Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

741–750 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#741
post #478

Earlier quoted context omitted.

Exactly this. The whole thing is a red herring. If Apple wanted to go evil, they can easily do so, and this very complex CSAM mechanism is the last thing that will help them.

I’ve read your comments, and they are a glass of cold water in the hell of this discourse. This announcement should force people to think about how they are governed - to the extent they can influence it - and double down on Free Software alternatives to the vendor locked reality we live in. Instead, a forum of presumably technically savvy people are reduced to hysterics over implausible futures and a letter to ask A…

Thanks. I couldn’t agree more.

We need both - develop free software alternatives (which means to stop pretending the alternatives are good enough), and to get real about supporting legal and governance principles that would protect against abuses.

If people want to do something about this, these are the only protections.

Re: Apple's child protection features spark concern within its own ranks: sources

#742
post #318

Earlier quoted context omitted.

>As currently implemented, iOS will only scan photos to be uploaded to iCloud Photos. If iCloud Photos is not enabled, then Apple isn't scanning the phone. Except for the "oops, due to an unexpected bug in our code, every image, document, and message on your device was being continuously scanned" mea culpa we will see a few months after this goes live.

The potential for this is overblown and I think a lot of people haven’t taken the time to understand how the system is set up. iOS is not scanning for hash matches and phoning home every time it sees one, it’s attaching a cryptographic voucher to every photo uploaded to iCloud that, if some number of photos represent hash matches (the fact of the match is not revealed until the threshold number is reached), then allo…

> it’s attaching a cryptographic voucher to every photo uploaded to iCloud that, if some number of photos represent hash matches

I see this number very quickly getting set to '1', because the spin in the opposite direction is "What, so you're saying, people get X freebies of CSAM that they can store in iCloud that Apple will never tell anybody about?"

_That_ is a whole other PR disaster.

Re: Apple's child protection features spark concern within its own ranks: sources

#743
post #710

Earlier quoted context omitted.

You are ignoring how the parts of the technology are used to separate responsibilities. > Apple can literally change it overnight to detect copyrighted content, or Snowden documents, or whatever. No, Apple doesn’t run the database. NCMEC does.

It doesn’t matter where the fingerprints are coming from, they’re all just fingerprints. Today they come from NCMEC. Tomorrow they could be from the Chinese Communist Party.

It’s hard to take seriously the complaint that this mechanism would give the Chinese Communist party more power.

Also, in the US, the 4th Amendment protects against the abuse you are talking about:

https://www.economist.com/united-states/2021/08/12/a-38-year...

Re: Apple's child protection features spark concern within its own ranks: sources

#744
post #492

Earlier quoted context omitted.

Apple is a fairly large company, that gives them some monetary leverage over governments. It's not as simple as you make it seem, I think.

Should this fact be reassuring or even more frightening ? Because it’s something to push back against governments by saying « I can’t ». But it’s a societal issue if a corporation can say « I don’t want » to a government. It’s really not the same thing and Apple just burned their « I can’t » card and are implying they can just say « no » to governments. Which is quite an even more dystopian thing.

They can say "no" but they have to cope with the fallout from that.

The statement from Apple is that they will say no. Whether that actually ever happens is something we will see, one way or another.

Re: Apple's child protection features spark concern within its own ranks: sources

#745

Earlier quoted context omitted.

Given that they obviously already have the capability to send software updates that add new on-device capability, this seems like a meaningless distinction. It’s already “just policy” preventing them from sending any conceivable software update to their phones.

I disagree, strongly. Let's say you're authoritarian government EvilGov. Before this announcement, if you went to Apple and said "we want you to push this spyware to your iPhones", Apple would and could have easily pushed back both in the court of public opinion and the court of law. Now though, Apple is already saying "We'll take this database of illegal image hashes provided by the government and use it to scan you…

There is so much disinformation about this with people not being informed. Apple have put out clear documentation, it would be a good idea to read it before fear-mongering.

1) The list of CSAM hashes is that provided by the relevant US government agency, that is it.

2) The project is not targeted to roll out anywhere other than the USA.

3) The hashes are baked into the OS, there is no capability to update them other than on signed and delivered Apple OS updates.

4) Apple has exactly the same leverage with EvilGov as at any other time. They can refuse to do as asked, and risk being ejected from the country. Their stated claim is that this is what will happen. We will see.

Re: Apple's child protection features spark concern within its own ranks: sources

#746

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

Apple is heavy on their advertising. If there's a way to spin it, they will

They’re certainly trying. But the video of Craig trying to use a novel definition of “law enforcement backdoor” and accusing people of being confused is contemptibly dishonest.

Re: Apple's child protection features spark concern within its own ranks: sources

#747

Earlier quoted context omitted.

Indeed, up until reading these comments I had no idea that iCloud wasn’t encrypted. Everything about Apples messaging makes you believe otherwise. That seems pretty disingenuous. Then again, 99% of consumers have very little choice that doesn’t include huddles and complicated setup. We all get the same moon goo, under a differ different brands. Good, bad, or just the fact of life?

> Indeed, up until reading these comments I had no idea that iCloud wasn’t encrypted. iCloud data is encrypted at rest (edit: except for Mail apparently). The type of encryption (service or end-to-end [E2E]) is specified here: https://support.apple.com/en-us/HT202303 It can be argued that from a user's viewpoint not having E2E encryption is tantamount to not having encryption at all, but from a technical standpoint t…

This is more from Schneier's book, but I would say the most import reason E2E encryption should be the default is that in the event of a data breach, nothing would be lost. If a company's servers are hacked, they'd have access to the symmetrical encryption keys, and therefore all of the data. It also ensures that the company can't be selling/sharing your data, as they don't have access to it in the first place.

Edit: I also meant iCloud backups in my original post and how Apple can decrypt your E2E encrypted iMessages with the key the backups contain. But I posted it last night and couldn't edit it once I caught the error. It would be amazing for other iCloud services to have E2E encryption so long as the implications of iCloud backups having your encryption keys is stated front and center when choosing to opt-in.

Re: Apple's child protection features spark concern within its own ranks: sources

#748

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

I don't think this is a good metaphor. You still get the privacy same privacy aspect as you did before. Only your iCloud images are now being scanned for visual matches. If you are already trusting Apple with rest of your private life this hardly is complete 180 degree turn. I don't quite understand why people are so against this. What if some algorithm scans your images? If you are using any cloud service to share y…

> why wouldn't we trust that these image hashes can't be reversed back into images?

You should avoid making political or moral arguments when your technical knowledge is 10 feet below your ego. An image is orders of magnitude larger than a password, meaning that many more collisions. Also, because it's a perceptual hash, even more collisions. One does not simply reverse a perceptual hash. Keep your hat on ;-)

Re: Apple's child protection features spark concern within its own ranks: sources

#749
post #285

Earlier quoted context omitted.

Send it via WhatsApp where it gets added to photos and later iCloud by default if I recall correctly

Citation desperately needed.

Try it? I'm not Wikipedia, first party research is allowed. Go for it

Re: Apple's child protection features spark concern within its own ranks: sources

#750
post #167

I just do not want Apple scanning my phone for the purpose of finding something they can send to the police. I’m not even talking about any “slippery slope” scenarios and I’ll never have any of the material they are looking for. And right or wrong, I don’t really fear a false identification, so this isn’t about a worry that they will actually turn me in. I just don’t want them scanning my phone for the purpose of tur…

> I just do not want Apple scanning my phone for the purpose of finding something they can send to the police. Yes. This is called vigilantism.[1] Apple is proposing to become a vigilante. 1. https://en.wikipedia.org/wiki/Vigilantism "Vigilantism is the act of enforcement, investigation or punishment of perceived offenses without legal authority."

Except that they do have the legal authority to do so. See 18 U.S.C. section 2258A(a)(1)(A)(ii). https://www.law.cornell.edu/uscode/text/18/2258A
Post reply on HN