Earlier quoted context omitted.
We hire, and train, terrible cops in America. They are basically Reveune Collectors. I would like to see all cops under federal jurisdiction. Let the FBI train them. I know in my county of Marin we have way to many just looking for any slight moving violation. I have felt for awhile that we also need complete bans in certain kinds of tech. With the exception of always on cop cameras.
Exactly, there's a reason the FBI takes over real criminal cases when they occur - the police are just there to settle petty, inconsequential local disputes.
An open letter against Apple's new privacy-invasive client-side content scanning
381–390 of 451 posts
Re: An open letter against Apple's new privacy-invasive client-side content scanning
#382Earlier quoted context omitted.
I agree with you, but if you'd take the time to read my post you would see that I am arguing that it's not good even by their own claims! They talk a lot about complex crypto to protect privacy but the primary thing it's doing is hiding what apple is matching against, which shields them against accountability. I fully agree that even if the behavior were currently threading the needle it would still be an extremely b…
> They talk a lot about complex crypto to protect privacy but the primary thing it's doing is hiding what apple is matching against, which shields them against accountability. NCMEC partners are not allowed to share the raw hashes, and I imagine Apple's contract with NCMEC to create a photo-comparison tool that will have auditable code (well, compiled code, but still) includes such a provision to slow or stop CSAM sh…
You don't have to have a copy of the database to be fairly confident that your modifications have made a target image non-matching. You would have to have the database in order to gather evidence that the matching was beginning to be used for unlawful, rights violating purposes, such as collecting targets for genocide.
I think it's a safe assumption that this sort of system is only effective against idiots-- which isn't an argument against it: lots of effective anti-crime measures mostly work against idiots. Adding functionality which destroys accountability which at most improves the system against non-targets, however, doesn't seem like an acceptable trade-off.
Re: An open letter against Apple's new privacy-invasive client-side content scanning
#383https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni... Apple uses sophisticated cryptography to make absolutely certain that you cannot hold them accountable for abuses of this system against you, NONE of which are prevented by its complex construction. The private set intersection is an alternative to sending you a list of bad-image hashes which uses significantly more bandwidth than simply sending you the…
> The private set intersection is an alternative to sending you a list of bad-image hashes which uses significantly more bandwidth than simply sending you the list. How can the image hashes take up more space than the images themselves? Are you sure about this?
Re: An open letter against Apple's new privacy-invasive client-side content scanning
#384I signed this, but I'm very doubtful this will ever achieve something. But this made me wonder: is there an history of people complaining about this sort of things and actually achieving something? I think this might have happened with MSFT's hailstorm/passport, where in the end industry opposition meant the project was abandoned, but I can't recall other instances.
Google cancelled its DoD drone program because of employee protests. https://www.fedscoop.com/google-project-maven-canary-coal-mi...
Re: An open letter against Apple's new privacy-invasive client-side content scanning
#385Apple's new policy will have only one effect - pedophiles will stop using ios. For the rest of us, our privacy will remain compromised.
Pedophiles in the know would presumably just have to disable iCloud sync, and the hash scan would never happen.
Re: An open letter against Apple's new privacy-invasive client-side content scanning
#386Earlier quoted context omitted.
Isn't it bit ironical or naive to trust their current software as it is (which is almost full blackbox), and then speculate what they could do without saying, when they add something? As far as I understand, you can disable this feature, because it is tied to iCloud sync. Based on their spec [1], this feature avoids to do the same as Google and others doing (scan everything on cloud), instead they scan on device, whi…
Exactly. Many people who are upset about having their images scanned before going to iCloud don't seem to realize all the big providers (Apple, Google, FB, Twitter, MS, etc...) have been scanning images with CSAM for years already. The client side/server side also does not matter because iOS users have had to trust Apple implicitly since day 1. All the 'what ifs' existed whether or not Apple added this feature. I spe…
Re: An open letter against Apple's new privacy-invasive client-side content scanning
#387Earlier quoted context omitted.
What cloud service are you putting your images on? I would be shocked if google photos hasn’t already been doing this.
You don't need the cloud: syncthing can sync your phone and your computer together without any issues. No nasty cloud provider involved: https://syncthing.net/
Also, you can restore an iPhone from what SyncThing can back up. Only an iTunes or equivalent iCloud device backup can. They also can’t back up things like MFA keys / seeds / IVs.
I’m glad ST exists and it’s useful for syncing photos for home use, but it is not a viable iCloud alternative, nor could one be made due to the private iOS API issue.
Re: An open letter against Apple's new privacy-invasive client-side content scanning
#388Re: An open letter against Apple's new privacy-invasive client-side content scanning
#389Earlier quoted context omitted.
What cloud service are you putting your images on? I would be shocked if google photos hasn’t already been doing this.
Cloud is other people's computers. So, get your own server, or use someone's you trust. or use e2e encryption.
Re: An open letter against Apple's new privacy-invasive client-side content scanning
#390Related but slightly off-topic: am I the only one that thinks more technology is not the answer to catching crooks? Can’t the police do good old fashioned police work to catch people doing these things? Why does EVERYONE need to be surveilled for the 0.01% (or less?) who don’t behave properly. To further this point: why do we need cameras on every street, facial recognition systems and 3-letter orgs storing huge data…
> "Can’t the police do good old fashioned police work to catch people doing these things?" I'm a detective that works exclusively on online child sexual offences. The short answer to this is "no", although the question doesn't make much sense to me. Policing has always been near the forefront of technology. Perhaps you could expand more on what "good old fashioned police work" means, in this context?