Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

581–590 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#581

Earlier quoted context omitted.

> but they needed to do something to address the CSAM issue lest governments come down on them hard. If Apple does not have decryption keys for iCloud content, they can't decrypt it, only the user can. For Apple, it's not technically feasible, and the law supports that. Apple has now demonstrated that it is technically feasible to overcome this challenge by doing things "pre-encryption" on the user's device. From a u…

> Apple has now demonstrated that it is technically feasible to overcome this challenge by doing things "pre-encryption" on the user's device. > From a legal stand point, they are now screwed, because now they _must_ do it. That's not the right takeaway. They're only required to turn over data to which they have access. If they continue writing software that makes it so they don't have access to the data, then they d…

Because Apple write the software, there will never be a time where they do not at some point have access to the data.

Re: Apple's child protection features spark concern within its own ranks: sources

#582

Earlier quoted context omitted.

I disagree, strongly. Let's say you're authoritarian government EvilGov. Before this announcement, if you went to Apple and said "we want you to push this spyware to your iPhones", Apple would and could have easily pushed back both in the court of public opinion and the court of law. Now though, Apple is already saying "We'll take this database of illegal image hashes provided by the government and use it to scan you…

> Apple is already saying "We'll take this database of illegal image hashes provided by the government and use it to scan your phone." This is incorrect. Apple has been saying—since 2019![0]—that they can scan for any potentially illegal content , not just images, not just CSAM, and not even strictly illegal. That's what should be opposed. CSAM is a red herring. [0] https://www.macobserver.com/analysis/apple-scans-up…

The difference is that's scanning in the cloud, on their servers, of things people choose to upload. It's not scanning on the user's private device, and currently they have no way to scan what's on a private device.

Re: Apple's child protection features spark concern within its own ranks: sources

#583
post #345

Earlier quoted context omitted.

I've looked through Apple's paper, what are you referring to?

So you know it’s not just a fingerprint. Did you notice the parts about the safety vouchers and the visual derivatives?

Yes, I did. You do realise that CSAM is just a policy control, and there is literally nothing technical from Apple adding non-CSAM content to the same policy and systems?

I feel like you may not have actually read the paper in depth. The paper clearly shows this is a generalised solution for detecting content that perceptually matches a database. The "what" is CSAM today, but nothing about the technicals require it to be CSAM.

To answer your specific response of safety voucher and visual derivative:

- The 'safety voucher' is an encrypted packet of information containing a part of the user's decryption keys, as well as a low resolution, grayscale version of the image (visual derivative). It is better described as "backdoor voucher".

- The 'visual derivative' is just the image but smaller and grayscale.

None of those two technologies have anything to do with CSAM. Apple's statement that they will only add CSAM to the database is a policy statement. Apple can literally change it overnight to detect copyrighted content, or Snowden documents, or whatever.

Re: Apple's child protection features spark concern within its own ranks: sources

#585
post #88

Earlier quoted context omitted.

They aren't being coaxed or coerced. If they were forced-- or even incentivized-- by the government to perform these searches than they'd be subject to the fourth amendment protecting against warrantless searches. Apple is engaging in this activity of their own free will for sake of their own commercial gain and are not being incentivized or coerced by the government in any way. As such, the warrantless search of the…

> Apple is engaging in this activity of their own free will for sake of their own commercial gain What's the commercial gain?

The commercial gain can be "don't break us up under antitrust law".

Apple is basically saying to governments: see our walled garden? The more you allow us to wall it, the more we can help you oppress your citizens.

Re: Apple's child protection features spark concern within its own ranks: sources

#586

Earlier quoted context omitted.

Could they though? An authoritarian government could just as easily say "if you do not implement this feature, we will not allow you to operate in this country" and refuse to entertain legal challenges.

Authoritarian countries are the least of the worries. There's a large class of illegal imagery that is policed in democratic countries: copyrighted media. We are only two steps away from having your phone rat you to the MPAA because you downloaded a movie and stored it on your phone. I can guarantee that some industry bigwigs are salivating at the prospect of this tech. Imagine youtube copyright strikes but local to…

One reason I haven't used itunes in years, and don't use iOS, is that I have a huge collection of mp3s. It's almost all of music which I bought and burned off CDs over decades, and it's become just stupidly difficult to organize your own mp3 collection via Apple's players. Even back in the ipod days, you could put your mp3s on an ipod but you needed piracy ware to rip them back off. I can easily see this leading to people like me getting piracy notices and having to explain that no, I bought this music, since we're now in a world where not that many people have their own unlocked music collection anymore.

Re: Apple's child protection features spark concern within its own ranks: sources

#588

Earlier quoted context omitted.

>As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone. Except for the "oops, due to an unexpected bug in our code, every image, document, and message on your device was being continuously scanned" mea culpa we will see a few months after this goes live.

Except for the "oops, due to an unexpected bug in our code, every image, document, and message on your device was being continuously scanned" mea culpa we will see a few months after this goes live. Only images that match the hashes of the database of CSAM held by the National Center for Missing and Exploited Children (NCMEC) that are uploaded to iCloud Photos are checked. Based on their technical documents, it's not…

>>> Only images that match the hashes of the database of CSAM held by the National Center for Missing and Exploited Children (NCMEC) that are uploaded to iCloud Photos are checked.

Incorrect. All files on the phone will be checked against a hash database before being uploaded to iCloud. Any time before, which means all the time, if you have iCloud enabled.

Re: Apple's child protection features spark concern within its own ranks: sources

#589
post #198

Earlier quoted context omitted.

This is the most honest take on this that I’ve seen. The slippery slope arguments don’t make sense, nor does the risk of false positives. But the idea of being suspected even in this abstract way, because of something other people do , is at the very least distasteful, bordering on offensive.

I agree with this take, but the slippery slope arguments do make sense, as exemplified by any spying technology ever. Once a capability exists, it's too enticing not to continue expanding the scope.

Exactly.

Selling dev consoles on ebay or drugs on the darkweb? We'll take the picture in the listing and find out who took it.

Can't find any matches? This is too ineffective. We'll need Apple to store all hashes on all devices for 6 months.

The slippery slope argument makes a LOT of sense.

Re: Apple's child protection features spark concern within its own ranks: sources

#590

Earlier quoted context omitted.

> Apple has now demonstrated that it is technically feasible to overcome this challenge by doing things "pre-encryption" on the user's device. > From a legal stand point, they are now screwed, because now they _must_ do it. That's not the right takeaway. They're only required to turn over data to which they have access. If they continue writing software that makes it so they don't have access to the data, then they d…

Because Apple write the software, there will never be a time where they do not at some point have access to the data.

Right, but there is a big difference between them having the software in place already to steal files off a phone for a government, versus a government telling them "you must deploy this new software." In the past Apple has said no to writing any new spyware for the government. They would not be able to say no very easily if the software is already on the devices.
Post reply on HN