Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

771–780 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#771
post #766
post #762

Earlier quoted context omitted.

No they don’t. Searches for things other than CSAM would be inadmissible under the 4th amendment. https://www.economist.com/united-states/2021/08/12/a-38-year...

That article is very obviously not about what is being searched for. It's about who it is being reported to. For example, if Apple one day decided to detect unauthorized copyrighted media, they could report it to the RIAA. The RIAA is independent of the government, thus the 4th amendment is not violated.

So then you must agree that the fears of government overreach are unwarranted. Given that’s what most of the complaints here raw about, that’s a big deal.

> For example, if Apple one day decided to detect unauthorized copyrighted media, they could report it to the RIAA. The RIAA is independent of the government, thus the 4th amendment is not violated.

It’s true that Apple could decide to implement any search or scanning mechanism at any time, and report anything they like to anyone they want to. So what? This is true of anyone who writes software that handles user data.

What does that have to do with the CSAM mechanism? It seems like an unrelated fear.

Re: Apple's child protection features spark concern within its own ranks: sources

#772

Earlier quoted context omitted.

That is, it seems like Apple really wanted to preserve "end-to-end" encryption,“ … except they still have not mentioned anything about E2E encryption… and they currently don’t encrypt icloud backups. You would think apple would get ahead of this story and mention … or maybe they don’t have any E2E plans at all.

This blog post got a lot of commentary on HN a couple days ago: https://news.ycombinator.com/item?id=28118350 . iMessages are already E2E encrypted, but you are correct, iCloud backups are decryptable with a warrant (and that was reportedly added at the FBI's request). But I agree with Ben Thompson's point in that blog post, that it's OK to not have strong, unbreakable encryption be the default, and that it's still p…

> But with Apple's CSAM proposal is NOT possible to have an iPhone that Apple isn't continuously scanning

This is not accurate. Scanning doesn’t happen without iCloud photos enabled.

Re: Apple's child protection features spark concern within its own ranks: sources

#773
Is there really anyone who does not see this for what it is, a really transparent effort to introduce surveillance infrastructure under the guise of "saving the children"?

If so, I would love to hear what assures you so much about this.

A couple reasons I don't believe a single word:

* After years of the surveillance state begging and pleading about compromising encryption, they went silent after talks with Apple and Google, over about the very time it can reasonably be expected it would take to develop this "feature".

* The number of pedos this could potentially even catch is supposedly so small that it is a compromise of everyone's rights … an inherent contradiction of not only Constitutional laws, but the very concept of innocence before being proven guilty. Not to mention that we have long been told there are no pedo rings, even in spite of the fact that even without this "feature" the last administration broke up more of these pedo rings than ever before. Why do we need this "feature" now then?

* Any actual pedo rings will easily work around this feature simply by altering images and changing the hash in various ways too numerous to list right now.

* Innocent people could easily be swept up in this if they happen to have images that hash to something the feds are comparing against, within the threshold of tolerance. What happens then, a secret court provides a secret court order to penetrate your network and devices to confirm whether you are a pedo because you took pictures of your grandchildren in a bathing suit?

* oh, did I mention the mountain of history of nothing but abuse and lies and lies and abuse in every single way possible and even to the point that he people exposing the not just illegal acts, but evil acts, are deliberately targeted by the state?

Why anyone would believe Apple, let alone the government that is clearly suspiciously standing in the background, looking away, whistling into the sky trying to act as if it has nothing to do with this, is beyond me. It's all just lies, front to back, top to bottom, left to right and in every other dimension.

What this clearly will be misused for is to identify or fingerprint dissidents and worngthinkers of any kind, including those who thing they are now rightthinkers, who will find themselves on the other side of the divide when they've expended their usefulness.

Re: Apple's child protection features spark concern within its own ranks: sources

#775
post #704

Earlier quoted context omitted.

Apple's system allows the middle to decrypt certain images or "visual derivatives" at least. True E2E doesn't.

I'm suggesting that the client-side CSAM scanning technology could allow Apple to turn on true E2E encryption and still satisfy the government's requirement to report on CSAM which as you point out is not something that Apple currently implements.

The "client side" CSAM detection involves a literal person in the middle examining suspected matches. The combination of that and whatever you think true E2E means isn't E2E by definition.

Re: Apple's child protection features spark concern within its own ranks: sources

#776
post #492

Earlier quoted context omitted.

Should this fact be reassuring or even more frightening ? Because it’s something to push back against governments by saying « I can’t ». But it’s a societal issue if a corporation can say « I don’t want » to a government. It’s really not the same thing and Apple just burned their « I can’t » card and are implying they can just say « no » to governments. Which is quite an even more dystopian thing.

They can say "no" but they have to cope with the fallout from that. The statement from Apple is that they will say no. Whether that actually ever happens is something we will see, one way or another.

Apple won't say no to a court order.

Re: Apple's child protection features spark concern within its own ranks: sources

#777

Earlier quoted context omitted.

Given that they obviously already have the capability to send software updates that add new on-device capability, this seems like a meaningless distinction. It’s already “just policy” preventing them from sending any conceivable software update to their phones.

I disagree, strongly. Let's say you're authoritarian government EvilGov. Before this announcement, if you went to Apple and said "we want you to push this spyware to your iPhones", Apple would and could have easily pushed back both in the court of public opinion and the court of law. Now though, Apple is already saying "We'll take this database of illegal image hashes provided by the government and use it to scan you…

> just Winnie the Pooh memes

I think it's hilarious that one of the world' great nations would scan for exactly this.

Re: Apple's child protection features spark concern within its own ranks: sources

#778

Earlier quoted context omitted.

They can say "no" but they have to cope with the fallout from that. The statement from Apple is that they will say no. Whether that actually ever happens is something we will see, one way or another.

Apple won't say no to a court order.

Of course they won't. The idea of a company refusing to comply with the laws of the countries they operate in purely out of some grand sense of principle just seems naive. Especially if it's the country where HQ is.

Re: Apple's child protection features spark concern within its own ranks: sources

#779

Earlier quoted context omitted.

There are methods for dealing with CP that would maintain privacy, not subject humans to child pornography, and would jive with their end to end encryption goals. But we’ll never know what they’re doing under the hood and I think that’s the concerning part.

Please elaborate on these magical methods.

They're not magical. They're just smart use of cryptography.

Ashton Kutcher's foundation Thorn https://en.wikipedia.org/wiki/Thorn_(organization) does a lot of work in this space. They have hashed content databases, they have suspected and watchlisted IP addresses, etc...

I don't know why I'm being downvoted. This is an active area of cryptography research, and I've applied these types of content checks in real life. You can maintain good privacy and still help combat child pornography.

Sometimes HN takes digital cynicism a step too far.

Re: Apple's child protection features spark concern within its own ranks: sources

#780

In their attempt to make this extra private by scanning 'on device', I think they've managed to make it feel worse. If they scan my iCloud photos in iCloud, well lots of companies scan stuff when you upload it. It's on their servers, they're responsible for it. They don't want to be hosting CSAM. It feels much worse them turning your own, trusty iPhone against you. I know that isn't how you should look at it, but tha…

The practical difference is that with on-device scanning, the system is just a few bit flips away from scanning every photo on your device, instead of just the ones that are about to be uploaded. With server-side scanning, the separation is clear—what's on Apple's server can be scanned, and what's only on your phone cannot. This all plays so perfectly into my long-time fears about the locked down nature of the iPhone…

Yes. This is it. When I wrote the above I couldn’t quite put my finger on why I felt like this but this is the reason. It’s the slippery slope of mine / yours.
Post reply on HN