Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

501–510 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#501

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

I don't think this is a good metaphor. You still get the privacy same privacy aspect as you did before. Only your iCloud images are now being scanned for visual matches. If you are already trusting Apple with rest of your private life this hardly is complete 180 degree turn.

I don't quite understand why people are so against this. What if some algorithm scans your images? If you are using any cloud service to share your images then your images are already being scanned and far more invasively. Is the the storing of hashes that concerns you? Your password(s) is already being stored as a hash and we trust that it can not be reversed back to plain text, why wouldn't we trust that these image hashes can't be reversed back into images?

I've seen some notion that this is a backdoor and governments and other Lovecraftian entities could use it to suppress freedom of speech by censoring certain images, but that would require them to first have the image in question, then creating hash of the image, and then inserting it into the Apple's database and after that it would only be flagged for human verification and again assuming you trust Apple to handle rest of your digital life (such as iMessages) why wouldn't you trust Apple to share your images? If some entity has it's hooks so deep in apple that they start to censor images why wouldn't they just stop all of your messages being sent?

Please correct me if I'm missing something obvious.

Re: Apple's child protection features spark concern within its own ranks: sources

#502
post #269

Earlier quoted context omitted.

> But with Apple's CSAM proposal is NOT possible to have an iPhone that Apple isn't continuously scanning. As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone.

>As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone. Except for the "oops, due to an unexpected bug in our code, every image, document, and message on your device was being continuously scanned" mea culpa we will see a few months after this goes live.

Except for the "oops, due to an unexpected bug in our code, every image, document, and message on your device was being continuously scanned" mea culpa we will see a few months after this goes live.

Only images that match the hashes of the database of CSAM held by the National Center for Missing and Exploited Children (NCMEC) that are uploaded to iCloud Photos are checked.

Based on their technical documents, it's not even possible for anything else to be checked; even if they could, they learn nothing from documents that aren't CSAM.

Re: Apple's child protection features spark concern within its own ranks: sources

#503
post #379

Earlier quoted context omitted.

This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…

iMessage isnt true E2E encryption. Apple could easily decode messages for a 3rd party if they wanted to. This has been widely discussed on HN previously. All they have to do is insert an additional private key in the two party chat, as the connection is ultimately handled centrally. There's a very good reason Signal (and previously Whatsapp) were recommended over iMessage. Not to mention the inability to swap iMessag…

Apple could easily decode messages for a 3rd party if they wanted to.

They don't have the keys, so how exactly would they decrypt these messages?

Re: Apple's child protection features spark concern within its own ranks: sources

#504
post #379

Earlier quoted context omitted.

iMessage isnt true E2E encryption. Apple could easily decode messages for a 3rd party if they wanted to. This has been widely discussed on HN previously. All they have to do is insert an additional private key in the two party chat, as the connection is ultimately handled centrally. There's a very good reason Signal (and previously Whatsapp) were recommended over iMessage. Not to mention the inability to swap iMessag…

Apple could easily decode messages for a 3rd party if they wanted to. They don't have the keys, so how exactly would they decrypt these messages?

They would be able to decrypt messages after the point of interception, not retroactively.

Re: Apple's child protection features spark concern within its own ranks: sources

#505
post #285

Earlier quoted context omitted.

Currently it would not catch that 4chan thing as they only scan things that are uploaded to icloud photos. So you'd have to click on it and save to photos. This is the current implementation. I would guess that once they have their hooks in though all files with an image extension/header will be scanned and reported.

Send it via WhatsApp where it gets added to photos and later iCloud by default if I recall correctly

yeah I'm not sure I do know it's a separate step to move photo from whatsapp to "general" photo access. I would guess it is roped off or they wouldn't need that step.

Re: Apple's child protection features spark concern within its own ranks: sources

#506
post #481

Earlier quoted context omitted.

>A set of multiple images must match. How many exactly? The threshold is secret, it could be 1 or 2 or maybe it is dynamic and depends on stuff like your identity.

It could be 1 or 2, but the claim is that it is set to only detect people who are actually building a collection of CSAM images because Apple doesn’t want this system to flag people who are unlikely to be actual criminals. I.e. they don’t just want no false positives, they don’t want positives that aren’t highly likely to be criminal. I’m guessing it’s a lot more than 2.

> but the claim is that it is set to only detect people who are actually building a collection of CSAM

From what I read the threshold is for a different purpose, ,the false positives are too many so to reduce the number of reports the threshold workaround is introduced, so is a hack to workaround the false positives and not a threshold to catch people with big collections.

Re: Apple's child protection features spark concern within its own ranks: sources

#507

> It's a complete change of narrative and there's no easy way to explain it and still defend Apple's Privacy narrative, wihout doing extreme mental gymnastics. Everyone who took Apple at their word was already doing extreme mental gymnastics because Apple's privacy stance was a farce on borrowed time to begin with. Now it's just blatantly obvious to everyone.

Please don't take HN threads further into flamewar. It makes discussion shallower, more tedious, and nastier.

We detached this subthread from https://news.ycombinator.com/item?id=28163326.

Re: Apple's child protection features spark concern within its own ranks: sources

#508

In their attempt to make this extra private by scanning 'on device', I think they've managed to make it feel worse. If they scan my iCloud photos in iCloud, well lots of companies scan stuff when you upload it. It's on their servers, they're responsible for it. They don't want to be hosting CSAM. It feels much worse them turning your own, trusty iPhone against you. I know that isn't how you should look at it, but tha…

> I know that isn't how you should look at it, but that's still how it feels. This is exactly how you should look at it. They turned your device against you.

I downvoted this comment because it's hyperbole.

There are plenty of over very real concerns with this. For example, say some activist intern at Apple decides they don't like your politics and hits the report button, next thing you know, the police show up to your door and are confiscating all your devices. Just one of many potential abuses.

Re: Apple's child protection features spark concern within its own ranks: sources

#509
post #507

> It's a complete change of narrative and there's no easy way to explain it and still defend Apple's Privacy narrative, wihout doing extreme mental gymnastics. Everyone who took Apple at their word was already doing extreme mental gymnastics because Apple's privacy stance was a farce on borrowed time to begin with. Now it's just blatantly obvious to everyone.

Please don't take HN threads further into flamewar. It makes discussion shallower, more tedious, and nastier. We detached this subthread from https://news.ycombinator.com/item?id=28163326 .

What criteria do you use to evaluate whether a post takes a thread further into a flamewar or not? In what way did my reply make the rest of the discussion "shallower, more tedious, and nastier"? I felt that this sparked a lively (albeit short) debate about a blindspot that a great many readers seem to have.

It took a six hour rollercoaster ride before flags killed it - not even a fair shake for anyone to vouch despite no flagged children.

Re: Apple's child protection features spark concern within its own ranks: sources

#510

Earlier quoted context omitted.

That is, it seems like Apple really wanted to preserve "end-to-end" encryption,“ … except they still have not mentioned anything about E2E encryption… and they currently don’t encrypt icloud backups. You would think apple would get ahead of this story and mention … or maybe they don’t have any E2E plans at all.

This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…

> iMessages are already E2E encrypted

Well, actually...I don't know if this post or another, but I remember something about Apple being able to invisibly add "someone else" to the E2E conversion if they really wanted to. But at the very least, this post mentions that most "E2E iMessages" are auto-backed up to the iCloud, which is NOT E2E.

https://blog.cryptographyengineering.com/2013/06/26/can-appl...

Post reply on HN