Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

691–700 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#691
post #689

Earlier quoted context omitted.

> Why are those the only two solutions? That seems like a false dichotomy. It's not? It's a real dichotomy. What other solution could there be? I mean, OK, I guess there are other solutions we could try like ignoring them or attacking them or putting them in prison or some garbage, but to me those kinds of solutions are off the table. So we either figure out some way to satisfy them, or convince them that we're right…

>> 2) We can offer them some kind of compromise solution that may or may not actually address their problem, but will make them feel like it does, and which will in theory make them less likely to try and ban encryption. > Why are those the only two solutions? That seems like a false dichotomy. It's not? It's a real dichotomy. What other solution could there be? 3) Offer a better technical that is less of a compromis…

> When I ask ‘what did I say that made you thunk that’, can you explain why you rarely answer?

Okay, sure. When you ask me to try and justify why I think you hold your position, I interpret that as a distraction (hopefully a good faith one). I don't want to argue on a meta-level about why I got confused about your comments, I want to know what you believe. I'm frustrated that you keep trying to dig into "why are you confused" instead of just clarifying your position.

My feeling is we could have skipped this entire debate if you had sat down and made an extremely straightforward checklist of your main points, consisting of maybe 5-10 bullet points, each one to two sentences max. This is a thing I've done multiple times now about my beliefs/positions during this discussion. If we get mixed up about what the other person is saying, the best thing to do is not to dive into that, it's to take a step back and try to clarify from the start in extremely clear language.

You looked at the final checklist and said "this looks like just a blunt attempt to win some argument of your own". I looked at it as a charitable invitation to step back, write 10-20 sentences instead of 15 paragraphs, and to just cut through the noise and figure out where we disagree. If your checklist doesn't overlap with mine, fine. It's not bad for us to discover that we're arguing past each other. What's bad is if we spend X paragraphs getting frustrated about meta-arguments that have nothing to do with Apple.

I don't want to debate language or start cross indexing each other's comments, I want to debate ideas.

So when you tell me that I'm wrong about what you believe, I look over your statements and try to reinterpret, and I move on. Very rarely is my instinct to sit down and try to catalog a list of statements to try and prove to you that you do believe what I think, because I take it as a given that if you tell me that I misinterpreted you... I did.

So I accept it and move on.

----

Yes, we could get into a giant debate about "what makes you think I think that". That might go something like:

> You seem to think this will help keep people from attacking encryption,

> What have I said that makes you think that?

And I could reply by linking back to one of your previous comments:

> "Most people just want reasonable solutions and aren’t going to be persuaded by either extreme. If you make an argument about creeping authoritarianism they’ll say ‘child porn is a real problem, and that risk is distant’.

> If you offer them a more privacy preserving solution to choose as well as a less privacy preserving option, they’ll likely choose the more privacy preserving option.

> Apple is offering a much more privacy preserving option than just disabling encryption. People will accept it because it seems like a reasonable trade-off in the absence of anything better."

Which to me sounds quite a bit like: "offer a solution that doesn't target encryption, and then these people won't target encryption because 'most people just want reasonable solutions'".

----

But what's the point of the above conversation? I already know that you don't interpret those 3 paragraphs about a "privacy preserving option" as meaning "a proposal that will stop reasonable people from attacking encryption." Because you told me that's not what you believe.

So how weird and petty would I need to be to start arguing with you, "actually you did mean that, and I have proof!" Is it any value to either of us to try and trip each other up over "well, technically you said"? I'm not here trying to trap you, I want to understand you.

Honestly, the short answer to why I rarely reply back with quotes about "why I think you said that", is I kind of interpreted "what makes you think I think that" as a vaguely rude attempt to derail the conversation and debate language instead of ideas, and I've been trying to graciously sidestep it and move on.

- I'm happy to debate privacy with someone

- I'm happy to listen to them so I can understand their views better

- I'm not happy to debate whether or not someone believes something. I think that's a giant meaningless waste of time.

I don't think that means you're operating in bad faith, but I can't think anything I would rather do less than spend all day going back over all of your statements to cross-reference them so I can prove that... what? That I misunderstood your actual position? I believe you, you don't need to prove to me that I misunderstood you! Let's just skip that part and move on to explaining what the actual position really is.

It doesn't matter "why I think you said what I said", it just matters that I understand you. So why get into that meaningless debate instead of just asking you to clarify or trying to reinterpret? I don't care about technicalities and I don't care about "winning" against you, and I interpret "justify why you thought I thought that" as a meaningless distraction that only has value in Internet points, not in getting me any closer to understanding what your views are.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#692
post #453

Earlier quoted context omitted.

My personal opinion is if we could spy on all citizens all the time we could stop all or most of the crimes, do we want this? If you say Yes then stop reading here. Else if you say 100% surveillance is too much then what do you have against people discussing where the line should be drawn? Some person that would sign that letter might be fine with video cameras in say a bank or some company building entrance but he i…

This only finds known pictures of child abuse not new ones and especially it doesn't find the perpetrators or prevent the abuse. But it creates a infrastructure for all other kind of "criminal" data. I bet sooner or later governments want to include other hashes to find the owners of specific files. Could be bomb creation manuals, could be flyers against a corrupt regime. The sky is the limit and the road to hell is…

It certainly does help find the perpetrators and prevent abuse. Unlike videos of many other kinks, CSAM distribution is not one-way from a small number of producers to a large number of consumers but is often based on sharing "their own" material.

When we arrest people for "consuming" known old CSAM, we often find new CSAM produced by themselves; the big part of busting online CSAM sharing rings is not the prevention of CSAM sharing but the fact that you do get a lot of actual abusers that way.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#693
post #213

Earlier quoted context omitted.

Anyone who engaged in such a discussion with a non-technical person is going to defacto seem like an advocate for child pornography, similar to how advocating for encryption can easily be twisted to being pro-crime. Having said that, there is an enormous amount of misinformation and fear-mongering about a pretty tame change. This seems like so much ado about very close to nothing. a) They optionally scan messaged pho…

> a) They scan photos for nudity using a NN if the participants are children and in a family (the account grouping), giving children warnings and information if they send or receive such material. A+++ thumbs up. Leave my kids alone. If they want to share photos of themselves naked, it's none of anyone's business except them and maybe me (maybe), certainly not a huge American corporation. Neither me or my kids have i…

> Leave my kids alone.

> If they want to share photos of themselves naked, it's none of anyone's business

What about if adult sexual predators want to share sexually explicit photos with your kids?

My understanding is that this feature isn’t about stopping kids from messaging each other - it’s about giving parents a warning if strangers are trying to groom them.

Also:

“ The Messages feature is specifically only for children in a shared iCloud family account. If you’re an adult, nothing is changing with regard to any photos you send or receive through Messages. And if you’re a parent with children whom the feature could apply to, you’ll need to explicitly opt in to enable the feature. It will not turn on automatically when your devices are updated to iOS 15.”

So basically the furore is based on a misunderstanding.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#694
post #689

Earlier quoted context omitted.

>> 2) We can offer them some kind of compromise solution that may or may not actually address their problem, but will make them feel like it does, and which will in theory make them less likely to try and ban encryption. > Why are those the only two solutions? That seems like a false dichotomy. It's not? It's a real dichotomy. What other solution could there be? 3) Offer a better technical that is less of a compromis…

> When I ask ‘what did I say that made you thunk that’, can you explain why you rarely answer? Okay, sure. When you ask me to try and justify why I think you hold your position, I interpret that as a distraction (hopefully a good faith one). I don't want to argue on a meta-level about why I got confused about your comments, I want to know what you believe. I'm frustrated that you keep trying to dig into "why are you…

>> When I ask ‘what did I say that made you thunk that’, can you explain why you rarely answer?

> Okay, sure.

> When you ask me to try and justify why I think you hold your position,

At this point it’s hard to read you as honest because of the frequency with which you misrepresent me. I have to assume you are unaware of this.

I am talking about why you won’t identify which words of mine lead to your misunderstandings of my position.

Why would you represent that as asking you to ‘justify’ your interpretation? That isn’t what I’m doing, and more importantly it’s not something I said. I’m just asking you to tell me what you are interpreting so I can see if what I said was ambiguous and if so how.

> I interpret that as a distraction (hopefully a good faith one).

A distraction from what? Are you not seeking to understand? Later in this comment you claim to want to know what my views are. If you ignore clarifying questions as a ‘distraction’, it seems likely that misunderstandings will keep arising.

> I don't want to argue on a meta-level about why I got confused about your comments,

Who is asking you to ‘argue on a meta-level’? I am asking you to simply say what words you are referring to when a misunderstanding becomes apparent.

> I want to know what you believe.

I recommend trying to get to the bottom of misunderstandings then.

> I'm frustrated that you keep trying to dig into "why are you confused"

You misrepresent me again. Can you not see that I haven’t asked ‘why are you confused’?

I have asked what you are referring to when you attribute a view to me that I don’t think is contained in what I wrote.

> instead of just clarifying your position.

I could clarify my position if you were willing to tell me what I said that lead to your interpretations of my views.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#695

Earlier quoted context omitted.

Hopefully this is another configurable option that falls under the already very extensive family screen time feature. I understand where you're coming from and respect your position, but I fall on the opposite side. This is something I do want for my kid.

On the Child Safety page one of the dialogs is the opt in (or out) configuration, so it seems, as one would expect, that the adult(s) in the family sharing group get to configure this. And it's a useful, valuable option that many (I would wager the overwhelming majority) parents will enable. Apple made a huge PR mistake announcing both of these systems together (the CP hashing system and the NN message warning system…

> it has led to lots of people conflating and mixing and matching elements of both into a fearsome frankensystems.

I agree they could have slowly walked people through the components one by one, but so much of what is in the comments is pure bad faith that I am not sure that it would have helped.

By “bad faith”, I mean strongly asserting as true claims that people know they haven’t checked, and which later turn out to be false.

In a cynical way this might actually be better PR for Apple. They know they can’t prevent people who dislike them from jumping to the most negative conclusions possible. By presenting these features together and letting the crazy interpretations abound, they make their opponents seem unhinged, and this obscures the real but less apocalyptic concerns.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#696

Earlier quoted context omitted.

Many people share photos of child pornography via the mail. There has been criticism that the USPS does not open all mail and scan them for child pornography. I would really like to hear from people who do not sign this letter how they think about that.

Not sure I'm going to go all in on unqualified support, but it seems like comparing an image to a series of known hashes is qualitatively somewhat different than the postal inspector open all your mail. Though those convenient little scans they'll send you if your mail if you sign up suggests they do have some interest in who sends you mail already.

A closer comparison would be a machine opening your mail, scanning the contents, then using the same perceptual “hash” with an unknown database of “hashes”

If whoever controls that database wants to prohibit say a meme making fun of a politician, they need only to add the picture to the DB.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#697
post #694

Earlier quoted context omitted.

> When I ask ‘what did I say that made you thunk that’, can you explain why you rarely answer? Okay, sure. When you ask me to try and justify why I think you hold your position, I interpret that as a distraction (hopefully a good faith one). I don't want to argue on a meta-level about why I got confused about your comments, I want to know what you believe. I'm frustrated that you keep trying to dig into "why are you…

>> When I ask ‘what did I say that made you thunk that’, can you explain why you rarely answer? > Okay, sure. > When you ask me to try and justify why I think you hold your position, At this point it’s hard to read you as honest because of the frequency with which you misrepresent me. I have to assume you are unaware of this. I am talking about why you won’t identify which words of mine lead to your misunderstandings…

> I could clarify my position if you were willing to tell me what I said that lead to your interpretations of my views.

Okay, holy crud, I'm out. I have zero interest in the evolution of this conversation from a debate about privacy/encryption tradeoffs, into "let's figure out who's arguing in good faith", into "explain to me why you think I'm asking you to explain to me what I'm thinking".

I've made a quick ~$5 donation to Matrix.org (https://imgur.com/a/wVj2neA) in the hope that their current work with on-by-default E2E encryption and P2P community hosting/connections will ideally make this entire conversation irrelevant in the future.

I wish you the best in coming up with your technical solutions.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#698
post #694

Earlier quoted context omitted.

>> When I ask ‘what did I say that made you thunk that’, can you explain why you rarely answer? > Okay, sure. > When you ask me to try and justify why I think you hold your position, At this point it’s hard to read you as honest because of the frequency with which you misrepresent me. I have to assume you are unaware of this. I am talking about why you won’t identify which words of mine lead to your misunderstandings…

> I could clarify my position if you were willing to tell me what I said that lead to your interpretations of my views. Okay, holy crud, I'm out. I have zero interest in the evolution of this conversation from a debate about privacy/encryption tradeoffs, into "let's figure out who's arguing in good faith", into "explain to me why you think I'm asking you to explain to me what I'm thinking". I've made a quick ~$5 dona…

> "explain to me why you think I'm asking you to explain to me what I'm thinking"

Again, not an honest interpretation of anything I have said. What I said was extremely clear.

I think it’s reasonable to conclude that you are deliberately misrepresenting me, and have been all along.

My conclusion is that you aren’t actually an honest person. I’m sorry.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#699
post #3

Please talk to non-tech people around you about this. This overreach simply cannot stand, and from a company that sees success from touting itself as a privacy-centric alternative? These really are some dark times. I imagine that if the world had Stasi fresher in its mind, this would never have happened.

Anyone who engaged in such a discussion with a non-technical person is going to defacto seem like an advocate for child pornography, similar to how advocating for encryption can easily be twisted to being pro-crime. Having said that, there is an enormous amount of misinformation and fear-mongering about a pretty tame change. This seems like so much ado about very close to nothing. a) They optionally scan messaged pho…

As a followup, to be clear on the intentions in my post, while I do think that a lot of the reactions have been over the top (there are numerous comments claiming outright falseshoods about this system, out of either ignorance or to prejudice), that Apple decided to do the CSAM stuff on device is incredibly ill considered.

Do it in the cloud just like every other service does. None of this anger would have happened if they just kept it in the cloud, and I truly can not fathom how this made it this far. I would peg overwhelming odds that they abandon the on device idea as it makes no sense and has brought incredible ill will.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#700

Earlier quoted context omitted.

> " Reducing the real-world occurrences for irrational fears doesn't make those fears go away. " " You're saying it yourself, these people aren't motivated by statistics about abuse, they're frightened of the idea of abuse " We could say the same thing the other way - people up in arms are not frightened by statistics of abuse of a surveillance system, but frightened of the idea of a company or government abusing it.…

> This thread is not full of statistics and data about existing content filtering and surveillance systems and how often they are actually being abused. It is filled with explanations about why the systems you mention are tangibly different from what Apple is proposing. There is a huge difference between scanning content on-device and scanning content in a cloud. That doesn't mean that scanning content in the cloud c…

> "Wait, hold on. Forget literally everything that we were talking about above. This is, like, 90% of what people are criticizing! These are really big concerns!"

My point is your original point - where is the data to support these criticisms, the the facts, the statistics? Merely saying "I can imagine some hypothetical future where this could be terrible and misused" should not be enough to conclude that it is, in fact, terrible, and will more likely than not be misused.

We've had years of leaks showing that three letter agencies and governments simply don't need to misuse things like this. The USA didn't slide down a slope of banning Asbestos for health reasons and end up "oops" banning recreational marijuana. The USA didn't slide down a slippery slope into the Transportation Security Authority after 9/11 it appeared almost overnight, and then didn't slide down a slippery slope into checking for other things, it stayed much the same ever since.

The fact that one can imagine a bad future is not the same as the bad future being inevitable; the fact that one can imagine a system being put to different uses doesn't mean it either will be, or that those uses will necessarily be worse, or that they will certainly be maximum-bad. It's your comment about "fear based reasoning" turned to this system instead of to encryption.

You ask "are you really implying that government surveillance doesn't count as a real slippery slope because sometimes activists reverse the trend?" and I'm saying the position "because slippery slopes exist, this system will slide down it and that's the same as being at the bottom of it" and then expecting the reader to accept that without any data, facts, evidence, stats, etc. is low quality unconvincing commenting, but is what makes up most of the comments in this thread.

> "Where? Here's the second paragraph:"

The paragraph which implies it happens to all photos (not just iCloud ones), and immediately alerts the authorities with no review and no appeal process. There are people in this thread saying "I don't need the FBI getting called on me cause my browser cache smelled funny to some Apple PhD's machine-learning decision" for a system which does not look at browser cacdhe, does not call the FBI, has a review process, does have an appeal process.

> "Holy crud, I would hope this is the bare minimum."

Why would you hope "the bare minimum" the letter could ask for is something the letter is clearly not asking for? Or that the bare minimum from a company known for its secrecy is openness and transparency? It would be nice if it was, yes. I expect it won't be, because we would all have very different legal systems and companies if laws and company policies were created with metrics to track their effectiveness and specified expiry dates and by default only get renewed if they are proving effective.

> "What else are people criticizing?"

My main complaint is that people are asking us to accept criticism such as "Iraq will use this to murder homosexuals" unquestioningly. But still, to quote from people in this thread: "Apple can (and likely will) say they won't do it and then do it anyway." - despite Apple announcing this in public they're going to lie about it, and you should just believe me without me supporting this position in any way. "This will lead to black mailing of future presidents in the U.S." - and you should believe that because reasons. "Made for China" - and you should agree because China is the boogeyman. (Maybe it is, if so justify why the reader should agree). "It's not Apple. It's the government" - because government bad. "Scan phones for porn, then sell it for profit and use it for blackmail. Epstein on steroids" - because QAnon or something, who even knows???. "the obvious conclusion is Apple will start to scan photos kept on device, even where iCloud is not used." - because they said 'obviously' you have to agree or you're clueless, I guess. "I never thought I'd see 'privacy' Apple come out and say we're going to [..] scan you imessages, etc." - and they didn't say that; unless the commentor is a minor which is against the HN guidelines.

It's very largely unreasoned, unjustified, unsupported, panicky worst-case fearmongering even when the concerns could be serious - if justified.

> "Nobody who's willing to bring out "think of the children" as a debate killer has ever dropped the argument because they got a concession."

That is probably true, but probably self-supporting. Someone who honestly uses "think of the children" likely thinks the children's safety is not being thought of enough, and is self-selectedly less likely to immediately turn around and agree the opposite.

> "It means very little to me that the EU says they care about privacy."

Well, the witch is being drowned despite her protests.

> "What real, tangible measures did they include to make sure that in practice encryption would not be weakened?"

Well they didn't /ban/ it for a start; which they could have done as exemplified by Saudi Arabia and Facetime discussed in this thread, and they didn't explicitly weaken it like the USA did with its strong encryption export regulations of the 1990s. Those should count for something in defense of their stated position?

Post reply on HN