Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
samrolken
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
samrolken
5y ago
Yes, it did something like that. If and only if the user signed up for, paid for, and enabled the iTunes Match service, the whole point of which is to replace your local files with cloud music. (I don’t find this desirable myself, but I can
62.
▲
by
samrolken
5y ago
It seems like this system was designed specifically so that this would be impossible, and such a feature would go against what seem to be design goals of this system. They went through the trouble of making this whole “private set” matching
63.
▲
by
samrolken
5y ago
> once this system is in place it will be used for anything, not just photos The system seems designed to make it hard to use it for anything else. How will a hash driven by a visual perception based neural net be used on ZIP files? How
64.
▲
by
samrolken
5y ago
Even if we accept that your image of your kids in the bath will match the hash of a known and identified CSAM picture (a real stretch), under this system the voucher payload does not contain the private key to decrypt the picture, so nobody
65.
▲
by
samrolken
5y ago
Fortunately that’s not how it works. You would have to have a whole collection of known and identified CSAM to be classified as anything at all with the system Apple has announced.
66.
▲
by
samrolken
5y ago
You’re missing the threshold that is part of this system. You would need multiple hash collisions across multiple photos to trigger these mechanisms.
67.
▲
by
samrolken
5y ago
A false positive will not have any effect. The threshold system they have means that they won’t be able to decrypt the results unless there are many separate matches.
68.
▲
by
samrolken
5y ago
Source?
69.
▲
by
samrolken
5y ago
It is a hash created with ML. So it’s both. But yes, it only matches already known material.
70.
▲
by
samrolken
5y ago
An image being erroneously flagged will not have any effect. Until the threshold is reached, Apple is not able to know if or how many images have matched. And even then, the voucher doesn’t include the key to decrypt the photo itself. Apple
71.
▲
by
samrolken
5y ago
> If the system detects any matches This part isn’t true. Unless a threshold of multiple matches is reached, Apple won’t have a complete key to decrypt anything.
72.
▲
by
samrolken
5y ago
Apple has documentation explaining how it all works with a database of known images.
73.
▲
by
samrolken
5y ago
Apple’s documentation discusses how they use a neural network to generate the bits which get turned into the hash.
74.
▲
by
samrolken
5y ago
The detection of sexual images in kids’ messages doesn’t use the same hashing setup as the iCloud Photos detection feature.
75.
▲
by
samrolken
5y ago
If you think Apple is going to install something onto your phone to scan everything for wrongthink and send it to the CCP, you shouldn’t be installing their updates or using an iPhone anyway. They can already do that at any time. This featu
76.
▲
by
samrolken
5y ago
You can opt out by not using iCloud for your photos. If you prefer, you can install Google Photos or OneDrive onto your iPhone and let your images be scanned in the clear in the cloud instead.
77.
▲
by
samrolken
5y ago
Your kid in the bath won’t be in the database being matched against.
78.
▲
by
samrolken
5y ago
At any time Apple could turn evil and include invasive spyware that sells you out. If you’re afraid this can happen, this new feature doesn’t make it any easier. You shouldn’t use Apple products at all if you distrust them to that degree.
79.
▲
by
samrolken
5y ago
The neural net is specifically designed to handle such cases. This is covered in Apple’s documentation about this.
80.
▲
by
samrolken
5y ago
It seems like it isn’t possible to store images in someone’s iCloud Photo Library without their involvement. This would be a major security incident and immediately patched, if someone were able to find a way to do this.
81.
▲
by
samrolken
5y ago
Apple never gets to see your photo. Even if the photo matches the database and even if you have enough photos matched to reach the threshold that lets Apple decrypt the hashes, the photo itself is not decrypted or sent to anyone as part of
82.
▲
by
samrolken
5y ago
Microsoft and Google hash your unencrypted photos on their own servers. Apple could easily do the same… I wonder why they didn’t…
83.
▲
by
samrolken
5y ago
What does that mean?
84.
▲
by
samrolken
5y ago
It remains to be seen if this is possible at all… let alone “easily” done. Have any other big tech companies that scan for illegal images been shown to be vulnerable to this?
85.
▲
by
samrolken
5y ago
An attacker who has a way to place multiple illegal images onto someone’s phone and into their iCloud Photo Library without their consent… it’s an interesting idea but how is it possible?
86.
▲
by
samrolken
5y ago
This is only applied to photos being uploaded to iCloud.
87.
▲
by
samrolken
5y ago
It sounds like this is a feature of the encryption used. Apple will not have enough of the key to decrypt anything unless there are enough vouchers which match.
88.
▲
by
samrolken
5y ago
If you are already planning to charge people that are signing up for free, then it is relevant at this point in time. How do you plan to handle: Today: customer signs up for free. In six months: you start charging fees In six months plus on
89.
▲
by
samrolken
5y ago
The pricing page mentioning “platform fees” without specifying what they are doesn’t seem like the best thing. If you charge, or plan to charge, other fees, maybe also mention them on the pricing page. If you aren’t charging fees yet you ca
90.
▲
by
samrolken
5y ago
It seems like this case has nothing to do with the DMCA. Google’s content ID and claim system is not related to that at all.
More ›