Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

51–60 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#51
post #17
post #12

Earlier quoted context omitted.

Only semi-good reason is it would enable E2E encryption in the cloud while still allowing detection of CSAM.

Except despite this being repeated over and over… Apple has not said anything about E2E

Apple almost never talks about features like that until they’re ready, so while you’re correct, it doesn’t mean much.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#52

Earlier quoted context omitted.

Even HN reporting / article linking / comments have been surprisingly low quality and seem to fulminate and declaim with surprisingly little interesting conversation and tons of super big assertions. Linked articles and comments have said apple's brand is now destroyed, that apple is committing child porn felonies somehow with this (the logical jumps and twisting to get to these claims are very far from strong plausi…

From https://www.hackerfactor.com/blog/index.php?/archives/929-On... > The laws related to CSAM are very explicit. 18 U.S. Code § 2252 states that knowingly transferring CSAM material is a felony. (The only exception, in 2258A, is when it is reported to NCMEC.) In this case, Apple has a very strong reason to believe they are transferring CSAM material, and they are sending it to Apple -- not NCMEC. > It does not matt…

Apple isn't looking at the actual image, but a derivative. Presumably their lawyers think this will be sufficient to shield them from accusations of possessing child porn.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#53
post #28

Earlier quoted context omitted.

Absolutely not true. Apple is using a similarity based hash, so if the NCMEC database contains a picture that's similar to one that you have, it could produce a match even if it's not the same. Apple says this isn't an issue, because a person will look at your picture(yes, a random person somewhere will look at the pictures of your newborn) and judge whether they are pictures of child abuse or not. If this unknown pe…

Keep in mind, this manual review only happens after Apple’s system detects multiple occurrences of matches. Until that point, no human is alerted of matches nor does anyone see how many matches there have been. In a TechCrunch interview Apple said that they are going after larger targets that are worth NCMEC’s time.

Parents take a lot of photos of their kid. Like, lots.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#54

Earlier quoted context omitted.

Absolutely not true. Apple is using a similarity based hash, so if the NCMEC database contains a picture that's similar to one that you have, it could produce a match even if it's not the same. Apple says this isn't an issue, because a person will look at your picture(yes, a random person somewhere will look at the pictures of your newborn) and judge whether they are pictures of child abuse or not. If this unknown pe…

Where’s your evidence on this? The NCMEC database and this hashing have been around for like 15 years. I’m curious as to how you know this.

False positives have been found, not because the photo hold any similarities but because the hashes match: https://www.hackerfactor.com/blog/index.php?/archives/929-On...

Re: The deceptive PR behind Apple’s “expanded protections for children”

#55
post #6

Earlier quoted context omitted.

It's worth reading this, which is basically the only good reporting I've seen on this topic: https://daringfireball.net/2021/08/apple_child_safety_initia... There are legitimate things to be concerned about, but 99% of internet discussion on this topic is junk.

Even HN reporting / article linking / comments have been surprisingly low quality and seem to fulminate and declaim with surprisingly little interesting conversation and tons of super big assertions. Linked articles and comments have said apple's brand is now destroyed, that apple is committing child porn felonies somehow with this (the logical jumps and twisting to get to these claims are very far from strong plausi…

Another reminder that many parts of HN have their own biases; they're just different than the biases found on other networks.

Instead of exclusively focusing on the authoritarian slippery slope like it's inevitable, it's worth wondering first: why do the major tech companies show no intention of giving up the server-side PhotoDNA scanning that has already existed for over a decade? CSAM is still considered illegal by half of all the countries in the entire world, for reasons many consider justifiable.

The point of all the detection is so that Apple isn't found liable for hosting CSAM and consequently implicated with financial and legal consequences themselves. And beyond just the realm of law, it's reputational suicide to be denounced as a "safe haven for pedophiles" if it's not possible for law enforcement to tell if CSAM is being stored on third-party servers. Apple was not the best actor to look towards if absolute privacy was one's goal to begin with, because the requests of law enforcement are both reasonable enough to the public and intertwined with regulation from the higher powers anyway. It's the nature of public sentiment surrounding this issue.

Because a third party insisting that user-hosted content is completely impervious to outside actors also means that it is possible for users to hide CSAM from law enforcement using the same service, thus making the service criminally liable for damages under many legal jurisdictions, I was surprised that this debate didn't happen earlier (to the extent it's taking place, at least). The two principles seem fundamentally incompatible.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#56
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Unlikely except if you send them to a iphone which is registered with a "child" account.

Apple uses two different approaches:

1. Some way to try to detect _known_ child pornographic material, but it's fuzzy and there is no guarantee that it doesn't make mistakes like detecting a flower pot as child porn. But the chance that your photos get "miss detected" as _known_ child pornographic material shouldn't be too high. BUT given how many parents have IPhones it's basically guaranteed to happen from time to time!

2. Some KI child porn detection on child accounts, which is not unlikely to labile such innocent photos as child porn.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#57
post #6

Earlier quoted context omitted.

It's worth reading this, which is basically the only good reporting I've seen on this topic: https://daringfireball.net/2021/08/apple_child_safety_initia... There are legitimate things to be concerned about, but 99% of internet discussion on this topic is junk.

It's still a non-zero chance it triggers a no-knock raid by the police that kills your family or pets. it happens all the time

Non-zero being technically true because of the subject matter, but I don’t see how Apple’s system increases the risk of authorities killing family or pets more than server-side scanning.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#58
post #6

Earlier quoted context omitted.

It's worth reading this, which is basically the only good reporting I've seen on this topic: https://daringfireball.net/2021/08/apple_child_safety_initia... There are legitimate things to be concerned about, but 99% of internet discussion on this topic is junk.

The EFF wrote a really shitty hit piece deliberately confused the parental management function with the matching against hashes of illegal images. Two different things. From there, a bazillion hot takes followed.

Yeah I found the EFF's piece to be really disappointing, coming from an organization I'm otherwise aligned with nearly 100% of the time.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#59
post #41

Earlier quoted context omitted.

For me it's the worst of both worlds - e2ee has no meaning if the ends are permanently compromised - and there's no local vs cloud separation anymore which you can use to delineate what is under your own control - nothing's under your control.

The end isn't really compromised with their described implementation. The only thing sent is the hash and signature and that's only if there are enough matches to pass some threshold. I don't really view that as 'permanently compromised' - at least not in any way more serious that Apple's current capabilities to compromise a device. I think e2ee still has meaning here - it'd prevent Apple from being able to see your…

Yeah, and as argued in one of the blog posts - that's just a policy decision - not a capability decision - malleable to authoritarian countries' requests.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#60

Earlier quoted context omitted.

They have a podcast together called Dithering which is pretty good (but not free) - they're friends. I think John's article is better than Ben's, but they're both worth reading. Ben takes the view that unencrypted cloud is the better tradeoff - I'm not sure I agree. I'd rather have my stuff e2ee in the cloud. If the legal requirements around CSAM are the blocker then Apple's approach may be a way to thread the needle…

One logical conclusion of systems like this is that modifying your device in any "unauthorized" way becomes suspicious because you might be trying to evade CSAM detection. So much for jail-breaking and right to repair! I think I'd rather have the non-e2ee cloud.

I don't really buy that - you could just turn off iCloud backup and it'd avoid their current implementation.
Post reply on HN