Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

571–580 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#571
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

Great, so what's the solution? What are you doing to fix it? Do you roll your own silicon? Do you grow your own food (we have no idea what someone could be putting in it)? Are you completely off-grid? Or are you as completely dependent on society writ large as everyone else? Making holier than thou comments about everyone else being sheep isn't helpful or thought provoking. Offer an alternative if it is a bad one (lo…

The solution won't be technological, it will be in realm of laws and regulations. We are weak peasants and don't have any power over big tech, but we can change legal environment for them.

IANAL but we (via our elected representatives) can push a law that prohibit restrictions on execution of users' code on their own devices. Or we can split app stores from vendors and obligate them to provide access to third-party stores, like we do with IE and windows.

Also, it's completely doable to stop NSA/Prism totalitarian nonsense.

What we can do as tech people?

- raise awareness

- help people to switch from big tech vendor locks

- help people harming BT by installing adblockers, pihole etc

- participate in opensource (with donations or work)

- probably something else

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#574

Earlier quoted context omitted.

Great, so what's the solution? What are you doing to fix it? Do you roll your own silicon? Do you grow your own food (we have no idea what someone could be putting in it)? Are you completely off-grid? Or are you as completely dependent on society writ large as everyone else? Making holier than thou comments about everyone else being sheep isn't helpful or thought provoking. Offer an alternative if it is a bad one (lo…

The solution is to go back to the original spirit of the Internet, when it was a set of open standards connecting people and organizations. Somehow it got forgotten and now we have a bunch of commercial companies giving you the same stuff in exchange for your privacy and who increasingly control everything you do.

It's when we substituted corporate mobile transmission for the "internet".

It became, "Sorry, AT&T carrier, AT&T rules."

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#575
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

Great, so what's the solution? What are you doing to fix it? Do you roll your own silicon? Do you grow your own food (we have no idea what someone could be putting in it)? Are you completely off-grid? Or are you as completely dependent on society writ large as everyone else? Making holier than thou comments about everyone else being sheep isn't helpful or thought provoking. Offer an alternative if it is a bad one (lo…

Dumping Facebook and its products as I and others have done is one strong step forward but people can't even manage this. It's deeply disappointing. Techno bears its seeds in rebellion but everybody throwing techno parties is coordinating on what is essentially an Orwellian state. Punks too, they're cozied up to this framework of oppression and can't see it for what it is.

I think people have a hard time seeing the ethics in the technology they choose to use. Maybe the next wave of net-natives will be able to rediscover that common thread of rebellion and resist. It's insidious, I'll give you that. It's not obvious what is being surrendered with every participation on these platforms but it doesn't take a genius to see clearly.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#576
post #221

Dear humans, 1) You willingly delegated the decision of what code is allowed to run on your devices to the manufacturer (2009). Smart voices warned you of today's present even then. 2) You willingly got yourself irrevocably vendor-locked by participating in their closed social networks, so that it's almost impossible to leave (2006). 3) You willingly switched over essentially all human communication to said social ne…

Great, so what's the solution? What are you doing to fix it? Do you roll your own silicon? Do you grow your own food (we have no idea what someone could be putting in it)? Are you completely off-grid? Or are you as completely dependent on society writ large as everyone else? Making holier than thou comments about everyone else being sheep isn't helpful or thought provoking. Offer an alternative if it is a bad one (lo…

I bought a pinephone recently, that's one fairly simple way to prevent corporations from scanning your life.

Pretty cheap, too.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#577
post #271
post #13

Earlier quoted context omitted.

It's still really, really bad. It always starts with child porn, and in a few years the offline Notes app will be phoning home if you write speech criticising the government in China. This technology inevitably leads to the sueveillance, suppression and murder of activists and journalists. It always starts with protecting the kids or terrorism. Perceptual hashes like what Apple is using are already used in WeChat to…

> in a few years the offline Notes app will be phoning home if you write speech criticising the government in China. A totalitarian autocracy like China does not need this technology to search for wrongspeech, sadly. You are of course aware that all Chinese iCloud users get their data stored in a special set of datacenters that Apple actually doesn't control.

This seems to be done voluntarily by NVIDIA, at least partially. While in Seattle I set up geo-blocking on my LAN as an experiment. Later when I tried to create an NVIDIA account I couldn't because it was attempting to store my PII at nvidia.cn. When I changed the url to nvidia.com everything worked just fine. I've always wondered what non-evil reasons one could use to explain that choice by NVIDIA. Ping was at least 2x longer to .cn.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#578

Earlier quoted context omitted.

Have you ever had the impression that special interests are much more interested in copyright violations than child pornography? Or that it might extend to memes that sabotages carefully crafted propaganda? I do have that impression a lot. I don't step in the lowest parts of the internet hell, but I am also not very picky about it. I have never encountered child pornography in 10 years of almost pathological internet…

Scanning for DRM violations was one of the use cases mentioned in the article linked above.

I didn't know what CSAM stood for so I first though this would be the reaction to the security issues iPhones faced. Oh, silly me.

Additionally, by calculating hashes of media on peoples devices, you can quickly determine networks. A private image you shared with your friends? Unique hash and everyone that has it is probably in your network. That is aside from the issue that they would also just read your contacts.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#579

Earlier quoted context omitted.

A lot of folks here need to go into a city. People WILL be a fan of all of this if the alternative is lots of robbery / car theft etc etc. We see this globally. If the state is not offering security now - they will accept incredible craziness for security. One note - in most cases folks trust Apple MORE than they would for example the Trump administration. Food for thought.

I live in a major city and I’m a fan of none of these things. I’m only one data point, but yours is a sweeping and inaccurate generalization that “cities are frighteningly unsafe”. Maybe one trusts Apple more than , but they cannot so easily elect away Apple.

Apple has generally locked things down successfully.

There was concern about phone's being grabbed - street robberies. Regardless of whether you believe their were sweeping generalizations - apple ended up creating more power for themselves with their activation lock system. If they don't want to let you sell your phone to someone - they can block use of your phone. But folks trust them to operate the system reasonably, and so far so good there.

They have locked down their app store very tightly for a variety of reasons including supposedly for security. Users have accepted that.

Apple's competitors (google photos etc) generally are directly scannable in the cloud by google et al. Facebook and others routinely scan users photos. Youtube scans their videos etc. My guess is apple will explain why they are doing it and users are going to be happy.

And yes, users are linking things like ring doorbells and home security video cameras together or registering them so that the police state can use them.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#580
post #228

Earlier quoted context omitted.

> While the difference between innocent images and something explicit easy for a human to identify, I’m not sure I’d trust AI to understand that nuance. In this case it’s not AI that’s understanding the nuance, it’s authorities that identify the exact pictures they want to track and then this tool lets them identify what phones/accounts have that photo (or presumably took it). If ‘AI’ is used here it is to detect if…

Is there some way of verifying that the fingerprints in this database will never match sensitive documents on their way from a whistleblower to journalists, or anything else that isn't strictly illegal? How will this tech be repurposed over time once it's in place?

You seem to be suggesting that the AI will go directly from scanning your photos for incriminating fingerprints to reporting you to journalists.

I have to assume humans are involved at some point before journalists are notified. The false-positive will be cleared up and no reputations sullied (except perhaps the reputation of using AI to scan for digital fingerprints).

Post reply on HN