Live data from Hacker News

One Bad Apple

hackerfactor.com

381–390 of 557 posts

Re: One Bad Apple

#381
> If someone were to release code that reverses NCMEC hashes into pictures, then everyone in possession of NCMEC's PhotoDNA hashes would be in possession of child pornography.

Please correct me if I'm wrong, but wouldn't it be more correct to say they "would be in possession of images recognized by PhotoDNA as child pornography" rather than actual CP?

Re: One Bad Apple

#382

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

> Nearly 1 in 10 children in the US will be sexually abused before the age of 18.

Please lets not invent distorted statistics or quote mouthpieces who has it in their own interest to scare people as much as possible into rash actions just like Apple has done.

Re: One Bad Apple

#383

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

Thanks for the write-up and putting all the work into this important issue.

> "There is nearly a 1-to-1 relationship between people who deal in CP and people who abuse children. And they rarely victimize just one child. Nearly 1 in 10 children in the US will be sexually abused before the age of 18."

One thing I wondered and have not seen brought up in the discussion so far is this: As far as I understand the perceptual hash solutions work based on existing corpora of abuse material. So, if we improve our detection ability of this existing content, doesn't that increase the pressure on the abusers to produce new content and in consequence hurt even more children? If so, an AI solution that also flags previously unknown abuse material and a lot of human review are probably our only chance. What is your take on this?

Re: One Bad Apple

#384

Earlier quoted context omitted.

What are the main instances where these claims were made fraudulently?

One example I quote from EFF's post Apple's Plan to "Think Different" About Encryption Opens a Backdoor to Your Private Life [1] on the topic: We’ve already seen this mission creep in action. One of the technologies originally built to scan and hash child sexual abuse imagery has been repurposed to create a database of “terrorist” content [2] that companies can contribute to and access for the purpose of banning such…

Thanks, I think I see what you mean. Essentially another organisation has used file hashes to scan for extremist material, by their definition of extreme.

I agree that has potential for abuse but it doesn't seem to explain what the actual link is to NCMEC. It just says "One of the technologies originally built to scan and hash child sexual abuse imagery has been repurposed..." but doesn't name this "technology". Is it talking about PhotoDNA?

Re: One Bad Apple

#385

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

Hey - thanks for writing the OP. I may be missing something obvious, but how does fotoforensics actually identify all the CSAM content it reports to NCMEC?

Re: One Bad Apple

#386

Earlier quoted context omitted.

> access the data in the vouchers for images matching CSAM. One of the data elements in the voucher is an “image derivative” (probably a thumbnail) So the author of the article is technically correct: Apple intentionally uploads CP to their servers for manual review which is explicitly forbidden by law. He even describes the issue with thumbnails

It is exceedingly unlikely that a system developed with NCMEC’s support and a Fortune 5 legal team somehow fails to comply with the most obviously relevant laws.

I'd say: A trillion-dollar company and a government agency can do whatever they feel like, and laws be damned :)

Re: One Bad Apple

#387

Earlier quoted context omitted.

> someone usually mocks "it's always about the kids, think about the kids." To those critics: They have not seen the scope of this problem or the long term impact. What you are saying here kind of sidetracks the actual problem those critics have though, doesn't it? The problem is not the acknowledgement of how bad child abuse is. The problem is whether we can trust the people who claim that everything they do, they d…

What are the main instances where these claims were made fraudulently?

https://en.wikipedia.org/wiki/Think_of_the_children

https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...

Re: One Bad Apple

#388
post #152

Earlier quoted context omitted.

> Too often the tech community's response is that the intangible concept of privacy is more important than the tangible issue of child abuse. Is it intangible? 18% of the world lives in China alone. That's more people than the "1/10 who are victims of child abuse*", and I'm sure that 18% will only grow as other authoritarian countries get more technologically advanced. I think "Think of the kids" applies very well to…

> I think "Think of the kids" applies very well to the CREATORS of pornography. Per wikipedia, there isn't any conclusive causal relationship between viewing CP and assaulting children. “Think of the Kids” damn well applies to the consumers of this content - by definition, there is a kid (or baby in some instances) involved in the CP. As a society, the United States draws the line at age 18 as the age of consent [the…

That is such a tortured, backwards argument, but the only one that has even a semblance of logic so it gets repeated ad nauseam. Why be so coy about the real reasons?

Re: One Bad Apple

#389

Earlier quoted context omitted.

It's their operating system! Files are already "scanned" by their processes, how do you think they get from the camera to the hard drive?

I'd imagine that they do that by writing the bits to the hard drive without creating a fuzzy hash used to match your picture with those in some organization's list?

Sorry, perhaps I misunderstood what you meant by "infrastructure".

Apple have always had the ability to do great evil to a lot of people, this update doesn't change that. They haven't gained any power they didn't already have.

The government, for example, do not currently have the infrastructure to push updates to iPhone. If they passed laws, built servers etc to allow this then that would be a meaningful change that would be worth all this chatter.

Re: One Bad Apple

#390
post #43
post #13

Earlier quoted context omitted.

Legality aside – how is this not a privacy risk? Privileged users of the infrastructure can gain information about users (whether they possess CSAM that's in the hash-database... for now).

Presumably the reviewers would not know the identity of the user whose photos are under review, as they have no need to.

Unless you're a public figure or celebrity. If I were, I wouldn't use iCloud photos, but that's not exactly how Apple markets their photo service.
Post reply on HN