Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

501–510 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#501
post #335

Earlier quoted context omitted.

That's a claim by Apple. Due to the opaque process this is completely unverifiable. As well this statement relies on the fact that no malicious actor out there is trying to thwart the system. The hashes used are deliberately chosen to easily produce collisions otherwise the system won't work. This almost certainly will be abused.

“This almost certainly will be abused.” is a claim by you and completely unverifiable. Apple has published white papers explaining how their hashing, matching, and cryptography work. How do you see someone thwarting that process specifically?

Apple's claims on how it will work are also completely unverifiable. What's stopping a government from providing Apple with hashes of any other sort of content they dislike?

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#502

Earlier quoted context omitted.

I used to downvote people a couple of years ago who were shedding doubt on Apple’s commitment to privacy. Boy. I was so wrong. I fell for the Marketing and it made sense at the time “Their business is selling hardware and services, not ads. Ofcourse they are privacy advocates”. Pass laws and legislation. I admit I was wrong and it’s refreshing to see this whole thing unfold before my eyes. It just solidified my opini…

Is it not weird to have people argue that Apple should be above the laws of places like Saudi Arabia and China, but this should be dealt with by "pass laws and legislation" and then expect Apple must obey those? ...?

I think people imply Apple should refuse to do business if it means following unjust laws contrary to their core values. Instead, it is a revelation that their core values aren't to protect the individual, but themselves.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#503

There has to be some incentive somewhere for Apple to do this. They know it's wrong, they know it will be abused. Tim Cook himself, if he wasn't rich and powerful, would be executed in a number of countries that Apple operates in for his sexual/romantic identity. Apple also removes LGBT based applications in countries where they're illigal, to continue doing business. This demonstrates that Apple complies with the de…

> There has to be some incentive somewhere for Apple to do this. They know it's wrong, they know it will be abused.

The most positive spin I can put on it is that it has become clear behind the scenes that NCMEC and partners have put enough pressure on Congress that Apple believes that on-device scanning for CSAM content will be soon be required by federal law, and this is their attempt to define the parameters in as privacy-preserving a way they can before the actual legislative language is drafted and can't be changed.

Even if all of that is true, I don't think this was the best way to do it and it is a huge own-goal to concede ground before there's even been a public debate about it.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#504

So the M1 has turned me off of Apple products because, quite frankly, I don't want to spend (more) of my time fixing shit a trillion dollar company broke and doesn't care to fix. This though, this will be the nail in the coffin with my 25 year relationship to Apple. I probably wouldn't even have batted an eye at it to be honest, iff, Apple hadn't been selling me on the idea that their platform is "private and secure.…

> " has absolutely zero chance of being detected once you're generating the hashes until too many lives are ruined. " ... the alerts go to Apple for human review. You think their human review won't notice a garbled nonsense picture triggering a false positive?

> the alerts go to Apple for human review

This should be read as "the alerts go to a barely-trained employee at a third party contractor like Cognizant[1] who has a quota of material to review every hour or they get fired and don't necessarily get points for accuracy for human review". I don't think Tim Cook is going to be double checking these images.

[1] https://www.theverge.com/2019/2/25/18229714/cognizant-facebo...

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#505
Wait, why is everyone so distraught about this? Am I missing something? This only affects people who upload their photos to iCloud?

Just don't store any data on iCloud. Seems simple enough. Yeah sure, we can make conspiracy theories and all, but based off of what was officially announced I'm not understanding all the hysteria.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#506

Earlier quoted context omitted.

yes it’s only icloud photos for now. what’s going to be next? are you going to have a huge scandal every time they turn on a new “feature”?

Its interesting that its only brought up when Apple does it. Google, MS, Dropbox, etc gets a pass..

Google, MS, Dropbox don't wave their Privacy flag and pretend they are better than everyone. Guess I'll add Apple to my "do not buy stuff from them" list

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#507

I'm waiting for orthodox authorities to do stuff like reporting pictures of people (not just girls) without head coverings. or dressed in bikinis, thongs, or underwear (like a significant number of "influencers" do, every day). There are already places in this world, where a couple can be arrested for kissing in public. I suspect that the folks enforcing those laws, would have some real interest in this capability. N…

That’s not at all how this works. It doesn’t scan for images of arbitrary subjects. It scans for exact matches of known CP. Your vacation pics are in no danger of being flagged.

No, it uses perceptual hashing which is inexact, and a fuzzy metric like hamming distance between hashes to determine whether or not two images come from the same source image.

Not only is it entirely possible for two images to have the same perceptual hash, it's even more likely that two unrelated images have similar hashes, which would indicate to the system that one image is likely an edited version of a source image in their database.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#508

Earlier quoted context omitted.

Apple doesn't "scan" iCloud. Not sure what you're talking about. Generally everything in iCloud is E2E encrypted, with the exception of iCloud Backups, where Apple holds onto a decryption key and will use it to comply with subpoenas. But nothing is "scanned," and if you don't use iCloud backup, Apple can't see your data.

iCloud Photos aren’t E2E encrypted, but it’s unlikely they’re scanned for CSAM today because Apple generates effectively 0 references to NCMEC annually.

[deleted]

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#509

Earlier quoted context omitted.

Alternatively, if you don’t use iMessage or iCloud then I don’t think these changes affect you.

lol. nope. trust is binary. you either trust apple or not. after peddling their privacy marketing for so long and doing this, they literally lost my trust.

For most people, trust isn't binary though.

For example, just because you hire someone for one purpose doesn't mean they should have the keys to your house.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#510
post #456

Earlier quoted context omitted.

Refusing to acknowledge egregious top-down decisions which threaten or violate either one's well-being or some perceived fundamental right has a much worse effect on public trust. "Why didn't you tell me this was going on?" "You're simply too stupid to handle the idea that your betters might occasionally be untrustworthy"

How are you going to argue that it’s bad for parents to be informed when strangers send sexual imagery to their children?

You argue the applications of the technology further down the line. Remind them how facebook's safety features turned into tools for censorship.
Post reply on HN