Live data from Hacker News

One Bad Apple

hackerfactor.com

541–550 of 557 posts

Re: One Bad Apple

#541

Earlier quoted context omitted.

Why doesn't anyone ever question their intent to protect children? There is no such intent. When they do protect children, these are the sorts of observations of what happens when the state has 100% control over children: https://www.kansascity.com/news/special-reports/article23820... Why does the state, when they treat children like this, get to proceed on "more" child protection to protect children ? Are we totally…

I am supportive of Apple’s new child protection policies. I spent two years helping to build some of the tools used for scanning and reporting content (EDIT: not at Apple). There are a few sentiments in this thread that I'd like to address. > Yeah, and none of these assholes (pardon the language) is willing to spend a penny to provide for millions of children suffering of poverty: free education, food, health, parent…

Meta-question: Is there a way to get rid of such "hot air" comments form throwaway accounts?

This comment does not add any argument in favor of its point, despite its length.

Re: One Bad Apple

#542
post #370

Earlier quoted context omitted.

> If that was their intention then I suspect they would have mentioned it alongside this announcement to provide a justification and quell the (justified) outrage. It’s August. New iPhones and iOS / macOS are released in September. If they want to introduce E2E encryption for photos and need this in place to do it, then it makes sense to announce this ahead of time and get the backlash out of the way so that they can…

Software features are announced at WWDC, which happens early summer and already happened this year. It's only the hardware that gets announced (and the software released) in September.

Some software features are announced at WWDC, mostly ones that affect developers. Consumer-facing services have also been announced during the September event; it’s not just hardware. Apple One, Apple TV+, and Apple Arcade were all announced during the last couple of September events.

Re: One Bad Apple

#543
post #94

Earlier quoted context omitted.

The use of the detection algorithm is for iCloud only today . Now that the technology is on-board the device, how many lines of codes do you think it will take to scan the full photo-roll? Do you think that this ability will not tempt LEA, law makers, governments, to push for that ever-so-small change to the code, either for blanket monitoring (see if China is not tempted, using their own database of "illegal" conten…

Based on this article (and my first rebuttal[0]) I actually think the whole "only photos syncing to icloud photos" part of it is the defining factor making it legal - if Apple specifically only sent themselves photos that were detected as CSAM, it would likely be a felony, while the planned system can use the reasoning I laid out to likely not be charged with such felony. 0: https://news.ycombinator.com/item?id=28112…

Oooooh. That makes sense.

Re: One Bad Apple

#544
post #486
post #447

Earlier quoted context omitted.

It seems that Apple does not need to be a co-conspirator, and that it would be sufficient if someone added ‘malicious’ hashes to the NCMEC database.

Not correct. When enough images to trigger a match are detected apple employees verify the visual derivative to make sure it matches before an alert is generated. They would need to collude.

You’re right, I was thinking about a breach of privacy in general instead of actual legal consequences. (Though the possibility of governments backdooring Apple’s servers to access decrypted files stands, that shouldn’t make a difference with this iCloud-Photos-only spyware)

Re: One Bad Apple

#545
post #301
post #270

Earlier quoted context omitted.

i dunno, reading this thing sure does make it sound like it's only for photos stored in icloud. and the existence of such an elaborate system sure does seem to indicate that photos are end to end encrypted on their servers, otherwise they could just hash them there. it does the matching client side, so the hashes never leave the client. what it does send with the photos is this threshold thing where if enough of them…

okay, so according to this [1], icloud photos are not e2e encrypted. point still stands, this is a system that is designed to flag the images without looking at them server side. assuming that it is successful, it paves the way for when they could turn on e2e encryption for icloud photos. [1] https://support.apple.com/en-us/HT202303

I don't buy this argument one bit. If you're going to release a feature with client-side data scanning in order to turn on e2e, you would specify that to provide the reasoning and prevent backlash. Apple would be smart enough to say that (if that was their plan).

Furthermore, e2e isn't all that meaningful with this feature. A client-side scanner that allows someone to view a thumbnail of the photo if it matches some other photo they have kinda takes most of the protection e2e is supposed to provide...

Re: One Bad Apple

#546
post #301

Earlier quoted context omitted.

okay, so according to this [1], icloud photos are not e2e encrypted. point still stands, this is a system that is designed to flag the images without looking at them server side. assuming that it is successful, it paves the way for when they could turn on e2e encryption for icloud photos. [1] https://support.apple.com/en-us/HT202303

I don't buy this argument one bit. If you're going to release a feature with client-side data scanning in order to turn on e2e, you would specify that to provide the reasoning and prevent backlash. Apple would be smart enough to say that (if that was their plan). Furthermore, e2e isn't all that meaningful with this feature. A client-side scanner that allows someone to view a thumbnail of the photo if it matches some…

i don't think they would necessarily advertise a plan to attempt e2e this early. what if it proved to be infeasible? reversing course after an announcement like that would be a massive black eye.

have you ever seen a system like this that would be capable of flagging accounts for hosting bad material with a tiny false positive rate while being capable of e2e encrypting the material at rest like this one? i haven't, and it's an awful lot of engineering going to waste if that's not the goal.

Re: One Bad Apple

#547

Earlier quoted context omitted.

> The law does not say that naked photos of (your or anyone else's) kids are inherently illegal, they have to actually be sexual in nature. But that depends on who looks at it. People have been arrested and (at least temporary) lost custody over their children because someone called the police over perfectly normal family photos. I remember one case a few years ago where someone had gotten into trouble because one ph…

> I'd say we get police or health care to talk to people who think perfectly normal images are sexual in nature, but until we get laws changed at least then keep us safe. Personally I don't find anecdotes convincing compared to the very real amount of CSAM (and actual child abuse) we already know exists and circulates in the wild, but I do get your point. That said personally I don't think changing the laws would rea…

> Personally I don't find anecdotes convincing compared to the very real amount of CSAM (and actual child abuse) we already know exists

First: This is not hearsay or anecdotal evidence, this is multiple innocent real people getting their lives trashed to some degree before getting aquitted.

> I don't think a random Walmart employee is up-to-date on the legal definitions of CSAM, they're going to potentially report it regardless of what the law is (and the question of whether this is a wider trend is debatable, again this is an anecdote).

Fine, I too report a number of things to the police that might or might not be crimes. (Eastern European car towing a Norwegian luxury car towards the border is one. Perfectly legal in one way but definitely something the police was happy to get told about so they could verify.)

> With that, they were eventually found innocent, so the law already agrees what they did was perfectly fine, which was my original point.

Remember the job of the police is more to keep law abiding citizens safe than to lock up offenders. If we could magically keep kids safe forever without catching would-be offenders I'd be happy with that.

Making innocent peoples lives less safe for a marginally bigger chance to catch small fry (i.e. not producers), does it matter?

The problem here and elsewhere is that police many places doesn't have a good track record of throwing it out. Once you've been dragged through court for the most heinous crimes you don't get your life completely back.

If we knew police would always throw out such cases I'd still be against this but then it wouldn't be so obviously bad.

Re: One Bad Apple

#548

Earlier quoted context omitted.

Why doesn't anyone ever question their intent to protect children? There is no such intent. When they do protect children, these are the sorts of observations of what happens when the state has 100% control over children: https://www.kansascity.com/news/special-reports/article23820... Why does the state, when they treat children like this, get to proceed on "more" child protection to protect children ? Are we totally…

I am supportive of Apple’s new child protection policies. I spent two years helping to build some of the tools used for scanning and reporting content (EDIT: not at Apple). There are a few sentiments in this thread that I'd like to address. > Yeah, and none of these assholes (pardon the language) is willing to spend a penny to provide for millions of children suffering of poverty: free education, food, health, parent…

Given NCMEC's continuing attacks against consenting adult sex workers, that they never seem to regard adult sexual identities as valid under any circumstances, that they repeatedly retweet abolitionist groups for adult sexual expression, their actions during Backpage, them lying to Congress about the level of abuse that occurs and the recent statements by their staff, I find it kind of baffling that anyone would defend their leadership at this point.

NCMEC are willing to completely compromise their mission in order to chase other moral crusades that are unrelated to children, and seem to never care about the consequences of any of the things they call for.

I don't trust them, and they've earned that.

Re: One Bad Apple

#549
post #546

Earlier quoted context omitted.

I don't buy this argument one bit. If you're going to release a feature with client-side data scanning in order to turn on e2e, you would specify that to provide the reasoning and prevent backlash. Apple would be smart enough to say that (if that was their plan). Furthermore, e2e isn't all that meaningful with this feature. A client-side scanner that allows someone to view a thumbnail of the photo if it matches some…

i don't think they would necessarily advertise a plan to attempt e2e this early. what if it proved to be infeasible? reversing course after an announcement like that would be a massive black eye. have you ever seen a system like this that would be capable of flagging accounts for hosting bad material with a tiny false positive rate while being capable of e2e encrypting the material at rest like this one? i haven't, a…

...this early?

no e2e on iCloud has been a major issue for years. It's not like they're beta testing (the underlying principle/structure that is)

and again, I haven't seen a system that flags bad material that is also e2e because the whole premise is flawed.

Re: One Bad Apple

#550
post #345

Earlier quoted context omitted.

Yeah, and none of these assholes (pardon the language) is willing to spend a penny to provide for millions of children suffering of poverty: free education, food, health, parental support. Nothing, zero, zilch. And these millions are suffering right now, this second, with life-long physical and psychological traumas that will perpetuate this poverty spiral forever.

Thank you! This is a really important observation about anything controversial „child“ related. Be it abortion or abuse you can tell what people‘s real priorities are by looking at how much they are willing to spend on the welfare of kids outside their immediate point of concern. All of these types of problems are likely better solved in some other ways. Why not have general mental health coaching in schools freely a…

No rant at all, you make very good points. Thanks for sharing
Post reply on HN