32 ms·
WhatsApp lead and other tech experts fire back at Apple’s Child Safety plan
- system2 5y agoIsn't WhatsApp part of Facebook? Why is it being separated as WhatsApp?
- deaddodo 5y agoBecause Will Cathcart is the lead of WhatsApp, not Facebook. As is mentioned clearly in the title. It's not like they are hiding the association as his quote is immediately followed up by: > WhatsApp’s owner, Facebook, has reasons to pounce on Apple for privacy concerns.
- wesleywt 5y agoTo be fair. Apple is opening up the door to allow Facebook to pounce.
- padolsey 5y agoLikely relevant as WhatsApp does not always see eye-to-eye with mother FB, notably on privacy issues. Source: used to work there.
- zpeti 5y agoI really hope there is enough momentum to stop this. It's definitely the last straw for me in terms of apple products. I haven't bought a new iphone for 4 years, I'm slowly trying to switch to a lightphone (non smartphone). My mac needs a change but I will probably switch to linux. It's absolutely ridiculous what apple has become. The exact opposite of what they used to represent, when I loved them. God rest Steve Jobs soul, his 1984 ad is exactly what apple is now. Screwed devs on app store, strongarmed into compliance, cooperation with china, worse and worse UX on phones, and now this... Really disappointing.
- Razengan 5y agoThis reads like a pre-prepared rant. > It's definitely the last straw for me in terms of apple products. Uhh and where else will you go where the grass is so much rosier privacy-wise?
- misnome 5y ago> I'm slowly trying to switch to a lightphone (non smartphone)
- nix23 5y agoPixel4 with LineageOS (Non google apps) F-Droid and Nextcloud for Backup and sync....grass is rosy for me ;)
- JackGreyhat 5y agoSame here. Doubles battery life too...
- nix23 5y agoThe Nextcloud-Client could be better, but i am pretty happy with my setup.
- JK_2234 5y agoComments from a different post shows this is "Presumably to implement E2E encryption, while at the same time helping the NCMEC to push for legislation to make it illegal to offer E2E encryption without this backdoor." If this is the case, then It is coming to every device (not just apple) or E2E will be made illegal(or a backdoor).
- 14 5y agoEnd-to-end encryption (E2EE) is a system of communication where only the communicating users can read the messages. In principle, it prevents potential eavesdroppers – including telecom providers, Internet providers, and even the provider of the communication service – from being able to access the cryptographic keys needed to decrypt the conversation.[1] End-to-end encryption is intended to prevent data being read or secretly modified, other than by the true sender and recipient(s). The messages are encrypted by the sender but the third party does not have a means to decrypt them, and stores them encrypted. The recipients retrieve the encrypted data and decrypt it themselves. Because no third parties can decipher the data being communicated or stored, for example, companies that provide end-to-end encryption are unable to hand over texts of their customers' messages to the authorities. Would it even be considered end 2 end encryption based on this Wikipedia definition? I don’t think it meets the definition if apple can determine certain files exist in a conversation.
- retskrad 5y agoTim Cook is one of the best managers in the world but this is one of very few instances where Apple completely forgot about their mission as a company under his leadership. I'm surprised he went ahead with this considering how much privacy goodwill they have built up over the years.
- pndy 5y ago> Tim Cook is one of the best managers What my SO says that he's just the manager of sales interested in selling their products and nothing else; the "else" is done by others - with marketing and pr and actual work.
- kfprt 5y ago'Child Safety' is extremely disingenuous. Their 'plan' provides no benefit to the safety of children and only strips users of their remaining shred of privacy. Authorities care more about stopping images than actual children currently being abused (lack of investigation into Sophie Long allegations). Of course this is because 'child safety' is merely a smokescreen for authoritarianism and tyranny. Just like China.
- HNisBaizuo 5y agoWait until you learn about how disingenuous using big tech to "fight Nazis" was
- mikro2nd 5y ago"The state must declare the child to be the most precious treasure of the people. As long as the government is perceived as working for the benefit of the children, the people will happily endure almost any curtailment of liberty and almost any deprivation." —Adolf Hitler
- fjfaase 5y agoI understand that the EU is working on legislation that would make Apple's Child Safety plan manditory on all private communication platforms within the EU.
- rmvt 5y agothat's awful. do you have a source on this?
- modernerd 5y agoSee https://european-pirateparty.eu/child-protection-through-scanning-of-private-messages-investigation-instead-of-monitoring/ https://european-pirateparty.eu/child-protection-through-sca.... > Not only searches for known pictures and videos are to be legalised, but also error-prone “artificial intelligence”, for example to automatically search text messages for “luring” of minors. If an algorithm reports a suspected message, message content and customer data could be automatically forwarded to law enforcement agencies and non-governmental organizations worldwide without human examination.
- heavenlyblue 5y agoIt will only take a few false-positive images shared on WhatsApp by everyone to take down that initiative.
- amelius 5y agoHow would that work on a Linux phone?
- ip_addr 5y agoIf you upload a file to email/a messenger service it would then scan the image.
- viktorcode 5y agoI believe it has a good chance of failing on level of different EU states. Just try telling a general German citizen that their private communications must be monitored.
- endisneigh 5y agoWhat are people switching too that is not susceptible to the same thing?
- bdibs 5y agoI’m considering a switch to GrapheneOS on a Pixel. I’m not sure if it’s an overreaction but I feel like I’ve lost what little trust I had remaining in Apple. It’s really unfortunate as they make quality products, but I guess everything sours eventually.
- PolCPP 5y agoWhy Graphene instead of Calyx? The later seems to be more user friendly (asking because i'm looking into it)
- bdibs 5y agoMy (limited) understanding so far is that Calyx is a "looser" Graphene security wise to make it a bit more user friendly, I'm wanting to just jump in with both feet. I don't use a ton of apps anyways so I don't think I'll be missing anything.
- myspy 5y agoWhat is striking is that a lot of misinformation is spreading around. How it works, what is behind it, what the alternatives could be, and especially what problem it tries to solve. This tweet here gives interesting options to learn more about it https://twitter.com/yoyoel/status/1424154582372872192?s=20 https://twitter.com/yoyoel/status/1424154582372872192?s=20 I have no imagination of the suffering of the kids behind it and it's definitely good that we fight it. But why not for older kids? Apparently this is already happening on all major platforms in the moment. Apples implementation is the most privacy friendly one, or isn't it?
- strzibny 5y agoIt isn't. It's the worst one.
- EtienneK 5y agoPlease elaborate. If as others have stated that this will enable E2E encryption in the cloud, then it very well might be?
- strzibny 5y agoThey don't provide E2E encryption in the cloud. And generally speaking I want my device to be mine. I don't even want debugging or app verification requests happening without my consent. It's my device and when I upload to the cloud, I'll use my own encryption.
- raspyberr 5y agoI think it's sad that the "think of the children" argument has been (ab)used so much that people are becoming numb to it.
- HNisBaizuo 5y agoWait until you find out your cherished support of using big tech to "fight nazis" over the last four years was a key part in normalizing moves like this.
- josefx 5y agoThe tool is just hilariously easy to abuse, in the west it "may" be limited to child porn, in some countries it might be images featuring gay sex, political dissent, parodies or other kinds of crimes against the regime.
- matheusmoreira 5y agoYeah. It's gotten to the point I automatically assume anyone who uses children as an argument is acting in bad faith.
- DavideNL 5y agoWhatsApp/Facebook critizing Apple for privacy… that’s hilarious.
- dalbasal 5y agoTake what you can get, just take it in context.
- danuker 5y agoTheater. Just like the FBI-Apple trial to get data from locked phones. https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_dispute https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d... I am pretty sure all of Big Tech is in collusion among themselves and with various governments, after what Snowden showed us. https://www.theguardian.com/world/2013/aug/23/nsa-prism-costs-tech-companies-paid https://www.theguardian.com/world/2013/aug/23/nsa-prism-cost...
- jensensbutton 5y agoI mean, at this point WhatsApp has a better rep. Facebook also hasn't compromised user data on behalf of China.
- mkl95 5y agoI find this controversy kind of vexing. Apple crossed the line between being strongly opinionated and patronising years ago. There's nothing about this plan that is out of character, Apple have and will continue making unilateral decisions on behalf of their users because it's their shtick.
- siscia 5y agoSo I was ignorant on the issue and completely against the approach of Apple. Then HN taught me that any company storing images on their infrastructure in the US must report pedophilic images to the US government. At this point, the approach taken by Apple seems like the best one to me, if you don't want to store pictures in clear on your servers. What other technical approach are people advocating for? Another point it is to try to change the law, but this is beyond the scope of the conversation.
- starfallg 5y ago>What other technical approach are people advocating for? Reduce user data stored in cloud data centres as much as possible. This is the approach taken by Whatsapp, so not surprised they are the ones most vocal against it. And at the risk of appearing to be supportive of a Facebook product, I think this is the right way to take computing. We don't need a central place to put stuff or to do compute when we can do it on our own devices. We just need orchestration.
- asutekku 5y agoHow would you do it? With whatsapp you have the file on messaging partner’s phone. People do not want to share their images over a peer network with random people.
- nicce 5y agoIt is a bit ironical that WhatsApp is worried about privacy. All message metadata is unecrypted and part of their business model. They don’t know about message contents, but they know everything about your social network (who do you message and when, who are part of your groups etc.) Add cross-app tracking with Facebook APIs and soon they can also categorize your message contents.
- ryanlol 5y ago> any company storing images on their infrastructure in the US must report pedophilic images to the US government Ones they know of… > What other technical approach are people advocating for? Apple already has a technical solution, encryption.
- Octabrain 5y agoWith the noble excuse of "protecting the children" they are just opening the vector that will allow them to go for other stuff in the future. I think this is just the first step and the intention is to make it "cognitively acceptable" for the majority of us later on. At this point, I have no doubt that in the future, a more ambiguous excuse such as "hate speech" will be used and under that umbrella, the elites will have a huge margin for pursuing any kind of "dissidence".
- HNisBaizuo 5y agoWait until you find out your noble support of using big tech to "fight nazis" over the last four years was a key part in normalizing moves like this.
- kfprt 5y agoThe authoritarian impulse is disturbingly common. This is a product of the long decline in societal trust. also, baizuo
- ashildr 5y agoThis vector has been opened for a while. Companies are not allowed to provide E2E encryption anymore, they have or will have (see EU) to scan every picture they host or transport for you.
- sebzim4500 5y agoThen how come so many companies provide E2E encryption? Are the signal devs about to be sent to Gitmo?
- HNisBaizuo 5y agoHN community was extremely avid about using big tech to stifle its political opponents based entirely on privacy-invading metadata collection over the last four years. They even bent over backwards with a mass addiction to the "Private companies can censor anyone they want" meme. They applauded it every step of the way. Now that the same tech will be applied to HN's child porn stash, all of a sudden, invasions of privacy are the grand evil. You people deserve the very worst of what big tech has to offer.
- fattybob 5y agoSeems to me a lot of noise about Apple joining all the other services in meeting US regulations, aren’t all major vendors equally compliant, maybe more invasively so!
- deleted 5y ago[deleted]
- ashildr 5y ago“other tech experts“ want to keep Apple from using End2End encryption so they have a reason why they don’t provide it to their customers. With Apple‘s approach Apple can only decrypt Data hosted with them if the (false) positives are over a threshold. It‘s a pretty neat way to implement a usecase so deeply wrong. All other companies protesting now want to keep access to userdata in the clear. Apple‘s approach is the only way to - at the same time - act lawfully regarding to EARN-IT act in the US and provide E2E in iCloud. I really hate these laws, but Apple is not the problem here. Read up on EARNIT and the EU laws currently in the works. All communication WILL HAVE TO BE SCANNED by the provider. Beating the drum against Apple will just lead to E2E encryption being forbidden. What needs to be forbidden instead is any access to communication. https://www.apple.com/child-safety/ https://www.apple.com/child-safety/ https://en.m.wikipedia.org/wiki/EARN_IT_Act_of_2020 https://en.m.wikipedia.org/wiki/EARN_IT_Act_of_2020 https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/12726-Bekampfung-des-sexuellen-Missbrauchs-von-Kindern-Erkennung-Entfernung-und-Meldung-illegaler-Online-Inhalte_de https://ec.europa.eu/info/law/better-regulation/have-your-sa...
- vorpalhex 5y agoEarn-IT is proposed legislation, not law. It has no power.
- thw0rted 5y agoJust to be clear, the EU already voted to allow snooping, the law "currently in the works" is to require it: https://www.patrick-breyer.de/en/posts/message-screening/?lang=en https://www.patrick-breyer.de/en/posts/message-screening/?la...
- elzbardico 5y agoThis applies only to photos that are uploaded to iCloud. Apple is doing to do the processing on the device though, but only for the photos that are going to be uploaded to iCloud. Like other services do. WhatsApp is a Facebook property and decided to use this confusion to hit Apple politically with a low punch. People that should know better prove once again that most people read no much than the headlines and base their conclusions on the tastiest sound bytes they hear.
- BatteryMountain 5y agoFacebook still sour about Apple blocking tracking mechanisms, hence the low punch?
- bitcurious 5y agoThat’s like building a tank and saying it’ll only be used for deliveries. Once the infrastructure is in place on every device to detect arbitrary images/messages on the device the switch will be flipped.
- elzbardico 5y agoiOS is not open source, so, Apple could just deliver the spy payload with another update and probably nobody would ever know if that was the intention. The slippery slope argument simply don't make much sense here (as usual, btw)
- pnt12 5y agoYou can keep that secret until someone goes to court or has police raid their house over photos that were supposedly end to end encrypted. Like whatsapp saying their chat is encrypted, is it really? Well, Facebook is trying really hard to losen this up, why don't they just release an update sending them the keys?
- charcircuit 5y agoThe infrastructure for detecting files does not need to be that complex. We are talking something a single engineer can do in less than an hour.
- holstvoogd 5y agoI'm so fucking tired of these asswipes from companies are a thousand times worse pretending they are better. They literally sell all your data to anyone who wants is, but noooo, apple bad! I'm not saying apple is some kind of bastion of privacy or whatever, but at least they are not selling my data to pay for their spyware vessels. To those 'experts': Get off you high horse and do better. Prove me wrong, go build a working open-source phone, go provide a image hosting service that does not analyze every single photo you upload. Go build a fucking app with out trying to steal my contact book. Fuck you
- iamstupidsimple 5y ago> Go build a fucking app with out trying to steal my contact book. Fuck you Not saying I agree. But people have tried, guess which social networks self-select out of survival?
- gbrown 5y agoWell, there was that priest who got outed through data brokers recently…
- badRNG 5y ago> But people have tried, guess which social networks self-select out of survival? Is the implication that a social media network won't survive if it doesn't steal my contacts? Besides, not all social media companies stoop to that level. For all it's problems, Reddit doesn't steal your contacts.
- a254613e 5y ago> They literally sell all your data to anyone who wants is Where/how can I buy all data for, let's say a dozen users, that facebook collects? No wonder public is completely misinformed about how ad revenue based companies operate when even on HN blatant lies are highly upvoted.
- cascom 5y agohttps://arstechnica.com/tech-policy/2021/07/catholic-priest-quits-after-anonymized-data-revealed-alleged-use-of-grindr/ https://arstechnica.com/tech-policy/2021/07/catholic-priest-...
- traceroute66 5y agoI'm in two minds about this Apple news. In one part, the pro-privacy part of me is of course aghast at the whole idea. However... If you "read the room", there have been increasing noises from the global political world in recent years, and perhaps especially in the US. So if you think about it that way, it might be a case of Apple jumping before they were pushed. I mean, let's face it, if you wait for the politicos to come up with a solution and force it through with legislation, they really would put in actual backdoors and encryption bans given half the chance. I suspect others, such as WhatsApp, might begrudgingly follow in due course. There's always GPG and a whole litany of other tools and apps for those who know what they are doing in terms of privacy.
- ndr 5y ago> There's always GPG and a whole litany of other tools and apps for those who know what they are doing in terms of privacy. And it's always there also for whoever they claim to want to catch, so this measure is useless. This is not protecting anyone, Apple might very well be anticipating the regulation, but that does not automatically deserve our praise. We should fight against this implementation and any regulation requiring similar measures.
- comeonseriously 5y ago> And it's always there also for whoever they claim to want to catch, so this measure is useless. Right. This will, a) catch the low hanging fruit type of criminal and b) keep honest people honest while forcing them to give up something for nothing.
- ndr 5y agoc) non-trivial chance it will be used for something much worse than what (a) & (b) fix, without solving the main issue That risk is not tiny, can you imagine any authoritarian government asking a compliant Apple to remove inconvenient pictures?
- studentrob 5y ago
- nyuszika7h 5y agoThis is extremely hypocritical coming from Facebook, who is working on a system to scan E2E encrypted WhatsApp messages to use them for targeted advertising.
- deleted 5y ago[deleted]
- throwaway75 5y agoSometimes there are more important things than maintaining individual privacy and this is clearly one of them. Finding and protecting even a few children from becoming victims of pornography is clearly something that is well worth my not having 100% privacy. Even knowing that there might be false alarms. Despite what the strident discourse has been, individual privacy is not some sancrosanct idea that cannot ever be tread upon. There are some things that are far far more important than that.
- okokwhatever 5y agoNo sir, not at all. The basement of all individual rights is freedom. If police can't do their job in a proper way we shouldn't abandone our right to not be monitored in our private life to supplant their ineffectiveness.
- HNisBaizuo 5y agoIt's a private company. They can do whatever they want. Something something "but we fought Nazis together!" forced justification
- gigel82 5y agoPoliticians love this guy ^ ; that's the way to right-think citizen, carry on :)
- throwaway75 5y agoChild pornographers love this guy ^ ; that's the way to right-think consumer, carry on :)
- 46ve18v 5y agoThat's not even Apple role to fight child abuses. That's the governements role
- 1024core 5y agoThe road to hell is paved with good intentions. Everything starts off with "won't anyone think of the children?". Next thing you know, Apple is scanning your photos for faces of known "terrorists", etc. I have children, and hate CP with a passion, but know that this is not the answer.
- vorpalhex 5y agoTerrorists, illegal drug use, "dangerous" materials like pipes or fuses (god forbid if you like model rocketry). The list goes on.
- TravisHusky 5y agoThis whole thing was the final straw to get me to switch away from iPhone. I decided to get a PinePhone, even though they are not ready for primetime, I am an embedded OS developer by trade, so I figure I might as well give it a go and see what I can contribute. I only use my phone for web browsing and Telegram anyway which are apparently usable on PinePhone.
- kkarakk 5y agoAnd the journey to not being able to trust big tech smartphones just like you can't trust big tech social media has been completed. Guess I'm gonna have to buy a semi terrible privacy focused smart device with phone capabilities in the near future.
- pyaamb 5y agodoes anyone know if there has been studies showing rise in child sexual exploitation that would warrant something so drastic? I would have imagined it would be lower as society progresses but i do not know. I dont see enough people asking if giving up our personal privacy is really warranted or if we are being mislead. People should be asking for hard proof.
- jgaa 5y agoChild porn was, as far as I remember, made illegal because 2 million children was used in it's production. Now that number is 5 million.
- amanaplanacanal 5y agoIs that five million a year, or five million total, including the original two million? This isn’t saying anything about whether more children are being abused now. Given how ubiquitous cameras are, I can fully imagine more pictures being taken, though.
- jgaa 5y agoIt's just a number taken out of thin air, just like the original 2 million.
- Componica 5y agoImagine taking a photo or have in your gallery a photo a dear leader doesn't want to spread. Ten minutes later there's a knock at your door.
- throwaway75 5y agoImagine now a young child being sexually abused in front of a camera for all its years of existence, and that there's no knock on the door.
- amanaplanacanal 5y agoSo if the camera goes away, the child abuse won’t happen? Somehow I doubt that.
- aeternum 5y agoFalse dichotomy, how long will it take the predators to learn not to use apple devices as cameras? Yet the privacy implications will last forever. Once it's implemented, it only takes a rubber-stamp warrant to compel Apple to scan your device for anything the government deems concerning. In fact, no warrant needed in most countries.
- throwaway75 5y ago> how long will it take the predators to learn not to use apple devices as cameras? Which is why you make it mandatory on all devices sold, not just apple.
- aeternum 5y agoThere are plenty of non-cloud connected digital cameras out there.
- Componica 5y agoImagine taking a photo or have in your gallery a photo a dear leader doesn't want to spread. Ten minutes later you heard a knocking at your door.
- isodev 5y agoIt’s funny that WhatsApp, who themselves do the very same thing (in a much less transparent and privacy minded way) would call out Apple.
- wydfre 5y agoWhat is going on with people - why on earth are people overreacting to this. Apple is doing something unconditionally good, and people are posting about how it is bad? I mean the people writing the opposition to this change just sound pants-on-head stupid, and obviously suffer from sort of mental health problem (such as this[0]). Imagine the poor NSA having to know this evil and doing nothing, and Apple is doing it's small bit to help. It sounds a lot better than the useless HUMINT divisions. [0]: https://www.reddit.com/r/apple/comments/p0i9vb/bought_my_first_pc_today/ https://www.reddit.com/r/apple/comments/p0i9vb/bought_my_fir...
- thw0rted 5y agoIf you care about the issue, this post[1] does a pretty good job explaining what people are worried about. 1: https://www.hackerfactor.com/blog/index.php?/archives/929-One-Bad-Apple.html https://www.hackerfactor.com/blog/index.php?/archives/929-On...
- voidnullnil 5y agoThe most annoying thing is that everyone denouncing Apple's action still agree that "CSAM" is a problem that needs action by technology companies (and thus decentralized stuff should be illegal). While "CSAM" is a problem, just like any crime, it's completely overblown and much more rare than they pretend it is. NO. The internet doesn't need regulation. Never. - Most instances of "child abuse" involve something that matches the legal term, but involves teenagers and is almost certainly not abuse - Lots of conservatives want to punish said teens and anyone involved for sexuality and go along with the sophistry of calling people abuse victims when they have consensual sex or post their nude photos online - Naturally, there is no incentive to look at naked 5 year olds, because that's not how the human body works. This is an edge case and is what the media makes out to be the norm Stop pretending to have a "mature perspective". Companies should literally never touch your data unless there is a search warrant. Now that I read this article I'm concerned about what WhatsApp is doing.
- nathanvanfleet 5y agoI had heard that WhatsApp and many other such products have been doing this, in a more unfettered way, for a decade?
- tablespoon 5y ago> Kendra Albert, an instructor at Harvard’s Cyberlaw Clinic, has a thread on the potential dangers to queer children and Apple’s initial lack of clarity around age ranges for the parental notifications feature. >> The idea that parents are safe people for teens to have conversations about sex or sexting with is admirable, but in many cases, not true. (And as far as I can tell, this stuff doesn't just apply to kids under the age for 13.) — Kendra Albert (@KendraSerra) August 5, 2021 >> EFF reports that the iMessage nudity notifications will not go to parents if the kid is between 13-17 but that is not anywhere in the Apple documentation that I can find. https://t.co/Ma1BdyqZfW https://t.co/Ma1BdyqZfW — Kendra Albert (@KendraSerra) August 6, 2021 I'm against Apple forcing a backdoor onto every device, but this argument falls totally flat to me. Yes there are shitty parents out there, but despite that, parents still need the ability to parent. If Apple's "think of the children" arguments for their backdoor are wrong, then this "think of the children" argument against it is wrong too. There's nothing wrong with notifying parents that their pre-teen is doing someone they shouldn't be doing with their phone. IMHO, I'd support the existence of such feature, but only as long as it's a user-installable option, not installed on every phone as part of the OS.
- hi41 5y agoFew years back Google informed authorities about a person who stored vile images of child porn in Google Drive. How is Apple’s implementation any different from that of Google. Aren’t both the same? However, I did not see lot of protests against Google at that time.
- darthrupert 5y agoDon't criticize this idea without informing us of a better way to protect against the worst offences of modern internet life. Privacy advocates don't seem to get it. There can not and will not be a future where these people can hide in the net. Either somebody figures a way to catch them without hurting the privacy of the innocent, or we will use systems that hurt the privacy of the innocent. There is no third option, so put your energy into finding a solution that satisfies the first option if you care about this so much.