Live data from Hacker News

In internal memo, Apple addresses concerns around new Photo scanning features

9to5mac.com

401–410 of 430 posts

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#401

A system on my phone where it has a list of bad files and a threshold on how many of those files are allowed. If the threshold is reached Apple can read them. Both the bad files list and threshold is controlled by Apple and is explicitly designed to be un-auditable... Honestly I would have been fine with Apple scanning my all photos after they are uploaded to iCloud but this is deeply disturbing

> Honestly I would have been fine with Apple scanning my all photos after they are uploaded to iCloud Apple has already been doing exactly this for years . Now they are going to check the photos right before uploading to iCloud which is actually more privacy friendly than they do now. It also lets Apple turn on e2e for iCloud photos if they want. I understand the 'what if' and slippery slope arguments, but wow, there…

> Now they are going to check the photos right before uploading to iCloud which is actually more privacy friendly than they do now.

That's like having the judge, jury, and executioner in my house.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#402

I'm seeing lots of news and pushback about the iCloud scanning stuff, but not a lot of news about the iMessage scanning and sharing stuff. I'm not a parent, thankfully; but if I were, I'm not sure I'd be entirely comfortable with the idea of other parents seeing my child naked. Even if I don't sign my child's account up for this scanning thing, the recipient could well be, and they won't be warned about that before s…

the imessage scanning is just to provide on-device warnings and blurring of photos that are suspected of being inappropriate. nothing is transmitted off the phone — parents are only given a notification (and only if their child is under 13, and only then if the child sends or replies to nude photos after being warned by the system)

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#403
post #392
post #271

Earlier quoted context omitted.

A lot of unwanted kids out there that end up in broken homes or on the street. There are also a lot of kids born in abusive families. Good ideas to stop the circulating would be to increase birth control education and access, increase foster care funding and access, implement common sense policies for adoption, and increase funding for Child Protective Services.

How does that stop existing CSAM from circulating?

It prevents CSAM from existing in the first place. Much like it would be ridiculous to search everyone's houses to stop drug use, it is far more effective to prevent the causes of drug dependency.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#404

Earlier quoted context omitted.

Apple doesn't currently have end-to-end encryption for iCloud Photos either: https://support.apple.com/en-us/HT202303

Not today. I think moving CSAM from the server where it's done today to device is in preparation for announcing e2e for iCloud photos.

That the insanity of all of this hand waving. Literally every public photo service does this today.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#405

Earlier quoted context omitted.

Android ROMs like GrapheneOS do not spy on you, verifiably.

It's non-trivial to unlock, root, and install a custom ROM - unless you are technical, very few people are going to be able to do this. Also, it's been several years since I used a custom ROM, but I thought rooted devices were not permitted to use the official Google Play Store? (happy to be corrected if I've got this point wrong!)

Rooting and installing a custom ROM are two independent things, you don't need one to have the other.

Rooted devices can use the official Play Store yes, though most people use Aurora Store to access the Play Store because they tend to remove Google Play Services from their phones as well.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#406

Earlier quoted context omitted.

It's still end-to-end for non-CSAM-matching content. Sounds fair, as long as it's strictly for CSAM check purposes.

> as long as it's strictly for CSAM check purposes And that's precisely the leaky part of this setup. Nothing about this system's design prevents that from changing on a mere whim or government request. Next year they could be adding new back-end checks against political dissident activity, Uyghur Muslims, ... and we'd be none the wiser.

Thank you for confirming the exact point I made.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#407

Earlier quoted context omitted.

I believe a lot of the outrage brewing now against Apple’s CSAM scanning is misdirected, and might actually be hurting the larger cause. Most ordinary people, especially those who have kids, won’t have a problem with a well-implemented, E2E encryption compatible scheme that is legally limited to only apply to this type of material. If explained the hash collision issue, they’d reasonably point out that Apple does man…

> Most ordinary people, especially those who have kids What are you basing this assumption on?

Experience with people.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#408

Earlier quoted context omitted.

Also, there's a "we can't show you the exact CP image that one of yours matched, because that would also be illegal" catch-22 that basically gives them the power to shroud this whole system in legally-obligated secrecy. Secrecy which will no doubt be abused to hide much more.

I do worry this is basically automating and scaling up the whole "idiot working at the mall photo development booth turns family in for child porn because they took pictures of 3 year old in bath" story that shows up every now and then.

[deleted]

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#409

I'm seeing lots of news and pushback about the iCloud scanning stuff, but not a lot of news about the iMessage scanning and sharing stuff. I'm not a parent, thankfully; but if I were, I'm not sure I'd be entirely comfortable with the idea of other parents seeing my child naked. Even if I don't sign my child's account up for this scanning thing, the recipient could well be, and they won't be warned about that before s…

the imessage scanning is just to provide on-device warnings and blurring of photos that are suspected of being inappropriate. nothing is transmitted off the phone — parents are only given a notification (and only if their child is under 13, and only then if the child sends or replies to nude photos after being warned by the system)

Not according to [1].

> Apple’s second main new feature is two kinds of notifications based on scanning photos sent or received by iMessage.

> To implement these notifications, Apple will be rolling out an on-device machine learning classifier designed to detect “sexually explicit images”.

> According to Apple, these features will be limited (at launch) to U.S. users under 18 who have been enrolled in a Family Account.

> In these new processes, if an account held by a child under 13 wishes to send an image that the on-device machine learning classifier determines is a sexually explicit image, a notification will pop up, telling the under-13 child that their parent will be notified of this content.

> If the under-13 child still chooses to send the content, they have to accept that the “parent” will be notified, and the image will be irrevocably saved to the parental controls section of their phone for the parent to view later.

[1] https://www.eff.org/deeplinks/2021/08/apples-plan-think-diff...

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#410

Earlier quoted context omitted.

Also, there's a "we can't show you the exact CP image that one of yours matched, because that would also be illegal" catch-22 that basically gives them the power to shroud this whole system in legally-obligated secrecy. Secrecy which will no doubt be abused to hide much more.

I do worry this is basically automating and scaling up the whole "idiot working at the mall photo development booth turns family in for child porn because they took pictures of 3 year old in bath" story that shows up every now and then.

I spent about a year working a retail photo processing lab - I can assure you that what you describe is exceedingly rare.

I saw “questionable” images on a probably weekly basis. Maybe once a month something would come through that I thought warranted bringing my supervisor over to provide a second set of eyes because I didn’t think it warranted calling the police over but wasn’t entirely sure. An example of that that comes to mind was a series of photos that appeared to show a young woman bound and gagged to a pipe in a basement area - but she was obviously of age, her eyes in the photos didn’t look fearful, and the rest of the roll showed her free and apparently happy. Finally, I was the person who accepted the roll of film and knew that she was the one who dropped it off. We didn’t call anyone on that, but I figured it wouldn’t hurt to get a second opinion. When she came to pick them up, I did ask her to review them and make sure everything was OK with them.

Twice in about a year we have photos come through that were obviously what’s now called “CSAM”. In both cases I called the police without consulting management then told them afterward. Also in both cases, the negatives were put into the store’s safe and the owners were arrested on-site when they came to pick them up.

All of this is to say - photo lab techs see some shit. If they called the police every time there was a picture of a kid in the bath, police brutality would be at an all time low because they’d not have time to respond to anything else. :)

Post reply on HN