Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

451–460 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#451

Earlier quoted context omitted.

> This is a misunderstanding of the system. It's not a classifier, it's a hash You know that a perceptual hash has more in common with a classifier than with a cryptographic hash, right? If they were using a crypto-hash, then, yes, your argument could be valid, but with perceptual hashing your picture of your baby in the bath could VERY well generate the same hash as a CSAM image. And nobody believes Apples "1 in a t…

I'd be surprised if a baby in the bath—or indeed any legitmately innocent photograph taken by a parent—could ever be a perceptual match to images tagged as "A1" by NCMEC and other agencies. This is the most extreme of the extreme: prepubescent minors actively engaged in sex acts.

You have a fundamental misunderstanding of perceptual hashes, then. If two images look similar to one another, then they will have similar perceptual hashes. That's the point of perceptual hashing.

They aren't doing simple hash matching, they're doing fuzzy matches on the hashes, so there will be far more false positives than just hash collisions.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#452

Earlier quoted context omitted.

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

Youtube current censorship outrage with abusive video take downs is a proof that perceptual hash false positive are a massive problem. Even if the tech has 1 in a trillion chance, it will happen a lot with billions of people generatin thousands of ilage every years. And of course, the hash database being abused.

Are those YouTube takedowns happening due to perceptual hashes?

I assume they are just standard ML.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#454

Earlier quoted context omitted.

You point that it "could have" been done more simply is completely irrelevant. This "much more simply" mechanism is exactly what was created by Apple. It's done right now, and there's no need to worry about how much more simply they COULD HAVE. It's a fait-accompli. The government wanted it, and now they have it. Now they can scan individual phones for whatever they want.

You keep saying they can scan for whatever they want but that’s not true, today, by Apple’s description.(which is all we have to go by and is what you are mad about) Yes the government could order them to change the system. They could also order Apple to create the system in the first place without all the indirection, safety vouchers, human review, etc which make it inefficient as a direct surveillance tool.

Since when has the government acted so transparently?

They could simply tell Apple that this is for CSAM so that people would support it, and then change it later after everyone is is acclimatized to it and forgot about it.

Which is exactly what had happened. And exactly what will happen in a few years.

You sound like a government plant trying to gas light people into thinking this isn’t a big deal. It is a huge deal and it’s not as simple as saying “the government could have asked for it much simpler!” This is them asking for it, plain and simple, and Apple delivering on it.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#455

> Am I getting a Pixel and putting GrapheneOS on it like a total nerd? FUCK. Thanks for depicting people who care about privacy and act on their beliefs as "total nerds", that's an encouraging attitude.

I'm a nerd and don't take it as an insult. Rather as "going full nerd on this" in the sense of giving a lot more importance and effort to a small detail in an already full life. And even if it was not, let's not get upset for every quip, I don't want to live in a world where bloggers have to ponder every word because they are afraid of offending someone. A bit of spice is ok, the dose makes the poison.

> I don't want to live in a world where bloggers have to ponder every word because they are afraid of offending someone.

I don't find it offending, I find it stupid to write like that, that's not the same. So you write a long piece about how Apple is bad for privacy, just at the end to detract the available alternatives because you know, you don't like them for no particular reason? Who said that privacy was going to be easy anyway?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#456

> Am I getting a Pixel and putting GrapheneOS on it like a total nerd? FUCK. Thanks for depicting people who care about privacy and act on their beliefs as "total nerds", that's an encouraging attitude.

Nerd in 2021 is equivalent to "not casual/mainstream". If you consider sideloading OS's you are in fact a nerd.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#457

Earlier quoted context omitted.

The false positive rate for any given image is not 1 in a trillion. Perceptual hashing just does not work like that. It also suffers from the birthday paradox problem - as the database expands, and the total number of pictures expands, collisions become more likely. The parent poster does make the mistake of assuming that other pictures of kids will likely cause false positives. Anything could trigger a false positiv…

> The false positive rate for any given image is not 1 in a trillion. Perceptual hashing just does not work like that. It also suffers from the birthday paradox problem - as the database expands, and the total number of pictures expands, collisions become more likely. There was a good article [0] that was on HN a couple days ago that touches on the flat out lie regarding "one in a trillion" and how PhotoDNA sounds po…

Apple is not using PhotoDNA, but in any event - this is a good article but they misconstrued the '1 in a trillion' quote, as is canvassed in the comments for the article itself. According to apple there is a 1 in a trillion chance of wrongly flagging an account, not a 1 in a trillion false positive rate for individual images, and we know that step to banning include: - multiple flagged images; and - human review

The details for those processes hasn't been fully disclosed, and it isn't possible to say whether 1 in a trillion is a reasonable estimate or otherwise.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#458

Earlier quoted context omitted.

You keep saying they can scan for whatever they want but that’s not true, today, by Apple’s description.(which is all we have to go by and is what you are mad about) Yes the government could order them to change the system. They could also order Apple to create the system in the first place without all the indirection, safety vouchers, human review, etc which make it inefficient as a direct surveillance tool.

Since when has the government acted so transparently? They could simply tell Apple that this is for CSAM so that people would support it, and then change it later after everyone is is acclimatized to it and forgot about it. Which is exactly what had happened. And exactly what will happen in a few years. You sound like a government plant trying to gas light people into thinking this isn’t a big deal. It is a huge deal…

I didn’t say it would be transparent or public. I’m a government plant for saying the government could just tell Apple to scan for whatever they want without messing with the CSAM stuff? I’m saying governments are already capable of ordering this kind of thing, gag orders included, so this specific tech implementation doesn’t really change that. And yes that’s bad and scary and we should probably try to prevent our governments from doing that.

But no, I don’t believe that a government could “fool” Apple by adding non-CSAM images to the database. The review step would catch that.

I don’t like on device scanning in principle and in precedent. I’m just saying this specific tech stack doesn’t seem like it would be useful for your surveillance scenario, and most of your criticisms don’t seem to be based in having read how this system actually works.

I’m AGAINST this system, I just wish the discussion here weren’t so full of misinformation and bad assumptions.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#459
post #257

Earlier quoted context omitted.

Then don't use Google products either (or don't use for photography). Seems obvious. "Dumb" phones and "dumb" cameras still exist.

That is not practical for many people who wish to be a part of society anymore. See: rollout of virtual vaccine passports, etc.

You can get a physical one by printing out a QR code, afaik.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#460

> The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember), debugging wifi drivers and tirelessly trying to make resume-from-suspend work? Oh come on. DOn't make it sound like it's that bad. Wifi is a solved problem for a long time now, and you can buy Lenovo, System76 or Tuxedo if you want to make sure 100% thi…

Second this. I use Ubuntu Mate on a RPi4 for a couple of weeks now. All went fine. Last week, I suddenly thought: I should connect my printer as well, and expected to have a slightly harder time, just like setting up my printer on my last Ubuntu pc.

Click-click-done. I didn't have a hard time, not even with connecting my printer. I'm almost disappointed a bit, since there's no way I'm a cool computer guy if it's this easy.

Post reply on HN