Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

551–560 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#551
post #100

Earlier quoted context omitted.

That is to say face scanning is equally insidious as the new feature?

The technical risk to user privacy - if your threat model is a coerced Apple building surveillance features for nation state actors - is exactly the same between CSAM detection and Photos intelligence which sync results through iCloud. In fact, the latter is more generalizable, has no threshold protections, and so is likely worse.

Nonsense. Building an entire system as opposed to adding a single image to a database is a substantially different level of effort. In the US at least this was used successfully as a defense. The US cannot coerce companies build new things on their behalf because it would effectively create "forced speech" which is forbidden by the US Constitution. However they can be coerced if there is minimal effort like adding a single hash to a database.

Re: Apple's child protection features spark concern within its own ranks: sources

#552

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

To me the issue is that it makes no sense: if it's just scanning iCloud photos, ___why does this feature need to exist at all__? Apple is saying this: "we need to scan your phone because we need to look for this material, and by the way, we're only scanning things _we've been scanning for years already_" Basiclaly, everything else aside, in the current state of things, this feature makes no sense. They are not scanni…

> "we need to scan your phone because we need to look for this material, and by the way, we're only scanning things _we've been scanning for years already_"

As far as we know, Apple is not already using their decryption keys to decrypt images upload to iCloud and compare them with known images. That's according to this blog post that claims Apple make very few reports to the NCMEC:

https://www.hackerfactor.com/blog/index.php?/archives/929-On...

Re: Apple's child protection features spark concern within its own ranks: sources

#553

Earlier quoted context omitted.

> But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still possible to use an iPhone without iCloud and get full E2E. I disagree completely on this. For one, users aren't aware that using iCloud means that Apple has your decryption key and can thereby read and share all of your phone's data. And two, opt-out is a dark pattern.…

I dunno, when I read the choices in iTunes about backups, I didn’t feel particularly manipulated. It seemed straight forward. Trade offs were clear to me. I guess some people just see dark patterns where I don’t.

The least of the biases at play, here, is the change aversion bias.

Making things "opt-out", without even making it hard, dramatically increases the number of people who opt-in. It can be used for many reasons.

For example, the UK switched it’s organ donation laws from opt-in to opt-out.

Another example, my government has decided that them selling their citizen's personal information to garages, insurance companies, etc, when we buy cars, should also be opt-out.

So they freely sell the car make, acquisition date, buyer's name,… [1][2]

Unless it has changed with GDPR. I’ve never bought a car.

While we're on the topic of GDPR, that is exactly why it insists on making cookies, tracking, and the "sharing of information with partners" opt-in.

And that is without hiding what you’re doing, making it unclear or confusing, or requiring multiple actions to change it.

(Links in French, sorry)

[1]: https://mobile.interieur.gouv.fr/Repertoire-des-informations...

[2]: https://www.carte-grise.org/actus/2014/05-12-L-Etat-vends-le...

Re: Apple's child protection features spark concern within its own ranks: sources

#554
post #167

I just do not want Apple scanning my phone for the purpose of finding something they can send to the police. I’m not even talking about any “slippery slope” scenarios and I’ll never have any of the material they are looking for. And right or wrong, I don’t really fear a false identification, so this isn’t about a worry that they will actually turn me in. I just don’t want them scanning my phone for the purpose of tur…

I like this take. It shortcuts around all the "but people misunderstand the technology" back and forth and gets to the root of it. "Don't scan my phone for stuff you can send to the police."

Should we consider the phone:

- as part of the home?

- as part of the human body?

In either cases we’re allowed to do crime at home as long as no-one knows it.

Re: Apple's child protection features spark concern within its own ranks: sources

#555

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

Apple privacy focus was always opportunistic: they couldn't get a foothold into online advertising so they decided to make that weakness a selling point instead.

They'll ditch privacy in a second if they can sell you enough ads, just as they ditched privacy for Chinese customers when the Chinese government asked them to.

Re: Apple's child protection features spark concern within its own ranks: sources

#556

"The ark of the covenant is open and now all your faces are going to melt" - to paraphrase "The Thick of It". Prior to this when a government tapped Apple on the shoulder asking to scan for what they (the government) deem illicit material, Apple could have feasibly say "we cannot do this, the technology does not exist". Now the box is open, the technology does exist, publicly and on the record - Now we are but a nati…

So even if they go back on this the announcement served as strong signalling of capability.

Re: Apple's child protection features spark concern within its own ranks: sources

#557

Earlier quoted context omitted.

I like this take. It shortcuts around all the "but people misunderstand the technology" back and forth and gets to the root of it. "Don't scan my phone for stuff you can send to the police."

Should we consider the phone: - as part of the home? - as part of the human body? In either cases we’re allowed to do crime at home as long as no-one knows it.

I don’t think that’s how crime works

Re: Apple's child protection features spark concern within its own ranks: sources

#558

Earlier quoted context omitted.

Could they though? An authoritarian government could just as easily say "if you do not implement this feature, we will not allow you to operate in this country" and refuse to entertain legal challenges.

Apple is a fairly large company, that gives them some monetary leverage over governments. It's not as simple as you make it seem, I think.

China just hung it's biggest tech companies out to dry.

Do you really think they would care in the slightest about banning iPhone?

Or that Putin cares more about people not being able to buy what amounts to a luxury item, than being able to hunt down opposition supporters?

Re: Apple's child protection features spark concern within its own ranks: sources

#559

Earlier quoted context omitted.

I disagree, strongly. Let's say you're authoritarian government EvilGov. Before this announcement, if you went to Apple and said "we want you to push this spyware to your iPhones", Apple would and could have easily pushed back both in the court of public opinion and the court of law. Now though, Apple is already saying "We'll take this database of illegal image hashes provided by the government and use it to scan you…

Authoritarian governments have never needed preexisting technical gizmos in order to abuse their citizens. Look at what Russia and the Nazis did with no magic tech at all. Privacy stems from valuing human rights, not easily disproven lies about it being difficult to actually implement the spying.

> Look at what Russia and the Nazis did

Something strikes me as odd; Why do you say “Russia” but not “Germany”? Why not say “Soviets” or something similar?

Is it because Russia is still portrayed as the bogeyman in the Anglosphere whereas the Germans are cool now?

Re: Apple's child protection features spark concern within its own ranks: sources

#560
post #546

Earlier quoted context omitted.

Because the government doesn't just care about CSAM, they care about terrorism, drug and human trafficking, gangs etc. Scanning for CSAM won't change the government's opposition to E2EE, and Apple knows this because, according to their transparency reports, they respond with customers' data to NSL and FISA data requests about 60,000 times a year. Occam's razor also says they aren't playing 11th dimensional chess, and…

The point is that with this technology, Apple can now please both the government and Apple users that want their data in the cloud to be fully encrypted. First they enable this technology to prove to the government that they can still scan for bad stuff, then they enable true E2E. I don't know if this is really their motivation but it sounds plausible to me.

If they scan on device unencrypted and report what they found (even if it's child porn now, we know that is not going to last), they made the e2e effectivelly useless. The point of end to end enceyption is to make the data accessible to just one or two people - and that is not fulfilled here.

EDIT: though you are right - they can please governments by making encryption useless while lying to people they still have it. Not sure that was your message though.

Post reply on HN