Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

351–360 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#351

Earlier quoted context omitted.

But we've already established there is no public oversight over the contents of the NCMEC database and that there cannot ever be, by design. Furthermore, it's known to contain hashes of non-CSAE images simply because they were found in a CSAE-related context. So how can this system guarantee civil freedom? How can it be guaranteed that it won't be exploited by the small number of people in power to actually inspect i…

Have we established that? Certainly not a reality I recognize. The processes involved in CSAM databases like NCMEC/ICSE are many years old. If it leads to widespread civil rights abuses, where are they? Google Drive has 1bn users. Google scans content for CSAM already. Shouldn't we be seeing these negative side effects already? Proponents of these systems can point to thousands upon thousands of actual "wins" (such a…

“ detractors cannot provide actual evidence of their theoretical disadvantages.”

This is the concern. The system is hidden and you have no way to challenge. You are simply “trusting” that this system is working well

Who watches the watchers?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#352
post #252
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

I actually view this as not a good sign. That many are still in the very very early stage of shock, what Apple is doing does not align with their perceived values. Deducting points from Apple in their own mental model. They write these letter because they think Apple is still mostly good and hope they could have a change of heart. What would happen as some others have pointed out, people will forget about it. Apple w…

Depends Apple is on my "call first list now" on my CV along with Chem and Bio weapons and payday loan type companies.

And I wont be buying the ipad I was thinking about.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#353
post #346
post #254

Earlier quoted context omitted.

Oh absolutely, the laws that started all of this are terribly thought through, all a child pornographer has to do to avoid these controls is not use iCloud Photo Library. That's it, just do that and they can have as much child porn on their phones as they like, and share it however they like using iMessage or anything else.

> all a child pornographer has to do to avoid these controls is not use iCloud Photo Library Yes, so as it is today , this system isn't even useful for its stated purpose. Apple are not so stupid that they don't know that. Either it will not always be as it is today, or the stated original purpose isn't the ultimate purpose. After all, the problem you state has a simple and obvious solution: just scan everything on t…

Or maybe be they are just doing what they said they are doing for the reasons they gave, to comply with the law, and that’s that. But apparently that not even a possibility you can conceive of.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#354

Earlier quoted context omitted.

> I am currently planning the migration away from the Apple ecosystem Me too. I told my wife today that I'll be looking at a feature phone as I'm not sure I can be bothered with jumping through all the hoops required to de-Google an Android phone. I remember a time before mobile phones, I was just fine without one - smartphones aren't that good, just convenient.

It's good that you're principled enough to do that but you guys will be rounding errors in Apple's revenue. Most people don't even know about this and those that do, most wont care. Even of those who do know and do care, most aren't motivated enough to change their habits beyond writing a few angry words on a forum Apple are never going to read anyway. Those that do change their buying habits, yourselves, are by far…

The best you can do is raise tech awareness, take apple interviews and cite this reason for not moving forward. Facebook faced constraint not just after a avalanche of bad press but also as the tech workers (employees and applicants) pushed back and worked to improve things. The biggest asset in information economy is the people; the employees can enact change. See many examples in how Google direction has been influenced in military contracts or what not.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#355

Earlier quoted context omitted.

I suspect it might be more effective to go to an Apple store and attempt to return your iphone and iPad (though probably they are outside of return windows.) I’m seriously considering doing that. Make it painful for the local staff by demanding a refund. Don’t take no for an answer for quite some time. Explain that they just broke the product with a remote update that you had no choice in, so thats why you’re only re…

> Explain that they just broke the product with a remote update that you had no choice in... Except when you turned on the phone, you agreed to automatic updates. Contract law isn't on your side.

No, I didn't agree to automatic updates by turning it on. In fact, I don't have automatic updates turned on.

What happened is that I updated based on what Apple claimed the update did, but they were lying. Contract law would seem to be on my side in such a case.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#356
post #268

Earlier quoted context omitted.

> a non-insignificant amount of people in tech take this seriously We're all here to make ourselves feel good saying we Took A Stand. In reality, four weeks from now, do you think anybody will still be talking about it? I made this same mistake. I was pretty convinced that people were taking Copilot seriously, and that there was possibly going to be ramifications for Microsoft. I wasn't particularly looking forward t…

>I'm not sure what to do about it For starters, please give up the defeatist attitude. They deserve the frontlash; even if it serves no purpose, as you describe it. Apple have placed 'Privacy' at the core of their messaging, in order to sell their high-end products. In comparison to the already excessive pearl clutching based on moral panic within the ecosystem e.g. sanitising and censoring language and apps. This is…

They’ll scan content if you have it set to goto iCloud so as to avoid being an accomplice.

Turn off sync to iCloud, make local backups only.

Who is to say politicians who started threatening tech companies publicly haven’t made threats behind closed doors about Apple maybe being on the hook as an accomplice for distribution?

My company only exists because our CEO had input on an executive order years ago. We hardly “made it” in the free market.

The headlines never tell the full story. Media colludes with politics to generate “the right” sentiment. The spec and implementation details aren’t being discussed, just classic speculation on privacy and overreach.

So much for this site having a higher level of discourse and it’s efforts to dissuade repetitive and knee jerk commentary though.

We’d have nicer things if we discussed how things work and instead of what corporate media wants us to discuss.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#358

Earlier quoted context omitted.

Have we established that? Certainly not a reality I recognize. The processes involved in CSAM databases like NCMEC/ICSE are many years old. If it leads to widespread civil rights abuses, where are they? Google Drive has 1bn users. Google scans content for CSAM already. Shouldn't we be seeing these negative side effects already? Proponents of these systems can point to thousands upon thousands of actual "wins" (such a…

“ detractors cannot provide actual evidence of their theoretical disadvantages.” This is the concern. The system is hidden and you have no way to challenge. You are simply “trusting” that this system is working well Who watches the watchers?

That’s the major concern I have: take as a given that NCMEC is on the side of the angels here, what happens when some government demands that Apple help identify anyone who has an image shared from a protest, leak, an underground political movement, etc.? The database is private by necessity, so there’s no way to audit for updates.

Now, currently this is only applied to iCloud photos which can already be scanned server side, making this seem like a likely step towards end to end encryption of iCloud photos but not a major change from a privacy perspective. What seems like more of a change would be if it extended to non-cloud photos or the iMessage nude detection scanner since those aren’t currently monitored, and in the latter case false positives become a major consideration if it tries to handle new content of this class as well.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#359

Earlier quoted context omitted.

> 1. Vote with your feet - Put your money in the pockets of the people aligned to your values. This is impossible. Just like modern democratic voting, you don’t get to vote on an individual policy. You vote on a bundle and that bundle almost certainly includes policies (or in this case “features”) that you don’t agree with.

So? If a corporation (or political party) does a shockingly egregious thing that doesn't align with your values then you absolutely should switch to an alternative that supports your values.

What if all of them do at least one egregious thing? Especially when "all" means just apple and Google?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#360
post #331

Earlier quoted context omitted.

>How often do you come into contact with the OS when developing for a phone, let alone use a phone That's exactly the point, Maybe you don't know what Plan9 is, but see it like that: The Phone is just a Terminal. If i want todo business i connect my terminal to my Workplace-servers, every application, datas and settings are there, the calculation heavy stuff and backup is made on the server. If finished i connect to…

Slightly problematic when your phone loses service, but I get where you are coming from. It would be nice for that to be viable, we’re probably decades away from having good enough network connectivity.

Truetrue, it need's some caching and cpu capability, like the map when your offline...stuff like that..but with 5G...well we will see ;)
Post reply on HN