Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

491–500 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#491

Earlier quoted context omitted.

That is, it seems like Apple really wanted to preserve "end-to-end" encryption,“ … except they still have not mentioned anything about E2E encryption… and they currently don’t encrypt icloud backups. You would think apple would get ahead of this story and mention … or maybe they don’t have any E2E plans at all.

This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…

But with Apple's CSAM proposal is NOT possible to have an iPhone that Apple isn't continuously scanning.

Sure it is—just don't use iCloud Photos. They've been quite clear about this.

Re: Apple's child protection features spark concern within its own ranks: sources

#492

Earlier quoted context omitted.

Could they though? An authoritarian government could just as easily say "if you do not implement this feature, we will not allow you to operate in this country" and refuse to entertain legal challenges.

Apple is a fairly large company, that gives them some monetary leverage over governments. It's not as simple as you make it seem, I think.

Should this fact be reassuring or even more frightening ?

Because it’s something to push back against governments by saying « I can’t ». But it’s a societal issue if a corporation can say « I don’t want » to a government.

It’s really not the same thing and Apple just burned their « I can’t » card and are implying they can just say « no » to governments. Which is quite an even more dystopian thing.

Re: Apple's child protection features spark concern within its own ranks: sources

#493

Earlier quoted context omitted.

I disagree, strongly. Let's say you're authoritarian government EvilGov. Before this announcement, if you went to Apple and said "we want you to push this spyware to your iPhones", Apple would and could have easily pushed back both in the court of public opinion and the court of law. Now though, Apple is already saying "We'll take this database of illegal image hashes provided by the government and use it to scan you…

Why do you think essentially no one is complaining about using ML to understand the content of photos, then (especially in comparison to this rather targeted CSAM feature)? My impression is that both Apple and Google have already been doing that since what? 2016? Earlier? There's been no need for a database of photos, either company could silently update those algorithms to ping on guns, drugs, Winnie the Pooh memes,…

Why do you think essentially no one is complaining about using ML to understand the content of photos…

At last in Apple's case, ML is used only if a minor child (less than 13 years old) who is on a Family account where the parent/guardian has opted-in to the ability to be alerted if potentially bad content is either sent or received using the Messages app.

Re: Apple's child protection features spark concern within its own ranks: sources

#494
post #315

Earlier quoted context omitted.

Woops, you're right, thanks for the correction. I think the issue is that, as Ben Thompson pointed out, the only thing preventing them from scanning other stuff now is just policy , not capability , and now that Pandora's box is open it's going to be much more difficult to resist when a government comes to them and says "we want you to scan messages for subversive content".

Yes, of course that is true. I use iCloud Photos and find this terribly creepy. If Apple must scan my photos, I'd rather they do it on their servers. I could maybe understand the new implementation if Apple had announced they'd also be enabling E2E encryption of everything in iCloud, and explained it as "this is the only way we can prevent CSAM from being stored on our servers."

If Apple must scan my photos, I'd rather they do it on their servers.

Scanning on their servers is much less privacy preserving for users but don't fret, Dropbox, Facebook, Microsoft, etc. already scan stored photos.

Re: Apple's child protection features spark concern within its own ranks: sources

#495

Earlier quoted context omitted.

This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…

> But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still possible to use an iPhone without iCloud and get full E2E. I disagree completely on this. For one, users aren't aware that using iCloud means that Apple has your decryption key and can thereby read and share all of your phone's data. And two, opt-out is a dark pattern.…

I dunno, when I read the choices in iTunes about backups, I didn’t feel particularly manipulated. It seemed straight forward. Trade offs were clear to me.

I guess some people just see dark patterns where I don’t.

Re: Apple's child protection features spark concern within its own ranks: sources

#496

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

[deleted]

Re: Apple's child protection features spark concern within its own ranks: sources

#497
post #315

Earlier quoted context omitted.

Yes, of course that is true. I use iCloud Photos and find this terribly creepy. If Apple must scan my photos, I'd rather they do it on their servers. I could maybe understand the new implementation if Apple had announced they'd also be enabling E2E encryption of everything in iCloud, and explained it as "this is the only way we can prevent CSAM from being stored on our servers."

> "this is the only way we can prevent CSAM from being stored on our servers." Why is that supposed to be their responsibility? Given the scale of their business, there is effectively a certainty that people are transmitting CSAM via Comcast's network. That's no excuse for them to ban end to end encryption or start pushing out code to scan client devices. When you hail a taxi, they don't search you for drugs before l…

Why is that supposed to be their responsibility?

They (and Google, Microsoft, Facebook, etc.) are essentially mandated reporters; if CSAM is on their servers, they're required to report it.

It's like how a doctor is a mandated reporter regarding physical abuse and other issues.

Because they're not the police. It isn't their role to enforce the law.

They're not enforcing the law; if the CSAM reaches a certain threshold, they check it out and if it's the real deal, they report to National Center for Missing and Exploited Children (NCMEC); they get law enforcement involved if necessary.

Re: Apple's child protection features spark concern within its own ranks: sources

#499

Earlier quoted context omitted.

>the system is just a few bit flips away from scanning every photo on your device I prefer to think of it as being just one national security letter away from that happening. Which is of course a schroedinger's cat kinda thing. It's already been sent. Or it hasn't. But why would the national security apparatus not take advantage of this obvious opportunity? Anyone giving benefit of the doubt to this kind of stuff now…

How would the agency issuing an NSL be able to generate a hash of a photo they’re looking for? Presumably if they already had a photo to derive the hash they’d already have whatever it is they’re searching for.

The program has capability to upload questionable photos for review.

Just make it do equivalent of .* of all photos on device. It would be hard to argue, that's more difficult than scanning for specific hash.

And there is nothing specific about images. Extending this to scan arbitrary data is probably not that much code, depending on how its program maybe configurable.

Re: Apple's child protection features spark concern within its own ranks: sources

#500

> It's a complete change of narrative and there's no easy way to explain it and still defend Apple's Privacy narrative, wihout doing extreme mental gymnastics. Everyone who took Apple at their word was already doing extreme mental gymnastics because Apple's privacy stance was a farce on borrowed time to begin with. Now it's just blatantly obvious to everyone.

It’s only a “farce on borrowed time” because you have the benefit of hindsight.

Many of us saw this coming years ago and got into pretty repetitive arguments with those who need the hindsight to see this.
Post reply on HN