Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

391–400 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#391
post #283

Earlier quoted context omitted.

Wait a second. You’re telling me that you believe a low-wage worker reviewing the worst of the worst human depravity, is going to stand up on a soap box and defend another nameless and faceless denizen of the Earth, when the crux of the argument is basically this: “Yeah I know the person tripped the safety threshold for CSAM, but these images aren’t that bad !” It’s not reasonable to trust the human reviewer. They pu…

This is a misunderstanding of the system. It's not a classifier, it's a hash. The only images that are going to be seen by this low-wage worker are going to be: A) Images which are a correct hash match to an image already known to NCMEC or other agencies which have already been assigned CSAM category A1 (A=prepubescent, B=sex act); B) Images which are a hash collision. According to Apple, the likelihood of a collisio…

> This is a misunderstanding of the system. It's not a classifier, it's a hash

You know that a perceptual hash has more in common with a classifier than with a cryptographic hash, right?

If they were using a crypto-hash, then, yes, your argument could be valid, but with perceptual hashing your picture of your baby in the bath could VERY well generate the same hash as a CSAM image. And nobody believes Apples "1 in a trillion" number.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#392

Earlier quoted context omitted.

The false positive rate for any given image is not 1 in a trillion. Perceptual hashing just does not work like that. It also suffers from the birthday paradox problem - as the database expands, and the total number of pictures expands, collisions become more likely. The parent poster does make the mistake of assuming that other pictures of kids will likely cause false positives. Anything could trigger a false positiv…

Then where are the news reports or articles of these false positives that would have shown up within the past decade? That's how long these companies have been using PhotoDNA on the server side. And the version of PhotoDNA from ten years ago would probably have been inferior to the version in place now. Is there even a single verifiable report of such a false positive? I feel that with the amount of attention brought…

> That's how long these companies have been using PhotoDNA on the server side.

Then where are their published peer reviewed papers demonstrating their false positive rate? The burden of proof is on them and they don't have any verifiable public data at all.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#393
post #53
post #28

Earlier quoted context omitted.

Keep in mind, this manual review only happens after Apple’s system detects multiple occurrences of matches. Until that point, no human is alerted of matches nor does anyone see how many matches there have been. In a TechCrunch interview Apple said that they are going after larger targets that are worth NCMEC’s time.

Parents take a lot of photos of their kid. Like, lots .

How many of them include erect adult penises and active participation in sex acts?

Apple's on-device list of hashes only includes images which have been classified "A1" under the CSAM categorisation scale. If any other photographs are accidental hash collisions to these images, it's going to be pretty damn obvious to the human reviewer.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#394
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

[deleted]

Re: The deceptive PR behind Apple’s “expanded protections for children”

#395

Earlier quoted context omitted.

This is a misunderstanding of the system. It's not a classifier, it's a hash. The only images that are going to be seen by this low-wage worker are going to be: A) Images which are a correct hash match to an image already known to NCMEC or other agencies which have already been assigned CSAM category A1 (A=prepubescent, B=sex act); B) Images which are a hash collision. According to Apple, the likelihood of a collisio…

> This is a misunderstanding of the system. It's not a classifier, it's a hash You know that a perceptual hash has more in common with a classifier than with a cryptographic hash, right? If they were using a crypto-hash, then, yes, your argument could be valid, but with perceptual hashing your picture of your baby in the bath could VERY well generate the same hash as a CSAM image. And nobody believes Apples "1 in a t…

I'd be surprised if a baby in the bath—or indeed any legitmately innocent photograph taken by a parent—could ever be a perceptual match to images tagged as "A1" by NCMEC and other agencies. This is the most extreme of the extreme: prepubescent minors actively engaged in sex acts.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#396
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

right, this tech is primarily about fingerprinting existing child porn, hashing that, and trying to prevent dissemination and what they might call "ininiation" into trading child porn for the casuals.

like most privacy invasions these days, its casting a widenet to put a dent in a problem that sill inevitable just route around it, and soon enough itll just be turned into a copyright cashgrab

Re: The deceptive PR behind Apple’s “expanded protections for children”

#397

Earlier quoted context omitted.

Then where are the news reports or articles of these false positives that would have shown up within the past decade? That's how long these companies have been using PhotoDNA on the server side. And the version of PhotoDNA from ten years ago would probably have been inferior to the version in place now. Is there even a single verifiable report of such a false positive? I feel that with the amount of attention brought…

> Why would they have to fear being convicted if they don't actually hold any incriminating evidence? Because going to court is extremely expensive? Because retaining legal council is extremely expensive? Because your district attorney will likely inflate the charges to coerce you into taking a plea deal, despite your innocence? Because you don't want all of your private documents, including ones completely unrelated…

Because we know that the US justice system is horribly corrupt and inept and don't care if they get it right, as long as they get a win.

Because a case like this, you'll be paying a lot of bail just for the privilege of defending yourself properly. (Might have to sell/mortgage your house, or your mother's house).

Because you will probably make the news, and the false accusation will be on the internet forever.

Because you will probably get the living shit beat out of you by the arresting police.

Because you will probably get the living shit beat out of you by your fellow inmates.

Because the incompetent people who charged you can't be sued due to qualified immunity, so no skin off their back.

Because your family will have a lot of stress on it and this will affect your spouse, children, siblings and parents in a very negative way, probably for the rest of their lives.

Because you've lost your job in the process.

Because you'll probably never get a decent job again.

Because you'll probably need a lot of psychological counseling assuming you survive this process.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#398

Earlier quoted context omitted.

Yes, if they wind up part of a child porn investigation. Your cloud account gets hacked. Some perv gets your images. He is then arrested and his "collection" added to the hash database... including your family photos. Context often matters more than the nature of the actual content. Police aquire thousands of images with little hope of ever knowing where they originated. If they are collected by pervs, and could be c…

> your family photos ... could be construed as illegal in the hands of pervs, the images become child porn and can be added to the databases. It's not as simple as that. Photos in the NCMEC database are tagged based on the severity of their content. The categories are A1, A2, B1, B2. According to this[0] PowerPoint presentation, page 22: A = prepubescent minor B = pubescent minor 1 = sex act 2 = "lascivious exhibitio…

A1 is nowhere near the most extreme material with which police must deal. Not even close. This is called child abuse imagery for a reason. Sex acts are literally the entry level for A1.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#399

Earlier quoted context omitted.

> This is a misunderstanding of the system. It's not a classifier, it's a hash You know that a perceptual hash has more in common with a classifier than with a cryptographic hash, right? If they were using a crypto-hash, then, yes, your argument could be valid, but with perceptual hashing your picture of your baby in the bath could VERY well generate the same hash as a CSAM image. And nobody believes Apples "1 in a t…

I'd be surprised if a baby in the bath—or indeed any legitmately innocent photograph taken by a parent—could ever be a perceptual match to images tagged as "A1" by NCMEC and other agencies. This is the most extreme of the extreme: prepubescent minors actively engaged in sex acts.

I’d be surprised that a YouTube video of white noise would be flagged for a copyright violation, and yet here we are.

Things may work right now in 2021. Things will always be changing. New hashes will be introduced. New code will be introduce. New laws in different countries will be introduced.

Now that Apple has introduced this technology that no other phone manufacturer has, it can and will be changed to decrease privacy and increase government control. If China passes a law that states that IPhone needs to scan everyone’s phones for anti-government material, do you really think Tim Cook will say no? They already acquiesced about storing iCloud backups unencrypted on Chinese servers.

And before you say that China would never do that, China and Hong Kong are hunting down the people who were videoed booing Chinese anthem in a shopping mall.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#400
post #364

Earlier quoted context omitted.

There is a manual review step by Apple. You have to first get a “significant” number of photos flagged, then they have to pass Apple’s manual review (ie looking at photo thumbnails), and only then does Apple report the account.

I find how severely this is all being misunderstood, as in very few actually RTFM, on a site like HN, incredibly eye opening.

It’s eye opening how naive some people on HN are despite decades of evidence that things are always twisted in favor of more government surveillance especially outside of the US.
Post reply on HN