Earlier quoted context omitted.
Given that they obviously already have the capability to send software updates that add new on-device capability, this seems like a meaningless distinction. It’s already “just policy” preventing them from sending any conceivable software update to their phones.
I disagree, strongly. Let's say you're authoritarian government EvilGov. Before this announcement, if you went to Apple and said "we want you to push this spyware to your iPhones", Apple would and could have easily pushed back both in the court of public opinion and the court of law. Now though, Apple is already saying "We'll take this database of illegal image hashes provided by the government and use it to scan you…
Apple's child protection features spark concern within its own ranks: sources
411–420 of 860 posts
Re: Apple's child protection features spark concern within its own ranks: sources
#412Earlier quoted context omitted.
With server-side scanning, the separation is clear In all these threads everyone is coming close to the crux of the issue, but I want to restate it in clearer terms: There is a sacrosanct line between "public" and "private," "mine" and "yours." That line cannot be crossed by Western governments without a warrant. Cloud computing has deliberately blurred this line over time. This on-device scanning implementation blow…
> There is a sacrosanct line between "public" and "private," "mine" and "yours." That line cannot be crossed by Western governments without a warrant. This is a self-delusion, I am afraid. The line has been crossed more than once, and it will be crossed again. UK and Australian governments are just two prime examples of waving terrorism and pedobear banners as a pretext to get invasive with each new legislation, and…
Even if the cops and private security along with TLAs are actively spying on people on an extremely regular basis, we're better off if officially they aren't supposed to be, if some court cases can get tossed for this, that they have to retreat sometimes, etc.
This is why having Apple overtly spying on the "private side" is still a big thing even with all the other revelations.
Re: Apple's child protection features spark concern within its own ranks: sources
#413Earlier quoted context omitted.
I disagree, strongly. Let's say you're authoritarian government EvilGov. Before this announcement, if you went to Apple and said "we want you to push this spyware to your iPhones", Apple would and could have easily pushed back both in the court of public opinion and the court of law. Now though, Apple is already saying "We'll take this database of illegal image hashes provided by the government and use it to scan you…
Why do you think essentially no one is complaining about using ML to understand the content of photos, then (especially in comparison to this rather targeted CSAM feature)? My impression is that both Apple and Google have already been doing that since what? 2016? Earlier? There's been no need for a database of photos, either company could silently update those algorithms to ping on guns, drugs, Winnie the Pooh memes,…
Have been whining about big data for and ML recognition systems for years.
Re: Apple's child protection features spark concern within its own ranks: sources
#414"...You can't have a backdoor that's only for the good guys. That any back door is something that bad guys can exploit."
"No one should have to choose between privacy and security. We should be smart enough to do both."
"You're assuming they're all good guys. You're saying they're good, and it's okay for them to look. But that's not the reality of today."
"If someone can get into data, it's subject to great abuse".
"If there was a way to expose only bad people.. that would be a great thing. But this is not the world. .... It's in everyone's best interest that everybody is blacked out."
"You're making the assumption that the only way to security is to have a back door.....to be able to view this data. And I wouldn't be so quick to make that judgement."
No matter the mental gymnastics now, it's still a pretty drastic departure from what it used to be.
Re: Apple's child protection features spark concern within its own ranks: sources
#415Earlier quoted context omitted.
It’s only a “farce on borrowed time” because you have the benefit of hindsight.
Not true, unless by "having the benefit of hindsight" you mean "having watched Apple's actions for the last few years". Yes, they do a lot for privacy. But when it comes to their bottom line, they also have a record of compromising on privacy (and consumer rights in general) to preserve business with less than freedom-loving countries such as China, the UAE, Russia. It is sometimes difficult to criticize them for thi…
Except that they are making money on overpriced headsets and acquisitions like Beatz.
I guess they have always compromised on privacy to make more $$, whether it is the crummy protections for browsing on iOS, selling out to Google, or the nearly required bluetooth. Now, I am sure there are a lot more things to add to this list..
Two Final thoughts:
From a business perspective this is a serious impairment on Goodwill.
Loss of Privacy is going to negatively impact Apple services.
Re: Apple's child protection features spark concern within its own ranks: sources
#416Earlier quoted context omitted.
Send it via WhatsApp where it gets added to photos and later iCloud by default if I recall correctly
Citation desperately needed.
Re: Apple's child protection features spark concern within its own ranks: sources
#417This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…
I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…
>... to address the CSAM issue lest governments come down on them hard.
And I think that is the springboard of why this is happening.
It's no secret that Apple has lobbyists which by turns have a "pulse" on the trajectory of Bills in the House and Senate.
What immediately came to mind to me was H.R.485 of 2021's House Session:
https://www.congress.gov/bill/117th-congress/house-bill/485/...
My (layperson) estimation is that Apple knows the rewording of it is liable pass both House/Senate in some way either in the 2022 or 2023 sessions and are attempting to get ahead of the issue. (most likely as a "rider" bill at this point)
That's my thought process on what may have precipitated Apple's move toward "CSAM"; and I welcome it in some ways (unequivocally, children should not be subjected to sexual abuse) and am wary of it in others (ML is in its infancy in too many respects, and if a false-positive arises who's to say what's liable to happen on the Law Enforcement level).
There are infinitely many concerns to be discussed on both sides of this argument, and I want both to succeed in their way. CSAM, however, feels like an attempt to throw a blanket over Apple's domains-of-future-interests while playing an Altruism Card.
One thing is certain, though: they've opened the floodgates to these discussions on an international level...
Re: Apple's child protection features spark concern within its own ranks: sources
#418Earlier quoted context omitted.
This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…
> But with Apple's CSAM proposal is NOT possible to have an iPhone that Apple isn't continuously scanning. As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone.
Re: Apple's child protection features spark concern within its own ranks: sources
#419This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…
To me the issue is that it makes no sense: if it's just scanning iCloud photos, ___why does this feature need to exist at all__? Apple is saying this: "we need to scan your phone because we need to look for this material, and by the way, we're only scanning things _we've been scanning for years already_" Basiclaly, everything else aside, in the current state of things, this feature makes no sense. They are not scanni…
Re: Apple's child protection features spark concern within its own ranks: sources
#420As far as I understand it, the CSAM hash database is part of the OS, which Apple can update in any way they like, including to read your messages or surreptitiously compromise the encryption of your photos (and they can force your device to install this code via a security update). We trust them not to do these things (they already have a track record of resisting the creation of backdoors), so I’m not sure why they we don’t trust them to also use this capability only for CSAM.
Sure, it would be technically easier for them to add the hash of the tank man photo (an example of something an oppressive government might be interested in) to their database after something like this is implemented, but it’s also not very hard for them to add scanning-for-the-tank-man-photo to their OS as it currently exists. Indeed, if the database of hashes lives on your device it makes it easier for researchers to verify that politically sensitive content is not present in that database.