Live data from Hacker News

One Bad Apple

hackerfactor.com

41–50 of 557 posts

Re: One Bad Apple

#41

> Apple then manually reviews each report to confirm there is a match, This is always the terrifying part for me. They will access your personal photos or data without telling you. I’m surprised how is that even legal given all the law that are already available. Are they immune to those laws stated in thd blog? Also what happens when they launch this in EU, AU, etc with different privacy laws?

I think the article got that wrong. Apple does manually review tagged images, but does not access the original image, but the security voucher containing metadata, including the NeuralHash and a "visual derivative" of it (see Apple's spec [1]).

Also, this only applies to pictures you upload to iCloud. So, it's not like they're accessing your personal photos without telling you.

[1] https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

Re: One Bad Apple

#42
post #34
post #12

> 18 U.S.C. § 2258A is specific: the data can only be sent to NCMEC. (With 2258A, it is illegal for a service provider to turn over CP photos to the police or the FBI; you can only send it to NCMEC. Then NCMEC will contact the police or FBI.) What Apple has detailed is the intentional distribution (to Apple), collection (at Apple), and access (viewing at Apple) of material that they strongly have reason to believe is…

This is the part that also caught my eye. Surely Apple's lawyers have also reviewed the same law, and if it's that clearly defined, how did they justify/explain their approach?

Because Apple (its employees) aren't actually viewing the images, nor transmitting them. They mention somewhere that it's a low res proxy of the image, or something similar.

Re: One Bad Apple

#43
post #13
post #3

> To reiterate: scanning your device is not a privacy risk, but copying files from your device without any notice is definitely a privacy issue. Not a lawyer, but I believe this part about legality is inaccurate, because they aren’t copying your photos without notice. The feature is not harvesting suspect photos from a device, it is attaching data to all photos before they are uploaded to Apple’s servers. If you’re n…

Legality aside – how is this not a privacy risk? Privileged users of the infrastructure can gain information about users (whether they possess CSAM that's in the hash-database... for now).

Presumably the reviewers would not know the identity of the user whose photos are under review, as they have no need to.

Re: One Bad Apple

#44

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

[deleted]

Re: One Bad Apple

#45
post #9
post #5

Earlier quoted context omitted.

What does "manual review" mean then and how are those images reported?

Before: you would upload images to iCloud Photos. Apple can access your images in iCloud Photos, but it does not. Now: You upload images to iCloud Photos. When doing so, your device also uploads a separate safety voucher for the image. If there are enough vouchers for CSAM matched images in your library, Apple gains the ability to access the data in the vouchers for images matching CSAM. One of the data elements in t…

Thank you for this explanation. Much more helpful than any of the lengthy articles I've read to date.

I think Apple has botched the rollout of this change by failing to explain clearly how it works. As a result, rumors and misunderstandings have proliferated instead.

Re: One Bad Apple

#46

Really nice explanation from someone who knows a thing or two about images/photos (Dr. Neal Krawetz is the creator of https://fotoforensics.com and specializes in computer forensics).

He wrongly interpreted CSAM scanning. He said that Apple will scan your photos and if finds something, it will send photo to Apple. Which is absolutely not how it works. Photo is only scanned before uploading to iCloud Photos. Apple already confirmed it to iMore and it’s clearly stated in Apple papers from press-release.

You're very clearly missing the forest for the trees. Right before uploading to icloud, "Apple will scan your photos and if finds something, it will send photo to Apple."

This process is automated and turned on on most iPhones. Most iPhones will have automatic photo upload to icloud enabled, and that's when this scanning takes place.

Re: One Bad Apple

#47

This feels like missing the forest from the trees — Steve Jobs said many times to the effect ‘it doesn’t matter how any of this stuff happens, GigaHertz, Ram, Speeds, it only matters that the user gets what they want.’ Right now Apple’s biggest unhappy user is the DOJ. As it stands with the legislation coming down the pipe and both previous administrations building on a keenness to ‘get something done’ about big tech…

Why do elected officials act as fake representatives to the people that elected them in the first place? Has it always been this way? It doesn’t matter left or right. The governing bodies should obey the people not the other way around.

Re: One Bad Apple

#48
post #41

> Apple then manually reviews each report to confirm there is a match, This is always the terrifying part for me. They will access your personal photos or data without telling you. I’m surprised how is that even legal given all the law that are already available. Are they immune to those laws stated in thd blog? Also what happens when they launch this in EU, AU, etc with different privacy laws?

I think the article got that wrong. Apple does manually review tagged images, but does not access the original image, but the security voucher containing metadata, including the NeuralHash and a "visual derivative" of it (see Apple's spec [1]). Also, this only applies to pictures you upload to iCloud. So, it's not like they're accessing your personal photos without telling you. [1] https://www.apple.com/child-safety/…

Most iPhones have icloud backups enabled, which will trigger this detection automatically. Most iPhones are set up to upload every photo to icloud in case you lose your phone.

Re: One Bad Apple

#49

Earlier quoted context omitted.

Agreed - so dissapointing. The idea that standard moderation steps are a felony is such a stretch. Almost all the major players have folks doing content screening and management - and yes, this may invovle the provider transmitting / copying etc images that are then flagged and moderated away. The idea that this is a felony is rediculous. The other piece is that folks are making a lot of assumptions about how this wo…

Does the law have a moderation carve out? There are plenty of laws that have what's called 'strict liability' where your intent doesn't matter. I'm not suggesting that this is absolutely positively a situation where strict liability exists and that moderation isn't allowed. But the idea that "hey we're trying to do the right thing here" will be honored in court is....not obvious.

If we investigated this author if they do in fact run a photo service we would inevitably find that unless they are incompetent they have to moderate content, either blind or based on flags.

So if apple is going to jail for child porn because they moderate / report content after flagging (this is normally actually required to do - report it), then this article writer should be going to jail as well - I guarantee his services stores, forwards and otherwise handles CASM content.

My complaint is just - HN used to focus on stuff where folks didn't just always jump to worst case arguments (ie, apple is guilty of child porn and is committing felonies) without at least allowing that apple MAY have given this a tiny bit of thought.

It's just tiresome to wade through. It's a mashup of they are blocking too much, are the evil govt henchperson to they are breaking the law and going to jail for felony child porn charges.

I get that it generates interaction (here I am), but it's annoying after a while. Clickbait sells though no question so things like "One Bad Apple" are probably going to keep on coming at us.

Re: One Bad Apple

#50
post #34

Earlier quoted context omitted.

This is the part that also caught my eye. Surely Apple's lawyers have also reviewed the same law, and if it's that clearly defined, how did they justify/explain their approach?

Because Apple (its employees) aren't actually viewing the images, nor transmitting them. They mention somewhere that it's a low res proxy of the image, or something similar.

> They mention somewhere that it's a low res proxy of the image, or something similar.

Perceptual hashes are just integer/byte encodings of images that were scaled down and had some transformations applied to them.

If you convert a hash into an array of pixels and reverse the transformations, you'll get some of the original image that was scaled down and hashed.

Post reply on HN