Live data from Hacker News

One Bad Apple

hackerfactor.com

531–540 of 557 posts

Re: One Bad Apple

#531

Earlier quoted context omitted.

> government YOU are electing does something stupid Is America the entire world to you? What should a Chinese citizen do? What should a Saudi citizen do? What should a Russian citizen do? Even if you ignore the fact that the chance of fascism in American is not zero, why should Apple make it easier for totalitarian regimes to spy on their citizens? Or do you expect a Saudi person to "just move to America"?

I am talking to people on this website which is banned in 3 of the 4 countries you are talking about. Stop moving your shitty goalpost we are talking about the US, Europe and other democracies. You know what would help people in regimes? Governing bodies that stand up for them in other countries... guess who could change that.

I'm not moving the goalposts. I, one, have empathy for people other than myself and two, I am not deluded enough to think that fascism will never return to the West. If you don't care about citizens in other countries, that's on you.

>You know what would help people in regimes? Governing bodies that stand up for them in other countries... guess who could change that.

What would also help is if Apple didn't build tools for those regimes to suppress opposing political bodies.

Re: One Bad Apple

#532
post #477

Earlier quoted context omitted.

What reason do we have to trust that the NSA won't knock on the door of apple and ask for a small expansion, as a matter of national security + here is your NDA outlining that any canary tampering will result in jail time? It's a closed system so we would have no way of knowing.

Sure, but that has nothing to do with this mechanism or this discussion. They could have done that at any time in the past, and could do so in future. ‘NSA could force Apple to do something in secret’ is an evergreen fear just like ‘think of the children’. Such comments get added to every thread about Apple and privacy or security.

It’s one thing to have a company build and keep secret such a system from everyone, from the ground up.

It’s a different thing entirely to do a minor extension to a system that they rolled out publicly that already essentially does this!

The first one will almost certainly be noticed, and will be clearly illegal/violate contracts, and can therefore be identified and rooted out.

The second one you could do for groups of people or targeted individuals trivially and would be under the radar and probably never noticed - and could be denied unless truly rock solid evidence existed. Which would be easy to avoid existing if you used the same mechanisms (but different types of matches) you were public about - in a closed ecosystem with a Secure Enclave, for instance. It’s not like anyone is going to be able to do step-by-step instruction debugging on the code running on their iPhone!

There is a long history of this happening. Not everyone is as blatant as the stasi - and even then, no one knew who was working for them or what was tapped until the whole system collapsed and their records became public. It still took a long time to unravel.

Re: One Bad Apple

#533

Earlier quoted context omitted.

Why doesn't anyone ever question their intent to protect children? There is no such intent. When they do protect children, these are the sorts of observations of what happens when the state has 100% control over children: https://www.kansascity.com/news/special-reports/article23820... Why does the state, when they treat children like this, get to proceed on "more" child protection to protect children ? Are we totally…

I am supportive of Apple’s new child protection policies. I spent two years helping to build some of the tools used for scanning and reporting content (EDIT: not at Apple). There are a few sentiments in this thread that I'd like to address. > Yeah, and none of these assholes (pardon the language) is willing to spend a penny to provide for millions of children suffering of poverty: free education, food, health, parent…

> Many people in child safety and I, personally, strongly support policies that enhance the lives of children, including improved education, food, access to health services, and support for parents. To your point, though, it's also true that ...

You work with people who, almost always against the will of children and parents kidnap children (sorry, but search on Youtube for images of their action: kidnap is the only correct term) ... then proceed to NOT care for those children and destroy their lives. Obviously this is the only correct reasoning is that this is entirely immoral until the care system is fixed, because they are not improving the lives of children, and their complete lack of caring about this tells you what they're goals aren't.

Watch "Short Term 12" for what facilities these children are provided with. Stop pretending that helping these people acquire children (because that's exactly what you're doing) helps a single child. It doesn't. Terrible, abusive, violent, parents take better care of children than these places do. The moral reaction should be to do what most of society, thankfully, does: sabotage the efforts of social workers.

And if you're unwilling to accept this, as soon as this whole covid thing dies down a bit, find the nearest children's facility and visit. Make sure to talk to the children. You will find you're making a big mistake.

Whatever you tell yourself, please don't believe that you're helping children. You're not. You're helping to destroy their lives

> I see this sentiment a lot. I have worked with people across law enforcement, survivors, survivor advocates, NGOs, social workers, private companies, etc. and I don't know anyone who responds this way to people raising privacy concerns.

I'm adding this response to the other reply to your comment ... which makes 2 people who disagree with your assessment: you are likely to be threatened in many places. I feel like one might even say it's likely we're 2 people who have been threatened.

I would like to add that either as a child or an adult, child protection authorities, the people you help, will threaten you, and I've never known a single exception if they think (correctly or otherwise) that you're hiding something from them. That's if you're at their mercy (which is why every child in child services makes sure to commit some despicable/violent/minor criminal act or two every month and keep it secret: if you don't have something to confess that won't get you sent to a "secure facility" you will be horribly punished at some unexpected random time. That's how these people work. And over time you may learn that, for a kid in the system, a whole host of places are traps. Like the hospital, child services itself, police, homeless shelters or school. As in every person in one of those places will be shown your "history" as soon as you mention your name and if they report you ... very bad things will happen. Some children explicitly make bad things happen (e.g. commit violent theft), because they'll get sent to "juvie" and finally the stress of suddenly getting punished out of nowhere disappears. Also some believe you get better schooling in juvie. So you hide, even if you're hurt or sick. This is why some of those kids respond angrily or even violently if someone suggests they should see a doctor for whatever reason. Sometimes literally to make sure the option of suicide remains open (which is difficult in "secure" care). And why does this happen? NOT to protect children: to protect themselves and "their reputation", and their peace of mind against these children).

This, of course, you will never hear your new friends mention needs fixing. They are in fact fighting with this side of the system over money, so that EVEN LESS money goes to the kids the system takes care of. That, too, you will never hear from them. They are doing the opposite of what someone who means well with disadvantaged children will do.

I have zero doubts they will use your work, not to convict offenders, because that's hard, years of very difficult work, but to bring more kids into a system that destroys children's lives, and MORE so than the worst of parents do. Because throwing children into this system (and destroying their lives) is very easy. I'm sure occasionally they will convict an offender (which, incidentally, doesn't help the kids) or get a good outcome for a child. It happens. If is absolutely not common.

And not to worry they will put great emphasis on this statement: "I've never seen anyone in the system who didn't mean well". Most are idiots, by the way, if you keep digging at their motivations, they will reveal themselves very clearly quite quickly.

These "people in child safety" DO NOT mean well with children. They merely hate a portion of society (which includes those victimized children) and want to see them punished HARD. If you are a moral person, volunteer at a nearby children's shelter and show understanding when the inevitable happens and you get taken advantage of (do not worry, you will learn). DO NOT HELP THESE PEOPLE GET MORE CHILDREN.

Re: One Bad Apple

#534

Earlier quoted context omitted.

Sorry, perhaps I misunderstood what you meant by "infrastructure". Apple have always had the ability to do great evil to a lot of people, this update doesn't change that. They haven't gained any power they didn't already have. The government, for example, do not currently have the infrastructure to push updates to iPhone. If they passed laws, built servers etc to allow this then that would be a meaningful change that…

The government, for example, do not currently have the infrastructure to push updates to iPhone That's the point, this is a slippery slope -- without this system, governments have no way to compel Apple to scan for objectionable photos, Apple could claim, rightly so, that due to encryption technology and privacy, they have no way to do it. But now they've removed both the technological and privacy hurdle, and it's ju…

I only disagree that Apple could have previously "rightly" said it was impossible.

If China had previously demanded they scan users photos for certain material, then Apple could always have done so.

Sure, it would involve pushing an update to all phones, but so would the change you are talking about (to check more hashes).

Re: One Bad Apple

#535
post #532
post #477

Earlier quoted context omitted.

Sure, but that has nothing to do with this mechanism or this discussion. They could have done that at any time in the past, and could do so in future. ‘NSA could force Apple to do something in secret’ is an evergreen fear just like ‘think of the children’. Such comments get added to every thread about Apple and privacy or security.

It’s one thing to have a company build and keep secret such a system from everyone, from the ground up. It’s a different thing entirely to do a minor extension to a system that they rolled out publicly that already essentially does this! The first one will almost certainly be noticed, and will be clearly illegal/violate contracts, and can therefore be identified and rooted out. The second one you could do for groups…

> The first one will almost certainly be noticed, and will be clearly illegal/violate contracts, and can therefore be identified and rooted out.

Well since they have made very detailed public statements about the limits of this system and. not letting it be misused, they would certainly be in violation of contracts if they did start misusing it.

> if you used the same mechanisms (but different types of matches)

What kinds of ‘different matches’ do you think this mechanism can be used to make?

Re: One Bad Apple

#536

Earlier quoted context omitted.

The consequences seem very simple - once this system is in place, it's only a matter of time until a state actor, be it China or US or Russia or pretty much anywhere goes to Apple and says "hey this hash matching algorithm you have there? If you want to keep operating in our country, you need to match hashes too, no, we won't tell you what they are and what they represent, but you have to report to our state agency w…

This is such a stupid fallacy and it comes up every time something like this is discussed. You don't know if anything is or will be abused you expect it because you expect your elected government to do so. The problem here is with you or your electors not with the technology itself. You want to fix the symptoms but not the problem. As usual.

It's not just idle speculation- history speaks for itself.

Re: One Bad Apple

#537

NCMEC has essentially shows that they have zero regard for privacy and called all privacy activists "screeching voices of the minority". At the same time, they're at the center point of a highly opaque, entrenched (often legally mandated) censorhip infrastructure that can and will get accounts shut down irrecoverably and possibly people's homes raided, on questionable data: In one of the previous discussions, I've se…

> I'm surprised, and honestly disappointed, that the author seems to still play nice, instead of releasing the whitepaper. I'm the author. I've worked with different parts of NCMEC for years. (I built the initial FotoForensics service in a few days. Before I wrote the first line of code, I was in phone calls with NCMEC about my reporting requirements.) Over time, this relationship grew. Some years, I was in face-to-f…

It doesn't matter how "nice" the people on the lower levels are.

An organization is determined to act like the management wants. If management consists of jerks the organization they lead will always behave accordingly.

A fish rots from the head down…

Re: One Bad Apple

#538
post #174

Earlier quoted context omitted.

It does make one wonder--careless work, trivial problem, reuse of existing projects, writer portrays self as extremely productive, or some combination?

I think you're assuming bad faith from someone who has proven very competent, technical, and coherent. It might simply be truthful. And if the author is proud of that, it is both irrelevant and perfectly okay. Let's focus on the facts and arguments relevant to the article, not personal attacks.

None of the options I proffered are in the "bad faith" category.

Re: One Bad Apple

#539

Earlier quoted context omitted.

Completely agree. I have absolutely no doubt this technology will be abused. I bet it will be used to silence dissent, opposition and wrongthink more often than to protect children.

Why doesn't anyone ever question their intent to protect children? There is no such intent. When they do protect children, these are the sorts of observations of what happens when the state has 100% control over children: https://www.kansascity.com/news/special-reports/article23820... Why does the state, when they treat children like this, get to proceed on "more" child protection to protect children ? Are we totally…

To add on this: Nothing else is to expect form a country that—under protection of its legal system!—tortures mentally ill and disabled children.

https://en.wikipedia.org/wiki/Judge_Rotenberg_Educational_Ce...

https://www.independent.co.uk/news/world/americas/massachuse...

Re: One Bad Apple

#540

Earlier quoted context omitted.

Post your passwords.

That's too short a thought, it detracts from the point. It is bad to post passwords, not just because you lose privacy, but because you'd lose control of important accounts. Asking people to post their passwords is not reasonable. I think you might have a point you're trying to make, but please spell it out fully.

Post your home address and phone number.
Post reply on HN