Live data from Hacker News

One Bad Apple

hackerfactor.com

521–530 of 557 posts

Re: One Bad Apple

#521
post #92
post #61

Earlier quoted context omitted.

They could have done all that without telling you. And as long as the traffic was combined with normal traffic no one would ever notice (and in this case it would end up mixed with normal traffic since it only applies to images being uploaded to iCloud, so communication with Apples servers would be expected). What it looks like to me is that Apple is planning on releasing end-to-end encryption for iCloud. But they kn…

Sticking to the apt analogy from the article, >To reiterate: scanning your device is not a privacy risk, but copying files from your device without any notice is definitely a privacy issue. > Think of it this way: Your landlord owns your property, but in the United States, he cannot enter any time he wants. In order to enter, the landlord must have permission, give prior notice, or have cause. Any other reason is tre…

That first line of the quote is misrepresenting what Apple is doing. They are not copying files from your device. You are sending them the files. As it stands the only images that will be scanned are the ones you are uploading to iCloud. And I'd be shocked if they weren't already analyzing those images on the server side.

When it comes to governments being able to pressure them into being more invasive, nothing has changed with this update. If a government wanted to poison the CSAM database, they could have already. You'd end up reported when the server does the scanning. If the government wanted to expand scanning to include things that you're not uploading, they already could have asked Apple to do that. It would have been possible to silently add a much simpler scanning mechanism or data exfiltration into an update.

This isn't a spin to say anyone is doing us a favor. iCloud should be end-to-end encrypted and there shouldn't be any scanning at all. But why should that opinion on how we should treat privacy be taken as the only valid opinion? The people who do want the scanning are not simply asking for it because they are stupid or uninformed. Instead they put different weights into what they value.

Re: One Bad Apple

#522
post #488

Earlier quoted context omitted.

I actually feel the same way. I miss those earlier eras. I just think that exaggerating scares is part of the problem, not the solution, regardless of which side of a debate is doing it.

Agreed in principle. But in this particular case, I think it's difficult to exaggerate the badness of this scare. This strikes me as one of the "Those who forget their history are doomed to repeat it" kind of things. Like with the TSA and the no-fly list. Civil liberties groups said it was going to be abused, and they said so well before any actual abuse had occurred. But they weren't overreacting, and they weren't e…

I don’t think the scare is warranted.

This really is a narrowly targeted solution that only works with image collections, and requires two factors to verify, and two organizations to cooperate, one of which is Apple who has unequivocally staked their reputation on it not being used for other purposes, and the other is NCMEC which is a non-profit staffed with people dedicated to preventing child abuse.

People who are equating this with a general purpose hashing or file scanning mechanism are just wrong at best.

It’s not like the no-fly list at all.

Re: One Bad Apple

#523

Earlier quoted context omitted.

One or two news reports of local councils maybe using CCTV, doesn’t back up your claim. The UK doesn’t have a super camera system used for minor crimes like you insinuate. The high camera counts in the UK come from including private CCTV cameras in the data which privately owned and are not linked together, hence the government is not using a network of cameras to monitor dog poo clean up as you claim.

The UK government explicitly lays out a strategy for provate cameras to be bought and operated with mandatory rules for police access to footage. [1] This is on top of the cameras that ARE owned by government entities - 18+ city councils [2]. And it's expanding [3]. Why do you think it matters if they are linked together? Retaining footage and handing it over to police on request (not warrant) is a requirement. The I…

I don't think any of your links remotely substantiate what you claimed ("the single biggest user of UKs camera system originally intended for serious crimes are housing councils checking to see who didn't clean up after their dog.").

What even is the "camera system originally intended for serious crimes"?

Re: One Bad Apple

#524
post #489

Earlier quoted context omitted.

> The governing bodies should obey the people not the other way around. Then they wouldn't be the governing body. By definition the governing body does not obey the people; they govern the people.

Isn't a democratic governing body representing the will of the people and society?

No, they represent themselves.

Re: One Bad Apple

#525

Good article, however- "Due to how Apple handles cryptography (for your privacy), it is very hard (if not impossible) for them to access content in your iCloud account. Your content is encrypted in their cloud, and they don't have access. If Apple wants to crack down on CSAM, then they have to do it on your Apple device" I do not believe this is true. Maybe one day it will be true and Apple is planning for it, but ri…

That's obviously completely untrue.

It doesn't matter anyway, end to end cryptography is meaningless if someone you don't trust owns one of the ends (and in this case, Apple owns both.)

Re: One Bad Apple

#526
Given that the weights for the NeuralHash algorithm are being shipped to every iOS device and neural network adversarial attacks are pretty well studied in literature, it should be trivial to make a website or Android camera app that tweaks a few pixels of an image to make it have a hash collision with apple's CSAM database. If anyone seriously wants to kill this initiative, widely distributing a few memes with hash collisions could go a long way.

Re: One Bad Apple

#527
post #227

Earlier quoted context omitted.

I believe it would because other image systems will probably have to make similar implementations and trade offs that PhotoDNA did.

Why? It would be interesting to compare the two systems, but there is no reason to assume the trade-offs are the same.

There are trade offs that can be made that are inherent to the space.

There are a handful of hashing methods in papers, and each can have its parameters tuned, again making trade offs for things like efficiency or accuracy.

Then when it comes to efficient searching through hashes for matches and fuzzy matches, there are common algorithms and data structures used across perceptual hashing systems, each with with their own trade offs, implementation details and parameters that can be tuned.

If there's an issue with PhotoDNA that doesn't come down to a poor implementation, then there's a good chance that other systems might have met the same pitfalls they did. And if it comes down to a poor implementation, it would be prudent for operators of other systems to make sure their own systems don't make the same mistakes.

Re: One Bad Apple

#528

Earlier quoted context omitted.

It's the exact same shit I was talking about instead of fixing your governing body you want to fix it with technology. All the crypto apologist are the same way if the government YOU are electing does something stupid you want to fix the symptom and not the governing body. You are just throwing around goal posts instead of working on the real problem.

> government YOU are electing does something stupid Is America the entire world to you? What should a Chinese citizen do? What should a Saudi citizen do? What should a Russian citizen do? Even if you ignore the fact that the chance of fascism in American is not zero, why should Apple make it easier for totalitarian regimes to spy on their citizens? Or do you expect a Saudi person to "just move to America"?

I am talking to people on this website which is banned in 3 of the 4 countries you are talking about. Stop moving your shitty goalpost we are talking about the US, Europe and other democracies. You know what would help people in regimes? Governing bodies that stand up for them in other countries... guess who could change that.

Re: One Bad Apple

#529
post #43
post #13

Earlier quoted context omitted.

Legality aside – how is this not a privacy risk? Privileged users of the infrastructure can gain information about users (whether they possess CSAM that's in the hash-database... for now).

Presumably the reviewers would not know the identity of the user whose photos are under review, as they have no need to.

... but the link between user and photo obviously exists somewhere in Apple's system.

Re: One Bad Apple

#530

Earlier quoted context omitted.

It's the exact same shit I was talking about instead of fixing your governing body you want to fix it with technology. All the crypto apologist are the same way if the government YOU are electing does something stupid you want to fix the symptom and not the governing body. You are just throwing around goal posts instead of working on the real problem.

Civil disobedience. If we think a law is unjust, it is our duty to disobey and undermine it. Technology is a tool that allows us to do exactly that.

This is not disobedience this is beanbag shaped, mayonnaise filled tech bros talking about freedom they've never lost but also never wanted.
Post reply on HN