Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

731–740 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#731

Earlier quoted context omitted.

> But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still possible to use an iPhone without iCloud and get full E2E. I disagree completely on this. For one, users aren't aware that using iCloud means that Apple has your decryption key and can thereby read and share all of your phone's data. And two, opt-out is a dark pattern.…

Indeed, up until reading these comments I had no idea that iCloud wasn’t encrypted. Everything about Apples messaging makes you believe otherwise. That seems pretty disingenuous. Then again, 99% of consumers have very little choice that doesn’t include huddles and complicated setup. We all get the same moon goo, under a differ different brands. Good, bad, or just the fact of life?

> Indeed, up until reading these comments I had no idea that iCloud wasn’t encrypted.

iCloud data is encrypted at rest (edit: except for Mail apparently). The type of encryption (service or end-to-end [E2E]) is specified here: https://support.apple.com/en-us/HT202303

It can be argued that from a user's viewpoint not having E2E encryption is tantamount to not having encryption at all, but from a technical standpoint the data is encrypted.

Re: Apple's child protection features spark concern within its own ranks: sources

#732
post #515

Earlier quoted context omitted.

Why is that supposed to be their responsibility? They (and Google, Microsoft, Facebook, etc.) are essentially mandated reporters; if CSAM is on their servers, they're required to report it. It's like how a doctor is a mandated reporter regarding physical abuse and other issues. Because they're not the police. It isn't their role to enforce the law. They're not enforcing the law; if the CSAM reaches a certain threshol…

> They (and Google, Microsoft, Facebook, etc.) are essentially mandated reporters; if CSAM is on their servers, they're required to report it. I don't think that's correct. My understanding is that if they find CSAM, they're obligated to report it (just like anyone is). I don't believe they are legally obligated to proactively look for it. (It would be a PR nightmare for them to have an unchecked CSAM problem on thei…

Last year Congress mulled over a bill (EARN IT Act) that would explicitly require online services to proactively search for CSAM, by allowing services to be sued by governments for failing to do so. It would also allow services to be sued for failing to provide law-enforcement back doors to encrypted data. There's also SESTA/FOSTA, already in law, that rescinded CDA 230 protection for cases involving sex trafficking.

Quite honestly, my opinion is that any service not scanning for CSAM is living on borrowed time.

Re: Apple's child protection features spark concern within its own ranks: sources

#733
post #564

Earlier quoted context omitted.

Those already doing far worse than banning a consumer electronics company's products? And, in all honesty, there's a lot of those.

I meant in the context of U.S. governments. What Democrat administration wants to ban Apple? What Republican administration wants to ban Apple? Sounds like political suicide on either side: government interference with the country's largest company, an iconic brand, for no reason other than to hopefully spy more on your citizens.

The concern being raised is about some unnamed authoritarian government without US legal norms, though.

Re: Apple's child protection features spark concern within its own ranks: sources

#735

Earlier quoted context omitted.

Indeed, up until reading these comments I had no idea that iCloud wasn’t encrypted. Everything about Apples messaging makes you believe otherwise. That seems pretty disingenuous. Then again, 99% of consumers have very little choice that doesn’t include huddles and complicated setup. We all get the same moon goo, under a differ different brands. Good, bad, or just the fact of life?

> Indeed, up until reading these comments I had no idea that iCloud wasn’t encrypted. iCloud data is encrypted at rest (edit: except for Mail apparently). The type of encryption (service or end-to-end [E2E]) is specified here: https://support.apple.com/en-us/HT202303 It can be argued that from a user's viewpoint not having E2E encryption is tantamount to not having encryption at all, but from a technical standpoint t…

It's encrypted at rest, but Apple has the decryption keys, and will give up your customer data when asked to by the government[1]. Also, iCloud photos are not encrypted[2].

[1] https://www.apple.com/legal/transparency/us.html

[2] https://support.apple.com/en-us/HT202303

Re: Apple's child protection features spark concern within its own ranks: sources

#737
post #574

Earlier quoted context omitted.

Please do not spread misinformation. The system DOES scan your local device for photos that match CSAM hashes that are downloaded to the device. What you probably meant is that currently it is only enabled if you have iCloud Photos enabled (which almost everyone has), but now that the mechanism for client-side scanning is in place there’s nothing preventing them to turn it on later regardless of your user settings.

I don’t like that system, but according to their summary document, CSAM detection system is only (as described today) processing images that are uploaded to iCloud. [1] https://www.apple.com/child-safety/pdf/Expanded_Protections_...

I'll need to see their source before I believe that. Apple ("privacy is a human right") lost their presumption of good faith when they announced that they will automatically notify law enforcement if their algorithms and processes suspect you're doing something naughty on your device.

Re: Apple's child protection features spark concern within its own ranks: sources

#738
post #710
post #583

Earlier quoted context omitted.

Yes, I did. You do realise that CSAM is just a policy control, and there is literally nothing technical from Apple adding non-CSAM content to the same policy and systems? I feel like you may not have actually read the paper in depth. The paper clearly shows this is a generalised solution for detecting content that perceptually matches a database. The "what" is CSAM today, but nothing about the technicals require it t…

You are ignoring how the parts of the technology are used to separate responsibilities. > Apple can literally change it overnight to detect copyrighted content, or Snowden documents, or whatever. No, Apple doesn’t run the database. NCMEC does.

It doesn’t matter where the fingerprints are coming from, they’re all just fingerprints. Today they come from NCMEC. Tomorrow they could be from the Chinese Communist Party.

Re: Apple's child protection features spark concern within its own ranks: sources

#739

Earlier quoted context omitted.

> Indeed, up until reading these comments I had no idea that iCloud wasn’t encrypted. iCloud data is encrypted at rest (edit: except for Mail apparently). The type of encryption (service or end-to-end [E2E]) is specified here: https://support.apple.com/en-us/HT202303 It can be argued that from a user's viewpoint not having E2E encryption is tantamount to not having encryption at all, but from a technical standpoint t…

It's encrypted at rest, but Apple has the decryption keys, and will give up your customer data when asked to by the government[1]. Also, iCloud photos are not encrypted[2]. [1] https://www.apple.com/legal/transparency/us.html [2] https://support.apple.com/en-us/HT202303

> Also, iCloud photos are not encrypted[2].

According to the table on the second link iCloud Photos are encrypted on the server (at rest). Am I missing something?

Re: Apple's child protection features spark concern within its own ranks: sources

#740

In their attempt to make this extra private by scanning 'on device', I think they've managed to make it feel worse. If they scan my iCloud photos in iCloud, well lots of companies scan stuff when you upload it. It's on their servers, they're responsible for it. They don't want to be hosting CSAM. It feels much worse them turning your own, trusty iPhone against you. I know that isn't how you should look at it, but tha…

Don’t second-guess yourself. The viewpoint you express is completely valid. Other child comments have pointed this out, but corporate messaging does not get to tell you how _you_ choose to look at things.
Post reply on HN