Earlier quoted context omitted.
And then Apple reviews the account and sees that what was flagged was not CSAM. And again, the hashes aren’t of arbitrary subject matter, they’re of specific images. Using that to police subject matter would be ludicrous.
How would Apple know what the content was that was flagged if all they are provided with is a list of hashes? I completely agree it's ludicrous, but there are plenty of countries that want that exact functionality.
An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology
621–630 of 713 posts
Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology
#622Earlier quoted context omitted.
Your position is to simply deny that child porn or predation is a serious problem. I outlined that this was one of the sides in the debate - I.e. you take position 2, and have no empathy for position 1. The problem is that this is a political trap. You can’t win position 2 by painting technologists as uncaring or dismissive. ‘Think of the children’ works for a reason.
> ‘Think of the children’ works for a reason. "Think of the children" will always work, no matter what the context is, no matter what the stats are, and no matter what we do. That does not mean that we should not care about the children, and it does not mean that we shouldn't care about blocking CSAM. We should care about these issues purely because we care about protecting children. If there are ways for us to reduc…
We could say the same thing the other way - people up in arms are not frightened by statistics of abuse of a surveillance system, but frightened of the idea of a company or government abusing it. This thread is full of people misrepresenting how it works, claims of slippery slopes straight to tyranny, there's a comparison to IBM and the Holocaust, and it's based on no real data and not even the understanding from simply reading the press release. This thread is not full of statistics and data about existing content filtering and surveillance systems and how often they are actually being abused. For example Skype has intercepted your comms since Microsoft bought it and routed all traffic through them, Chrome and FireFox and Edge do smartscreen blocking of malware websites - what are the stats on those systems being abused to block politically inconvenient memes or similar? Nothing Apple could do would in any way reassure these people because the fears are not based on information. For example your comment:
> "We know the risks of outing minors to parents if they're on an LGBTQ+ spectrum."
Minors will see the prompt "if you do this, your parents will find out" and can choose not to and the parents don't find out. There's an example of the message in the Apple announcement[1]. This comment from you is reacting to a fear of something disconnected from the facts of what's been announced where that fear is guarded against as part of the design.
You could say that the hash database is from a 3rd-party so that it's not Apple acting unilateraly, but that's not taken as reassurance because the government could abuse it. OK guard against that with Apple reviewing the alerts before doing anything with them, that's not reassuring because Apple reviews are incompetent (where do you hear of groups that are both incompetent and capable of implementing worldscale surveillance systems? conspiracy theories, mostly). People say it scans all photos and when they learn that it scans only photos about to be uploaded to iCloud their opinion doesn't seem to change, because it's not reasoned based on facts, perhaps? People say it will be used by abusive partners who will set their partner to be a minor to watch their chats. People explain that you can't change an adult AppleID to a minor one just like that, demonstrating the argument was fear based not fact based. People say it is a new ability for Apple to install spyware in future, but it's obviously not - Apple have been able to "install spyware in future" since they introduced auto-installing iOS updates many years ago. People say it's a slippery slope - companies have changed direction, regulations can change, no change in opinion; nobody has any data or facts about how often systems do slide down slippery slopes, or get dragged back up them. People saying it could be used by bad-actors at Apple to track their Ex's. From the design, it couldn't. But why facts when there's fearmongering to be done? The open letter itself has multiple inaccurate descriptions of how the thing works by the second paragraph to present it as maximally-scary.
> "We would also in general like to see more stats about how serious the problem of CSAM actually is"
We know[2] that over 12 million reports of child abuse material to NMEC were related to FaceBook messenger and NMEC alone gets over 18 million tips in a year. Does that change your opinion either way? Maybe we could find out more after this system goes live - how many alerts Apple receives and how many they send on. A less panicky "Open Letter to Apple" might encourage them to make that data public, how many times it triggered in a quarter, and ask Apple to commit to removing it if it's not proving effective. And ask Apple to state what they intend to do if asked to make the system detect more things in future.
> "their fear is not based on real risk analysis or statistics or practical tradeoffs"
Look what would have to happen for this system to ruin your life in the way people here are scaremongering about:
- You would have to sync to iCloud, such that this system scans your photos. That's optional. - Someone would have to get a malicious hash into the whole system and a photo matching it onto your device. That's nontrivial to say the least. - Enough of those pictures to trigger the alarm. - The Apple reviewers would have to not notice the false alarm photo of a distorted normal thing. - The NMEC and authorities would have to not dismiss the photo.
It's not impossible, but it's in the realms of the XKCD "rubber hose cryptography" comic. Sir Cliff Richard, his house was raided by the police, the media alerted, his name dragged through the mud, then the crown prosecution service decided there was nothing to prosecute. The police apologised. He sued the police and they settled out of court. The BBC apologised. He sued them and won. The crown prosecution service reviewed their decision and reaffirmed that there was nothing to prosecute. His name is tarnished, forever people will be suspicious that he paid someone off or otherwise pulled strings to get away with something; a name-damaging flase alarm which is something what many people fear happening in this thread. Did anyone need to use a generative-adversarial network to create a clashing perceptual hash uploaded into a global analysis platform to trigger a false alarm convincing enough to pass two or three human reviews? No, two men decided they'd try to extort money and made a false rape allegation.
People aren't interested in how it works, why it works the way it does, whether it will be an effective crime fighting tool (and how that's decided) or whether it will realistically become a tyrannical system, people aren't interested in whether Apple's size and influence could be an independent oversight on the photoDNA and NCMEC databases to push back against any attempts of them being misused to track other-political topics, people are jumping straight to "horrible governments will be able to disappear critics" and ignoring that horrible governments already do that and have many much easier ways of doing that.
> "So in the real world we know that the majority of child abuse comes from people that children already know."
Those 12 million reports of child abuse material related to FaceBook messenger; does it make any difference if they involved people the child knew? If so, what difference do you think that makes? And Apple's system is to block the spread of abuse material, not (directly) to reduce abuse itself - which seems an important distinction that you're glossing over in your position "it won't reduce abuse so it shouldn't be built" when the builders are not claiming it will reduce abuse.
> "Nobody in any political sphere has ever responded to "think of the children" with "we already thought of them enough.""
Are the EFF not in the political sphere? Are the groups quoted in the letter not? Here[3] is a UK government vote from 2014 on communication interception, where it was introduced with "interception, which provides the legal power to acquire the content of a communication, are crucial to fighting crime, protecting children". 31 MPs voted against it. Here[4] is a UK government vote from 2016 on mass retention of UK citizen internet traffic, many MPs voted against it. It's not the case that "think of the children" leads to political universal agreement of any system, as you're stating. Which could be an example of you taking your position by fear instead of fact.
> "It doesn't matter what solutions we come up with or what the rate of CSAM drops to, those people are still going to be scared of the idea of privacy itself."
The UK government statement linked earlier[2] disagrees when it says "On 8 October 2019, the Council of the EU adopted its conclusions on combating child sexual abuse, stating: “The Council urges the industry to ensure lawful access for law enforcement and other competent authorities to digital evidence, including when encrypted or hosted on IT servers located abroad, without prohibiting or weakening encryption and in full respect of privacy". The people whose views you claim to describe explicitly say the opposite of how you're presenting them. Which, I predict, you're going to dismiss with something that amounts to "I won't change my opinion when presented with this fact", yes?
There are real things to criticise about this system, the chilling effect of surveillance, the chance of slippery slope progression, the nature of proprietary systems, the chance of mistakes and bugs in code or human interception, the blurred line between "things you own" and "things you own which are closely tied to the manufacturer's storage and messaging systems" - but most of the criticisms made in this thread are silly.
[1] on the right, here: https://www.apple.com/v/child-safety/a/images/child-safety__...
[2] https://www.gov.uk/government/publications/international-sta...
[3] https://www.theyworkforyou.com/debates/?id=2014-07-15a.704.0...
[4] https://www.theyworkforyou.com/debates/?id=2016-06-07a.1142....
Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology
#623> To help address this, new technology in iOS and iPadOS* will allow Apple to detect known CSAM images stored in iCloud Photos. After reading OP, my understanding had been that this update will cause _all_ photos on Apple devices to be scanned. However, the above quote from Apple's statement seems to indicate that only photos uploaded to iCloud Photos are scanned (even though they are technically scanned offline). Th…
And this has always been Apple’s stance because of the government. We lock down the phone and don’t let the government in but if you use cloud service that doesn’t have the same rights because it’s not stored on your property. https://morningstaronline.co.uk/article/w/apple-drops-plans-... This sounds like them trying to find a way to encrypt your data and remove the fbi from having a “what about the children excuse”…
Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology
#624Earlier quoted context omitted.
> What makes you think that? That's just your opinion. It’s not just my opinion that Apple has implemented a hash based mechanism to scan for child pornography that runs on people’s phones. People complaining about it have definitely lost the battle already. It is already here. > I understand you may try to convince readers that it is over, because it may be your opinion. That is not an accurate understanding of my a…
Are you falling into their trap knowingly or not? There is a child molestation problem everywhere in the world, including online. I have seen nothing explaining it is getting bigger / worse. I have read that most of the cases are family members, in the real world. So when I hear Apple and Government explain "because of the children" they want to monitor our phones more, in the context of growing assumed dictatorships…
This is a false dichotomy and a false assumption.
> There is a child molestation problem everywhere in the world, including online.
Agreed.
> I have seen nothing explaining it is getting bigger / worse. I have read that most of the cases are family members, in the real world.
Have you listened to Sam Harris, or heard the FBI? They have a very different view.
It could be that both are true: there is a child porn problem and governments are using it as an excuse.
The only thing you seem to be going on is a story you once heard, that may have been true at the time, but may not be now.
> So when I hear Apple and Government explain "because of the children" they want to monitor our phones more, in the context of growing assumed dictatorships, Pegasus, Snowden reveleation, do you really think that solving the child pornography issue will help refrain them, or slow them down?
That would misleading sense given that you are assuming child porn is not a growing problem.
Porn in general is growing hugely why wouldn’t child porn also be growing?
Generally Apple has resisted overreach, but I agree that they are slowly moving in the wrong direction.
Apple is not the government.
> Open source hardware,
> political pressure, consumer pressure, and regulation, possibly monopoly break-ups. In the US, it starts with the people.
You contradict yourself here. You seem to think the government can’t be slowed and yet political pressure will work. Which is it?
> But doing better with child pornography won't change anything there,
I agree - it won’t eliminate the forces that want to weaken encryption etc.
But a more privacy respecting solution would still help.
> it juts moves the discussion to some other topic. Distraction. That is my point all along.
> There is no data that shows that all of a sudden child pronography has progressed leaps and bounds. So people suddenly concerned by that are
Isn’t there? The FBI claims it is growing.
> most likely not truthful,
Ok, we know you don’t trust the FBI.
But enough people do that we can’t ignore them. Even if the problem isn’t growing as Sam Harris claims it is, trying to persuade people that the problem doesn’t need to be solved seems like a good way to undermine the causes you support.
> a dn they have a very strong agenda. That's what we need to focus on, not their "look at the children"
As I say, I agree there are people trying to exploit ‘look at the children’ in support of their own agenda.
I just don’t think that means there isn’t a real problem with child porn. Denying that there is a problem seems equally agenda driven.
Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology
#625Earlier quoted context omitted.
Android has been doing this all along, so not using iOS devices will not help. As I said, there are no good solutions.
* drop your phone * don't store images on your phone * use a rom like Graphene, don't install a cloud storage or Google Play Services Those aren't great solutions, but they're options.
If your goal is to inform a small minority of expert users that they should protect themselves against corporate/government encroachment, by the looks of the comments here, I’d say you’ve already succeeded.
Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology
#626Earlier quoted context omitted.
You’re ignoring the sentence after I mention the slippery slope, where I say: > These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it. I’m not the one ignoring the middle ground.
I have read through your comments on the article. You are the bogeyman. Good bye. You are the one promoting the latest false middle ground along an actual sliding slope. That is disingenuous.
What disingenuous argument have I made?
The only thing I have argued for is for hackers to attempt technical solutions that are more to their liking than Apple’s, because arguments are not preventing the slide.
Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology
#627Earlier quoted context omitted.
As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography. 2. The complaints are all slippery slope arguments that governments will force Apple to abuse the mechanism. These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it. However: Child pornography and the related abuse is widely thought of as a massive probl…
The intention to prevent child sexual abuse material is indeed laudable. But the "solution" is not. Especially when we all know that this "solution" gives a legal backing to corporates to do even more data mining on its users, and can easily be extended (to scan even more "illegal" content) and abused into a pervasive surveillance network desired by a lot of government around the world. For those wondering what's wro…
Agreed, that’s my point, and I would say that your comment outlines some good principles a better solution might respect, although it’s worth noting that those principles have only ever constrained the legal system.
Your employer, teacher, customers, vendors, parents etc, have never been constrained in these ways.
Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology
#628US Government: We suspect the person in this photo of committing a crime. Here is your subpoena, Apple. You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them. Chinese Government: Here is the NeuralHash for Tienanmen square. Delete all photos you find matching this or we will bar you from China. Apple has at this point already admitted thi…
What will Apple do when Iran or Qatar (or any of the other 71 countries where homosexuality is illegal) upload photos to the CSAM database that they consider illegal acts? In some of those countries same-sex sex is punishable by death.
Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology
#629Earlier quoted context omitted.
No, M1 isn't locked down at all. You can disable secure boot and there are efforts to port Linux to it. You can block *.apple.com and everything will still work.
Puppies aren't messy at all. You can shave all their hair off and there are efforts to deal with the slobbering. You can put a diaper on the back end of it and everything will still work.
Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology
#630Wait, why is everyone so distraught about this? Am I missing something? This only affects people who upload their photos to iCloud? Just don't store any data on iCloud. Seems simple enough. Yeah sure, we can make conspiracy theories and all, but based off of what was officially announced I'm not understanding all the hysteria.