Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

481–490 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#481
post #358

Earlier quoted context omitted.

No, what you have said is bullshit. The perceptual hashes are not generalized. They do not match ‘child porn’ or ‘pride flag’. They match specific photos from a database. You might argue that that database could contain a specific photo of a pride flag. You would be right, but there are safeguards against that. The system will not trigger with just one match. A set of multiple images must match. So no, the system won…

>A set of multiple images must match. How many exactly? The threshold is secret, it could be 1 or 2 or maybe it is dynamic and depends on stuff like your identity.

It could be 1 or 2, but the claim is that it is set to only detect people who are actually building a collection of CSAM images because Apple doesn’t want this system to flag people who are unlikely to be actual criminals. I.e. they don’t just want no false positives, they don’t want positives that aren’t highly likely to be criminal. I’m guessing it’s a lot more than 2.

Re: Apple's child protection features spark concern within its own ranks: sources

#482

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

Apple was always pro “think of the children”, not just privacy.

Re: Apple's child protection features spark concern within its own ranks: sources

#483
I feel like this is a good thing given the circumstances we're already in. It might catch some predators while still keeping everyone's photos private. Sure, it's ripe for abuse, but when has it not been that way? Haven't we always had to trust Apple to do the right thing with our iDevices?

This could marginally reduce Apple's leverage against evil governments seeking to pry into iPhones since "if you can do it for CP, you can do it for tank man". But with Apple already being the dictator of all OS-level code running on your device, this capability isn't anything fundamentally new. Do we have any guarantee that certain devices in China haven't received a "special" version of some software update that introduces a backdoor?

Personally, I have an Android and hope that my next phone will run some flavor of Linux.

Re: Apple's child protection features spark concern within its own ranks: sources

#484
post #198

Earlier quoted context omitted.

This is the most honest take on this that I’ve seen. The slippery slope arguments don’t make sense, nor does the risk of false positives. But the idea of being suspected even in this abstract way, because of something other people do , is at the very least distasteful, bordering on offensive.

I would not say the slippery slope take doesn't make sense. It is perfectly possible that had no one cried out about this change then the next change would have been: Large government to Apple: "Please now also create a hash on each photo metadata field including date/time and location. Let us query these. AND BTW, this change must be kept secret. Thanks."

> Large government to Apple: "Please now also create a hash on each photo metadata field including date/time and location. Let us query these. AND BTW, this change must be kept secret. Thanks."

How do you know this hasn’t already happened? What does it have to do with the CSAM technology?

Re: Apple's child protection features spark concern within its own ranks: sources

#485

Good. I would be furious if I worked there. After the San Bernardino case, I viewed them as the paragon of privacy and security, to the extent I ignored most criticisms, including their lack of support for right-to-repair and concerns over App Store rejections. All of that is back on the table for me after this decision. It is out-of-step with everything they've been doing up to this point, and it makes me wonder who…

What's fishy to me is the fact that they are letting this be known. Like, if you're trying to capture people who share CSAM or have it on their phone, why would you go around saying that you can now scan for it? I think this announcement would have been well known to cause a major outrage so why say anything? I'm wondering if this is a cover up for something else. Get people talking about this in the news and getting…

Announcing it isn't fishy. If they didn't announce it, they'd risk a whistleblower telling the story for them. In fact, the story did break a day before Apple could officially announce it. That may already have hurt them more because they weren't even part of the discussion at that point. What you want is to tell the story on your terms. If someone beats you to it you can't do that.

Unrelated to Apple, but that's one of the big problems with misinformation. You can't get ahead of it because it's all made up.

Re: Apple's child protection features spark concern within its own ranks: sources

#486
post #198

Earlier quoted context omitted.

This is the most honest take on this that I’ve seen. The slippery slope arguments don’t make sense, nor does the risk of false positives. But the idea of being suspected even in this abstract way, because of something other people do , is at the very least distasteful, bordering on offensive.

How do the slippery slope arguments not make sense? This is a capability that: 1. Did not exist prior (scanning stuff on the endpoint) 2. Has a plausible abuse case (the same system, applied to stuff that isn't CSAM) I find this very compelling, especially in the shittier regimes (China...) that Apple operates in.

Neither 1 nor 2 are in fact true. Spotlight indexes all kinds of metadata, as does photos search. Adding an agent to upload data from these is easier than extending the CSAM mechanism, and the CSAM mechanism as is is not all that plausible to abuse either technically or socially given how clear Apple’s promises are.

Re: Apple's child protection features spark concern within its own ranks: sources

#487
> But Apple was surprised its stance then was not more popular, and the global tide since then has been toward more monitoring of private communication.

Personally speaking, Apple denying breaking into a phone in 2016 was indeed one of the reasons I believed them when they said they stand up for privacy. This is now developing a foul after taste - when it really counts, they don’t publicly stand up against governments.

Re: Apple's child protection features spark concern within its own ranks: sources

#488
post #486

Earlier quoted context omitted.

How do the slippery slope arguments not make sense? This is a capability that: 1. Did not exist prior (scanning stuff on the endpoint) 2. Has a plausible abuse case (the same system, applied to stuff that isn't CSAM) I find this very compelling, especially in the shittier regimes (China...) that Apple operates in.

Neither 1 nor 2 are in fact true. Spotlight indexes all kinds of metadata, as does photos search. Adding an agent to upload data from these is easier than extending the CSAM mechanism, and the CSAM mechanism as is is not all that plausible to abuse either technically or socially given how clear Apple’s promises are.

Why should Apple's promises be taken at face value? Doubly so in a world where they can be compelled legally to break those promises and say nothing (especially in the more totalitarian countries they willingly operate in and willingly subvert some of their other privacy guarantees)?

What stops Apple from altering the deal further?

And if you have an answer for that, what makes you believe that 10 years in the future, with someone else at the helm, that they won't?

Your device is now proactively acting as a stool pigeon for the government where it wasn't prior. This is a new capacity.

And it's for CSAM. For now. The technological leap from locally scanning just the stuff you upload, to scanning everything, is a very simple change. The leap from scanning for CSAM to scanning for some other perceptual hashes the government wants matched is very simple.

Re: Apple's child protection features spark concern within its own ranks: sources

#489
I understand they are going to make perceptual hashes of images, but what are they going to do to videos?

Did they not see Fight Club where frames were added on videos? Are they going to hash each frame from videos as well? All 60 fps 4k videos? I’m sure that a lot of people saw that movie, and some of them might be pedophiles. It really looks like an half assed solution

Re: Apple's child protection features spark concern within its own ranks: sources

#490
post #478

Earlier quoted context omitted.

The technical risk to user privacy - if your threat model is a coerced Apple building surveillance features for nation state actors - is exactly the same between CSAM detection and Photos intelligence which sync results through iCloud. In fact, the latter is more generalizable, has no threshold protections, and so is likely worse.

Exactly this. The whole thing is a red herring. If Apple wanted to go evil, they can easily do so, and this very complex CSAM mechanism is the last thing that will help them.

I’ve read your comments, and they are a glass of cold water in the hell of this discourse. This announcement should force people to think about how they are governed - to the extent they can influence it - and double down on Free Software alternatives to the vendor locked reality we live in.

Instead, a forum of presumably technically savvy people are reduced to hysterics over implausible futures and a letter to ask Apple to roll back a change that is barely different from, and arguably better than, the status quo.

Post reply on HN