Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

381–390 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#381

Earlier quoted context omitted.

We hire, and train, terrible cops in America. They are basically Reveune Collectors. I would like to see all cops under federal jurisdiction. Let the FBI train them. I know in my county of Marin we have way to many just looking for any slight moving violation. I have felt for awhile that we also need complete bans in certain kinds of tech. With the exception of always on cop cameras.

Exactly, there's a reason the FBI takes over real criminal cases when they occur - the police are just there to settle petty, inconsequential local disputes.

Inconsequential to you. Consequential to those people involved. Jesus Christ dude not everything revolves only around you or your concerns.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#382
post #175

Earlier quoted context omitted.

I agree with you, but if you'd take the time to read my post you would see that I am arguing that it's not good even by their own claims! They talk a lot about complex crypto to protect privacy but the primary thing it's doing is hiding what apple is matching against, which shields them against accountability. I fully agree that even if the behavior were currently threading the needle it would still be an extremely b…

> They talk a lot about complex crypto to protect privacy but the primary thing it's doing is hiding what apple is matching against, which shields them against accountability. NCMEC partners are not allowed to share the raw hashes, and I imagine Apple's contract with NCMEC to create a photo-comparison tool that will have auditable code (well, compiled code, but still) includes such a provision to slow or stop CSAM sh…

What they are making available is sufficient to 'cheat' the system in the sense that if you have an image you are concerned might match in some database you can modify it until the 'perceptual hash', which you can compute on your own, changes. The novel changed image is then unlikely to be a match in the database.

You don't have to have a copy of the database to be fairly confident that your modifications have made a target image non-matching. You would have to have the database in order to gather evidence that the matching was beginning to be used for unlawful, rights violating purposes, such as collecting targets for genocide.

I think it's a safe assumption that this sort of system is only effective against idiots-- which isn't an argument against it: lots of effective anti-crime measures mostly work against idiots. Adding functionality which destroys accountability which at most improves the system against non-targets, however, doesn't seem like an acceptable trade-off.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#383
post #153

https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni... Apple uses sophisticated cryptography to make absolutely certain that you cannot hold them accountable for abuses of this system against you, NONE of which are prevented by its complex construction. The private set intersection is an alternative to sending you a list of bad-image hashes which uses significantly more bandwidth than simply sending you the…

> The private set intersection is an alternative to sending you a list of bad-image hashes which uses significantly more bandwidth than simply sending you the list. How can the image hashes take up more space than the images themselves? Are you sure about this?

Using private set intersection takes more bandwidth than the server simply sending you a list of hashes to match against. (Significantly more, once you're taking about testing multiple images.)

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#384
post #40
post #2

I signed this, but I'm very doubtful this will ever achieve something. But this made me wonder: is there an history of people complaining about this sort of things and actually achieving something? I think this might have happened with MSFT's hailstorm/passport, where in the end industry opposition meant the project was abandoned, but I can't recall other instances.

Google cancelled its DoD drone program because of employee protests. https://www.fedscoop.com/google-project-maven-canary-coal-mi...

I’m sure they just got Lockheed/Boeing/General Dynamics/Northrop/Raytheon/IBM to take it on for 10x the price.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#385
post #323

Apple's new policy will have only one effect - pedophiles will stop using ios. For the rest of us, our privacy will remain compromised.

Pedophiles in the know would presumably just have to disable iCloud sync, and the hash scan would never happen.

This. It’s not like iCloud and GDrive are the only two cloud storage vendors, or like there’s no way to encrypt things before uploading them.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#386
post #205

Earlier quoted context omitted.

Isn't it bit ironical or naive to trust their current software as it is (which is almost full blackbox), and then speculate what they could do without saying, when they add something? As far as I understand, you can disable this feature, because it is tied to iCloud sync. Based on their spec [1], this feature avoids to do the same as Google and others doing (scan everything on cloud), instead they scan on device, whi…

Exactly. Many people who are upset about having their images scanned before going to iCloud don't seem to realize all the big providers (Apple, Google, FB, Twitter, MS, etc...) have been scanning images with CSAM for years already. The client side/server side also does not matter because iOS users have had to trust Apple implicitly since day 1. All the 'what ifs' existed whether or not Apple added this feature. I spe…

This makes the most sense for “why” and “why now” IMO.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#387
post #18

Earlier quoted context omitted.

What cloud service are you putting your images on? I would be shocked if google photos hasn’t already been doing this.

You don't need the cloud: syncthing can sync your phone and your computer together without any issues. No nasty cloud provider involved: https://syncthing.net/

And because no one except Apple have access to the private iOS APIs required to run background processes forever, you would have to remember to keep the app in the foreground while it completes syncing on a regular basis.

Also, you can restore an iPhone from what SyncThing can back up. Only an iTunes or equivalent iCloud device backup can. They also can’t back up things like MFA keys / seeds / IVs.

I’m glad ST exists and it’s useful for syncing photos for home use, but it is not a viable iCloud alternative, nor could one be made due to the private iOS API issue.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#388
It seems like it is coming together. They'll be able to figure out what kind of person you are by looking at your phone's content. Then at your next vaccination, you'll get one that causes a blood clot or you'll get sterilized. It's not like government hasn't done some of those things. Now it is only going to be automated.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#389
post #20

Earlier quoted context omitted.

What cloud service are you putting your images on? I would be shocked if google photos hasn’t already been doing this.

Cloud is other people's computers. So, get your own server, or use someone's you trust. or use e2e encryption.

That would be great if I could run an iCloud back-end on my home servers. Unfortunately, I can’t, and no software other than iCloud can do what iCloud does on iOS due to Apple’s usage of private iOS APIs to accomplish things like persistent background sync or syncing parts of the OS which would be required to do a full device restore that aren’t accessible to user space apps.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#390
post #50

Related but slightly off-topic: am I the only one that thinks more technology is not the answer to catching crooks? Can’t the police do good old fashioned police work to catch people doing these things? Why does EVERYONE need to be surveilled for the 0.01% (or less?) who don’t behave properly. To further this point: why do we need cameras on every street, facial recognition systems and 3-letter orgs storing huge data…

> "Can’t the police do good old fashioned police work to catch people doing these things?" I'm a detective that works exclusively on online child sexual offences. The short answer to this is "no", although the question doesn't make much sense to me. Policing has always been near the forefront of technology. Perhaps you could expand more on what "good old fashioned police work" means, in this context?

First very brave of you to post here and thanks for that. Second thanks for all your hard work in keeping this world sane. However, I would point out that this is a complete invasion of privacy and essentially working around the 4th amendment in both spirit and the law via using Apple as a proxy to spy on us. I realize police just want to do their job and have to push on the limits, but with all due respect I think this is going too far. That's why we push back when something as ridiculous as this happens. I don't want to be policed on my own devices, and the only way police should have a way into that is with a warrant, then you can drop a world of security on me. The pedos will just work around this and this is the first step into allowing police into all our personal devices while the criminals work around it. Anyway, again I mean this in a respectful tone, I just think it goes way too far. Cloud drives are already being scanned and that's with corporate permission on their own devices, so that's tolerable if undesirable but what Apple is doing here is going too far.
Post reply on HN