Live data from Hacker News

One Bad Apple

hackerfactor.com

51–60 of 557 posts

Re: One Bad Apple

#51

> However, nothing in the iCloud terms of service grants Apple access to your pictures for use in research projects, such as developing a CSAM scanner. (Apple can deploy new beta features, but Apple cannot arbitrarily use your data.) In effect, they don't have access to your content for testing their CSAM system. > If Apple wants to crack down on CSAM, then they have to do it on your Apple device. I don’t understand……

> Apple can’t change their TOS Why not... has anyone actually successfully sued a company for changing their ToS from under them?

Yes, see Douglas v. Talk America.

Re: One Bad Apple

#52

> However, nothing in the iCloud terms of service grants Apple access to your pictures for use in research projects, such as developing a CSAM scanner. (Apple can deploy new beta features, but Apple cannot arbitrarily use your data.) In effect, they don't have access to your content for testing their CSAM system. > If Apple wants to crack down on CSAM, then they have to do it on your Apple device. I don’t understand……

> Apple can’t change their TOS Why not... has anyone actually successfully sued a company for changing their ToS from under them?

Doesn't every TOS include that clause about the customer automatically accepting any change the company makes to the TOS at any time and without notification?

Re: One Bad Apple

#53
post #47

This feels like missing the forest from the trees — Steve Jobs said many times to the effect ‘it doesn’t matter how any of this stuff happens, GigaHertz, Ram, Speeds, it only matters that the user gets what they want.’ Right now Apple’s biggest unhappy user is the DOJ. As it stands with the legislation coming down the pipe and both previous administrations building on a keenness to ‘get something done’ about big tech…

Why do elected officials act as fake representatives to the people that elected them in the first place? Has it always been this way? It doesn’t matter left or right. The governing bodies should obey the people not the other way around.

If the people had their way, those suspected of child sex crimes wouldn’t even get trials. Things like privacy and due process only exist to the extent that a ruling class has the power to impose their own values, contrary to popular will.

Re: One Bad Apple

#54

> However, nothing in the iCloud terms of service grants Apple access to your pictures for use in research projects, such as developing a CSAM scanner. (Apple can deploy new beta features, but Apple cannot arbitrarily use your data.) In effect, they don't have access to your content for testing their CSAM system. > If Apple wants to crack down on CSAM, then they have to do it on your Apple device. I don’t understand……

Apple said it is coming in iOS 15 and when you install it, you will need to accept TOS. It might change at that point.

Re: One Bad Apple

#55

Good article, however- "Due to how Apple handles cryptography (for your privacy), it is very hard (if not impossible) for them to access content in your iCloud account. Your content is encrypted in their cloud, and they don't have access. If Apple wants to crack down on CSAM, then they have to do it on your Apple device" I do not believe this is true. Maybe one day it will be true and Apple is planning for it, but ri…

I think that section was rewritten, it currently reads:

> [Revised; thanks CW!] Apple's iCloud service encrypts all data, but Apple has the decryption keys and can use them if there is a warrant. However, nothing in the iCloud terms of service grants Apple access to your pictures for use in research projects, such as developing a CSAM scanner. (Apple can deploy new beta features, but Apple cannot arbitrarily use your data.) In effect, they don't have access to your content for testing their CSAM system. > If Apple wants to crack down on CSAM, then they have to do it on your Apple device.

(which also doesn't really make sense, if the iCloud ToS don't grant Apple the necessary rights to do CSAM scanning there, they could just revise it, however, I think they probably have the rights they need already)

Re: One Bad Apple

#56

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

>I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper.

Would it help anything? Apple isn't using PhotoDNA, so proving PhotoDNA is bad would just be met with "we don't use that".

Re: One Bad Apple

#57
I appreciate just about everything about this post, but this part keeps getting lost in everything I see written about it:

>As noted, Apple says that they will scan your Apple device for CSAM material. If they find something that they think matches, then they will send it to Apple. The problem is that you don't know which pictures will be sent to Apple.

It's iCloud Photos. Apple has explicitly said it's iCloud photos. If it's being synced to iCloud Photos, you know it's getting scanned one way or another (server side, currently, or client side, going forward).

It notes privacy issues, but... iCloud syncs by default. You wouldn't do the kind of work they're talking about (e.g, investigation) and store that kind of material where it could be synced to a server to begin with.

Everyone keeps proclaiming that Apple is scanning your entire device, but that's not what's happening with this change. It's not even comparable to A/V in this respect - it would be a very different story if that was the case. The wording and explanation matters.

Re: One Bad Apple

#58
post #12

> 18 U.S.C. § 2258A is specific: the data can only be sent to NCMEC. (With 2258A, it is illegal for a service provider to turn over CP photos to the police or the FBI; you can only send it to NCMEC. Then NCMEC will contact the police or FBI.) What Apple has detailed is the intentional distribution (to Apple), collection (at Apple), and access (viewing at Apple) of material that they strongly have reason to believe is…

Why is it insane that the law places extremely tight controls on the legitimate distribution of CSAM?

Re: One Bad Apple

#59
post #18

There are a lot of articles about Apples hadh algorithm and for me they are mostly irrelevant to the main problem. The main problem is that Apple has backdoored my device. More types of bad images or other files will be scanned since now apple does not have plausible deniablity to defend any of ghe government’x requests. In the future a false? positive that happened? to be of a political file that crept in the list c…

Exactly. The issue is that the iPhone is now a snitch AI for whatever purpose Apple deems fit.

Re: One Bad Apple

#60
post #29

The author of this article purports to have done a ton of research into this system, but appears to have missed basic information that I’ve acquired from a few podcasts. Namely the “1-in-a-trillion” false positives per account per year is based on the likelihood of multiple photos matching the database (Apple doesn’t say how many are required to trip their manual screening threshold).

So they are assuming that the photos are independent. Common error with probabilistic reasoning. What if the same photo (or photos of the same scene taken seconds apart) gets uploaded more than once? The likelihood no longer multiplies. I don't believe the "one in a trillion" claim.

They say that they address this issue through a mechanism outside of the cryptographic protocol, but don't say specifically how. The quote from the paper:

A user might store multiple variants or near-duplicates of the same image on their client. In our language, this means that a single client could hold two triples (y,id,ad) and (y,id′,ad) that have same hash y, but different identifiers. This causes an issue that is addressed outside of the cryptographic protocol. Suppose a user copies a single image from a USB drive onto his or her device. The image will be assigned an identifier id. Later the user copies the same image from the USB drive onto a different client device. The new copy of the image will be assigned a new identifier id′ which is likely to be different from id. Because the two copies have different identifiers they will count twice towards the tPSI-AD threshold. In particular, the two triples will cause two distinct Shamir shares to be sent to the sever, even though they correspond to the same semantic image. Several solutions to this were considered, but ultimately, this issue is addressed by a mechanism outside of the cryptographic protocol. [0]

[0]: https://www.apple.com/child-safety/pdf/Apple_PSI_System_Secu...

Post reply on HN