Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

711–720 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#711
post #484

Earlier quoted context omitted.

> Large government to Apple: "Please now also create a hash on each photo metadata field including date/time and location. Let us query these. AND BTW, this change must be kept secret. Thanks." How do you know this hasn’t already happened? What does it have to do with the CSAM technology?

How do you know the invisible pink unicorn doesn't exist? You don't, but going after the known bad things is the most effective action you can take. You certainly don't ignore known bad things just because there may be even worse unknown things.

Right, but this isn’t a bad thing. The bad things people are claiming are things they imagine could be done in the future.

Exactly like an Invisible Pink Unicorn.

If you go after imaginary bad things, you will never stop. That is the problem with paranoia.

Re: Apple's child protection features spark concern within its own ranks: sources

#712

Earlier quoted context omitted.

Authoritarian countries are the least of the worries. There's a large class of illegal imagery that is policed in democratic countries: copyrighted media. We are only two steps away from having your phone rat you to the MPAA because you downloaded a movie and stored it on your phone. I can guarantee that some industry bigwigs are salivating at the prospect of this tech. Imagine youtube copyright strikes but local to…

One reason I haven't used itunes in years, and don't use iOS, is that I have a huge collection of mp3s. It's almost all of music which I bought and burned off CDs over decades, and it's become just stupidly difficult to organize your own mp3 collection via Apple's players. Even back in the ipod days, you could put your mp3s on an ipod but you needed piracy ware to rip them back off. I can easily see this leading to p…

You could access the music no problem, just some metadata was messed up.

Re: Apple's child protection features spark concern within its own ranks: sources

#713

Earlier quoted context omitted.

I would not say the slippery slope take doesn't make sense. It is perfectly possible that had no one cried out about this change then the next change would have been: Large government to Apple: "Please now also create a hash on each photo metadata field including date/time and location. Let us query these. AND BTW, this change must be kept secret. Thanks."

> it is possible that had no-one cried about this change, The “UK porn filter” has already been extended to all sorts of “« extremism online »” (to no effect in the capital of knife attacks, it seems — as usual invasive police rights do not equal a reduction of criminality) and it’s already being proposed to be extended to: - Online Harms - Online Safety Bill https://en.wikipedia.org/wiki/Web_blocking_in_the_United_K…

Right. My argument against the slippery slope argument is not that governments won’t make demands.

It’s that if they do, this technology is irrelevant.

Re: Apple's child protection features spark concern within its own ranks: sources

#714
post #431

Earlier quoted context omitted.

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

> …to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. If Apple is surprised by the blowback, it’s entirely Apple’s fault because it didn’t engage with many outside experts on the privacy front. I recall reading either in Alex Stamos’s tweets or Matthew Green’s tweets that Apple was invited before for discussions related to handling CSAM, but it didn’t participate. Sec…

Just because Apple didn’t attend Alex’s mini conference for his contacts does not mean they didn’t engage any privacy experts. Furthermore, Alex is a security expert and not a privacy expert. Finally, if that conference was really pushing the envelope on privacy, where are the innovations from those who did attend? The status quo of CSAM scanning is at least as dangerous as an announcement of an alternative.

Re: Apple's child protection features spark concern within its own ranks: sources

#715

Earlier quoted context omitted.

Because Apple write the software, there will never be a time where they do not at some point have access to the data.

Right, but there is a big difference between them having the software in place already to steal files off a phone for a government, versus a government telling them "you must deploy this new software." In the past Apple has said no to writing any new spyware for the government. They would not be able to say no very easily if the software is already on the devices.

Apple has the software to “steal files off a phone” through iCloud Backup. Whether they do this for governments is a policy matter.

Re: Apple's child protection features spark concern within its own ranks: sources

#716

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

I actually think something else happened, and to be honest I think many at Apple behind this decision are likely pretty surprised by the blowback. That is, it seems like Apple really wanted to preserve "end-to-end" encryption, but they needed to do something to address the CSAM issue lest governments come down on them hard. Thus, my guess is, at least at the beginning, they saw this as a strong win for privacy. As th…

They announced CSAM scanning but would you trust there is no scanning if they said they reversed their decision and eventually gave you E2E? Considering how big the firmware size is and that all images are processed by their APIs and they control both SW and HW they could hide such scanning in the firmware or even hardware if they wanted or were forced to. They could add a new separate microcontroller similar to Secure Enclave which would (in addition to "AI-enhancing" the picture) compute and compare CSAM hash. On a positive match, the main CPU would decrypt and run a hidden reporting code which would report the image over TLS-secured channel with Secure Enclave-backed certificate pinning to prevent any MITM. No one would notice because it would be decrypted only after a positive match and no one could see the image being sent out on a positive match because of TLS. It is not just Apple, though. We currently don't have enough control over our devices, especially smart phones. There are some vendor binary blobs on Android too. Now or in the future, these proprietary, very capable devices are ideal for many types of spying. Stallman warned about this many years ago.

Re: Apple's child protection features spark concern within its own ranks: sources

#717
post #486

Earlier quoted context omitted.

Neither 1 nor 2 are in fact true. Spotlight indexes all kinds of metadata, as does photos search. Adding an agent to upload data from these is easier than extending the CSAM mechanism, and the CSAM mechanism as is is not all that plausible to abuse either technically or socially given how clear Apple’s promises are.

> the CSAM mechanism as is is not all that plausible to abuse either technically or socially given how clear Apple’s promises are. That’s the problem: Apples promise means nothing exactly because it’s so easy to abuse. Apple says they will refuse when asked to scan for anything that is not CSAM. That’s one of those nice ‘technically true’ statements lawyers like to include. Apple will not have to refuse anything, bec…

> And when ‘manually’ checking, they aren’t actually looking at potential CSAM, they are checking the ‘visual derivative’ (whatever that means exactly), basically a manual check if the hashes match.

The visual derivative is enough to tell the difference between a collection of CSAM and say documents, or pictures of protests.

It can’t be abused without Apple’s involvement.

Re: Apple's child protection features spark concern within its own ranks: sources

#718

Its a terrible move for their business, I am already looking for an alternative.

Nice, what have you found so far? I just started a Nextcloud today, 2GB free from most providers listed here: http://nextcloud.com

Ahh, for a cloud, https://trinpod.us :)

Re: Apple's child protection features spark concern within its own ranks: sources

#719

Cancelled my Apple TV+, iCloud. In the process of selling my iPhone and Apple watch. I know it seems crazy but I feel betrayed and this is the only way I can protest this. Will I have less privacy on android? Yes.

I've had a pretty good experience with LineageOS for microG: https://lineage.microg.org/

Re: Apple's child protection features spark concern within its own ranks: sources

#720

This was such a weird way for them to announce that they’re no longer pursuing privacy as a differentiation strategy.

And that's all it ever was, perceived differentiation. They were never truly concerned with privacy ever.

It was easier to dismiss in the past because the evidence to the contrary has been largely circumstantial, of sufficiently dubious origin, or not direct enough for people to accept as proof.

They publicly announced a backdoor this time. They can’t un-invent the capability. You can now prove that Apple is lying about its concern for privacy by citing their own website.

Post reply on HN