Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

661–670 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#661
post #657
post #647

Earlier quoted context omitted.

> If you build a back door, then people will use it. So let’s build it anyway because it is a middle ground. This looks a completely made up position that has nothing to do with anything I have said. If you can find a comment where I am advocating building back doors, I invite you to quote it. > That seems as clear as day. Why do I have to keep repeating myself? If it was clear you’d be able to support it with a quot…

Sure, I am quite willing to hang you with your own words. zepto “As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography.” “ > The more sophisticated child molesters out there will find out about what Apple is doing and quickly avoid it. I think this is exactly what Apple wants to he the result of their their iMessage scanning. They are not in this to make arrests…

> Sure, I am quite willing to hang you with your own words.

That isn’t what you’ve done.

“As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography.”

- False as you even argued

I don’t argue that.

>> They are not in this to make arrests. They just want parents to feel safe letting children use their products. Driving predators to use different tools is fine with them.”

> So according to your very own words,

Erm..

> this ISN’T a serious attempt to build a privacy supporting solution to child pornography.

These are your words, not what you quoted of mine.

It’s absolutely a solution to the problem of child porn on their platform. They care about making it safe for their users. Who is expecting Apple to solve the problem beyond that?

> It is at best something to keep the FBI at bay

These are your words, not something I have said.

> even though as you say it also introduces a back door.

Where do I say it introduces a back door?

> “2. The complaints are all slippery slope arguments that governments will force Apple to abuse the mechanism. These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it.”

> False, these are not slippery slope arguments

It is your opinion that they are not slippery slope arguments. I think they are, and as you have quoted I think they are reasonable. Slippery slope arguments are fallacies in the sense that the conclusions don’t logically follow, but that doesn’t mean that they are always wrong.

You haven’t hung me with anything - you’ve just voiced some misrepresentations of your own interleaved with quotes of me.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#662
post #4

I recently listened to a Darknet Diaries episode on messaging app Kik. This app is apparently being used by many people to trade child pornography. In this episode, there was some criticism expressed on how Kik doesn't scan all the images on their platform for child pornography. I would really like to hear from people who sign this open letter, how they think about this. Should the internet be a free for all place wi…

The conversation today is not really about PhotoDNA (checking image hashes against known bad list). That ship has sailed and most large tech companies already do it. Apple will do it one way or another. It’s a good way to fight the sharing of child porn, which is why it is so widely adopted. The question is whether it is worse to do it on-device, than on the server. That’s what Apple actually announced. I suspect App…

You have the exact same level of privacy as before. Before, the images were scanned in the cloud. Now they are being scanned as they exit your phone. In that way, the avoidance protocol is the same, namely

> I can choose to not upload and avoid the technology

They are not scanning your entire photo library at rest.

Could they? Sure. But they’ve had the hardware to do this for years, so they could have done so silently at any time.

This entire saga has been one of poor messaging and rampant speculation.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#663
post #659

Earlier quoted context omitted.

> Neither of us disagree that such people exist. Indeed we both believe that they do. > Why does changing such a person’s mind matter? Okay, finally! I think I understand why we're disagreeing. Please tell me if I'm misunderstanding your views below. > You’ll need to explain what the contradiction is. I kept getting confused because you would agree with me right up to your conclusion, and then suddenly we'd both go i…

> My belief is that by definition, a fear that is not based on any kind of rational basis is an irrational fear. I don't believe there is a separate category of people who are irrationally scared of child predators, but fully willing to listen to alternative solutions instead of banning encryption. We disagree here, indeed. My view is not that there are ‘semi-rational’ people. My view is that there are hard to quanti…

> My view is that there are hard to quantify risks that it is rational to have some fear about and see as problems to be solved.

Heavily agreed. But those are not irrational fears.

They become irrational fears when learning more about the risks and learning more about the benefits and downsides of different mitigation techniques doesn't change anything about those fears one way or another.

We all form beliefs based on incomplete information. That's not irrational. It is irrational for someone to refuse to look at or engage with new information. If someone is scared of the potential for encryption to facilitate CSAM because they're working with incomplete information, that's not irrational.

If someone is scared of encryption because they have incomplete information, and they refuse to engage with the issue or to learn more about the benefits of encryption, or the risks of banning it, or what the stats on child predators actually are -- at that point, it's an irrational belief. What makes them irrational is the fact that they are no longer being adjusted based on new information.

A rational person is not someone who knows everything. A rational person is someone who is willing to learn about things when given the opportunity.

> Why do you mention this again? Nobody is arguing for a solution designed to assuage people’s fears.

I guess I don't understand what you are arguing for then.

Let's look at your "reasonable people who are reasonably afraid" camp. We'll consider that these people have doubts about encryption, but don't hate it. They are scared of the potential for abusers to run rampant, but are having trouble figuring out what that looks like or what the weak points are in a complicated system. They are confused, but not bad-faith, and they have fears about something that is legitimately horrific. We will say that these people are not irrational, they recognize a real problem and earnestly want to do something about it.

There are 2 things we can do with these types of people:

1) We can educate them about the dangers of banning encryption and encourage them to research more about the problem. We can remain open to other proposals that they have, while making it clear that each proposal's social benefits have to be weighed against their social costs.

or

2) We can offer them some kind of compromise solution that may or may not actually address their problem, but will make them feel like it does, and which will in theory make them less likely to try and ban encryption.

You seem to be suggesting that we try #2? And this apparently isn't designed to assuage their fears? But I'm not sure what it does then. Presumably the reason they'll accept your proposal is because it addresses the fears they have.

My preference is to try #1. I believe that if someone is actually in the camp you describe, if they have reasonable fears but they're looking at a complex social problem, openly talking to those people about the complex downsides of banning encryption is OK. They'll listen. They might come up with other ideas, they might bring up their own alternative solutions. All of that is fine, none of us are against reducing CSAM, we just want people to understand the risks behind the systems being proposed.

But importantly, if someone is genuinely reasonable, if they aren't irrational and they're just trying to grapple with a complex system -- then talking about the downsides should be enough, because those people are reasonable and once they understand the downsides then they'll understand why weakening encryption isn't a feasible plan. From there we can look at alternatives, but the alternatives are not a bargaining chip. Even if there were no alternatives, that wouldn't change anything about the downsides of making software more vulnerable. First, people must understand why a proposed solution won't work, and then we can propose alternatives.

To me, if someone comes to me and says, "I'm not interested in hearing about the downsides of banning encryption, come up with a solution or we'll ban it anyway" -- I don't think that person is reasonable, I don't think they're acting rationally, and certainly I'm not interested in working with that person or coming up with solutions with that person.

> If we don’t offer an alternative solution we aren’t offering them anything at all.

Where I fall on this is that I am totally willing to look for alternative solutions; but encryption, device ownership, privacy, and secure software -- these are not prizes to be won, conditional on me finding a solution.

We can look for a solution together once we've taken those things off the table.

Because if someone comes to me asking to find a good solution, I want to know that they're coming in good faith, that they genuinely are looking for the best solution with the fewest downsides. If they're not, if they're using encryption as some kind of threat, then they're not really acting in good faith about honestly looking at the upsides and downsides. I have a hard time figuring out how I would describe that kind of a person as "reasonable".

> I personally think you would be very disappointed

> Why would you think this? Did I say anything anywhere about convincing people who are arguing for weakening encryption?

Let me be even more blunt. I think that you could come up with a brilliant solution today with zero downsides that reduced CSAM by 90%. And I think you would be praised if you did come up with that solution, and it would be great, and everyone including tech people like me would love you for it. And I also think it would change literally nothing about the current debates we're having. I think we would be in the exact same place, I think all of the people who are vaguely worried about CSAM and encryption (even the good faith people you mention above) would still be just as worried tomorrow. You could come up with the most innovative amazing reduction strategy for CSAM ever conceived, and it would not change any of those people's opinions on encryption.

I'm not just talking the irrational people. It would not change the opinions of the reasonable people you're describing above. Because why would it? However good your solution is, if encryption is genuinely not worth preserving, then it would always be better to implement your solution and ban encryption. I don't say that derisively, if the benefits of banning encryption really did outweigh the downsides, then it would genuinely be good to get rid of encryption.

The only reason we don't get rid of encryption is because its benefits do heavily outweigh its downsides. Not because this is some kind of side in a debate, but because when you examine the issue rationally and reasonably, it turns out that weakening encryption is a really bad idea.

> My argument is that the best way to make things better is to make better options available.

This is another point where we differ then.

As far as I can tell, any reasonable person who is convinced that encryption is a net negative is always going to be interested in getting rid of encryption unless they understand what the downsides are. Any reasonable person who is on the fence about encryption is going to stay on the fence until they get more information. I don't see how proposing alternative solutions is going to change that.

So I believe that the only way these reasonable people you describe are going to change their minds are if they're properly educated about the downsides of making software vulnerable, if they're properly educated about the upsides of privacy, and if they're properly educated about the importance of device ownership.

And maybe I'm overly optimistic here, but I also do believe that reasonable people are willing to engage in good faith about their proposed solutions and to learn more about the world. I don't think that a reasonable person is going to clam up and get mad and stop engaging just because someone tells them that their idea to backdoor software has negative unintended side effects. I think that education works when offered to reasonable people.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#664

Earlier quoted context omitted.

You won’t. Understand what this is instead of falling for the hysteria.

It starts with comparing file hashes. I’m worried about where this goes next.

By that logic, how do you know it hasn’t already gone there, years ago?

And this scan is currently happening on the server. They’re just making it so that the scan will now happen at the time of upload as opposed to N seconds later.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#665

> To help address this, new technology in iOS and iPadOS* will allow Apple to detect known CSAM images stored in iCloud Photos. After reading OP, my understanding had been that this update will cause _all_ photos on Apple devices to be scanned. However, the above quote from Apple's statement seems to indicate that only photos uploaded to iCloud Photos are scanned (even though they are technically scanned offline). Th…

And this has always been Apple’s stance because of the government. We lock down the phone and don’t let the government in but if you use cloud service that doesn’t have the same rights because it’s not stored on your property. https://morningstaronline.co.uk/article/w/apple-drops-plans-... This sounds like them trying to find a way to encrypt your data and remove the fbi from having a “what about the children excuse”…

Exactly this. And this further opens the opportunity for E2EE iCloud Photos where Apple can’t look at your photos on their servers at all. This gives them cover that they’re not hosting illegal content.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#666
post #73

Earlier quoted context omitted.

I'm not defending any specific point of view. I'm merely pointing out a problem of map-territory conflation.

> I'm merely pointing out a problem of map-territory conflation. Using complicated language does not make you smart... It just makes you hard to understand. Maybe if you expressed yourself in common language, you'd understand that the points you're trying to make are bogus.

I think OP is saying that it can become less straight-forward to apply judgement in some real-world situations (which is encapsulated in the old adage "the map is not the territory", which I guess I thought _was_ common language but we all love in our own bubbles, I suppose). Anyway, I believe the reason that is often cited for why child pornography is so bad is because it involves the coercion/exploitation of a human being that is unable to consent. I believe OPs position is that if this harm is removed, there would need to be some other grounds on which to prosecute someone. That is, some identifiable harm would need to be demonstrated.

There may be a reasonable counter to this argument but I would not say that OPs position is "bogus" on is face.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#667
post #661
post #657

Earlier quoted context omitted.

Sure, I am quite willing to hang you with your own words. zepto “As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography.” “ > The more sophisticated child molesters out there will find out about what Apple is doing and quickly avoid it. I think this is exactly what Apple wants to he the result of their their iMessage scanning. They are not in this to make arrests…

> Sure, I am quite willing to hang you with your own words. That isn’t what you’ve done. “As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography.” - False as you even argued I don’t argue that. >> They are not in this to make arrests. They just want parents to feel safe letting children use their products. Driving predators to use different tools is fine with the…

Resplendent. I won’t even add my own words. I will let you speak for yourself.

““ As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography.” I don’t argue that.””

“ Apple’s solution is the best on offer. ”

“ I think this is exactly what Apple wants to he the result of their their iMessage scanning. They are not in this to make arrests. They just want parents to feel safe letting children use their products. Driving predators to use different tools is fine with them.”

“2. The complaints are all slippery slope arguments that governments will force Apple to abuse the mechanism. These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it.”

“So: where are the proposals for a better solution?”

Let the viewer decide. Are you going to argue that I have misrepresented your words? Feel free to argue with yourself.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#668

Earlier quoted context omitted.

yes, think about the children! nobody thinks about the children that are literally starving every day or that are in social settings where they simply cannot succeed. Let’s just treat everyone like disgusting criminals until THEY prove they are innocent by giving us access to everything they do. The more I see, the more I want to literally dump all technology and go live off the grid.

Translation: The child porn industry needs to wait until we solve world hunger. Priorities, people!

The real translation is that nobody gives a fuck about the children but they use this as an excuse to peddle their bs backdoors.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#669
post #429
post #416

Earlier quoted context omitted.

As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography. 2. The complaints are all slippery slope arguments that governments will force Apple to abuse the mechanism. These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it. However: Child pornography and the related abuse is widely thought of as a massive probl…

> So: where are the proposals for a better solution? Better policing and child protective services to catch child abuse at the root, instead of panicking about the digital files it produces? If you'd been paying attention, you'd have noticed that real-world surveillance has massively increased, which should enable the police to catch predators more easily. Why count only privacy-betraying technology as a "solution",…

You have overlooked that the system for protecting minors from sexual messaging /is/ the parental controls you wish it was, and is /not/ the serious privacy invasion you think it is. It is on-device only, it only alerts the parents, in the condition that the parents enable it and the child continues past a warning informing them that their parent will find out if they continue.

> "The parent can be the admin of the child's devices, and have access to their otherwise encrypted messages."

Apple have done even better - the parent doesn't get access to all their messages (at least not as part of this system).

This is not the same system as the photo-scanning and authority-alerting one.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#670

Earlier quoted context omitted.

I'm just surprised they did it for CP and not terrorism.

I think it's terrorism, and CP. I have a feeling the CIA, or FBI, had a little chat with Tim Cook, and Tim caved into the pressure. Who knows they might have some very embarrassing info about the man, and used it to get what they wanted. I guarantee government, including the IRS, Immigration, etc. will be accessing Apples severs. At least we won't have to listen to Apple privacy commercials anymore.

> I guarantee government, including the IRS, Immigration, etc. will be accessing Apples severs.

Not sure if I'd go that far, but if they're using fingerprinting to identify CP, no reason they can't/wouldn't use ML to classify iMessages client-side as terrorist/not-terrorist.

Post reply on HN