Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

671–680 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#671
post #667
post #661

Earlier quoted context omitted.

> Sure, I am quite willing to hang you with your own words. That isn’t what you’ve done. “As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography.” - False as you even argued I don’t argue that. >> They are not in this to make arrests. They just want parents to feel safe letting children use their products. Driving predators to use different tools is fine with the…

Resplendent. I won’t even add my own words. I will let you speak for yourself. ““ As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography.” I don’t argue that.”” “ Apple’s solution is the best on offer. ” “ I think this is exactly what Apple wants to he the result of their their iMessage scanning. They are not in this to make arrests. They just want parents to fee…

It looks like you’ve copied and pasted some quotes from my comments into a jumble.

There is nothing to ‘hang’ anyone with. Just a series of quotes taken out of context which even then don’t look particularly nefarious.

Remind us again what you’re trying to prove with this?

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#673
post #659

Earlier quoted context omitted.

> My belief is that by definition, a fear that is not based on any kind of rational basis is an irrational fear. I don't believe there is a separate category of people who are irrationally scared of child predators, but fully willing to listen to alternative solutions instead of banning encryption. We disagree here, indeed. My view is not that there are ‘semi-rational’ people. My view is that there are hard to quanti…

> My view is that there are hard to quantify risks that it is rational to have some fear about and see as problems to be solved. Heavily agreed. But those are not irrational fears. They become irrational fears when learning more about the risks and learning more about the benefits and downsides of different mitigation techniques doesn't change anything about those fears one way or another. We all form beliefs based o…

> There are 2 things we can do with these types of people:

> 1) We can educate them about the dangers of banning encryption and encourage them to research more about the problem. We can remain open to other proposals that they have, while making it clear that each proposal's social benefits have to be weighed against their social costs.

> or

> 2) We can offer them some kind of compromise solution that may or may not actually address their problem, but will make them feel like it does, and which will in theory make them less likely to try and ban encryption.

Why are those the only two solutions? That seems like a false dichotomy.

Again why would you think I’m suggesting #2.

Can I ask you straight up, are you trolling?

There is a pattern where you say “I think you are saying X” where X is unrelated to anything I have actually said. I ask “why do you think I think X”, and you don’t answer, but just move on to repeat the process.

I have been assuming there is good faith misunderstanding going on, but the fact that you keep not explaining where the misunderstandings have arisen from when asked is starting to make me question that.

Most of what you’ve written in this reply is frankly incoherent, or at least seems to be based on assumptions about my position that are neither valid nor obvious, as to make it seem seem unconnected from our previous discussion.

For example this:

> To me, if someone comes to me and says, "I'm not interested in hearing about the downsides of banning encryption, come up with a solution or we'll ban it anyway" -- I don't think that person is reasonable, I don't think they're acting rationally, and certainly I'm not interested in working with that person or coming up with solutions with that person.

Just seems like a gibberish hypothetical that doesn’t have much to do with what we are talking about.

And this:

> You could come up with the most innovative amazing reduction strategy for CSAM ever conceived, and it would not change any of those people's opinions on encryption.

What does it even mean to ‘reduce CSAM’? Why do we care about changing people’s minds here about encryption?

Let’s take another part:

> Where I fall on this is that I am totally willing to look for alternative solutions; but encryption, device ownership, privacy, and secure software -- these are not prizes to be won, conditional on me finding a solution.

Ok, but those are all in fact fluid concepts whose status is changing as time goes by, and mostly not in the directions it sounds like you would prefer. Nobody is thinking of them as prizes. The status quo is that they are in jeopardy.

> We can look for a solution together once we've taken those things off the table.

Ok, but this just means you aren’t willing to participate with people who don’t agree to a set of terms, which in fact don’t represent anything anyone has so far developed.

That’s a comment about your personal boundaries not about whether a better solution than what Apple is proposing could be built.

That’s fine by me, in fact I’d be happy if a solution did incorporate all of the concepts you require. I agree we need that. I argue for it quite often.

I don’t think such a thing has been built yet, and if it were built, I suspect parents would like to have some mechanism to control whether it was. vector of child exploitation before they let their kids use it.

So what would that solution look like?

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#674
post #667
post #661

Earlier quoted context omitted.

> Sure, I am quite willing to hang you with your own words. That isn’t what you’ve done. “As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography.” - False as you even argued I don’t argue that. >> They are not in this to make arrests. They just want parents to feel safe letting children use their products. Driving predators to use different tools is fine with the…

Resplendent. I won’t even add my own words. I will let you speak for yourself. ““ As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography.” I don’t argue that.”” “ Apple’s solution is the best on offer. ” “ I think this is exactly what Apple wants to he the result of their their iMessage scanning. They are not in this to make arrests. They just want parents to fee…

Zepto complained that it was out of context. Here are entire comments.

“ As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography. 2. The complaints are all slippery slope arguments that governments will force Apple to abuse the mechanism. These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it. However: Child pornography and the related abuse is widely thought of as a massive problem, that is facilitated by encrypted communication and digital photography. People do care about this issue. ‘Think of the children’ is a great pretext for increasing surveillance, because it isn’t an irrational fear. So: where are the proposals for a better solution? I see here people who themselves are afraid of the real consequences of government/corporate surveillance, and whose fear prevents them from empathizing with the people who are afraid of the equally real consequences of organized child sexual exploitation. ‘My fear is more important than your fear’, is the root of ordinary political polarization. What would be a hacker alternative would be to come up with a technical solution that solves for both fears at the same time. This is what Apple has attempted, but the wisdom here is that they have failed. Can anyone propose anything better, or are we stuck with just politics as usual? Edit: added ‘widely thought of as’ to make it clear that I am referring to a widely held position, not that I am arguing for it.”

> The more sophisticated child molesters out there will find out about what Apple is doing and quickly avoid it. I think this is exactly what Apple wants to he the result of their their iMessage scanning. They are not in this to make arrests. They just want parents to feel safe letting children use their products. Driving predators to use different tools is fine with them. As far as the FBI goes, this is presumably not their preference, but it’s still good for them if it makes predation a little harder.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#675

Earlier quoted context omitted.

Translation: The child porn industry needs to wait until we solve world hunger. Priorities, people!

The real translation is that nobody gives a fuck about the children but they use this as an excuse to peddle their bs backdoors.

You got that right—this is a bullshit back door. That's my favourite kind of back door. Because it does one thing incredibly well: it starves of oxygen the one remotely tractable argument politicians have found to break real E2E encryption with real, non-bullshit back doors.

With this technology in place, never again will the Government be able to wail "think of the children" when claiming E2E needs a back door in order to protect the the children.

Give me the bullshit back door any day.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#676
post #645

Earlier quoted context omitted.

I notice you edited your top level comment, and it seems like several others to change the meaning of our thread. I’m not missing your point if you are changing your point after I have replied.

For some reason I couldn't reply to your comment initially, so I put this in a sibling (typos and grammar excepted): I haven't touched any of my comments since they first received a reply. I often touch my comments within a couple minutes of posting in order to correct typos or clarify my intentions, usually by appending a paragraph. But I don't do so without remark once they've become canonical in a thread. Your rep…

[deleted]

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#677
post #674
post #667

Earlier quoted context omitted.

Resplendent. I won’t even add my own words. I will let you speak for yourself. ““ As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography.” I don’t argue that.”” “ Apple’s solution is the best on offer. ” “ I think this is exactly what Apple wants to he the result of their their iMessage scanning. They are not in this to make arrests. They just want parents to fee…

Zepto complained that it was out of context. Here are entire comments. “ As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography. 2. The complaints are all slippery slope arguments that governments will force Apple to abuse the mechanism. These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it. However: Child…

Still out of context - they are replies to things you wrote. You have left out your side of the conversation for some reason. How does that help?

Did you know they can still be seen exactly as I wrote them in the thread, where anyone can make sense of them, and see what I was replying to?

Remind us what this copy and paste behavior is meant to prove?

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#678
post #667
post #661

Earlier quoted context omitted.

> Sure, I am quite willing to hang you with your own words. That isn’t what you’ve done. “As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography.” - False as you even argued I don’t argue that. >> They are not in this to make arrests. They just want parents to feel safe letting children use their products. Driving predators to use different tools is fine with the…

Resplendent. I won’t even add my own words. I will let you speak for yourself. ““ As far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography.” I don’t argue that.”” “ Apple’s solution is the best on offer. ” “ I think this is exactly what Apple wants to he the result of their their iMessage scanning. They are not in this to make arrests. They just want parents to fee…

Also in contrast to zepto, here are words from Edward Snowden: No matter how well-intentioned, @Apple is rolling out mass surveillance to the entire world with this. Make no mistake: if they can scan for kiddie porn today, they can scan for anything tomorrow.

They turned a trillion dollars of devices into iNarcs—without asking.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#679
post #673

Earlier quoted context omitted.

> My view is that there are hard to quantify risks that it is rational to have some fear about and see as problems to be solved. Heavily agreed. But those are not irrational fears. They become irrational fears when learning more about the risks and learning more about the benefits and downsides of different mitigation techniques doesn't change anything about those fears one way or another. We all form beliefs based o…

> There are 2 things we can do with these types of people: > 1) We can educate them about the dangers of banning encryption and encourage them to research more about the problem. We can remain open to other proposals that they have, while making it clear that each proposal's social benefits have to be weighed against their social costs. > or > 2) We can offer them some kind of compromise solution that may or may not…

> Why are those the only two solutions? That seems like a false dichotomy.

It's not? It's a real dichotomy. What other solution could there be?

I mean, OK, I guess there are other solutions we could try like ignoring them or attacking them or putting them in prison or some garbage, but to me those kinds of solutions are off the table. So we either figure out some way to satisfy them, or convince them that we're right. That's not a false dichotomy, those are the only 2 options.

I assume you're suggesting #2 because you're sure as heck not suggesting #1, and I can't figure out what else you could be suggesting.

----

> why do you think I think X

Frankly, if this isn't what you think, then I don't understand what you're thinking.

You keep on saying that we need to offer solutions, we can't just criticize Apple's proposal, we have to offer an alternative if we're going to criticize. But why?

- I thought the point was to get rid of people's fears: no, you're saying that's not what you mean.

- I thought the point was to compromise with critics: no, you're saying that's not what you mean.

- I thought the point was to try and get people to stop attacking encryption: no, you're saying that's not what you mean.

- Heck, I thought the point was to reduce CSAM, and you're telling me now that even that's not what you mean either?

> What does it even mean to ‘reduce CSAM’? Why do we care about changing people’s minds here about encryption?

What? We're on the same thread, right? We're commenting under an article about Apple instituting policies to reduce CSAM, ie, to make it so there is less CSAM floating around in the wild. When you talk about a "solution", what problem are you even trying to solve? Because all of us here are talking about CSAM, that's what Apple's system is designed to detect.

I don't understand. How can you possibly not be talking about CSAM right now? That's literally what this entire controversy is about, that's the only reason this thread exists.

----

Honest to God, hand over my heart, I am not trolling you right now. I understand that this is frustrating to you, but my experience throughout this conversation has been:

- You say something

- I try to interpret and build on it

- You tell me that's not what you meant and ask me why I thought that

- Okay, I try to reinterpret and explain

- The cycle repeats

- The only information I can get out of you is that I apparently don't understand you. I'm not getting any clarification. You just tell me that I'm misunderstanding your position and then you move on.

What are you trying to accomplish by proposing "alternative" solutions to Apple's proposal? You seem to think this will help keep people from attacking encryption, but I'm wrong to say that it will help by reducing their fears, or by distracting them, or by teaching them, or by solving the problems that they think they have, or... anything.

You tell me that "if we think it’s a bad trade-off that is taking us in the direction of worse and worse privacy compromises, we aren’t likely to be able to persuade people to ignore the real trade-offs, but we stand a chance of getting them to accept a better solution to the same problem." But then you tell me that "encryption is not a prize" and the goal is not to convince them of anything, which to me completely contradicts the previous sentence.

If encryption isn't a prize, if "nobody is thinking of them as prizes", then why does it sound like you're telling me that preserving encryption is conditional on me coming up with some kind of alternative? If encryption isn't a prize, then great, let's take it off the table.

But then I'm told that taking encryption off the table means that "you aren’t willing to participate with people who don’t agree to a set of terms". So apparently encryption is on the table, and I am coming up with alternative solutions in order to convince people to attack something else? But that's not what you mean either, because you tell me that people will always attack encryption, so I don't even know.

You're jumping back and forth between positions that seem completely contradictory to me. I thought that you had a different view than me about how reasonable privacy-critics actually were, but apparently you also have different views than me about what the problem is that Apple is trying to solve, what privacy-critics even want in the first place, what the end goal of all of this public debate actually is. Maybe you even disagree with me about what privacy and human rights are, since "those are all in fact fluid concepts whose status is changing as time goes by".

So I need you to either lay out your views very plainly without any flowery language or expansion in a way that I can understand, or I need to stop having this conversation because I don't know what else I can say other than that I find your views incomprehensible. If you can't do that, then fine, we can mutually call each others' views gibberish and incoherent, and we can go off and do something more productive with our evenings. But I'll give this exactly one last try:

----

> Most of what you’ve written in this reply is frankly incoherent

Okay, plain language, no elaboration. Maybe this isn't what you're arguing about, maybe it is. I don't care. Here's my position:

A) it is desirable to reduce CSAM without violating privacy.

B) the downsides of violating privacy are greater than the upsides of reducing CSAM.

C) most of the people arguing in favor of violating privacy to stop CSAM are either arguing in bad faith or ignorance.

D) the ones that aren't should be gently educated about the downsides of breaking encryption and violating human rights.

E) the ones that refuse to be educated are never going to change their views.

F) compromising with them is a waste of time, and calls to "work with the critics" instead of educating them are a waste of time.

G) working with critics who refuse to be educated about the downsides of violating privacy will not help accomplish point A (it is desirable to reduce CSAM without violating privacy).

H) thus, we should refuse to engage with people about reducing CSAM unless they take encryption/privacy/human rights off of the table (on this point, you understood my views completely, people who view CSAM as a bigger deal than human rights shouldn't be engaged with)

I) a technical solution that reduces CSAM without violating privacy may or may not be possible. But it doesn't matter. Even if a technical solution without violating privacy is impossible, violating privacy is still off the table, because the downsides of removing poeple's privacy rights would still be larger than the upsides of removing CSAM.

Can you give me a straightforward, bullet-point list of what statements above you disagree with, if any?

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#680
post #581

Earlier quoted context omitted.

> This only finds known pictures of child abuse not new ones No, it finds images that have similar perceptual hashes, typically using the hamming distance or another metric to calculate differences between hashes. I've built products that do similar things. False positives are abound with perceptual hashes, especially when you start fuzzy matching them.

But these are just variations of known pictures to recognize them if they cropped or scaled. The hash of a really new picture isn't similar to the hash of a known picture.

Sure it is possible to have collisions, this is the main thing about hashes , in general collisions are rare but this are a different type of hashes and Apple is probably tweaking the parameters so the collisions are manageable.

But if the database of hashes is big and the total number of unique photos of all iPhone users is also a giant number you will find for sure collisions.

Post reply on HN