Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

361–370 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#361

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

> This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy.

yes, but at least they are telling the truth now...

Re: Apple's child protection features spark concern within its own ranks: sources

#362

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

That would be the best case scenario, but then why wouldn’t they come out and say that?

They could have announced this all in one shot and saved themselves a lot of blowback.

I believe they have to understand that, which makes me think the theory of them planning to add E2E may not be true.

Re: Apple's child protection features spark concern within its own ranks: sources

#363

Earlier quoted context omitted.

Important adjustment -- privacy and surveillance are what's on a spectrum. Security is not the inverse of privacy.

I was going to say; I'm aware security is always a compromise (vs speed or ease of use or budget etc), but I've never seen that privacy and security are the natural opposites / inverses in same spectrum.

"Security vs privacy" is unfortunately the most common mistake made about privacy discussions.

Re: Apple's child protection features spark concern within its own ranks: sources

#364
post #198
post #167

I just do not want Apple scanning my phone for the purpose of finding something they can send to the police. I’m not even talking about any “slippery slope” scenarios and I’ll never have any of the material they are looking for. And right or wrong, I don’t really fear a false identification, so this isn’t about a worry that they will actually turn me in. I just don’t want them scanning my phone for the purpose of tur…

This is the most honest take on this that I’ve seen. The slippery slope arguments don’t make sense, nor does the risk of false positives. But the idea of being suspected even in this abstract way, because of something other people do , is at the very least distasteful, bordering on offensive.

I would not say the slippery slope take doesn't make sense. It is perfectly possible that had no one cried out about this change then the next change would have been:

Large government to Apple: "Please now also create a hash on each photo metadata field including date/time and location. Let us query these. AND BTW, this change must be kept secret. Thanks."

Re: Apple's child protection features spark concern within its own ranks: sources

#365

Earlier quoted context omitted.

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

Something probably did happen. Apple no doubt became increasingly aware of just how legally culpable they are for photos uploaded to iCloud. For content that is pirated Apple would receive a slap on the wrist, but for content that shows the exploitation of children? And that Apple is hosting on their owned servers? There is no doubt every government will throw their full legal weight behind that case. Now they are st…

They could just keep scanning the data stored on their servers like everyone else does (Google, Etc) and leave it at that.

Re: Apple's child protection features spark concern within its own ranks: sources

#366
post #292

Apple's track record on user protection compared to Google or Samsung has been very good. For example, resisting wide net Federal "because terrorism" warrants as much as they legally can. There's a reason why Apple 0 day exploits sell for way more on the black market than Android exploits. Trust is hard to earn, easy to lose and even harder to regain. User trust is such a huge part of Apple's business and success, it…

And yet, the way Apple openly operates iCloud in China is infinitely worse than Google's Dragonfly ever could have been. Apple's reputation for privacy is entirely undeserved.

Re: Apple's child protection features spark concern within its own ranks: sources

#367

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

I sold all the Netflix stock I had purchased when they announced Qwikster. Woe is me!

Re: Apple's child protection features spark concern within its own ranks: sources

#368

Earlier quoted context omitted.

I just mean that there's an intuitive sense of ownership over a physical device that you don't have over data stored in the cloud. My point is that this distinction is artificial. You don't really own the (software on the) device, but you should own the data the company is processing on your behalf. Whether this processing happens on the physical device or in the cloud seems like an irrelevant distinction.

Appreciate the context. I like this take as well, it brings up questions about what "ownership" really means. Where do you land on privacy then, do you go radically open or radically closed, something else?

To me ownership means I have exclusive control over who gets to use something and for what purpose. If I own my data, someone processing this data on my behalf has no right or obligation to scan it for illegal content. The fact that this data sometimes sits on hard drives owned by another party just isn't a relevant factor. Presumably I still own my car when it sits in the garage at the shop. They have no right to use it outside of purposes explicitly agreed upon. I don't see abstract data as any different.

Personally, I strongly favor privacy. I avoid all cloud services that don't involve local encryption. I have an old model rooted android phone with two firewalls. All apps have internet access blocked by default. I stay as anonymous as possible on social media. And so on. Recently my group at work moved our repositories to Github Enterprise. It made me uncomfortable. I voiced my concerns but they fell on deaf ears.

Re: Apple's child protection features spark concern within its own ranks: sources

#369

Earlier quoted context omitted.

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

Something probably did happen. Apple no doubt became increasingly aware of just how legally culpable they are for photos uploaded to iCloud. For content that is pirated Apple would receive a slap on the wrist, but for content that shows the exploitation of children? And that Apple is hosting on their owned servers? There is no doubt every government will throw their full legal weight behind that case. Now they are st…

Then grow a pair and point at government influence. Leak DOJ demand letters. Do something to indicate this was forced on them. Or is a gag order in place? That’s my bet right now.

Re: Apple's child protection features spark concern within its own ranks: sources

#370
0. I've initially been ambivalent or even supportive of Apple on this, because much of the initial criticism was uninformed and easily refuted, or hysterical. But I'm getting around to this being a momentous blunder.

1. I understand Apple doesn't like to discuss its plans publicly, but rather present the final product when it is ready to ship. But if anything was a good candidate for one of the rare exceptions, then this, no?

2. Why announce unambiguously that this feature is "available" in the US only at first, in other words, can be enabled/disabled/configured per region? What is the plan when country X comes and says "fine feature you've built there, here's our list of perceptual hashes of illegal imagery, and the contact data of our competent authority to notify in case of matches."? Replying "ah, sorry, we can't" is not going to fly anymore, ever (!).

Even if they walk this back, what defence will they have left in the future if any government requires them to implement this odious feature and scan all images on-device and notify some authority if anything untoward (in that jurisdiction) is found?

Post reply on HN