Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

601–610 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#601

Earlier quoted context omitted.

This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…

> But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still possible to use an iPhone without iCloud and get full E2E. I disagree completely on this. For one, users aren't aware that using iCloud means that Apple has your decryption key and can thereby read and share all of your phone's data. And two, opt-out is a dark pattern.…

As someone who frequently has to help older family members recover from lost passwords and broken phones, I sincerely hope they leave strong encryption of backups to be "opt out".

It's fine if you know you want to be the sole person in the world who can get to your data and have the discipline to store master passwords, and you accept Apple support cannot help you even if you have a purchase receipt for the device. But for the average older person that's not a good default.

Re: Apple's child protection features spark concern within its own ranks: sources

#602
post #576

Earlier quoted context omitted.

> 1. Your comment didn't add any information—it was just grandiose, inflammatory claims ("extreme mental gymnastics", "farce to begin with" and "blatantly obvious") "Extreme metal gymnastics" was the only inflammatory claim and it was the same language used by the person I was replying to. "Farce" has no more charitable a synonym [1] and "to begin with" does not make it any more or less inflammatory. "Blatantly obvio…

> Worst case I'm guilty of extreme snark. That's a really bad worst case, far below the line the guidelines draw. Would you mind reviewing them ( https://news.ycombinator.com/newsguidelines.html ) and taking the intended spirit of the site more to heart? We want thoughtful, curious conversation here, not snark and fulmination. > People get defensive sometimes, so what? The problem is that it evokes worse from others…

> That's a really bad worst case, far below the line the guidelines draw. Would you mind reviewing them (https://news.ycombinator.com/newsguidelines.html) and taking the intended spirit of the site more to heart? We want thoughtful, curious conversation here, not snark and fulmination.

Please give me the benefit of the doubt that after a decade on HN I have read the guidelines many times and reply to the meat of my comment instead of the knee-jerk rhetoric (aka joke) at the end.

*> The problem is that it evokes worse from others and leads to a degenerative spiral, ultimately to flamewars, and in the long run to the site burning itself to a crisp.

IMO it demonstrably didn't.

Re: Apple's child protection features spark concern within its own ranks: sources

#603

"The ark of the covenant is open and now all your faces are going to melt" - to paraphrase "The Thick of It". Prior to this when a government tapped Apple on the shoulder asking to scan for what they (the government) deem illicit material, Apple could have feasibly say "we cannot do this, the technology does not exist". Now the box is open, the technology does exist, publicly and on the record - Now we are but a nati…

> CSAM is beyond abhorrent, morally reprehensible and absolutely should be stopped. This is not in question. Agreed. And the same holds for this subversion of user control of devices. It too is beyond abhorrent and morally reprehensible.

I agree with you, however they are different kinds of reprehensible, I don’t believe they are equivalent.

One stokes an intimate and personal fear or revulsion, something that any parent or anyone with empathy will feel.

The second allows for quiet enforcement of the subversion of the relationship the state has with it’s citizens.

Both are awful, but in their own incomparable way.

Re: Apple's child protection features spark concern within its own ranks: sources

#605

Earlier quoted context omitted.

> Apple is already saying "We'll take this database of illegal image hashes provided by the government and use it to scan your phone." This is incorrect. Apple has been saying—since 2019![0]—that they can scan for any potentially illegal content , not just images, not just CSAM, and not even strictly illegal. That's what should be opposed. CSAM is a red herring. [0] https://www.macobserver.com/analysis/apple-scans-up…

The difference is that's scanning in the cloud, on their servers, of things people choose to upload. It's not scanning on the user's private device, and currently they have no way to scan what's on a private device.

The phrase is “pre-screening” of uploaded content, which is what is happening. I'm pretty sure this change in ToS was made to enable this CSAM feature.

Re: Apple's child protection features spark concern within its own ranks: sources

#606
post #358
post #343

Earlier quoted context omitted.

This is false information, the scanning system is highly generalized to finding any type of photo via fuzzy matched perceptual hashes. It can target a pride flag just as easily as CP.

No, what you have said is bullshit. The perceptual hashes are not generalized. They do not match ‘child porn’ or ‘pride flag’. They match specific photos from a database. You might argue that that database could contain a specific photo of a pride flag. You would be right, but there are safeguards against that. The system will not trigger with just one match. A set of multiple images must match. So no, the system won…

"(...) but there are safeguards against that."

Hah! Nice one :D

Re: Apple's child protection features spark concern within its own ranks: sources

#607

Good. I would be furious if I worked there. After the San Bernardino case, I viewed them as the paragon of privacy and security, to the extent I ignored most criticisms, including their lack of support for right-to-repair and concerns over App Store rejections. All of that is back on the table for me after this decision. It is out-of-step with everything they've been doing up to this point, and it makes me wonder who…

What's fishy to me is the fact that they are letting this be known. Like, if you're trying to capture people who share CSAM or have it on their phone, why would you go around saying that you can now scan for it? I think this announcement would have been well known to cause a major outrage so why say anything? I'm wondering if this is a cover up for something else. Get people talking about this in the news and getting…

Also, I think it would have been a matter of time before some researcher analyzing network traffic would have discovered something.

Re: Apple's child protection features spark concern within its own ranks: sources

#608

Earlier quoted context omitted.

> But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still possible to use an iPhone without iCloud and get full E2E. I disagree completely on this. For one, users aren't aware that using iCloud means that Apple has your decryption key and can thereby read and share all of your phone's data. And two, opt-out is a dark pattern.…

As someone who frequently has to help older family members recover from lost passwords and broken phones, I sincerely hope they leave strong encryption of backups to be "opt out". It's fine if you know you want to be the sole person in the world who can get to your data and have the discipline to store master passwords, and you accept Apple support cannot help you even if you have a purchase receipt for the device. B…

> help older family members recover from lost passwords and broken phones,

Apple just needs to design good UX to help these people.

Perhaps a large cardboard 'key' comes with every phone. When first setting up the phone, you scan a QR code on it to encrypt your data with the key, and then you tell the owner that of they ever lose the key to their phone, they won't be able to get in again.

People understand that - it's like losing the only key to a safe.

From time to time you require them to rescan the key to verify they haven't lost it, and if they have, let them generate a new one.

Re: Apple's child protection features spark concern within its own ranks: sources

#609

Earlier quoted context omitted.

>As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone. Except for the "oops, due to an unexpected bug in our code, every image, document, and message on your device was being continuously scanned" mea culpa we will see a few months after this goes live.

Apple can’t even keep settings values correctly. After they introduced AirTags I went and disabled item detection on all my devices. Yesterday I went into settings and guess what, that feature is enabled again. On all my devices! I’m not sure when that happened, but my guess would be that latest iOS update caused that… My point is, you will only have things working to the extent you have testing for, and test coverag…

Just like the facebook and it's Messenger application "forget" that you had your in-app sounds turned off and turns it off now and then.

Re: Apple's child protection features spark concern within its own ranks: sources

#610
post #167

I just do not want Apple scanning my phone for the purpose of finding something they can send to the police. I’m not even talking about any “slippery slope” scenarios and I’ll never have any of the material they are looking for. And right or wrong, I don’t really fear a false identification, so this isn’t about a worry that they will actually turn me in. I just don’t want them scanning my phone for the purpose of tur…

Not to mention how this kind of stuff can be abused. Think about the digital version of the cop that drops a small bag containing a white powder in the back of your car. Good luck proving that it wasn't you.
Post reply on HN