Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

431–440 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#431
post #416

US Government: We suspect the person in this photo of committing a crime. Here is your subpoena, Apple. You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them. Chinese Government: Here is the NeuralHash for Tienanmen square. Delete all photos you find matching this or we will bar you from China. Apple has at this point already admitted thi…

As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography. 2. The complaints are all slippery slope arguments that governments will force Apple to abuse the mechanism. These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it. However: Child pornography and the related abuse is widely thought of as a massive probl…

Yes. “We must do something, “It’s for the children”, “Even if it saves just one person”. No one has ever used this triple fallacy before.

How big do you really think the market is on kiddie porn that there are people storing it plainly on their iPhones and are “safe” because they aren’t uploading it to iCloud?

This is bullshit through and through.

The best case is this is the step Apple needs to get E2E iCloud storage, to prove they’re doing enough while maintaining privacy. The worst case is that if their is potential for a list and reporting to be abused, it will.

There seems to be no scenario for the best case to exist without the worst case.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#432

Earlier quoted context omitted.

There is a shared (among all of the major tech companies and presumably law enforcement) hash database of child abuse material. Going from a photo to the hash is deterministic: How it gets to a hash on your phone is surely the same way it gets to a hash running the exact same algorithm on the cloud, whether iCloud, Amazon Photos, etc. Such a collision would generate a human validation. This applies to cloud-shared fi…

1. how many false positives have there been? 2. is it really reviewed by a human? I see how YT works, and automated failure at scale is the name of the game 3. apple has said that the on-device scanning only provides a binary yes/no on CP detection. How do you defend against a "yes" accusation? (when stored on someone else's server, the evidence is there)

This is part of iCloud photo sync, and on hitting some threshold of matching pictures it would trigger human review.

There would also presumably be human review involved in the legal process, e.g. law enforcement getting a subpoena based on Apple notifying them, and then using gathered evidence for a warrant.

The system is based on known image hashes, not arbitrary ML detection.

As this system is used only for iCloud photo uploads, the evidence gathering should be similar to that done by LE with other cloud hosting providers for years

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#433
post #416

US Government: We suspect the person in this photo of committing a crime. Here is your subpoena, Apple. You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them. Chinese Government: Here is the NeuralHash for Tienanmen square. Delete all photos you find matching this or we will bar you from China. Apple has at this point already admitted thi…

As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography. 2. The complaints are all slippery slope arguments that governments will force Apple to abuse the mechanism. These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it. However: Child pornography and the related abuse is widely thought of as a massive probl…

>2. The complaints are all slippery slope arguments that governments will force Apple to abuse the mechanism. These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it.

I don't know how old you are but for anyone over 30 the slippery slope isn't a logical fallacy, it's a law of nature. I've seen it happen again and again. The only way to win is to be so unreasonable that you defend literal child porn so you don't need to defend your right to own curtains.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#434

Should they persist in this, if I don't replace my current iPhone with an alternative, I will definitely not buy an iPhone for my next phone. It's a gross overreach and I'd be too worried about false positives.

the next phone? I will stop buying Apple products period.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#435
post #399

Earlier quoted context omitted.

Do keep in mind that atleast one govt has successfully preassured apple to give up on its privacy Also the difference here compared to the scenarios you've mentioned above is that Apple has walked pretty far. All it would take is to make the verification happen on all local files irrespective of its being uploaded to iCloud or not. Then any government can provide their own hashes to apple to keep track of. Apple won'…

"Do keep in mind that at least one govt has successfully pressured apple to give up on its privacy" No company can defend you from your government. "All it would take"... That is the slippery slope. If a government is going to say "that's a nice looking hashing system you have there, now we need you to..." they could as easily -- more easily -- have said "that's a nice filesystem you have there, we need you to...". H…

Sure no company can completely defend me from my govt but atleast they can not build tools that make it easier. Also while it could be easy for a college graduate to build such a system, only Apple has the capability of rolling out this system to all of their phones. Otherwise we would have already seen such a system implemented in other countries

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#436

Earlier quoted context omitted.

Laptop | Desktop: https://www.dell.com/en-us/work/shop/overview/cp/linuxsystem... Router: https://www.turris.com/en/omnia/overview/ Media Center: https://osmc.tv/vero/ Cloud (Use TrueNAS Scale): https://www.truenas.com/systems-overview/ Phone: https://www.pine64.org/pinephone/ Watch: https://pine64.com/product/pinetime-smartwatch-sealed/ Smart Thermostat: https://hestiapi.com/product/hestiapi-touch-one-free-shippin..…

I'm sympathetic to remove Apple and Google from my life, but this list looks so sad. You know the experience, integration and headache of all this is going to be horrible.

Depends what you're looking to do - if you really value your privacy, yes, you're going to have to give up some convenience, but I can assure you, it's really not that bad if you put in a little work on an occasional basis, it's not the constant maintenance nightmare that some people seem to expect.

I fired up Syncthing on my phone and NAS and restic to perform encrypted backups nightly to B2, sure, you're not going to get some magical cloud image recognition stuff, but do you really need or even want it?

Everything can integrate quite nicely, but plan to do the connecting work yourself as a one-off with some occasional maintenance a few times a year.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#437
post #3

Please talk to non-tech people around you about this. This overreach simply cannot stand, and from a company that sees success from touting itself as a privacy-centric alternative? These really are some dark times. I imagine that if the world had Stasi fresher in its mind, this would never have happened.

Anyone who engaged in such a discussion with a non-technical person is going to defacto seem like an advocate for child pornography, similar to how advocating for encryption can easily be twisted to being pro-crime. Having said that, there is an enormous amount of misinformation and fear-mongering about a pretty tame change. This seems like so much ado about very close to nothing. a) They optionally scan messaged pho…

Why does everyone mention they already did it on cloud like that has any relevance whatsoever?

I have never once in my life thought about activating an automatic back up to cloud feature on any phone I have ever owned, for a single second. So yes, it is hella different. This is for all the same reasons I backup personal data only to my NAS and use cloud accounts for generic shit like purchased music backups and nothing more.

I prefer losing all my photos if my phone is pickpocketed in between backups to having a public record of everything I ever photographed. Am I the 0.00000001% or something? I didn't even realize I was the odd man out, honestly.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#438

Earlier quoted context omitted.

What are the ramifications that I "do not understand"? I will repeat: It is a very tame change. Were you frantic and delirious when a neural network first identified a dog in your photos? Isn't that the slippery slope to it reporting you to the authorities for something bong shaped? Speaking of which, every bit of fear mongering relies upon a slippery slope fallacy. What is clearly a PR move is somehow actually the m…

> Why would Apple do that? Because it gets required to by the laws of countries responsible for most of their market? And because authoritarian regimes intentionally blur the lines between criminal and political surveillance over time, making it harder for companies to draw hard policy lines? Concern about this doesn't require any bond villains, it just requires well-intentioned pragmatists on one side and idealogica…

In which case how is this a slippery slope? They didn’t do something and there was no legal mandate. Now they are required to do something to be able to operate in said company. Is the slippery slope that they can be in compliance faster?

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#439
post #278
post #158

Earlier quoted context omitted.

The Chinese government already has direct access to everyone's data and messages. There is no encryption. This is mandated. [0]: https://www.nytimes.com/2021/05/17/technology/apple-china-ce...

"Apple CEO Tim Cook Slams Indiana’s ‘Religious Freedom’ Law" https://www.rollingstone.com/politics/politics-news/apple-ce... The hypocrisy levels are vomit inducing...

What hipocrisy are you seeing?

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#440

Earlier quoted context omitted.

Laptop | Desktop: https://www.dell.com/en-us/work/shop/overview/cp/linuxsystem... Router: https://www.turris.com/en/omnia/overview/ Media Center: https://osmc.tv/vero/ Cloud (Use TrueNAS Scale): https://www.truenas.com/systems-overview/ Phone: https://www.pine64.org/pinephone/ Watch: https://pine64.com/product/pinetime-smartwatch-sealed/ Smart Thermostat: https://hestiapi.com/product/hestiapi-touch-one-free-shippin..…

I'm sympathetic to remove Apple and Google from my life, but this list looks so sad. You know the experience, integration and headache of all this is going to be horrible.

If you had the option of buying this hardware stack through an integrated third-party brand/storefront that offered support for the products and their integration would that make you feel differently?
Post reply on HN