Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
fossuser
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
17 ms
·
121.
▲
by
fossuser
5y ago
I don't really buy that - you could just turn off iCloud backup and it'd avoid their current implementation.
122.
▲
by
fossuser
5y ago
The end isn't really compromised with their described implementation. The only thing sent is the hash and signature and that's only if there are enough matches to pass some threshold. I don't really view that as 'permane
123.
▲
by
fossuser
5y ago
Thanks - I couldn't have said it better.
124.
▲
by
fossuser
5y ago
They have a podcast together called Dithering which is pretty good (but not free) - they're friends. I think John's article is better than Ben's, but they're both worth reading. Ben takes the view that unencrypted cloud
125.
▲
by
fossuser
5y ago
It's two factors, both the match on an image hash and an unknown threshold of matches at which point the data gets sent up. If the threshold is not met then nothing gets notified (even if there is a match). Arguably this is why this ap
126.
▲
by
fossuser
5y ago
It's worth reading this, which is basically the only good reporting I've seen on this topic: https://daringfireball.net/2021/08/apple_child_safety_initia... There are legitimate things to be concerned ab
127.
▲
by
fossuser
5y ago
When the human lifespan is on the order of a star's - I'll be a lot happier.
128.
▲
by
fossuser
5y ago
Basically Permutation City: https://en.wikipedia.org/wiki/Permutation_City
129.
▲
by
fossuser
5y ago
I think a lot about Alcor too - I think it's probably worth doing. Hopefully you can get someone you care about to do it too. In the unlikely event it does work, there'd at least be a handful of people - it'd be pretty unlike
130.
▲
by
fossuser
5y ago
"At another point in the discussion, a man spoke of some benefit X of death, I don't recall exactly what. And I said: "You know, given human nature, if people got hit on the head by a baseball bat every week, pretty soon th
131.
▲
by
fossuser
5y ago
Agreed - software like this doesn't exist in a vacuum of frozen dependencies (at least not until Urbit takes over). Subscription models make sense for stuff that requires updates over time to keep it working. Their stuff is reasonably
132.
▲
by
fossuser
5y ago
Thanks - good to know the truth around that specific story. The example and class of failure (even if it didn't actually occur in this specific case) is still the point I was trying to make. Those types of failures can happen - even if
133.
▲
by
fossuser
5y ago
And there’s that famous computer vision story of a model that was supposed to detect tanks in images but actually just detected whether or not it was sunny (all the tank pictures in the training set were sunny, non tanks overcast). Children
134.
▲
by
fossuser
5y ago
I found this to be a pretty good list: https://danromero.org/crypto-reading/ Some more details here if you're curious: https://news.ycombinator.com/item?id=27812093
135.
▲
by
fossuser
5y ago
Looks like the Ted Chiang short story? Thanks - it’s great. I’d recommend his other stories too if you like that one. I’ve also got a bunch of links to other stories I’ve liked here too: https://zalberico.com/about/
136.
▲
by
fossuser
5y ago
There was a funny related example of the African Gray parrot Alex surprising the trainers by silently counting in his head. They were training a younger parrot and trying to get the younger parrot to count to two by tapping twice. Alex over
137.
▲
by
fossuser
5y ago
Yeah - my read of this is Apple wants to increase their e2e adoption while still handling CSAM in a way that gets them an okay from the regulators. Ben Thompson's suggested approach for them in this article is to just do the unencrypte
138.
▲
by
fossuser
5y ago
This is by far the best reporting on this issue I’ve seen on HN or elsewhere. If you skipped the article to read the HN comments, I wouldn’t bother. The article’s discussion is much better - just read that.
139.
▲
by
fossuser
5y ago
This Daring Fireball blog post is a better summary than the discussion I’ve found on HN: https://daringfireball.net/2021/08/apple_child_safety_initia... Occam’s razor is that they’re doing what they say they’re do
140.
▲
by
fossuser
5y ago
At the time of my comments people weren’t discussing the fuzziness of perceptual hashing - they weren’t discussing implementation details at all. I don’t know enough about the specific implementation or perceptual hashing details and probab
141.
▲
by
fossuser
5y ago
I suspect that's why they have some threshold that moves the false positive rate to one in one trillion. The iMessage bit is different - it's only on device, only on child accounts, and only alerts parents. It's more akin to
142.
▲
by
fossuser
5y ago
I think it has gotten more sophisticated to detect cropped images and small changes now: https://inhope.org/EN/articles/what-is-image-hashing The example is somewhat contrived. If a 'friend' takes your p
143.
▲
by
fossuser
5y ago
I don't know - I think these are the good questions and the things I would want to know in more detail. I think this kind of thing is where the risk lies. I think this is why getting the details right matter because if people are argui
144.
▲
by
fossuser
5y ago
This is just a slippery slope argument. The implementation specifically for detecting CSAM can be okay while using that for other purposes can not be okay. The goal is to stop child sexual abuse, FB reports millions of cases a year with a
145.
▲
by
fossuser
5y ago
Then that's a different photo and will have a different hash.
146.
▲
by
fossuser
5y ago
That isn’t CSAM. https://www.nytimes.com/interactive/2019/09/28/us/child-sex-... Apple’s thing has some sort of threshold anyway so one image would not trigger it. I don’t buy your example - the CSA
147.
▲
by
fossuser
5y ago
Being specific with the arguments and addressing the nuance matters imo. Most of the HN responses are dumb, get the details wrong, and don’t take the trade offs seriously. That kind of thing causes me to dismiss them entirely. There are l
148.
▲
by
fossuser
5y ago
It’s not naive, it’s math.
149.
▲
by
fossuser
5y ago
Yeah, that’s essentially zero.
150.
▲
by
fossuser
5y ago
This is not true. The check is only against known CSAM hashes.
More ›