Live data from Hacker News

One Bad Apple

hackerfactor.com

61–70 of 557 posts

Re: One Bad Apple

#61
post #18

There are a lot of articles about Apples hadh algorithm and for me they are mostly irrelevant to the main problem. The main problem is that Apple has backdoored my device. More types of bad images or other files will be scanned since now apple does not have plausible deniablity to defend any of ghe government’x requests. In the future a false? positive that happened? to be of a political file that crept in the list c…

They could have done all that without telling you. And as long as the traffic was combined with normal traffic no one would ever notice (and in this case it would end up mixed with normal traffic since it only applies to images being uploaded to iCloud, so communication with Apples servers would be expected).

What it looks like to me is that Apple is planning on releasing end-to-end encryption for iCloud. But they know that whenever E2EE comes up, people get mad that terrorists, child molesters, and mass shooters can hide their data and communications. Hell, they've been painted as the villain when they say they can't unlock iPhones for the FBI. This heads off those concerns for the most common out of those crimes.

Re: One Bad Apple

#62
There was parents arrested over bath time and playing in the yard sprinklers, photos being processed at photo mats, will the same thing happen by apple mistakenly reporting parents?

When I worked telecom, we had md5sum database to check for this type of content. If you emailed/sms/uploaded a file with the same md5sum, your account was flagged and sent to legal to confirm it.

Also if a police was involved, the account was burned to dvd in the datacenter, and only a police officer would touch the dvd, no engineer touched or saw the evidence. (Chain of Evidence maintained)

Prob changed since I haven't worked in telecom in 15 years, but one thing I've read for years, is the feds knew who these people are, where they hang out online, even ran the some of the honeypots. The problem is they leave these sites up to catch the ring leaders, the feds are aware, they have busts almost every month of rings of criminals. Twitter has had accounts reported, and they stay up for years.

I dont think finding the criminals are the problem, seems like every time this happens, theres been people of interest for years, just not enough law enforcement dedicated to investigating this.

All the defund the police, I think moving some police from traffic duty to Internet crimes would be more of an impact on actual cases being closed. Those crimes lead to racketeering and other organized crime anyways.

Re: One Bad Apple

#63

Earlier quoted context omitted.

> Apple can’t change their TOS Why not... has anyone actually successfully sued a company for changing their ToS from under them?

Doesn't every TOS include that clause about the customer automatically accepting any change the company makes to the TOS at any time and without notification?

German banks just fell on their face with this one. They tried to implement fee increases this way (often turning free into paid accounts), but the courts nixed this.

Unfortunately not fast enough, so some banks got away with the first year or two worth of loot due to statutes of limitations, but it's now clear that companies can't just change material parts of the ToS without explicit, active consent (it's not enough to notify customers and consider it agreement if they don't do anything).

Re: One Bad Apple

#64

Good article, however- "Due to how Apple handles cryptography (for your privacy), it is very hard (if not impossible) for them to access content in your iCloud account. Your content is encrypted in their cloud, and they don't have access. If Apple wants to crack down on CSAM, then they have to do it on your Apple device" I do not believe this is true. Maybe one day it will be true and Apple is planning for it, but ri…

They want to move to e2e for photos so they don't have to keep those keys. That's what this is part of — a way to prevent their service from being used for CSAM, yet still provide e2e encryption. I feel very ambivalent about this.

> They want to move to e2e for photos so they don't have to keep those keys.

That's my suspicion too, but has it actually been confirmed?

Re: One Bad Apple

#65
I think Apple may have really screwed the pooch with this move. They're going to catch hell for being able to take images from your device without warning or consent, and, they'll catch hell if they remove it.

Worse, they've also opened the door to government censorship of images and content and propped that door wide open.

Re: One Bad Apple

#66

To help fight back against false positives, why not just repeatedly trigger the code that sends the data to NCMEC (per the article's claimed legal requirements) and create a DoS attack?

That code is not accessible to us. The report to NCMEC would be generated by Apple after they have manually reviewed the derived images included in the security vouchers your device submitted after it analysed your photos.

Re: One Bad Apple

#67
post #2

This reads like a failure of the NCMEC, and the legal system surrounding it. It is insane that using perceptual hashes is likely illegal. As the hashes are actually somewhat reversible and so possession of the hash is a criminal offence. It just shows how twisted up in itself the law is in this area. One independent image analysis service should not be beating reporting rates of major service providers. And NCMEC sho…

> This reads like a failure of the NCMEC

Yes, it's a "failure" of a "private" Non(lol, technically, wink wink) Governmental Organization who works extremely closely with the FBI to put their camel-shaped nose under the very tent that the FBI happens to have been trying to breach for 20+ years.

Come on. It's beyond gullibility, at this point, to believe that NCMEC isn't an arm of the Feeb. Specifically, it's an arm that isn't required to comply with FOIA requests, which is particularly convenient.

Two years. At the current rate, you have approximately two years until the Feeb have full access to your iDevice. Though, I will admit, Apple's development of the SEP, their high-priced bug bounties, and their convincing play-acting at defying the FBI after the San Bernardino case definitely had me fooled.

We probably should have been more keen after they failed to close the bugs that GreyKey et. al. exploited.

But now we know. Everything they gave to China, they will give doubly so to their own corporate domicile.

Re: One Bad Apple

#68

Question: who is or will be making money on this deal? Answer that ("follow the money") and then I think we'll have a handle on what's really going on.

Apple gets to maintain its 30% commission and monopoly abuse of the app store (which is becoming the de-facto place where all consumer software downloads and payments occur), in return for feeding the iCloud data of all users worldwide to US intelligence agencies.

Presumably the quid pro quo outcome is that Apple is allowed to win the Epic vs Apple lawsuit.

Re: One Bad Apple

#69

Question: who is or will be making money on this deal? Answer that ("follow the money") and then I think we'll have a handle on what's really going on.

My guess: Apple is doing this to get regulators of its back while implementing end-to-end encryption.

Re: One Bad Apple

#70

Earlier quoted context omitted.

He wrongly interpreted CSAM scanning. He said that Apple will scan your photos and if finds something, it will send photo to Apple. Which is absolutely not how it works. Photo is only scanned before uploading to iCloud Photos. Apple already confirmed it to iMore and it’s clearly stated in Apple papers from press-release.

You're very clearly missing the forest for the trees. Right before uploading to icloud, "Apple will scan your photos and if finds something, it will send photo to Apple." This process is automated and turned on on most iPhones. Most iPhones will have automatic photo upload to icloud enabled, and that's when this scanning takes place.

"The problem with AI is that you don't know what attributes it finds important.... It determined that ... a guy with long hair is female."

Lots of people had this problem back in the 60s. Funny - except that some guys were jailed or worse because of it.

Post reply on HN