Live data from Hacker News

In internal memo, Apple addresses concerns around new Photo scanning features

9to5mac.com

381–390 of 430 posts

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#381
Just an aside as we all discuss iCloud storage of photos, etc. ...

I don't back up anything to iCloud. Instead, I connect my iPhone to my laptop and run the excellent "iExplorer" utility from Macroplant[1].

This allows me to browse my iPhone like a filesystem and copy off all of the photos/videos to a directory where I can then rsync them to my local fileserver.

You can also dump iMessages and notes and all of those other thing but I just export photos ...

[1] https://macroplant.com/iexplorer

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#382
post #257

Earlier quoted context omitted.

If I learned anything in my lifetime, it’s that “slippery slope” is not, in fact, a fallacy at all. Rather, it’s a rule of thumb.

There are plenty of examples where it is fallacious though, often absurdly so. The important distinction is: does A abstractly "lead to" B, or does A directly enable B, but for some will to use it that way. For one example, it was always absurd to suggest that gay marriage would lead to legalized pedophilia, bestiality, or marriage to objects.

Meanwhile, trolls and staunch intellectuals demanding "enough" evidence think they can gatekeep what's acceptable to notice is already slipping and gaslight others for noticing and worrying, only to find that years later, the Overton window shifted and newer generations were none the wiser, bringing the things that were previously unacceptable into the mainstream with reckless abandon.

(edited for brevity, expanding more on this in a reply...)

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#384
post #145

Earlier quoted context omitted.

>"A cryptographic hash + file size combo" SHA already uses the length in the output hash. Having the explicit length is quite superfluous

> Having the explicit length is quite superfluous Not entirely. It makes it so that, to achieve a "full" collision, you have to ensure that the sets of data collide both in SHA hash and in length, helping to prevent attacks that rely on appending/prepending/removing data (for example, "length extension attacks" involve manipulation of the hash by appending data). TL;DR: It is harder to find a collision SHA(B) for SHA…

This is completely wrong.

The known collision attacks for the MD-family and SHA-1 all in fact produce collisions with the exact same length. The method used necessarily does this.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#385

Apple's mistake is that they seemingly believe there is pushback because people misunderstand how it works. The reality is more nuanced: People understand exactly how it works, and how it works is that it is turn-key onboard spyware, that Apple pinky-swears isn't being used wrong today . For example if the scope/mission expands (e.g. foreign governments), suddenly you've created a drag-net for whatever "badness" is o…

It's just a matter of time until someone can create a "ThisChildPornDoesNotExist" site, then send links to targets to have their lives ruined. I am extremely worried by humans policing the Intertubes, and even more worried by algorithms doing so because they make the perfect excuse to do sloppy checking. See Youtube DMCA related takedowns for multiple examples.

> It's just a matter of time until someone can create a "ThisChildPornDoesNotExist" site, then send links to targets to have their lives ruined.

“Their” in this case referring to the sender, which makes the particular problem somewhat self-limiting, right?

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#386

Earlier quoted context omitted.

There are plenty of examples where it is fallacious though, often absurdly so. The important distinction is: does A abstractly "lead to" B, or does A directly enable B, but for some will to use it that way. For one example, it was always absurd to suggest that gay marriage would lead to legalized pedophilia, bestiality, or marriage to objects.

Meanwhile, trolls and staunch intellectuals demanding "enough" evidence think they can gatekeep what's acceptable to notice is already slipping and gaslight others for noticing and worrying, only to find that years later, the Overton window shifted and newer generations were none the wiser, bringing the things that were previously unacceptable into the mainstream with reckless abandon. (edited for brevity, expanding…

I'm going to get a little facetious here:

The corporation that is the U.S government acts just like one: roadmaps and planning ahead for radical policy changes to occur within longer spans of time to signify progress (or something), and then absolutely losing their shit if an opposing candidate wins & gets in the way of their progress, as we observed these past 5 years.

Acceptance of pedophilia has been set in motion for several years now. One only need look at some of California's SB-145, the ever-expanding reach of public schools teaching sex-ed to kindergartners, and the N number of drag queens sexualizing themselves in front of young children in public libraries and schools with grand applause and media gushing as these facilities move a few steps away from becoming brothels.

(See what I did there? Surely our libraries won't become brothels, that would be absurd! I mean, the chances of that happening are 2nd to none; and if 10 years from now, libraries still aren't brothels, then I'd have been wrong after all, and my playful exaggeration will have expired. A gatekeeper would have done their noble internet duty to inform me just how idiotic my suggestion was from the start, to be sure. The joke's on them for losing 15 minutes crafting the perfect response to my alarmism that will definitely change my mind.)

We had none of this just 3 years ago, but I'm pretty confident I'll be gaslit in response to my highly misinformed and "hateful" comments, as it goes. ;) That's no matter though. I take responsibility for that by standing by what I say, not bending to the winds of outrage.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#387

Earlier quoted context omitted.

This is how I feel as well. I don’t use iCloud photos but if I did, sure scan them for CP, I don’t care. Maybe you will catch some bad guys that willingly gave you their photos. But scanning everyone’s phones is beyond creepy and feels like exactly what the fourth amendment is about. It’s British soldiers suddenly having the ability to search EVERY home in colonial America as often as they want. > Amendment 4. The ri…

May I ask what phone? I am not here to criticize.

I’m a cheap bastard so I got a Pixel 2 used for ~$55. I’m sure people will tell me Android is no better and I’d be open to hearing that but they don’t scan your phone as far as I know. I also have the option to install things like Calyx OS, Graphene OS I believe.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#388

Wondering If this implementation is related to the chat control effort in the EU: https://www.patrick-breyer.de/en/posts/message-screening/?la... Just installing graheneos on a pixel, writing this from my Librem 14 (got it after the M1, the phoning home of apple apps, the new lockdown of kernel extensions). Goodbye Apple.

Now that I think about it, is there any good, viable alternative for Windows 10 on a new ThinkPad? One that ideally is able to run MS Office (or at least Excel...)? Any recommendations regarding decent, and ideally user friendly, Linux versions?

Kubuntu, Linux Mint, Pop_OS!

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#389

Earlier quoted context omitted.

This is how I feel as well. I don’t use iCloud photos but if I did, sure scan them for CP, I don’t care. Maybe you will catch some bad guys that willingly gave you their photos. But scanning everyone’s phones is beyond creepy and feels like exactly what the fourth amendment is about. It’s British soldiers suddenly having the ability to search EVERY home in colonial America as often as they want. > Amendment 4. The ri…

Constitution applies between the government and you. Apple is not (knowingly) a government agency, they're a private business. Therefore the amendment doesn't apply to their actions. Vote with the wallet instead.

Yes that’s true but I assume this program is working closely with the government. I could care less about child abuser protection but history shows us that it is a very short maybe non-existent slope from “protecting the kids” to whatever overstep a government organization wants to take.

I wouldn’t care nearly as much about Apple scanning my phone it’s about who is pulling those strings they are working with and in America they are (or should be!) bound by the Constitution. I can only imagine the obliteration of rights that will happen in other places. Imagine a Hong Kong protestor with this program on their phone.

We’ve got to do everything we can to keep George Orwell’s quote from coming true-

“If you want a picture of the future, imagine a boot stamping on a human face—for ever.”

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#390

Earlier quoted context omitted.

It's just a matter of time until someone can create a "ThisChildPornDoesNotExist" site, then send links to targets to have their lives ruined. I am extremely worried by humans policing the Intertubes, and even more worried by algorithms doing so because they make the perfect excuse to do sloppy checking. See Youtube DMCA related takedowns for multiple examples.

> It's just a matter of time until someone can create a "ThisChildPornDoesNotExist" site, then send links to targets to have their lives ruined. “Their” in this case referring to the sender , which makes the particular problem somewhat self-limiting, right?

Probably so, but a more smart malware that grabs fake images from an encrypted server somewhere, then plants them in the victims PC/phone/whatever, then deletes itself, isn't rocket science.
Post reply on HN