Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

531–540 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#531

Earlier quoted context omitted.

How many of them include erect adult penises and active participation in sex acts? Apple's on-device list of hashes only includes images which have been classified "A1" under the CSAM categorisation scale. If any other photographs are accidental hash collisions to these images, it's going to be pretty damn obvious to the human reviewer.

The problem with all of this, is that it's about to trust. We're are supposed to trust apple's algorithm to avoid false positives, we're supposed to trust apple that even with false positives there's some threshold to cross, and then supposed to trust apple that their employees will do a good job verifying the pictures, and then(most imporantly) trust that a giant american corporation won't honor secretive state requ…

I trust that Apple knows that an actual, real world false accusation will make this week's media challenges look like a fleabite.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#532

Earlier quoted context omitted.

What kind of hardware are we talking about here for a self-built PC which isn't supported by Linux?

● Intel Core i9 with 64Gb RAM ● Samsung 500 GB 2.5" SSD ● 2 x Western Digital 4TB mirrored disks ● NVIDIA GeForce GTX 1650 ● Sharkoon 600 Watt power supply ● 2 x Samsung U28R55 28" 4k IPS panels ● Das Keyboard 4 Professional ● S.M.S.L M6 Hifi Audio USB DAC with headphone amplifier ● 2 x Behringer MS40 digital 40-watt stereo near-field monitors ● Sennheiser HD 650 Open back headphones ● ELP 1080P wide angle webcam ● M…

Everything apart from the DAC should work (that may also work, but I'm not sure). The most important factor however, the motherboard, is missing in your post.

The GPU should work on distros like Ubuntu or Pop!Os per default, but due to Nvidia driver shenanigans you might have to do some manual config on e.g. debian.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#533
post #237

Earlier quoted context omitted.

The EFF article refers to a "classifier", not just matching hashes. So, three different things. I don't know how much you know about them, but this is what the EFF's role is. Privacy can't be curtailed uncritically or unchecked. We don't have a way to guarantee that Apple won't change how this works in the future, that it will never be compromised domestically or internationally, or that children and families won't b…

> When you take a picture of your penis to send to your doctor and it accidentally syncs to iCloud and trips the CSAM alarms, will you get a warning before police appear? You would have to have not one, but N perceptual hash collisions with existing CSAM (where N is chosen such that the overall probability of that happening is vanishingly small). Then, there'd be human review. But no, presumably there won't be a warn…

That isn't an offer of legal protections or guarantees that the trustworthiness and accuracy of their methods can be verified in court.

It really doesn't matter how they do it now that we know that iOS has vulnerabilities that allow remote monitoring and control of someone's device to the extent that it created a market for at least one espionage tool that has lead to the deaths of innocent people.

I remember when the popular way to shut down small forums, business competitors, or get embarrassing information taken off the web was to anonymously upload CP to it and then report it, repeatedly. With this, what's to stop virtual "SWATing" of Apple customers? Not necessarily just those whose Apple products have been compromised, whose iClouds have been compromised, or who are the victims of hash collisions (see any group of non-CSAM images that CSAM detection flags).

Will Apple analyze all hardware to ensure no innocent person is framed because of an undisclosed vulnerability? What checks are being offered on this notoriously burdensome process on the accused?

>If you think that Apple creates malicious iOS updates targeting specific people, then you have more to worry about than this new feature

Oof. Good point.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#534

Earlier quoted context omitted.

I'd be surprised if a baby in the bath—or indeed any legitmately innocent photograph taken by a parent—could ever be a perceptual match to images tagged as "A1" by NCMEC and other agencies. This is the most extreme of the extreme: prepubescent minors actively engaged in sex acts.

You have a fundamental misunderstanding of perceptual hashes, then. If two images look similar to one another, then they will have similar perceptual hashes. That's the point of perceptual hashing. They aren't doing simple hash matching, they're doing fuzzy matches on the hashes, so there will be far more false positives than just hash collisions.

All of us can only guess how much "fuzz" is being allowed for in their hash matches. I see no reason to believe Apple phoned in their analysis which leads them to be confident in a false positive rate of 1 in 1 billion per iCloud account. While we can only guess, they actually know how their algorithm behaves, and I dare say they've validated it against tens of millions, if not hundreds of millions of real customer images.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#535
post #427

Earlier quoted context omitted.

Sure, but none of those images will be a hash match to any material in NCMEC databases.

What if they decide next year to use AI to automatically detect potential violating images? I hope you won't throw the "slippery slope is a fallacy" fallacy at me.

Slippery slope isn't always a fallacy, but it is the way most people use it. Most people just define the slope however they want to suit their argument. Let me

Does this change to the software code represent a slippery slope of motive or opportunity? Many here have said yes, but in my opinion, no. When software can update itself, every single update is an opportunity for the software to betray you. That risk is already high; the risk profile doesn't increase because a particular change feels slippery slopey to you.

As soon as any closed-source software implements automatic software updates, you've always one malicious update away from the system betraying you. Interim steps are unnecessary. Whether it's Chrome, or Firefox, or Windows, or Android. Heck, even Ubuntu. Any of them could betray you at any time. Potentially trash their reputation in the process, but that's a mere technicality.

Therefore the slippery slope is the wrong metaphor. The correct metaphor is trust. Does this change lower my trust in Apple? Me personally, no. If anything, Apple's transparency has increased my trust in them. It gives me confidence that Apple won't use the fear of bad PR as an excuse to conceal serious things like this.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#536

Earlier quoted context omitted.

Fun fact: We had to switch from Lenovo to something else because wifi did not work reliably in fedora.

Which Lenovo model?

Sounds very odd indeed since Lenovo support is the first which hits the kernel. Maybe model was too new and bit patience was required.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#537

Earlier quoted context omitted.

That's the problem I had with Ben's post - it's always been policy since Apple controls and distributes iOS.

Yeah - the sense I got was he just liked the cleaner cut policy of a hard stop at the phone itself (and he was cool with the tradeoff of unencrypted content on the server). It does have some advantages - it's easier to argue (see: the disaster that is most of the commentary on this issue). It also could in theory be easier to argue in court. In the San Bernardino case - it's easier for Apple to decline to assist if a…

I have no idea if this feature existing makes it harder or easier for Apple to refuse. Based on how the feature works, it would still require a special build of iOS just like what the FBI wanted in order to remove the unlock count years ago.

Given the amount of nuance here, I also think it's important to differentiate between the FBI showing up and asking for something and government passing laws forcing encryption backdoors. The former is what Apple has fought to date b/c they can. The later is much harder to fight and Apple will most likely have to comply regardless of what features already exist or not (see China/iCloud). The later is also the most dangerous since politicians rarely understand technology enough to do something sensible. It remains to be seen, but Apple could be trying to get in front of long term law changes with an alternate solution.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#538

Earlier quoted context omitted.

It's entirely possible for one innocuous picture to look like an illegal picture in that database, and if they do look similar, they'll have similar perceptual hashes. That's the point of perceptual hashing.

Furthermore - and the extent of this was eye opening to me and I'm not the most naive person: What for parents is "children playing in the pool in the garden - shared on YouTube so grandparents could see it" - is something that is collected into playlists and shared with "interesting" timestamps in certain circles. A story here on HN a couple of years ago about a (for us normal people) totally innocent video having r…

I agree that "children playing in the pool in the garden" can function as CP when viewed by a sick bastard. But just because material can function as CP doesn't turn it into CSAM. It would never be classified under any of the formal CSAM categories (A1, A2, B1, B2) unless the video included lascivious exhibition, e.g. focus on genitals, sexual touching or posing, or an aroused adult.

The definitions are horrifyingly, depressingly, tragically very clear. I did not enjoy reading them.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#539

Earlier quoted context omitted.

> I’d be surprised that a YouTube video of white noise would be flagged for a copyright violation, and yet here we are. Speak for yourself, because that didn't surprise me at all. When your corpus of "copyrighted" material is so utterly massive and almost entirely devoid of defined rules or boundaries, this kind of error is inevitable. If anything I'm more surprised that we haven't seen even more of these kinds of ma…

You completely bypassed the point of my post. It doesn't matter about what happens now. What matters is in the future. If China creates a law saying that not only should this system work for CSAM but also for objectionable material or anti-government material, is Apple really going to say no if it means billions of dollars in losses and Apple execs being targets by the CCP? Of course they won't.

If you think it's Apple's (or Google's, or Microsoft's) role to act as the international human rights arm of the US State Department, then I have some bad news for you.

China can do whatever China wants. If China wanted Apple to scan the iPhones of Chinese residents for pictures of Winnie The Pooh, they could have done that last year. They pass a law, Apple must comply or leave. They don't have a choice.

Of course I don't like it. I think many things China does are awful. But at the end of the day I wouldn't stand for China exporting their morality onto me, and I'm not a hypocrite.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#540

> The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember), debugging wifi drivers and tirelessly trying to make resume-from-suspend work? Oh come on. DOn't make it sound like it's that bad. Wifi is a solved problem for a long time now, and you can buy Lenovo, System76 or Tuxedo if you want to make sure 100% thi…

Linux has all kinds of issues, but I haven’t had a single one with drivers in the last (probably over) 7 years, whereas I had a few on Windows.
Post reply on HN