Live data from Hacker News

The deceptive PR behind Apple’s “expanded protections for children”

piotr.is

61–70 of 595 posts

Re: The deceptive PR behind Apple’s “expanded protections for children”

#61
post #41

Earlier quoted context omitted.

For me it's the worst of both worlds - e2ee has no meaning if the ends are permanently compromised - and there's no local vs cloud separation anymore which you can use to delineate what is under your own control - nothing's under your control.

The end isn't really compromised with their described implementation. The only thing sent is the hash and signature and that's only if there are enough matches to pass some threshold. I don't really view that as 'permanently compromised' - at least not in any way more serious that Apple's current capabilities to compromise a device. I think e2ee still has meaning here - it'd prevent Apple from being able to see your…

> The end isn't really compromised with their described implementation.

They've turned your device into a dragnet for content the powers that be don't like. It could be anything. They're not telling you. And you're blindly trusting them to have your interests at heart, to never change their promise. You don't even know these people.

You seriously want to cuddle up with that?

Re: The deceptive PR behind Apple’s “expanded protections for children”

#62

I really don't see why the scanning would ever be done on the phone instead of on iCloud if it only affects iCloud images. But I do have guesses why.

This article speculates that that's because Apple is not scanning on iCloud to respect their privacy policy: https://www.hackerfactor.com/blog/index.php?/archives/929-On... Apple's report count to the NCMEC is really low so it's probably true that they are not scanning on iCloud unless they receive a warrant.

"In order to respect our privacy policy, we need to even more egregiously violate your privacy in a weird lawyer-y way"

Re: The deceptive PR behind Apple’s “expanded protections for children”

#63
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

Unlikely except if you send them to a iphone which is registered with a "child" account. Apple uses two different approaches: 1. Some way to try to detect _known_ child pornographic material, but it's fuzzy and there is no guarantee that it doesn't make mistakes like detecting a flower pot as child porn. But the chance that your photos get "miss detected" as _known_ child pornographic material shouldn't be too high.…

Even in the child account case it's not sent to Apple - it alerts parent accounts in the family. It's also just nudity generally, more akin to garden variety parental control content filtering.

The child account iMessage thing is really entirely separate from the CSAM related iCloud announcement. It's unfortunate people keep confusing them.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#64
post #17

Earlier quoted context omitted.

Except despite this being repeated over and over… Apple has not said anything about E2E

Apple almost never talks about features like that until they’re ready, so while you’re correct, it doesn’t mean much.

It's been leaked before that Apple folded under pressure from the FBI not to add iCloud encryption for images.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#65
post #26
post #17

Earlier quoted context omitted.

Except despite this being repeated over and over… Apple has not said anything about E2E

As I said, the design enables this, if Apple chose to do it. It remains to be seen if they will.

The design more plausible enables total device surveillance than questionable iCloud Backups. (I refuse to call a backdoored setup E2EE)

Re: The deceptive PR behind Apple’s “expanded protections for children”

#66

Any idea why Apple didn’t just implement server side scanning like everyone else?

Pessimistically: to allow them to (eventually) scan other content that you don't upload. I think pessimism about Apple's behavior is somewhat warranted at this point.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#67

Earlier quoted context omitted.

As covered in other articles, that is exactly what they were doing previously.

I'm not so sure. John Gruber's write-up said that Apple has only sent over a couple hundred reports in the last year to the gov't, compared to over 20 million from Facebook. This suggests to me that Apple's scanning wasn't nearly so widespread.

Because no one in their right mind uploads CP to a cloud service, and apparently pedos abuse Facebook’s easy sign up process to bulk upload CP.

Not that it matters when those Facebook sign ups are probably proxied with throwaway emails

Re: The deceptive PR behind Apple’s “expanded protections for children”

#68
post #41

Earlier quoted context omitted.

For me it's the worst of both worlds - e2ee has no meaning if the ends are permanently compromised - and there's no local vs cloud separation anymore which you can use to delineate what is under your own control - nothing's under your control.

The end isn't really compromised with their described implementation. The only thing sent is the hash and signature and that's only if there are enough matches to pass some threshold. I don't really view that as 'permanently compromised' - at least not in any way more serious that Apple's current capabilities to compromise a device. I think e2ee still has meaning here - it'd prevent Apple from being able to see your…

> The only thing sent is the hash and signature and that's if there are enough matches to pass some threshold.

Not true. If there are enough matches, someone at Apple will have a look at your pictures. Even if they are innocent.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#69
post #6
post #2

I have a newborn at home, and like every other parent, we take thousands of pictures and videos of our newest family member. We took pictures of the very first baby-bath. So now I have pictures of a naked baby on my phone. Does that mean that pictures of my newborn baby will be uploaded to Apple for further analysis, potentially stored for indefinite time, shared with law enforcement?

It's worth reading this, which is basically the only good reporting I've seen on this topic: https://daringfireball.net/2021/08/apple_child_safety_initia... There are legitimate things to be concerned about, but 99% of internet discussion on this topic is junk.

“If it works as designed” is I think where Gruber’s article does it’s best work: he explains that the design is pretty good, but the if is huge. The slippery slope with this is real, and even though Apple’s chief of privacy has basically said everything everyone is worried about is currently impossible, “currently” could change tomorrow if Apple’s bottom line is threatened.

I think their design is making some really smart trade offs, given the needle they are trying to thread. But it shouldn’t exist at all, in my opinion; it’s too juicy a target for authoritarian and supposedly democratic governments to find out how to squeeze Apple into using this for evil.

Re: The deceptive PR behind Apple’s “expanded protections for children”

#70
post #7

Earlier quoted context omitted.

If you don't choose upload to icloud, no upload to apple at all. If you do choose icloud upload (most do), they were being uploaded already and stored and may be available to law enforcement. If you do upload to icloud, NOW they will be screened for matches with "known" images in a database, and if you have more than a threshold number of hits, you may be reported. This will happen on device. Apple will also scan pho…

Arent the perceptual hashes based on a chunk of the image? I wonder what the false positive rates are for: - A random image against the DB of perceptual hashes - Images of a baby's skin against the DB of perceptual hashes It seems like the second would necessarily have a higher false positive rate: similar compositions (contains baby's skin) would more likely have similar chunks. Is it just a little higher or several…

According to

https://rentafounder.com/the-problem-with-perceptual-hashes/

the false-positive rate will be likely high. Given the billions of pictures going through this system there are going to be a lot of false accusations of child porn possession likely (and alone such an accusation can ruin lives).

HN discussion of that article from a few days ago:

https://news.ycombinator.com/item?id=28091750

Post reply on HN