Live data from Hacker News

In internal memo, Apple addresses concerns around new Photo scanning features

9to5mac.com

421–430 of 430 posts

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#421

Earlier quoted context omitted.

This is completely wrong . The known collision attacks for the MD-family and SHA-1 all in fact produce collisions with the exact same length. The method used necessarily does this.

> This is completely wrong. Which part? The fact that storing "length" along with a hash is not superfluous? You can probably find many things which have a SHA hash of "ca978112ca1bbdcafac231b39a23dc4da786eff8147c4e72b9807785afee48bb" (infinite things, if we assume arbitrary-sized inputs), but you can only find ONE thing which has that hash and has length 1. I just made it impossible (not just unlikely) for you to fi…

> Which part? The fact that storing "length" along with a hash is not superfluous?

The part where you make a false claim out of ignorance.

> You can probably find many things which have a SHA hash of "ca978112ca1bbdcafac231b39a23dc4da786eff8147c4e72b9807785afee48bb"

No reason I should go looking for such things. You're the one making the false claims, if you have found "many things" with that hash then list them to prove your point, otherwise go away.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#422

Earlier quoted context omitted.

> This is completely wrong. Which part? The fact that storing "length" along with a hash is not superfluous? You can probably find many things which have a SHA hash of "ca978112ca1bbdcafac231b39a23dc4da786eff8147c4e72b9807785afee48bb" (infinite things, if we assume arbitrary-sized inputs), but you can only find ONE thing which has that hash and has length 1. I just made it impossible (not just unlikely) for you to fi…

> Which part? The fact that storing "length" along with a hash is not superfluous? The part where you make a false claim out of ignorance. > You can probably find many things which have a SHA hash of "ca978112ca1bbdcafac231b39a23dc4da786eff8147c4e72b9807785afee48bb" No reason I should go looking for such things. You're the one making the false claims, if you have found "many things" with that hash then list them to p…

> The part where you make a false claim out of ignorance.

Which false claim did I make? I'm still waiting...

> No reason I should go looking for such things. You're the one making the false claims, if you have found "many things" with that hash then list them to prove your point, otherwise go away.

You don't need to look for those things. By definition, you know they exist. I don't need to find or enumerate all primes to know that an infinite number of them exist.

For more information, see here: https://en.wikipedia.org/wiki/Pigeonhole_principle

By definition, assuming arbitrarily-sized inputs, there are infinite messages that collide to the same hash value.

But, don't worry... it is clear you have no actual meaningful point to add, so I won't continue this conversation with you any further. Have a nice day.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#423
post #351

Earlier quoted context omitted.

I think this is highly unlikely, everything points to Apple ditching the idea altogether : https://www.bbc.com/news/technology-51207744 Many foreign countries have also clearly stated that they do not want this (E2EE) to happen and would legislate against it (the UK comes to mind first). I do believe that you are correct with the idea that this technology was initially developed as a compromise to E2EE. But while E2E…

I read that article and see this new method as work around for the FBI complaints, and once again allowing E2EE to move forward. Technology doesn't live in a vacuum. Given the calls from the government for backdoors to encryption, I think it's safe to assume this is Apple getting out in front of what could likely be heavy handed legislation to add actual backdoors like master keys. But, we'll have to wait and see if…

> Technology doesn't live in a vacuum. Given the calls from the government for backdoors to encryption, I think it's safe to assume this is Apple getting out in front of what could likely be heavy handed legislation to add actual backdoors like master keys.

I broadly agree but I cannot foresee a scenario where limiting at this particular issue (CSAM) would be seen as a sufficient compromise by legislators to allow E2EE to be expanded.

And other countries will have very different interpretations, much less palatable to Apple's values, on what should be checked for and they will have no qualm legislating to require it.

Quoting the NY Times (via Daring Fireball) :

> Mr. Neuenschwander dismissed those concerns, saying that safeguards are in place to prevent abuse of the system and that Apple would reject any such demands from a government.

> “We will inform them that we did not build the thing they’re thinking of,” he said.

They can tell themselves that but it doesn't matter : they precisely did.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#424
post #332

Earlier quoted context omitted.

If they can do a manual review at all, then there isn’t end to end encryption anymore, so I’m missing what the point of client side scanning is.

End to end encryption of messages is by comparison easy as the devices can handle all of that internally. However, losing your iPhone is one of the main reasons to have an iCloud backup. Require a user to come up with a private key and any user who lost it also loses all their data. Most people don’t really want end to end on consumer backup services, because of the associated risks. If however you don’t want unsecur…

The main selling point of Apple is how well integrated the ecosystem is, they could make it super simple to backup the private key on your different devices like watch, tablet and laptop.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#425

Earlier quoted context omitted.

Apple doesn't currently have end-to-end encryption for iCloud Photos either: https://support.apple.com/en-us/HT202303

Not today. I think moving CSAM from the server where it's done today to device is in preparation for announcing e2e for iCloud photos.

Apple has gotten a ton of heat over this and they haven't once mentioned that e2e on iCloud is something they're working on or that this technology would make possible, so can people stop spreading this narrative that this is their goal? It's completely baseless.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#426

Earlier quoted context omitted.

Meanwhile, trolls and staunch intellectuals demanding "enough" evidence think they can gatekeep what's acceptable to notice is already slipping and gaslight others for noticing and worrying, only to find that years later, the Overton window shifted and newer generations were none the wiser, bringing the things that were previously unacceptable into the mainstream with reckless abandon. (edited for brevity, expanding…

I'm going to get a little facetious here: The corporation that is the U.S government acts just like one: roadmaps and planning ahead for radical policy changes to occur within longer spans of time to signify progress (or something), and then absolutely losing their shit if an opposing candidate wins & gets in the way of their progress, as we observed these past 5 years. Acceptance of pedophilia has been set in motion…

The only example you mentioned that is attributable to government is sex-ed.

Sex education isn't about teaching you how to have sex, it's "here's all the reasons you need to be very careful with sex".

In my classes I learned about many different STI's and the dangers of unprotected sex. Not once was I taught a Kamasutra position or what to do with my fingers.

For younger kids I assume the curriculum would be more about what kinds of behaviors they need to be careful of and immediately warn other adults about.

I suppose the name is very unfortunate because a lot of people seem to think sex-ed is about getting young people to start having sex, when in fact it has the opposite result and we can see it in statistics.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#427

Earlier quoted context omitted.

Ah ok, so as long as it is profitable ethics don't matter. Got it.

Companies don't have to be ethical, they just have to be legal.

Precisely. I just have a problem with them being hypocrite.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#428

Earlier quoted context omitted.

> Which part? The fact that storing "length" along with a hash is not superfluous? The part where you make a false claim out of ignorance. > You can probably find many things which have a SHA hash of "ca978112ca1bbdcafac231b39a23dc4da786eff8147c4e72b9807785afee48bb" No reason I should go looking for such things. You're the one making the false claims, if you have found "many things" with that hash then list them to p…

> The part where you make a false claim out of ignorance. Which false claim did I make? I'm still waiting... > No reason I should go looking for such things. You're the one making the false claims, if you have found "many things" with that hash then list them to prove your point, otherwise go away. You don't need to look for those things. By definition, you know they exist. I don't need to find or enumerate all prime…

You are misrepresenting or more likely have simply misunderstood the Pigeonhole Principle. Which I guess makes sense for somebody who didn't understand why length extension matters. It does not prove that any particular output will recur, and what you've got here is one very particular output.

Again, you need actual examples. Not handwaving, not the unwavering yet entirely unjustified certainty that you're correct, you need examples. And you don't have any.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#429
post #286

Earlier quoted context omitted.

Could you please expand on the other uses of contact tracing in those countries?

This is a compilation of what others have posted: - Germany https://www.golem.de/news/hamburg-polizei-nutzt-corona-konta... https://www.ccc.de/de/updates/2021/luca-app-ccc-fordert-bund... - Australia Australia, WA, check-in data: https://www.abc.net.au/news/2021-06-15/safewa-app-sparks-urg... Australia, WA, border pass data: https://www.abc.net.au/news/2021-06-17/g2g-app-data-accessed... Australia, VIC, check-in data…

Thank you, that was very thorough and enlightening.

Re: In internal memo, Apple addresses concerns around new Photo scanning features

#430

Earlier quoted context omitted.

> The part where you make a false claim out of ignorance. Which false claim did I make? I'm still waiting... > No reason I should go looking for such things. You're the one making the false claims, if you have found "many things" with that hash then list them to prove your point, otherwise go away. You don't need to look for those things. By definition, you know they exist. I don't need to find or enumerate all prime…

You are misrepresenting or more likely have simply misunderstood the Pigeonhole Principle. Which I guess makes sense for somebody who didn't understand why length extension matters. It does not prove that any particular output will recur, and what you've got here is one very particular output. Again, you need actual examples . Not handwaving, not the unwavering yet entirely unjustified certainty that you're correct,…

Again, which false claim have I made? Be specific and quote me: you need actual examples, not handwaving.

Until you do that, I'm not pursuing this conversation any further. Have a nice day.

EDIT: Also, if you do want to have a conversation, make sure to stick to HN rules and talk about what is being discussed, rather than about me. Thanks.

Post reply on HN