Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

451–460 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#451
post #435

Earlier quoted context omitted.

> If you avoid Apple, what's the point of M1? - (Potentially) programmable top notch security chip with no overhead encryption - Fanless (Air), cool running, fast processor with very low power consumption - All metal body - Top notch HiDPI screen with color accuracy. - Top notch sensors - Excellent, illuminated keyboard - Big trackpad with pressure sensitivity and taptic engine - Excellent battery life - Excellent ba…

Nearly all the HW items have equivalent or superiour replacements, and a fair amount are dependent on the Apple ecosystem. Without Apple's ecosystem it's a good system but overpriced, and that's before you run into Linux compatibility problems. For example, take the monitor - there are monitors with higher refresh rates or more resolution (Retina does 'only' 6K). Also, Mac OS colour processing has no good equivalent…

Don't higher density displays take more power? Can we actually start making laptop displays that cap out at 1080 or 1440p?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#452
post #388

Earlier quoted context omitted.

The selling point of Macs is the Apple ecosystem and UX. If you avoid Apple, what's the point of M1? Linux on equivalent AMDs is cheaper and more compatible.

> If you avoid Apple, what's the point of M1? - (Potentially) programmable top notch security chip with no overhead encryption - Fanless (Air), cool running, fast processor with very low power consumption - All metal body - Top notch HiDPI screen with color accuracy. - Top notch sensors - Excellent, illuminated keyboard - Big trackpad with pressure sensitivity and taptic engine - Excellent battery life - Excellent ba…

- No dumb LEDs keeping you awake.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#453
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

I would trade all my personal privacy if that meant eliminating pompous drivel producing dolts like you from all aspects of my life.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#454
post #213

Could we get a more useful link here, people? CSAM? According to Google that's Confocal Scanning Acoustic Microscopy. Or something. And what with the tweeters? I think my laptop just gave me thighburns from the CPU bloat that clicking on that link caused. Eight seconds to render the page? Why do folks still use this twerker website?

If your machine takes 8 seconds to render a Twitter page, perhaps you need a new machine.

Or maybe the web is getting too bloated?

https://idlewords.com/talks/website_obesity.htm

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#455
post #394

Earlier quoted context omitted.

What if I have a locksmith verify it for me? Like Apple and Android have been checked by several security researchers and while they absolutely have holes, there is are at least gates that can have them. Sandboxing is the bare minimum an OS should do if it wants to have third party applications installed.

You can only hire someone to verify your lock if the lock is verifiable in the first place. Apple is trying to make it non-verifiable.

Anything concrete on that?

For a fact we know that ios has strong sandboxing, secure bootchain and apps are revokably verified.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#456

Earlier quoted context omitted.

But it said they use a "perceptual hash" - so it's not just looking for 1:1, byte-for-byte copies of specific photos, it's doing some kind of fuzzy matching. This has me pretty worried - once someone has been tarred with this particular brush, it sticks.

You can’t do a byte-for-byte hash on images because a slight resize or minor edit will dramatically change the hash, without really modifying the image in a meaningful way. But image hashes are “perceptual” in the sense that the hash changes proportionally with the image. This is how reverse image searching works, and why it works so well.

Sure, I get how it works, but I feel like false positives are inevitable with this approach. That wouldn't necessarily be an issue under normal police circumstances where they have a warrant and a real person reviews things, but it feels really dangerous here. As I mentioned, any accusations along these lines have a habit of sticking, regardless of reality - indeed, irrational FUD around the Big Three (terrorism, paedophilia and organised crime) is the only reason Apple are getting a pass for this.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#457

I'm really conflicted about this. For context, I deeply hate the abuse of children and I've worked on a contract before that landed 12 human traffickers in custody that were smuggling sex slaves across boarders. I didn't need to know details about the victims in question, but it's understood that they're often teenagers or children. So my initial reaction when reading this Twitter thread was "let's get these bastards…

> I'm really conflicted about this.

I'm not. I am very unambiguously against this and I think if word gets out Apple could have a real problem.

I would like to think I am against child porn as any well-adjusted adult. That does not mean I wish for all my files to be scanned without my consent or even knowledge for compliance, for submission to who knows where matching to who knows what reporting to, well, who knows.

That's crossing a line. You are now reading my private files, interpreting them, and doing something based on that interpretation. That is surveillance.

I am very not OK with this.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#458

Earlier quoted context omitted.

I honestly don't like too much these smug takes > 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 99% of the population will delegate the decision of what code is allowed to run to someone, be it the manufacturer, the government, some guy on the Internet or whatever. For that 99% of the population,…

Not GP but... >99% of the population will delegate the decision of what code is allowed to run to someone, be it the manufacturer, the government, some guy on the Internet or whatever. For that 99% of the population, by the way, it's actually more beneficial to have restrictions on what software can be installed to avoid malware I do not agree with this. You are saying people are too stupid to make decisions and that…

> I do not agree with this. You are saying people are too stupid to make decisions and that is amoral in my opinion.

I'm not saying that at all. I'm saying that it's impossible for all people to make informed decisions on all the issues that surround them, because of both knowledge and time. And it doesn't just happen with computer and privacy, see food, for example. Do you make all decisions about what's allowed or not in your food chain? It's impossible! Unless you dedicate quite a lot of time to it, you can't know if certain foods have certain ingredients, and whether those are harmful or not. That's why we have regulation on food. We trust that regulation because we need to do more things than just worrying constantly about our food.

In the same way, most people delegate control on what can run on their device because they don't have the time or knowledge to inspect constantly what is running on their devices.

> Data portability is a thing. This was the original problem with FB and thats how we got 'takeout'.

And did takeout solve any problems? No, because it's not a technical issue.

> Using the extreme in arguments is dishonest. We are talking on HN where it is a selective group of like minded people(bubble). How does your delivery driver communicate with their social circles? Or anyone that services you?

The GP used the extreme by saying that "essentially all human communication" has been moved to social networks.

But yes, we do agree that HN is not the real world. So I'd love to know what were the warning signs to people like a delivery driver, or basically anyone that wasn't active in computer circles. Not to mention that, before, social networks, most communication was done through channels controlled by third parties (phone, letters, television). From a non-technical standpoint, things didn't change that much.

> We do not need more laws as technology advances but rather an enforcement of personal rights and protections enabling users to be aware of what is happening.

"Enforcement" is done through laws and regulations.

> It appears you are stating "people aren't smart enough to control their devices" and "We need laws to govern people"

I'm not saying that at all. I'm saying that people shouldn't need to invest a significant amount of time constantly verifying that their devices and networks are doing what they say they are doing, and that laws and regulations should be applied to corporations instead so that people can reasonably trust that the ones offering those devices and networks are doing things somewhat correctly.

And again, this has been done already with quite a lot of things. There are regulations for cars, food, furniture, clothes... Not because people aren't smart to control what they use, but because it's impossible for any one person to have the time and knowledge to control everything that they use.

Imagine applying your argument when talking about, say, carcinogenic substances on food. You could argue that the best way to fight that is for people to grow their own food and check that their food doesn't contain those substances, or trust that some company that sells them food is doing it for them. Or, you could push for regulation and organisms that ensure that those substances don't make their way into the food chain.

Well, this is the same. Most people have other things to do instead of learning to ensure that their devices are secure and private and then checking that for everything they get their hands on. You need regulations so that there's a consensus on what can you expect, and then enforcement so that the products you get actually comply with those regulations.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#459
post #366

Earlier quoted context omitted.

> closed social networks It’s not clear that governments would give the open social networks an easier ride either. It could be argued that distributed FOSS developers are easier to pressurise into adding back doors, unless we officially make EFF our HR/Legal department. The other problem is workers have a right to be paid. The alternatives are FOSS and/or distributed social media. Who in good conscience would ask a…

> … who amongst us will do UX… imho, we have everything in the foss world working tightly except great UX/UI. in my experience in the open source world – which is not insignificant – great UX is the only thing stopping us from a paradigm shift to actual tech liberation. even outside of corporate funded work/commits, we see an astounding number of people donating incredible amounts of their time towards great quality…

There are tons of OSS projects with great UX... just not for "normies". That's the issue: Most OSS contributors write software primarily for themselves, and if their needs don't align with those of the general population, the end product will not be very attractive to the masses.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#460
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

> closed social networks It’s not clear that governments would give the open social networks an easier ride either. It could be argued that distributed FOSS developers are easier to pressurise into adding back doors, unless we officially make EFF our HR/Legal department. The other problem is workers have a right to be paid. The alternatives are FOSS and/or distributed social media. Who in good conscience would ask a…

UO?
Post reply on HN