32 ms·
Apple's plan to “think different” about encryption opens a backdoor to your life
- trangus_1985 5y agoI've been maintaining a spare phone running lineage os exactly in case something like this happened - I love the apple watch and apple ecosystem, but this is such a flagrant abuse of their position as Maintainers Of The Device that I have no choice but to switch. Fortunately, my email is on a paid provider (fastmail), and my photos are on a NAS, I've worked hard to get all of my friends on Signal. While I still use google maps, I've been trialing out OSM alternatives for a minute. The things they've described are in general, reasonable and probably good in the moral sense. However, I'm not sure that I support what they are implementing for child accounts (as a queer kid, I was terrified of my parents finding out). On the surface, it seems good - but I am concerned about other snooping features that this portents. However, with icloud photos csam, it is also a horrifying precedent that the device I put my life into is scanning my photos and reporting on bad behavior (even if the initial dataset is the most reprehensible behavior). I'm saddened by Apple's decision, and I hope they recant, because it's the only way I will continue to use their platform.
- 2OEH8eoCRo0 5y ago>While I still use google maps You can still use Google Maps without an account and "incognito". I wish they'd allow app store usage without an account though- similar to how any Linux package manager works.
- trangus_1985 5y agoThat's not really the issue. The issue is that for google maps to work properly, it requires that the Play services are installed. Play services are a massive semi-monolithic blob that requires tight integration with Google's backend, and deep, system-level permissions to operate correctly. I'm not worried about my search history.
- 2OEH8eoCRo0 5y agoAhhh, gotcha. Did not realize that. Makes sense.
- boring_twenties 5y agoLast I checked (about a year ago), the Google Maps app did work with microG (a FOSS reimplementation of Google Play Services).
- trangus_1985 5y agoI use maps on my phone on a regular basis - I would vastly prefer to have something less featured and stable versus hacking the crap out of my phone. But that's good to know.
- andrepd 5y agoOsmAnd is an absolutely brilliant map app for android. Very fully featured but also pleasant to use (though I dislike some of the defaults).
- d110af5ccf 5y agoHave you tried either of these? https://f-droid.org/en/packages/net.osmand.plus/ https://f-droid.org/en/packages/net.osmand.plus/ https://f-droid.org/en/packages/app.organicmaps/ https://f-droid.org/en/packages/app.organicmaps/
- brundolf 5y agoOne workaround is to use the mobile web app, which is surprisingly pretty decent for a web app. And because it's a web app, you can even disable things like sharing your location if you want to
- techrat 5y agoPeople need to remember that most of Android got moved into Play Services. It was the only way to keep a system relatively up to date when the OEMs won't update the OS itself. Yeah, it's a dependency... as much as the Google Maps APK needing to run on Android itself.
- opan 5y agoIn addition to F-Droid, you can get Aurora Store (which is on F-Droid) which lets you use an anonymous login to get at the Play Store. I use it for a couple free software apps that aren't on F-Droid for some reason.
- C19is20 5y agoWhat are the apps?
- opan 5y agoBoth are for marking anime. One for MAL[0], one for Kitsu[1]. [0] https://github.com/Drutol/MALClient https://github.com/Drutol/MALClient [1] https://github.com/hummingbird-me/kitsu-mobile https://github.com/hummingbird-me/kitsu-mobile
- sunshineforever 5y agoI also recommend Aurora Store as a complete replacement for the Play store. The one thing is that I've never tried using apps that I paid for on it but it works very well for any free apps. There is an option to use a Google account with Aurora but I've only ever used the anonymous account. The only slight dowbside is that I haven't figured out how to auto update appd, so your apps will get out of date without you being notified and you have to manually do it. This problem might literally be solved by a simple setting thay I haven't bothered to look for, IDK. On the plus side it includes all the official play store apps, along side some that aren't allowed by play store. For examples, Newpipe, the superior replacement YouTube app that isn't allowed on play store due to it subverting advertisements and allowing a few features that are useful for downloading certain things.
- _red 5y agoYes, my history was Linux 95-04, Mac 04-15, and now back to Linux from 2015 onwards. Its been clear Tim Cook was going to slowly harm the brand. He was a wonderful COO under a visionary CEO-type, but he holds no particular "Tech Originalist" vision. He's happy to be part of the BigTech aristocracy, and probably feels really at home in the powers it affords him. Anyone who believes this is "just about the children" is naive. His chinese partners will use this to crack down on "Winnie the Poo" cartoons and the like...before long questioning any Big Pharma product will result in being flagged. Give it 5 years at max.
- ursugardaddy 5y agoyou make that sound like a bad thing, I'd love to live in a world without child abuse spreading rampant on the internet and not having to suffer though what passes for political speech (memes) these days. maybe once we detect and stop stuff like this from happening before it gets very bad, we can grow as a society and adjust our forms of punishment accordingly too
- withinboredom 5y agoI don’t think anyone is arguing that making it harder to abuse children is a bad thing. It’s what is required to do so that is the bad thing. It’d be like if someone installed microphones all over every house to report on when you admit that you’re guilty to bullying. No one wants bullying, but I doubt you want a microphone recording everything and looking for certain trigger words. Unless you have an Alexa or something, then I guess you probably wouldn’t mind that example.
- jcrites 5y agoAlexa and iPhones with Siri enabled, and Android phones, are all continuously listening with their microphones for their wake word, unless you've specifically turned the feature off. The difference is that the Alexa connects to your wifi, so if you wanted to, you could trivially tell if it's communicating when it shouldn't be. When I worked at Amazon, I was given the impression that the system that handles detecting the wake word was implemented in hardware, and the software system that does the real speech recognition doesn't "wake up" or gain access to the audio channel unless the wake word is detected by that hardware system -- and it's very obvious when you've woken it up (the colored ring lights up, it speaks, etc.) Echo devices also sit in one room. If you're like most people you take your phone everywhere, which means that if it's spying on you, it could literally have a transcript of every word you spoke the entire day, as well as any people you've been around. To make matters worse, it would be difficult to tell if that was happening. Unless you're an uber-hacker who knows how to root an iPhone, or a radio geek who knows enough to monitor their device's cellular transmissions, good luck figuring out whether Siri is listening to and passing on audio that it shouldn't. The problem is that phones have so many apps and responsibilities -- given that they are essentially full computers -- these days that nonstop data transfer on a wifi network from my phone wouldn't be alarming: it might be backing up pictures to a cloud, or syncing the latest version of apps, etc. I think the dedicated devices like Echo/Alexa are what you should buy if you're the most privacy-sensitive, since they have zero reason to be uploading to the Internet unless you're actively talking to them, and they have zero reason to be downloading unless they're receiving a software patch, which should be very rare. And because they're on your wifi (not cell) you can monitor their network traffic very easily.
- rasengan 5y agoYour original post said postmarketOS. That is weird that you changed it to lineage (and misspelled that).
- trangus_1985 5y agoYeah, sorry, I mixed them up in my head. I'm currently running Lineage on a PH-1, not Postmarket. I would not consider what I have set up to be "production ready", but I'm going to spend some time this weekend looking into what modern hardware can run Lineage or other open mobile OSes
- hsousa 5y agoLineage OS is 100% production ready, it's been my daily driver for almost 2 years and I've been Google and apple - free since.
- trangus_1985 5y agoSorry, wasn't ripping on Lineage. It's more the entire ecosystem. I mentioned in prior comments, but I think that in a few years we'll have a practical, open source, third party in the mobile phone os wars - one that has reasonable app coverage. I don't care if I use google or apple services, btw, I just want the data flow to be on my terms.
- trangus_1985 5y agoOh hey wait you're the freenode guy. While we're on the topic of hostile actions by a platform provider...
- rasengan 5y agoDoesn’t change that you’re a liar.
- noasaservice 5y agoHe's uh, a prince, or something. (Probably got the crown out of a cereal box.) But from the looks of his numbers ( https://upload.wikimedia.org/wikipedia/commons/8/83/IRC_top_10_networks_2021.png https://upload.wikimedia.org/wikipedia/commons/8/83/IRC_top_... ) he's doing a real bang-up job!
- Saris 5y agoI think no matter what devices you use, you've nailed down the most important part of things which is using apps and services that are flexible, and can be easily used on another platform.
- trangus_1985 5y agoI knew that eventually it'd probably matter what devices I used, I just didn't expect it to be so soon. But yeah, I could reasonably use an iphone without impact for the foreseeable future with some small changes.
- threatofrain 5y agoWhat is your home NAS setup like?
- trangus_1985 5y agoFreenas, self-signed tightly-scoped CA installed on all of my devices. 1TBx4 in a small case shoved under the stairs. tbh, i would vastly prefer to use a cloud based service with local encryption - I'm not super paranoid, just overly principled
- voltaireodactyl 5y agoIf you haven’t already heard of it, cryptomator might be just what you’re after.
- quest88 5y agoWhat do you use to sync phone photos to your NAS? I like Google Photos' smartness, but I also want my photos on my Synology NAS.
- _arvin 5y agoTake a look at https://internxt.com https://internxt.com. Been using them for a couple weeks and am incredibly impressed. Great team, great product, just great everything. It was exactly what I was looking for
- lcfcjs 5y agoFound the paedo.
- Andrew_nenakhov 5y agoSignal is still a centralised data silo where by default you trust CA to verify your contacts identify.
- trangus_1985 5y agoYeah, but it's also useful for getting my friends on board. I think it's likely that I eventually start hosting matrix or some alternative, but my goal is to be practical here, yet still have a privacy protecting posture.
- Sunspark 5y agoYour friends aren't going to want to install an app to have it connect to trangus_1985's server. Be happy just getting them on Signal.
- trangus_1985 5y agoMy friends are significantly more technical (and paranoid) than the average user. We've already discussed it. But... yeah. Yeah. Which is why I got as many people on Signal as I could. Baby steps. The goal here, right now, is reasonable privacy, not perfection.
- Sunspark 5y agoWell said, as I like to point out sometimes, Signal is a privacy app not an anonymity app.
- playguardin 5y agoWhat is matrix?
- chimeracoder 5y ago> Signal is still a centralised data silo where by default you trust CA to verify your contacts identify. You can verify the security number out-of-band, and the process is straightforward enough that even nontechnical users can do it. That's as much as can possibly be done, short of an app that literally prevents you from communicating with anyone without manually providing their security number.
- LazyR0B0T 5y agoOrganic Maps on Fdroid is a really clean osm based map.
- JackGreyhat 5y agoNearly the same as MagicEarth...I use it all the time.
- crocodiletears 5y agoDoes it let you select from multiple routes? I've been using Pocketmaps, but it only gives you a single option for routing, which can lead to issues in certain contexts
- Sunspark 5y agoI'm impressed, it actually has smooth scrolling unlike OsmAnd which is very slow loading tiles in. Critical points I'd make about Organic Maps, I'd want a lower inertia setting so it scrolls faster, and a different color palette.. they are using muddy tones of green and brown.
- m-p-3 5y agoAnd I also invite everyone to contribute to OSM through StreetComplete, it's quite intuitive and it adds something to look for when taking a walk.
- alksjdalkj 5y agoHave you found any decent google maps alternatives? I'd love to find something but nothing comes close as far as I've found. Directions that take into account traffic is the big thing that I feel like nobody (other than Apple, MS, etc.) will be able to replicate. Have you tried using the website? I've had some luck with that on postmarketOS, and it means you don't need to install Play services to use it.
- manuelmagic 5y agoI'm using since many years HERE Maps https://wego.here.com/ https://wego.here.com/
- krobbn 5y agoI really like Here WeGo, and it allows you to download maps for specific countries too to have available offline.
- nickexyz 5y agoOrganic maps is pretty good: https://github.com/organicmaps/organicmaps https://github.com/organicmaps/organicmaps
- beermonster 5y agoOsmAND
- cle 5y agoUnfortunately with SafetyNet, I feel like an investment into Android is also a losing proposition...I can only anticipate being slowly cut off from the Android app ecosystem as more apps onboard with attestation. We've collectively handed control of our personal computing devices over to Apple and Google. I fear the long-term consequences of that will not be positive...
- trangus_1985 5y agoI don't think it's implausible that I carry around a phone that has mail, contacts, calendars, photos, and private chat on it. And then, have a second, older phone that has like Instagram and mobile games. It's tragic.
- sodality2 5y agoUnfortunately a big bulk of the data they profit off of is simply the ads and on-platform communication and behavior. Doesn't really matter if you use a different device if you still use the platform. Sure, it's slightly better, but it really isn't a silver bullet if you're still using it. And this is coming from someone who does this already.
- trangus_1985 5y agoI don't really mind if they make a profit off of the free things I use. What I mind is when my personal life, the stuff that _actually_ matters, is being monitored or has a backdoor that allows ANY third party easy access to monitor it.
- techrat 5y agoLoosing sight of the forest for this one tree. 1) Google doesn't release devices without unlockable bootloaders. They have always been transparent in allowing people to unlock their Nexus and Pixels. Nexus was for developers, Pixels are geared towards the end user. Nothing changed with regards to the bootloaders. 2) Google uses Coreboot for their ChromeOS devices. Again, you couldn't get more open than that if you wanted to buy a Chromebook and install something else on it. 3) To this day, app sideloading on Android remains an option. They've even made it easier for third party app stores to automatically update apps with 12. 4) AOSP. Sure, it doesn't have all the bells and whistles as the latest and greatest packaged up skin and OS release, but all of the features that matter within Android, especially if you're going to de-Google yourself, are still there. Any one of those points, but consider all four, and I have trouble understanding why people think REEEEEEEE Google. So you can't play with one ball in the garden (SafetyNet), you've still got the rest of the toys. That's a compromise I'm willing to accept in order to be able to do what I want to and how I want to do it. (Eg, Rooting or third party roms.) If you don't like what they do on their mobile OS, there's nothing that Google is doing to lock you into a Walled Garden to where the only option you have is to completely give up what you're used to... ...Unlike Apple. Not one iOS device has been granted an unlockable bootloader. Ever.
- new_realist 5y agoThe argument from reactionary HN neckbeards is basically, "can't you see that this _could_ be used for great evil?" No shit. That's obvious to just about... everyone on the planet. Many things in this world can be used for great evil: knives, gasoline, guns, TNT, cars--even most household items when used with creativity. It is quite impossible to create something which can't be abused in some form. But society still allows them, because it judges that the good outweighs the bad, and systems exist to manage the risk of evil use. In this case, I have every expectation that this scanning will be auditable, and society will eventually work out most of the imperfections in systems like these, and strike the right balance to make the world a better place.
- deleted 5y ago[deleted]
- artimaeis 5y agoIt's not the device that's less secure or private in this context, it's the services. There's no reason you couldn't just continue using your NAS for photo backup and Signal for encrypted-communications completely unaffected by this. Apple seems to not have interest in users devices, which makes sense -- they're not liable for them. They _do_ seem interested in protecting the data that they house, which makes sense, because they're liable for it and have a responsibility to remove/report CSAM that they're hosting.
- deleted 5y ago[deleted]
- adriancr 5y agoSo they should do that scanning server side at their boundary instead of pushing software to run on phones with potential to extend scope later if no push back.
- gowld 5y agoThey don't want to do it serve side because they don't want to see your unencrypted data!
- adriancr 5y agoWell good thing they're looking at it anyway client side...
- dustyharddrive 5y agoApple already holds the key to iCloud Photos content, and regularly responds to search warrants.
- trangus_1985 5y agoThat's not the issue. The issue is that they have shipped spyware to my device. That's a massive breach of trust. I suspect that this time next year, I'll still be on ios, despite my posturing. I'm certainly going to address icloud in the next few weeks - specifically, disusing it. However, I would be surprised if I'm still on ios a year or two after that. What Apple has done here isn't horrible in the absolute sense. Instead, it's a massive betrayal of trust with minimal immediate intrusiveness; and yet, a giant klaxon that their platform dominance in terms of privacy is coming to an end
- JumpCrisscross 5y ago> with icloud photos csam, it is also a horrifying precedent I'm not so bugged by this. Uploading data to iCloud has always been a trade of convenience at the expense of privacy. Adding a client-side filter isn't great, but it's not categorically unprecedented--Apple executes search warrants against iCloud data--and can be turned off by turning off iCloud back-ups. The scanning of childrens' iMessages, on the other hand, is a subversion of trust. Apple spent the last decade telling everyone their phones were secure. Creating this side channel opens up all kinds of problems. Having trouble as a controlling spouse? No problem--designate your partner as a child. Concerned your not-a-tech-whiz kid isn't adhering to your house's sexual mores? Solved. Bonus points if your kid's phone outs them as LGBT. To say nothing of most sexual abuse of minors happening at the hands of someone they trust. Will their phone, when they attempt to share evidence, tattle on them to their abuser? Also, can't wait for Dads' photos of their kids landing them on a national kiddie porn watch list.
- mojzu 5y agoIf The Verge's article is accurate about how/when the CSAM scanning occurs then I don't have a problem with that, sounds like they're moving the scanning from server to client side, the concerns about false positives seem valid to me but I'm not sure the chance of one occurring has increased over the existing icloud scanning. Scope creep for other content scanning is definitely a possibility though so I hope people keep an eye on that I'm not a parent but the other child protection features seem like they could definitely be abused by some parents to exert control/pry into their kids private lives. It's a shame that systems have to be designed to prevent abuse by bad people but at Apple's scale it seems like they should have better answers for the concerns being raised
- SquishyPanda23 5y ago> sounds like they're moving the scanning from server to client side That is good, but unless a system like this is fully open source and runs only signed code there really aren't many protections against abuse.
- 5y ago
- bambax 5y ago> probably good in the moral sense How, how is it even morally good?? Will they start taking pictures of your house to see if you store drugs under your couch? Or cook meth in your kitchen?? What is moral is for society to be in charge of laws and law enforcement. This vigilante behavior by private companies who answer to no one is unjust, tyrannical and just plain crazy.
- tekknik 5y ago> Will they start taking pictures of your house to see if you store drugs under your couch? Or cook meth in your kitchen?? How many people have homepods? When will they start listening for illegal activity?
- pjerem 5y agoNo worries, it's totally local voice recognition ! We'll only send samples when you speak about herbs.
- OJFord 5y ago> While I still use google maps I use Citymapper simply because I find it better (for the city-based journeys that are my usual call for a map app) - but it not being a Google ~data collection device~ service is no disadvantage. At least, depending why you dislike having everything locked up with Google or whoever I suppose. Personally it's more having everything somewhere that troubles me, I'm reasonably happy with spreading things about. I like self-hosting things too, just needs a value-add I suppose, that's not a reason in itself for me.
- biztos 5y agoI’ve been thinking about switching my main email to Fastmail from Apple, for portability in case the anti-power-user trend crosses my personal pain threshold. But if your worry is governments reading your mail, is an email company any safer? I’m sure FM doesn’t want to scan your mail for the NSA or its Australian proxy, but do they have a choice? And if they were compelled, would they not be prevented from telling you? “We respect your privacy” is exactly what Apple has been saying.
- vineyardmike 5y agounfortunately, self hosting is a pretty clear alternative. Not much else seems to be.
- dustyharddrive 5y agoI think self-hosting email has too many downsides (spam filtering, for example) to be worth it; I’m more concerned about losing my messages (easily solved with POP or mbox exports while still using a cloud account) than government data sharing. Email is unencrypted in transit anyway, and it’s “industry standard” to store it in clear text at each end.
- mackrevinack 5y agothere's always protonmail which is supposedly e2e, so they shouldn't be able to scan your mail
- trangus_1985 5y ago> if your worry is governments reading your mail complicated. As long as they require a reasonable warrant (ha!), I'm fine. Email is an inherently insecure protocol and ecosystem, anyways. I haven't used email for communication that I consider to be private for a while - I've moved most, if not all, casual conversation to signal, imessage. Soon, I hope to add something like matrix or mattermost into the mix. My goal was never to be perfect. My goal is to be able to easily remove myself from an invasive spyware ecosystem, and bring my friends along, with minimal impact.
- neop1x 5y agoI have been self-hosting email for 7 years successfully. But it required a physical server in a reputable datacenter, setting up Dovecot, Exim, SpamAssasin, reverse-DNS, SPF, DKIM. It took a bit of time to gain IP reputation but then it has worked flawlessly since. Occasionally some legit mail is flagged as spam or vice versa but it is not worse than any other mail provider. So it can be done! But my first attempts to do that on a VPS failed as IP blocks of VPS providers are often hopelessly blacklisted in major email providers.
- vineyardmike 5y ago> as a queer kid, I was terrified of my parents finding out I think many queer people have a completely different idea of the concept of "why do you want to hide if you're not doing anything wrong" and the desire to stay private. Especially since anything sexual and related to queerness is way more aggressively policed than hetero-normative counterparts. Anything "think of children" always has a second order affect of damaging queer people because lots of people still think of queerness as dangerous to children. It is beyond likely that lots of this monitoring will catch legal/safe queer content - especially the parental-controls focused monitoring (as opposed to the gov'ment db of illegal content)
- heavyset_go 5y ago> Anything "think of children" always has a second order affect of damaging queer people because lots of people still think of queerness as dangerous to children. For example, YouTube does this with some LGBT content. YouTube has demonitized LGBT content and placed it in restricted mode, which screens for "potentially mature" content[1][2]. YouTube also shadowbans the content[1], preventing it from showing up in search results at all. From here[1]: > Filmmaker Sal Bardo started noticing something strange: the views for his short film Sam, which tells the story of a transgender child, had started dipping. Confused, he looked at the other videos on his channel. All but one of them had been placed in restricted mode — an optional mode that screens “potentially mature” content — without YouTube informing him. In July of that year, most of them were also demonetized. One of the videos that had been restricted was a trailer for one of his short films; another was an It Gets Better video aimed at LGBTQ youth. Sam had been shadow-banned, meaning that users couldn’t search for it on YouTube. None of the videos were sexually explicit or profane. There are more examples like that here[2]. [1] https://www.rollingstone.com/culture/culture-features/lgbtq-youtube-lawsuit-censorship-877919/ https://www.rollingstone.com/culture/culture-features/lgbtq-... [2] https://www.washingtonpost.com/technology/2019/08/14/youtube-discriminates-against-lgbt-content-by-unfairly-culling-it-suit-alleges/ https://www.washingtonpost.com/technology/2019/08/14/youtube...
- vineyardmike 5y agoAnd it's not just YouTube. Most platforms are at least partially guilty of this. Then there is tumblr, which is all but dead - explicitly for a "think of the children" concern from apple.
- playguardin 5y agoYou and your morality can suck it.
- _arvin 5y agoI'm really loving fastmail. Thanks for the heads up!
- samstave 5y agoWhat I am reminded of is all of the now seemingly prophetic writing and story telling in a lot of cyber-punk-dystopian anime about the future of the corporate state, and how mega corps rule EVERY THING. What I always thought was interesting was that the Police Security Services in Singapore were called "CISCO" -- and you used to see these swat-APV-type vans driving around and armed men with CISCO emblazened on their gear/equip/vehicles... I always was reminded of Cyberpunk Anime around that.
- m4rtink 5y agoInteresting! But actually this is not the singly thing with an "interesting" name in Singapore - well at least as long as you speak Czech. ;-) You see, the mass transit company in Singapore is handled by the Singapore Municipal Rapid Transit company, abbreviated SMRT. There is also a SMRT corporation (https://en.wikipedia.org/wiki/SMRT_Corporation https://en.wikipedia.org/wiki/SMRT_Corporation), SMRT buses, the SMRT abbreviation is heavily used on train, stations, basically everywhere. Well, in Czech "smrt" means literarily death. So let's say for Czech speakers riding the public transport in Singapore can be a bit unnerving - you stand at a station platform and then a train with "DEATH" written on it in big letters pulls into the station. ;-)
- samstave 5y agoWow. Thanks for that. Imagine if you were a Czech child who was old enough to read but not old enough to disassociate the locality of the spellings... that would be odd.
- gowld 5y ago> I'm not sure that I support what they are implementing for child accounts (as a queer kid, I was terrified of my parents finding out) If you don't want your parents to look at your phone, you shouldn't be using a phone owned by your parent's account. The new feature doesn't change this calculus. As a queer kid, would you enjoy being blackmailed by someone who tricked you into not telling your parents?
- ekianjo 5y agoSignal is next on the list since it's a centralized solution - you can expect they will come for it next.
- trangus_1985 5y agoI'm just trying to buy time until open source and secure alternatives have addressed these problems. Apple doing this has moved my timeframes up by a few years (unexpectedly).
- forgingahead 5y agoThis can happen only because whenever any slippery-slope action was taken previously, there is an army of apologists and "explainers" who rush to "correct" your instinctive aversion to these changes. It's always the same - the initial comment is seemingly kind, yet with an underlying menace, and if you continue to express opposition, they change tack to being extremely aggressive and rude. See the comment threads around this topic, and look back to other related events (notably the tech giants censoring people "for the betterment of society" in the past 12 months). Boiling a frog may happen slowly, but the water continues to heat up even if we pretend it doesn't. Very disappointed with this action by Apple.
- raxxorrax 5y agoThis is typical obedient behavior. Some abused spouses get through lengths to come up with excuses for their partners. Since I don't own an iOS device, I don't really care about this specific instance. But I don't want these people normalizing deep surveillance and fear that I have to get rid of my OSX devices when this trend continues.
- GeekyBear 5y ago> with icloud photos csam, it is also a horrifying precedent That precedent was set many years ago. >a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect’s Gmail account. Microsoft’s “PhotoDNA” technology is all about making it so that these specific types of illegal images can be automatically identified by computer programs, not people. PhotoDNA converts an image into a common black-and-white format and size the image to a uniform size, Microsoft explained last year while announcing its increased efforts at collaborating with Google to combat online child abuse. https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-led-to-a-mans-arrest-for-child-porn-was-not-a-privacy-violation/ https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le...
- trangus_1985 5y agocloud versus local device is a massive distinction imo. or maybe im a dinosaur ;)
- d110af5ccf 5y agoNo, you're not a dinosaur. It is entirely reasonable for a hosting provider not to want certain content on their servers. And it is also quite reasonable to want to automate the process of scanning for it. My physical device, on the other hand, is (supposed to be) mine and mine alone.
- GeekyBear 5y agoThe data is only scanned when you attempt to upload it to the cloud in either case. Apple scans the data on device before it is sent. Google scans it on it's own servers after it is sent.
- deleted 5y ago[deleted]
- taurath 5y agoIf my parents had the feature to be alerted about porn their kid’s device while I was a teen they would have sent me to a conversion camp, and that is not an exaggeration. Apple thinks the appropriate time for queer kids to find themselves is after they turn 18.
- neop1x 5y agoMaybe Apple will decrease child abuse cases but increase cases of child suicides..
- mrtranscendence 5y agoIf you're just downloading and looking at porn, no problem. It only becomes an issue if you're sharing porn via Messages or storing it in iCloud. And to be fair, I don't think they're alerted to the nature of the pornography, so you might be able to avoid being outed even if you're sharing porn (or having porn shared with you). Edit: I'm wrong in one respect: if the kid under 13 chooses to send a message with an explicit image despite being warned via notification, the image will be saved to a parental controls section. This won't happen for children >= 13.
- taurath 5y agoSure, but the parents can then unlock and go thru the phone and out the poor kid.
- rStar 5y ago> it is also a horrifying precedent that the device I put my life into is scanning my photos and reporting on bad behavior apples new customers are the various autocratic regimes that populate the earth. apples customers used to be human beings. there exist many profiteers in mountain view, cupertino menlo and atherton in the service of making our monopolies more capable of subjugating humanity.
- SOMA_BOFH 5y agohow does apple protect againat hash collisions?
- jeromegv 5y agoIt doesn't trigger for a single match, I guess that's the first line of defence.
- peakaboo 5y agoI also use Fastmail but being fully aware that Australia where its hosted is part of the 5 eyes spy network, and also one of the countries acting extreamly oppressive towards its citizens when it comes to covid restrictions. So I don't actually expect my mail to be private. But at least it's not Google.
- robjan 5y agoFastmail is hosted in New Jersey. If it was hosted in Aus the user experience would be pretty bad for most of its users.
- qwerty456127 5y ago> While I still use google maps, I've been trialing out OSM alternatives for a minute. Is there a way to set up Android to handle shared locations without Google Maps? Every time someone shares location with me (in Telegram) it displays as a tiny picture and once I click it it says I have to install Google Maps (I use an alternative for actual maps and don't have Google Maps installed). So I end up zooming the picture and then finding the location on the map manually.
- deleted 5y ago[deleted]
- TheRealDunkirk 5y ago> I hope they recant This is very much like driving a car through a crowd of protestors. They will slowly, inexorably, eventually push through.
- paulcarroty 5y ago> Fortunately, my email is on a paid provider Paid doesn't mean more secure, it's popular mistake.
- triska 5y agoI remember an Apple conference where Tim Cook personally assured us that Apple is fully committed to privacy, that everything is so secure because the iPhone is so powerful that all necessary calculations can happen on the device itself, and that we are "not the product". I think the Apple CEO said some of this in the specific context of speech processing, yet it seemed a specific case of a general principle upheld by Apple. I bought an iPhone because the CEO seemed to be sincere in his commitment to privacy. What Apple has announced here seems to be a complete reversal from what I understood the CEO saying at the conference only a few years ago.
- nerdponx 5y agoThe cynical take is that Apple was never committed to privacy in and of itself, but they are commited to privacy as long as it improves their competitive advantage, whether by marketing or by making sure that only Apple can extract value from its customers' data. Hanlon's razor does not apply to megacorporations that have enormous piles of cash and employ a large number of very smart people, who are either entirely unscrupulous or for whom scruples are worth less than their salaries. We probably aren't cynical enough. I am not arguing that we should always assume every change is always malicious towards users. But our index of suspicion should be high.
- hpen 5y agoI've always been convinced that Apple cared about privacy as a way of competitive advantage. I don't need them to be committed morally or ethically, I just need them to be serious about it because I will give them my money if they are.
- philistine 5y agoTim Cook looks like he believes in money, first and foremost. Anything goes second.
- withinboredom 5y agoI’d say you’re spot on, but I can’t say why.
- threatofrain 5y agoRecent relevant discussion. https://news.ycombinator.com/item?id=28068741 https://news.ycombinator.com/item?id=28068741 https://news.ycombinator.com/item?id=28075021 https://news.ycombinator.com/item?id=28075021 https://news.ycombinator.com/item?id=28078115 https://news.ycombinator.com/item?id=28078115
- dang 5y agoThanks! Macroexpanded: Expanded Protections for Children - https://news.ycombinator.com/item?id=28078115 https://news.ycombinator.com/item?id=28078115 - Aug 2021 (291 comments) Apple plans to scan US iPhones for child abuse imagery - https://news.ycombinator.com/item?id=28075021 https://news.ycombinator.com/item?id=28075021 - Aug 2021 (349 comments) Apple enabling client-side CSAM scanning on iPhone tomorrow - https://news.ycombinator.com/item?id=28068741 https://news.ycombinator.com/item?id=28068741 - Aug 2021 (680 comments)
- Calvin02 5y agoI think the issue is that what the tech community sees as privacy is different than what the general public thinks of as privacy. Apple, very astutely, understands that difference and exploited the latter to differentiate its phones from its main competitor: cheap(er) android phones. Apple didn’t want the phones to be commoditized, like personal computers before it. And “privacy” is something that you can’t commoditize. Once you own that association, it is hard to fight against it. Apple also understands that the general public will support its anti child exploitation and the public will not see this as a violation of privacy.
- websites2023 5y agoApple's battle is against Surveillance Capitalism, not against state-level surveillance. In fact, there is no publicly traded company that is against state-level surveillance. It's important not to confuse the two. Think of it this way: If you want to hide from companies, choose Apple. If you want to hide from the US Government, choose open source. But if your threat model really does include the US government or some other similarly capable adversary, you are well and truly fucked already. The state-level apparatus for spying on folks through metadata and traffic interception is now mode than a decade old.
- tablespoon 5y ago> Think of it this way: If you want to hide from companies, choose Apple. If you want to hide from the US Government, choose open source. It's not just the US government: they've been cooperating with the PRC government as well (e.g. iCloud in China runs on servers owned by a state-owned company, and apparently China rejected the HSM Apple was using elsewhere, so they designed one specifically for China). Apple has some deniability there, but I personally wouldn't be surprised if China could get any data from them that it wanted. https://www.nytimes.com/2021/05/17/technology/apple-china-censorship-data.html https://www.nytimes.com/2021/05/17/technology/apple-china-ce...
- websites2023 5y agoBoth the US government and Chinese government can get whatever they want from both iCloud and IMessage. Best not to use it for anything that could make you a target of theirs.
- krrrh 5y agoThe problem is that as governments gain access to new technological capabilities and exploit crises to acquire more emergency powers, increasingly large numbers of peoples’ threat models begin to include government. The best hopes against a population-wide Chinese-style social credit system being implemented in the US remain constitutional and cultural, but the more architectural help we get from technology the better. “Code is law” is still a valid observation.
- tomxor 5y agoI keep thinking, It's like they are trying to be the most ironic company in history... But then I have to remind myself, the old Apple is long gone, the new Apple is a completely different beast, with a very different concept of what it is marketing.
- amelius 5y agoIt's the RDF. People still think of Apple as the Old Apple. The rebellious company that stood for creative freedom. The maker of tools that work for the user, not against the user.
- endisneigh 5y agoUnless the entire stack you’re using is audited and open source this sort of thing is inevitable. As far as this is concerned, seems like if you don’t use iMessage or iCloud you’re safe for now.
- _red 5y ago>don’t use iMessage 1. Send someone you hate a message with cartoon making fun of tyrant-president. 2. That person is now on a list. Its swatting-as-a-service.
- ezfe 5y agoIf you read the article, you'd understand that among ALL the issues, this is not one: - Photos scanning in Messages is on-device only (no reporting to govt.) and doesn't turn on unless you're an adult who turns it on for a minor via Family Sharing controls. - iCloud Photos scanning doesn't take effect unless you save the photo and it's already in a database of flagged photos. So in your scenario, you'd have to save the photo received from the unknown number to get flagged.
- _red 5y ago>So in your scenario, you'd have to save the photo received from the unknown number to get flagged. Whew! I was worried there for a minute. Maybe for extra safety I could say "SIRI I DISAVOW OF THIS MESSAGE!"??
- bingidingi 5y agowould you not report unsolicited child porn to the FBI anyway?
- samatman 5y agoY'know, I have no idea what I'd do in this situation and I really hope I'll never find out. If a kilo of heroin just showed up in the back seat of my car, I'd throw it out the window and try not to think about it. I certainly wouldn't bring it to the police, because mere possession is a serious crime. CP is the same way, except it comes with a nice audit trail which could sink me even if I delete it immediately. Do I risk that, or do I risk the FBI deciding I'm a Person of Interest because I reported the incident in good faith? There are no good choices there.
- edison112358 5y ago“This means that when the features are rolled out, a version of the NCMEC CSAM database will be uploaded onto every single iPhone.” So every iPhone will now host the explicit images from the National Center for Missing & Exploited Children database.
- spiznnx 5y agoThe database contains perceptual hashes, not images.
- pgoggijr 5y agoNo, they will host the hashes computed from those images.
- hartator 5y agoYes, everyone in jail! It’s probably just the md5 or something like that, but I don’t like it either.
- joshstrange 5y ago> So every iPhone will now host the explicit images from the National Center for Missing & Exploited Children database. It's hashes, not the images themselves.
- cblconfederate 5y agoAnd how did the user end up with the hashes? He hashed the original images which he then deleted, your honor! BTW this is going to be a major target for smearing people that the US doens't like
- joshstrange 5y agoI'm sorry but this is the most ridiculous thing I've read today. Hashes have never and probably will never be used "smear" someone the US doesn't like. We can speculate about them planting evidence but trying to prosecute based on hashes baked into the OS used by millions? That's absurd.
- literallyaduck 5y agoIt is okay to use the back door when we want to find people: being terrorists exploiting children who are not vaccinated use the wrong politically correct language anything else we don't like
- Shank 5y agoI really love the EFF, but I also believe the immediate backlash is (relatively) daft. There is a potential for abuse of this system, but consider the following too: 1. PhotoDNA is already scanning content from Google Photos and a whole host of other service providers. 2. Apple is obviously under pressure to follow suit, but they developed an on-device system, recruited mathematicians to analyze it, and published the results, as well as one in-house proof and one independent proof showing the cryptographic integrity of the system. 3. Nobody, and I mean nobody, is going to successfully convince the general public that a tool designed to stop the spread of CSAM is a "bad thing" unless they can show concrete examples of the abuse. For one and two: given the two options, would you rather that Apple implement serverside scanning, in the clear, or go with the on-device route? If we assume a law was passed to require serverside scanning (which could very well happen), what would that do to privacy? For three: It's an extremely common trope to say that people do things to "save the children." Well, that's still true. Arguing against a CSAM scanning tool, which is technically more privacy preserving than alternatives from other cloud providers, is an extremely uphill battle. The biggest claim here is that the detection tool could be abused against people. And that very well may be possible! But the whole existence of NCMEC is predicated on stopping the active and real danger of child sex exploitation. We know with certainty this is a problem. Compared to a certainty of child sex abuse, the hypothetical risk from such a system is practically laughable to most people. So, I think again, the backlash is daft. It's been about two days of the announcement being public (leaks). The underlying mathematics behind the system has barely been published [0]. It looks like the EFF rushed to make a statement here, and in doing so, it doesn't look like they took the time to analyze the cryptography system, to consider the attacks against it, or to consider possible motivations and outcomes. Maybe they did, and they had advanced access to the material. But it doesn't look like it, and in the court of public opinion, optics are everything. [0]: https://www.apple.com/child-safety/pdf/Alternative_Security_Proof_of_Apple_PSI_System_Mihir_Bellare.pdf https://www.apple.com/child-safety/pdf/Alternative_Security_...
- api 5y ago(2) is important. Apple put effort into making this at least somewhat privacy-respecting, while the other players just scan everything with no limit at all. They also scan everything for any purpose including marketing, political profiling, etc. Apple remains the most privacy respecting major vendor. The only way to do better is fully open software and open hardware.
- mcone 5y agoI wish there was a privacytools.io for hardware. I've been an iPhone user since the beginning but now I'm interested in alternatives. Last I checked, PinePhone was still being actively developed. Are there any decent phones that strike a balance between privacy and usability?
- Knighttime 5y agoThere are tons of devices compatible with LineageOS. I suggest taking a look there. https://lineageos.org/ https://lineageos.org/
- kivlad 5y agoI'd go a step further and recommend https://grapheneos.org/ https://grapheneos.org/ with a Pixel phone.
- Knighttime 5y agoThat too! It's restricted to Pixel devices though, and (I'm not 100% sure on this. It at least doesn't include it.) doesn't support things like MicroG which is a must for getting some apps that rely on Play Services to work correctly. I really think Graphene is only good for hardcore privacy and security enthusiasts, or for situations that actually require the security. I guess it just depends on how much convenience you want to sacrifice.
- Dracophoenix 5y agoCalyxOS is another option. It's hardened but also has MicroG installed.
- josh_today 5y agoSerious question- how can anyone know these operating systems are truly secure? Is there a way to test the source code? From a code perspective could Google have placed a back door in Android to access these forks?
- babesh 5y agoApple is part of the power structure of the US. That means that it has a hand in shaping the agenda for the US but with that power comes the responsibility to carry out the agenda. This also means that it is shielded from attack by the power structure. That is the bargain that the tech industry has struck. The agenda is always towards increasing power for the power structure. One form of power is information. That means that Apple is inexorably drawn towards increasing surveillance. Also, Apple’s massive customer base both domestic and overseas is a juicy surveillance target.
- babesh 5y agoThe die was cast with the 2020 elections when Apple decided get into the fray. Much of tech also got into the fray. Once they openly decided to use their power, they couldn’t get back out.
- babesh 5y agoAnd if you don’t believe me, ask yourself who holds the keys to iCloud data for both foreign and domestic customers. Ask Apple if it has ever provided data for a foreign customer to the US government. What do you think GDPR is for? Hint: it isn’t end to end encrypted, Apple doesn’t need your password to read the information, and you will never know Who the frack would design a system that way and why?
- strictnein 5y agoThis is an excellent example of how far off the rails the EFF has gone. This is completely false: > "Apple is planning to build a backdoor into its data storage system and its messaging system"
- dukeofdoom 5y agoTechnocrats are the new railway tycoons
- new_realist 5y agoStudies have shown that CCTV reduces crime (https://whatworks.college.police.uk/toolkit/Pages/Intervention.aspx?InterventionID=1 https://whatworks.college.police.uk/toolkit/Pages/Interventi...). I expect results here will be even better. This technology uses secret sharing to ensure a threshold of images are met before photos are flagged. In this case, it's even more private than CCTV. Totalitarian regimes to do not need some magic bit of technology to abuse citizens; that's been clear since the dawn of time. Those who are concerned about abuse would do well to direct their efforts towards maintenance of democratic systems: upholding societal, political, regulatory and legal checks and balances. Criminals are becoming better criminals by taking advantage of advancements in technology right now, and, for better or worse, it's an arms race and society will simply not accept criminals gaining the upper hand. If not proven necessary, society is capable of reverting to prior standards (Habeas Corpus resumed after the Civil War, and parts of the Patriot Act have expired, for example.).
- kappuchino 5y agoYou link to an article that says ... "Overall, the evidence suggests that CCTV c an reduce crime.". And then continues mention that specific context matters: Vehicle crime ... oh well, I wonder if we could combat that without surveilance, like better locks, remote disable of the engine ... There as here with the phones, society has to evaluate the price of the loss of privacy and abuse by totalitarien systems, which will happen - we just can't say when. This is why some - like me - resist backdoors at all if for the price of "more crime".
- wellthisisgreat 5y agoApple's parental controls are HORRIBLE. There is at least 20% false positives there, that flag all sorts of absolutely benign sites as "adult". Any kind of machine-based contextual analysis of users' content will be a disaster.
- robertoandred 5y agoGood news! It's not doing contextual analysis of content. It's comparing image hashes.
- wellthisisgreat 5y agooh that's actually kind of good news then. I couldn't believe Apple wouldn't know about the inadequacy of their PC
- pseudalopex 5y agoYou confused the 2 new features. The child pornography detector compares perceptual hashes. The iMessage filter tries to classify sexually explicit images.
- wellthisisgreat 5y agoCould you explain please - can these hash comparisons be extended to other areas such as contextual analysis of photos or texts? For example would it be easy now to get to the hypothetical scenario where texts containing certain phrases will be flagged if some partner / regulator demands that? Or doing face recognition on images, etc.? Or is this still completely different from that
- bississippi 5y agoFirst they built a walled garden beautiful on the inside and excoriated competitors [1] for their lack of privacy. Now that the frogs have walked into the walled garden, they have started to boil the pot [2] . I don’t think the frogs will ever find out when to get off the pot. [1] https://www.vox.com/the-goods/2019/6/4/18652228/apple-sign-in-feature-facebook-google-privacy https://www.vox.com/the-goods/2019/6/4/18652228/apple-sign-i... [2] https://en.wikipedia.org/wiki/Boiling_frog https://en.wikipedia.org/wiki/Boiling_frog
- deleted 5y ago[deleted]
- Spooky23 5y agoThis article is irresponsible hand-waving. “ When Apple releases these “client-side scanning” functionalities, users of iCloud Photos, child users of iMessage, and anyone who talks to a minor through iMessage will have to carefully consider their privacy and security priorities in light of the changes, and possibly be unable to safely use what until this development is one of the preeminent encrypted messengers.” People sending messages to minors that trigger a hash match have more fundamental things to consider, as they are sending known photos of child exploitation to a minor. The EFF writer knows this, as they describe the feature in the article. They should be ashamed of publishing this crap.
- itake 5y ago> they are sending known photos of child exploitation to a minor How do you know its a known photo of child exploitation? The original image that was hashed and then deleted. Two completely different images have the same hash. WhatsApp automatically saves images to photos. What if you receive a bad image and are reported due to someone else sending the image to you?
- Spooky23 5y agoYou’re obliged to report that image to the police. These types of images are contraband.
- itake 5y ago> You’re obliged to report that image to the police. Is this a legal obligation for all countries that iPhones operate in? I wasn't able to find a law via a quick google search for the US. For US law, are there protections for people that report the contraband? I'm not sure if good samaritan or whistle blower laws protect you.
- morpheuskafka 5y agoYou’ve got it mixed up. The messages are scanned for any explicit material (which in many but not all cases is illegal), not specific hash matches. That’s only for uploads to iCloud Photos. Additionally, you are not “obliged” to report such photos to the police. Uninvolved service providers do have to submit some sort of report iirc, but to require regular users to do so would raise Fifth Amendment concerns.
- shmerl 5y agoIs anyone even using Apple if they care about privacy and security?
- FpUser 5y agoLuckily I only use phone to make phone calls, offline GPS and to control some gizmos like drones. Do not even have data plan. Not an Apple customer either so I guess my exposure to things mentioned is more limited.
- outworlder 5y ago> these notifications give the sense that Apple is watching over the user’s shoulder—and in the case of under-13s, that’s essentially what Apple has given parents the ability to do. Well, yes? Parents are already legally responsible for their young children and under their supervision. The alternative would be to not even give such young children these kind of devices to begin with - which might actually be preferable. > this system will give parents who do not have the best interests of their children in mind one more way to monitor and control them True. But the ability to send or receive explicit images would most likely not be the biggest issue they would be facing. I understand the slippery slope argument the EFF is making, but they should keep to the government angle. Having the ability for governments to deploy specific machine learning classifiers is not a good thing.
- deleted 5y ago[deleted]
- hncurious 5y agoApple employees successfully pressured their employer to fire a new hire and are petitioning to keep WFH. https://www.vox.com/recode/2021/5/13/22435266/apple-employees-petition-controversial-antonio-garcia-martinez-new-hire-departure https://www.vox.com/recode/2021/5/13/22435266/apple-employee... https://www.vox.com/recode/22583549/apple-employees-petition-work-home-employee-activism https://www.vox.com/recode/22583549/apple-employees-petition... Will they apply that energy and leverage to push back on this? How else can this be stopped before it goes too far? Telling people to "Drop Apple" is even less effective than "Delete Facebook".
- lijogdfljk 5y agoI doubt this will be as clean. A large swath of people will defend this "for the children".
- system2 5y agoDefinitely that's why they use the most vulnerable subject. I can't think of anything more sensitive than this. Every parent would be okay with this.
- RightTail 5y agoThis is going to be used to suppress political dissidents aka "populist/nationalist right" aka the new alqaeda searching for CP is the original pretext
- robertoandred 5y agoHow? Please be specific.
- gruez 5y agoPresumably by adding signatures for "populist/nationalist right" memes.
- anthk 5y agoMore like the reverse, fool. The power loves right wing people and racists. If anything, the left and progressive left will be prosecuted. China? They even attacked Marxist demonstrations in universities. Current ideology in China is just Jingoism or "keep shit working no matter how".
- klempotres 5y agoTechnically speaking, if Apple plans to perform PSI on device (as opposed to what Microsoft does), how come that "the device will not know whether a match has been found"? Is there anyone who's familiar with the technology so they can explain how it works?
- gruez 5y ago>how come that "the device will not know whether a match has been found" Probably using some sort of probabilistic query like a bloom filter.
- klempotres 5y agoBut the claim is that Apple does that "on device". To the best of my understanding, this would mean that both parties in the PSI protocol are "on the same device". Do they probably use some kind of TEE (Trusted Execution Environment) to evaluate the "other side" of the PSI protocol?
- c7DJTLrn 5y agoCatching child pornographers should not involve subjecting innocent people to scans and searches. Frankly, I don't care if this "CSAM" system is effective - I paid for the phone, it should operate for ME, not for the government or law enforcement. Besides, the imagery already exists by the time it's been found - the damage has been done. I'd say the authorities should prioritise tracking down the creators but I'm sure their statistics look much more impressive by cracking down on small fry. I've had enough of the "think of the children" arguments.
- bambax 5y agoYes. I'm not interested in catching pedophiles, or drug dealers, or terrorists. It's the job of the police. I'm not the police.
- adolph 5y agoYes, if you act as the police you are a vigilante.
- mrits 5y agoThere isn't any reason to believe the CSAM hash list is only images. The government now has the ability to search for anything in your iCloud account with this.
- 2OEH8eoCRo0 5y agoWhy is it always "think of the children"? It gets people emotional? What about terrorism, murder, or a litany of other heinous violent crimes?
- temeritatis 5y agothe road to hell is paved with good intentions
- slaymaker1907 5y agoI'd be surprised if this goes through as is since you can't just save this stuff indefinitely. Suppose a 14 year old sexts a 12 year old. That is technically child porn and so retention is often illegal.
- nicetryguy 5y agoI'm looking forward to this platform being expanded to facially ID against more databases such as criminals, political dissenters, or anyone with an undesirable opinion so that SWAT teams can barge into the homes of false positive identifications to murder them and their dogs.
- new_realist 5y agoMoral panics are nothing new, and have now graduated into the digital age. The last big one I remember was passage of the DMCA in 1999; it was just absolutely guaranteed to kill the Internet! And as per usual, the Chicken Littles the world were proven wrong. The sky will not fall in this case, either. Unfortunately civilization has produced such abundance and free time that outage viruses like this one will always circulate.
- deleted 5y ago[deleted]
- iamleppert 5y agoIt’s pretty trivial to iteratively construct an image that has the same hash as another, completely different image if you know what the hash should be. All one needs to do, in order to flag someone or get them caught up in this system, is to gain access to this list of hashes and construct an image. This data is likely to be sought after as soon as this system is implemented, and it will only be a matter of time before a data breach exposes it. Once that is done, the original premise and security model of the system will be completely eroded. That said, if this does get implemented I will be getting rid of all my Apple devices. I’ve already switched to Linux on my development laptops. The older I get, the less value Apple products have to me. So it won’t be a big deal for me to cut them out completely.
- jjtheblunt 5y agoCryptographic hashes are exactly not trivial to "dupe". https://en.wikipedia.org/wiki/Cryptographic_hash_function https://en.wikipedia.org/wiki/Cryptographic_hash_function that said, it's not clear to me from https://www.apple.com/child-safety/pdf/Apple_PSI_System_Security_Protocol_and_Analysis.pdf https://www.apple.com/child-safety/pdf/Apple_PSI_System_Secu... how collision resistant what's to be used will be.
- pseudalopex 5y agoPerceptual hashes aren't cryptographic.
- handoflixue 5y agoIs there anything stopping them from using an actual cryptographic hash, though?
- pseudalopex 5y agoEven the smallest change to an image changes a cryptographic hash.
- layoutIfNeeded 5y ago
- new_realist 5y agoMoral panics are nothing new, and have now graduated into the digital age. The last big one I remember was passage of the DMCA in 1999; it was just absolutely guaranteed to kill the Internet! And as per usual, the Chicken Littles the world were proven wrong. The sky will not fall in this case, either. Unfortunately civilization has produced such abundance and free time that outage viruses like this one will always circulate. Humans need something to spend their energy on.
- nopeYouAreWrong 5y agouhhh....dmca has been a cancer and destroyed people...so...the fears werent exactly unfounded
- kevin_thibedeau 5y agoIt would be a shame if we had to start an investigation into your anti-competitive behavior...
- roody15 5y agoMy two cents: I get the impression this is related to NSO pegasus software. So once the Israeli firms leaks were made public Appple had to respond and has patched some security holes that were exposed publicly. NSO used exploits in iMessage to enable them to grab photos, texts among other things. Now shortly after Apple security patches we see them pivot and now want to “work” with law enforcement. Hmmm almost like once access was closed Apple needs a way to justify “opening” access to devices. Yes I realize this could be a stretch based on the info. Just seems like an interesting coincidence… back door exposed and closed…. now it’s back open… almost like governments demand access
- MichaelMoser123 5y agoI guess it doesn't matter, the smartphone is a tracking device by definition, they can track your movement with a dumb phone too, but there are much more possibilities in a device with recording capabilities and an internet connection. In Orwells '1984' they mandated the installation of a televisor tracking device, now they have one in every pocket, and so it goes that we traded privacy for convenience. It's a bit of an irony, that Apple started with the big brother commercial, and ended up bringing us the televisor. https://www.youtube.com/watch?v=zIE-5hg7FoA https://www.youtube.com/watch?v=zIE-5hg7FoA Just because opportunity for an exploit is creating the reality of using that exploit, it seems as if it is then used for it's intended purpose..
- m3kw9 5y agoGonna get downvoted for this, I maybe the few that supports this and I hope they catch these child exploiters by the boat load and save 1000s of kids from traffickers and jail their asses
- pseudalopex 5y agoThe child pornography detection only tries to find known child pornography. It does nothing to stop traffickers.
- etempleton 5y agoI think this is probably the reasonable and responsible thing for Apple to do as a company, even if it it goes against their privacy ethos. Honestly they probably have been advised by their own lawyers that this is the only way to cover themselves and protect shareholder value. The question will be if Apple will bend to requests to leverage this for other reasons less noble than the protection of children. Apple has a lot of power to say no right now, but they might not always have that power in the future.
- Drblessing 5y agoUse signal y'all
- system2 5y agoAnyone who thinks the apps they will use make any difference is super naive. They are literally installing a trojan in the phone.
- everyone 5y agoWhen u upload any build to app store, before you can have it in testflight or submit it for release, you have to fill out this questionnaire asking "does your app use encryption?" If you say yes, you're basically fucked, good luck releasing it.. You have to say no as far as I'm aware.
- unstatusthequo 5y ago4th Amendment. Plaintiff lawyers gear up.
- cblconfederate 5y agoMakes you rally for NAMBLA
- geraneum 5y agoDidn’t they [Apple] make the same points that EFF is making now, to avoid giving FBI a key to unlock an iOS device that belonged to a terrorist? “ Compromising the security of our personal information can ultimately put our personal safety at risk. That is why encryption has become so important to all of us.” “… We have even put that data out of our own reach, because we believe the contents of your iPhone are none of our business.” “ The FBI may use different words to describe this tool, but make no mistake: Building a version of iOS that bypasses security in this way would undeniably create a backdoor. And while the government may argue that its use would be limited to this case, there is no way to guarantee such control.” Tim Cook, 2016
- rubatuga 5y agoThink of the children!!!
- cwizou 5y agoThe FT article mentioned it was US only, but I'm more afraid of how other governments will try to pressure Apple to adapt said technology to their needs. Can they trust random government to give them a database of only CSAM hashes and not insert some extra politically motivated content that they deem illegal ? Because once you've launched this feature in the "land of the free", other countries will require for their own needs their own implementation and demand (through local legislation which Apple will need to abide to) to control said database. And how long until they also scan browser history for the same purpose ? Why stop at pictures ? This is opening a very dangerous door that many here will be uncomfortable with. Scanning on their premises (considering they can as far as we know ?) would be a much better choice, this is everything but (as the "paper" linked tries to say) privacy forward.
- aalam 5y agoThe initial rollout is limited to the US, with no concrete plans reported yet on expansion. “The scheme will initially roll out only in the US. […] Apple’s neuralMatch algorithm will continuously scan photos that are stored on a US user’s iPhone and have also been uploaded to its iCloud back-up system.” Researchers interviewed for the article would agree with your analysis. “Security researchers [note: appears to be the named security professors quoted later in the article], while supportive of efforts to combat child abuse, are concerned that Apple risks enabling governments around the world to seek access to their citizens’ personal data, potentially far beyond its original intent.” Article link for ease of access: https://www.ft.com/content/14440f81-d405-452f-97e2-a81458f5411f https://www.ft.com/content/14440f81-d405-452f-97e2-a81458f54...
- cwizou 5y agoThanks, after some fiddling I managed to finally read the full text from the article and it's definitely short on details on the rollout. Let's hope they rethink this. I'm also fairly concerned about the neural part behind the name, which I hope is just (incredibly poor) marketing around the perceptive hash thing.
- falcolas 5y agoApple, Not that you care, but this is the straw that's broken this camel's back. It's too ripe for abuse, it's too invasive, and I don't want it. You've used one of the Four Horsemen of the Infocalypse perfectly… and so I'm perfectly happy to leave your ecosystem. Cheers.
- thedream 5y agoThe Cult Of The Apple hawks its slimy surveillance Snake Oil to a gluttonous throng of thralls. So where's the news?
- arihant 5y agoI’m very concerned that a bunch of false positives will send people’s nudes to Apple for manual review. I don’t trust apple’s on device ML for something this sensitive. I also can’t imagine that Apple will now not be forced to implement government forced filtering and reporting on iMessage. And this will likely affect others like WhatsApp because now governments know that there is a way to do this on E2E. What are some other fully encrypted photo options out there?
- mccorrinall 5y agoThey are putting their own users under surveillance. Didn’t expect that from Apple.
- skee_0x4459 5y agowow. in the middle of reading that, i realized that this is a watershed moment. why would apple go back on their painstakingly crafted image and reputation of being staunchly pro privacy? its not for the sake of the children (lol). no, something happened that has changed the equation for apple. some kind of decisive shift has occurred. maybe apple has finally caved in to the chinese market, like everyone else in the US, and is now making their devices compatible with chinese surveillance. or maybe the US government has finally managed to force apple to crack open its shell of encryption in the name of a western flavored surveillance. but either way, i think it is a watershed moment because securing privacy will from this moment onward be a fringe occupation in the west. unless a competitor rises up -- but thats impossible because there arent enough people who care about privacy to sustain a privacy company. thats the real reason why privacy has died today. if you really want to save the children, why not build the scanning into safari? scan the whole phone! just scan it all. its really no different than what they are doing. its not like they would have to cross the rubicon to do it, not anymore anyway. and also i think its interesting how kids will adjust to this. i think a lot of kids wont hear about this and will find themselves caught up in a child porn case. im so proud of the responses that people seem to generally have. it makes me feel confident in the future of the world. isnt there some device to encrypt and decrypt messages with a separate device that couples to your phone? like a device fit into a case and that has a keyboard interface built into a screen protector with indium oxide electrodes.
- zionic 5y agoYou can’t “save the children” by building a dystopia for them to grow up in.
- divbzero 5y agoA sibling comment speculates that this is related to Pegasus [1] which sounds wild to me but maybe, just maybe, it’s not. [1]: https://news.ycombinator.com/item?id=28080539 https://news.ycombinator.com/item?id=28080539
- judge2020 5y agoConspiracy theories should be considered, just don't endure consequences as a result of blind belief in them.
- swiley 5y agoI'm really worried about everyone. Somehow I've missed this until now and I've felt sick all day since hearing about it.
- andrewmcwatters 5y agoI suspect Apple is subject to government and gag orders and Microsoft has already been doing this with OneDrive but no one has heard about it yet.
- CubsFan1060 5y agoIt it literally in the Wikipedia article https://en.wikipedia.org/wiki/PhotoDNA https://en.wikipedia.org/wiki/PhotoDNA “ It is used on Microsoft's own services including Bing and OneDrive,[4] as well as by Google's Gmail, Twitter,[5] Facebook,[6] Adobe Systems,[7] Reddit,[8] Discord[9] and the NCMEC,[10] to whom Microsoft donated the technology.”
- andrewmcwatters 5y agoOh, I forgot about this. IIRC, Bing also flags you for search queries for illegal content.
- NazakiAid 5y agoWait until a corrupt govenment starts forcing Apple or Microsoft to scan for leaked documents exposing them and then automatically notifying them. Just one of the many ways this could go wrong in the future.
- panny 5y agoI left Apple behind years ago after using their gear for more than a decade. I recently received a new M1 laptop from work and liked it quite a bit. It's fast, it's quiet, it doesn't get hot. I liked it so much, that I was prepared to go back full Apple for a while. I was briefly reviewing a new iPhone, a M1 mini as a build server, a display, and several accessories to go along with a new M1 laptop for myself. (I don't like to mix work and personal) Then this news broke. Apple, you just lost several thousand dollars in sales from me. I had items in cart and was pricing everything out when I found this news. I will spend my money elsewhere. This is a horrendous blunder. I will not volunteer myself up to police states by using your gear now or ever again in the future. I've even inquired about returning the work laptop in exchange for a Dell. Unsafe at any speed. Stallman was right. etc etc etc.
- imranhou 5y agoI think it's easy to say no to any solution, but harder to say "this is bad, but we should do this instead to solve the problem". In a world with ubiquitous/distributed communication, the ideas that come up would generally avoid direct interception but need some way to identify a malicious transaction. When saying no to ideas like this, we should at the same time attempt to also share our thoughts on what would be an acceptable alternative solution.
- cwizou 5y agoI think everyone is offended on scanning being done on device and not on their servers (which I had assumed they might already did, quite frankly, Google Photos and others already do), and selling that as being privacy forward. Considering they hold the keys and the scheme already allows them to decrypt as a last step the users photos, this is not exactly a progress. It just maintains the illusion that those backups are encrypted while they (ultimately) aren't. I've personally (and some may disagree) always assumed that anything you put in any cloud (and that includes the very convenient iCloud backups that I use) is fair game for local authorities, whether that's true in practice or not. Putting a "snitch" on device, even if it's only for content that's going to the cloud (and in the case of an iCloud backup, doesn't that mean all your iPhone content ?) is the part that goes a step too far and will lead to laws in other countries asking for even more. Once you've opened the door to on device scanning, why limit it to data that goes to iCloud ? Why limit it to photos ? They proved they have the "tech" and governments around the world will ask for it to be bent to their needs. I'm sure the intent was well meaning but I'd much rather they just do this on their premises and not try to pretend they do this for privacy.
- imranhou 5y agoImagine someone was hired to reduce the problem of child trafficking/exploitation, and are the head of this group at the justice dept. Lets say they have the option to work with private orgs that may have solutions that could walk a fine line between privacy and their dept goals. I'm interested in knowing your perspective on how one should approach achieving these goals.
- Sunspark 5y agoThis is going to do wonders for Apple's marketshare once the teenagers realize that Apple is going to be turning them in to the police. Teens are not stupid. They'll eventually clue-in that big brother is watching and won't appreciate it. They'll start by using other messengers instead of imessage and then eventually leaving the ecosystem for Android or whatever else comes down the pike in the future.
- r00fus 5y agoApple's definition of "child" is 13yo or younger. So by the time they're more likely to be complaining about this feature, they will be aged out. I'd like to get verification but that hopefully means your scenario is unlikely.
- strogonoff 5y agoIf Mallory gets a lawful citizen Bob to download a completely innocuous looking but perceptual-CSAM-hash-matching image to his phone, what happens to Bob? I imagine the following options: - Apple sends Bob’s info to law enforcement; Bob is swatted or his life is destroyed in some other way. Worst, but most likely outcome. - An Apple employee (or an outsourced contractor) reviews the photo, comparing it to CSAM source image sample used for the hash. Only if the image matches according to human vision, Bob is swatted. This requires there to be some sort of database of CSAM source images, which strikes me as unlikely. - An Apple employee or a contractor reviews the image for abuse without comparing it to CSAM source, using own subjective judgement. Better, but implies Apple employees could technically SWAT Apple users.
- bitexploder 5y agoDo we know that they are using perceptual hashing? I am curious about the details of the hash database they are comparing against, but I assumed perceptual hashing would be pretty fraught with edge cases and false positives. e: It is definitely not a strict/cryptographic hash algorithm: "Apple says NeuralHash tries to ensure that identical and visually similar images — such as cropped or edited images — result in the same hash." They are calling it "NeuralHash" -- https://techcrunch.com/2021/08/05/apple-icloud-photos-scanning/ https://techcrunch.com/2021/08/05/apple-icloud-photos-scanni...
- deleted 5y ago[deleted]
- anonuser123456 5y agoDownloading an image to your phone is different than uploading it to iCloud. Downloaded images are not uploaded to iCloud w/out user intervention.
- strogonoff 5y agoPresuming iCloud Photos is enabled by Bob, an unsuspecting citizen, all downloaded images are synced to iCloud either right away or next time on Wi-Fi, depending on settings.
- rotbart 5y agoAs a former 13year old, that would be the end of 13 year olds using iMessages... I smell an opportunity.
- stakkur 5y agoImagine if the government said they were installing a backdoor in your checking account to 'anonymously' analyze your expenses and payees, 'just to check for known illegal activity'. Every time you use your debit card or pay a bill, the government analyzes it to see if it's 'safe'.
- system2 5y agoEveryone knows CC transactions are completely shared with government, IRS, bank, credit score companies, etc. Not even close to what's being done here.
- djanogo 5y agoWhy didn't apple just add option in screen time to block all images in iMessage?, that would have let parents choose what's best for their kids?
- xanaxagoras 5y agoBecause then they wouldn't be able hook these children in like junkies as easily. Having a hard time buying this is about "the kids" or children in any way, shape or form. This is typical erosion of privacy under a worn out flag, just more emotional manipulation. Have you seen what smartphones have done to people, especially children? Apple, Google, Facebook, Twitter, the whole lot of them. They are out to destroy children, not save them. If they thought they could "generate" 1 more dollar in "value" they'd be selling these abhorrent images to the highest bidder.
- robertwt7 5y agoWhen I thought that Tim Cook really respected everyone’s privacy sincerely. Apparently I was wrong, I loved apple products and ecosystem. Not sure what to switch after this :/
- XorNot 5y agoVarious copyright enforcement lobbies are all furiously drafting letters right now.
- hamburgerwah 5y agoIt will take a matter of days for other parties including copyright holders, if they have not already, to get in on this action. The infrastructure will then be compromised by human int so that it can be used to intelligence agencies to find people hitting red flag words like snowden and wikileaks. But lets be real for a moment that anyone who thinks apple cares about security or privacy over profits is in some way kidding themselves.
- suizi 5y agohttps://news.ycombinator.com/item?id=28081184 https://news.ycombinator.com/item?id=28081184 The NCMEC already had it's problems. But, this takes it to a whole new level.
- throw7 5y agoThe question that should be asked is if you think it's ok if the U.S. gov't looks at every picture you take and have taken and store and will store. The U.S. gov't will access, store, and track that information on you for your whole life. Past pictures. Present pictures. Future pictures. I don't use apple products, but if I found out google was scanning my photos on photos.google.com on behalf of the government I would drop them. I'm not saying it wouldn't hurt, because it definitely would, but in a capitalistic country this is the only way to fight back.
- tlogan 5y agoOh well… it always starts with “protect the children”. Then “protect us from terrorists”, then “terrorist sympathizers“, … And I bet that Saudis and other oppressive regimes will use this to detect other “crimes”.
- jimt1234 5y ago> ... a thoroughly documented, carefully thought-out, and narrowly-scoped backdoor is still a backdoor.
- j1elo 5y agoI'm not sure what's the point; in this day and age, I'm pretty sure that if your 14 years old wants to send a nude picture, if they really have already reached to that decision, they will do it. The only practical barrier here is that their parents have educated them and their mental model arrives by its own at "no, this is a very bad idea" instead of "yes, I want to send this pic". Anything else, including petty prohibitions from their parents, will not be a decision factor in most cases. Have we forgotten how it was to be a teenager? (I mean people, both underage and criminals, will just learn to avoid apple and use other channels)
- mfer 5y agoThat’s not what this does. Articles aren’t communicating the details well. There’s a set of known photos of kids going around. They are looking for those specific photos. It’s hash based checks
- majjam 5y agoThats the first feature, the second is, from the article: “The other feature scans all iMessage images sent or received by child accounts—that is, accounts designated as owned by a minor—for sexually explicit material, and if the child is young enough, notifies the parent when these images are sent or received. This feature can be turned on or off by parents.”
- j1elo 5y agoYeah I see the detail about matching hashes with well known images from a database... but what triggered my comment is this other function that is mentioned: > The other feature scans all iMessage images sent or received by child accounts—that is, accounts designated as owned by a minor—for sexually explicit material, and if the child is young enough, notifies the parent Which seems to be a feature that would allow parents to fix with prohibitions what they didn't achieve with education.
- nick_naumov 5y agoGoodbye Apple! I have trusted you for 12 years. All I wanted was you to trust me.
- xyst 5y agoIf this project goes live, I would drop Apple in a heart beat.
- balozi 5y agoDoes it matter if the project goes live? Once the company's attitude towards user privacy and customer concerns has been revealed, what's there left to hang onto?
- contingencies 5y agoNever buying another Apple product.
- haskaalo 5y agoAt this point, I think phones can be compared to a home in terms of privacy. In your house, you might have private documents, do some things you don't want other people to have or see just like what we have on our phones nowadays. The analogy I'm trying to make is that if suddenly the government decided to install cameras in every houses with the premise to make sure no pedophile is abusing a child and that the cameras never send data unless the AI done locally detects it is something that I believe would shock everyone.
- decebalus1 5y ago> At this point, I think phones can be compared to a home in terms of privacy. unfortunately the law hasn't really kept up with technology. Let's hope this gets in front of a judge who's able to extrapolate some 'digital' rights from the (outdated) constitution. Unless of course they also 'think of the children'.
- mackrevinack 5y agoits a good analogy that's useful for a lot of things. if someone was standing across the road from your house with a telescope, writing down every tv show or movie you watched, i think most people would be very angry about that. but when people hear they are being profiled online in the same way they are not bothered at all. it doesn't help that most things online are very abstract, with terms like 'the cloud' making things even harder to understand, which in reality is just someone else's computer
- fsflover 5y agohttps://news.ycombinator.com/item?id=24463347 https://news.ycombinator.com/item?id=24463347
- farmerstan 5y agoPolice routinely get drug sniffing dogs to give false positives so that they are allowed to search a vehicle. How do we know Apple or the FBI don’t do this? If they want to search someone’s phone all they need to do is enter a hash of a photo they know is on the targets phone and voila, instant access. Also, how is this not a violation of the 14th amendment? I know Apple isn’t part of the government but they are basically acting as a defacto agent of the police by scanning for crimes. Using child porn as a completely transparent excuse to start scanning all our material for anything they want makes me very angry.
- anonuser123456 5y ago> How do we know Apple or the FBI don’t do this? Because it requires Apple and law enforcement, two separate organizations, to collude against you. The false positive would have to be affirmed to a court and entered into evidence. If the false positive we’re found to not match the true image by the court, any warrant etc. would be found invalid and the fruit of any search etc would be invalid as well. Apple is a private company. By agreeing to use iCloud photos you agree to their terms, this no 14th amendment violation.
- decebalus1 5y ago> Because it requires Apple and law enforcement, two separate organizations, to collude against you. Does it really? As I understand it, the thing is pretty one-sided. Who manages and governs the collection of 'hashes'? If it's law enforcement there's no collusion needed. Also, someone can just text you such a photo, or some 0-day exploiting malware (of which governments have a bunch) would plant one on your phone. > The false positive would have to be affirmed to a court and entered into evidence. If the false positive we’re found to not match the true image by the court, any warrant etc. would be found invalid and the fruit of any search etc would be invalid as well. All of this would happen after you're arrested, labeled a pedo and have your life turned upside down. All of which can be used to coerce a suspect into becoming an informant, plead guilty to some unrelated charge or whatever. This type of thing opens the door to a whole new world of abuse.
- zionic 5y ago
- Wowfunhappy 5y agoThis isn't the biggest issue at play, but one detail I can't stop thinking about: > If an account held by a child under 13 wishes to send an image that the on-device machine learning classifier determines is a sexually explicit image, a notification will pop up, telling the under-13 child that their parent will be notified of this content. [...] For users between the ages of 13 and 17, a similar warning notification will pop up, though without the parental notification. Why is it different for children under 13, specifically? The 18-year cutoff makes sense, because turning 18 carries legal weight in the US (as decided via a democratic process), but 13? 13 is an age when many parents start granting their children more freedom, but that's very much rooted in one's individual culture—and the individual child. By giving parents fewer options for 13-year-olds, Apple—a private company—is pushing their views about parenting onto everyone else. I find that a little disturbing. --- Note: I'm not (necessarily) arguing for greater restrictions on 13-year-olds. Privacy for children is a tricky thing, and I have mixed feelings about this whole scheme. What I know for sure, however, is that I don't feel comfortable with Apple being the one to decide "this thing we've declared an appropriate invasion of privacy for a 12-year-old is not appropriate for a 13-year-old."
- websites2023 5y agoThe feature is opt-in. So, Apple isn't forcing anyone to do anything.
- Wowfunhappy 5y agoBut you have fewer options if your child is 13 years old. Or am I misunderstanding the article?
- websites2023 5y agoParents need to expressly opt in to Communication Safety when setting up a child's device with Family Sharing, and it can be disabled if a family chooses not to use it.
- 5y ago
- DaveSchmindel 5y ago(1) I'm a bit frustrated, as a true Apple "bitch", at the irony here. As a loyal consumer, I am (likely) never going to be privileged enough to know exactly which part of Apple's budget allowed for this implementation to occur. I can only assume that such data would speak volumes as to _why_ the decision to introduce CSAM this way has come to light. (2) I'm equally intrigued by the paradox that in order for the algorithms that perform the CSAM detection to work, it must require some data set that represents these reprehensible images (which are illegal to possess).
- Waterluvian 5y agoIf I go on 4chan and an illegal image loads and caches into my phone before moderators take it down or I hit the back button, will Apple’s automated system ruin my life? This kind of stuff absolutely petrifies me because I’m so scared of getting accidentally scooped up for something completely unintentional. And I do not trust police one bit to behave like intelligent adult humans. Right now I feel like I need to stop doing ANYTHING that goes anywhere outside the velvet ropes of the modern commercial internet. That is, anywhere that cannot pay to moderate everything well enough that I don’t run the risk of having my entire life ruined because some #%^*ing algorithm picks up on some content I didn’t even choose to download.
- benzoate 5y ago> If I go on 4chan and an illegal image loads and caches into my phone before moderators take it down or I hit the back button, will Apple’s automated system ruin my life? No, only if you save multiple CSAM images to your photo library and have iCloud Photo Library turned on.
- pzo 5y agofor 4chan maybe that's true but I'm not sure what about some public whatsapp group? I have been part of few public hiking/travelling group and even though I have most of them muted (to avoid distraction) all pictures end up in my Photos 'Recent' Album.
- cruano 5y agoYou can turn that off in Settings -> Chats -> Save to Camera Roll
- replwoacause 5y agoBut what if you don’t realize you can do this or you forget to? This should be off by default if you ask me.
- benzoate 5y ago
- superkuh 5y agoI guess Apple has given up on Apple Pay and becoming a bank. Without that as motivation for security this is probably the first of many compromises to come.
- neilv 5y agoThe article spends time on the implications for kids messaging other kids. Though I think parents as a group might tend to lean more towards wanting that snooping going on. Separate from kids, I wonder whether Apple's is yet shooting itself in the foot for teens. Teens should start caring about privacy around then, are very peer/fashion-sensitive, and have shown that they'll readily abandon platforms. Many parents/teachers/others still want to be treating teens as children under their power, but teens have significant OPSEC motivation and ability. Personally, I'd love to see genuinely good privacy&security products rushing to serve the huge market of a newly clueful late-teen generation. The cluefulness seems like it would be good for society, and market forces mean the rest of us then might also be able to buy products that aren't ridiculously insecure and invasive.
- didibus 5y agoI have a question, does this mean that Apple will have a way to decrypt photos in iCloud? It seems this can then be a security risk, since Apple could be breached and they'd have the means to server side decrypt things. If it was simply that client side end to end encryption can be turned on/off based on if the account is a child account or not (or as a configuration for parental control) that be different. As just a config, then I mean the slippery slope always existed, Apple could always just be forced into changing the settings of what gets end to end encrypted and when. But if this means that all photos are sent unencrypted to Apple at some point, or sent to Apple in a way they can decrypt, then it does open the door to your photos not being securely stored and attackers being able to steal them. That seems a bit of an issue.
- hu3 5y agoI hate to break it to you but Apple backtracked from their plan to e2e encrypt iCloud backups. Allegedly after being pressured by FBI: https://www.bbc.com/news/technology-51207744 https://www.bbc.com/news/technology-51207744 They have the encryption key that allows them to read their customer data.
- Animats 5y agoIs Apple under some legal pressure to do this? Is there some kind of secret deal here: "put in spyware and we back off on antitrust?"
- fragileone 5y agoFor years now congressmen have said stuff along the lines of "exceptional access to encrypted content for law enforcement" ie a backdoor. This is Apple pre-empting any more litigation like Australia, Germany and Ireland's recent privacy violating laws so that governments can just ask Apple to add XYZ prohibited content to their client-side scanner.
- walterbell 5y agoNow that we know iPhones have the ability to perform frame-level, on-device PhotoDNA hashing of videos and photos, could the same infrastructure be used to identify media files which are attempting to exploit the long list of buffer overflows that Apple has patched in their image libraries, as recently as 14.7.1? This would be super useful for iPhone security, e.g. incoming files could be scanned for attempting to use (closed) exploits, when the user can easily associate a malicious media file with the message sender or origin app/site. On jailbroken devices (e.g. iPhone 7 and earlier with unpatchable boot ROMs), is there a Metasploit equivalent for iOS, which aggregates PoCs for public exploits? A related question: will PhotoDNA hashing take place continuously or in batch, e.g. overnight? How will associated Battery/Power usage be accounted, e.g. attributed to generic "System" components or itemized separately? If the former, does that create class-action legal exposure for a post-sale change in device "fitness for purpose"?
- gcanyon 5y agoAre child porn viewers actually going to use iCloud backup? That seems like even the stupidest person would know not to do that. So I'll propose an alternative theory: Apple is doing this not to actually catch any child pornographers, but to ensure that any CP won't actually reach their servers. Less public good, more self-serving.
- deleted 5y ago[deleted]
- gowld 5y agoI get the concern, but "Corporation X can be compromised by the State, which is evil" is not a problem with the corporation. It's a problem with your civilization. If you don't trust the rule of law, Apple can't fix that for you.
- tango-unchained 5y agoAdvancement of the surveillance state is especially terrifying after this past summer of police abuse. We already know that in our country people in power abuse their authority and nothing happens (unless international protests prompt an action). This just collects more power under the disgusting guise of "won't somebody think of the children" while calling the people opposed pedophile supporters. Does anybody have recommendations on what to do to help oppose this instead of just feeling helpless?
- fragileone 5y agoVote with your wallet and don't give Apple another cent.
- deleted 5y ago[deleted]
- n_io 5y agoThis is exactly the event that I’ve been preparing for. I figured out long ago that it’s not a matter of if, but when, Apple fully embraces the surveillance economy. This seems to be a strong step in that direction. As dependant as I’ve been on the Apple ecosystem, I’ve been actively adopting open source solutions in place of the Apple incumbents so that when I have to fully pull the plug, I can at least soften the blow. In place of Mail: Tutanota In place of iMessage: Signal And so on…
- _robbywashere 5y agoThis is waaaay too turnkey for searching images on our devices that someone/something doesn’t like. Absolutely terrifying.
- voidmain 5y agoThis seems less concerning than the fact that iCloud backup is not end-to-end encrypted in the first place.
- stereoradonc 5y agoThe privacy creep usually happens by building narratives around CSAM. Yes, agreed it was objectionable, but there was no "scientific analysis" that such measures would prevent dissemination in the first place. Surveillance is morally discreditable, and Apple seems to have tested the waters well - by building a privacy narrative and then screwing the users in the process. Most users believe it is "good for them". Though, it remains the most restrictive system.
- aetherspawn 5y agoYeah, sure. I’m happy to be downvoted to hell, but I know people who would have benefit greatly from this (perhaps have entirely different lives) if it were implemented 10 years ago. Convince me that a strong step to ending CSA at the expense of a little privacy is a bad thing.
- suizi 5y agoI seriously doubt the majority of cases are recorded and uploaded to the internet.
- mulmen 5y agoWill my photos still be scanned if I do not use iCloud Photos?
- deleted 5y ago[deleted]
- tw600040 5y agoI wish there existed some decentralized device that can do iCloud backups and people can just buy that divide and set it up in their home.
- suizi 5y agoThe FBI doesn't even have the resources to review all the reports they do get (we learned that in 2019), and yet they want to intrude on everyone's rights to get even more to investigate (which they won't).
- goatse-4-this 5y agoWhere's that knob tptacek telling us why we're all paranoid simpletons for not using Apple?
- joering2 5y ago> This means that when the features are rolled out, a version of the NCMEC CSAM database will be uploaded onto every single iPhone. Question - if most people literally don't want to have anything to do with CP, isn't uploading of a hash database of that material to their phones precisely that? For once I think I will feel disgusted walking around with my phone in a pocket; a phone that is full of hashes of child porn. That's a terrible feeling.
- akouri 5y agoNobody is talking about the performance implications to the photos and messages app. All these image hashes and private set intersection operations are going to eat CPU and battery life. This is the downside to upgrading your iOS version. Once you update, it's not like you can go back, either. You're stuck with a slower, more power-hungry phone for the life of the phone.
- system2 5y agoDepends on how many photos you receive or take per day. I don't think it would be significantly different.
- deleted 5y ago[deleted]
- alana314 5y agoI thought Apple's iMessage wasn't end-to-end anyway but instead used a key stored on Apple's servers?
- TroisM 5y agoat least they dont lie about their spying on your device anymore...
- alfiedotwtf 5y agoLet's call it out for what it is - Apple's Dragnet.
- deleted 5y ago[deleted]
- jra_samba 5y agoSorry Apple fans, but you have been living in the very definition of "The Hotel California". Apple has altered the deal. Pray they do not alter it any further. Now you have to live with the consequences of convenience.
- young_unixer 5y agoLately, I've been on the fence about open source software, and I've been tempted by propietary programs. Mainly because FOSS is much less polished than commercial closed-source software, and I care about polish. I even contemplated buying an Apple M1 at some point. But now I'm reminded of how fucking awful and hostile Apple and other companies can be. I'm once again 100% convinced that free software is the only way to go, even if I have to endure using software with ugly UIs and bad UX. It will be worth it just not to have to use software written by these assholes. Stallman was right.
- mulmen 5y agoGive as much money to your favorite open source project as you would have to Apple for the M1. Polish costs money but it doesn’t have to cost freedom.
- jason2323 5y agoWhats the alternative here? What other viable alternative operating system will we use?
- fragileone 5y agoAndroid ROMs like GrapheneOS for now, mobile Linux distros in the near future.
- shrimpx 5y agoFrom Apple's original text[0]: > Apple’s method of detecting known CSAM is designed with user privacy in mind. Instead of scanning images in the cloud, the system performs on-device matching [...] It's incredible that Apple arrived at the conclusion that client-side scanning that you cannot prevent is more private than cloud-scanning. Since they claim they're only scanning iCloud content, why not scan in the cloud? They decided the most private way is to scan iCloud content before it's uploaded to the cloud... Because if they scanned in the cloud it would be seen as a breach of privacy and is bad optics for a privacy-focused company? But scanning on the physical device that they have described as "personal" and "intimate" has better optics? That's amazing. This decision can only be read as Apple paving the way to scanning all content on the device, to bypass the pesky "Backup to iCloud" options being turned off. [0] https://www.apple.com/child-safety/ https://www.apple.com/child-safety/
- vmladenov 5y ago> Since they claim they're only scanning iCloud content, why not scan in the cloud? Because (I suspect) this is a precursor to E2EE encrypted iCloud Photos. Apple cannot plausibly claim it does not store malicious E2EE content on its servers without some kind of filter upon upload. This is that filter. Other services, including the current implementation of iCloud Photos, skate by because they do not allow E2EE photos.
- blintz 5y agoOne disappointing development from a larger perspective is that many privacy-preserving technologies (multi-party computing, homomorphic encryption, hardware enclaves, etc) are actually getting used to build tools that undermine once-airtight privacy guarantees. E2E starts to become… whatever this is. A more recent example is how private set intersection became an easy way to get contact tracing tech everywhere while maintaining an often perfunctory notion of privacy. I wonder where large companies will take this next. It behooves us cryptography/security people who actually care about not walking down this slippery slope to fight back with tech of our own. This whole thing also somewhat parallels the previous uses of better symmetric encryption and enclaves technologies for DRM and copyright protection.
- villgax 5y agoThe impact a false positive can have on relations between parents & friends of the family is huge for something banal as an art poster/music cover art
- iamnotwhoiam 5y agoIf sexual images exchanged by a kid are saved to the parent’s phone then doesn’t that put the parent at risk for charges if the kids are sexting?
- deleted 5y ago[deleted]
- Clubber 5y agoWhat are some options for phones that don't spy on me or my children?
- whycombagator 5y agoAndroid device (pixel for example) and graphene or lineage OS.
- 14 5y agoWill the jailbreakers be able to disable this feature?
- system2 5y agoWhat's the percentage of jailbroken iPhones out there? Average joe will be sheepishly keep using.
- fortran77 5y agoWhat’s to stop a malicious person from sending a prohibited image to an unsuspecting person, and causing the target to get into legal trouble for which there is no legal defense ("strict liability" for possession).
- citboin 5y agoAll of my hardware is outdated so I was about to make the jump to Apple all across the board. Now I’m probably going to dive into the deep end and go into FOSS full throttle. I’m going to investigate Linux OEM vendors tonigh. The only one that I know of is System 76. Are there any Linux based iPad competitors?
- bishoprook2 5y agoThat's a great question. I keep looking for Linux tablets but not much joy so far. The Pinetab is unavailable and pretty slow. If I had to guess, I'd hunt around for a Windows tablet that someone had good luck running Linux on. Maybe a Surface Pro.
- physicles 5y agoThinkpads also run Linux very well. I've got an X1 Carbon 7th gen running Pop!_OS, and everything on the machine works, including the fancy microphones on top (haven't tried the fingerprint reader though).
- hashslingslash 5y agoApple has become the hash slinging slasher. I am furious.
- roamerz 5y agoBad Apple. Today it is something socially unacceptable - child exploitation. The reason that is used as a reason is plainly obvious. What will be the next socially unacceptable target? Guess it depends on who the ruling class. Very disappointed in this company’s decision.
- system2 5y agoI don't think there is another one like this subject. Let's see if Samsung and other android phones add this type of stuff soon.
- viktorcode 5y agoOn device data scan, however well-intended it may be, is an invasion of privacy. Server scan is entirely different matter, because it is an optional service which may come with any clauses its provider may deem necessary. I understand that it doesn't scan everything, but it don't matter. What matter is there's an implemented technical capability to run scans against external fingerprint database. it's a tool which may be used for many needs. I hope some countries will prohibit Apple doing that. Germany with its strict anti-snooping laws comes to mind. Maybe Japan. The more, the better. Oh, and by the way, every tech-savvy sex predator now knows what they should avoid doing. As always with mass privacy invasions: criminals are the last to suffer from it.
- sadness3 5y agoFor me, this crosses a line. There should be no need to "strike a balance" with authorities wanting what are essentially unwarranted searches. The right balance is, "fuck off". I'm looking into privacy phones for the first time and will be switching.
- hungryforcodes 5y agoAm I bring cynical? https://techcrunch.com/2021/04/28/apple-record-china-2021/ https://techcrunch.com/2021/04/28/apple-record-china-2021/ Apple's iPhone revenu just doubled from last year in China -- now 17 billion. Thats not a small number. The play against Huawei has done it's job, apparently -- it's quite mortally injured. For sure the CCP would love to scan everyone's phones for files or images it finds troubling and for sure every country will eventually be allowed to have its own entries in this database or even their own custom DB. So my cynical side says...Apple just sold out. MASSIVELY. The loosers -- everyone pretty much that buys their phones.
- benzoate 5y agoThe CCP can already scan everything server side – iCloud encryption is weaker in China and the servers are controlled by a different entity than Apple. Getting iPhones to scan for illicit content doesn’t help the CCP.
- hungryforcodes 5y agoIf I keep all my data sequestered on my phone -- which I'm bound to do if I am privacy conscious -- then obviously scanning the phone benefits the CCP.
- thysultan 5y agoAll that expansive "privacy" marketing undone by a single move.
- xbar 5y agoPolice-state-designed device.
- _carl_j_b_223 5y agoDoes Apple really think those bastards share their disgusting content via iCloud or message themself via iMessage? Even if some idiots did, they'll stop by now. So even if Apple has pure good intentions it'll be pretty useless and so Apple don't even have to start with these kind of questionable practices.
- xbmcuser 5y agoApple scanning for law enforcement in 1 country gives proof of concept for another country to ask for the same for their own laws. And with a big enough market can easily arm twist Apple to comply as $$ means more than all privacy they talk about.
- barrkel 5y agoOnce this tech is implemented, courts will direct it to be used in situations Apple did not intend. Apple will have created a capability and the courts will interpret refusal to expand its use as contempt.
- kntoukakis 5y agoFrom https://www.apple.com/child-safety/ https://www.apple.com/child-safety/ “The threshold is set to provide an extremely high level of accuracy and ensures less than a one in one trillion chance per year of incorrectly flagging a given account.” How did they calculate this? Also, I can imagine more than a trillion photos being uploaded to iCloud a year.
- nullc 5y agoYour smartphone or desktop computer is your agent. You can't accomplish many necessary tasks without it, you're nearly required by law to use one. It handles your most private data, and yet you have no real visibility into its actions. You just have to trust it. As such, it should NEVER do anything that isn't in your best interest-- to the greatest extent possible under the law. Your relationship with your personal computer is closer and more trusted than your relationship with your doctor or lawyer-- in fact, you often communicate with these parties via your computer. We respect the confidentiality you enjoy with your professional agents but that confidentiality cannot functionally exist if your computing devices are not equally duty bound to act in their users best interest! This snitching 'feature' is a fairly general purpose tracing/tracking mechanism-- We are to assume that the perceptual hashes are exclusively of unlawful images (though I can't actually find a firm, binding assertion of that!)-- but there is nothing assuring that to us except for blind trust. Even if the list today exclusively has unlawful images there is no guarantee that tomorrow it won't have something different-- no guarantee that some hysterical political expediency won't put images associated with your (non-)religion or ethnicity into it, no guarantee that the facility serving these lists won't be hacked or abused by insiders. Considering that possession of child porn is a strict liability crime, Apple themselves has presumably not validated the content of the list themselves and certainly you won't be allowed to check it. Moreover, even if there were some independent vetting of the list content there is nothing that would prevent targeted parties from being given a different unvetted list without their knowledge. The pervasive scanning can also be expected to dramatically increases the effectiveness of framing. It's kind of cliche that the guilty person often claims "I was framed"-- but part of the reason that framing is rare is because the false evidence has to intersect a credibly motivated investigation, and they seldom do except where there are other indicators of guilt. With automated scanning it would be much more reliable to cause someone a world of trouble by slipping some indicated material on their device, and so framing would have a much better cost/benefit trade-off. Any of the above flaws are sufficiently fatal on their own-- but add to it the potential for inadvertent false positives both in the hash matching and in the construction of the lists. Worse, it'll probably be argued that the detailed operation of the system must be kept secret from the very users whos systems it runs on specifically because knowledge of the operation would greatly simplify the malicious construction of intentional false positives which could be used for harassment by causing spurious investigations. In my view Apple's actions here aren't just inappropriate, they're unambiguously unethical and in a more thoughtful world they'd be a violation of the law.
- anupamchugh 5y agoBy notifying parents of children under 13 for image abuse, looks like Apple wants to be both the police and the parent of iPhone owners.
- Grustaf 5y agoThe articles I've read say: _Hashes_ of photos will be scanned for _known_ abusive material, client side. So the only thing Apple can find out about you is if you have some of these known and catalogued images. They will definitely not know if you have other nude photos, including of your children. The other, separate feature is a parental control feature. You as a parent can be told if your children send or receive nude photos. This obviously sacrifices some of their privacy, but that is what parenting is. It's not more intrusive than screentime, or any number of things you might do as a parent to make sure your children are safe..
- zekica 5y agoThese are not cryptographic hashes you are thinking of but perceptual hashes for which collisions are much easier to find.
- fetzu 5y agoI honestly fail to see how the “oppressive regimes could just turn the on-device scanning into a state surveillance tool” is not a slippery slope arguments when on-device scanning and classification (NN for image processing and classification) has been going on for years on iOS devices. It just seem very paradoxical to be using a cloud based photo and/or un-encrypted backup service and then worry about one’s privacy being at risk.
- hmwhy 5y agoAnd, in the meantime, Roblox is promoted in the App Store. For context, see https://news.ycombinator.com/item?id=20620102 https://news.ycombinator.com/item?id=20620102
- lovelyviking 5y ago- Apple: Dear User, We are going to install Spyware Engine in your device. - User: Are you out of your f... mind? - Apple: It's for children protection. - User: Ah, ok, no problem, please install spyware and do later whatever you wish and forget about any privacy, the very basis of rights, freedom and democracy. This is by the way how Russia started to filter the web from political opponents. All necessary controls were put in place under the same slogan: "to protect children" Yeah, right. Are modern people that naive and dumb and can't think 2 steps forward? Is that's why it's happening? Edit: Those people would still need to explain how living in society without privacy, freedom and democracy with authoritarian practices when those children will grow up will make them any 'safer' ...
- beebeepka 5y agoMy fellow Earthicans, we enjoy so much freedom, it's almost sickening. We're free to chose which hand our sex-monitoring chip is implanted in.
- lenkite 5y agoCan the legions of Apple Apologists on this forum at-least agree that all the talk about how well the iPhone supports individual privacy is just a bunch of bald-faced lies ? I mean they use the privacy argument to avoid side-loading apps, lol. But scanning your photos is OK. What absolute hypocrisy.
- egotripper 5y agoWho ordered Apple to do this, "or else?" What was the "or else?" How easy will it be to expand this capability by Apple or anyone outside of Apple? I expect that any time you take a photo, the scan will be performed right away, and the results file will be waiting to be sent the next time you enable voice and data. This capability crushes the trustworthiness of the devices.
- RedComet 5y agoIt won't be long before this is turned on political dissidents. * knock knock * "we received an anonymous report that you have hate speech an illegal meme on your phone, please come with us"
- rStar 5y agoi’m ashamed of every single apple employee who worked to make this happen. their work will be used to subjugate the most vulnerable among us. i hope you all hate yourselves forever for your cowardice and immorality.
- dep_b 5y agoSo we have a person that is technical enough to find known CP, so the stuff that's already automatically filtered out by Google and co because those same hashes are already checked against for all images they index. So knowledge of dark web should be assumed, something I don't even know how to use let alone how find the filth on there. Yet....dumb enough to upload it unencrypted to iCloud instead of storing it in a strongly encrypted folder on their PC? The two circles in this diagram have a very thin overlap I think. Dumb move by Apple, privacy is either 100% private or not private. Unless somebody can enlighten me that like 23% of all investigated pedophiles that had an iPhone seized had unencrypted CP on their iCloud accounts? I am willing to be proven wrong here.
- volta83 5y agoSo Apple is putting a database of child pornography on my phone ? I’d rather not have that on my phone.
- avnigo 5y ago> Once a certain number of photos are detected, the photos in question will be sent to human reviewers within Apple, who determine that the photos are in fact part of the CSAM database. If confirmed by the human reviewer, those photos will be sent to NCMEC, and the user’s account disabled. Chilling. Why have human reviewers, unless false positives are bound to happen (this is of 100% certainty with the aggregate amount of photos to be scanned)? So, in effect, Apple has hired human reviewers to police your photos that an algorithm has flagged. Whether you knowingly consent to or not (through some fine print), you are being subjected to a search without probable cause. This is not the future I was looking forward to.
- dsign 5y agoApple is not a dumb company, they did this fully knowing of the backslash they would receive, very likely impacting their bottom line. Two scenarios come to mind: 1. They expect must people will shrug and let themselves be scanned. That is, this privacy invasion will result in minimal damage to the Apple brand, or 2. They know privacy-savvy people will put them from now on on the same league with Android, and they are prepared to take the financial loss. Scenario 1 is the most plausible, though it hints an impish lack of consideration for their customers. Scenario 2 worries me most. No smart company does something counter-productive financially unless under dire pressure. What could possibly make Apple shoot itself on the foot and announce it publicly? In other words, Apple's actions, from my perspective, look like a dead canary.
- Guthur 5y agoI think it's becoming very apparent that through apathy, indoctrination, and fear that freedom will be well and truly stamped out. You just have to say for the greater good and you can get away with anything. Over the last year and half so many have been desensitised to over bearing collectivism that at this stage i think governments and their any Big Corp lackeys could get away with just about anything now.
- mactavish88 5y agoWhat kind of amateur criminal would store illegal material in their iCloud account?
- mrwww 5y agoSo if your Apple ID/icloud gets compromised, and somebody save an album of CP to your icloud photos, it is then only a question of time until the police comes knocking?
- dalbasal 5y ago"”Apple sells iPhones without FaceTime in Saudi Arabia, because local regulation prohibits encrypted phone calls. That's just one example of many where Apple's bent to local pressure. What happens when local regulations in Saudi Arabia mandate that messages be scanned not for child sexual abuse, but for homosexuality or for offenses against the monarchy?”" Good question. Companies have to follow laws. The naive, early 2000s notion that the internet was unstoppable and ungovernable was mistaken. Apple, Google and the other internet bottlenecks were, it turned out, the pathway to a governable internet. That fight is lost. Now that it's governable, attention needs to be on those governing... governments, parliaments, etc. The old version of freedom of speech and such didn't come from the divine. They were created and codified and now we have them. We need to do that again. Declare new, big, hairy freedoms that come with a cost that we have agreed to pay. There are dichotomies here, and if we deal with them one droplet at a time, they'll be compromised away. "Keep your private messages private" and "Prevent child pornography and terrorism in private messages" are incompatible. But, no one is going to admit that they are choosing between them... not unless there's an absolut-ish principle to defer to. Once you're scanning email for ad targeting, it's hard to justify not scanning it for child abuse.
- bogomipz 5y agoThe article states: >"The (unauditable) database of processed CSAM images will be distributed in the operating system (OS), the processed images transformed so that users cannot see what the image is, and matching done on those transformed images using private set intersection where the device will not know whether a match has been found" Am I reading this correctly in that Apple will essentially be pushing out contraband images to user's phones? Couldn't the existence of these images on a user's phone potentially have consequences and potentially be used against an unwitting iPhone user?
- christkv 5y agoWhy don’t they just run their trained classifier on the phone itself to do this stuff. There should not be any need to do this on the server no matter what they say.
- citizenpaul 5y agoI fully support this. History has shown us that humanity and especially their governments are very well equipped to deal with near godlike power of surveillance. There are basically no examples of this power being abused through all of history. Maybe a couple of bad apples. We should really look into how this can be expanded. Imagine if crime could be stopped before it starts.
- scratchmyhead 5y agoIf Apple broadcasts their surveillance strategy so publicly, wouldn't criminals stop using Apple products and delete their iCloud data immediately? Who will be left to "catch" at that point? The most incompetent criminals? I'm missing how this will actually work if perpetrators knew Apple was going to analyze their data beforehand. Could someone explain?
- chinchilla2020 5y agoChild abusers are dumb, but smart enough to know not to upload pictures to the cloud. If was a conspiracy type, I would assume this is more likely to be apple responding to an NSA request to de-crypt data. This idea will be gradually expanded: 1. To detect child abuse (unsuccessfully) 2. To detect terrorism (also unsuccessfully) 3. To detect criminal activity (successful only against low-level criminals) 4. To detect radical political views as defined by Apple corporation 5. To detect human behaviors that are not supported by Apple's corporate vision
- dragonwriter 5y ago> Child abusers are dumb, but smart enough to know not to upload pictures to the cloud. No, they aren't, categorically. That's why they keep getting caught that way.
- chinchilla2020 5y agoVery few get caught that way. Most of the major cases involve seizures of offline hardrives.
- dragonwriter 5y ago> Very few get caught that way. Maybe, I haven't seen any numbers. (I've seen several cases from email is or cloud providers IDing specific content and tipping off law enforcement, but not aggregate stats.) > Most of the major cases involve seizures of offline hardrives. Are most cases major cases? Are even most of the individuals caught caught in major cases (I doubt it; the number of publicized major caelses and the number claimed caught in each, and the total number of cases don't seem to line up with that.) And even for the major cases, how do they get the initial leads that they work back to?
- alisonkisk 5y agoOP completely misunderstands the situation. > OS and iPadOS will use new applications of cryptography to help limit the spread of CSAM online, while designing for user privacy. CSAM detection will help Apple provide valuable information to law enforcement on collections of CSAM in iCloud Photos. WhatsApp is not a hosting service.
- michalu 5y agoThis will have only one effect, pedophiles will stop using ios and for all the rest of us our privacy will remain compromised.
- miika 5y agoPeople at Apple really think that someone who has such images would add them to iCloud Library?
- shadowhack 5y agoThey want to do this, but not interested in taking out apps like Kik from their app store...