Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

611–620 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#611
post #486

Earlier quoted context omitted.

How do the slippery slope arguments not make sense? This is a capability that: 1. Did not exist prior (scanning stuff on the endpoint) 2. Has a plausible abuse case (the same system, applied to stuff that isn't CSAM) I find this very compelling, especially in the shittier regimes (China...) that Apple operates in.

Neither 1 nor 2 are in fact true. Spotlight indexes all kinds of metadata, as does photos search. Adding an agent to upload data from these is easier than extending the CSAM mechanism, and the CSAM mechanism as is is not all that plausible to abuse either technically or socially given how clear Apple’s promises are.

> the CSAM mechanism as is is not all that plausible to abuse either technically or socially given how clear Apple’s promises are.

That’s the problem: Apples promise means nothing exactly because it’s so easy to abuse.

Apple says they will refuse when asked to scan for anything that is not CSAM. That’s one of those nice ‘technically true’ statements lawyers like to include.

Apple will not have to refuse anything, because they won’t be asked.

Apple doesn’t get a huge pile of CSAM images (obviously), they get a list of hashes from a 3rd party. They have no way of ensuring that these hashes are only for CSAM content. And when ‘manually’ checking, they aren’t actually looking at potential CSAM, they are checking the ‘visual derivative’ (whatever that means exactly), basically a manual check if the hashes match.

So yes, they would technically refuse if asked to scan for other material, but they will just accept any list of hashes provided to them by NCMEC (an organization created by the US government and funded by the US DoJ) no questions asked. The US government could include any hash they wish into this list without Apple ever noticing.

Re: Apple's child protection features spark concern within its own ranks: sources

#612
post #167

I just do not want Apple scanning my phone for the purpose of finding something they can send to the police. I’m not even talking about any “slippery slope” scenarios and I’ll never have any of the material they are looking for. And right or wrong, I don’t really fear a false identification, so this isn’t about a worry that they will actually turn me in. I just don’t want them scanning my phone for the purpose of tur…

This is exactly how I feel to a T. It's intangible to explained but I'm not a criminal and I'm not on probation. Apple as zero business scanning my phone for anything and I don't want that to be done.

Re: Apple's child protection features spark concern within its own ranks: sources

#613

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

Adding to the confusion, they announced both the AI powered parental control feature for iMessage and hash-based scanning of iCloud pictures.

The iMessage thing is actual spyware, by design, it is a way for parents to spy on their children, which is fine as long as it is a choice and the parents are in control. And that's the case here.

The iCloud thing is much more restrictive, comparing hashes of pictures before you send them to Apple servers. For some reason, they do it client side and not server side. AFAIK, iCloud photos are not E2E encrypted so I don't really know why they are doing it that way when everyone else does it server-side.

But combine the news and it sounds like Apple is using AI to scan all your pictures. Which is not true. Unless you are a child and still under your parents authority, it will only compare hashes of picture you send in the cloud, no fancy AI here, and it is kind of understandable for Apple not to want to host child porn.

Re: Apple's child protection features spark concern within its own ranks: sources

#614

Cancelled my Apple TV+, iCloud. In the process of selling my iPhone and Apple watch. I know it seems crazy but I feel betrayed and this is the only way I can protest this. Will I have less privacy on android? Yes.

It's arguable Android, even stock, is better for privacy

Re: Apple's child protection features spark concern within its own ranks: sources

#615

Earlier quoted context omitted.

Why do you think essentially no one is complaining about using ML to understand the content of photos… At last in Apple's case, ML is used only if a minor child (less than 13 years old) who is on a Family account where the parent/guardian has opted-in to the ability to be alerted if potentially bad content is either sent or received using the Messages app.

By default iPhones autocategorise your photos, don't they?

The sure do, and now extract text from images

Re: Apple's child protection features spark concern within its own ranks: sources

#616

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

Apple privacy focus was always opportunistic: they couldn't get a foothold into online advertising so they decided to make that weakness a selling point instead. They'll ditch privacy in a second if they can sell you enough ads, just as they ditched privacy for Chinese customers when the Chinese government asked them to.

> Apple privacy focus was always opportunistic: they couldn't get a foothold into online advertising so they decided to make that weakness a selling point instead.

You could spin that the other way: Apple’s foray into advertising was opportunistic, but didn’t sit with their focus on privacy. You’d need internal memos to prove it went either way.

Re: Apple's child protection features spark concern within its own ranks: sources

#617
post #572

Earlier quoted context omitted.

> But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still possible to use an iPhone without iCloud and get full E2E. I disagree completely on this. For one, users aren't aware that using iCloud means that Apple has your decryption key and can thereby read and share all of your phone's data. And two, opt-out is a dark pattern.…

I agree. If Apple wants to go this route, they should abstain from pushing the user towards using iCloud as they currently do, and instead just present a clear opt-in choice. "Do you want to enable iCloud photos? Your private photos will be uploaded encrypted to Apple's servers, so that only you can access them. Before uploading, your photos will be locally scanned on your device for any illegal content. Apple will o…

Yes, but...

An option like this, after the lawyers get at it, will be 14 pages long.

"We can change this at any time", "except by court order", "no guarantee", "not liable", and on and on and on...

Re: Apple's child protection features spark concern within its own ranks: sources

#618

Earlier quoted context omitted.

CSAM scanning is probably the easiest thing they could do to satisfy this demand, and if you don't use iCloud Photos, you're not affected by it at all. As far as encrypted backups go, it's an open question whether they want to deal with the legal and support headaches that such a change would bring. If they continued to do nothing, Congress might force their hand by legislatively outlawing stronger encryption - they…

> For users, if you enable this feature, but then lose your password, you are entirely screwed and Apple can't help you. Exactly the same with the phone if you forget your PIN/passcode. So they already do this.

Especially on Apple devices. You cannot just reset the device if it was ever associated with an account and you don't know the password anymore. You must contact Apple support. Some people still want to employ Apple devices in a business environment.

The amount of money that is spend on their devices is just insane.

Re: Apple's child protection features spark concern within its own ranks: sources

#619
post #167

I just do not want Apple scanning my phone for the purpose of finding something they can send to the police. I’m not even talking about any “slippery slope” scenarios and I’ll never have any of the material they are looking for. And right or wrong, I don’t really fear a false identification, so this isn’t about a worry that they will actually turn me in. I just don’t want them scanning my phone for the purpose of tur…

From what I understand, Apple does not want to scan your phone.

They want to have end-to-end encryption and store your photos encrypted. This is why they scan before sending them encrypted.

They won't scan anything which you would not put in the cloud anyway.

This is pretty clever way to preserve end-to-end encryption and satisfy requirement not to store anything CP related on their servers. Probably too clever for journalists to understand :(

Re: Apple's child protection features spark concern within its own ranks: sources

#620

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

G
Post reply on HN