Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

501–510 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#501

I really don't see why the scanning would ever be done on the phone instead of on iCloud if it only affects iCloud images. But I do have guesses why.

That's the crux of it. Why bother with on-device identification, unless one of: a. Apple intends to E2E encrypt iCloud data. b. This is intended to extend to all photos on the device in the future. I'm hoping it's (a), but it's probably (b). And in either case it sets a bad precedent for other companies to follow. Edit: This also turns every jailbreak into a possible CSAM detection avoidance mechanism, giving the gov…

End-to-end encryption sometimes leaking raw content to a "trusted party". What a joke.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#502

> The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember), debugging wifi drivers and tirelessly trying to make resume-from-suspend work? Oh come on. DOn't make it sound like it's that bad. Wifi is a solved problem for a long time now, and you can buy Lenovo, System76 or Tuxedo if you want to make sure 100% thi…

I don't know why, but Ubuntu still manages to make installing updates a 50/50 chance of breaking the NVIDIA GPU drivers, which then means I have to reinstall them in 800x600 where the "Software Updater" window doesn't fit on screen anymore. Also, getting full USB3 support on Ubuntu is still a struggle. On Windows and Mac, the same USB camera "just works". On Linux, I need to learn how to download the kernel sources,…

> I don't know why, but Ubuntu still manages to make installing updates a 50/50 chance of breaking the NVIDIA GPU drivers, which then means I have to reinstall them in 800x600 where the "Software Updater" window doesn't fit on screen anymore.

I cannot dismiss your experience. I think you are telling the truth.

But I was introduced to Ubuntu by a (mildly) enthusiastic 50 years old electrical engineer back in 2006, so I know it used to work for some ordinary people even back then.

I really don't know some HN-ers manage to break Ubuntu repeatedly while it just works for non technical users, but a qualified guess is a combination of exotic hardware and tinkering (a good thing).

Re: The deceptive PR behind Apple’s “expanded protections for children”

#503

Earlier quoted context omitted.

> The worst part is: how do I put my money where my mouth is? ..., debugging wifi drivers and tirelessly trying to make resume-from-suspend work? Coincidentally, this is actually a good idea. Apart from using supported hardware (that others have checked actually works), contributing fixes for hardware that's not officially supported yet and hasn't been tested would benefit everyone in the future! I remember having to…

Yeah... when you have a home-built PC with *nix unsupported hardware and invested lots of $$ you're still looking for a hard time. First, there's the hardware cost. I'm not throwing my Surface out, and I'm not throwing out my perfectly working desktop components either. But that aside... Every time I read how the great unwashed should just contribute fixes already to benefit everyone, I despair. I write code. I build…

> Every time I read how the great unwashed should just contribute fixes already to benefit everyone, I despair. I write code. I build my own PCs and I have a rather good knowledge of how to debug, fix, optimise and otherwise maintain all my software and hardware.

But i'm not saying that everyone should contribute, or even that everyone can. I know that i'm certainly not experienced enough in systems programming to do that, instead being more proficient with higher abstraction level languages.

That said, the fact that there's the possibility of contributing for at least some people is better than what Windows and other OSes let you do. Not only that, but if the problem is annoying enough and makes enough people frustrated enough, it's likely that there's actually someone amongst all of them who cares enough to fix the problem for everyone.

For the fix to land in the mainline might take a few months or years, but the end result is still better than looking at a black box and having literally no options to get it to do what you want.

If a new Debian updates break my GRUB install, it's likely that there will be people on GitHub discussing workarounds and fixes within minutes. If my off brand hardware doesn't work as i'd like, it's likely that i'll have to do some digging but the chances of me finding a fix aren't 0 either. If the same happened with Windows drivers, i'm not entirely sure what i could even do, since the hardware setup is something that almost noone actually cares about. In the case of *nix, if i were skilled enough, i could probably dig around the source myself and work on fixing it, as someone luckily had.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#504

> The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember), debugging wifi drivers and tirelessly trying to make resume-from-suspend work? Oh come on. DOn't make it sound like it's that bad. Wifi is a solved problem for a long time now, and you can buy Lenovo, System76 or Tuxedo if you want to make sure 100% thi…

You ommitted resume from suspend which is still a frigging problem. At least some finally support UEFI so your usb key install doesnt freeze on the first screen.

But yeah wifi and nvidia are solved - just a black screen and single mode startup the first time to deactivate the opensource drivers for some obscure reason (I understand they prefer it but why does it crashes... might as well just put the nvidia ones directly)

Re: The deceptive PR behind Apple’s “expanded protections for children”

#505

Earlier quoted context omitted.

> The false positive rate for any given image is not 1 in a trillion What's relevant is the overall false positive rate. If they require 6 matches for example, it's enough for each match to have a 1% false positive rate in order to get 1 in trillion overall.

Sadly not, because like the original comment implies, a false positive on a given image might cause it to be uploaded to Apple for manual review. So if Apple has a "1 in a trillion" 1e^-12 chance of flagging a person and they require (my guess) 3 hits to flag someone, then that would mean the chance of each single image being false positive is (1e^-12)^(1/3) = 1e^-4. So that means: Expect 1 in 1000 images to be uploa…

No, manual review only happens after the threshold is reached. Meaning, there is a 1 in a trillion chance that threshold-number of images are manually verified by Apple.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#506

Earlier quoted context omitted.

Sure, but none of those images will be a hash match to any material in NCMEC databases.

It's entirely possible for one innocuous picture to look like an illegal picture in that database, and if they do look similar, they'll have similar perceptual hashes. That's the point of perceptual hashing.

'Similar' hashes wouldn't do anything; the system hashes perceptually similar images (cropped, resized etc.) to the same hash.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#507

> The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember), debugging wifi drivers and tirelessly trying to make resume-from-suspend work? Oh come on. DOn't make it sound like it's that bad. Wifi is a solved problem for a long time now, and you can buy Lenovo, System76 or Tuxedo if you want to make sure 100% thi…

Until they can manage to make updating software seamless, it will continue to not be viable for mainstream.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#508

Earlier quoted context omitted.

Explain to me how photos get into the NCMEC database to begin with

I've absolutely no knowledge of how they operate, but it occurs to me that there would be at least two very obvious avenues: 1) During the course of investigation an officer infiltrates a CSAM sharing ring and/or poses as a customer for CSAM. Material is shared with the officer as it would be to an actual consumer of CSAM. 2) When someone is charged with child abuse, possession of child porn, etc, their physical and…

3) No one really knows and since the content is illegal to possess no one can audit it either.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#509

> The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember), debugging wifi drivers and tirelessly trying to make resume-from-suspend work? Oh come on. DOn't make it sound like it's that bad. Wifi is a solved problem for a long time now, and you can buy Lenovo, System76 or Tuxedo if you want to make sure 100% thi…

Fun fact: We had to switch from Lenovo to something else because wifi did not work reliably in fedora.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#510

Earlier quoted context omitted.

Sure, but none of those images will be a hash match to any material in NCMEC databases.

It's entirely possible for one innocuous picture to look like an illegal picture in that database, and if they do look similar, they'll have similar perceptual hashes. That's the point of perceptual hashing.

Furthermore - and the extent of this was eye opening to me and I'm not the most naive person:

What for parents is "children playing in the pool in the garden - shared on YouTube so grandparents could see it"

- is something that is collected into playlists and shared with "interesting" timestamps in certain circles. A story here on HN a couple of years ago about a (for us normal people) totally innocent video having reached a million views or something on YouTube because of this sick and ugly thing.

But now we must ask ourselves: is that video CP?

No, for everyone else.

Yes for these sick bastards.

How do you classify that?

If it is classified, what happens to the parents when they switch from Android to iPhone and backup the photos and videos to "summer memories 2017" in iCloud?

Post reply on HN