Live data from Hacker News

An open letter against Apple's new privacy-invasive client-side content scanning

github.com

411–420 of 451 posts

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#411
post #285
post #252

Earlier quoted context omitted.

I actually view this as not a good sign. That many are still in the very very early stage of shock, what Apple is doing does not align with their perceived values. Deducting points from Apple in their own mental model. They write these letter because they think Apple is still mostly good and hope they could have a change of heart. What would happen as some others have pointed out, people will forget about it. Apple w…

It might be hard to understand, but iOS is a blackbox. Based on what they add and say, we still don't know what exactly is happening. All we have is trust. We can speculate that with "what ifs", but same "if" is applying already. Once we take other big platforms on account, Apple is actually trying to note privacy. Other platforms just scan everything you put in cloud, but Apple tries to limit the information what th…

IIRC, Apple was already scanning iCloud server-side for CSAM [0] so I'm not sure if that excuse holds.

[0] https://www.macobserver.com/analysis/apple-scans-uploaded-co...

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#412

Earlier quoted context omitted.

Have we established that? Certainly not a reality I recognize. The processes involved in CSAM databases like NCMEC/ICSE are many years old. If it leads to widespread civil rights abuses, where are they? Google Drive has 1bn users. Google scans content for CSAM already. Shouldn't we be seeing these negative side effects already? Proponents of these systems can point to thousands upon thousands of actual "wins" (such a…

> If it leads to widespread civil rights abuses, where are they? This is disingenuous, since up to this point these databases weren't used in systems residing on end user devices, scanning their local files. The disadvantages aren't merely "theoretical"; they just haven't materialized yet since the future does not yet exist. To ignore these obvious faults by hand-waving them as theoretical is to blatantly ignore vali…

The distinction between scanning locally before upload, and on server after upload, is an implementation detail. The only reason Apple have done this is to allow them to implement E2EE for iCloud without hosting CSAM.

All arguments relating to anything other than this are arguing against something that doesn't exist.

I don't dispute that fictional proposals in the imaginations of HNers might pose a grave (fictional) threat to civil freedoms.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#413

Earlier quoted context omitted.

Nobody is proposing that though... It's a fact that NCMEC referrals have identified teachers who were secretly pedophiles, who were subsequently banned from teaching. Most people see this as a good thing. If you want to do away with this, you have to bring a compelling argument. I support everybody's right to argue for the type of society they want to see, but there's an arrogance/conspiratorial flavor to a lot of th…

I don't deny the system has some benefits, they just aren't benefits I will gladly give up my own freedom for nor the freedom of my fellow citizens. I don't want to do away with anything; I just want "you" out of my devices, where "you" don't belong anyway and where you haven't been up to this point. (Well, you still aren't there because I don't use an iPhone, but hopefully the point is clear.) Also note that I'm not…

Sorry, to clarify, you do in fact support Apple running the exact same scans on their server side CPUs? A situation that has the exact same effects on society...?

Your only concern then, is with a future authoritarian policy of your own imagination?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#414

The common, instinctive reaction in tech circles & HN seems to be some version of "consumer action," vote-with-your-dollar stuff. This isn't going to work. It almost never does. At most, it'll be affect a minor tweak or delay. This is a political issue, IMO. A thousand people protesting outside Apple HQ and/or stores is worth more than 100 thousand consumer striking. IMO, the main non-political avenue here is alterna…

> The common, instinctive reaction in tech circles & HN seems to be some version of "consumer action," vote-with-your-dollar stuff. This isn't going to work. It almost never does. At most, it'll be affect a minor tweak or delay. If "vote with your wallet" doesn't work and only causes, say, 1 million people (out of the billion+ customers) to switch off of iOS, doesn't that mean that the rest of the billion+ people rea…

>>If "vote with your wallet" doesn't work and only causes, say, 1 million people (out of the billion+ customers) to switch off of iOS, doesn't that mean that the rest of the billion+ people really don't care enough?

IMO, no. This is silly logic. I don't particularly care that Apple scan my photos.

First, most people don't care about or understand any particular issue well. You might care about the freedom issue here. Another person cares about oceanic biodiversity. Another person cares about factory working conditions. All of them make purchasing decisions that affect all of these. The civilians will always outnumber activists 100-1 on any particular issue.

Second, in this particular case, choices are few and poor. Hence exasperated declarations of going back to dumb phones or DIYing something.

Third people's individual purchasing decisions don't have any effect on the thing they're trying to affect.

In any case, my point was empirical, not theoretical. There are very few significant examples of consumer action amounting to anything. Where it has (eg dolphin safe tuna), consumer action was one piece of a much bigger puzzle, and more about raising awareness than direct. IE people buying dolphin safe tuna also become insistent on regulatory action. By the same logic, you could conclude that people don't care enough about anything. In which case, we come to the same conclusion.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#415
post #321

Earlier quoted context omitted.

Thanks for the link, but have you read it? "the only country that spends more on military is China" 1 1 United States 778 4.4 -10 3.7 4.8 39 2 2 China [252] 1.9 76 [1.7] [1.7] [13] 3 3 India 72.9 2.1 34 2.9 2.7 3.7 :facepalm:

I compared US' __police__ spending of $100 billion, to the __military__ spending of other countries. I assume you missed that. The comparison is not between militaries, but US' police vs the military. :facepalm:

Ay, I did miss that, didn't go up enough to see the parent :facepalm: China do spend more on defense than policing, at lease nominally, per page 5 of the 2021 budget proposal hosted on Xinhua:

"National defense spending was 1.267992 trillion yuan, 100% of the budgeted figure. Public security expenses totaled 183.59 billion yuan, 100.2% of the budgeted figure. "

http://www.xinhuanet.com/english/download/20210313budget.pdf

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#416

Earlier quoted context omitted.

Nobody is proposing that though... It's a fact that NCMEC referrals have identified teachers who were secretly pedophiles, who were subsequently banned from teaching. Most people see this as a good thing. If you want to do away with this, you have to bring a compelling argument. I support everybody's right to argue for the type of society they want to see, but there's an arrogance/conspiratorial flavor to a lot of th…

> If you want to do away with this, you have to bring a compelling argument. I'm a law-and-order guy myself, have applied for (technical) position in police and would even accept a paycut for it. But it is with this like with other security related things, many people only considers two of the three cornerstones: - confidentiality - integrity - availability Same here: Justice is not only about punishing every very ba…

I completely agree with your characterization of the various concerns.

I don't agree with the characterization that this system will cause baseless accusations.

These systems have been in place for many years and have proven themselves useful and reliable.

Apple have tried to implement it in a way that allows them to turn on E2EE on iCloud, and HN has turned that into a conspiracy theory.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#417
post #122

Earlier quoted context omitted.

Yes, there seems to be a lot of conflation between the two separate systems (in the media, and in comments on here). As you say, it’s important to be precise, otherwise people won’t take your arguments seriously. To summarise: One system involves hash checking. This is performed when photos are being uploaded to iCloud. The hashes are calculated on-device. Private set intersection is used to determine whether the pho…

Based on my reading, the first system is interesting in that the threshold is also cryptographically determined. Each possible hit forms part of a key, and until a complete key is made none of the images can be reviewed. Should also be noted the second system sends no images to Apple or is reviewed by Apple employees in any way. It's just using the same on device ML that finds dog pics for example. I think Apple PR s…

> Should also be noted the second system sends no images to Apple or is reviewed by Apple employees in any way.

You are directly contradicting Apple's public statement:

> Apple manually reviews all reports

( https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni... )

Moreover, it was found that in US v. Ackerman that the NCMEC's inspection of a user's private email was an unlawful violation of their fourth amendment rights specifically because AOL passed along the email based on a hit against the NCMEC database without inspecting it. Had AOL inspected it than the repetition of the inspection by NCMEC would simply be a repetition of the search performed by AOL which was permitted under their contract with the customer.

Not only does Apple state that they will "review" the images, they must do so in order to deprive the user of their forth amendment protection against unlawful search by the government.

> and is probably one of the blockers to full E2E encryption for iCloud photos

Apple is free to provide encryption and they are choosing to not do so.

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#418
post #398
post #360

Earlier quoted context omitted.

Truetrue, it need's some caching and cpu capability, like the map when your offline...stuff like that..but with 5G...well we will see ;)

Ah yes, 5G. The bag of promises telco execs have dangled in front of large customers for nearly a decade that will deliver on all their needs. If they could just figure out how to deliver on it ;-)

>If they could just figure out how to deliver on it

Install an antenna? You know that before 5G there was a 4,3,2,1,0.5 G?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#419
post #396
post #331

Earlier quoted context omitted.

>How often do you come into contact with the OS when developing for a phone, let alone use a phone That's exactly the point, Maybe you don't know what Plan9 is, but see it like that: The Phone is just a Terminal. If i want todo business i connect my terminal to my Workplace-servers, every application, datas and settings are there, the calculation heavy stuff and backup is made on the server. If finished i connect to…

I both know plan 9 and what falling in love with an idea to the degree where one stops thinking about the implications looks like.

Having Unix and try to implement Plan9 on top of it?

Re: An open letter against Apple's new privacy-invasive client-side content scanning

#420
post #417

Earlier quoted context omitted.

Based on my reading, the first system is interesting in that the threshold is also cryptographically determined. Each possible hit forms part of a key, and until a complete key is made none of the images can be reviewed. Should also be noted the second system sends no images to Apple or is reviewed by Apple employees in any way. It's just using the same on device ML that finds dog pics for example. I think Apple PR s…

> Should also be noted the second system sends no images to Apple or is reviewed by Apple employees in any way. You are directly contradicting Apple's public statement: > Apple manually reviews all reports ( https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni... ) Moreover, it was found that in US v. Ackerman that the NCMEC's inspection of a user's private email was an unlawful violation of their fourth amen…

I was referring the second system mentioned by the parent. NOT the CSAM system. Conflating these systems has been huge issue with the random articles coming out. They are distinct.

From the GP > The second, independent, system, is a machine learning model which runs on-device to detect sexually explicit photos being received on Messages.app. This system is designed to be run on children’s phones. The system will hide these explicit images by default, and can be configured to alert parents - that feature is designed for under-13s. This system doesn’t use the CSAM hash list.

> Apple is free to provide encryption and they are choosing to not do so.

Sort of. They cited the FBI a few years ago when they put the brakes on adding E2EE to everything. It would also create a huge target for legislation, 'Apple is helping CP people - think of the children!' The new method of CSAM will let Apple add E2EE, and fight off calls for legislation.

Post reply on HN