3 ms·
This is so frustrating, I generally expected the Hacker News community to observe a more sophisticated take on this topic. Let's get it straight: the other Big
by memetomancer 5y ago
This is so frustrating, I generally expected the Hacker News community to observe a more sophisticated take on this topic.
Let's get it straight: the other Big Tech companies have done this CSAM scanning for many, many years. Their users have been reported. Arrests have been made. Microsoft had this sorted in 2009 with PhotoDNA, and made it available to everyone else in 2014[1]. I doubt very much this has stopped any of you from working at Microsoft or the FAANGs when given the chance.
The ONLY distinctions here are that Apple has opted to do the mundane hashing part on the device prior to upload, have been up front about the plan, have take comments from the public and are saying that they will work out a more satisfying scheme.
Apple even appears to be responsive to the shady claims that a 'reverse engineered (old) version of NeuralHash' might have resulted in some novel collisions, and spend the money to improve their current implementation.
The other big tech concerns did not do these things; they simply imposed it all and started informing the police.
As far as I can see, the only real misstep Apple has taken is being explicit about their plans and assuming people could understand the scope of the subject at hand. Instead they've stepped into a bear-trap of outraged hysteria, a moral panic from people who should know better.
The take away lesson here is "Do not announce stuff like this, the general public will flip out if you try to keep them informed". Is that anyone's goal here?
[1] https://www.microsoft.com/en-us/photodna https://www.microsoft.com/en-us/photodna
- blagie 5y agoThere are two possibilities: 1) You're missing something. 2) Everyone else is missing something. That includes organizations like the EFF. In terms of missing nuance: What Facebook is doing absolutely and completely different from what Apple is doing. You should take time to understand why Apple's approach is so utterly repulsive, while I'm 100% in support of Facebook's. There are distinctions other than your "ONLY distinctions." You should take time to understand what those are, and why they're important. As a hint, those have to do with where users might or might not have expectations of privacy, with due process, and with who owns what.
- robertoandred 5y agoThe EFF's goal is to get donations. Hence why they've lied about the system since the beginning to stoke outrage.
- blagie 5y agoI guess we're all in on the conspiracy :)
- memetomancer 5y agoYours is a vague and disrespectful response that does not really contribute to the conversation. You suggest that I'm uninformed, yet do not specify what I've missed or provide any sources. You've spoken down to me and offered vague generalities as to why your hysterical repulsion is justified but can't actually articulate the issues - instead only appealing to the EFF and offering a paltry 'hint' as if your perspective were somehow self evident. My position stands. However yours needs some clarification. You seem to suggest that expectations of privacy, due process, and 'who owns what' (you could just say 'ownership' here) somehow doesn't apply to Facebook? Or that they have somehow satisfied those concerns? Facebook? That point is plainly absurd, they are among the most abusive in this regard - as supported by hundreds of articles on the much vaunted EFF's site[1]. If Apple's approach, which I've characterized as 'performing the mundane hashing on-device' is really and truly repulsive, please do elaborate. I'm sincere in saying that I want to know. And if you can be bothered, please also clear up the matter of how the other Big Tech organizations have managed to accomplish this same law enforcement obligation to your satisfaction. [1] https://www.eff.org/search/site/facebook https://www.eff.org/search/site/facebook
- blagie 5y agoYour position does stand. It is: "the Hacker News community" is not "sophisticated" "on this topic" and is engaged in "a bear-trap of outraged hysteria, a moral panic from people who should know better," while I have "hysterical repulsion." I responded to this position. Since you're now asking for a clarification: If I am running a social media platform for the sharing of photos, I am responsible for the content on that platform. It is my platform. I'd better have scanning for not just CSAM, but hate speech, misinformation, harassment, criminal activity, and a slew of other things. If Facebook becomes a platform for the sharing of child pornography, or the collapse of our democracy, or polarization, Facebook has done something deeply unethical, and should be held accountable, whether through the courts of law or the courts of public opinion. On the other hand, users have little expectation of privacy on Facebook. In contrast, if I paid for a phone or a computer, it is MY private device. I bought it, and I should have an expectation of privacy there. I should be able to trust that my device isn't out to get me. Even a space like AWS or GCE, where I am paying for a machine, I should have some reasonable expectation of privacy. It's the difference between running a shopping mall (or an exclusive club) and selling a private home. If I'm running a business, I'm responsible for what happens on my turf. If I'm selling you a product, you're responsible for what you do with it. Your home developer have no right to install spy cameras in your home, even if they will only call up the police if they're 100% sure you're a racist terrorist raping underage [taboo] [taboo] [taboo] .... There are plenty of other distinctions, such as around evidence and due process, but I don't want this turning into an essay. You can use a search engine for yourself; plenty has been written on this, and insulting people isn't a good lead-in to asking them to save you that effort. And the EFF is right that Facebook does plenty of nasty things. This just doesn't happen to be one of them.
- rebuilder 5y agoIf scanning is done in the cloud, I can disable cloud uploads and reasonably trust no filter list will get me reported. If it’s done on-device, I have to rely on Apple to uphold their policy of only scanning material uploaded to iCloud. That’s a big difference.
- sodality2 5y ago>If scanning is done in the cloud, I can disable cloud uploads and reasonably trust no filter list will get me reported Or that it uploads local copies to be scanned in the cloud and doesn't save them to your account but may trigger LE response... Though I suppose that would cause concern about the massive network traffic, whereas no one would notice Apple scanning local photos (w/o some sort of advanced disassembly to see how much the on-board ML chip is used)
- rebuilder 5y agoI’m thinking more about what legal defence a phone manufacturer has against inevitable LE requests for access. Not having the technical capability is much stronger than not being willing, even though it’s obvious that a targeted “software update” is within the capabilities of Google and Apple alike.
- pcurve 5y agoApple painted itself into corner by refusing to do iCloud scanning to maintain its differentiated stance compared to its competitor, so the only way it COULD comply with government pressure is to do the scanning at device level. Except, that turns out to be a whole lot more intrusive and unpalatable for people because the surveillance is taking placing on a device the user paid for and thereby expect higher level of privacy than what is stored on a cloud. Apple is stuck between rock and a hard place. They don't want to be like Google or MS, but their solution is worse from public's perspective. Optics aren't looking so great at this point, because they are also dragging Google and MS through the mud by effectively saying, "Well, they've been doing it too!"