15 ms·
US Government: We suspect the person in this photo of committing a crime. Here is your subpoena, Apple. You are directed to scan all iPhone and iCloud storage f
by sathackr 5y ago
US Government: We suspect the person in this photo of committing a crime. Here is your subpoena, Apple. You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them.
Chinese Government: Here is the NeuralHash for Tienanmen square. Delete all photos you find matching this or we will bar you from China.
Apple has at this point already admitted this is within is capability. So regardless of what they do now, the battle is already lost. Glad I don't use iThings.
- xyst 5y agoSelfies are suddenly going to be used as surveillance tools by the govt, or maybe a bad actor at Apple wants to find/track down their ex. This system has so much potential for abuse with very little upside.
- calmworm 5y agoSuddenly?
- EnlightenedBro 5y agoNailed it. It was the intention all along. Funny how everyone just pretends that it's not what it is.
- fny 5y agoThe Chinese government already has direct access to everyone's data and messages. There is no encryption. This is mandated. [0]: https://www.nytimes.com/2021/05/17/technology/apple-china-censorship-data.html https://www.nytimes.com/2021/05/17/technology/apple-china-ce...
- FabHK 5y ago> direct access to everyone's data and messages. From what I understand, only to Chinese customers's data and messages (bad enough, sure, but not as bad as you say).
- brasscodemonkey 5y agoDepends on the company. If it’s a Chinese company like TikTok, data is stored in China and therefore property of the state. Things are about to get worse and they crack down on private companies in China. And it’s not just Americans who worry about this. When word got out that Line was storing user data in China servers, it blew up in the news in Japan and Taiwan and went into immediate investigation. Line ended up moving Japanese user data to South Korea. Chinese aggression and Xi’s obsession with power is not just something Americans spout off in Reddit and YouTube comments. They’re a legit threat to Taiwan, Japan, Australia and India. https://asia.nikkei.com/Business/Technology/Line-cuts-off-access-from-China-to-protect-personal-data-in-Japan https://asia.nikkei.com/Business/Technology/Line-cuts-off-ac...
- jazzyjackson 5y agoTikTok is run by a US-based subsidiary of ByteDance They have insisted “that TikTok U.S. user data is stored in Virginia, with a back-up in Singapore and strict controls on employee access.” https://techcrunch.com/2020/08/17/tiktok-launches-a-new-information-hub-and-twitter-account-to-correct-the-record-it-says/ https://techcrunch.com/2020/08/17/tiktok-launches-a-new-info...
- giantrobot 5y agoChina's state security laws trump all "strict controls" for employees.
- jazzyjackson 5y agoWhich employees? The ones who aren't Chinese citizens and aren't located in China? What does China state security have to do with them?
- giantrobot 5y agoByteDance's Douyin product has Chinese employees that are based in China. TikTok employees are also ByteDance employees which means a ByteDance employee that passes through their "strict controls" can access whatever TikTok data they want. Even if that's a dozen Chinese nationals that can get access that's a dozen people required by Chinese law to help the state security aparatus. I don't see any reason to give them the benefit of the doubt considering they already moderate content the Chinese government doesn't like [0] as a matter of company policy. [0] https://www.theguardian.com/technology/2019/sep/25/revealed-how-tiktok-censors-videos-that-do-not-please-beijing https://www.theguardian.com/technology/2019/sep/25/revealed-...
- belter 5y ago"Apple CEO Tim Cook Slams Indiana’s ‘Religious Freedom’ Law" https://www.rollingstone.com/politics/politics-news/apple-ceo-tim-cook-slams-indianas-religious-freedom-law-91777/ https://www.rollingstone.com/politics/politics-news/apple-ce... The hypocrisy levels are vomit inducing...
- zepto 5y agoWhat hipocrisy are you seeing?
- belter 5y agoYou must be trolling...Provoking...Joking...Or you are Tim Cook :-) Are the personal ethics and values disconnected from daily business, to be changed based on the place of business or Apple must do it because they are just complying with local laws in China ? Because IBM was also in 1939...Just the local laws. https://en.wikipedia.org/wiki/IBM_and_the_Holocaust https://en.wikipedia.org/wiki/IBM_and_the_Holocaust
- zepto 5y agoSo this is just about China? When Apple started working in China, the prevailing western belief was that economic liberalization would cause political liberalization in China, so even though China was still relatively repressive, doing business there would help move things in a better direction. At the time, this was a very reasonable and widespread belief, which turned out to be wrong. Betting on other people and turning out to be wrong doesn’t make you a hypocrite. It makes you naive.
- belter 5y agoNaive is not something I would associate with Apple, but I guess they have seen it now. I guess they must be ready to pull off any time...Or is their CEO too busy, lecturing others on the righteous paths in other jurisdictions? "Apple's Good Intentions Often Stop at China's Borders" https://www.wired.com/story/apple-china-censorship-apps-flag/ https://www.wired.com/story/apple-china-censorship-apps-flag...
- hughrr 5y agoYeah as I mentioned down the thread, once you act against the users, you're dead. I'm done. They are going from my life. Good job it's ebay 80% off fees this weekend here in the UK.
- klysm 5y agoI mean eBay isn’t exactly free of bad behavior…
- p410n3 5y agoI think they're just selling their iDevices on there
- johnnyApplePRNG 5y agoGuess I'll just keep my spyPhone then. /s
- ju_sh 5y agoPretty sure I read this would only apply to US based users
- hughrr 5y agoYes so far. Once the mechanism is in place it will be rolled out. I'm in the UK and we have a fairly nasty set of state legislation on censorship already and an increasingly authoritarian government so this is a big worry.
- brasscodemonkey 5y agoHasn’t Google been parsing Google Photos images, email content, and pretty much everything else since forever? Do you just stay off of smartphones and cloud platforms entirely?
- fh973 5y agoMicrosoft and Google have been doing that in their online services for ages, but not on your personal devices.
- brasscodemonkey 5y agoSo if I don’t backup with Google Photos or Google Drive, would they be safe for now?
- vineyardmike 5y agoyes theoretically.
- deleted 5y ago[deleted]
- sathackr 5y agoThey scan things I send them. They don't (publicly announce that they) scan things on my device.
- davidcbc 5y agoHave they? The whitepaper made it sound like the encrypted security voucher is created from the database of known cp on the device at the time the image is uploaded, and the only way for Apple to decrypt something is if it matched something in that database. It did not sound like they could retroactively add additional hashes and decrypt something that already was uploaded. They could theoretically add something to the list of hashes and catch future uploads of it but my understanding was they cannot do this for stuff that has already been stored.
- sathackr 5y agoDirectly from the link: > ...the system performs on-device matching using a database of known CSAM image hashes provided by NCMEC and other child safety organizations. Apple further transforms this database into an unreadable set of hashes that is securely stored on users’ devices. >... The device creates a cryptographic safety voucher that encodes the match result along with additional encrypted data about the image. This voucher is uploaded to iCloud Photos along with the image.
- vineyardmike 5y ago> they cannot do this for stuff that has already been stored. That's a very simple software update. Every year iOS gets more images the automatic tagging supports (dogs, shoes, bridges, etc). And if you add a friend's face to known faces, it'll go and search every other photo for that face. It sounds absolutely trivial to re-scan when the hash DB gets updated.
- andruby 5y agoWhat will Apple do when Iran or Qatar (or any of the other 71 countries where homosexuality is illegal) upload photos to the CSAM database that they consider illegal acts? In some of those countries same-sex sex is punishable by death.
- gordon_gee123 5y agoNothing is stopping these countries from doing this already. China, Saudi Arabia, Iran already consider forcing tech companies to track user activity. At the end of the day these companies are subject to laws of the country they do business in and this has already screwed over HK, Uigher, Iranian, Egyptian citizens. Laws forcing data to be stored in given regions alongside encryption keys has already made it dangerous to be homosexual in these countries you’ve mentioned (except Iran which most businesses cannot do business in)
- khazhoux 5y ago> You are directed to scan all iPhone and iCloud storage for any pictures matching this NeuralHash and report to us where you find them. I think the US Govt (and foreign) would actually send Apple tens of thousands of NeuralHashes a week. Why would they limit themselves? False positives are "free" to them.
- dane-pgp 5y ago> False positives are "free" to them. Correct, just look at the incentives when it comes to handling sniffer dogs.
- snowwrestler 5y agoI get this sentiment but the known-bad-image-scanning technology is not new. That’s not what Apple announced. Many tech services already do that, which already enables the slippery slope you’re illustrating here. I’m not trying to minimize the danger of that slope. But as someone who is interested in the particulars of what Apple announced specifically, it is getting tiresome to wade through all the comments from people just discovering that PhotoDNA exists in general.
- vineyardmike 5y agoBut now its on your device. "Its just when you upload to icloud or recieve an iMessage" they say. BUT the software's on your device forever. What about next year? What about after an authoritarian goverment approaches them? By 2023 it might be searching non-uploaded photos. You can always not use cloud tech like PhotoDNA but you can't not use software BUILT IN to your device. Especially when its not transparent.
- mirkules 5y agoIt’s also not inconceivable to access the camera live and perform recognition live on feeds. It’s not even that expensive to do that anymore.
- osmarks 5y agoIt would probably kill the battery to do that constantly, as the processor would not be able to sleep ever. Although relying on energy efficiency to not improve is not a good long term situation.
- mirkules 5y agoYou can be selective about it. There is GPS to tell you where you are, microphone to tell you how many people are around, motion sensor, light sensor to sense if you’re in a pocket, etc. It doesn’t have to be constant, it could even be on demand. Personally, I am resigned to the fact that this kind of surveillance will happen. Technology cannot be slowed down or stopped artificially. There are just too many actors (not just Apple) to expect all of them to act in good faith. On top of that, the governments all over the world are salivating over this technology too. I don’t trust governments will curtail technology - and thus themselves - via policy. And even if one does, there is always another. This is almost nothing new in the UK, for example. I’m not optimistic in the direction we have been heading for the ladt 15 years or so.
- geekles 5y agoAs if this will be limited to "iThings". If you don't think this tech is coming to all devices, you're not paying attention to the state of the world.
- zepto 5y agoAs far as I can see: 1. This is a serious attempt to build a privacy preserving solution to child pornography. 2. The complaints are all slippery slope arguments that governments will force Apple to abuse the mechanism. These are clearly real concerns and even Tim Cook admits that if you build a back door, bad people will use it. However: Child pornography and the related abuse is widely thought of as a massive problem, that is facilitated by encrypted communication and digital photography. People do care about this issue. ‘Think of the children’ is a great pretext for increasing surveillance, because it isn’t an irrational fear. So: where are the proposals for a better solution? I see here people who themselves are afraid of the real consequences of government/corporate surveillance, and whose fear prevents them from empathizing with the people who are afraid of the equally real consequences of organized child sexual exploitation. ‘My fear is more important than your fear’, is the root of ordinary political polarization. What would be a hacker alternative would be to come up with a technical solution that solves for both fears at the same time. This is what Apple has attempted, but the wisdom here is that they have failed. Can anyone propose anything better, or are we stuck with just politics as usual? Edit: added ‘widely thought of as’ to make it clear that I am referring to a widely held position, not that I am arguing for it.
- MikeUt 5y ago> So: where are the proposals for a better solution? Better policing and child protective services to catch child abuse at the root, instead of panicking about the digital files it produces? If you'd been paying attention, you'd have noticed that real-world surveillance has massively increased, which should enable the police to catch predators more easily. Why count only privacy-betraying technology as a "solution", while ignoring the rise of police and surveillance capabilities? Edit as reply because two downvotes means I am "posting too fast, please slow down" (thank you for respecting me enough to tell me when I can resume posting /s): > How do you police people reaching out to children via messaging with sexual content? First, this is one small element of child abuse - you want to prevent child rape, merely being exposed to sexual content is nowhere near severe enough to merit such serious privacy invasion. To prevent the actual abuse, one could use the near-omnipresent facial recognition cameras, license plate readers, messaging metadata, to find when a stranger is messaging or stalking a child, DNA evidence after the fact that is a deterrent to other offenders, phone location data, etc. etc. At first I thought I didn't have to spell this out. Second, to answer your question: very easily. With parental controls, a decades old technology that is compatible with privacy and open-source. The parent can be the admin of the child's devices, and have access to their otherwise encrypted messages. There is no need to delegate surveillance (of everyone, not just children) to governments and corporations, when we have such a simple, obvious, already existing solution. It frankly boggles the mind how one could overlook it, especially compared to how technically complex Apple's approach is. Does the mention of child abuse simply cause one's thinking to shut down, and accept as gospel anything Apple or the government says, without applying the smallest bit of scrutiny?
- indymike 5y agoIts worse: Apple: hey govt, here's some probable cause. Govt: warrant, search, arrest User: prosecuted
- ggggtez 5y agoTechnically true, though I don't know why you think that capability is limited to Apple products... https://transparencyreport.google.com/youtube-policy/featured-policies/child-safety?hl=en https://transparencyreport.google.com/youtube-policy/feature...
- davidham 5y agoEven if you don’t use iOS, seems likely Google could do/is doing this also.
- emodendroket 5y agoWas it ever actually in doubt that Apple could read stuff you put in their cloud of they so desired? It seems obvious.