Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

371–380 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#371
post #61

Earlier quoted context omitted.

> The end isn't really compromised with their described implementation. They've turned your device into a dragnet for content the powers that be don't like. It could be anything. They're not telling you. And you're blindly trusting them to have your interests at heart, to never change their promise. You don't even know these people. You seriously want to cuddle up with that?

> "They've turned your device into a dragnet for content the powers that be don't like. It could be anything. They're not telling you" They're pretty explicitly telling us what it's for and what it's not for. > "And you're blindly trusting them to have your interests at heart, to never change their promise. You don't even know these people." You should probably get to work building your own phone, along with your own…

Yes. All the fabs and stuff we have now shoufd be devoted to implementing a surveillance state. This must happen. It cannot be any other way.

This is what you sound like. The problem here isn't the tech. It's that Big Tech has deluded society into believing privacy and personal ownership of devices doesn't exist because it would inconvenice Big Tech. Law enforcement echoes it because they were spoiled by the brief period that they tasted ClearNet, and they don't want to return to having to investigate the old fashioned way.

Every other major industry has increasingly started doing the same thing. It is not okay. We have no right to sell out future generation's privacy. It's cowardly, selfish, and does more harm to them in the long run.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#372

Earlier quoted context omitted.

PhotoDNA is Microsoft’s algorithm. Apple’s new one is NeuralHash. Plus the hashes are encrypted and blinded before being stored on the phone. They can’t be reversed.

In order for this system to work, Apple has to be able to compare the CSAM NeuralHash hashes against the NeuralHash hashes of the images to be synced with iCloud. How do they compare the hashes without decrypting?

They compare the encrypted forms of the hashes, the first step on the device and the second on the server.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#373

Earlier quoted context omitted.

> Facebook checks for potential CSAM when you upload from your client device (sometimes an iphone) to their servers or after it's on their system and a user flags it. Thats not the issue according to the linked source. Instagram transmits all photos and assumes it's not CSAM until flagged - thats safe content. Apple transmits ONLY CSAM - thats a no-no content because they're assuming it is CSAM and you can't transmit…

Huh? Apple uploads all photos to iCloud photos (just as google does). This includes CSAM and not CSAM. It keeps a counter going of how much stuff is getting flagged as possible CSAM. They don't even get an alert about anything until you hit some thresholds etc. And no one has reviewed anything yet at all, the system is flagging things up as other systems do. Are you sure (legally) that one can't review flags from a m…

> Are you sure (legally)

> Is your goal that apple

I'm not a lawyer and i want apple to do nothing especially not scan my device.

I'm saying the linked article in discussion says you can't transmit content you KNOW (or suspect) is CSAM. You don't assume that all your customers' content is CSAM, but post-scan, you should assume.

The only legal way to transmit (according to article) is if it's to the government authorities.

I don't know the legal view on the "false positive" suspicion vs legality of transmitting. That's a gamble it seems. I don't have a further opinion on it since IANAL and this is very legal grey area.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#374
post #320

Earlier quoted context omitted.

> because E2EE ”like” implementation. Did apple actually say photos would be e2ee or are we just assuming?

Did you read the spec? This is why the scanning happens on the device.

I don't recall them explicitly saying anything was e2ee except imeessage which is not relevant for this discussion.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#375

Earlier quoted context omitted.

Then where are the news reports or articles of these false positives that would have shown up within the past decade? That's how long these companies have been using PhotoDNA on the server side. And the version of PhotoDNA from ten years ago would probably have been inferior to the version in place now. Is there even a single verifiable report of such a false positive? I feel that with the amount of attention brought…

> Then where are the news reports or articles of these false positives that would have shown up within the past decade?... Is there even a single verifiable report of such a false positive? I feel that with the amount of attention brought to this issue, if there was such a report then it probably would have been brought up by now. Positives get reviewed by humans, at which point false positives are identified and dis…

>Positives get reviewed by humans, at which point false positives are identified and discarded.

Let's not forget, this part only happens if you are lucky. You get the wrong photo reviewer and you catch your girlfriend with the wrong type of lighting that makes her look as if she could pass for 17 and you're going to have the police show up at your work and cuff you, demanding to know who this person of interest is. Adult males have been tried for possession of CSAM for having images of well-known absolutely above 18 adult video stars: https://reason.com/2010/05/03/porn-star-saves-man-from-incom...

Re: The deceptive PR behind Apple’s “expanded protections for children”

#376
post #307

Earlier quoted context omitted.

While I don't expect any Linux phone to become "mainstream" any time soon, it would be good if we had at least one "polished" alternative available. PinePhone is still in beta and according to its own creators "aimed solely at early adopters"[1], while Librem 5 is experiencing supply chain issues with backorder shipping now scheduled to resume in October[2] There is a version of the Librem 5 which is made in USA and…

Problem will always be the hardware. Until we get some 80's IBM style architecture on mobile, there is no viable Linux for smartphone. I have 4 phones. None of them support lineage os.

I recently saw a review of the "Volla Phone" which is running Ubuntu Touch. Seemed much better than the Pinephone but still has issues:

https://youtu.be/neG2Z21epLI

Re: The deceptive PR behind Apple’s “expanded protections for children”

#377
post #254

Earlier quoted context omitted.

> because a person will look at your picture(yes, a random person somewhere will look at the pictures of your newborn) No. If the number of matches to known CSAM in your library exceeds a threshold, then a person will look at a "visual derivative" of only those pictures whose perceptual hatch match that of known CSAM. Note that, if I understand correctly, pictures that Android users sync to Google have already been s…

>>the number of matches to known CSAM in your library exceeds a threshold, then a person will look at a "visual derivative" of only those pictures whose perceptual hatch match that of known CSAM Apple very specifically said that their employees will look at the suspected picture before sending it through to authorities. Where do you see the bit about visual derivatives? What would that even mean or look like? Also wh…

[deleted]

Re: The deceptive PR behind Apple’s “expanded protections for children”

#378

Earlier quoted context omitted.

It’s good to know that if I use the “section” glyph in an otherwise completely false analysis born of extending my experience past where I’m competent, readers will quickly repeat whatever it is I said as factual and “quite irrefutable”. The power of one blog post is quite something. You’re the third person I’ve seen quote that very post and go “welp, sure is a smoking gun” despite it being completely, utterly, demon…

Thanks for coming on here. You WILL be downvoted. I'm a parent, it's also crazy to me how THIS of all things is where folks are going crazy over privacy. Literally, they will build something to track your every mouse move, scan every photo, log and sell all your browsing history and TV watching history (including big ISPs and mfgs). And this is the thing folks get outraged about? Apple can already scan your stuff on…

Most who really care about the central hypocrisy have been banging our heads bloody about all those other surveillance issues. We're so damned concerned, because this is a textbook case of cramming through another brick in the wall of deconstructed privacy now and into the future. There is plenty of terrible arguments, but the good ones that people keep trying to handwave or ignore are the more pressing one.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#379
post #369
post #365

Earlier quoted context omitted.

> Any technical or financial excuse they might have used in the past to not scan files locally is now rendered null. This just proves that people don’t understand much about technology in depth. Capability has been there already, for very long time. 99% of their work has gone for implementing that perceptual hashing function and their PSI system. If you want to give excuses, there will be always more. But they are no…

> Capability has been there already, for very long time. Capability was always there but it wasn't implemented. Now arguments like excessive battery drain or processor usage or any argument they could have come up with can no longer be used since they went ahead and implemented software that scans iPhone files. Perceptual hashing is a mere detail of how they are scanning files TODAY. Same for scanning only files whic…

I think you missunderstood a bit what I said. Capability was there, already as implemented, for example as Neural Nets which categorizes your photos, by scanning all of them. Detecting faces and giving them names. So on. Even your Files app scans all of your files, and probably collects some metadata for iCloud sync process.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#380

Earlier quoted context omitted.

Their neural hashing is new, and they claim has a one in a trillion collision rate. There are 1.5 trillion images created in the US and something like 100 million photos in the compared database. That's a heck of a lot of collisions. And that's just a single year, Apple will be comparing everyone's back catalog. A lot of innocent people are going to get caught up in this.

We’ll have to wait and see how good their neural hashing is, but just to clarify the 1 trillion number is the “probability of incorrectly flagging a given account” according to Apple’s white paper. I think some people think that’s the probability of a picture being incorrectly flagged, which would be more concerning given the 1.5 trillion images created in the US. Source: https://www.apple.com/child-safety/pdf/CSAM_D…

From Apple's technical summary:

"The threshold is selected to provide an extremely low (1 in 1 trillion) probability of incorrectly flagging a given account. This is further mitigated by a manual review process wherein Apple reviews each report to confirm there is a match..."

So it's 1 in 1 trillion per account PRIOR to manual review in which the odds of error get reduced even further.

Post reply on HN