Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

381–390 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#381
post #320

Earlier quoted context omitted.

Did you read the spec? This is why the scanning happens on the device.

I don't recall them explicitly saying anything was e2ee except imeessage which is not relevant for this discussion.

Just read the techical paper. [1]

[1] https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

Re: The deceptive PR behind Apple’s “expanded protections for children”

#382

Earlier quoted context omitted.

That 1/1t rate apple gave is post human review according to a recent interview

Do you have a link to that interview? That's a really big asterisk on the "one in a trillion" claim if true.

> Apple Privacy head Erik Neuenschwander addresses concerns about its new systems to detect CSAM

> We want to ensure that the reports that we make to NCMEC are high-value and actionable, and one of the notions of all systems is that there’s some uncertainty built in to whether or not that image matched. And so the threshold allows us to reach that point where we expect a false reporting rate for review of one in 1 trillion accounts per year.

https://techcrunch.com/2021/08/10/interview-apples-head-of-p...

Leaves some ambiguity but it sounds like the reporting to gov is 1/1t

Re: The deceptive PR behind Apple’s “expanded protections for children”

#383
post #332

Earlier quoted context omitted.

Are Mac and Windows not also full of an enormous amount of crap that we don't need?

That does sound quite bad, doesn’t it? That some Linux distributions are getting closer to them? We have a freedom, let’s use it. I’m using it for something minimal, like Arch Linux.

I used to run Arch but I got sick of trying to fix my Grub/EFI settings etc. which it would occasionally break.

Freedom to me is being able to ignore the OS' existence, and frankly Ubuntu is better at that than Arch.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#384

Earlier quoted context omitted.

An “interesting” part of this is, up until now these photos had little technical exposure. But now that millions of phones can be affected, creating unrelated pictures that purposefully match these hashes becomes a shinny target.

This is untrue. The same photos being used by Apple for this scheme are already in use for CSAM scanning by many major platforms (Google, Facebook, Microsoft). If someone wanted to generate a false positive image, they could already leverage it on these other platforms.

I'd wager the target size of all iOS devices, with the scanning happening by default right after the photo hits the device, is bigger than the other platforms combined.

Google Photos (+ Google Drive I guess ?) is on by default only on Pixel phone I think, and not by default on Samsung phones. For Facebook you have to post the images, for Microsoft I don't think there is any scanning inside Windows itself and by default, I guess it's on OneDrive ? Those companies are big, but the majority of pictures still go through iOS first and foremost.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#385
post #209

Earlier quoted context omitted.

I'm not sure EULA's can effectively bargain away US constitutional protections.

Where does the constitution come into play here? This is a private company scanning content uploaded to its own servers.

...as a pre-requisote of avoiding criminal liability for statutory violation of a Federal statute. Transitive property of logic therefore yields that this private entity is acting as a Government proxy. Therefore, Constitutional considerations.

I don't find this unreasonable.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#386

What would prevent someone from, for instance, printing off an illegal photo, “borrowing” a disliked co-workers iCloud enabled phone, and snapping a picture of the illegal picture with their camera? On iOS the camera can be accessed before unlocking the phone, and wouldn’t this effectively put illegal image(s) in the targets possession without their knowledge?

These illegal photos are not trivial to obtain. Possessing (and here, the printing step necessitates possession) these illegal photos is in and of itself a crime in most relevant jurisdictions. But OK, let's say that you've found a way to get the photos and you're comfortable with the criminal implications of that. At that point why don't you just hide the printed photos in your coworker's desk? My point is that if y…

Yes, the bad actor would need to do non-trivial bad things.

To stay on the topic of iCloud, my point is that it seems quite hard to protect yourself/device from even this most basic attack scenario.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#387
post #308
post #166

Earlier quoted context omitted.

> It all depends on what perceptual hashes you use. I’m talking about the mechanism as described, not a hypothetical. > If Apple can institute a process whereby those are tied to the OS version, but not to the region, then it would be impossible to impose jurisdiction-specific exceptions. As it is the mechanism they have built only works in the US jurisdiction.

> As it is the mechanism they have built only works in the US jurisdiction. That is very worrisome. How do they want to withstand political pressure then to make the database of "bad hashes" dependent on the jurisdiction if they've already made the feature dependent on the jurisdiction?

Presumably they’ll just say, we built a child abuse prevention mechanism and we have no intention of using it for anything else.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#388
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Yes, if they wind up part of a child porn investigation. Your cloud account gets hacked. Some perv gets your images. He is then arrested and his "collection" added to the hash database... including your family photos. Context often matters more than the nature of the actual content. Police aquire thousands of images with little hope of ever knowing where they originated. If they are collected by pervs, and could be c…

> your family photos ... could be construed as illegal in the hands of pervs, the images become child porn and can be added to the databases.

It's not as simple as that. Photos in the NCMEC database are tagged based on the severity of their content. The categories are A1, A2, B1, B2. According to this[0] PowerPoint presentation, page 22:

  A = prepubescent minor
  B = pubescent minor
  1 = sex act
  2 = "lascivious exhibition"
Apple are only searching for images tagged as "A1" by NCMEC and other agencies. This is the most extreme of the extreme. There is a massive gulf between the A1 category and anything you could even remotely conceive of being in anyone's family photos.

[0] https://www.prosecutingattorneys.org/wp-content/uploads/Pres...

Re: The deceptive PR behind Apple’s “expanded protections for children”

#389
post #366

Earlier quoted context omitted.

This is where the thresholding and manual review come in, but could be a bit scary for sure.

Even with thresholding and manual review, the idea that most iphone users (who don't have any CP) are going to have a non-zero child porn score in apple's database is just super creepy. Just a minor policy change (lower threshold) away from calling millions of people pedophiles.

The threshold is cryptographically enforced. See page 4 of Apple's technical summary.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#390

Earlier quoted context omitted.

This is all behind a huge, neon-flashing-lights asterisk of "for now." How long until they try to machine-learn based on that database? The door's open.

Apple previously stored photo backups in their cloud in cleartext. The door was always open. At some point if you are providing your personal images for Apple to store, you have to exercise a modicum of trust in the company. If you don't trust Apple, I suggest you don't use an iPhone.

I would argue that in a discussion about privacy, if trust is brought up it’s no longer a discussion about privacy.
Post reply on HN