Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

411–420 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#411
I'm confused. If iCloud backups are not encrypted [1], and this only scans iCloud photos, why can't they just do this server side? I'm not saying server-side is OK, but its at least not device side (which is obviously a slippery slope).

[1] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#412
post #388

Earlier quoted context omitted.

Laptop: Dell XPS 13 and very happy. Maxed out specs and clearly higher price range. Or: Lenovo Yoga Convertible. My second device. I just don't do games. Or bigger data stuff on this machine. Some design work. Some photo and smaller video stuff. I love the flexibility of the convertible when working with PDF and doing annotations by hand.

The battery on my xps seems to be swelling and messing up the trackpad. Apparently it’s a pretty common issue Edit: seems to be the precision line too > The same problem is happening with the Precision 1510 line with the same batteries. I purchased 10 of these laptops for my department around the same time you did. We've had four of these failures so far in three laptops. reddit.com/r/Dell/comments/6bzhtw/dell_xps_15…

Good to know. Will watch for it. Currently not an issue.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#413
post #377

Earlier quoted context omitted.

The new system is overkill for iCloud, which Apple already scans. The obvious conclusion is Apple will start to scan photos kept on device, even where iCloud is not used. Very smart people are not getting this wrong.

>> The obvious conclusion is Apple will start to scan photos kept on device, even where iCloud is not used. Wrong [1]. It's even in the first line of the document which you apparently didn't even read: CSAM Detection enables Apple to accurately identify and report iCloud users who store known Child Sexual Abuse Material (CSAM) in their iCloud Photos accounts This doesn't mean I'm supporting their new "feature". 1. ht…

nah. it means that they don’t scan it yet.

also by reading that doc and pointing to it means you trust apple.

i used to trust apple when they were peddling their privacy marketing stuff. not anymore.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#414
post #335

Earlier quoted context omitted.

The chance of you getting enough false positives to reach the flagging threshold is one in a trillion. And then the manual review would catch the error easily. The FBI won’t be called on you.

That's a claim by Apple. Due to the opaque process this is completely unverifiable. As well this statement relies on the fact that no malicious actor out there is trying to thwart the system. The hashes used are deliberately chosen to easily produce collisions otherwise the system won't work. This almost certainly will be abused.

The concept of checking images against a hash list is not unique to Apple or even new.

https://en.m.wikipedia.org/wiki/PhotoDNA

What Apple announced is a way to do it on the client device instead of the server. That has some security implications, but they’re more specific than just “hashes might collide.”

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#415

I'm waiting for orthodox authorities to do stuff like reporting pictures of people (not just girls) without head coverings. or dressed in bikinis, thongs, or underwear (like a significant number of "influencers" do, every day). There are already places in this world, where a couple can be arrested for kissing in public. I suspect that the folks enforcing those laws, would have some real interest in this capability. N…

That’s not at all how this works. It doesn’t scan for images of arbitrary subjects. It scans for exact matches of known CP. Your vacation pics are in no danger of being flagged.

In the real world, exact matching of image hash values won't work.

It's routine for images to change in small ways over their lifetimes as they're shared. According to the model you suggest, modifying a single pixel in the image by even the smallest amount would cause a hash mismatch against the original. If Apple's system is truly that inflexible, it will be trivial to circumvent in no time. Just increment / decrement a random RGB pixel in each of your images, and voila, your porn is scot free.

Of course this countermeasure will be employed almost instantly by miscreants, so how will the FBI respond? Will they give up? Certainly not. They already have a blank check to spy on our phones. So they will devise a clumsier match algorithm that scans more sources of data on your phone and your cloud accounts and your backups, and produces more false positives. Why wouldn't they do this?

Once any telecom service provider opens a door which compromises security or privacy, they will have a much harder time closing it.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#416

US Government: We suspect the person in this photo of committing a crime. Here is your subpoena, Apple. You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them. Chinese Government: Here is the NeuralHash for Tienanmen square. Delete all photos you find matching this or we will bar you from China. Apple has at this point already admitted thi…

As far as I can see:

1. This is a serious attempt to build a privacy preserving solution to child pornography.

2. The complaints are all slippery slope arguments that governments will force Apple to abuse the mechanism. These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it.

However:

Child pornography and the related abuse is widely thought of as a massive problem, that is facilitated by encrypted communication and digital photography. People do care about this issue.

‘Think of the children’ is a great pretext for increasing surveillance, because it isn’t an irrational fear.

So: where are the proposals for a better solution?

I see here people who themselves are afraid of the real consequences of government/corporate surveillance, and whose fear prevents them from empathizing with the people who are afraid of the equally real consequences of organized child sexual exploitation.

‘My fear is more important than your fear’, is the root of ordinary political polarization.

What would be a hacker alternative would be to come up with a technical solution that solves for both fears at the same time.

This is what Apple has attempted, but the wisdom here is that they have failed.

Can anyone propose anything better, or are we stuck with just politics as usual?

Edit: added ‘widely thought of as’ to make it clear that I am referring to a widely held position, not that I am arguing for it.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#417

I'm confused. If iCloud backups are not encrypted [1], and this only scans iCloud photos, why can't they just do this server side? I'm not saying server-side is OK, but its at least not device side (which is obviously a slippery slope). [1] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

there has been some speculation that they will turn on encryption after pushing this out. if this turns out to be true apple sucked at controlling the PR for this whole thing.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#418
post #399

Earlier quoted context omitted.

We can carry every single element back to its inception and make identical arguments. That's the problem with slippery slopes. Apple - creates messaging platform. Slippery slope - governments can force Apple to send them all messages. Apple - creates encrypted messaging platform. Slippery slope - governments can force Apple to send them the keys and all messages Apple - Adds camera to device (GPS, microphone, acceler…

Do keep in mind that atleast one govt has successfully preassured apple to give up on its privacy Also the difference here compared to the scenarios you've mentioned above is that Apple has walked pretty far. All it would take is to make the verification happen on all local files irrespective of its being uploaded to iCloud or not. Then any government can provide their own hashes to apple to keep track of. Apple won'…

"Do keep in mind that at least one govt has successfully pressured apple to give up on its privacy"

No company can defend you from your government.

"All it would take"...

That is the slippery slope. If a government is going to say "that's a nice looking hashing system you have there, now we need you to..." they could as easily -- more easily -- have said "that's a nice filesystem you have there, we need you to...".

Hashing files and comparing them against a list is literally a college grad afternoon project. There is absolutely nothing in Apple's announcement that empowers any government anywhere in any meaningful way at all. It is only fear-mongering (or simply raw factual errors as seen throughout this discussion) that makes it seem like it does.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#419

So the M1 has turned me off of Apple products because, quite frankly, I don't want to spend (more) of my time fixing shit a trillion dollar company broke and doesn't care to fix. This though, this will be the nail in the coffin with my 25 year relationship to Apple. I probably wouldn't even have batted an eye at it to be honest, iff, Apple hadn't been selling me on the idea that their platform is "private and secure.…

I used to downvote people a couple of years ago who were shedding doubt on Apple’s commitment to privacy.

Boy. I was so wrong. I fell for the Marketing and it made sense at the time “Their business is selling hardware and services, not ads. Ofcourse they are privacy advocates”.

Pass laws and legislation. I admit I was wrong and it’s refreshing to see this whole thing unfold before my eyes. It just solidified my opinion about open source hardware.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#420
post #95

Earlier quoted context omitted.

It is not the role of infrastructure providers to reach into private, on device content. That is like the USPS opening every letter and scanning what is inside. Even if it's done with machine learning, that is absolutely not okay, no matter what it is for.

Though we were okay with Gmail doing the same because "hey, it's free!". But I understand your concern here. All our lives are now digitalised and maybe stored forever somewhere and anything you do, even if completely benign, could be considered a crime in some country or even in your own country in a few years from now.

nope. i’m not okay with Gmail doing that. in fact I’ve completed removed all google products from my life. i don’t need someone to constantly spy on me.
Post reply on HN