6 ms·
> We've always put our trust on Apple to not do any shady things on our phone …and now we have a case in point of them doing shady things on our phones. This b
by Infernal 5y ago
> We've always put our trust on Apple to not do any shady things on our phone
…and now we have a case in point of them doing shady things on our phones. This breaks the trust.
- Retric 5y agoI don’t see what’s shady about this because it’s so public. They could do everything that’s happening on phone on the iCloud servers without telling you. So at worst it uses extra bandwidth per upload and some processing power and thus battery life from your phone. The minor advantage is you can actually inspect their procedural hashing algorithm, though not how they compare images server side. Sure, they could do something else in the future but that’s alway the risk with every update.
- Infernal 5y agoIt's the same point as above. They could do shady things with your data on their server. They could do shady things with the data on your phone. They always /could/, and up till now I trusted them not to. But now they /have/, that is the change.
- Retric 5y agoOk they lost your trust and it’s completely your choice to make that decision however you want, but how was this shady?
- brokenmachine 5y agoCreating a novel on-device scanning mechanism and claiming that is somehow more privacy is a lie, and therefore shady. Using that novel on-device scanning capability to secretly report people to authorities, that's beyond shady. Claiming that the novel hashing algorithm is verifiable by third parties, but simultaneously suing any third parties that try to analyze the actual code running (without being subject to Apple NDA), is mega shady. Secretly reporting people to authorities based on unverifiable novel image hashing algorithms and only image "derivatives", whatever that means, that's ultra shady. Pretending that people are somehow "misunderstanding" if they are alarmed by this unprecedented, unverifiable scanning and secret snitching mechanism being run over their private photos, that's extra ultra mega shady, but typical of Apple. Look at this shitshow explanation. When have you ever seen Apple being so terrible at explaining a feature? None of this smells right: https://www.youtube.com/watch?v=OQUO1DSwYN0 https://www.youtube.com/watch?v=OQUO1DSwYN0
- Retric 5y agoOk, so you are largely misunderstanding the details. > Creating a novel on-device scanning mechanism and claiming that is somehow more privacy is a lie, and therefore shady. Would you rather Apple actually directly look at your images? If not then it is a privacy improvement. Because they are legally required to search their servers for this stuff when directed to by the FBI. > Using that novel on-device scanning capability to secretly report people to authorities, that’s beyond shady. Except they don’t actually do that, phones don’t get the hashes to do any comparisons. Sever side comparisons only flags images which causes Apple employees to look at down samples images. Critically they don’t have the authority or incentives to prosecute you. > suing any companies that try to analyze the code running, is mega shady. And not something their actually doing. > Based on unverifiable Again false people have been looking at the algorithm used.
- brokenmachine 5y ago>Would you rather Apple actually directly look at your images? No. Why would that be necessary? I would expect to be reported if I willingly uploaded images matching exact hashes of CSAM to Apple servers. I don't understand why Apple employees would ever be able to, or need to, view my images, and I would expect Apple if it were really a privacy-focused company to never let that happen. >Except they don’t actually do that, phones don’t get the hashes to do any comparisons. Sever side comparisons only flags images which causes Apple employees to look at down samples images. Critically they don’t have the authority or incentives to prosecute you. It's client side, that's why we're having this discussion. This is all a secret process. As I said, Apple employees look at an unspecified number of "derivatives" of people's images in a secret process, and if they tick a box, the authorities get all your data. There's nothing saying how close a "derivative" needs to be to actual CSAM to trigger this process, just "trust us, because children". No audits, no due process, no mandatory notifying customers that are affected, no notifying of how many total customers were reported every month, just a secret illegal search and snitching mechanism with some crypto mumbo jumbo and "trust us, because children" sprinkled on top. >And not something their actually doing. *they're. Yes they are: https://news.ycombinator.com/item?id=28219278 https://news.ycombinator.com/item?id=28219278 From a comment: > ... “With their left hand, they make jail-breaking difficult and sue companies like Corellium to prevent them from existing. Now with their right hand, they say, ‘Oh, we built this really complicated system and it turns out that some people don’t trust that Apple has done it honestly—but it’s okay because any security researcher can go ahead and prove it to themselves.’” >people have been looking at the algorithm used. Who? How? Are you talking about the ones that are gagged by Apple NDA? Link to papers? As another commenter posted, no amount of spin will make on-device scanning a good idea.