Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

421–430 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#421

Earlier quoted context omitted.

This hypothetical lacks an explanation for why every politician has not demanded Apple (or say Google) do this scope creep already for photos stored in the cloud where the technical feasibility and legal precedent has already been established by existing CSAM scanning solutions deployed at scale.

I have to note that one of those solutions deployed at scale is Google's. But the big difference is that when those were originally rolled out, they didn't make quite that big of a splash, especially outside of tech circles. I will also note that, while it may be a hypothetical in this particular instance as yet, EU already went from passing a law that allows companies to do something similar voluntarily (previously,…

Ok but now you’ve said that the precedent established by Google and others already moved the legislation to require terrible invasions of privacy far along. You started by saying Apple’s technology (and, in particular, its framing of the technology) has brought new legal risk. What I’m instead hearing is the risk would be present in a counter factual world where nothing was announced last week.

At this point of the discussion, people usually pivot to scope creep: the on-device scanning could scan all your device data, instead of just the data you put on the cloud. This claim assumes that legislators are too dumb to connect the fact that if their phone can search for dogs with “on-device processing,” then it could also search for contraband. I doubt it. And even if they are, the national security apparatus will surely discover this argument for them, aided by the Andurils and NSOs of the world.

As I have repeatedly said: the reaction to this announcement sounds more like a collective reckoning of where we are as humans and not any particular new risk introduced by Apple. In the Apple vs. FBI letter, Tim urged us to have a discussion about encryption, when we want it, why we want it, and to what extent we should protect it. Instead, we elected Trump.

Re: Apple's child protection features spark concern within its own ranks: sources

#422

Earlier quoted context omitted.

I doubt a judge can find apple liable for hosting encrypted data if its illegal. That would mean every e2e storage solution, or even just encryption and storing files on a s3 bucket host would be liable. Apple should use it's gigantic legal arm to set good precedents for privacy in court.

First, there is nothing stopping a full legislative assault on end to end encryption, various such proposals have had traction recently in both the US and EU. The lawyerly phrase is “knew or should have known.” It could be argued that now that this technology is feasible, failure to apply it is complicity. Think about GDPR. Eventually homomorphic encryption is going to be at a point where “we need your data in the cl…

The way to win that situation is to not play.

Pull all apple products from the shelves for a month and launch a billion dollar ad campaign about what the hell our government is up too.

At least try to stick to one governments. Tech companies are entering tricky waters by trying to follow laws of many nations (which conflict) simply because their customers are there

Re: Apple's child protection features spark concern within its own ranks: sources

#423

Earlier quoted context omitted.

Something probably did happen. Apple no doubt became increasingly aware of just how legally culpable they are for photos uploaded to iCloud. For content that is pirated Apple would receive a slap on the wrist, but for content that shows the exploitation of children? And that Apple is hosting on their owned servers? There is no doubt every government will throw their full legal weight behind that case. Now they are st…

Yea, I agree. I see so many comments where people view the issue is black and white and that apple is clearly in the wrong. Yes, privacy is a great ideal. There are absolute monsters in this world and there is zero chance that no apple employees have brushed up against those monsters. I would ask that every single developer step back and think about putting themselves into a situation where software that you write is…

Easy.

When I was young, I was not effectively spied on. My activity and digital trail were ephemeral, and hard to pin down. i wasn't the subkect of constant analysis and scrutiny. I had the privilege of being invited into the engine of an idling train to share an Engineer's drinks along with my parents and no one batted an eye.

There were pedophiles then too. guess what? We didn't sacrifice everyone's right to privacy. We didn't lock more and more rights out of the reach of minors. You didn't need a damn college degree and an insane amount of idealistic commitment to opt out of the surveillance machine. I could fill most prescriptions, even out of State.

We didn't fear the monster. They were hunted with everything we could justify mustering, but you weren't treated as one by default.

I imagine that maybe, somehow, tomorrow's youth may get to experience that. Not live in fear, but in appreciation of the fact that we too, looked into things absolutely worth being afraid of, but resisted the temptation to surrender yet more liberties for the promise of a safety that will never manifest. Just change its stripes.

Those are the best nights.

Re: Apple's child protection features spark concern within its own ranks: sources

#424
post #384
post #262

Earlier quoted context omitted.

And all the while: Sir James Wilson Vincent Savile OBE KCSG (/ˈsævɪl/; 31 October 1926 – 29 October 2011) was an English DJ, television and radio personality who hosted BBC shows including Top of the Pops and Jim'll Fix It. He raised an estimated £40 million for charities and, during his lifetime, was widely praised for his personal qualities and as a fund-raiser. After his death, hundreds of allegations of sexual ab…

There's never been any indication that there has been any more difficulty in catching these guys with better smartphone privacy features. It's easier than ever largely because the police have become better at investigations involving the internet. Asking the police to put some investigative effort in rather than a dragnet sweep of every photo on every persons device is not too much to ask. Importantly this should be…

[deleted]

Re: Apple's child protection features spark concern within its own ranks: sources

#425

Earlier quoted context omitted.

A false positive in matching faces results in a click to fix it or a wrongly categorized photo. A false positive in this new thing may land you in jail or have your life destroyed. Even an allegation of something so heinous is enough to ruin a life. The "one in trillion" chance of false positives is Apple's invention. They haven't scanned trillions of photos and it's a guess. And you need multiple false positives, ye…

Ok. So iCloud Photos circa 2020 [and Google Photos and Facebook and Dropbox and OneDrive] aren’t a risk you should be willing to take. This feature doesn’t change anything in that regard; the scanning was already happening.

I literally do not take that risk in 2021. I do, currently, make the reasoned assurance that the computational overhead of pushing changes down to my phone, and the general international security community, are keeping me approximately abreast of whether my private device is actively spying on me (short answer: it definitely is, longer answer: but to what specific intent?)

Apple's new policy is: "of course your phone is scanning and flagging your private files to our server - that's normal behavior! Don't worry about it".

Re: Apple's child protection features spark concern within its own ranks: sources

#426

Earlier quoted context omitted.

> Secondly, it seems rife for abuse: dont like someone who uses an ios device, msg them some cp and destroy their entire life. I see this a lot. First of all, if you even have CP in the first place that seems quite bad and that you've made yourself vulnerable. Messaging someone will also reveal yourself as the sender. But my bigger question of this hypothetical issue is that Facebook, Google, Dropbox, Microsoft, etc…

>Messaging someone will also reveal yourself as the sender Sending a link to 4chan /b would probably be enough. Or a hidden iFrame in a forum post. Its very very easy to get images onto someones device without their consent, getting them to upload them to a 3rd party is completely different.

Idk, most phones you just save an image and a cloud service auto syncs.

Re: Apple's child protection features spark concern within its own ranks: sources

#427
post #391

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

Apple only had pro privacy PR. They were always working this way. What you're witnessing is a PR change and not a technical one.

Aren't a number of things E2EE with Apple?

Re: Apple's child protection features spark concern within its own ranks: sources

#429

Earlier quoted context omitted.

> That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. This seems like an incredible reach to me.

Why? It's already been well-reported that Apple makes a teeny fraction of the NCMEC reports that other large cloud providers make, and that the reason they hold the keys to iCloud backups was from some requests/pressure from the FBI.

What other "large cloud providers"? Ones that are similar to Apple? Or general cloud companies?

And is "pressure from the FBI" really the only reason why Apple might hold backup keys? Please sketch out your "lost device, need to restore from backup" user journey. For a real person, who has only an iPhone.

Re: Apple's child protection features spark concern within its own ranks: sources

#430
post #167

I just do not want Apple scanning my phone for the purpose of finding something they can send to the police. I’m not even talking about any “slippery slope” scenarios and I’ll never have any of the material they are looking for. And right or wrong, I don’t really fear a false identification, so this isn’t about a worry that they will actually turn me in. I just don’t want them scanning my phone for the purpose of tur…

Wait until you hear about judges who are actively on the take to send people to jail - like the judge who was taking money from for-profit juvenile detention centers to send kids to their facilities on ridiculous charges.

Yeah - this is an architecture designed to be abused.

Post reply on HN