Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

551–560 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#551

Earlier quoted context omitted.

Apple previously stored photo backups in their cloud in cleartext. The door was always open. At some point if you are providing your personal images for Apple to store, you have to exercise a modicum of trust in the company. If you don't trust Apple, I suggest you don't use an iPhone.

Apple never had the technology to do offline scans of stuff directly on your phone. Now they have it. How long will it take, until some three/four letter agency makes them scan other stuff too, since they clearly have the tech to do so, and it's just one "if()" removed, to check eg. who was the first person with wikileaked photos.

Tiananmen square tank man.

The CCP already gets Apple to censor the Taiwanese flag emoji and store all Chinese iCloud user data on CCP-accessible servers in China.

We know Apple presently actively and eagerly cooperates with CCP censors to be permitted to operate and sell in China.

This is tailor-made for CCP abuse.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#552
post #115

I really don't get all the hype. This is not a backdoor as it's called in TFA. It's not Apple "reaching into your device". It is literally checking for specific images and reporting their presence to Apply if found. It's not using AI to analyze your photos or anything like that. It's looking for specific images, and only prior to uploading them to iCloud. It won't even flag your own nasty images because the hash won'…

I agree with you, but I want to correct you - they are using an image analysis hash, not a cryptographic hash. However it doesn’t change the logic of your argument. They require multiple positive marches, and they also require a visual derivative of the CSAM images to match.

>> they are using an image analysis hash, not a cryptographic hash. However it doesn’t change the logic of your argument.

Yes, I think it fundamentally changes it. A crypto hash would be looking for specific known CSAM images. Image analysis is error-prone and will lead to problems and false positives. I don't care how good it is, that's actually looking at the users images and making a judgement.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#553

Earlier quoted context omitted.

It’s good to know that if I use the “section” glyph in an otherwise completely false analysis born of extending my experience past where I’m competent, readers will quickly repeat whatever it is I said as factual and “quite irrefutable”. The power of one blog post is quite something. You’re the third person I’ve seen quote that very post and go “welp, sure is a smoking gun” despite it being completely, utterly, demon…

Thanks for coming on here. You WILL be downvoted. I'm a parent, it's also crazy to me how THIS of all things is where folks are going crazy over privacy. Literally, they will build something to track your every mouse move, scan every photo, log and sell all your browsing history and TV watching history (including big ISPs and mfgs). And this is the thing folks get outraged about? Apple can already scan your stuff on…

> I'm a parent [...] > Apple can already scan your stuff on their servers (and should!).

It's crazy to me how you fail to see that instead of everyone playing cyber cowboys and child predator indians the focus for preventing child abuse should be in real life. Criminalizing content does absolutely nothing for those kids who are abused by someone close to them. And unfortunately the vast majority (~75%) of cases happen like that.

If the stats are even remotely right it's unfathomable how bad prevention and deterrence is. (Over the course of their lifetime, 28% of U.S. youth ages 14 to 17 had been sexually victimized -- https://victimsofcrime.org/child-sexual-abuse-statistics/ )

This shows how bad our aggregated priorities are. War on X so far only made X worse. ¯\_(ツ)_/¯

Re: The deceptive PR behind Apple’s “expanded protections for children”

#554

Earlier quoted context omitted.

They compare the encrypted forms of the hashes, the first step on the device and the second on the server.

How does one compare encrypted forms of hashes?

You hash images in the same way, then encrypt the hashes in the same way, and see if the results match.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#555

Earlier quoted context omitted.

The privacy violation here is smaller than the one we all used to have to go through to get photos developed at all.

Exactly why people avoided taking naughty pictures with film. Digital, on the other hand, is private. And should remain so.

According to an article I read this morning in the WSJ, you would have to upload about 30 matching images to iCloud, at which point it would be flagged for review, and even then only the flagged images would be shown to the reviewer. This strikes me as not a serious privacy risk.

Article here: https://apple.news/AhVzAY--DT36Oz22W7taL9Q

Re: The deceptive PR behind Apple’s “expanded protections for children”

#557

Earlier quoted context omitted.

I largely agree with your point fossuser. I am also in favour of E2E by default for everything without any device or cloud based scanning. However, Apple doesn't want to be caught in having developed a service that enables for child exploitation. Doing nothing may have even more invasive requirements legally forced by government, so Apple is stuck with a dilemma. Also lets not forget that Apple should also not want c…

They can rely on users reporting it. They are not obligated by law to do this.

For now, but if they don’t do something like this laws can change and that change could make things a lot worse for privacy than this implementation.

I suspect they’re trying to get ahead of that and solve this in the most privacy protecting way possible.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#558

Earlier quoted context omitted.

I recently saw a review of the "Volla Phone" which is running Ubuntu Touch. Seemed much better than the Pinephone but still has issues: https://youtu.be/neG2Z21epLI

> Seemed much better than the Pinephone Just curious, how is it better than the Pinephone?

I am mostly going by what I saw in the review. I saw the review of pinephone on Linus’ channel where it seemed very slow. The review of volla phone seemed much better. Maybe I am wrong though as I haven’t owned either.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#559
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Lots of people responding to this seem to not understand how perceptual hashing / PhotoDNA works. It's true that they're not cryptographic hashes, but the false positive rate is vanishingly small. Apple claims it's 1 in a trillion [1], but suppose that you don't believe them. Google and Facebook and Microsoft are all using PhotoDNA (or equivalent perceptual hashing schemes) right now. Have you heard of some massive i…

Thank you for the paper.

>"...report iCloud users who store known Child Sexual Abuse Material (CSAM) in their iCloud Photos accounts."

OK. They're not trying to tag and bag your images for 'abuse content'.

If you collect your child abuse porn on iCloud, we're going to report you?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#560

Earlier quoted context omitted.

You completely bypassed the point of my post. It doesn't matter about what happens now. What matters is in the future. If China creates a law saying that not only should this system work for CSAM but also for objectionable material or anti-government material, is Apple really going to say no if it means billions of dollars in losses and Apple execs being targets by the CCP? Of course they won't.

If you think it's Apple's (or Google's, or Microsoft's) role to act as the international human rights arm of the US State Department, then I have some bad news for you. China can do whatever China wants. If China wanted Apple to scan the iPhones of Chinese residents for pictures of Winnie The Pooh, they could have done that last year. They pass a law, Apple must comply or leave. They don't have a choice. Of course I…

One explanation for this CSAM thing is to muddy the water about content scanning using an unassailable goal so that apple can give the Chinese and Saudi governments what they want and not get the same degree of criticism.
Post reply on HN