Live data from Hacker News

An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

appleprivacyletter.com

701–710 of 713 posts

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#701
post #685

Earlier quoted context omitted.

I saw your blogpost [1] mentioning how the iPhone 12 is likely your last. Have you given any thought since then to what your next smartphone would be? Or if you still use smartphone at all? [1] https://sneak.berlin/20210202/macos-11.2-network-privacy/

I already don't put a SIM in my phone; I use a dumbphone for GSM. I will likely begin using Lineage OS or Graphene. I'll begin testing soon and will probably post what I end up doing, either on my blog or the bbs.

Have you considered Purism and Fairphone or are their specs too underwhelming to consider?

With regards to your laptop, does not being able to use Mac-specific development tools (XCode, etc.) interfere with your work in any way or do you just limit the work you take to ones that are friendlier to Linux?

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#702
post #408

Earlier quoted context omitted.

The Apple feature discussed here is for photos being synched to iCloud Photos. It does not scan arbitrary local content.

> It does not scan arbitrary local content. Yet. Before it was "only content uploaded to iCloud is scanned" and now it's "photos are scanned on-device". That's frog boiling that tomorrow easily becomes "arbitrary files are scanned anywhere on the device".

Only photos being uploaded to iCloud are scanned on device for CE imagery. This is the alternative to having cloud storage having broad decryption ability to do scanning in-service (as say Microsoft, Google, Twitter, and Facebook do)

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#703

Earlier quoted context omitted.

They already can decrypt iCloud photos, why else perform an on-device scan ? If not with the intention to scan all local contents ?

And the matching photo is uploaded upon match. So regardless the photo is uploaded. What's the point again of taking this further step?

That is an EXCELLENT question, fwiw.

They could have just had a local failure. I suspect there were a lot of arguments around this point - should they be making an attempt merely to prevent such content from their servers, or to detect/report behaviors which may be illegal and harmful.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#704
post #568

Earlier quoted context omitted.

Raising awareness won't stop any of this. It's inevitable. We have the technological capacity and institutional interest required to implement it, it will be done, and it will be endemic. Raising awareness is about letting people know so that they might take the necessary precautions if they consider themselves to be at risk of its abuse, and degrades their faith in the institutions that support it.

It doesn’t matter whether they are aware. They can’t take precautions. There are no technical solutions that people can use, and technologists seem to be uninterested in working on them. Apple’s solution is the best on offer. Raising awareness about Facebook’s problems hasn’t harmed Facebook.

Leave the phone at home. That's a technical solution to the police in your pocket.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#705
post #685

Earlier quoted context omitted.

I already don't put a SIM in my phone; I use a dumbphone for GSM. I will likely begin using Lineage OS or Graphene. I'll begin testing soon and will probably post what I end up doing, either on my blog or the bbs.

Have you considered Purism and Fairphone or are their specs too underwhelming to consider? With regards to your laptop, does not being able to use Mac-specific development tools (XCode, etc.) interfere with your work in any way or do you just limit the work you take to ones that are friendlier to Linux?

I run macOS on some of my laptops, connected to the internet only via a VPN router on which I have root and can filter traffic.

Rarely do I need to do macOS-specific stuff though.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#706
post #705

Earlier quoted context omitted.

Have you considered Purism and Fairphone or are their specs too underwhelming to consider? With regards to your laptop, does not being able to use Mac-specific development tools (XCode, etc.) interfere with your work in any way or do you just limit the work you take to ones that are friendlier to Linux?

I run macOS on some of my laptops, connected to the internet only via a VPN router on which I have root and can filter traffic. Rarely do I need to do macOS-specific stuff though.

Laptops with an "s"? How many do you have and how many do you carry on your person? When you say you run MacOS on your laptops, do you mean as a VM or on Apple hardware? Did you keep the M1 laptop you blogger about or did you send it back?

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#707
post #453

Earlier quoted context omitted.

This only finds known pictures of child abuse not new ones and especially it doesn't find the perpetrators or prevent the abuse. But it creates a infrastructure for all other kind of "criminal" data. I bet sooner or later governments want to include other hashes to find the owners of specific files. Could be bomb creation manuals, could be flyers against a corrupt regime. The sky is the limit and the road to hell is…

It certainly does help find the perpetrators and prevent abuse. Unlike videos of many other kinks, CSAM distribution is not one-way from a small number of producers to a large number of consumers but is often based on sharing "their own" material. When we arrest people for "consuming" known old CSAM, we often find new CSAM produced by themselves; the big part of busting online CSAM sharing rings is not the prevention…

I would like to read more about your claims,the problem is this subject is very dangerous , the only things I know about it is from articles that got popular and part of this articles are about innocent people that had their lives destroyed because someone made a mistake(like read an IP address wrong).

A nightmare scenario bould be soemthing like,

- giant tech creates secret algorithm , with secret params and threshold that they can tweak at will

- bad guys reverse it or find a way to make a inocent looking picture to trigger the algorithm

- the previous is used by idiots in chat groups or even DMs to troll you, like SWAT-ing in US , or DDOS and other shjit some "gamers" do to get revenge for losing some multiplayer game.

- consequences innocent person loses his job, family, friends, health etc.

I don't trust giants moderators either, they make mistake or just don't do they job and randomly click stuff.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#708

Earlier quoted context omitted.

> This thread is not full of statistics and data about existing content filtering and surveillance systems and how often they are actually being abused. It is filled with explanations about why the systems you mention are tangibly different from what Apple is proposing. There is a huge difference between scanning content on-device and scanning content in a cloud. That doesn't mean that scanning content in the cloud c…

> " Wait, hold on. Forget literally everything that we were talking about above. This is, like, 90% of what people are criticizing! These are really big concerns! " My point is your original point - where is the data to support these criticisms, the the facts, the statistics? Merely saying "I can imagine some hypothetical future where this could be terrible and misused" should not be enough to conclude that it is, in…

I'm not going to push too hard on this, but I do want to quickly point out:

> Well they didn't /ban/ it for a start [...] and they didn't explicitly weaken it

Does not match up with:

> urges the industry to ensure lawful access for law enforcement and other competent authorities to digital evidence, including when encrypted

If you're pushing a company to ensure access to encrypted content based on a warrant, you are banning/weakening E2E encryption. It doesn't matter what they say their intention is/was, or whether they call that an outright ban, I don't view that as a credible defense.

----

My feeling is that we have a lot of evidence from the past and present, particularly in the EU, about how filtering/reporting laws evolve over time (EU's CSAM filters within the ISP industry are a particularly relevant example here, you can find statements online where the EU leaders argue that expanding the system to copyright is a good idea specifically because the system already exists and would inexpensive to expand). I also look at US programs like the TSA and ICE and I do think their scope, authority, and restrictions have expanded quite a bit over the years. I don't agree that those programs came out of nowhere or that they're currently static.

If you don't see future abuse of this system as credible, or if you don't see a danger of this turning into a general reporting requirement for encrypted content, or if you don't think that it's credible that Apple would be willing to adapt this system for other governments -- if you see that stuff as fearmongering, then fine I guess. We're looking at the same data and the same history of government abuses and we're coming to different conclusions, so our disagreement/worldview differences are probably more fundamental than just the data.

To complain about some of the more extreme claims happening online (and under this article) is valid, but I feel you're extrapolating a bit here and taking some uncharitable readings of what people are saying (you criticize the article for "implying" things about the FBI, and the article doesn't even contain the words FBI). Regardless, the basic concerns (the "chilling effect of surveillance, the chance of slippery slope progression, the nature of proprietary systems, the chance of mistakes and bugs in code or human interception, the blurred line between 'things you own' and 'things you own which are closely tied to the manufacturer's storage and messaging systems'") are enough of a problem on their own. We really don't need to debate whether or not Apple will be willing to expand this system for additional filtering in China.

We can get mad about people who believe that Apple is about to start blackmailing politicians, but the existence of those arguments shouldn't be taken as evidence that the system doesn't still have serious issues.

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#709

Earlier quoted context omitted.

Laptop | Desktop: https://www.dell.com/en-us/work/shop/overview/cp/linuxsystem... Router: https://www.turris.com/en/omnia/overview/ Media Center: https://osmc.tv/vero/ Cloud (Use TrueNAS Scale): https://www.truenas.com/systems-overview/ Phone: https://www.pine64.org/pinephone/ Watch: https://pine64.com/product/pinetime-smartwatch-sealed/ Smart Thermostat: https://hestiapi.com/product/hestiapi-touch-one-free-shippin..…

Is there a Linux Laptop at 2560 x 1600 resolution like Macbooks ? System 76 still runs at 1920x1080. It really makes a difference wrt crisp font rendering and less eye strain.

Most of them I believe should allow you to get HiDPI (aka Retina) displays.

I've been looking at replacing my now 9y-old Macbook Pro (primarily running Manjaro Gnome as my daily driver) with a dedicated Linux laptop, and I've narrowed my selection down to the Lenovo ThinkPad P series or the Framework laptop. For the ThinkPad's, the 4k display (3840 x 2160) is recommended I believe (over the WQHD ones). The Framework laptop comes with a standard 2256 x 1504 display.

- https://www.lenovo.com/us/en/laptops/thinkpad/thinkpad-p/c/t...

- https://frame.work/products/laptop

Re: An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology

#710

Earlier quoted context omitted.

Apple doesn't "scan" iCloud. Not sure what you're talking about. Generally everything in iCloud is E2E encrypted, with the exception of iCloud Backups, where Apple holds onto a decryption key and will use it to comply with subpoenas. But nothing is "scanned," and if you don't use iCloud backup, Apple can't see your data.

iCloud Photos aren’t E2E encrypted, but it’s unlikely they’re scanned for CSAM today because Apple generates effectively 0 references to NCMEC annually.

It's too late to edit my post, but you're right. iCloud Photos are not E2E encrypted, my misunderstanding.
Post reply on HN