13 ms·
So I was ignorant on the issue and completely against the approach of Apple. Then HN taught me that any company storing images on their infrastructure in the U
by siscia 5y ago
So I was ignorant on the issue and completely against the approach of Apple.
Then HN taught me that any company storing images on their infrastructure in the US must report pedophilic images to the US government.
At this point, the approach taken by Apple seems like the best one to me, if you don't want to store pictures in clear on your servers.
What other technical approach are people advocating for?
Another point it is to try to change the law, but this is beyond the scope of the conversation.
- starfallg 5y ago>What other technical approach are people advocating for? Reduce user data stored in cloud data centres as much as possible. This is the approach taken by Whatsapp, so not surprised they are the ones most vocal against it. And at the risk of appearing to be supportive of a Facebook product, I think this is the right way to take computing. We don't need a central place to put stuff or to do compute when we can do it on our own devices. We just need orchestration.
- asutekku 5y agoHow would you do it? With whatsapp you have the file on messaging partner’s phone. People do not want to share their images over a peer network with random people.
- nicce 5y agoIt is a bit ironical that WhatsApp is worried about privacy. All message metadata is unecrypted and part of their business model. They don’t know about message contents, but they know everything about your social network (who do you message and when, who are part of your groups etc.) Add cross-app tracking with Facebook APIs and soon they can also categorize your message contents.
- ryanlol 5y ago> any company storing images on their infrastructure in the US must report pedophilic images to the US government Ones they know of… > What other technical approach are people advocating for? Apple already has a technical solution, encryption.
- ashildr 5y agoEncryption does not help, Apple still is responsible. If Apple intends to let the user store photos in iCloud (or send by imessage) encrypted, they either have to keep the keys, so they can decrypt and scan the photos or or to keep the user from uploading incriminating content. Apple found a third way: they will only get to reconstruct the keys if the user uploads too many pictures triggering alarms.
- adambatkin 5y agoSource? I am not aware of a law in the US that requires Apple to actively scan images, or to store them unencrypted (or keep copies of the keys).
- hef19898 5y agoThe US aren't the only government with a stake in that. And countries like China, Saudi, the Emirates have a lot of leverage. Financially and diplomatic. Heck, Facebook bowed to Myanmar just to get the users there.
- nicce 5y agoEvery cloud infrastructure holder is required for doing that. Closing an eye does not take a duty away. You must be actively pursuing that. Encryption would start flood of new laws https://www.govinfo.gov/app/details/USCODE-2011-title18/USCODE-2011-title18-partI-chap110-sec2258A/summary https://www.govinfo.gov/app/details/USCODE-2011-title18/USCO...
- PolCPP 5y agoYou could generate hash on device, send it to server alongside the file, once validated delete hash or create decoding voucher.
- nicce 5y agoThis is exactly what they are doing right now. Decoding voucher applies when their system thinks that too many hashes goes into CSAM category.
- nojito 5y agoApple doesn’t scan iCloud for CSAM and refuses to do it. Which is why they researched intensively on differential privacy.
- sneak 5y agoBut they could, as iCloud Photos is not e2e (Apple can read all of it) and they turn over the user data on over 30,000 users per year to the USG without even a warrant. This is just farce.
- zepto 5y ago> But they could, as iCloud Photos is not e2e Client side scanning is a prerequsite to making it e2e if you also want countermeasures against CSAM.
- amanaplanacanal 5y agoHas Apple said this is what they are going to do, or are people just guessing?
- zepto 5y agoThey haven’t announced this, but they invest a lot in encryption and privacy, and have stated that user privacy is a value of theirs. They have also expressed that they don’t want access to be able to be forced by law enforcement.
- sneak 5y agoTheir actions speak louder than their words.
- zepto 5y agoAnd their actions show that they aren’t likely to do any of the scary things they are being accused of. That’s the point - people keep claiming some nefarious slippery slope, which is of course in the realm of possibility, but is not actually happening.
- viktorcode 5y agoThe problem I have with this approach is that it introduces on-device scan for images. All what is needed to adopt it to scan for different kind of images is to connect it to different database, say, Winnie the Pooh memes featuring CCP chairman, and boom, jailed dissenters. And ability to scan all images is but a minor firmware update away. Server scanning makes it clear that the company running the servers has access to your photos. So you can either find a form of encrypted storage, or be okay with that, depending on your privacy stance. Having device with ability to scan your photos removes that choice. It is a privacy invasion.
- EveYoung 5y agoBut Apple only plans to scan photos that are synced with iCloud, don't they? So you could just switch to an E2E encrypted alternative and drop iCloud completely.
- unionpivo 5y agoYes but it probably took additional code to only scan pictures that are synced to iCloud. Probably not monumental task, to change to scan every picture.
- nicce 5y agoI have to remind again, that iOS is a blackbox, closed source system. All this speculation applies also for a moment before they added anything. They might have had this code ready for years already. All we have is what they say. It is already very trivial to scan everything on on your device and send that metadata. Few lines of code. At the moment when they say about scanning everything in phone publicly without opt-out, then we should be worried. Once again, there is no way telling what they are doing already.
- unionpivo 5y agoThe difference is now every government knows too. They can't pretend they don't have the capability. And if they can scan for CP, why can't they scan for "whatever" else instead.
- 542458 5y agoDo mandatory reporter laws work like that? I was under the impression that you had to report something if you saw it, but you had no obligation to be actively scanning or to compromise encryption to do so. For example, I don’t think S3 does any active scanning and you can definitely shove any encrypted blob you want onto their servers with no obligation to give them a decryption key. IMO this appears to be Apple either a) trying to preempt future criticism or regulation or b) responding to some behind-closed-doors pressure/bargaining with US authorities.
- nicce 5y agoI think you have to be aware of what is happening, before you can say that nothing criminal happens. This is where scanning steps in. You can’t turn blind eye.
- amanaplanacanal 5y agoThere is a big jump from reporting criminal activity if you happen to see it, to actively searching it out. It is the jump from police arresting you if they see you smoking a joint to police searching your rooms to make sure you don’t have any cannabis in there.
- nicce 5y agoI read the law and you are correct, there is explicitly mentioned that provider is not required to enforce seeking of CSAM evidence. However, they might be required to comply the demands of NCMEC if they ask to stop redistribution of certain visual depictions by providing hashes. This is were scanning steps in.
- sebzim4500 5y agoThey could still do the scanning, but if the photo fails it would just refuse to upload it and display an error to inform the user that the photo will not synchronize. There is no reason that the results of the scans need to be sent to Apple servers.
- nicce 5y agoIf you read the technical details, result of the scan is packed with the photo. So, if upload of photo fails, then result of the scan is not uploaded as well.
- GeekyBear 5y ago> Then HN taught me that any company storing images on their infrastructure in the US must report pedophilic images to the US government. It's certainly been going on for the past decade. For example: >a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-led-to-a-mans-arrest-for-child-porn-was-not-a-privacy-violation/ https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le...
- matheusmoreira 5y agoSimple. 1. Encrypt everything. 2. Don't store images on your servers at all. There's nothing to report if all you have is some encrypted blob. Alternatively, just don't consume any user data at all. Data is and should be a massive liability.
- skinkestek 5y ago> Data is and should be a massive liability. My thoughs as well. If you don't want there very dangerous weapon you have thought out to be abused, don't create a physical assembly of it and don't tell anyone who has a habit of abusing powerful weapons.
- LatteLazy 5y agoApple aren't required to decrypt anything. This is why ever other server/storage provider are not also demanding access to everything client side (or keys to decrypt server side). It's a red herring for Apple to pretend they're "required" to do this, they're no more required to do so any more than the post office are required to open your mail on the off chance they might be handling CP...
- hef19898 5y agoBecause once that functionality is there it affects everyone, not just in the US. And it basically means we sell out our democratic principles, or rather allow our tech giants to sell it out. Or force them to do it, like our elected governments doing it. Either way, I don't like the outcome.
- zepto 5y ago> Because once that functionality is there it affects everyone, not just in the US. The functionality to detect CSAM uploaded to Apple’s servers or sent to pre-teens? > And it basically means we sell out our democratic principles What democratic principle is being sold out?
- hef19898 5y agoThe right to secret communication. The right of not being under surveillance. The government cannot open letters without a warrant, but somehow Apple, Google, MS and co can sniff through electronic communication as they see fit because of a clause in an EULA. No idea how came there, but maybe the days when Stasi surveillance was the poster child of government intrusion into private life are too long gone to be remembered. Or they aren't and certain people choose to make shit load of money from the thing.
- amanaplanacanal 5y agoMight as well make it legal for police to search our houses at will, as long as they are looking for child abuse images. Doesn’t sound much like the US any more at that point.
- zepto 5y ago> Apple, … can sniff through electronic communication as they see fit Except that they can’t and don’t.
- hef19898 5y agoGoogle is checking, apparently, Gmail for cp. Apple is doing it, soon, on your phone. Checking your mail for analog cp requires a warrant and can only be done by police. See the difference?
- ianmiers 5y agoApple's banned image reporting wont stay iCloud only.iMessage is next. Maybe all data on your phone. 1) phone scanning is overkill for pics already on their servers. You don't build this and take the PR flack for something you can already do server side 2) Even if it's somehow not Apple's plan, they will be forced to use it on iMessage. Congress has been trying to for years.See the EARN IT act[0]. Apple just erroneously said "it's safe" despite the fact that it clearly can be abused. [0] https://blog.cryptographyengineering.com/2020/03/06/earn-it-is-an-attack-on-encryption/ https://blog.cryptographyengineering.com/2020/03/06/earn-it-...
- zepto 5y ago> You don't build this and take the PR flack for something you can already do server side That’s exactly what you do if you plan to enable E2E.
- ianmiers 5y agoYep. That certainly is the next step. And then, once you are scanning encrypted data, iMessage is next whether you want it or not.
- zepto 5y ago> And then, once you are scanning encrypted data, They aren’t. > iMessage is next whether you want it or not. Is there some evidence you have of this plan? Sounds like this is just a fear you have.
- ianmiers 5y ago>Is there some evidence you have of this plan? Sounds like this is just a fear you have. The EARN IT act. It may not be Apple's plan, Apple's plan, as you suggest, might only be for doing scanning on encrypted iCloud and excluding encrypted iMessage. But what Apple will be pushed to do after that is pretty clear.
- tyingq 5y ago>if you don't want to store pictures in clear on your servers Reading https://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303 , it seems that Apple may encrypt pictures on their servers, but they have the key. The list of what's actually end-to-end encrypted doesn't include photos. So, they may be scanning on your phone, but they can scan on their servers if they wanted to.
- siscia 5y agoI believe the want this update exactly to enable E2E encryption. In this way the can get rid of the keys on their servers and still find pedo pictures.
- thw0rted 5y agoI posted more detail upthread but what I've found suggests that Apple does have a key to decrypt pictures but they claim to use it only to respond to a warrant. (They could of course be lying about that, but I don't believe they are.)
- dhfjskh 5y ago>Then HN taught me that any company storing images on their infrastructure in the US must report pedophilic images to the US government. That's not true though.