Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

521–530 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#521

Earlier quoted context omitted.

That’s not at all how this works. It doesn’t scan for images of arbitrary subjects. It scans for exact matches of known CP. Your vacation pics are in no danger of being flagged.

No, it uses perceptual hashing which is inexact, and a fuzzy metric like hamming distance between hashes to determine whether or not two images come from the same source image. Not only is it entirely possible for two images to have the same perceptual hash, it's even more likely that two unrelated images have similar hashes, which would indicate to the system that one image is likely an edited version of a source im…

It’s possible, but very unlikely. Then of course you need many matches to flag the account. And then of course there’s the manual review. The likelihood that an innocent person would get caught up in this at all is zero.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#522

Earlier quoted context omitted.

Apple's claims on how it will work are also completely unverifiable. What's stopping a government from providing Apple with hashes of any other sort of content they dislike?

And then Apple reviews the account and sees that what was flagged was not CSAM. And again, the hashes aren’t of arbitrary subject matter, they’re of specific images. Using that to police subject matter would be ludicrous.

How would Apple know what the content was that was flagged if all they are provided with is a list of hashes? I completely agree it's ludicrous, but there are plenty of countries that want that exact functionality.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#523

Earlier quoted context omitted.

I don't want to be arrested by the FBI and my life ruined because my daughter, who is 6 and doesn't know any better, takes a selfie with my phone while she happens to be undressed/changing clothes and the photo automatically syncs to the cloud.

You won’t. Understand what this is instead of falling for the hysteria.

It starts with comparing file hashes. I’m worried about where this goes next.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#524
post #335

Earlier quoted context omitted.

That's a claim by Apple. Due to the opaque process this is completely unverifiable. As well this statement relies on the fact that no malicious actor out there is trying to thwart the system. The hashes used are deliberately chosen to easily produce collisions otherwise the system won't work. This almost certainly will be abused.

The concept of checking images against a hash list is not unique to Apple or even new. https://en.m.wikipedia.org/wiki/PhotoDNA What Apple announced is a way to do it on the client device instead of the server. That has some security implications, but they’re more specific than just “hashes might collide.”

They're not just checking against a hash list, they're using perceptual hashing, which is inexact and unlike cryptographic hashing or checksumming. Then, they use a fuzzy metric like hamming distance to determine if one image is a derivative of an illegal image.

The problem is that the space for false positives is huge when you use perceptual hashing, and it gets even larger when you start looking for derivative images, which they have to do otherwise criminals would just crop or shift color channels in order to bypass filters.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#525
post #441

So the M1 has turned me off of Apple products because, quite frankly, I don't want to spend (more) of my time fixing shit a trillion dollar company broke and doesn't care to fix. This though, this will be the nail in the coffin with my 25 year relationship to Apple. I probably wouldn't even have batted an eye at it to be honest, iff, Apple hadn't been selling me on the idea that their platform is "private and secure.…

> So the M1 has turned me off of Apple products because, quite frankly, I don't want to spend (more) of my time fixing shit a trillion dollar company broke and doesn't care to fix. What is broken about the M1?

M1 Macs are basically iPads, with the same iOS-style locked-down boot process. They even have the same DFU mode as iOS devices.

In my case "my" M1 bricked itself, because Apple servers have refused to permit changes to NVRAM in the machine, and it can't boot a reinstalled OS without Apple's approval.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#526

Earlier quoted context omitted.

No, it uses perceptual hashing which is inexact, and a fuzzy metric like hamming distance between hashes to determine whether or not two images come from the same source image. Not only is it entirely possible for two images to have the same perceptual hash, it's even more likely that two unrelated images have similar hashes, which would indicate to the system that one image is likely an edited version of a source im…

It’s possible, but very unlikely. Then of course you need many matches to flag the account. And then of course there’s the manual review. The likelihood that an innocent person would get caught up in this at all is zero.

> It’s possible, but very unlikely.

I have built products in this space. It is entirely likely, and in fact, it is incredibly common. You can look at literally any reverse image search engine's results and see this, because they use the same perceptual hashing techniques to do reverse image lookups.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#527

Earlier quoted context omitted.

It’s possible, but very unlikely. Then of course you need many matches to flag the account. And then of course there’s the manual review. The likelihood that an innocent person would get caught up in this at all is zero.

> It’s possible, but very unlikely. I have built products in this space. It is entirely likely, and in fact, it is incredibly common. You can look at literally any reverse image search engine's results and see this, because they use the same perceptual hashing techniques to do reverse image lookups.

And you don’t think the threshold for a match will be a lot tighter for this use case compared to an image search engine? And you’re ignoring all the other guards I mentioned? Come on. You may not like Apple, but they’re not stupid.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#528
post #355

Earlier quoted context omitted.

You want Apple employees going trough naked photos of your kid and deciding if its child porn or not because the algo flagged it? Because that is what this means.

No, it doesn't. You have conflated two entirely different systems.

What would the two different systems be then?

I am certainly willing to agree I conflated them if you clarify.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#529
post #256

Earlier quoted context omitted.

The dell and lenovo laptops are nowhere the quality of the apple machines, sadly. I have a maxed out xps and it is a downgrade in all respects but privacy. :/

Yeah, I figured. When waiting for lsp autocompletes in emacs, my entry level M1 MacBook with no gccjit is orders of magnitudes faster than my almost maxed out Lenovo with emacs and GCCjit. The difference is so stark that I cannot bear to autocomplete on type on the Lenovo machine, it lags too much and frequently locks up.

My thinkbook g2 14 are is almost the same speed as m1 macbook and runs linux without any issue. It has "only" 9 hours of battery in my usecase, but that's completely fine by me.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#530
post #416

Earlier quoted context omitted.

As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography. 2. The complaints are all slippery slope arguments that governments will force Apple to abuse the mechanism. These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it. However: Child pornography and the related abuse is widely thought of as a massive probl…

I appreciate this well thought out and logical approach. The issue I have is with the way this is presented. I actually really like the local-only features related to making underage users second-guess sending/viewing potentially harmful content. IMO this is a huge problem especially since most do not have the context to understand how things live forever on the internet, and is likely a source of a large percentage…

> But just like this entire function can be added with an update, it can also be modified with an update.

That argument is a valid argument that by using an Apple device you are trusting them not to issue an abusive update in the future. It applies regardless of whether they release this feature or not - at any time they could issue spyware to any or all devices.

I actually fully agree that this is a problem.

My position is that Apple isn’t going to solve this problem. If we want it solved, we need to solve it.

The value of using Apple devices today, and even the sense that they are going to protect children who use their devices, far outweighs relatively vague and unproven assertions about future abuses that haven’t yet materialized in most people’s minds even if they turn out to be right in the end.

Post reply on HN