Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

491–500 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#491

I know the privacy approach Apple has been pushing was just marketing, but I didn't care too much because I enjoyed my iPhone and M1 macbook. Because of this decision (and the fact that my iPhone more-or-less facilitates poor habits throughout my life), I'm considering moving completely out of the Apple ecosystem. Does anyone have any recommendations for replacements? * On laptops: I have an X1 carbon extreme running…

If I were to buy a laptop, it would be the Framework laptop that just started shipping. It doesn't have a Ryzen chip, though, so that's a deal breaker for me. Otherwise, that laptop ticks all of my boxes.

Phone-wise, there are many options to choose from. I like the idea behind the Teracube 2E[1], as they take some of the principles behind Framework and apply it to phones.

> On cloud: I've considered executing on a NAS forever, but I'm unsure where to start.

Depends on how much you want to tinker. You can't go wrong with a Raspberry Pi and some external harddrives, but there is also dedicated NAS equipment that requires less setup and maintenance, some of them are Linux based, as well.

[1] https://myteracube.com/pages/teracube-2e

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#492
post #435

Earlier quoted context omitted.

Sure no company can completely defend me from my govt but atleast they can not build tools that make it easier. Also while it could be easy for a college graduate to build such a system, only Apple has the capability of rolling out this system to all of their phones. Otherwise we would have already seen such a system implemented in other countries

"only Apple has the capability of rolling out this system" Right. Exactly. Any country in the world can mandate that Apple do anything they want (any of the slippery slope mandates), and Apple can comply or withdraw from the market. If any country wanted to demand that Apple compare all files against a ban list, they could have done that in 2007, or any year since. There is zero technical barrier and it would be a tr…

> "only Apple has the capability of rolling out this system"

I guess this is where I differ with you. No government was able to preassure apple to implement a complete client side verification till now but who knows how things will be now that they have a system in place that can be easily modified.

Anyways I hope your prediction turns out right. I live in a place where privacy laws don't really exist. The last thing I want is any system that can be easily exploited by authorities to crush dissent.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#493

So the M1 has turned me off of Apple products because, quite frankly, I don't want to spend (more) of my time fixing shit a trillion dollar company broke and doesn't care to fix. This though, this will be the nail in the coffin with my 25 year relationship to Apple. I probably wouldn't even have batted an eye at it to be honest, iff, Apple hadn't been selling me on the idea that their platform is "private and secure.…

I used to downvote people a couple of years ago who were shedding doubt on Apple’s commitment to privacy. Boy. I was so wrong. I fell for the Marketing and it made sense at the time “Their business is selling hardware and services, not ads. Ofcourse they are privacy advocates”. Pass laws and legislation. I admit I was wrong and it’s refreshing to see this whole thing unfold before my eyes. It just solidified my opini…

That's part of downvote culture -- rather than verbally disagreeing, just press a button. It's easy. You don't have to present a counter-argument, you just begin to bury the opposing side. Everyone adds a shoveful of dirt and eventually that thing is just ... gone. Wished into the cornfield.

And it feels good, too. You've done your part, helping to make that sort of thing vanish.

Now you've seen how it works. That's why real engagement is so very important, it allows us to communicate and specify. What would a real commitment to privacy look like? Now we know that it isn't just a press release and a bunch of shiny happy faces (carefully chosen) holding Apple products. Now we can start talking about what a real commitment to privacy looks like in the world.

I know you think laws and legislation are a good idea, but my guess is that this is a big no, or we will get them but with all kinds of loopholes for three-letter agencies, or no penalties specified for infraction.

We know we won't get any kind of legal punishment, that recent ebay case is a fantastic example of the golden parachute you get.

Perhaps commitment looks like a bond held in escrow. If my Apple TV is found to be exfiltrating the filenames of everything in a network share, the five million in that escrow account gets kicked over to the EFF. Stocks could be held out in reserve.

Essentially, commitment looks like the Sword of Damocles, held over the heads of these corporate actors, and scissors are to be held by people who do not like them much.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#494
post #209

US Government: We suspect the person in this photo of committing a crime. Here is your subpoena, Apple. You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them. Chinese Government: Here is the NeuralHash for Tienanmen square. Delete all photos you find matching this or we will bar you from China. Apple has at this point already admitted thi…

Have they? The whitepaper made it sound like the encrypted security voucher is created from the database of known cp on the device at the time the image is uploaded, and the only way for Apple to decrypt something is if it matched something in that database. It did not sound like they could retroactively add additional hashes and decrypt something that already was uploaded. They could theoretically add something to t…

> they cannot do this for stuff that has already been stored.

That's a very simple software update.

Every year iOS gets more images the automatic tagging supports (dogs, shoes, bridges, etc). And if you add a friend's face to known faces, it'll go and search every other photo for that face.

It sounds absolutely trivial to re-scan when the hash DB gets updated.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#495
post #204

Earlier quoted context omitted.

Microsoft and Google have been doing that in their online services for ages, but not on your personal devices.

So if I don’t backup with Google Photos or Google Drive, would they be safe for now?

yes theoretically.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#496
post #470

Earlier quoted context omitted.

> child pornography cases is going down each year, from 1,593 in 2016 to 1,023 cases in 2020 Sam Harris (and the FBI) would likely say this is because detection is getting harder thanks to encryption. The only authority on this is actually the FBI, but I presume you wouldn’t trust them. That distrust is reasonable, but irrelevant. What matters is that many people will trust them and see the fear as legitimate. Arguin…

>One winning move would be to take the problem seriously What makes you think that the problem is not taken seriously? I am no specialist, but it looks like cases are investigated and people are going to jail. You say that it is not the case, so I am curious what leads you to this statement. Yes, policies can be based on fears and opinion, but some numbers and rationality usually help make better decisions. I'd love…

> Yes, policies can be based on fears and opinion, but some numbers and rationality usually help make better decisions.

Sure, but you aren’t the decision maker. This is a political decision, and so will be based on the balance of fears and forces at play, not a rational analysis.

It doesn’t matter how right or rational you are. It only matters how many people think you understand what they care about.

If the Hacker position is ‘people shouldn’t care about child pornography because the solutions are all to invasive’ so be it. I just don’t think that’s an effective position.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#497
post #408

Earlier quoted context omitted.

They scan things I send them. They don't (publicly announce that they) scan things on my device.

The Apple feature discussed here is for photos being synched to iCloud Photos. It does not scan arbitrary local content.

It also scans every photo that an iMessage user sends/receives.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#498

Earlier quoted context omitted.

The hashes are computed from images that live in iCloud - how is this different?

Suppose Apple flags some image in iCloud using a hash that was probably sent from the device. Do they currently have the capability to decrypt the image to check if the content is actually illegal before reporting it to the authorities without needing access to the physical device? (Not trying to make a counter-argument to your comment. I genuinely don't get this part).

Hmm not sure what you mean. The hashes are shipped with iOS, and then (if parental controls are enabled) compared with the hashes computed against the unencrypted data on-device, and displays a warning to the user and their parents.

I'm not sure how the image is displayed on the parents' device - it could be sent from the child's device, or the image used to compute the hash that the child's image matched could be displayed.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#499

Earlier quoted context omitted.

>Child pornography and the related abuse is a massive problem >proposals for better solution How do you define "massive"? What makes you think that current approach is not working well enough? Of course, it's really bad as soon as the very first case. But we need to go beyond the sensationalist articles which talk about millions of pictures outthere. Even though this is, yes, a problem. In the US, it looks like the n…

> In the US, it looks like the number of child pornography cases is going down each year Prosecuting fewer cases doesn't mean less abuse is occurring. It doesn't even mean that the number of instances of abuse for which cases are prosecuted are going down, just that the number of offenders prosecuted is going down.

Agree. It may well be a bad proxy. But it does not mean the problem is getting worse either, one would need to back it up with some arguments/estimates. The number of pictures on the internet does not seems a good one to me (cats population has not grown that big).

I am thinking that people don't seem to know if the problem is really getting bigger. They just say it. If we don't know that, we cannot use growing child pornography as an argument to reducing civil liberties.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#500

Earlier quoted context omitted.

Replace Chinese with absolutely any government and that's what'll happen. We're pretty much at a point where any hacker/leaker anywhere on earth is "found" to have committed sex crimes or have 300 gigabytes of child abuse on their computers. Eventually Disney will be getting their hands in it to detect copyrighted content and then it's all over.

You're right, though the ability to detect copyrighted content has been around for a good while. Although with this, I think it's more likely that Disney's executives and/or employees will be charged and arrested before that happens. I mean, with this track record... 1. (Aug 2021) https://djhjmedia.com/kari/disney-workers-caught-in-child-se... 2. (Dec 2017) https://variety.com/2017/biz/news/jon-heely-disney-music-gro…

[deleted]
Post reply on HN