Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

521–530 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#521
post #486

Earlier quoted context omitted.

Neither 1 nor 2 are in fact true. Spotlight indexes all kinds of metadata, as does photos search. Adding an agent to upload data from these is easier than extending the CSAM mechanism, and the CSAM mechanism as is is not all that plausible to abuse either technically or socially given how clear Apple’s promises are.

Why should Apple's promises be taken at face value? Doubly so in a world where they can be compelled legally to break those promises and say nothing (especially in the more totalitarian countries they willingly operate in and willingly subvert some of their other privacy guarantees)? What stops Apple from altering the deal further? And if you have an answer for that, what makes you believe that 10 years in the future…

What stops them from altering the deal is that they have said they won’t, and there really is no evidence to believe otherwise.

If they do, then they do. There are never any guarantees about anyone’s future behavior. However just saying ‘what stops you from becoming a thief?’, does not imply that you will become a thief.

There is no new capability other than what they have said. They already had far more general purpose mechanisms for analysing and searching your files already in the operating system.

The leap from doing spotlight indexing to searching for the keywords ‘falun gong’ or ‘proud boys’ in your files is also simple. So is the leap from searching your photos locally for ‘dogs’, to searching locally for ‘swastikas’ and reporting back when they are found.

If they decide to build some spyware, there is no need for it to be based on this. It’s a red herring.

Re: Apple's child protection features spark concern within its own ranks: sources

#522
post #507

Earlier quoted context omitted.

Please don't take HN threads further into flamewar. It makes discussion shallower, more tedious, and nastier. We detached this subthread from https://news.ycombinator.com/item?id=28163326 .

What criteria do you use to evaluate whether a post takes a thread further into a flamewar or not? In what way did my reply make the rest of the discussion "shallower, more tedious, and nastier"? I felt that this sparked a lively (albeit short) debate about a blindspot that a great many readers seem to have. It took a six hour rollercoaster ride before flags killed it - not even a fair shake for anyone to vouch despi…

Two issues:

1. Your comment didn't add any information—it was just grandiose, inflammatory claims ("extreme mental gymnastics", "farce to begin with" and "blatantly obvious")

2. Replies like https://news.ycombinator.com/item?id=28163531 are to be expected to such comments. This is the way that discussion degrades. (That was the top reply to your comment before I downweighted it, so the effect was a lot more obvious before that.)

Ok, three issues:

3. This entire subthread is way more generic than the better parts of the discussion. That's to be expected from inflammatory comments that don't add information. Generic threads are much more predictable and much less interesting than specific ones: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor....

Re: Apple's child protection features spark concern within its own ranks: sources

#523

In their attempt to make this extra private by scanning 'on device', I think they've managed to make it feel worse. If they scan my iCloud photos in iCloud, well lots of companies scan stuff when you upload it. It's on their servers, they're responsible for it. They don't want to be hosting CSAM. It feels much worse them turning your own, trusty iPhone against you. I know that isn't how you should look at it, but tha…

> I know that isn't how you should look at it, but that's still how it feels

It's definitely how you should look at it because it's right. Once a device is compromised in this way, there's no going back and the erosion of privacy and expansion of scope will become neverending. If a capability exists, it will just be too hard for spooks to keep their fingers out of the cookie jar.

Re: Apple's child protection features spark concern within its own ranks: sources

#524

Earlier quoted context omitted.

Why do you think essentially no one is complaining about using ML to understand the content of photos, then (especially in comparison to this rather targeted CSAM feature)? My impression is that both Apple and Google have already been doing that since what? 2016? Earlier? There's been no need for a database of photos, either company could silently update those algorithms to ping on guns, drugs, Winnie the Pooh memes,…

Why do you think essentially no one is complaining about using ML to understand the content of photos… At last in Apple's case, ML is used only if a minor child (less than 13 years old) who is on a Family account where the parent/guardian has opted-in to the ability to be alerted if potentially bad content is either sent or received using the Messages app.

By default iPhones autocategorise your photos, don't they?

Re: Apple's child protection features spark concern within its own ranks: sources

#525

Earlier quoted context omitted.

With server-side scanning, the separation is clear In all these threads everyone is coming close to the crux of the issue, but I want to restate it in clearer terms: There is a sacrosanct line between "public" and "private," "mine" and "yours." That line cannot be crossed by Western governments without a warrant. Cloud computing has deliberately blurred this line over time. This on-device scanning implementation blow…

> There is a sacrosanct line between "public" and "private," "mine" and "yours." That line cannot be crossed by Western governments without a warrant. This is a self-delusion, I am afraid. The line has been crossed more than once, and it will be crossed again. UK and Australian governments are just two prime examples of waving terrorism and pedobear banners as a pretext to get invasive with each new legislation, and…

The line is not a delusion just because it happened to be crossed at some point. The line is there because humans intuitively consider it to be there.

The fact that the line is there gives us a reason and a foothold to fight back when someone attempts crossing it.

Re: Apple's child protection features spark concern within its own ranks: sources

#527

Earlier quoted context omitted.

That is, it seems like Apple really wanted to preserve "end-to-end" encryption,“ … except they still have not mentioned anything about E2E encryption… and they currently don’t encrypt icloud backups. You would think apple would get ahead of this story and mention … or maybe they don’t have any E2E plans at all.

This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…

iCloud Backup is a backdoor in the iMessage e2e, and Apple can decrypt all the iMessages. No warrant is required for Apple to do so.

Even with iCloud off, the other endpoint (the phones you're iMessaging with) will be leaking your conversations to Apple because they will still have iCloud Backup defaulted to on.

iMessage is no longer an e2e messenger, and Apple intentionally preserves this backdoor for the FBI and IC.

They access 30,000+ users' data per year without warrants.

Re: Apple's child protection features spark concern within its own ranks: sources

#530

Earlier quoted context omitted.

I have to note that one of those solutions deployed at scale is Google's. But the big difference is that when those were originally rolled out, they didn't make quite that big of a splash, especially outside of tech circles. I will also note that, while it may be a hypothetical in this particular instance as yet, EU already went from passing a law that allows companies to do something similar voluntarily (previously,…

Ok but now you’ve said that the precedent established by Google and others already moved the legislation to require terrible invasions of privacy far along. You started by saying Apple’s technology (and, in particular, its framing of the technology) has brought new legal risk. What I’m instead hearing is the risk would be present in a counter factual world where nothing was announced last week. At this point of the d…

The precedent established by Google et al is that it's okay to scan things that are physically in their data centers. It's far from ideal, but at least it's somewhat common sense in that if you give your data to strangers, they can do unsavory things with it.

The precedent now established by Apple is that it's okay to scan things that are physically in possession of the user. Furthermore, they claim that they can do it without actually violating privacy (which is false, given that there's a manual verification step).

Post reply on HN