Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

351–360 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#351

Earlier quoted context omitted.

There are numerous incorrect statements in your comment. First: Apple has disclosed who gets to curate the hash list. The answer is NCMEC and other child safety organizations. https://twitter.com/AlexMartin/status/1424703642913935374/ph... Apple states point-blank that they will refuse any demands to add non-CSAM content to the lists. Second: Why can't the FBI / CCCP inject a hash into the list. Here's a tweet thread…

How do you know there aren’t bad actors working at the NCMEC? If I know that adding a hash to a list will get it flagged, and I could conveniently arrest or discredit anyone I wanted, I would certainly send people to work there. How will Apple know whether a hash is for non-CSAM content? Spoiler alert: they won’t. And Apple claims it will be reviewed by a human. Sure, just like YouTube copyright claims? Or will it ge…

> How will Apple know whether a hash is for non-CSAM content? Spoiler alert: they won’t.

As I said, the flagged content is reviewed by an Apple employee before it actually triggers an external report. If the flagged material is not in fact CSAM, it will not be reported.

> And Apple claims it will be reviewed by a human. Sure, just like YouTube copyright claims? Or will it get automated in the near future? And what about in China? Or Saudi Arabia or other countries with less human rights?

First of all, the volume of flagged CSAM content is much, much smaller than the volume of YouTube copyright claims. It's entirely plausible to ensure that a human reviews all flags. Second, Apple is actually constitutionally-barred from automating this step entirely. You can thank Neil Gorsuch's decision in United States v. Ackerman for this. [1] The crux is that since NCMEC is a qausi-governmental entity, automatically sending CSAM-matched content to NCMEC without an Apple employee first inspecting the content would constitute an unreasonable search and seizure and would violate the 4th amendment.

[1] https://library.law.virginia.edu/gorsuchproject/united-state...

Re: The deceptive PR behind Apple’s “expanded protections for children”

#352
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

I have tried to play around with perceptual hashing on an image set consisting of very similar images (flowers) and there were clashes all the time.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#353
post #220

Earlier quoted context omitted.

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

I think most people don't upload to facebook pictures of their kids taking a bath? But they more than likely store such pictures on their phones/laptops.

Sure, but none of those images will be a hash match to any material in NCMEC databases.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#354

>The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember) people really need to retire this meme. On the desktop in particular as a dev environment Linux is completely fine at this point. I can understand people not wanting to run a custom phone OS because that really is a ton of work but for working software de…

Good luck if you have two screens with different DPIs.

Hello, user with two screens with two different DPIs (and two separate resolutions as well, and one of them a giant touch-screen drawing tablet). Nice to meet you, I use Arch btw.

X11's handling of different DPIs is annoying but workable; there's a couple of different possible methods of handling it that have their own pros/cons. Per-monitor scaling is supported, but I personally don't like the way it's handled, so instead I just pick a happy medium scaling that works OK for both monitors. My understanding is that Wayland makes this easier, but I haven't switched over yet because I'm waiting either for GPU prices to drop or for NVidia to figure out whether it's ever going to play nice with Wayland.

There are definitely pain points with Linux, but it's completely serviceable as a workstation computer, the meme is really dead at this point. If you're on a touchscreen device, Gnome's most recent release arguably has comparable if not better touch handling than Windows (admittedly not a high bar to clear, but remarkable considering how bad Linux's touchscreen support used to be). I use a Mac at work so I'll fit in with my coworkers, but outside of work I do not own a single computer with Windows installed on it.

I'm not going to tell everyone to switch to Linux, there are very valid reasons why someone might not want to, including an increased technical burden. That's real, it's just not the giant hurdle that a lot of people seem to think it is. The "year of the Linux desktop" is really out of touch in my experience, modern Linux as a desktop OS is fine; it's perfectly serviceable as a professional environment for a lot of people. I use Linux in part because it makes it easier for me to get an ergonomic setup for drawing tablets, device compatibility, etc...

And at some point I figured out that I don't really care what desktop Linux's market share is, because even <1% still seems to be big enough that the desktop stays usable for professional work and for more complicated device/media setups, which is all I need it to do.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#355

Earlier quoted context omitted.

That 1/1t rate apple gave is post human review according to a recent interview

Do you have a link to that interview? That's a really big asterisk on the "one in a trillion" claim if true.

According to Apple's technical summary:

"The threshold is selected to provide an extremely low (1 in 1 trillion) probability of incorrectly flagging a given account. This is further mitigated by a manual review process wherein Apple reviews each report to confirm there is a match..."

So no, "one in a trillion" doesn't include manual review.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#356
post #209

Earlier quoted context omitted.

You agreed to the EULA :)

I'm not sure EULA's can effectively bargain away US constitutional protections.

Where does the constitution come into play here? This is a private company scanning content uploaded to its own servers.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#357

Earlier quoted context omitted.

The false positive rate for any given image is not 1 in a trillion. Perceptual hashing just does not work like that. It also suffers from the birthday paradox problem - as the database expands, and the total number of pictures expands, collisions become more likely. The parent poster does make the mistake of assuming that other pictures of kids will likely cause false positives. Anything could trigger a false positiv…

Then where are the news reports or articles of these false positives that would have shown up within the past decade? That's how long these companies have been using PhotoDNA on the server side. And the version of PhotoDNA from ten years ago would probably have been inferior to the version in place now. Is there even a single verifiable report of such a false positive? I feel that with the amount of attention brought…

Kinda funny how almost every leaker or hacker in the last decade always seems to end up with child pornography in some way, shape, or form once the authorities get to them. Besides which, law enforcement isn't picky about when they pick people up.

>The issue in that case is the violation of the innocent person's privacy, not that they have a risk of being falsely convicted. The courts would still need admissible evidence, and I don't believe that only having a perceptual hash and a set of legally photographed images clears that bar.

So... You admit that this type of scanning is an invasion of privacy, and would likely be a flagrant constitutional violation if done by the Government?

So why is it okie-dokie for the private sector to do this type of systematic check and balance evasion? That's what gets to me.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#358

Earlier quoted context omitted.

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

The false positive rate for any given image is not 1 in a trillion. Perceptual hashing just does not work like that. It also suffers from the birthday paradox problem - as the database expands, and the total number of pictures expands, collisions become more likely. The parent poster does make the mistake of assuming that other pictures of kids will likely cause false positives. Anything could trigger a false positiv…

My guess is that the one in a trillion figure includes the threshold that must be exceeded, requiring multiple false positives, bringing the full chance of your account being flagged to 1 in a trillion.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#359
post #61

Earlier quoted context omitted.

> The end isn't really compromised with their described implementation. They've turned your device into a dragnet for content the powers that be don't like. It could be anything. They're not telling you. And you're blindly trusting them to have your interests at heart, to never change their promise. You don't even know these people. You seriously want to cuddle up with that?

> "They've turned your device into a dragnet for content the powers that be don't like. It could be anything. They're not telling you" They're pretty explicitly telling us what it's for and what it's not for. > "And you're blindly trusting them to have your interests at heart, to never change their promise. You don't even know these people." You should probably get to work building your own phone, along with your own…

> They're pretty explicitly telling us what it's for and what it's not for.

Nobody should blindly trust Apple. As an organization, they already love secrecy and shadows--what better place to sneak in and test this kind of feature, free from employee ethics and scrutiny?

They've been cooking this up without telling anyone, which is also indicative of how above board they are. Who knows what else they're doing with this now or will do in the future.

The CIA, FBI, MI6, Mossad, FSB, CCP, et al. will use this to learn more about their targets.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#360

>The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember) people really need to retire this meme. On the desktop in particular as a dev environment Linux is completely fine at this point. I can understand people not wanting to run a custom phone OS because that really is a ton of work but for working software de…

I’ve been using Ubuntu and now pop os on a Thinkpad for a couple years now, and I don’t miss Windows (which I used since…well, DOS 6) at all. Quite the opposite. As time goes on, seeing what’s happening with MacOS and Windows, I’m more and more happy that my computer is actually my computer.
Post reply on HN