Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

371–380 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#371

US Government: We suspect the person in this photo of committing a crime. Here is your subpoena, Apple. You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them. Chinese Government: Here is the NeuralHash for Tienanmen square. Delete all photos you find matching this or we will bar you from China. Apple has at this point already admitted thi…

> You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them.

I think the US Govt (and foreign) would actually send Apple tens of thousands of NeuralHashes a week. Why would they limit themselves? False positives are "free" to them.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#372

I know the privacy approach Apple has been pushing was just marketing, but I didn't care too much because I enjoyed my iPhone and M1 macbook. Because of this decision (and the fact that my iPhone more-or-less facilitates poor habits throughout my life), I'm considering moving completely out of the Apple ecosystem. Does anyone have any recommendations for replacements? * On laptops: I have an X1 carbon extreme running…

TBH I've been considering just dropping a smartphone all together, I don't really get much value out of it since i'm on my laptop most of the time when I want to internet anyway

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#373
I'm sorry, I just don't see how this is any different from Google auto-searching Google Drive files and flagging/deleting them. Apple is only doing this to "Apple Cloud" files and flagging/deleting them if they see them.

The best counterargument I've seen to that is that Apple is lying and it's not limited to Apple Cloud, unlike Google. However, no one yet has been able to substantiate that claim.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#374

It’s astounding how many very smart people are getting this wrong. Perhaps I missed it, but does anywhere on this letter mention that that both of these features are optional? CSAM depends on using iCloud Photos. Don’t rent someone else’s computer if you don’t want them to decide what you can put on it. Content filter for iMessages is for kids accounts only, and can be turned off. Or, even better: skip iMessages for…

this is how it always starts, Apple went from 'no it's not possible to unlock the shooters phone' to 'yeah you can give us the fingerprint of any image (maybe doucuments too) and we'll check which of our users has it'

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#375
post #355

Earlier quoted context omitted.

Hopefully this is another configurable option that falls under the already very extensive family screen time feature. I understand where you're coming from and respect your position, but I fall on the opposite side. This is something I do want for my kid.

You want Apple employees going trough naked photos of your kid and deciding if its child porn or not because the algo flagged it? Because that is what this means.

No, it doesn't. You have conflated two entirely different systems.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#376

It’s astounding how many very smart people are getting this wrong. Perhaps I missed it, but does anywhere on this letter mention that that both of these features are optional? CSAM depends on using iCloud Photos. Don’t rent someone else’s computer if you don’t want them to decide what you can put on it. Content filter for iMessages is for kids accounts only, and can be turned off. Or, even better: skip iMessages for…

Then why do the "CSAM" perceptual hashes live on the device and the checks themselves run on the device? Those hashes could be anything. Your phone is turning into a snitch against you, and the targeted content might be CCP Winnie the Pooh memes or content the people in charge do not like. We are not getting this wrong. Apple is taking an egregious step to satisfy the CCP and FBI. Future US politicians could easily b…

iCloud photos aren’t currently encrypted, but this system provides a clear path to doing that, while staving accusations that E2E of iCloud will allow people to host CP there with impunity.

When the device uploads an image it’s also required to upload a cryptographic blob derived from the CSAM database which can then be used by iCloud to identify photos that might match.

As built at the moment, your phone only “snitches” on you when it uploads a photo to iCloud. No uploads, no snitching.

We know that every other cloud provider scans uploads for CSAM, they just do it server side because their systems aren’t E2E.

This doesn’t change the fact that having such a scanning capability built into iOS is scary, or can be misused. But in its original conception, it’s not unreasonable for Apple to say that your device must provide a cryptographic attestation that data uploaded isn’t CP.

I think Apple is in a very hard place here. They’re almost certainly under significant pressure to prove their systems can’t be abused for storing or distributing CP, and coming out and saying they’ll do nothing to prevent CP is suicide. But equally the alternative is a horrific violation of privacy.

Unfortunately all this just points to a larger societal issue. Where CP has been weaponised, and authorities are more interested in preventing the distribution of CP, rather than it’s creation. Presumably because one of those is much easier to solve, and creates better headlines, than the other.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#377

It’s astounding how many very smart people are getting this wrong. Perhaps I missed it, but does anywhere on this letter mention that that both of these features are optional? CSAM depends on using iCloud Photos. Don’t rent someone else’s computer if you don’t want them to decide what you can put on it. Content filter for iMessages is for kids accounts only, and can be turned off. Or, even better: skip iMessages for…

The new system is overkill for iCloud, which Apple already scans. The obvious conclusion is Apple will start to scan photos kept on device, even where iCloud is not used. Very smart people are not getting this wrong.

>> The obvious conclusion is Apple will start to scan photos kept on device, even where iCloud is not used.

Wrong [1]. It's even in the first line of the document which you apparently didn't even read:

  CSAM Detection enables Apple to accurately identify and report iCloud users who store
  known Child Sexual Abuse Material (CSAM) in their iCloud Photos accounts
This doesn't mean I'm supporting their new "feature".

1. https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#378

Earlier quoted context omitted.

> The obvious conclusion is Apple will start to scan photos kept on device, even where iCloud is not used. Why is this the obvious conclusion?

Partly it falls under the supposition of "if they can, they will". It's also suggested when they tout that they are going to start blurring "naked" pictures, of any kind, sent to children under 14. Which means they need some kind of tech to detect "naked" pictures, locally, across encrypted channels, in order to block them. In theory, this is different tech than CSAM, which is supposed to checking hashes against a gl…

>They already scanning all of the photos up on iCloud already

I can't find a source for this. Do you happen to have one?

It seems to me that Apple doesn't want to host CSAM on their servers, so they're scanning your device so that if it does get uploaded, they can remove it and then ban you.

They're not scanning all photos on iCloud, as far as I can tell.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#379

I know the privacy approach Apple has been pushing was just marketing, but I didn't care too much because I enjoyed my iPhone and M1 macbook. Because of this decision (and the fact that my iPhone more-or-less facilitates poor habits throughout my life), I'm considering moving completely out of the Apple ecosystem. Does anyone have any recommendations for replacements? * On laptops: I have an X1 carbon extreme running…

Laptop: Framework Laptop Phone: Pixel with GrapheneOS or CalyxOS. In the future a Linux phone when the software improves.

CalyxOS is fantastic. You can get a like-new Pixel on swappa.com for cheap, and have a virtually Google-free, Apple-free phone that supports most/all the apps you would want via MicroG. Can't recommend it enough. GrapheneOS is similar except without support for MicroG if you don't need it.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#380

Earlier quoted context omitted.

Are the only phone options iOS or Android? I’m also considering leaving my iPhone behind because of this privacy violation but I’m definitely not moving to Google. That seems like two steps back.

Calyx is a degoogled Android ROM. It's probably the best choice until mobile Linux improves.

What are the benefits over graphene OS?
Post reply on HN