Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

561–570 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#561
Those being outraged about this decision haven’t accepted yet that one can’t solve legal issues around encryption with technology - not even with open source.

The UK for example can throw people in prison if they don’t hand over their passwords/keys.

Admitting this however would by necessity lead to admitting that citizens of the US/EU have almost zero say in how their government legislate encryption. All these countries wanted to subvert encryption for decades already and they have all the time in the world, unlimited budgets and every other possible tool in their arsenal.

Re: Apple's child protection features spark concern within its own ranks: sources

#562

Earlier quoted context omitted.

Ok but now you’ve said that the precedent established by Google and others already moved the legislation to require terrible invasions of privacy far along. You started by saying Apple’s technology (and, in particular, its framing of the technology) has brought new legal risk. What I’m instead hearing is the risk would be present in a counter factual world where nothing was announced last week. At this point of the d…

The precedent established by Google et al is that it's okay to scan things that are physically in their data centers. It's far from ideal, but at least it's somewhat common sense in that if you give your data to strangers, they can do unsavory things with it. The precedent now established by Apple is that it's okay to scan things that are physically in possession of the user. Furthermore, they claim that they can do…

The precedent established by Apple, narrowly read, is it’s ok to scan data that the user is choosing to store in your data center. As you pointed out, this is at least partly a legal matter, and I’m sure their lawyers - the same ones who wrote their response in Apple vs. FBI I’d imagine - enumerated the scope or lack thereof.

Apple’s claim, further, is that this approach is more privacy-preserving than one which requires your cloud provider to run undisclosed algorithms on your plaintext photo library. They don’t say this is not “violating privacy,” nor would that be a well-defined claim without a lot of additional nuance.

Re: Apple's child protection features spark concern within its own ranks: sources

#564

Earlier quoted context omitted.

Could they though? An authoritarian government could just as easily say "if you do not implement this feature, we will not allow you to operate in this country" and refuse to entertain legal challenges.

Who wants to be the government who shuts down Apple? These are politicians we are talking about.

Those already doing far worse than banning a consumer electronics company's products?

And, in all honesty, there's a lot of those.

Re: Apple's child protection features spark concern within its own ranks: sources

#565

Earlier quoted context omitted.

Given that they obviously already have the capability to send software updates that add new on-device capability, this seems like a meaningless distinction. It’s already “just policy” preventing them from sending any conceivable software update to their phones.

I disagree, strongly. Let's say you're authoritarian government EvilGov. Before this announcement, if you went to Apple and said "we want you to push this spyware to your iPhones", Apple would and could have easily pushed back both in the court of public opinion and the court of law. Now though, Apple is already saying "We'll take this database of illegal image hashes provided by the government and use it to scan you…

> Apple is already saying "We'll take this database of illegal image hashes provided by the government and use it to scan your phone."

This is incorrect.

Apple has been saying—since 2019![0]—that they can scan for any potentially illegal content, not just images, not just CSAM, and not even strictly illegal.

That's what should be opposed. CSAM is a red herring.

[0] https://www.macobserver.com/analysis/apple-scans-uploaded-co...

Re: Apple's child protection features spark concern within its own ranks: sources

#566
post #198

Earlier quoted context omitted.

This is the most honest take on this that I’ve seen. The slippery slope arguments don’t make sense, nor does the risk of false positives. But the idea of being suspected even in this abstract way, because of something other people do , is at the very least distasteful, bordering on offensive.

I would not say the slippery slope take doesn't make sense. It is perfectly possible that had no one cried out about this change then the next change would have been: Large government to Apple: "Please now also create a hash on each photo metadata field including date/time and location. Let us query these. AND BTW, this change must be kept secret. Thanks."

> it is possible that had no-one cried about this change,

The “UK porn filter” has already been extended to all sorts of “« extremism online »” (to no effect in the capital of knife attacks, it seems — as usual invasive police rights do not equal a reduction of criminality) and it’s already being proposed to be extended to:

- Online Harms

- Online Safety Bill

https://en.wikipedia.org/wiki/Web_blocking_in_the_United_Kin...

Re: Apple's child protection features spark concern within its own ranks: sources

#567

Earlier quoted context omitted.

Could they though? An authoritarian government could just as easily say "if you do not implement this feature, we will not allow you to operate in this country" and refuse to entertain legal challenges.

Authoritarian countries are the least of the worries. There's a large class of illegal imagery that is policed in democratic countries: copyrighted media. We are only two steps away from having your phone rat you to the MPAA because you downloaded a movie and stored it on your phone. I can guarantee that some industry bigwigs are salivating at the prospect of this tech. Imagine youtube copyright strikes but local to…

> Authoritarian countries are the least of the worries.

That really depends. And is quite a strange, perhaps worrying, take.

Because, for many people, copyright strikes are the least of their problems.

Not that I disagree on it being an issue.

Re: Apple's child protection features spark concern within its own ranks: sources

#568
post #546

Earlier quoted context omitted.

Because the government doesn't just care about CSAM, they care about terrorism, drug and human trafficking, gangs etc. Scanning for CSAM won't change the government's opposition to E2EE, and Apple knows this because, according to their transparency reports, they respond with customers' data to NSL and FISA data requests about 60,000 times a year. Occam's razor also says they aren't playing 11th dimensional chess, and…

The point is that with this technology, Apple can now please both the government and Apple users that want their data in the cloud to be fully encrypted. First they enable this technology to prove to the government that they can still scan for bad stuff, then they enable true E2E. I don't know if this is really their motivation but it sounds plausible to me.

True E2E means the middle can't decrypt anything. You meant false E2E.

Re: Apple's child protection features spark concern within its own ranks: sources

#569

Earlier quoted context omitted.

The technical risk to user privacy - if your threat model is a coerced Apple building surveillance features for nation state actors - is exactly the same between CSAM detection and Photos intelligence which sync results through iCloud. In fact, the latter is more generalizable, has no threshold protections, and so is likely worse.

Nonsense. Building an entire system as opposed to adding a single image to a database is a substantially different level of effort. In the US at least this was used successfully as a defense. The US cannot coerce companies build new things on their behalf because it would effectively create "forced speech" which is forbidden by the US Constitution. However they can be coerced if there is minimal effort like adding a…

Photos intelligence already exists, and if people are really going to cite the legal arguments in Apple vs. FBI, then it’s important to remember the “forced speech” Apple argued it could not be compelled to make was changing a rate limit constant on passcode retries.
Post reply on HN