8 ms·
It's worth reading this, which is basically the only good reporting I've seen on this topic: https://daringfireball.net/2021/08/apple_child_safety_initiatives_s
by fossuser 5y ago
It's worth reading this, which is basically the only good reporting I've seen on this topic: https://daringfireball.net/2021/08/apple_child_safety_initiatives_slippery_slope https://daringfireball.net/2021/08/apple_child_safety_initia...
There are legitimate things to be concerned about, but 99% of internet discussion on this topic is junk.
- Spooky23 5y agoThe EFF wrote a really shitty hit piece deliberately confused the parental management function with the matching against hashes of illegal images. Two different things. From there, a bazillion hot takes followed.
- dathinab 5y agoTwo different things which are sold as one package by Apple. Two different things which both are known to be prone to all kind of miss-detection.
- rootusrootus 5y agoYeah I found the EFF's piece to be really disappointing, coming from an organization I'm otherwise aligned with nearly 100% of the time.
- shapefrog 5y agoEFF today is really not the organisation it was just a few years ago. I dont know who they hired badly, but the reasoned takedowns have been replaced with hysterical screaming.
- merpnderp 5y agoCan you quote what you found confusing, because I didn't see anything that didn't agree with the Apple announcement they linked in the piece.
- washadjeffmad 5y agoThe EFF article refers to a "classifier", not just matching hashes. So, three different things. I don't know how much you know about them, but this is what the EFF's role is. Privacy can't be curtailed uncritically or unchecked. We don't have a way to guarantee that Apple won't change how this works in the future, that it will never be compromised domestically or internationally, or that children and families won't be harmed by it. It's an unauditable black box that places one of the highest, most damaging penalties in the US legal system against a bet that it's a perfect system. Working backwards from that, it's easy to see how anything that assumes its own perfection is an impossible barrier for individuals, akin to YouTube's incontestable automated bans. Best case, maybe you lose access to all of your Apple services for life. Worst case, what, your life? When you take a picture of your penis to send to your doctor and it accidentally syncs to iCloud and trips the CSAM alarms, will you get a warning before police appear? Will there be a whitelist to allow certain people to "opt-out for (national) security reasons" that regular people won't have access to or be able to confirm? How can we know this won't be used against journalists and opponents of those in power, like every other invasive system that purports to provide "authorized governments with technology that helps them combat terror and crime[1]". Someone's being dumb here, and it's probably the ones who believe that fruit can only be good for them. [1] https://en.wikipedia.org/wiki/Pegasus_(spyware) https://en.wikipedia.org/wiki/Pegasus_(spyware)
- FabHK 5y ago> When you take a picture of your penis to send to your doctor and it accidentally syncs to iCloud and trips the CSAM alarms, will you get a warning before police appear? You would have to have not one, but N perceptual hash collisions with existing CSAM (where N is chosen such that the overall probability of that happening is vanishingly small). Then, there'd be human review. But no, presumably there won't be a warning. > Will there be a whitelist to allow certain people to "opt-out for (national) security reasons" that regular people won't have access to or be able to confirm? Everyone can opt out (for now at least) by disabling iCloud syncing. (You could sync to another cloud service, but chances are that then they're scanned there.) Beyond that, it would be good if Apple built it verifiably identically across jurisdictions. (If you think that Apple creates malicious iOS updates targeting specific people, then you have more to worry about than this new feature.) > How can we know this won't be used against journalists and opponents of those in power, like every other invasive system that purports to provide "authorized governments with technology that helps them combat terror and crime[1]". By ensuring that a) the used hash database is verifiably identical across jurisdictions, and b) notifications go only to that US NGO. Would be nice if Apple could open source that part of the iOS, but unless one could somehow verify that that's what's running on the device, I don't see how that would alleviate the concerns.
- samename 5y agoJohn Gruber is biased because his brand is closely tied to Apple’s brand. Ben Thompson wrote a better review on the topic: https://stratechery.com/2021/apples-mistake/ https://stratechery.com/2021/apples-mistake/ There’s also the Op-Ed by Matthew Green and Alex Stamos, cyber security researchers: https://www.nytimes.com/2021/08/11/opinion/apple-iphones-privacy.html https://www.nytimes.com/2021/08/11/opinion/apple-iphones-pri...
- fossuser 5y agoThey have a podcast together called Dithering which is pretty good (but not free) - they're friends. I think John's article is better than Ben's, but they're both worth reading. Ben takes the view that unencrypted cloud is the better tradeoff - I'm not sure I agree. I'd rather have my stuff e2ee in the cloud. If the legal requirements around CSAM are the blocker then Apple's approach may be a way to thread the needle to get the best of both worlds.
- deleted 5y ago[deleted]
- AlexandrB 5y agoOne logical conclusion of systems like this is that modifying your device in any "unauthorized" way becomes suspicious because you might be trying to evade CSAM detection. So much for jail-breaking and right to repair! I think I'd rather have the non-e2ee cloud.
- slownews45 5y agoEven HN reporting / article linking / comments have been surprisingly low quality and seem to fulminate and declaim with surprisingly little interesting conversation and tons of super big assertions. Linked articles and comments have said apple's brand is now destroyed, that apple is committing child porn felonies somehow with this (the logical jumps and twisting to get to these claims are very far from strong plausible interpretation). How do you scan for CASM in an E2EE system is the basic question Apple seems to be trying to solve for. I'd be more worried about the encrypted hash DB being unlockable - is it clear this DOES NOT have anything that could be recreated into an image? I'd actually prefer NOT to have E2EE and have apple scan stuff server side, and keep DB there.
- still_grokking 5y agoFrom https://www.hackerfactor.com/blog/index.php?/archives/929-One-Bad-Apple.html https://www.hackerfactor.com/blog/index.php?/archives/929-On... > The laws related to CSAM are very explicit. 18 U.S. Code § 2252 states that knowingly transferring CSAM material is a felony. (The only exception, in 2258A, is when it is reported to NCMEC.) In this case, Apple has a very strong reason to believe they are transferring CSAM material, and they are sending it to Apple -- not NCMEC. > It does not matter that Apple will then check it and forward it to NCMEC. 18 U.S.C. § 2258A is specific: the data can only be sent to NCMEC. (With 2258A, it is illegal for a service provider to turn over CP photos to the police or the FBI; you can only send it to NCMEC. Then NCMEC will contact the police or FBI.) What Apple has detailed is the intentional distribution (to Apple), collection (at Apple), and access (viewing at Apple) of material that they strongly have reason to believe is CSAM. As it was explained to me by my attorney, that is a felony. Apple is going to commit child porn felonies according to US law this way. This claim seems actually quite irrefutable.
- rootusrootus 5y agoApple isn't looking at the actual image, but a derivative. Presumably their lawyers think this will be sufficient to shield them from accusations of possessing child porn.
- echelon 5y agoGruber practically (no, perhaps actually) worships Apple. He'd welcome Big Brother into his house if it came with an Apple logo, and he'd tell us how we were all wrong for distrusting it. He's not the voice to listen to this time, and you should trust him to have your best interests at heart. People are furious with Apple, and there's no reason to discount the completely legitimate concerns they have. This is a slippery slope into hell. It's a good thing congress is about to start regulating Apple and Google. Maybe our devices can get back to being devices instead of spy tools, chess moves, and protection rackets. (read: Our devices are supposed to be property. Property is something we fully own that behaves the way we want. It doesn't spy on us. Property is something we can repair. And it certainly is not a machination to fleece the industry by stuffing us into walled and taxed fiefdoms, taking away our control. Discard anything that doesn't behave like property.) [edit: I've read Gruber's piece on this. It's wish-washy, kind of like watching a moderate politician dance on the party line. Not the direct condemnation this behavior deserves. Let's not take his wait and see approach with Dracula.]
- mistrial9 5y ago> regulating Apple and Google this is not strong safety for citizens source: political history
- acdha 5y ago> Gruber practically (no, perhaps actually) worships Apple. He'd welcome Big Brother into his house if it came with an Apple logo, and he'd tell us how we were all wrong for distrusting it. You mean the same Gruber who described the situation as “justifiably, receiving intense scrutiny from privacy advocates.”? The one who said “this slippery-slope argument is a legitimate concern”? I'm having a hard time reconciling your pat dismissal with the conclusion of his piece which very clearly rejects the position you're attributing to him as grounds for dismissal: > But the “if” in “if these features work as described and only as described” is the rub. That “if” is the whole ballgame. If you discard alarmism from critics of this initiative who clearly do not understand how the features work, you’re still left with completely legitimate concerns from trustworthy experts about how the features could be abused or misused in the future. I mean, sure, know where he's coming from but be careful not to let your own loyalties cause you to make a bad-faith interpretation of a nuanced position on a complex issue.
- ursugardaddy 5y agoIt's still a non-zero chance it triggers a no-knock raid by the police that kills your family or pets. it happens all the time
- lawkwok 5y agoNon-zero being technically true because of the subject matter, but I don’t see how Apple’s system increases the risk of authorities killing family or pets more than server-side scanning.
- merpnderp 5y agoTheir neural hashing is new, and they claim has a one in a trillion collision rate. There are 1.5 trillion images created in the US and something like 100 million photos in the compared database. That's a heck of a lot of collisions. And that's just a single year, Apple will be comparing everyone's back catalog. A lot of innocent people are going to get caught up in this.
- lawkwok 5y agoWe’ll have to wait and see how good their neural hashing is, but just to clarify the 1 trillion number is the “probability of incorrectly flagging a given account” according to Apple’s white paper. I think some people think that’s the probability of a picture being incorrectly flagged, which would be more concerning given the 1.5 trillion images created in the US. Source: https://www.apple.com/child-safety/pdf/CSAM_Detection_Technical_Summary.pdf https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
- jhayward 5y agoHow is it that you are going to "wait and see how good their neural hashing is"? Do you think there is going to be any shred of transparency about the operation of this system? It is completely unaccountable - starting with Apple and going on to NCMEC and the FBI.
- 5y ago
- montagg 5y ago“If it works as designed” is I think where Gruber’s article does it’s best work: he explains that the design is pretty good, but the if is huge. The slippery slope with this is real, and even though Apple’s chief of privacy has basically said everything everyone is worried about is currently impossible, “currently” could change tomorrow if Apple’s bottom line is threatened. I think their design is making some really smart trade offs, given the needle they are trying to thread. But it shouldn’t exist at all, in my opinion; it’s too juicy a target for authoritarian and supposedly democratic governments to find out how to squeeze Apple into using this for evil.
- bastardoperator 5y agoLike this part? "The Messages feature is specifically only for children in a shared iCloud family account. If you’re an adult, nothing is changing with regard to any photos you send or receive through Messages. And if you’re a parent with children whom the feature could apply to, you’ll need to explicitly opt in to enable the feature. It will not turn on automatically when your devices are updated to iOS 15."
- mdoms 5y agoYou must be joking. It would be hard to find anyone more biased in favour of Apple than Gruber.
- joe_the_user 5y ago99% of internet discussion on this topic is junk. And how is that? It seems like the Gruber article follows a common formula for justifying controversial approaches. First, "most of what you hear is junk", then "here's a bunch of technical points everyone gets wrong"(but where the wrongness might not change the basic situation), then go over the non-controversial and then finally go to the controversial parts and give the standard "think of the children" explanation. But if you've cleared away all other discussion of the situation, you might make these apologistics sound like new insight. Is Apple "scanning people's photos"? Basically yes? They're doing it with signatures but that's how any mass surveillance would work. They promise to do this only with CSAM but they previously promised to not scan your phone's data at all.
- madeofpalk 5y agoBut some of those technical points are important. Parent comment was concerned that photos of their own kids will get them in trouble - it appears the system was designed to explicitly to prevent that.
- joe_the_user 5y agoThe Daring Fireball article actually is a little deceptive here. It goes over a bunch of that won't get parents in trouble and gives a further couched justification of the finger printing example. The question is whether an ordinary baby photo is likely to collide with the one of the CSAM hashes Apple will be scanning for. I don't think Apple can give a definite no here (Edit: how could give a guarantee that a system that finds any disguised/distorted CSAM won't tag a random baby picture with a similar appearance. And given such collision, the picture might be looked at by Apple and maybe law enforcement). Separately, Apple does promise only to scan things going to iCloud for now. But their credibility no long appears high given they're suddenly scanning users' photos on the users' own machines. Edited for clarity.
- FabHK 5y ago> how could give a guarantee that a system that finds any disguised/distorted CSAM won't tag a random baby picture with a similar appearance. Cannot guarantee, but by choosing a sufficiently high threshold, you can make the probability of that happening arbitrarily small. And then you have human review. > And given such collision, the picture might be looked at by Apple and maybe law enforcement No, not "the picture", but a "visual derivative".
- Dah00n 5y agoYes but so is much in that link or at least it is very biased. This one is far better: https://www.hackerfactor.com/blog/index.php?/archives/929-One-Bad-Apple.html https://www.hackerfactor.com/blog/index.php?/archives/929-On...
- vondur 5y agoI still don't understand how this is allowed. If the police want to see the photos on my device, then they need to get a warrant to do so. Full stop. This type of active scanning should never be allowed. I hope that someone files a lawsuit over this.
- fossuser 5y agoSpeculating (IANAL) - it's only when iCloud photos is enabled. I'd guess this is akin to third party hosting the files, I think the rules around that are more complex.
- amelius 5y agoYou agreed to the EULA :)
- vondur 5y agoI'm not sure EULA's can effectively bargain away US constitutional protections.
- fortenforge 5y agoWhere does the constitution come into play here? This is a private company scanning content uploaded to its own servers.
- salawat 5y ago...as a pre-requisote of avoiding criminal liability for statutory violation of a Federal statute. Transitive property of logic therefore yields that this private entity is acting as a Government proxy. Therefore, Constitutional considerations. I don't find this unreasonable.
- refulgentis 5y agoIt's also not even wrong in so many ways that it really highlights how far DF has fallen over the years. Really ugly stuff, handwaving about hashing and nary a mention of perceptual hashing and collisions. Not a technology analysis of any sort.