Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

401–410 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#401

Earlier quoted context omitted.

> a non-insignificant amount of people in tech take this seriously We're all here to make ourselves feel good saying we Took A Stand. In reality, four weeks from now, do you think anybody will still be talking about it? I made this same mistake. I was pretty convinced that people were taking Copilot seriously, and that there was possibly going to be ramifications for Microsoft. I wasn't particularly looking forward t…

A typical defeatist neo-luddism stance. You are part of the problem. Instead of spreading your nihilism, you could be a force for good. We are not powerless. We can make a difference. Contact your elected officials. Start a movement. Create a direct competitor to Apple. I know it’s tough, but we all just need to come together and stop the negativity. Excuses or results. You choose. Sent from my iPhone

Contacting your local representative is the right move. Bear in mind this change is specifically to comply with a law mandating the scanning of photos stored in the cloud, that’s why apart from the opt in for children’s iMessages, it only applies to photos you upload to iCloud storage.

The way to stop companies complying with the law is to get the law changed.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#402
post #41

Honestly I'm glad to see a non-insignificant amount of people in tech take this seriously, especially when the goal Apple announces appears to be for the greater good. It can be hard to stand on the side that doesn't immediately appear to be correct. We have already lost so many freedoms for 'national security' and other such blanket terminology. Just be warned, there will be those that unfairly try to cast this as h…

> a non-insignificant amount of people in tech take this seriously We're all here to make ourselves feel good saying we Took A Stand. In reality, four weeks from now, do you think anybody will still be talking about it? I made this same mistake. I was pretty convinced that people were taking Copilot seriously, and that there was possibly going to be ramifications for Microsoft. I wasn't particularly looking forward t…

> Like it or not, we aren't in control.

Yes you are. Leave the default and don’t enable this for your children’s iPhones, and the iMessage change won’t affect you. Switch off iCloud photo storage and none of your photos will be scanned. You have complete control over this.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#403

Earlier quoted context omitted.

> a non-insignificant amount of people in tech take this seriously We're all here to make ourselves feel good saying we Took A Stand. In reality, four weeks from now, do you think anybody will still be talking about it? I made this same mistake. I was pretty convinced that people were taking Copilot seriously, and that there was possibly going to be ramifications for Microsoft. I wasn't particularly looking forward t…

A typical defeatist neo-luddism stance. You are part of the problem. Instead of spreading your nihilism, you could be a force for good. We are not powerless. We can make a difference. Contact your elected officials. Start a movement. Create a direct competitor to Apple. I know it’s tough, but we all just need to come together and stop the negativity. Excuses or results. You choose. Sent from my iPhone

God pompous people like you are the worst. You are the same idiot that thinks recycling is the answer. It's actually your BS we have the power garbage that is the problem.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#404
post #240

Earlier quoted context omitted.

I think it makes sense to take a step back and ask yourself if Apple, or any sensible Western company, would set up a system that could falsely flag millions of people, or even a hundred. Even without going into implementation details, it seems clear that they would not have a system that would flag standard family photos.

I wouldn't over-/underestimate the support capabilities of a big corp like Apple. I remember the Twitter account takeover hack a year ago, which was possible only because customer support had some 2FA-bypass: https://en.wikipedia.org/wiki/2020_Twitter_account_hijacking To prevent false-positives, who knows if they have a "review" team that takes a tiny little peek at my naked son. Do you know for sure that no such sy…

They are not looking at your photos at all, they are comparing hashes of them to hashes of KNOWN predatory material. Your family photos will not be in that database.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#405
post #267

Earlier quoted context omitted.

> The private set intersection is an alternative to sending you a list of bad-image hashes which uses significantly more bandwidth than simply sending you the list. How can the image hashes take up more space than the images themselves? Are you sure about this?

That’s not what they wrote, double check your comprehension.

Obviously I don't understand it then, care to explain?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#406
post #269

Notice, for example, that Thunderbird is sending file names and SHA-256 hashes when you open most (e.g. .pdf) attachments, in the clear, to Google. This seems worse to me (in the Apple case, the information is revealed only if enough files from one device match against a predefined hash list) and nobody really cares... I have just tested with a fresh profile with a freshly downloaded thunderbird-78.12.0.tar.bz2 (x64…

I had no idea. What is the reason for this default behaviour?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#407

Earlier quoted context omitted.

But we've already established there is no public oversight over the contents of the NCMEC database and that there cannot ever be, by design. Furthermore, it's known to contain hashes of non-CSAE images simply because they were found in a CSAE-related context. So how can this system guarantee civil freedom? How can it be guaranteed that it won't be exploited by the small number of people in power to actually inspect i…

Have we established that? Certainly not a reality I recognize. The processes involved in CSAM databases like NCMEC/ICSE are many years old. If it leads to widespread civil rights abuses, where are they? Google Drive has 1bn users. Google scans content for CSAM already. Shouldn't we be seeing these negative side effects already? Proponents of these systems can point to thousands upon thousands of actual "wins" (such a…

> If it leads to widespread civil rights abuses, where are they?

This is disingenuous, since up to this point these databases weren't used in systems residing on end user devices, scanning their local files.

The disadvantages aren't merely "theoretical"; they just haven't materialized yet since the future does not yet exist. To ignore these obvious faults by hand-waving them as theoretical is to blatantly ignore valid concerns raised by thousands of informed citizens.

No system is perfect, but that doesn't mean there aren't some systems that simply go too far.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#408

Earlier quoted context omitted.

This is a reality you have to accept. It is a simple matter to get away with owning this kind of material, dragnet method or not. There is no point in trying to eradicate all such material and bring the number to absolute zero. It's impossible. The only way to semi-ensure this would be absolute slavery of the citizenry, which I hope is a non-goal.

Nobody is proposing that though... It's a fact that NCMEC referrals have identified teachers who were secretly pedophiles, who were subsequently banned from teaching. Most people see this as a good thing. If you want to do away with this, you have to bring a compelling argument. I support everybody's right to argue for the type of society they want to see, but there's an arrogance/conspiratorial flavor to a lot of th…

I don't deny the system has some benefits, they just aren't benefits I will gladly give up my own freedom for nor the freedom of my fellow citizens.

I don't want to do away with anything; I just want "you" out of my devices, where "you" don't belong anyway and where you haven't been up to this point. (Well, you still aren't there because I don't use an iPhone, but hopefully the point is clear.)

Also note that I'm not against the use of such technology in certain situations, such as in unencrypted cloud storage. Though concerns with lack of oversight exist there as well! But installing this on end user devices goes a (huge) step too far.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#410

Earlier quoted context omitted.

I think your proclamation of it all being futile is a bit premature and can be disheartening for those that do want to act. It may even play a part in negative change, leading to some people dropping their original intention because you successfully convinced them that nothing can possibly change. Yet, I'm not convinced that you can reasonably know this. So if we can all agree that what's happening here with Apple is…

The irony here is while arguing that we should fight for our freedoms you are suggesting I shouldn't exercise one of my freedoms. I do get your point, honestly I do, but you can't have it both ways.

I do want to emphasize that this wasn't a "you can't do that" type of thing, though. You absolutely have the freedom to do it.

My comment was meant more in a "Do you really want to, given that this might have an effect that we both deem negative?" kind of way.

Post reply on HN