Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

451–460 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#451

Earlier quoted context omitted.

USPS regularly X-rays mail, and the only protection against abuse is policy (it’s not admissible evidence in the United States).

Not only that, but they log all metadata on the envelope of every letter sent.

Law Enforcement can also get access to that metadata -- it's called a mail cover. See U.S. v. Choate.

"A mail cover is a surveillance of an addressee's mail conducted by postal employees at the request of law enforcement officials. While not expressly permitted by federal statute, a mail cover is authorized by postal regulations in the interest of national security and crime prevention, and permits the recording of all information appearing on the outside cover of all classes of mail."

Re: Apple's child protection features spark concern within its own ranks: sources

#452

Earlier quoted context omitted.

I doubt a judge can find apple liable for hosting encrypted data if its illegal. That would mean every e2e storage solution, or even just encryption and storing files on a s3 bucket host would be liable. Apple should use it's gigantic legal arm to set good precedents for privacy in court.

First, there is nothing stopping a full legislative assault on end to end encryption, various such proposals have had traction recently in both the US and EU. The lawyerly phrase is “knew or should have known.” It could be argued that now that this technology is feasible, failure to apply it is complicity. Think about GDPR. Eventually homomorphic encryption is going to be at a point where “we need your data in the cl…

> First, there is nothing stopping a full legislative assault on end to end encryption, various such proposals have had traction recently in both the US and EU.

And nothing stops Apple from fighting against the legislative assault. They have made themselves a champion of user privacy and have deep pockets to fight the fight, yet they just surrender at first attempt.

Re: Apple's child protection features spark concern within its own ranks: sources

#453
post #124

Earlier quoted context omitted.

There is no law that requires providers to scan users private documents, even uploaded. However, if they do review the material and see child porn they're obligated to report it.

Any chance you have a good link explaining this? I saw the parent comment earlier and wanted to add this. But I only recently learned that the US federal government cannot require or incentivize providers to scan user's private documents, so didn't want to post without clear sources.

It's covered in 18 U.S. Code § 2258A - Reporting requirements of providers

Re: Apple's child protection features spark concern within its own ranks: sources

#454
post #198
post #167

I just do not want Apple scanning my phone for the purpose of finding something they can send to the police. I’m not even talking about any “slippery slope” scenarios and I’ll never have any of the material they are looking for. And right or wrong, I don’t really fear a false identification, so this isn’t about a worry that they will actually turn me in. I just don’t want them scanning my phone for the purpose of tur…

This is the most honest take on this that I’ve seen. The slippery slope arguments don’t make sense, nor does the risk of false positives. But the idea of being suspected even in this abstract way, because of something other people do , is at the very least distasteful, bordering on offensive.

How do the slippery slope arguments not make sense? This is a capability that:

1. Did not exist prior (scanning stuff on the endpoint)

2. Has a plausible abuse case (the same system, applied to stuff that isn't CSAM)

I find this very compelling, especially in the shittier regimes (China...) that Apple operates in.

Re: Apple's child protection features spark concern within its own ranks: sources

#455

Earlier quoted context omitted.

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

> but they needed to do something to address the CSAM issue lest governments come down on them hard. If Apple does not have decryption keys for iCloud content, they can't decrypt it, only the user can. For Apple, it's not technically feasible, and the law supports that. Apple has now demonstrated that it is technically feasible to overcome this challenge by doing things "pre-encryption" on the user's device. From a u…

> Apple has now demonstrated that it is technically feasible to overcome this challenge by doing things "pre-encryption" on the user's device.

> From a legal stand point, they are now screwed, because now they _must_ do it.

That's not the right takeaway. They're only required to turn over data to which they have access. If they continue writing software that makes it so they don't have access to the data, then they do not need to turn it over because they can't. The fact that you can write software to store or transmit unencrypted data is irrelevant.

Re: Apple's child protection features spark concern within its own ranks: sources

#456

Earlier quoted context omitted.

But that’s not the proposed design. Browser cache isn’t getting advanced. It’s photos for iCloud. I’m not asking if people do bad things, I’m saying over and over again this is getting coverage on Hn and people are pointing to this hypothetical issue — yet this hypothetical issue has been possible for years on many more devices.

As far as I have read its scanning any images and messages on the device, as well as text entered into Siri. So accidentally stick a w in your siri teen porn search and you'll be seeing https://www.apple.com/v/child-safety/a/images/guidance-img__... If it was photos taken on the device there would be no existing hash for the image to match.

Totally tangential, but i didn't realize that there were well-advertised "anonymous helplines for at-risk thoughts". I'm kind of curious about it as a pathology (what does "help" look like?), but I'm uneasy about even getting that in my search history

Re: Apple's child protection features spark concern within its own ranks: sources

#457

Earlier quoted context omitted.

> No, the Fourth Amendment applies to private actors acting on behalf of the government. It applies to private actors acting as agents of the government , it doesn't apply to private actors who for private reasons not directed by the government conduct searches and report suspicious results to the government (other property and privacy laws might, though.)

So the 4th Amendment doesn't cover Apple voluntarily inducing their devices to check for CSAM prior to cloud upload. But the 4th Amendment would cover Apple being forced to modify their system to scan for anything else the Government has told them to.

That's correct. If the government asked them to do it, then it would require a warrant to conduct the search.

Re: Apple's child protection features spark concern within its own ranks: sources

#458
post #448

Earlier quoted context omitted.

What follows is conjecture: >... to address the CSAM issue lest governments come down on them hard. And I think that is the springboard of why this is happening. It's no secret that Apple has lobbyists which by turns have a "pulse" on the trajectory of Bills in the House and Senate. What immediately came to mind to me was H.R.485 of 2021's House Session: https://www.congress.gov/bill/117th-congress/house-bill/485/...…

> It's no secret that Apple has lobbyists which by turns have a "pulse" on the trajectory of Bills in the House and Senate. Great, let the bills pass and then they get to publicly blame congress for being "forced to legally comply" instead of jumping the gun and doing an about face on 80% of your reputation built over the last 20+ years. There is 0 reason to do this before being legally forced to. It's not a gamble w…

Yes, 100% agree, make congress go through with passing such a law. Make it a public discussion. Make them consider if they would like their own devices to be built insecurely. They're among the biggest targets of people who would like to subvert US policy.

Re: Apple's child protection features spark concern within its own ranks: sources

#459
post #238

Earlier quoted context omitted.

because its scanning the content of the device, not what you did on the device. An iFrame full of CP downloaded from 4chan that fills the browser cache with CP just by visiting a harmless site would not go anywhere near Google Photos, Facebook messenger, etc etc It would trigger a scanner checking the browser cache for CP images. Those are just the obvious ways, by "rife" I mean there is any number of ways to get CP…

Good thing this system doesn’t scan browser cache, then. Unless you’re programmatically extracting photos from your browser cache and uploading them to iCloud, which would be a pretty impressive way to make sure you’re using up all your storage.

Ok, here is something that happened that could have triggerd this:

Back when I used WhatsApp I got a lot of nice photos from friends and family there.

WhatsApp doesn't (at least didn't) have a way to export them but I could find them on disk and I had an app that copied that folder to a cloud service. Problem is this folder contained all images from all chats.

Now I'm not very edgy so most of my pictures are completely non-problematic (in fact I don't know of any problematic ones), but once in a while someone will join one of your groups and post shock pr0n.

I've long since stopped backing up everything since I use Telegram now and it allows me to selectively backup the chats I want.

But I wanted to mention just one very simple way were doing something completely reasonable could result in an investigation of an innocent person.

Re: Apple's child protection features spark concern within its own ranks: sources

#460
post #448

Earlier quoted context omitted.

What follows is conjecture: >... to address the CSAM issue lest governments come down on them hard. And I think that is the springboard of why this is happening. It's no secret that Apple has lobbyists which by turns have a "pulse" on the trajectory of Bills in the House and Senate. What immediately came to mind to me was H.R.485 of 2021's House Session: https://www.congress.gov/bill/117th-congress/house-bill/485/...…

> It's no secret that Apple has lobbyists which by turns have a "pulse" on the trajectory of Bills in the House and Senate. Great, let the bills pass and then they get to publicly blame congress for being "forced to legally comply" instead of jumping the gun and doing an about face on 80% of your reputation built over the last 20+ years. There is 0 reason to do this before being legally forced to. It's not a gamble w…

Your lobbyists might get some extra favors if you don't pass the blame on congress.
Post reply on HN