Live data from Hacker News

One Bad Apple

hackerfactor.com

81–90 of 557 posts

Re: One Bad Apple

#81
post #47

This feels like missing the forest from the trees — Steve Jobs said many times to the effect ‘it doesn’t matter how any of this stuff happens, GigaHertz, Ram, Speeds, it only matters that the user gets what they want.’ Right now Apple’s biggest unhappy user is the DOJ. As it stands with the legislation coming down the pipe and both previous administrations building on a keenness to ‘get something done’ about big tech…

Why do elected officials act as fake representatives to the people that elected them in the first place? Has it always been this way? It doesn’t matter left or right. The governing bodies should obey the people not the other way around.

I can't say this for certain, but I suspect most people are actually happy about this sort of thing; their elected representatives are doing exactly what they want.

Re: One Bad Apple

#82
post #47

Earlier quoted context omitted.

Why do elected officials act as fake representatives to the people that elected them in the first place? Has it always been this way? It doesn’t matter left or right. The governing bodies should obey the people not the other way around.

If the people had their way, those suspected of child sex crimes wouldn’t even get trials. Things like privacy and due process only exist to the extent that a ruling class has the power to impose their own values, contrary to popular will.

I’m one of the people and that’s not my way.

I wonder where you got your data from.

Re: One Bad Apple

#83
post #3

> To reiterate: scanning your device is not a privacy risk, but copying files from your device without any notice is definitely a privacy issue. Not a lawyer, but I believe this part about legality is inaccurate, because they aren’t copying your photos without notice. The feature is not harvesting suspect photos from a device, it is attaching data to all photos before they are uploaded to Apple’s servers. If you’re n…

> they’re not knowingly transferring CSAM, because the system is designed only to notify them when a certain “threshold” of suspect images has been crossed

And when they’re notified, Apple manually checks (a modified but legible version of) the images.

Re: One Bad Apple

#84
post #2

This reads like a failure of the NCMEC, and the legal system surrounding it. It is insane that using perceptual hashes is likely illegal. As the hashes are actually somewhat reversible and so possession of the hash is a criminal offence. It just shows how twisted up in itself the law is in this area. One independent image analysis service should not be beating reporting rates of major service providers. And NCMEC sho…

> And NCMEC should not be acting like detection is a trade secret.

It feels to me like they want to hide their detection algorithms so people don't find out how bad they are.

Re: One Bad Apple

#86
post #66

Earlier quoted context omitted.

That code is not accessible to us. The report to NCMEC would be generated by Apple after they have manually reviewed the derived images included in the security vouchers your device submitted after it analysed your photos.

> That code is not accessible to us. Not to tools like IDA and Ghidra

No, the tool that reports to NCMEC is on Apple employee workstations (or a private server). The stuff running in the iPhone essentially just flags things as possibly-CSAM, after which someone at Apple verifies it.

Now, I suppose you could DDoS Apple's verification process.

Either way, though, it's not like anyone who would do either of these things would win any points in the court of popular opinion. I can see the headlines now: "Hackers Disable Apple's CSAM Reporting Tools; Legitimate CSAM Reports Get Lost".

Re: One Bad Apple

#87
I've been a FOSS dev for 25 years and I remember when everyone else I worked with were avid linux/freeBSD users because 'we didn't trust the big end of town'.. over the years I've watched the vast majority of devs move to apple devices for all sorts of 'just works', 'shinier' reasons that just boil down to 'convenience is more important than privacy'.

Perhaps this is just the benefit of longevity but from my POV it was engineer early adoption and advocacy that made Apple, Google Search etc what they are, and it will be engineer early adoption and advocacy that dethrones these problematic companies from controlling the ecosystem..

Back 20 years ago, before the community filled with $_$ dollars-struck startup founders, software was built by people who wanted to use it.. rather than sell it. There are still some people doing this now, Look at Matrix network for instance.

What will it take for a grass-roots software industry to start building privacy-first apps and systems that don't suck, based on decentralised, distributed principles? We have the skills to build highly polished alternatives to these things, but it takes a determination to step away from convenience for a period of time for the sake of privacy.

How bad does it have to get before the dev community realise this? or are we in a frog boiling slowly scenario and it's hopeless?

Re: One Bad Apple

#88
I don't see many people pushing back on the child pornography laws themselves that are the cause of this. I'm stepping into a hornets nest by even bringing this up, because any criticism of the laws on the books makes one look they're a pedo, so I'll preface by saying, child pornography (filmed with actual kids) is vile and disgusting, but it is the production of it that is evil to be fought and suppressed, not the possession of it. Remember in the 90s, we had to deal with the Communications Decency Act I & II, because every time they want to crack down on the internet, the excuse is always "it's for the children!" And pedophilia is the go-to excuse in a lot of circumstances.

The CPPA had bans on virtual child porn (e.g. using look-alike adult actresses or CGI), that was overturned by SCOTUS, and then Congress responded with the PROTECT act which tightened up those provisions. These laws on possession are practically unenforceable with modern technology, peer to peer file sharing, onion routing, and encrypted hard drives.

Thus, in order to make them enforcement, the government has to put surveillance at all egress and ingress points of our private/secure enclaves, whether it's at the point of storing it locally, or the point of uploading it to the cloud.

While I agree with the goal of eliminating child porn, should it come at the cost of an omnipresent government surveillance system everywhere? One that could be used for future laws that restrict other forms of content? How about anti-vax imagery? Anti-Semitic imagery? And with other governments of the world watching, especially authoritarian governments, how long until China, which had a similar system with Jingwang Weishi (https://en.wikipedia.org/wiki/Jingwang_Weishi) starts asking: hey, can you extend this to Falun Gong, Islamic, Hong Kong resistance, and Tiananmen square imagery? What if Thailand passes a law that requires Apple to scan for images insulting to the Thai Monarch, does Apple comply?

This is a very bad precedent. I liked the Apple that said no to the FBI instead of installing backdoors. I'd prefer if Apple get fined, and battle all the way to the Supreme Court to resist this.

Re: One Bad Apple

#89

Earlier quoted context omitted.

If the people had their way, those suspected of child sex crimes wouldn’t even get trials. Things like privacy and due process only exist to the extent that a ruling class has the power to impose their own values, contrary to popular will.

I’m one of the people and that’s not my way. I wonder where you got your data from.

This made me come up with a thought experiment. If you sampled a thousand parents and asked them if they think sex offenders deserve a fair and just trial, what do you think the result would be?

Re: One Bad Apple

#90
post #79

Earlier quoted context omitted.

These are not “claims.” The process by which they get access to only the safety vouchers for images matching CSAM is private set intersection and comes with a cryptographic proof. In no step of the proposal does Apple access the images you store in iCloud. All access is through the associated data in the safety voucher. This design allows Apple to switch iCloud storage to end to end encrypted with no protocol changes…

What good is end to end encryption if the OS is prebuilt with a method of breaking that encryption? This is definitional backdooring, and you’re back to trusting Apple’s goodwill (and/or willingness to resist governments) to keep your data safe (I.e., not add new decryptable triggers). Not having backdoors is a hard requirement for end to end encryption offering privacy guarantees.

This is taking the discussion into the realm of hypothetical. If we end up in a world where there are reliable public cloud providers that offer end to end encryption with no content scanning whatsoever, I'll be glad to give them my money.
Post reply on HN