Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

441–450 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#441

"The ark of the covenant is open and now all your faces are going to melt" - to paraphrase "The Thick of It". Prior to this when a government tapped Apple on the shoulder asking to scan for what they (the government) deem illicit material, Apple could have feasibly say "we cannot do this, the technology does not exist". Now the box is open, the technology does exist, publicly and on the record - Now we are but a nati…

Well stated. I am one of those that trusted Apple, and though it seems totally obvious now (the problems present with not having full control of ones device) for whatever reason it took all this for me to realize how privacy truly requires that control.

You are also right that it would take a lot for me to trust Apple again and they are unlikely to do the things required for that since transparency, openness are not typically how they operate.

Re: Apple's child protection features spark concern within its own ranks: sources

#442

In their attempt to make this extra private by scanning 'on device', I think they've managed to make it feel worse. If they scan my iCloud photos in iCloud, well lots of companies scan stuff when you upload it. It's on their servers, they're responsible for it. They don't want to be hosting CSAM. It feels much worse them turning your own, trusty iPhone against you. I know that isn't how you should look at it, but tha…

> I know that isn't how you should look at it

Why not? The argument seems perfectly reasonable to me.

Re: Apple's child protection features spark concern within its own ranks: sources

#443
post #391

Earlier quoted context omitted.

Apple only had pro privacy PR. They were always working this way. What you're witnessing is a PR change and not a technical one.

Aren't a number of things E2EE with Apple?

The few things that are get backed up in cleartext. Also E2EE doesn't mean jack shit if someone else owns the ends.

Re: Apple's child protection features spark concern within its own ranks: sources

#444
post #262

Earlier quoted context omitted.

And all the while: Sir James Wilson Vincent Savile OBE KCSG (/ˈsævɪl/; 31 October 1926 – 29 October 2011) was an English DJ, television and radio personality who hosted BBC shows including Top of the Pops and Jim'll Fix It. He raised an estimated £40 million for charities and, during his lifetime, was widely praised for his personal qualities and as a fund-raiser. After his death, hundreds of allegations of sexual ab…

Respectfully, I don't understand where you're going with this at all. I could point to it and say, "Wow, we need to make sure nothing like that ever happens again, no matter what the cost to personal liberty!"

I can see that interpretation for sure. My impression is that folks like Savile will always be protected from CSAM by the same powers that be calling for CSAM. I'm not certain if that viewpoint is realism or cynicism, or if there is a difference.

Re: Apple's child protection features spark concern within its own ranks: sources

#445
post #318

Earlier quoted context omitted.

>As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone. Except for the "oops, due to an unexpected bug in our code, every image, document, and message on your device was being continuously scanned" mea culpa we will see a few months after this goes live.

The potential for this is overblown and I think a lot of people haven’t taken the time to understand how the system is set up. iOS is not scanning for hash matches and phoning home every time it sees one, it’s attaching a cryptographic voucher to every photo uploaded to iCloud that, if some number of photos represent hash matches (the fact of the match is not revealed until the threshold number is reached), then allo…

> it’s attaching a cryptographic voucher to every photo uploaded to iCloud that, if some number of photos represent hash matches

OK, but what if Apple silently pushes out an update (or has existing code that gets activated) that "accidentally" sets that number to zero? Or otherwise targets a cryptographic weakness that they know about because they engineered it? That wouldn't require "significant modification".

Funamentally, it's closed software and hardware. You can't and shouldn't trust it. Even if they did do some "significant modification" how are you going to notice/prove it?

Re: Apple's child protection features spark concern within its own ranks: sources

#446
I actually really enjoy the loop of “we can trust them to police us, they are trustworthy” to “oh no, they abused that power; why did they do that” that society goes through.

All this HN rebellion is a storm in a teacup. Some innocent dude will get in trouble and everyone will talk about how “tech companies need to be regulated” and then they’ll go back to “we should trust the government to police us” after a few weeks of burning through their outrage. Always exceptions. Always surprised. Always trusting.

Re: Apple's child protection features spark concern within its own ranks: sources

#447

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

> but they needed to do something to address the CSAM issue lest governments come down on them hard.

If Apple does not have decryption keys for iCloud content, they can't decrypt it, only the user can. For Apple, it's not technically feasible, and the law supports that.

Apple has now demonstrated that it is technically feasible to overcome this challenge by doing things "pre-encryption" on the user's device.

From a user's point-of-view, Apple's privacy is worth nothing. It makes no sense for them to encrypt anything, if they leak all data before encryption. Children today, terrorism tomorrow. All your messages, photos, and audio, can be leaked.

There are thousands of people at Apple involved in the release of any single feature, from devs and testers, to managers all the way up to VPs.

The fact that this feature made it to production proofs that Apple is an organization that I can't trust with my privacy.

Their privacy team must be pulling their hairs out. They better start looking for a new job.

Re: Apple's child protection features spark concern within its own ranks: sources

#448

Earlier quoted context omitted.

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

What follows is conjecture: >... to address the CSAM issue lest governments come down on them hard. And I think that is the springboard of why this is happening. It's no secret that Apple has lobbyists which by turns have a "pulse" on the trajectory of Bills in the House and Senate. What immediately came to mind to me was H.R.485 of 2021's House Session: https://www.congress.gov/bill/117th-congress/house-bill/485/...…

> It's no secret that Apple has lobbyists which by turns have a "pulse" on the trajectory of Bills in the House and Senate.

Great, let the bills pass and then they get to publicly blame congress for being "forced to legally comply" instead of jumping the gun and doing an about face on 80% of your reputation built over the last 20+ years.

There is 0 reason to do this before being legally forced to. It's not a gamble with a possible upside somewhere. It's directly shooting yourself in the foot.

Re: Apple's child protection features spark concern within its own ranks: sources

#449

Earlier quoted context omitted.

I would not say the slippery slope take doesn't make sense. It is perfectly possible that had no one cried out about this change then the next change would have been: Large government to Apple: "Please now also create a hash on each photo metadata field including date/time and location. Let us query these. AND BTW, this change must be kept secret. Thanks."

That’s not at all how hashes work here.

I know that is not how it works currently, I was merely suggesting how something could change.

Re: Apple's child protection features spark concern within its own ranks: sources

#450

There are two things that make me think this will be walked back. Firstly, and most importantly, this kind of backdoor is the kind of thing that makes big corps prohibit the use/purchases of devices. Secondly, it seems rife for abuse: dont like someone who uses an ios device, msg them some cp and destroy their entire life.

> Secondly, it seems rife for abuse: dont like someone who uses an ios device, msg them some cp and destroy their entire life. I see this a lot. First of all, if you even have CP in the first place that seems quite bad and that you've made yourself vulnerable. Messaging someone will also reveal yourself as the sender. But my bigger question of this hypothetical issue is that Facebook, Google, Dropbox, Microsoft, etc…

I think a lot of people overestimate how hard it is to stay hidden for small jobs.

Furthermore there is a lack of imagination here:

- work from a hacked account (I've seen gmail accounts that have been "shared" with an attacker for long enough to let the attacker having conversations with their bank, i.e. attacker used the account but stayed hidden until the bank called to verify details.)

- VPNs exist.

- Russia exist.

- nasty images can be embedded into details of innocent high resolution photos.

- very soon they'll have to scan pdfs, pdf attachments and zip files otherwise this is just a joke.

- at this time it becomes even easier to frame someone

- etc

Remember, the goal is probably not to get someone convicted, just to mess up their lives by getting business contacts, family and neighbors to wonder if they were really innocent or if they just got off the hook.

That said, the bigger problem with having a secret database of objects to scan for is that it is secret: anything can go into it, allowing all kinds of fishing expeditions.

I mean: if you have such a wonderful system it would be a shame not to use it to stop copyright infringement in the west, blasphemy (Christian or Atheist literature) in Muslim countries or lack of respect for the dear leader (Winnie Pooh memes) in China.

Post reply on HN