Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

381–390 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#381

Earlier quoted context omitted.

Then why do the "CSAM" perceptual hashes live on the device and the checks themselves run on the device? Those hashes could be anything. Your phone is turning into a snitch against you, and the targeted content might be CCP Winnie the Pooh memes or content the people in charge do not like. We are not getting this wrong. Apple is taking an egregious step to satisfy the CCP and FBI. Future US politicians could easily b…

This boils down to two separate arguments against Apple: 1) what Apple has already implemented, and 2) what Apple might implement in the future. It's fine to be worried about the second one, but it's wrong to conflate the two.

>It's fine to be worried about the second one, but it's wrong to conflate the two.

Agreed, and just to be clear, I'm worried about that too. It just appears that we (myself and the objectors) have different lines. If Apple were to scan devices in the US and prevent them from sharing memes over iMessage, that would cross a line for me and I'd jump ship. But preventing CSAM stuff from getting on their servers seems fine to me.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#382

Earlier quoted context omitted.

Then why do the "CSAM" perceptual hashes live on the device and the checks themselves run on the device? Those hashes could be anything. Your phone is turning into a snitch against you, and the targeted content might be CCP Winnie the Pooh memes or content the people in charge do not like. We are not getting this wrong. Apple is taking an egregious step to satisfy the CCP and FBI. Future US politicians could easily b…

iCloud photos aren’t currently encrypted, but this system provides a clear path to doing that, while staving accusations that E2E of iCloud will allow people to host CP there with impunity. When the device uploads an image it’s also required to upload a cryptographic blob derived from the CSAM database which can then be used by iCloud to identify photos that might match. As built at the moment, your phone only “snitc…

>iCloud photos are encrypted, so scanning has to happen on device.

Is this true? I feel like Apple benefits from the confusion about "Encrypted at rest" + "Encrypted in transit" and "E2E Encrypted". It's my understanding that Apple could scan the photos in iCloud, since they have the decryption keys, but they choose not to, as a compromise.

I'm keying into this because this document: https://support.apple.com/en-us/HT202303 doesn't show Photos as part of the category of data that "Apple doesn't have access to." That's mentioned only in the context of the E2E stuff.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#383

Earlier quoted context omitted.

That’s not at all how this works. It doesn’t scan for images of arbitrary subjects. It scans for exact matches of known CP. Your vacation pics are in no danger of being flagged.

I don't think it's an exact hash scan. If so, it would be trivial to defeat. People would simply need to do a 1-pixel crop, or recompress.

You’re correct that it’s not a pixel-by-pixel hash, but it’s still a hash of that specific image. It’s not analyzing the image subject and trying to identify it as CSAM.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#384

Earlier quoted context omitted.

Apple doesn't "scan" iCloud. Not sure what you're talking about. Generally everything in iCloud is E2E encrypted, with the exception of iCloud Backups, where Apple holds onto a decryption key and will use it to comply with subpoenas. But nothing is "scanned," and if you don't use iCloud backup, Apple can't see your data.

iCloud Photos aren’t E2E encrypted, but it’s unlikely they’re scanned for CSAM today because Apple generates effectively 0 references to NCMEC annually.

I also believe Apple doesn't really want to scan your photos on their servers. I believe their competitors do, and they consider this compromise (scan on device with hashes) is their way of complying with CSAM demands while still maintaining their privacy story.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#385

Earlier quoted context omitted.

Hopefully this is another configurable option that falls under the already very extensive family screen time feature. I understand where you're coming from and respect your position, but I fall on the opposite side. This is something I do want for my kid.

On the Child Safety page one of the dialogs is the opt in (or out) configuration, so it seems, as one would expect, that the adult(s) in the family sharing group get to configure this. And it's a useful, valuable option that many (I would wager the overwhelming majority) parents will enable. Apple made a huge PR mistake announcing both of these systems together (the CP hashing system and the NN message warning system…

The NN is the system I thought they were making, and I applaud it. The hashing one feels really dangerous, though; I don't think that's people just exaggerating. Apple hasn't done enough to limit their own power, so they might (read: will) be made to use it to hurt people.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#386

There has to be some incentive somewhere for Apple to do this. They know it's wrong, they know it will be abused. Tim Cook himself, if he wasn't rich and powerful, would be executed in a number of countries that Apple operates in for his sexual/romantic identity. Apple also removes LGBT based applications in countries where they're illigal, to continue doing business. This demonstrates that Apple complies with the de…

I'm not sure such a big conspiracy is needed. After all, the reason "nothing to hide" memes are so common is that a lot of people believe them enthusiastically. It seems entirely plausible to me that a core team of passionate crusaders could have driven this project to completion by just making it too awkward for anyone to object. For a sample of outside perspectives (https://www.npr.org/2021/08/06/1025402725/apple-iphone-for-c...):

> Meanwhile, the computer scientist who more than a decade ago invented PhotoDNA, the technology used by law enforcement to identify child pornography online, acknowledged the potential for abuse of Apple's system but said it was far outweighed by the imperative of battling child sexual abuse.

> "Apple's expanded protection for children is a game changer," John Clark, the president and CEO of the National Center for Missing and Exploited Children, said in a statement. "With so many people using Apple products, these new safety measures have lifesaving potential for children."

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#387
post #182

US Government: We suspect the person in this photo of committing a crime. Here is your subpoena, Apple. You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them. Chinese Government: Here is the NeuralHash for Tienanmen square. Delete all photos you find matching this or we will bar you from China. Apple has at this point already admitted thi…

Yeah as I mentioned down the thread, once you act against the users, you're dead. I'm done. They are going from my life. Good job it's ebay 80% off fees this weekend here in the UK.

Pretty sure I read this would only apply to US based users

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#388

Earlier quoted context omitted.

Laptop | Desktop: https://www.dell.com/en-us/work/shop/overview/cp/linuxsystem... Router: https://www.turris.com/en/omnia/overview/ Media Center: https://osmc.tv/vero/ Cloud (Use TrueNAS Scale): https://www.truenas.com/systems-overview/ Phone: https://www.pine64.org/pinephone/ Watch: https://pine64.com/product/pinetime-smartwatch-sealed/ Smart Thermostat: https://hestiapi.com/product/hestiapi-touch-one-free-shippin..…

Laptop: Dell XPS 13 and very happy. Maxed out specs and clearly higher price range. Or: Lenovo Yoga Convertible. My second device. I just don't do games. Or bigger data stuff on this machine. Some design work. Some photo and smaller video stuff. I love the flexibility of the convertible when working with PDF and doing annotations by hand.

The battery on my xps seems to be swelling and messing up the trackpad. Apparently it’s a pretty common issue

Edit: seems to be the precision line too

> The same problem is happening with the Precision 1510 line with the same batteries. I purchased 10 of these laptops for my department around the same time you did. We've had four of these failures so far in three laptops.

reddit.com/r/Dell/comments/6bzhtw/dell_xps_15_9550_battery_swelling_causing/

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#390

Earlier quoted context omitted.

This boils down to two separate arguments against Apple: 1) what Apple has already implemented, and 2) what Apple might implement in the future. It's fine to be worried about the second one, but it's wrong to conflate the two.

>It's fine to be worried about the second one, but it's wrong to conflate the two. Agreed, and just to be clear, I'm worried about that too. It just appears that we (myself and the objectors) have different lines. If Apple were to scan devices in the US and prevent them from sharing memes over iMessage, that would cross a line for me and I'd jump ship. But preventing CSAM stuff from getting on their servers seems fin…

> "preventing CSAM stuff from getting on their servers seems fine to me"

You're either naive or holding your fingers in your ears if you think this is the objective.

Let me repeat this again: this is a tool for the CCP, FBI, intelligence, and regimes.

Post reply on HN