Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

511–520 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#511

Earlier quoted context omitted.

Woops, you're right, thanks for the correction. I think the issue is that, as Ben Thompson pointed out, the only thing preventing them from scanning other stuff now is just policy , not capability , and now that Pandora's box is open it's going to be much more difficult to resist when a government comes to them and says "we want you to scan messages for subversive content".

Given that they obviously already have the capability to send software updates that add new on-device capability, this seems like a meaningless distinction. It’s already “just policy” preventing them from sending any conceivable software update to their phones.

There's a difference -- often a big one -- between being theoretically able to build some feature into a phone (plus the server-side infra and staffing to support it), and actually having built it. That's the capability angle.

However, the difference between having a feature enabled based on the value of a seemingly-unrelated user-controlled setting, versus having that feature enabled all the time... is basically zero. Additionally, extending this feature to encompass other kinds of content is a matter of data entry, not engineering. That's the policy angle.

When you don't yet have a capability, it might take a lot of work and commitment to develop it. But on the contrary, policy can be changed with the flip of a switch.

Re: Apple's child protection features spark concern within its own ranks: sources

#512

Earlier quoted context omitted.

Something probably did happen. Apple no doubt became increasingly aware of just how legally culpable they are for photos uploaded to iCloud. For content that is pirated Apple would receive a slap on the wrist, but for content that shows the exploitation of children? And that Apple is hosting on their owned servers? There is no doubt every government will throw their full legal weight behind that case. Now they are st…

Yea, I agree. I see so many comments where people view the issue is black and white and that apple is clearly in the wrong. Yes, privacy is a great ideal. There are absolute monsters in this world and there is zero chance that no apple employees have brushed up against those monsters. I would ask that every single developer step back and think about putting themselves into a situation where software that you write is…

I think there will always be a small number bad people in the world, that will always find a way to be bad.

I know they’re out there in the world, but I leave my home anyways, because living my entire life curled up in my bed in fear would be a sad and short life.

I’m more afraid that people will lose the ability to be happy because they’re so full of fear and skepticism that they don’t form meaningful relationships, relax, experience life.

I’m also more afraid of what can happen when a small group of people are allowed to dictate and control the lives of many, justifying it by pushing fear. Then it’ll be more than a small group of abusers harming a small group of people (in this case, child abusers). It becomes a different group of abusers (dictators) harming the entire population through their dystopian politics.

How many people, including children, died when a group of dictators used fear & skepticism in the 1930s to push an agenda that ultimately led to WWII and concentration camps?

We need to be extraordinarily careful that we don’t try to save a very small number of lives at the expense of many lives in the future, as a result of policies that we put in place today.

Re: Apple's child protection features spark concern within its own ranks: sources

#513
Can we talk about the irony that the NCMEC's database of CSAM (two abbreviations I didn't know before this week) is literally a huge child porn collection, or is that too immature? The whole story sounds like bad science fiction to me, I gotta say. But sadly I think we have to beware of anything that's packaged as anti-child-porn just like whatever's anti-terrorism, anti-crime etc. etc. You should be thinking "What is the thing that's slightly less heinous than child porn, that needed to be wrapped in the magic cloak of comparative heinousness for anyone to be horrified enough to accept it?"

Re: Apple's child protection features spark concern within its own ranks: sources

#514

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

I'm not a techie, but I think iOS already has similar technology: Camera detects faces, Photos can recognize people and objects (or cats) — all with help of AI (or ML). I think they are just expanding this and combining with "share".

Re: Apple's child protection features spark concern within its own ranks: sources

#515

Earlier quoted context omitted.

> "this is the only way we can prevent CSAM from being stored on our servers." Why is that supposed to be their responsibility? Given the scale of their business, there is effectively a certainty that people are transmitting CSAM via Comcast's network. That's no excuse for them to ban end to end encryption or start pushing out code to scan client devices. When you hail a taxi, they don't search you for drugs before l…

Why is that supposed to be their responsibility? They (and Google, Microsoft, Facebook, etc.) are essentially mandated reporters; if CSAM is on their servers, they're required to report it. It's like how a doctor is a mandated reporter regarding physical abuse and other issues. Because they're not the police. It isn't their role to enforce the law. They're not enforcing the law; if the CSAM reaches a certain threshol…

> They (and Google, Microsoft, Facebook, etc.) are essentially mandated reporters; if CSAM is on their servers, they're required to report it.

I don't think that's correct. My understanding is that if they find CSAM, they're obligated to report it (just like anyone is). I don't believe they are legally obligated to proactively look for it. (It would be a PR nightmare for them to have an unchecked CSAM problem on their services, so they do look for it and report it.)

Consider that Apple likely does have CSAM on their servers, because they apparently don't scan iCloud backups right now. I don't believe they're breaking any laws, at least until and unless they find any of it and (hypothetically) don't report it

Re: Apple's child protection features spark concern within its own ranks: sources

#516

Earlier quoted context omitted.

First, there is nothing stopping a full legislative assault on end to end encryption, various such proposals have had traction recently in both the US and EU. The lawyerly phrase is “knew or should have known.” It could be argued that now that this technology is feasible, failure to apply it is complicity. Think about GDPR. Eventually homomorphic encryption is going to be at a point where “we need your data in the cl…

> First, there is nothing stopping a full legislative assault on end to end encryption, various such proposals have had traction recently in both the US and EU. And nothing stops Apple from fighting against the legislative assault. They have made themselves a champion of user privacy and have deep pockets to fight the fight, yet they just surrender at first attempt.

> champion of user privacy

> surrender at first attempt

The irony

Re: Apple's child protection features spark concern within its own ranks: sources

#517

Earlier quoted context omitted.

I'm assuming you're kidding here, but if you look at the list of countries already selling/supporting iPhones, what's not on the US export ban list that's a totalitarian regime? https://www.apple.com/iphone/cellular/

China is obviously the big one as is Russia.

But they’re already in both countries.

Re: Apple's child protection features spark concern within its own ranks: sources

#518
post #481

Earlier quoted context omitted.

It could be 1 or 2, but the claim is that it is set to only detect people who are actually building a collection of CSAM images because Apple doesn’t want this system to flag people who are unlikely to be actual criminals. I.e. they don’t just want no false positives, they don’t want positives that aren’t highly likely to be criminal. I’m guessing it’s a lot more than 2.

> but the claim is that it is set to only detect people who are actually building a collection of CSAM From what I read the threshold is for a different purpose, ,the false positives are too many so to reduce the number of reports the threshold workaround is introduced, so is a hack to workaround the false positives and not a threshold to catch people with big collections.

I have seen both in comments from Apple. Certainly spokespeople have talked about wanting any reports to NCMEC to be actionable.

I think a lot hinges on what you call a ‘false positive’. It could mean ‘an image that is not CSAM’ or it could mean ‘an account that has some apparent CSAM, but not enough to be evidence of anything’.

Re: Apple's child protection features spark concern within its own ranks: sources

#520

Earlier quoted context omitted.

That is, it seems like Apple really wanted to preserve "end-to-end" encryption,“ … except they still have not mentioned anything about E2E encryption… and they currently don’t encrypt icloud backups. You would think apple would get ahead of this story and mention … or maybe they don’t have any E2E plans at all.

This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…

They are not E2E encrypted if they are decryptable. We should use the correct terminology here, especially to not subject users to false security.
Post reply on HN