4 ms·
I think the difference here is that it's ON YOUR DEVICE. I think there's a pretty clear understanding that if you upload stuff to a cloud provider they can do
by mightybyte 5y ago
I think the difference here is that it's ON YOUR DEVICE. I think there's a pretty clear understanding that if you upload stuff to a cloud provider they can do whatever they want with it. This is different. This is reaching into what has up until now mostly been considered a private place. Law enforcement often has to get warrants to search this kind of thing.
This is the difference between putting CSAM on a sign in your front yard (maybe not quite front yard but I can't come up with quite the same physical equivalent to a cloud provider) and keeping it in a password protected vault in your basement. One of those things is protected in the U.S. by laws against unlawful search and seizure. Cloud and on your device are two very different things and consumers are right to be alarmed.
I'll say it again, if you are concerned with this privacy violation, sell your Apple stock and categorically refuse to purchase Apple devices. Also go to https://www.nospyphone.com/ https://www.nospyphone.com/ and make your voice heard there.
- GeekyBear 5y agoON YOUR DEVICE (where it's encrypted in a way that Apple can't read until the 30 image threshold is crossed) is more private than doing the same scan on server where a single false positive can be misused by anyone who can get a subpoena.
- pasquinelli 5y agowhat kind of encryption can't be decrypted until some threshold has been crossed? maybe you mean to say that apple says they won't read it until that threshold has been crossed.
- GeekyBear 5y agoNo, I'm saying they designed the system so that they don't have the key to decypt the scan result "vouchers" until after the device tells them that the 30 image threshold is crossed. >Apple is unable to process individual vouchers; instead, all the properties of our system mean that it’s only once an account has accumulated a collection of vouchers associated with illegal, known CSAM images that we are able to learn anything about the user’s account. Now, why to do it is because, as you said, this is something that will provide that detection capability while preserving user privacy. https://techcrunch.com/2021/08/10/interview-apples-head-of-privacy-details-child-abuse-detection-and-messages-safety-features/ https://techcrunch.com/2021/08/10/interview-apples-head-of-p... Meanwhile, a single false positive from an on server scan is open to malicious use by anyone who can get a subpeona.
- telside 5y agoThe lady doth protest too much, methinks Just going to respond to every post on here with these absurd points? K apple guy.
- zepto 5y ago> what kind of encryption can't be decrypted until some threshold has been crossed? The kind Apple has built. You should read the docs. This is literally how it works.
- mightybyte 5y agoThis is the same company that saved the disk encryption password as the password hint. You really trust them to not screw this up when the stakes are that it could ruin your life and/or land you in jail? I'm simply not ok with that.
- zepto 5y agoHow exactly do you imagine a bug in this will land you in jail?
- mightybyte 5y agoEver heard of planted evidence?
- zepto 5y agoYou haven’t explained how evidence could be planted. That is what you are being asked.
- deleted 5y ago[deleted]
- heavyset_go 5y ago> where it's encrypted in a way that Apple can't read This doesn't matter because Apple can read iCloud data, including iCloud Photos. They hold the encryption keys, and they hand over customers' data for about 150,000 users/accounts a year in response to requests from the government[1]. [1] https://www.apple.com/legal/transparency/us.html https://www.apple.com/legal/transparency/us.html
- GeekyBear 5y agoOf course Apple can read iCloud data. How do you think Google and Microsoft scan everything in your account? They all have the capability to read your cloud data. What Apple cannot read are the results of your device scanning your iCloud Photos. Those results are encrypted and stay that way until your device finds 30 matches for known kiddie porn. Once you pass the threshhold, Apple gets the decryption key and a human review is triggered to make sure there weren't just 30 false positives.
- mightybyte 5y ago> ON YOUR DEVICE (where it's encrypted in a way that Apple can't read until the 30 image threshold is crossed) First of all, you have to be able to read it to do the comparison that can increment the counter to 30. So regardless of whether it is or is not encrypted there, they're accessing the unencrypted plaintext to calculate the hash. And yes, on my device is definitively more private than on someone else's server--just like in my bedside drawer is more private than in an office I rent in a co-working space.
- kelnos 5y agoA poster upthread made an analogy that I really like. Sure, like all analogies, it's imperfect, but I think it strikes at why many people are uneasy about this. Let's say the TSA were to install air-travel-contraband scanners in everyone's homes, but promise only to scan things that are being put into your luggage as you prepare to go to the airport. And let's say that this became a requirement if you want to board a plane. That's what this feels like. I'm fine with Google scanning through everything in my GMail account, or everything I've uploaded to GDrive, or created in GDocs. That stuff is on their servers, unencrypted, and I explicitly put it there. But I'm sure as hell not going to let Google install something on my laptop (or phone!) that lets them look at my stuff, even if they pinky-promise that they'll only scan stuff that I intend to upload.
- onethought 5y agoOnly the safety tokens are generated on your device, the action triggering scan happens in the cloud (just like all the others) and then it goes to human review, so if it's a hash collision it'd be caught there when they review the images, and they can only review the images that matched CSAM. I honestly can't find the uproar here. Google devices can face match photos offline... so they are applying a neural net (scanning) ON THE DEVICE! How is that not worse than what apple do?
- mightybyte 5y agoOne is matching a face--yes, concerning, and I don't like it but IMO Google has had a much worse privacy reputation for quite some time--and the other is reporting private data to law enforcement and potentially abusive parents. It's quite a bit different. The difference can also be seen from a customer service perspective. One is a feature that lets you sort according to which friends you were with. The other is a feature that puts you in jail. No thanks. Not gonna pay money for that.
- onethought 5y agoNo it reports you to Apple, Apple report you to police. Exactly like google, they will also report you to the police, just they search your library unencrypted. Literally no difference. If you have illegal stuff only on your phone neither google or Apple will be notified or notify anyone else.