Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

551–560 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#551

Earlier quoted context omitted.

>touting itself as a privacy-centric alternative There is a difference between selling your data to the highest bidder through a stalker capitalism ecosystem and giving governments carte blanche access. I am not at all advocating for the latter, but if you are fighting that battle, CP is not the hill to die on.

This is why it's a problem - this is the most defensible usecase for it, and any upscaling later will just get seen as a natural progression.

My point was that battle was already lost a long time ago when terrorism was the use case.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#552
post #460

Earlier quoted context omitted.

Yes. “We must do something , “It’s for the children” , “Even if it saves just one person” . No one has ever used this triple fallacy before. How big do you really think the market is on kiddie porn that there are people storing it plainly on their iPhones and are “safe” because they aren’t uploading it to iCloud? This is bullshit through and through. The best case is this is the step Apple needs to get E2E iCloud sto…

Your position is to simply deny that child porn or predation is a serious problem. I outlined that this was one of the sides in the debate - I.e. you take position 2, and have no empathy for position 1. The problem is that this is a political trap. You can’t win position 2 by painting technologists as uncaring or dismissive. ‘Think of the children’ works for a reason.

> ‘Think of the children’ works for a reason.

"Think of the children" will always work, no matter what the context is, no matter what the stats are, and no matter what we do. That does not mean that we should not care about the children, and it does not mean that we shouldn't care about blocking CSAM. We should care about these issues purely because we care about protecting children. If there are ways for us to reduce the problem without breaking infrastructure or taking away freedoms, we should take those steps. Similarly, we should also think about the children by protecting them from having their sexual/gender identities outed against their wishes, and by guaranteeing they grow up in a society that values privacy and freedom where they don't need to constantly feel like they're being watched.

But while those moral concerns remain, the evergreen effectiveness of "think of the children" also means that compromising on this issue is not a political strategy. It's nothing, it will not ease up on any pressure on technologists, it will change nothing about the political debates that are currently happening. Because it hasn't: we've been having the same debates about encryption since encryption was invented, and I would challenge you to point at any advancement or compromise from encryption advocates as having lessened those debates or having appeased encryption critics.

Your mistake here is assuming that anything that technologists can build will ever change those people's minds or make them ease up on calls to ban encryption. It won't.

Reducing the real-world occurrences for irrational fears doesn't make those fears go away. If we reduce shark attacks on a beach by 90%, that won't make people with a phobia less frightened at the beach, because their fear is not based on real risk analysis or statistics or practical tradeoffs. Their fear is real, but it's also irrational. They're scared because they see the deep ocean and because Jaws traumatized them, and you can't fix that irrational fear by validating it.

So in the real world we know that the majority of child abuse comes from people that children already know. We know the risks of outing minors to parents if they're on an LGBTQ+ spectrum. We know the broader privacy risks. We know that abusers (particularly close abusers) often try to hijack systems to monitor and spy on their victims. We would also in general like to see more stats about how serious the problem of CSAM actually is, and we'd like to know whether or not our existing tools are being used effectively so we can balance the potential benefits and risks of each proposal against each other.

If somebody's not willing to engage with those points, then what makes you think that compromising on any other front will change what's going on in their head? You're saying it yourself, these people aren't motivated by statistics about abuse, they're frightened of the idea of abuse. They have an image in their head of predators using encryption, and that image is never going to go away no matter what the real-world stats do and no matter what solutions we propose.

The central fear that encryption critics have is a fear of private communication. How can technologists compromise to address that fear? It doesn't matter what solutions we come up with or what the rate of CSAM drops to, those people are still going to be scared of the idea of privacy itself.

Nobody in any political sphere has ever responded to "think of the children" with "we already thought of them enough." So the idea that compromising now will change anything about how that line is used in the future -- it just seems naive to me. Really, the problem here can't be solved by either technology or policy. It's cultural. As long as people are frightened of the idea of privacy and encryption, the problem will remain.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#553
post #542
post #538

Earlier quoted context omitted.

You must be trolling...Provoking...Joking...Or you are Tim Cook :-) Are the personal ethics and values disconnected from daily business, to be changed based on the place of business or Apple must do it because they are just complying with local laws in China ? Because IBM was also in 1939...Just the local laws. https://en.wikipedia.org/wiki/IBM_and_the_Holocaust

So this is just about China? When Apple started working in China, the prevailing western belief was that economic liberalization would cause political liberalization in China, so even though China was still relatively repressive, doing business there would help move things in a better direction. At the time, this was a very reasonable and widespread belief, which turned out to be wrong. Betting on other people and tu…

Naive is not something I would associate with Apple, but I guess they have seen it now. I guess they must be ready to pull off any time...Or is their CEO too busy, lecturing others on the righteous paths in other jurisdictions?

"Apple's Good Intentions Often Stop at China's Borders"

https://www.wired.com/story/apple-china-censorship-apps-flag...

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#554
post #236

Earlier quoted context omitted.

> If I similarly draw other crimes being committed, the same does not apply. Why is that? The answer is much more simple than you seem to think it is. Because the law doesn't say it is. I can only go by the law in my country, which is that (loosely translated) 'ownership of any image of someone looking like a minor in a sexually suggestive position' is a crime. Since a drawing is an image, it's a crime. Having an ima…

It is a pretty dumb law IMHO for the mere fact that two teenagers sexting on snapchat when they are 17 years and 355 days old are committing a fairly serious crime that can completely mess up their lives if caught but doing that the next day is totally ok all of a sudden and they can talk and laugh about it.

> but doing that the next day is totally ok all of a sudden and they can talk and laugh about it.

Unless a leap year is positioned unfortunately (probability ~1/4), in which case it's back to being a serious crime.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#555
post #391
post #387

Earlier quoted context omitted.

Pretty sure I read this would only apply to US based users

Yes so far. Once the mechanism is in place it will be rolled out. I'm in the UK and we have a fairly nasty set of state legislation on censorship already and an increasingly authoritarian government so this is a big worry.

Absolutely agree, this will no doubt reach Apple devices worldwide, just a matter of time.

But there is still time for Apple to halt these changes.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#556
post #525
post #441

Earlier quoted context omitted.

> So the M1 has turned me off of Apple products because, quite frankly, I don't want to spend (more) of my time fixing shit a trillion dollar company broke and doesn't care to fix. What is broken about the M1?

M1 Macs are basically iPads, with the same iOS-style locked-down boot process. They even have the same DFU mode as iOS devices. In my case "my" M1 bricked itself, because Apple servers have refused to permit changes to NVRAM in the machine, and it can't boot a reinstalled OS without Apple's approval.

No, M1 isn't locked down at all. You can disable secure boot and there are efforts to port Linux to it. You can block *.apple.com and everything will still work.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#557
post #528

Earlier quoted context omitted.

No, it doesn't. You have conflated two entirely different systems.

What would the two different systems be then? I am certainly willing to agree I conflated them if you clarify.

One system optionally checks iMessages (to be sent or received) against one or more "nudity" neural networks if the user is identified as a child in the iCloud family sharing group. If it triggered, the child is given information/opt out, optionally choosing to go ahead with sending or viewing, with the caveat that their parent(s) will be notified (optionally, I presume). Nothing about this event is sent off device. Apple employees aren't receiving or evaluating the photos. No one other than the identified parent(s) is party to this happening.

Neural networks are from perfect, and invariably parents and child are going to have a laugh when it triggers on a picture of random things.

The other, completely separate system checks files stored in iCloud photos against a hash list of known, identified child abuse photos. This is already in place on all major cloud photo sites.

Apple clearly wanted to roll out the first one but likely felt they needed more oomph in the child safety push so they made a big deal about expanding the second system to include on-device image hash functionality. I would not be surprised at all if they back down from the latter (though 100% of that functionality will still happen on the servers).

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#558

US Government: We suspect the person in this photo of committing a crime. Here is your subpoena, Apple. You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them. Chinese Government: Here is the NeuralHash for Tienanmen square. Delete all photos you find matching this or we will bar you from China. Apple has at this point already admitted thi…

> You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them. I think the US Govt (and foreign) would actually send Apple tens of thousands of NeuralHashes a week. Why would they limit themselves? False positives are "free" to them.

> False positives are "free" to them.

Correct, just look at the incentives when it comes to handling sniffer dogs.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#559
post #391

Earlier quoted context omitted.

Yes so far. Once the mechanism is in place it will be rolled out. I'm in the UK and we have a fairly nasty set of state legislation on censorship already and an increasingly authoritarian government so this is a big worry.

Absolutely agree, this will no doubt reach Apple devices worldwide, just a matter of time. But there is still time for Apple to halt these changes.

Well it’s now common knowledge that they can and will do this. So oppressive governments will almost certainly mandate that its required to do business in those countries. Thus it’s a no win game for the end user. Unless you choose not to play.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#560
post #525

Earlier quoted context omitted.

M1 Macs are basically iPads, with the same iOS-style locked-down boot process. They even have the same DFU mode as iOS devices. In my case "my" M1 bricked itself, because Apple servers have refused to permit changes to NVRAM in the machine, and it can't boot a reinstalled OS without Apple's approval.

No, M1 isn't locked down at all. You can disable secure boot and there are efforts to port Linux to it. You can block *.apple.com and everything will still work.

Puppies aren't messy at all. You can shave all their hair off and there are efforts to deal with the slobbering. You can put a diaper on the back end of it and everything will still work.
Post reply on HN