17 ms·
This part is legit though: governments around the world could pressure Apple to add other forms of surveillance. Be it hashes of non-CSAM, or simply pressure NE
by elisbce 5y ago
This part is legit though: governments around the world could pressure Apple to add other forms of surveillance. Be it hashes of non-CSAM, or simply pressure NEMEC or other hash providers, or extending its capabilities to all messages or photos on device.
In my opinion, this is the biggest concern, not the technology. Before, Apple could simply refuse by saying we don't have the capabilities. But now, that excuse is gone. Apple's promise to human review content and only report CSAM is the weakest link.
- zepto 5y ago> governments around the world could pressure Apple to add other forms of surveillance. What do they have now that they didn’t have before?
- karlshea 5y agoIf you read their Security Threat Model Review [1] they're only using the "intersection of hashes provided by at least two child safety organizations operating in separate sovereign jurisdictions". So you'd have to pressure NEMEC and another org under a different government to both add the non-CSAM hash, plus Apple would need to be pressured to verify a non-CSAM derivative image, plus you'd need other hash matches on-device to exceed the threshold before they could even do the review in the first place (they can't even tell if there was a match unless the threshold is exceeded). I get why people are concerned, but between this thread and the other thread yesterday it's clear that pretty much everyone discussing this has no idea how it works. 1: https://www.apple.com/child-safety/pdf/Security_Threat_Model_Review_of_Apple_Child_Safety_Features.pdf https://www.apple.com/child-safety/pdf/Security_Threat_Model...
- jjulius 5y agoI think you're missing what concerns people; what guarantee do we have that Apple will, always and forever, only use the "intersection of hashes provided by at least two child safety organizations operating in separate sovereign jurisdictions"?
- karlshea 5y agoIt’s almost like you didn’t read the paper or my whole comment.
- deleted 5y ago[deleted]
- jjulius 5y agoI've actually read your comment, along with the linked PDF, in full multiple times in an effort to make sure I wasn't missing a point you were trying to make. Before I continue, I want to make it clear that I fully understand that adding non-CSAM content into the existing NCMEC/CSAM/IWF environment would more than likely raise a lot of red flags. You and I have an understanding there. As it happens, I still think you're missing the point that myself and others are trying to make. Perhaps the following is a better way of phrasing my inquiry: What guarantees to we have that Apple will, always and forever, only use the NCMEC/CSAM/IWF system to scan images on phones? By that I mean, isn't it perfectly plausible that Apple can leave the NCMEC/CSAM/IWF system in place, as it is described in your post and the linked PDF, and at the same time partner with [random body X/Y/Z], who has their own database of [whatever] that they scan separately from the NCMEC/CSAM/IWF system? These two different scans wouldn't ever need to communicate with each other, and could run at the same time.
- karlshea 5y agoWell yeah it's plausible they would just turn the contents of everyone's entire iCloud backups over to the FBI, which they can totally do right now at any time since they already have the keys! So what? What you're describing is not what this system does. You could argue against literally any possibility anyone could dream up, because they're the platform vendor and they can make any change they want. If that's a problem when you're evaluating your threat model then this new system is the least of your worries. And as far as I can see this system is the least intrusive version of what any of the other cloud vendors are doing. Don't want it? Turn off iCloud Photos and sync to something else like your own Nextcloud instance.
- zimpenfish 5y ago> So you'd have to pressure NEMEC and another org under a different government To be fair, if the other organisation is IWF[1] under the UK government, I don't think there'd be much pressure needed to get them to comply - just offer to bung them and their mates a few million in contracts and you'd be golden. It's a sensible plan, it just might not be as strong as it seems. [1] https://www.iwf.org.uk https://www.iwf.org.uk
- karlshea 5y agoLooks like you forgot to take into account the entire rest of that sentence you quoted.
- zimpenfish 5y agoNo, just pointing out that the first part isn't as strong as Apple seem to think it might be. The rest of it might well catch this, yes, (and that's good!) but it doesn't obviate that "only considering images from two or more providers" can be subverted, possibly easily, given the pressure USGOV can bring to bear on their partners.
- testfoobar 5y agoApple doesn't even have to know how their scanner will be used. It could simply be a requirement for selling phones in Country X, Apple must scan devices for hashes from DB-20210819-Illegal-Hashes-Country-X.zip. The hash file will be provided by Country X as will the messaging contacts for appropriate state security services.
- zepto 5y agoThat’s pure fantasy. The system involves Apple reviewing any detected images.
- zimpenfish 5y ago> governments around the world could pressure Apple to add other forms of surveillance. Be it hashes of non-CSAM, or simply pressure NEMEC or other hash providers could, yes, but given PhotoDNA has been using similar hashes from NCMEC for a decade and doesn't appear to have had similar surveillance pressure imposed, what makes the Apple scanning different to warrant slippery slope arguments like this?
- cwizou 5y agoPhotoDNA is not exclusive to NCMEC, and has been used for about 5 years by FB, MS and Youtube on terrorist content : https://about.fb.com/news/2016/12/partnering-to-help-curb-spread-of-online-terrorist-content/ https://about.fb.com/news/2016/12/partnering-to-help-curb-sp...
- zimpenfish 5y ago> has been used for about 5 years by FB, MS and Youtube on terrorist content Not with the hashes provided by NCMEC, though, right?
- cwizou 5y agoNot provided by them but I don't think that was the point that parent was making. The same system is already in use for things other than NCMEC by other providers.