't you just hide the printed photos in your coworker's desk? My point is that if y…
An “interesting” part of this is, up until now these photos had little technical exposure. But now that millions of phones can be affected, creating unrelated pictures that purposefully match these hashes becomes a shinny target.
If someone wanted to generate a false positive image, they could already leverage it on these other platforms.
Re: The deceptive PR behind Apple’s “expanded protections for children”
#343>The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember) people really need to retire this meme. On the desktop in particular as a dev environment Linux is completely fine at this point. I can understand people not wanting to run a custom phone OS because that really is a ton of work but for working software de…
Re: The deceptive PR behind Apple’s “expanded protections for children”
#344Earlier quoted context omitted.
From https://www.hackerfactor.com/blog/index.php?/archives/929-On... > The laws related to CSAM are very explicit. 18 U.S. Code § 2252 states that knowingly transferring CSAM material is a felony. (The only exception, in 2258A, is when it is reported to NCMEC.) In this case, Apple has a very strong reason to believe they are transferring CSAM material, and they are sending it to Apple -- not NCMEC. > It does not matt…
It’s good to know that if I use the “section” glyph in an otherwise completely false analysis born of extending my experience past where I’m competent, readers will quickly repeat whatever it is I said as factual and “quite irrefutable”. The power of one blog post is quite something. You’re the third person I’ve seen quote that very post and go “welp, sure is a smoking gun” despite it being completely, utterly, demon…
You WILL be downvoted.
I'm a parent, it's also crazy to me how THIS of all things is where folks are going crazy over privacy. Literally, they will build something to track your every mouse move, scan every photo, log and sell all your browsing history and TV watching history (including big ISPs and mfgs).
And this is the thing folks get outraged about? Apple can already scan your stuff on their servers (and should!).
Instead of apple being charged criminally, other companies that do any kind of E2E without this may be required to do something like this. That's my prediction.
We will see if these "irrefutable" claims amount to anything like a child porn charge against apple.
Re: The deceptive PR behind Apple’s “expanded protections for children”
#345Earlier quoted context omitted.
There will only be an alert if that photo is extremely similar to an image in the NCMEC database, AND there are numerous other such photos on the account that match. The threshold number of matches to trigger an alert is tuned for a 1/trillion chance of false positive. Furthermore, if you were using say Google Photos to store your images, then you were already subject to this vulnerability.
So what if a small circle of people produce their CSAM material by themselves and share only among themselves? None of the pictures is being uploaded to that database, so either the algorithms are really really good at recognizing them, or it will require human intervention, that is, scanning one by one all phones, then deciding which picture matches the criteria and write down the names of the people involved. I can…
However, if at any point one of them screws up and shares a known CSAM image, the entire ring can be caught. This is not actually an implausible scenario. See for example: https://twitter.com/alexstamos/status/1424037132201431045?s=...
Re: The deceptive PR behind Apple’s “expanded protections for children”
#346Earlier quoted context omitted.
That strategy will last ~15 minutes until Google is doing the same thing. Then what? I would argue that what Google is doing already is way more privacy-compromising than this.
Google couldn’t do it, not effectively anyway because android vendors and variants are decentralised. They could do it for the pixels but that represents less thats half a percent of the market - not to mention that everyone on a pixel could just move to lineageOS if they didn’t like it. That freedom and decentralisation doesn’t exist on Apple (at least yet, maybe the DOJ or congress will regulate them).
Re: The deceptive PR behind Apple’s “expanded protections for children”
#347Earlier quoted context omitted.
The false positive rate for any given image is not 1 in a trillion. Perceptual hashing just does not work like that. It also suffers from the birthday paradox problem - as the database expands, and the total number of pictures expands, collisions become more likely. The parent poster does make the mistake of assuming that other pictures of kids will likely cause false positives. Anything could trigger a false positiv…
Then where are the news reports or articles of these false positives that would have shown up within the past decade? That's how long these companies have been using PhotoDNA on the server side. And the version of PhotoDNA from ten years ago would probably have been inferior to the version in place now. Is there even a single verifiable report of such a false positive? I feel that with the amount of attention brought…
Because going to court is extremely expensive?
Because retaining legal council is extremely expensive?
Because your district attorney will likely inflate the charges to coerce you into taking a plea deal, despite your innocence?
Because you don't want all of your private documents, including ones completely unrelated to the alleged crime, entered into the court records?
Because a "jury of your peers" can be convinced to believe just about anything?
Because even if you're acquitted, most people will still believe you're guilty, and treat you as such?
There are a myriad of reasons one shouldn't let the police go on mass criminal fishing expeditions. A lot of innocent people take collateral damage as a direct result of the incentives involved in an adversarial justice system.
Re: The deceptive PR behind Apple’s “expanded protections for children”
#348Earlier quoted context omitted.
The false positive rate for any given image is not 1 in a trillion. Perceptual hashing just does not work like that. It also suffers from the birthday paradox problem - as the database expands, and the total number of pictures expands, collisions become more likely. The parent poster does make the mistake of assuming that other pictures of kids will likely cause false positives. Anything could trigger a false positiv…
> Anything could trigger a false positive Don't you think Apple has independently arrived at that very same possibility? Maybe even thought about it and extensively tested it? Then put a probability on it? And then chosen the threshold such that the overall probability of falsely flagging an account is, indeed, minuscule?
Re: The deceptive PR behind Apple’s “expanded protections for children”
#349Earlier quoted context omitted.
> "visual derivative". Do you have any idea that means? Because I certainly don't - how could you possibly identify whether an image is CSAM without looking at something which is reasonably the same image? What is a visual derivative? Take that algorithm and run it over some normal images and show me what they look like. All of this is being aggressively talked around because everyone knows it's not going to stand up…
> Do you have any idea that means? No, I don't know what that means. Presumably it is some sort of thumbnail, maybe color inverted or something. > does Apple's implementation flag on any of those? Who knows - they're not going to refer to anything specific about how they got "1 in a trillion" I assume they've tested NeuralHash on big datasets of innocuous pictures, and gotten some sort of bound on the probability of…
What's interesting about this faulty argument is that it hinges an assumption that "innocuous pictures" is a well defined space that you can use for testing and get reliable predictions from.
A neural network does classification by drawing a complex curve between one large set and another large set on a high dimensional feature space. The problem is those features can include, often include, incidental things like lighting, subject placement and so-forth. And this often work because your target data set really does uniquely have feature X. So you can get a result that your system can reliably find X but when you go out to the real world, you find those incidental features.
I don't know exactly how the NeuralHash works but I'd presume it has the same fundamental limitations. It has to find images even they've been put through easy filters that are going to change every particular pixel so it's hard to see how it wouldn't find picture A that looking like picture B if you squint.
Re: The deceptive PR behind Apple’s “expanded protections for children”
#350Earlier quoted context omitted.
The false positive rate for any given image is not 1 in a trillion. Perceptual hashing just does not work like that. It also suffers from the birthday paradox problem - as the database expands, and the total number of pictures expands, collisions become more likely. The parent poster does make the mistake of assuming that other pictures of kids will likely cause false positives. Anything could trigger a false positiv…
Then where are the news reports or articles of these false positives that would have shown up within the past decade? That's how long these companies have been using PhotoDNA on the server side. And the version of PhotoDNA from ten years ago would probably have been inferior to the version in place now. Is there even a single verifiable report of such a false positive? I feel that with the amount of attention brought…
Positives get reviewed by humans, at which point false positives are identified and discarded. We would not hear about them, and there would not be any reporting about them in the press.
You might think that this is the system working as intended, but I do not and would never consent to Apple giving my photos to some random anon to look at.