Live data from Hacker News

Apple's child protection features spark concern within its own ranks: sources

reuters.com

781–790 of 860 posts

Re: Apple's child protection features spark concern within its own ranks: sources

#781

Earlier quoted context omitted.

Please look more carefully at that document. It says, on page 5: "Instead of scanning images in the cloud, the system performs on-device matching using a database of known CSAM image hashes provided by NCMEC and other child safety organizations." And look at the diagram. The matching of image hashes with user photos occurs "on device."

I know that scanning is done by one’s device. I just think that there are better arguments against it without unnecessary exaggeration. So I wanted to be more specific on which images on your device are scanned according to that paper. Obviously I should have phrased is better, like “about to be uploaded to iCloud”…

I see. I didn't realize that was the distinction you were making, but now I see what you meant.

Just to spell this out (since I think this thread could still be a little confusing):

1. The photo scanning does occur on the device, not in the cloud. However,

2. Apple's explanation indicates that this device-based scanning will only occur on photos that may be uploaded to iCloud.

Re: Apple's child protection features spark concern within its own ranks: sources

#782
I keep hearing the same argument from people, and I'm mostly in agreement, but to summarize the argument:

>"I am not afraid of personally being found with child pornography, but I don't want Apple searching my files looking for criminal intent"

But I would argue that you SHOULD be afraid of personally being found with child pornography.

First and foremost, this feature could be exploited for harm. If anyone ever wants to hurt you, all they have to do is get access to your unlocked Apple device long enough to drop CASM into a backed-up folder, and you get reported to the feds.

Or, way more realistically, maybe you downloaded some amateur porno that you didn't know had underage participants in it, and you saved it where it got backed up to the cloud, and two years later the government has added the video to their known CSAM database and you get reported to the feds for having it.

Given how the mere accusation of child sex crimes is enough to destroy careers, marriages, and lives, I see absolutely no reason anyone should trust their Apple devices with anything should this become normal practice.

And if this becomes normal practice, it follows that CASM won't be the only thing they end up looking for.

Re: Apple's child protection features spark concern within its own ranks: sources

#783
post #771
post #766

Earlier quoted context omitted.

That article is very obviously not about what is being searched for. It's about who it is being reported to. For example, if Apple one day decided to detect unauthorized copyrighted media, they could report it to the RIAA. The RIAA is independent of the government, thus the 4th amendment is not violated.

So then you must agree that the fears of government overreach are unwarranted. Given that’s what most of the complaints here raw about, that’s a big deal. > For example, if Apple one day decided to detect unauthorized copyrighted media, they could report it to the RIAA. The RIAA is independent of the government, thus the 4th amendment is not violated. It’s true that Apple could decide to implement any search or scann…

> What does that have to do with the CSAM mechanism? It seems like an unrelated fear.

He CSAM mechanism proves that Apple can and will go this route, even if users are against that.

Re: Apple's child protection features spark concern within its own ranks: sources

#785
post #576

Earlier quoted context omitted.

> Worst case I'm guilty of extreme snark. That's a really bad worst case, far below the line the guidelines draw. Would you mind reviewing them ( https://news.ycombinator.com/newsguidelines.html ) and taking the intended spirit of the site more to heart? We want thoughtful, curious conversation here, not snark and fulmination. > People get defensive sometimes, so what? The problem is that it evokes worse from others…

> That's a really bad worst case, far below the line the guidelines draw. Would you mind reviewing them ( https://news.ycombinator.com/newsguidelines.html ) and taking the intended spirit of the site more to heart? We want thoughtful, curious conversation here, not snark and fulmination. Please give me the benefit of the doubt that after a decade on HN I have read the guidelines many times and reply to the meat of my…

It did enough to make the point; but in any case, what matters is not the outcome in any one particular case, but the statistical outcome in the long run.

Re: Apple's child protection features spark concern within its own ranks: sources

#786
post #771

Earlier quoted context omitted.

So then you must agree that the fears of government overreach are unwarranted. Given that’s what most of the complaints here raw about, that’s a big deal. > For example, if Apple one day decided to detect unauthorized copyrighted media, they could report it to the RIAA. The RIAA is independent of the government, thus the 4th amendment is not violated. It’s true that Apple could decide to implement any search or scann…

> What does that have to do with the CSAM mechanism? It seems like an unrelated fear. He CSAM mechanism proves that Apple can and will go this route, even if users are against that.

The CSAM mechanism proves that Apple will send information to the RIAA or another non-government entity?

How exactly does it prove that?

Re: Apple's child protection features spark concern within its own ranks: sources

#787
post #705

Earlier quoted context omitted.

> ... to make photo search go evil, or spotlight start reporting files that match keywords for that matter. As your immediate parent has already said: there isn't any process by which an image of a hotdog will be sent to someone else without my knowledge. Neither "photo search" nor "spotlight" report anything to third parties currently.

No, but a ‘bit flip’ could make them do so just as easily as a ‘bit flip’ could make the CSAM detector do something nefarious.

How are you still not getting this?: "search" and "spotlight" do not have the code to report anything to anyone.

Re: Apple's child protection features spark concern within its own ranks: sources

#788

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

If you will believe anything a company says I have a bridge to sell.

Re: Apple's child protection features spark concern within its own ranks: sources

#789

This CSAM Prevention initiative by Apple is a 180 degress change of their general message around privacy. Imagine investing hundreds of millions of dollars in pro-privacy programs, privacy features, privacy marketing, etc... just to pull this reverse card. Of course this is going to spark concern within their own ranks. It's like working for a food company that claims to use organic, non-processed, fair-trade ingredi…

If a grandmother takes a photo of their grandchild in a bathtub this is technically against federal law 18 U.S.C. § 2252. There is no "I am grandma" exception. This is a serious felony with serious consequences. If you use an algorithm without any context I think you are looking at a ton of new 18 U.S.C. § 2252 (child pornography) charges through these scans. These charges are notoriously difficult to defend against…

You seem to be missing the fact that they're only scanning for existing images in a database, not detecting brand new images. Grandma's photo won't be in the database unless she uploads it somewhere that reports it.

Re: Apple's child protection features spark concern within its own ranks: sources

#790

Earlier quoted context omitted.

> Whole point of hashing algorithms is that they produce unique hashes for different inputs. Wouldn't a larger input value (bits of the image) make it harder to have collisions? Standard cryptographic hashes should have certain properties like https://en.wikipedia.org/wiki/Avalanche_effect However, a perceptual hash desires the opposite. Due to the pigeonhole principle, a larger space mapping to a smaller space, invo…

Thanks for that, I still dont get why this is such a big privacy concern for everyone.

You're welcome. I think the crux is that people are worried about the police knocking at their door and/or inspecting their photos due to mismatching on this purportedly unreliable hash method.
Post reply on HN