Apple to scan iPhones for child sex abuse images
bbc.co.uk
bbc.co.uk
Apple's plan to “think different” about encryption opens a backdoor to your life – https://news.ycombinator.com/item?id=28079171 – Aug 2021 (748 comments)
Expanded Protections for Children - https://news.ycombinator.com/item?id=28078115 - Aug 2021 (353 comments)
Apple plans to scan US iPhones for child abuse imagery - https://news.ycombinator.com/item?id=28075021 - Aug 2021 (368 comments)
Apple enabling client-side CSAM scanning on iPhone tomorrow - https://news.ycombinator.com/item?id=28068741 - Aug 2021 (716 comments)
SwiftOnSecurity:
> Just to state: Apple's scanning does not detect photos of child abuse. It detects a list of known banned images added to a database, which are initially child abuse imagery found circulating elsewhere. What images are added over time is arbitrary. It doesn't know what a child is.
(from https://twitter.com/SwiftOnSecurity/status/14233832560037478...)
Don't Google already do this for images you store in their cloud?
You can just not share the photos to iCloud, the exact same way you'd opt out of it happening on iCloud, no?
EDIT: Just checked, I don't backup pictures from my phone in the cloud. At least that's what my Google camera app insists on.
[...] when the photo is about to be uploaded to the cloud. If you don't use iCloud Photos, it won't be scanning your photos.it's scanning ON your device. This means Apple now has the capability to scan and find files on your device. Which means they have opened the pandoras box of over-reaching government requests.
"Messages uses on-device machine learning to analyze image attachments and determine if a photo is sexually explicit."
Furthermore: "This program is ambitious, and protecting children is an important responsibility. These efforts will evolve and expand over time."
Per: https://www.apple.com/child-safety/
The road to hell is paved with the best of intentions.
I can see law enforcement showing up at my door one day demanding to have a look around, and I would have no idea why they’re there, but they’ll want to look through all my personal belongings.
Worse yet, I might come home from work one day, see my windows broken, see my place has been ransacked and my computers are missing. I would call the police to report a burglary only to hear that I’m under investigation and they need me to give them the key to decrypt my hard drives.
I feel like I need to do some risk analysis on my digital life. I need my phone for 2FA apps for investment accounts. If I use a dumb phone, I’m stuck with SMS, which is easy to hack. But if we use iPhones, there is a small but costly risk of a completely erroneous investigation. How do you balance these without knowing the probability and impact of the later?
At least it's a lot more possible to mis classify a photo than a sms message. Plus as I mentioned in another post, what if you have a young kid and you happen to shoot a photo when he or she is not fully dressed?
This technology at Apple is very much about matching hashes.
p = 1.0.
(This is a sports in the machine learning community: https://openai.com/blog/adversarial-example-research/ .)
Of course you will be off the hook after a long embarrassing investigation.
https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-...
But I seriously doubt they will make iCloud end-to-end encrypted. If they wanted to do that they would have done so already. And why not announce it at the same time, which might give them an overall PR win? But we shall see I guess!
It's not matching an AI's interpretation of "is this a naked child?" though - it's specifically only matching perceptual hashes against a known database of CSAM percpetual hashes provided by NCMEC which will then be manually reviewed if there's more than a threshold of matches.
What's stopping said people from leaking photos?
No? Not unless they're matching the perceptual hashes of the CSAM provided by NCMEC and in that case, sorry, my sympathy does not extend that far.
If anything, this makes it harder for random Apple people to look at your iCloud photos if moving the matching step down to the phone means iCloud photos are going to be end-to-end encrypted, right? (Which is not a given, of course, just a theory that some people have about why it's moving down to the phone level.)
You trust automated systems more than I do.
Thats not how it works. Your house is still protected from search and seizure even if you rent it.
I want to add that this may be a serious issue for people with young kids. Imagine you shoot a video/photo of your kid with little dressed on. Now what happens? Are we supposed to fully dress kids because we have no idea what Apple will do after the scan?
If your photos never go to iCloud, they won't be scanned.
Not a clue. Maybe they're going to make iCloud Photos fully E2E and this is the only way they can keep the CSAM scanning alive? Or maybe they just want to avoid it arriving on their servers at all (but I don't think anything has said matching CSAM photos will not be uploaded?) Or they just want to save some CPU on the iCloud side by punting that down to the phones themselves?
(Or, yeah, this is just the precursor to doing more client-side scanning and the slippery slope cassandras will be proven correct.)
This opens, for Apple, a catalog of answers for "How can we make a buck," and none of the answers will be friendly to privacy or freedom.
I actually don’t have many nudeish pics of him because it’s very cold right now, but we take dozens and dozens of daily pictures so — but in the summer… when maybe he’s going to the kiddie pool grandpa has…
Yes, children is so precious and helpless. I think in order to protect them you all have to give up your liberty, so to protect the future of human race.
Blast on every channel message that your product will actively look for children porn store on it. Stir great debate.
And then quietly drop the proposed feature.
Your product will be viewed as unsafe to use by the pedophiles maybe even whole apple ecosystem will.
There seems to be little chance of false positives here. I keep seeing references to machine learning algos and that's not what they are doing at all. I do still lament losing yet more control though. A device that I buy should not be working for somebody else, for better or worse.
CSAM is not new and is already in widespread use. The difference here just seems to be that your device itself will sell you out.
Edit: Follow up question- They run this on images before they are uploaded to iCloud. Why has Apple chosen to do this on-device rather than just run it in iCloud? They say for privacy reasons:
'Apple’s method of detecting known CSAM is designed with user privacy in mind.'
Here's Apple's documentation on it : https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
Simplified: If you draw a circle and i draw a circle, their fingerprints will be closer then if I would have drawn a rectangle.
If so, there will be false positives but they will be intentional. Black hat can send a collection of 100 modified but innocent meme images with nefarious hashes.
Before 2013, the more cynical ones among us were simply branded conspiracy nuts and crackpots.
If anyone believed Apple's lies about privacy, that's on them. The solution is to buy more smart stuff from American companies. They are the only ones that can be trusted
It is scanning phones, but only files that are about to, but haven't yet, be uploaded to iCloud. That scan is happening on the phone itself.
I don't know if that's the reason, but seems like a reasonable guess.
Interesting. They say they do, seemingly for many things, though not all[1]. Do you have more info?
But the majority of users' sensitive data is not included in that set of features. For example the Photos (what's being affected here), Drive, and Backup features don't use it. Note that any encryption keys backed up using iCloud Backup are therefore effectively not end-to-end protected either.
Somewhat misleadingly, this page indicates those features use encryption both "in transit" and "at rest", but Apple controls the encryption keys in those cases, so they are actually not end-to-end encrypted.
Here is a report indicating that scanning is already happening on the server side: https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-...
Here is a report about how the FBI specifically pressured them against adding end-to-end encryption to iCloud backups: https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
>>Before an image is stored in iCloud Photos, an on-device matching process is performed for that image against the known CSAM hashes
In any case, this will be automated, rather than some poor Tier-1 pouring over iCloud Photos.
So only the guilty (and the false positives) would worry.
The "nothing to hide" argument tends to fall apart when the database being used against you is full of legal imagery (which often isn't borderline or pornographic at all -- some of the flagged images literally don't show people).
Slippery slope to non-CSAM material? That ship has sailed already. The databases are a mess. From day 1, it detects non-CSAM.
Would the device belong to us, or be covered by some misguided sense of ownership and privacy?
The garden was already walled, and the name on the gate wasn't the user's to begin with.
Now, where's my rusty yet trusty Nokia? Oh, wait, it doesn't have VoLTE...
If you truly want to "protect the children" you should have no issue for the police to visit and inspect your, and all of your neighbors houses. Every few days. Unannounced, of course. And if you were to resist, you MUST be a pedophile who is actively abusing children in their basement.
You're not guilty, are you?
/s (if not already clear enough)
My social life is crippled for the rest of my life because of a false positive. Which can happen to anyone. Which means everyone should worry.
Everyone already doing this, Google Photos/Drive, Dropbox, Youtube, etc. The only difference is Apple just started doing it?
Edit: people are downvoting for asking a question...
That's a big policy change, since they're circumventing their own E2EE using their super-admin powers to do it.
The barrier when uploading to unencrypted services is that you are at least aware you're granting access. This is invading the phone to do it anyway - that's quite different.
But more importantly: when flagged this is going to send the results to human reviewers. Which has not been elaborated on: there's no way human reviewers can screen things without being sent a copy of the image in question. Which means, a neural network system is going to randomly send your personal images to human reviewers - and it will, largely, be false positives.
Note that Apple are not discussing anything about the reliability of this system: have they run it against a sample set of normal images? How many did it flag? Because, if they give a number, it'll be pretty easy for people to realize that some % multiplied by the number of phones and average number of images per phone, and I'm willing to bet what you get is: the system will false positive at least (and probably more then 1) personal photo per iPhone user, and send it to human reviewers.
And that might get people's attention: certainly more then just, unfortunately, us techies.
EDIT:
And let's talk about these human reviewers: these are not random citizens seeing something and wondering if they should be concerned. The context these people are going to be given is possible child abuse image. This is not a neutral review process - at all.
Normalisation of this invasive behaviour is not okay. Apple specifically argued they are not Google and do not invade your privacy.
You make it seem like it is weird to care about sudden local government corruption just because there are other countries that already were corrupted.