3 ms·
> The parts of it being uploaded to iCloud, not the whole thing, yes? This is policy, not capability. The capability is each and every image can be scanned. >
by krinchan 5y ago
> The parts of it being uploaded to iCloud, not the whole thing, yes?
This is policy, not capability. The capability is each and every image can be scanned.
> As I understand it, the whole point is that the hashes are computed on-device and compared to the NCMEC database on-device. Is my understanding incorrect?
You are incorrect but also the concern is NCMEC’s database’s accuracy. Also, going by other NPO’s the government has taken an interest in, NCMEC is very exposed to government control. They can easily decide to allow the government to slip a few extra hashes in their database and tell no one. They can do this in exchange for protecting their NPO status, a national security letter, anything. We will never know and if we find out, we will have no way to hold them accountable. Ever.
Anyway, the NMEC database is NDA’ed and a secret. It’s not open to review or auditing. It’s also grossly inaccurate and nearly useless.
You are taking these points entirely out of context and in a vacuum. It reads a bit bad faith and win an Internet argument at any cost.
- bzbarsky 5y ago> This is policy, not capability. The capability is each and every image can be scanned. Are you familiar with the implementation? If it's in the uploader, then the capability for each image to be scanned sounds like it would involve a bunch of code changes. But let's posit that the implementation just checks the "uploaded to iCloud" flag and hence this is "just policy". I agree that this is concerning, but I think it's important to distinguish between "could do X" and "is doing X" when describing a situation. > You are incorrect I would love to be enlightened here. Can you please point me to an explanation of how my understanding is incorrect? > but also the concern is NCMEC’s database’s accuracy I absolutely share this concern. > You are taking these points entirely out of context and in a vacuum. No, I don't think I am. I think there is enough heated rhetoric going on here, with people mis-stating what is actually going on to justify how they feel about it, that it's worth being very clear about what the problems here really are. Otherwise it feels like people are arguing against strawmen and makes it too easy to dismiss concerns that are very pertinent. The original article for this thread, by the way, does a good job here.
- krinchan 5y agoAgree to disagree on the rest, I don’t feel there’s more to say that would convince you or vice versa. But I will respond to this point: I said: > Anyway, the NMEC database is NDA’ed and a secret. It’s not open to review or auditing. NMEC itself would never go for the entirety of the database sitting on each phone. It’s a jailbreak away from “Them” having the database and being able to check their images before uploading them places. (This overlooks the fact that it’s almost universally accepted by everyone outside of NMEC that deals with NMEC that “They” have the database several times over.)
- benhurmarcel 5y ago> This is policy, not capability. The capability is each and every image can be scanned. That capability is in every software/app that has access to your photos and to the internet, on any device.