In internal memo, Apple addresses concerns around new Photo scanning features
9to5mac.com
9to5mac.com
For example if the scope/mission expands (e.g. foreign governments), suddenly you've created a drag-net for whatever "badness" is of interest in whatever today's moral panic is (e.g. terrorism after 9/11). Plus perceptual hashing, by its very design, is created to be less precise than traditional cryptographic hashing.
A cryptographic hash + file size combo is unlikely to have a false positive within our lifetime (and it has been used successful by multiple companies to combat CP). The interesting thing about a perceptual hash is that the closer the source material is to the banned material in terms of actual content (e.g. nudity), the more likely for a false positive.
Therefore, if Apple does mess up via false-positive and manually review your material, it is more likely to be sensitive private materials (involving consenting adult(s), not CP) because that is what the perceptual hashes are looking for similarities to.
PS - If you think this concept cannot happen in a Western country, see the UK's internet filters as a textbook example. Originally started to fight CP, and now used to fight a ton of other stuff too with more proposals every year: https://en.wikipedia.org/wiki/Web_blocking_in_the_United_Kin...
You can't trust a feature whose only impediment from being abused in the future is such pinky promise.
Add hashes of politicians. Businessmen in suits. Army uniforms.
At the end you have a weapon that can only shoot civilians.
Once a hash matches, law enforcement would need a subpoena to access the raw image. If a person were to be arrested, that evidence would be turned over to the defense.
It would be very obvious that a picture of a police officer was not child pornography.
Are you under the impression people are jailed for hash collisions? Because that's not the case at all....
Let's stick to the topic of discovery and how courts work.
You still don't get to be technically incorrect, though. You still need to know how courts work, if you want to participate in that discussion.
You still need to know the process, though. Images of police officers are not being used to convict CP charges.
So in that case in discovery the picture of a police officer would be evidence that you broke that hypothetical law. The technology deployed to protect the children opens up the possibility of its deployment for other things later, based on legal requirements of course.
For example don't take pictures of copyrighted material would be something people might want to work on.
Hypothetical situations are not an argument to real world discussions. Sure, if that happened, it'd be terrible. But, that's not happening....
"While this image may be insightful for understanding the character of the fallacy, it represents a misunderstanding of the nature of the causal relations between events. Every causal claim requires a separate argument. Hence, any "slipping" to be found is only in the clumsy thinking of the arguer, who has failed to provide sufficient evidence that one causally explained event can serve as an explanation for another event or for a series of events"
You need to argue things that are actually happening. Appealing to hypotheticals, especially when technically incorrect, serves no one.
The slippery slopes being discussed here are not about events and the causes that link them, but about the applications of technology and to a certain extent about laws being used beyond their original mandate. This kind of slippery slope is a logical one.
Thus the technology being used for this mean that it can be used for other things - what kinds of things can it be used for? Are there things that people would like to make illegal or that are illegal now that this technology can be used catch people infringing on these hypothetical laws. Thus - if we allow this technology in our devices now are we opening ourselves up for other potential uses for the technology in the future that will hurt us.
If this argument seems the same to you as the domino theory and that we must take every hypothetical problem when it actually occurs I wonder how you are ever able to plan for any eventuality?
Apple, however, is still not a sovereign state, and as such must bow to the wishes of actual sovereign states. Sovereign states have proven again and again that they will grab as much power as they can, and doing it insidiously, in the form of a private database of hashes of undesired content, is especially attractive to them.
This is not a hypothetical. For a real-world example look to England where its nation-wide internet blocking system is already used beyond its original scope. Or think of what countries like China will certainly do with such a mechanism. Scope creep, in the form of power grabs by nation states, is a realistic concern, based on vast historical experience, not a fallacy.
Apart from the concern of scope creep, there is also the concern of false positives. When deployed on such a scale, there will undoubtedly be perfectly legimate images being flagged. I'm not happy about my phone containing software that's always vigilant, ready to ruin my life over a false positive.
No. You don't get to control the narrative by saying that. You have to discuss things that could happen when discussing things this invasive.
Apple is deploying a technology with few legitimate uses that makes terrible things not only possible but easy all without the voluntary consent of the device's owner.
Not if Apple provides it to them without a subpoena.
However, that does not mean that while this investigation is under way, the accused is now go about their business.
For CP, or other crimes of violence, that makes sense.
But if laws are passed against peaceful protest, then that means someone could be held in detention while those photos are investigated. An anonymous photo now is trackable.
Or have Microsoft, Google, Apple, Facebook, etc., been doing this with such stealth that no-one has actually noticed it happening yet?
PhotoDNA and similar are done in on-premises machines, nothing on your own private phone.
Does Facebook scan local files?
A company looking at content uploaded to servers they own is quite different from a company spying on the contents of a device they don’t own.
Step back for a second and think about why perhaps falling for the ‘but the children’ trap tells you Apple wants to go in the absurd direction you are pointing. Think about if it makes any sense at all they would want to go that way, think about why they would even let you know and think about how plausible it is for these steps to lead to each other.
edit: here's an example of the slippery slope "fallacy" in action
"First they came for the socialists, and I did not speak out— Because I was not a socialist."
In this case, the arguments against this mechanism are generatly slippery slope arguments - logic doesn’t guarantee the bad outcomes. However it’s quite reasonable to be concerned that the bad outcomes will happen because of the actors involved.
This represents a very common misunderstanding of fallacies, IIRC it's called the Fallacy Fallacy: fallacies don't give you any information about the truth of the conclusion, they only indicate that the logic that ties that conclusion to the premises is unsound. So "slippery slope fallacy" means "worse things don't logical follow in increments from better things" but that doesn't mean that in any real situation "worse things follow in increments from better things" is not true.
The most common example of this misunderstanding is probably Occam's Razor, it says nothing about whether things are or aren't more complex in any real situation, only that it's easy to reason about things if you don't add additional aspects that aren't needed.
For one example, it was always absurd to suggest that gay marriage would lead to legalized pedophilia, bestiality, or marriage to objects.
(edited for brevity, expanding more on this in a reply...)
The corporation that is the U.S government acts just like one: roadmaps and planning ahead for radical policy changes to occur within longer spans of time to signify progress (or something), and then absolutely losing their shit if an opposing candidate wins & gets in the way of their progress, as we observed these past 5 years.
Acceptance of pedophilia has been set in motion for several years now. One only need look at some of California's SB-145, the ever-expanding reach of public schools teaching sex-ed to kindergartners, and the N number of drag queens sexualizing themselves in front of young children in public libraries and schools with grand applause and media gushing as these facilities move a few steps away from becoming brothels.
(See what I did there? Surely our libraries won't become brothels, that would be absurd! I mean, the chances of that happening are 2nd to none; and if 10 years from now, libraries still aren't brothels, then I'd have been wrong after all, and my playful exaggeration will have expired. A gatekeeper would have done their noble internet duty to inform me just how idiotic my suggestion was from the start, to be sure. The joke's on them for losing 15 minutes crafting the perfect response to my alarmism that will definitely change my mind.)
We had none of this just 3 years ago, but I'm pretty confident I'll be gaslit in response to my highly misinformed and "hateful" comments, as it goes. ;) That's no matter though. I take responsibility for that by standing by what I say, not bending to the winds of outrage.
Sex education isn't about teaching you how to have sex, it's "here's all the reasons you need to be very careful with sex".
In my classes I learned about many different STI's and the dangers of unprotected sex. Not once was I taught a Kamasutra position or what to do with my fingers.
For younger kids I assume the curriculum would be more about what kinds of behaviors they need to be careful of and immediately warn other adults about.
I suppose the name is very unfortunate because a lot of people seem to think sex-ed is about getting young people to start having sex, when in fact it has the opposite result and we can see it in statistics.
Also, that father violated a gag order, and acted against the decisions of the both custodial parent and his child's medical professionals. You're being disingenuous to misrepresent that as "for calling his daughter[sic] she".
However it's what comes after this, the slippery slope of what to enforce and not. The genie doesn't go back in the bottle.
First using paper forms and later using apps.
Why would you object to limiting the spread of the Coronavirus ?
Fast forward to the present where law enforcement in Germany, Australia and Singapore have used contact-tracing for other purposes.
So no to this plan from Apple, they must discard all plans of client-side scanning and instead increase their privacy stance.
- Germany
https://www.golem.de/news/hamburg-polizei-nutzt-corona-konta...
https://www.ccc.de/de/updates/2021/luca-app-ccc-fordert-bund...
- Australia
Australia, WA, check-in data: https://www.abc.net.au/news/2021-06-15/safewa-app-sparks-urg...
Australia, WA, border pass data: https://www.abc.net.au/news/2021-06-17/g2g-app-data-accessed...
Australia, VIC, check-in data: https://www.theage.com.au/politics/victoria/police-sought-ac...
Australia, QLD, check-in data: https://www.abc.net.au/news/2021-06-29/queensland-coronaviru...
- Singapore
https://fortune.com/2021/02/01/singapore-covid-data-tracetog...
https://www.straitstimes.com/singapore/politics/police-can-a...
https://www.straitstimes.com/singapore/proposed-restrictions...
https://www.straitstimes.com/singapore/politics/bill-limitin...
I don't understand how people were so naive to install those applications. I did the exact opposite: whipped my phone and bought two cheap ones so I can separate my calling phone (which I leave home), from my media phone (no connections), and my GPS phone (no connections aside from GPS and turned off most of the time).
I saw “questionable” images on a probably weekly basis. Maybe once a month something would come through that I thought warranted bringing my supervisor over to provide a second set of eyes because I didn’t think it warranted calling the police over but wasn’t entirely sure. An example of that that comes to mind was a series of photos that appeared to show a young woman bound and gagged to a pipe in a basement area - but she was obviously of age, her eyes in the photos didn’t look fearful, and the rest of the roll showed her free and apparently happy. Finally, I was the person who accepted the roll of film and knew that she was the one who dropped it off. We didn’t call anyone on that, but I figured it wouldn’t hurt to get a second opinion. When she came to pick them up, I did ask her to review them and make sure everything was OK with them.
Twice in about a year we have photos come through that were obviously what’s now called “CSAM”. In both cases I called the police without consulting management then told them afterward. Also in both cases, the negatives were put into the store’s safe and the owners were arrested on-site when they came to pick them up.
All of this is to say - photo lab techs see some shit. If they called the police every time there was a picture of a kid in the bath, police brutality would be at an all time low because they’d not have time to respond to anything else. :)
You can literally read any thread on HN or Reddit to see this is the case. Thousands of comments about facial recognition and AI, completely misunderstanding how it works. The EFF article itself was FUD.
The EFF article starts right off claiming a backdoor, which is completely incorrect. Taking hashes of client-side content is not a backdoor, and the EFF should be embarrassed for not understanding that.
Correct, Apple can access unencrypted files stored on your device.
> That's why the eff was calling it a backdoor
Accessing unencrypted files on a device is not a backdoor
> actively reporting any suspicious looking files to the authority all the time on its own
Yep, that's a problem. Not a backdoor, though.
I don't like FUD driving discussions. I think we need to have serious discussions about this technology. I think people that don't understand it shouldn't participate....
It's not breaking it, but it is rendering it moot. Why even bother with E2E encryption if you can't trust your endpoint? Would upgrading your exterior door's security protect you from theft if it's your roommate who's stealing from you?
> No one is locking people up for political photos.
Authoritarian dictatorships like China are, and they'd love to use this tool to help them with that.
In what weird universe is this even remotely true?
They don't believe this. The lack of understanding trick is often used by governments and corporations because it robs the opposite party the choice to oppose, as opposition is framed as lack of understanding instead of a political choice. It's a semi-elaborate way of calling idiots people who disagree. This is why governments "educate" on topics they don't people to oppose.
I've read too many contentious-change memos to believe it's a mistake. These things are authored by committee with Legal always present, and everything is written expecting it to leak. It's just a passive way to manufacture consent by convincing at least some segment of people to doubt their own thought processes. I'd call it "gaslighting" if that word wasn't already massively misused. See also: iPhone 4 owners who were "holding it wrong".
I don’t consider us in “crap”. I welcome Apple’s decision.
We hold people to certain standards and can do the same for companies.
The parent poster is not advocating for profits over ethics - just pointing out the reality for companies like Apple etc
>The server then uses the decryption key to decrypt the inner encryption layer and extract the NeuralHash and visual derivatives for the CSAM matches.
This "visual derivative" term shows up repeatedly. To me, the implication seems to be that Apple doesn't look at the actual suspected image before deciding whether to proceed with a report. Instead, I infer that they only verify whether (as the device reports) the image's neuralhash is indeed present in the NCMEC database. If my understanding is correct, their "manual review" process actually provides no protection at all against collisions or erroneous database entries.
Further supporting this, on page 4:
>Apple reviews each report to confirm there is a match
It only refers to a match, not about whether the image appears to be illegal.
This makes perfect sense from Apple's perspective- who would want to be in the business of reviewing reports of probably-illegal images?- but it means that the references to a manual review safeguard would seem to be false reassurance. Maybe I'm misunderstanding the paper.
If people look at today's state (phone movement tracking, voice capture, cameras and face ID, etc.) from the mental model of 30 years ago, they would see neither privacy nor freedom. At all.
Sadly, it is not the case of preserving what we still have, if we want freedom and privacy we will have to reacquire them. And a lot of the price will have to be paid in blood.
It may be grayscale and resized/normalized in other ways. Only apple knows exactly what it is.
It's only a matter of time until internet trolls find a way to abuse this. The database is stored on user's devices, so someone downloading it and permuting innocuous images enough until they match the database, and then spreading them for funzies via some underhanded method (wallpaper download sites?)... is not too far fetched.
Most people don’t really want end to end on consumer backup services, because of the associated risks. If however you don’t want unsecured backups you can handle this manually.
Of course nobody wants the company to actually look at your data, but that’s a separate issue.
I could think of a couple of companies this could be outsourced to, with strict business and privacy agreements in place, of course, and also conveniently on the lowest end of European minimum wage for the tier 1 reviewers.
SHA already uses the length in the output hash. Having the explicit length is quite superfluous
Not entirely. It makes it so that, to achieve a "full" collision, you have to ensure that the sets of data collide both in SHA hash and in length, helping to prevent attacks that rely on appending/prepending/removing data (for example, "length extension attacks" involve manipulation of the hash by appending data).
TL;DR: It is harder to find a collision SHA(B) for SHA(A) if you add the additional constraint that the length of B must match the length of A.
The known collision attacks for the MD-family and SHA-1 all in fact produce collisions with the exact same length. The method used necessarily does this.
Which part? The fact that storing "length" along with a hash is not superfluous?
You can probably find many things which have a SHA hash of "ca978112ca1bbdcafac231b39a23dc4da786eff8147c4e72b9807785afee48bb" (infinite things, if we assume arbitrary-sized inputs), but you can only find ONE thing which has that hash and has length 1. I just made it impossible (not just unlikely) for you to find a collision.
> The known collision attacks for the MD-family and SHA-1 all in fact produce collisions with the exact same length.
Emphasis mine. And note that I did not claim otherwise in my comment.
The part where you make a false claim out of ignorance.
> You can probably find many things which have a SHA hash of "ca978112ca1bbdcafac231b39a23dc4da786eff8147c4e72b9807785afee48bb"
No reason I should go looking for such things. You're the one making the false claims, if you have found "many things" with that hash then list them to prove your point, otherwise go away.
Which false claim did I make? I'm still waiting...
> No reason I should go looking for such things. You're the one making the false claims, if you have found "many things" with that hash then list them to prove your point, otherwise go away.
You don't need to look for those things. By definition, you know they exist. I don't need to find or enumerate all primes to know that an infinite number of them exist.
For more information, see here: https://en.wikipedia.org/wiki/Pigeonhole_principle
By definition, assuming arbitrarily-sized inputs, there are infinite messages that collide to the same hash value.
But, don't worry... it is clear you have no actual meaningful point to add, so I won't continue this conversation with you any further. Have a nice day.
Again, you need actual examples. Not handwaving, not the unwavering yet entirely unjustified certainty that you're correct, you need examples. And you don't have any.
Until you do that, I'm not pursuing this conversation any further. Have a nice day.
EDIT: Also, if you do want to have a conversation, make sure to stick to HN rules and talk about what is being discussed, rather than about me. Thanks.
always think about the worst case scenario when it comes to privacy, because that will be the end result
Is there any doubt 50 years from now all this will be on algorithmic autopilot for digital authoritarianism? All societies will have Chinese style monitoring but to an unimaginable degree even to people in China right now.
People outside IT were barely even using the internet 25 years ago. We are at the very start of this and already too far gone. You just have to enjoy these times and what we still have.
I’m guessing their real prerogative is to keep unlawful content from ever reaching their servers. You wouldn’t know that from reading their press releases though.
Why wouldn't they delete them directly, but rather send report to the government?
Why wouldn't they go even further and if image detected on the webpage that is problematic => It doesn't allow it to get to my filesystem either, so that I don't get into trouble if for some reason police decides to search my laptop.
All relevant questions. Answer is the only one: so that when police knocks on your door you were blissfully unaware.
Quite honestly this is all too sad. Again this argument about CP that everyone will buy, but which doesn't work in the wild. There are some bad people out there, but if these people are into buying or creating CP => they will rarely upload it into iCloud. Especially now, when everyone knows Apple is looking for it. So they will go even deeper into hiding, while everyone else will have to live with devices that are spying on them...
It's not a mistake. It's gaslighting.
Apple just communicates this message because that's what they need to say for their business, that's all.
And they can do so because they also know this uproar will disapear like tears in the rain in a short time if they keep smiling. Their bottom line will not be affected because people don't care.
Remember that now, Bill Gates, who we used to associate ti Satan in the 90s, is now viewed as a hero.
Remember that about 1 american out of 160 is working at Amazon, a company with the reputation of treating their employees terribly. Most people hence knows somebody impacted by this, but don't stop shopping at amazon.
Remember you could say you grab them by the pussy and be elected president.
Remember people gives in mass their data to someone who said "they trust me, the dumb fucks".
Remember that when somebody risked his life to unveil a massive conspiracy to spy on the entire world, the person has been hunted as a traitor.
Remember that one president can lie about WMD, go to war against the vote of the UN, kill thousands of civiliands, spend 600 billions of dollars there while poverty is rising at home, and suffer no consequence whatsoever. Most people have forgotten already. Hell, my girlfriend don't even remember the name of the guy.
But it's you that have to be monitored all the time for CP. And you will be punished harshly if you behave badly, not just according to law, but also according to social contracts, both which powerful people can escape now with money and PR.
That's the world we are living right now.
> and more than a few are worried about the implications
they sacked these government employees because they allegedly were engaged in "anti-national activities", no courts, no trial, no hearing. just sentencing that since you are allgedly found to be engaged in such activities, your employment is terminated and there is no recourse. https://www.organiser.org/Encyc/2021/8/3/Govt-s-policy-of-No...
here they have decided to not give passports to protesters or give then government jobs because "anti national activities" again the same trope. this might be a small issue but here is a jounalist https://thewire.in/rights/kashmiri-journalist-masrat-zahra-p... whose father was beaten to a pulp because she being a decorated journalist had criticized the government, they slapped terrorism charges on her and german government gave her asylum so they did the next best thing, hurt her parents because why not. now if she didnt have her passport because she was already a known suspect of "anti national activities", asylum might be a little difficult so they want that.
i know 100% indian government and for that matter pakistan government as well will use this technology for "national interests" in finding out protesters and dissidents and they either do not even go for trials or if they do, the same are sham ones so doesn't matter if they make a show of a trial because the guilty are condemned already.
The chance of a "technical" false positive is tiny, but they need to look all false positives: If some joker sends you a lewd picture through WhatsApp, WhatsApp by default saves every picture to your photo library, then you are now on the naughty list.
Good luck trying to explain yourself out of that one.
Now all they have to do is keep adding hashes to the list and voila. Trump supporters = terrorists = you're in jail because of political games.
The other mistake is to think that removing privacy with longing effects on society [1] and thus attacking the very fabric of a free democratic society respecting human rights would not make children any safer. When they grow up they possibly would have to live in concentration camps or Chine-like regime. It is very safe, but not sure it is very pleasant.
It's about values. It should be absolutely illegal to install any spyware on personal device without warrant
But I know I have paradoxical values here:
On the one hand, I regard abusive porn as evil. I want it stopped.
On the other, I have witnessed formerly-legal acts become illegal, and grew up in a place where there are sexual acts you can legally perform yet not legally possess images of. I think the governments (and people in general) follow a sense of disgust-minimisation, even when this is at the expense of harm-minimisation.
And any AI which can genuinely detect a category of image can also be used to generate novel examples that are also in that category without directly harming a real human.
I don’t have a strong grasp on what I expect the future to look like. My idea of what “the singularity” is, is that rather than a single point in the future where all tech gets invented at once, it’s an event horizon beyond which we can no longer make reasonably accurate predictions. I think this horizon is currently 2025-2035, and that tech is changing the landscape of what morality looks like so fast that I can’t see past that.
“Their” in this case referring to the sender, which makes the particular problem somewhat self-limiting, right?
Hm. Seems like a good attack would be take a celebrity, photoshop some nakedness, and put that in the database. Output: real photo of said celebrity.
This is not acceptable.
Matches can be forced from the outside, by sending pictures to the phone. They don't even have to be from the known-bad image set. Using an adversarial system to try to create hash matches might allow generating innocuous pictures which trigger a phone dump.
Expect a toolset for doing that to be developed. Although it may take a while for word of it to leak out. This has applications for entrapment, swatting, political retribution, etc.
The actual specifics of what material is currently deemed wrong is irrelevant, because it will be expanded.
This. Is. Not Okay.
This is something you'd expect China to mandate, not a Western company like Apple to advertise as a feature.
It almost sounds like a feature Apple is building to explicitly support the imprisonment of dissents through tje false planting of child pornography.
What the actual f--k?
But you can already do this without these changes - cf the UK police officer currently under investigation for having CP on her phone that someone else sent her and (she claims) never opened.
https://www.theguardian.com/uk-news/2020/aug/02/former-polic...
"Williams was sentenced to 200 hours of unpaid work and placed on the sex offender register for five years, which damages her chances of getting another job.
Williams completed her community service in a charity shop, and having finished the hours the court ordered her to do, returned to volunteer further."
Not according to the technical summary PDF they released[1], "Only those images that have a voucher that corresponds to a true CSAM match can have their vouchers’ data decrypted [...] Even if the device-generated inner encryption key for the account is reconstructed based on the above process, the image information inside the safety voucher for non-matches is still protected by the outer layer of encryption"
[1] https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
The fact there is a match in NCMEC's database does not mean the content is CSAM. It does not even mean it's illegal. In fact, it doesn't even mean there's a single person in the picture frame.
And no, this is not theoretical. NCMEC's database is this much of a mess today.
In fact, given there's a threshold at all I'm pushed into believing that Apple know the database is faulty.
Got a handy link about this? A quick search doesn't show anything obvious.
> This is spin by Apple, driven by ignorance or deliberately misleading statements.
The claim was that Apple got access to all the pictures on the phone which isn't correct according to their technical summary. Nothing to do with the validity of NCMEC hashes.
Worse, if your decision to not use an iphone makes others people life slightly anoying for 2 seconds a week, many will bash on you.
As a FOSS user with no FB nor whatsapp account that ask to avoid photos to be taken of him with smartphones, I can tell you I pay regularly the price the price for what I think is doing the right thing. It's just easier to let the abuse go on.
And we have other fights in life. I didnt pick up smoking (pot of cigarets), stopped drinking alcohol, became vegetarian. They all come with social challenges. Add then you have your familly, job, health and goals that needs your care, attention and time.
At some point you just want to say "screw them", create your own bubble of freedom and let them enjoy their distopia. Except we kind of live in it, don't we?
I'm usually an upbeat person but these types of event arrive in a never ending stream, and today I feel tired.
Androids spy on you already.
Apple will be spying on you.
The dark side of economies of scale.
Nobody cares. It's just an annoyance for them.
And it requires an enormous more amounr of energy to live your live this way than not caring. Even more if you gotta explain.
And so here we are.
It doesn't need to be perfect. People have constraints, and life is hard.
But politicians and busines people don't care about being good or bad. They just follow the wind.
Now being gay is trendy, well, they are pro gay.
More people care about organic, they sell organic.
Just caring a little, demonstarting a little that we disaprove and want something else orient their decisions. Because their decisions are not driven by moral, it's just business.
Also, even if you don't do any of this, and I can believe I have to even state this, not teasing or shaming those who do would be an improvement.
What is to be preserved as core is to have the alternatives. Note: in some areas they are already fading...
(I have this flash of Mr. Pink first trying a "We are professionals, right?", than shielding himself behind concrete.)
Also, it's been several years since I used a custom ROM, but I thought rooted devices were not permitted to use the official Google Play Store? (happy to be corrected if I've got this point wrong!)
Rooted devices can use the official Play Store yes, though most people use Aurora Store to access the Play Store because they tend to remove Google Play Services from their phones as well.
Things might be better, but it’s not all roses.
Something tells me that this could be used as marketing, e.g. "protect your children from abuse", "be aware of when pictures of them are taken", and "protect your children from pornography".
Honestly I would have been fine with Apple scanning my all photos after they are uploaded to iCloud but this is deeply disturbing
You can't audit anything Apple does on their servers.
First terrorist content, then "misinformation", then political speech. Apple will be unable to resist government demands to use this preexisting backdoor with a different set of perceptual hashes.
This is Apple explicitly announcing they are actively backdooring all iOS and Mac devices, and using your CPU cycles to determine whether you should be reported to the government.
macOS already supports silent database updates, for example for Gatekeeper and MRT signatures.
Why wouldn’t Apple use this feature on iOS, too?
It's not true end-to-end encryption since in some cases the content can be decrypted without the user key but it's significantly closer than what they have today.
That being said I don't know if that is their plan or not, but it is a plausible reason to make this change.
On the topic of backdoors, automatic update systems could be used as backdoors.
People are making an extreme claim that Apple went out of their way to implement a fancy system to ruin their own value proposition, and the evidence they have to offer is mere speculation.
Many foreign countries have also clearly stated that they do not want this (E2EE) to happen and would legislate against it (the UK comes to mind first).
I do believe that you are correct with the idea that this technology was initially developed as a compromise to E2EE. But while E2EE on iCloud was indefinitely shelved, somehow this was not.
And someone at Apple thought this could be repurposed as a privacy win anyway ?
The other way I can think of it is if the ultimate goal is to add those checks to iMessage. One could argue the tech would make a lot more sense there (it's mostly E2EE with caveats), and it would certainly catch many more positive hashes.
I think someone at Apple massively misjudged the global implications of this and opened the company to a (literal) world of upcoming legislative hurt.
Technology doesn't live in a vacuum. Given the calls from the government for backdoors to encryption, I think it's safe to assume this is Apple getting out in front of what could likely be heavy handed legislation to add actual backdoors like master keys.
But, we'll have to wait and see if Apple starts adding more services to E2EE again. It also may all be moot if legislation gets passed that forces companies to be able to break the encryption for warrants.
I broadly agree but I cannot foresee a scenario where limiting at this particular issue (CSAM) would be seen as a sufficient compromise by legislators to allow E2EE to be expanded.
And other countries will have very different interpretations, much less palatable to Apple's values, on what should be checked for and they will have no qualm legislating to require it.
Quoting the NY Times (via Daring Fireball) :
> Mr. Neuenschwander dismissed those concerns, saying that safeguards are in place to prevent abuse of the system and that Apple would reject any such demands from a government.
> “We will inform them that we did not build the thing they’re thinking of,” he said.
They can tell themselves that but it doesn't matter : they precisely did.
https://en.wikipedia.org/wiki/Hash_collision
option three : don't allow Apple to judge user data at all.
It's at OS level, anything you have on your phone can be scanned. Even if an app tries to circumvent it by keeping files encrypted at rest it can scan them in-memory. And since it's all done client-side you'd never know it was happening until it found a match and sent it to Apple.
> Amendment 4. The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
I have moved away from Apple ecosystem, already purchased another phone yesterday. The Constitution is holy to me, it’s all we have protecting us from technological dystopia.
I wouldn’t care nearly as much about Apple scanning my phone it’s about who is pulling those strings they are working with and in America they are (or should be!) bound by the Constitution. I can only imagine the obliteration of rights that will happen in other places. Imagine a Hong Kong protestor with this program on their phone.
We’ve got to do everything we can to keep George Orwell’s quote from coming true-
“If you want a picture of the future, imagine a boot stamping on a human face—for ever.”
Apple has already been doing exactly this for years. Now they are going to check the photos right before uploading to iCloud which is actually more privacy friendly than they do now. It also lets Apple turn on e2e for iCloud photos if they want.
I understand the 'what if' and slippery slope arguments, but wow, there is so much misunderstanding in this thread. Apple makes the OS and doesn't need a fancy system to scan all the files on the device if that's what they want to do.
I highly suggest reading this: https://www.apple.com/child-safety/ and the associated PDFs. Apple PR hosed this up by putting 3 distinct features on one page that people seem to be conflating.
Is that an assumption made based on that "everyone is doing it" or is there some evidence?
> Apple makes the OS and doesn't need a fancy system to scan all the files on the device if that's what they want to do.
If the goal is to scan all the files on everyones device this system is exactly what they need. It's not like they could upload hashes of every file on every users phone continuously.
https://digit.fyi/apple-admits-scanning-photos-uploaded-to-i...
That's like having the judge, jury, and executioner in my house.
We're more civilised here, you see? We just put you on a list. You can go about the rest of your life. It'll be a bit... shit, but at least you'll get to regret angering the rich and powerful.
[1] https://www.opensecrets.org/federal-lobbying/clients/summary...
It's shocking to me that they don't even acklowege the critisms and fully ignore them. It would be one thing if they said that the potential implications are worth it, but they don't even acklowege them.
EDIT: hmm, scratch that. Confusingly, it was an internal memo from Apple quoting a separate memo from NCMEC.
...which is ultimately what they are going to try to do: label those who oppose this feature as being supporters of child abuse. It's a classic "if you're not with us, you're against us" argument.
I'm not a parent, thankfully; but if I were, I'm not sure I'd be entirely comfortable with the idea of other parents seeing my child naked. Even if I don't sign my child's account up for this scanning thing, the recipient could well be, and they won't be warned about that before sending it.
This is an abusive parent's wet dream waiting to happen, and it disgusts me. Minors should be free to explore their sexuality with their peers. It's how we grow as people.
EDIT: Upon further thought; how is this NOT illegal? How else can this be framed than "Apple knowingly and willingly assists in the dissemination of child pornography into the hands of adults"?
> Apple’s second main new feature is two kinds of notifications based on scanning photos sent or received by iMessage.
> To implement these notifications, Apple will be rolling out an on-device machine learning classifier designed to detect “sexually explicit images”.
> According to Apple, these features will be limited (at launch) to U.S. users under 18 who have been enrolled in a Family Account.
> In these new processes, if an account held by a child under 13 wishes to send an image that the on-device machine learning classifier determines is a sexually explicit image, a notification will pop up, telling the under-13 child that their parent will be notified of this content.
> If the under-13 child still chooses to send the content, they have to accept that the “parent” will be notified, and the image will be irrevocably saved to the parental controls section of their phone for the parent to view later.
[1] https://www.eff.org/deeplinks/2021/08/apples-plan-think-diff...
from the eff page:
>…if the under-13 user accepts the image, the parent is notified and the image is saved to the phone. … once sent or received, the “sexually explicit image” cannot be deleted from the under-13 user’s device.
apple’s info sheet:
https://www.apple.com/child-safety/pdf/Expanded_Protections_...
- one is parental control, it’s upon request, uses ML, it’s “local” (that is, it’s sent to the parent)
- the other one is plain hash matching, which does not “save the children” but rather is “catch the viewer” — exclusively. This has no impact on the abuse of the CSAM subjects because it only matches publicly-known content.
I don’t know why NCMEC is excited since stopping the viewer does not stop the abuse; This does not affect them.
Conspirationally speaking, it almost feels like things aren’t the way they’re described and Apple will in fact ML to detect new content and report that.
The threshold thing doesn’t even make sense otherwise. One known CSAM picture should be enough to trigger the report, but it sounds like they want better accuracy for ML detection.
They get to keep their jobs :)
Are you claiming victims of child sexual abuse wouldn't care if images of the abuse are circulating freely and being viewed with impunity by pedophiles?
> many thousands of sexually exploited victimized children will be rescued
This does not aid rescue.
Good ideas to stop the circulating would be to increase birth control education and access, increase foster care funding and access, implement common sense policies for adoption, and increase funding for Child Protective Services.
IMO posession of CSAM should be legal but heavily regulated, so that users who don't want to hurt children (probably will most of them) cooperate with authorities to investigate producer (child abusers), get connected to mental health care, and not be driven into a criminal underworld full of blackmail.
Pictures they can’t use as evidence, or use to “discover” evidence due to fourth-amendment protections.
[1]: In his book Tears of Rage, Walsh openly admits being in a relationship with 16-year-old Revé when Walsh was in his 20s and aware of the age of consent being 17 in New York. Critics of the Adam Walsh Act have pointed out that, had he been convicted, Walsh himself would have been subject to sex offender registration under the law which he aggressively promoted.
“But you know, she had this way about her. She had a certain presence. And after a while I just got over how young she was. She was way more sophisticated than anybody in her high school and she always dated older guys.”
But also she’s a director at NCMEC. What else is she supposed to say? “Cool I guess, thanks Apple.”
Is NCMEC's mission protecting children or self promotion? Facts are best for the 1st.
All the "what if Apple turns evil one day" applies equally well to iOS without this feature.
Most ordinary people, especially those who have kids, won’t have a problem with a well-implemented, E2E encryption compatible scheme that is legally limited to only apply to this type of material. If explained the hash collision issue, they’d reasonably point out that Apple does manual review before notifying law enforcement, so this rare eventuality is something they can live with. Meanwhile, in the other camp, many of the vocally outraged fail to understand that no E2E encryption breakage has to be taking place for this feature to work.
What’s actually a problem is that earlier, back in 2019, Apple changed their ToS to allow pre-screening of generally any “potentially illegal” content[0]. This should trigger much wider audience, and for legitimate reasons (the phrasing is clearly unnecessarily broad, and opposing this does not undermine kids’ safety in any way), yet no one is talking about it to my knowledge.
[0] https://www.macobserver.com/analysis/apple-scans-uploaded-co...
Rare is an assumption.
Do you work for Apple?
[1] https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
The only event in which Apple can gain access to your content is if you happen to have multiple CSAM matches; then they can access only the matching content, and only then if it’s manually confirmed by a human to be CSAM an action is taken.
The issue is if this type of matching is done for other purposes than CSAM; and unfortunately they gave themselves legal permission to do it back in 2019. That’s what we should object to, not CSAM reporting.
The issue is the hash algorithm is secret. The decryption threshold is secret. The database of forbidden content can't be audited. People claim it includes entirely legal images. And it's a small step from scanning local only files.
And that's precisely the leaky part of this setup. Nothing about this system's design prevents that from changing on a mere whim or government request.
Next year they could be adding new back-end checks against political dissident activity, Uyghur Muslims, ... and we'd be none the wiser.
What are you basing this assumption on?
Again, pure speculation and really the most generous means of explaining this controversial decision.
I've missed where this has security implications. Did you mean privacy implications?
That’s scary
Which is a very scary statement any company to make (the means to get to that point?!). But I am sure some countries see this is as a great technology to push for slogans of their own: "no citizen of Nonhomostan is a practicing homosexual!", "no citizen of Oppositionkillerian has any mind-corrupting western banners on their phone!"
This technology will allow large powers to make sweeping statements about data kept on private devices.
Companies doing good things brings good PR. That could just be it.
Sadly, it's probably really to appeal to China or the US government.
I wouldn't be shocked to hear of some secret court order ordering them to add some kind of backdoor, and this legally meets the bare minimum.
How long till Apple gets a secret warrant from the FISA courts to scan for a certain file on all US iPhones? Apple can’t claim it isn’t possible.
It could be happening now. We wouldn’t know because all we have is a list of hashes.
The entire premise of this system is that the targeted users are ignorant of its existence. If we can be so sure they don't know it exists, then surely having an option to disable it would cause no difference in outcome.
If the people in favor of this system don't like the idea of making it optional, perhaps that shows that the premise behind it is flawed.
For now at least, who knows about the future since it's on-device and doesn't actually require you to upload anything.
[1] https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
Today photos are not end-to-end encrypted, there is nothing preventing Apple from decrypting your photos if they want (or if they are asked by law enforcement). If a part of this implementation is to make it so only the user keys OR the CSAM keys in the case of a match are able to decrypt the photos then that is a clear step in the right direction over the current system. It's not real end-to-end encryption, but it still prevents Apple from just decrypting your photos without probable cause of a very specific crime.
If that is the case they should have made it a lot clearer in the initial announcement though.
The issue is that this mechanism applies to photos (/data) on the local device that wouldn't otherwise make its way up to iCloud.
The EFF posts says it applies to 2 cases: photos being uploaded to iCloud, and photos through iMessage if the account holder is a child and the feature hasn't been disabled.
https://www.eff.org/deeplinks/2021/08/apples-plan-think-diff...
You're right that only scanning photos uploaded to iCloud is currently pointless. But maybe Apple plans to do semi-end-to-end encryption on iCloud photos in the future, and then this feature would be useful.
In Computer Security we are required to provide responsible disclosure when the privacy of users was (potentially) violated. When law enforcement has a search warrant for my place, I can at least notice that an intrusion happened and in many countries I can request the warrant.
Here, a false positive never gets any of the "Five Ws" answered: Who used this system (which government agency / company)? Why was I (mistakenly) flagged? Which particular piece of my data triggered the system? When did the system phone home? What is the intended purpose of this system?
And most importantly: What parts of my privacy were violated? Who had access to those, and how was the infringement of my rights remedied?
We have hardware fuses, trustzones and so on. It must be possible to have a auditable and tamper-proof system that triggers once such a system calls home and then discloses the "breach" to the user after X days.
If the public had access to that information and transparency reports about the success rate vs. false positivity rate, then society could evaluate the system is adequate. I'd wager many would question the "save the children" argument if they regularly heard about false positives and egregious access to private photos by law enforcement.
Many there are barely any false positives, I'd personally support a CSAM in that case. As it stands we won't know.
(1) Other less invasive system (Youtube strikes, many social media bans) also share the laid out concerns.
https://www.patrick-breyer.de/en/posts/message-screening/?la...
Just installing graheneos on a pixel, writing this from my Librem 14 (got it after the M1, the phoning home of apple apps, the new lockdown of kernel extensions).
Goodbye Apple.
"It should run microsoft office" is a difficult problem to solve and only serves to deeply entrench the big players.
I'm aware that I've had this same criteria myself for choosing a new device (because: pragmatism) but I've come to just "accept" it.
If I look a bit further away and remove my implicit acceptance of the status quo: I'm actually quite horrified that we're so tied to one company and what _it_ decides to support.
If the next versions of Microsoft Office didnt work on apple devices at all: what would the world do? Run Windows exclusively due to pragmatism is my initial assumption.
Nice one Apple. Hopefully they're not referring to the minority that buy their products as a result of them being marketed with privacy and security as setting them aside from their competitors.
Here is a list [1] of at least some of the 'minority'
WhatsApp have also fired back at them [2].
[1] https://appleprivacyletter.com/
[2] https://www.theverge.com/2021/8/6/22613365/apple-icloud-csam...
I'm sure the government has tens of thousands of hours of audio and will gladly supply the sound signatures. Think I should submit my idea to Apple??!
Isn't it pretty rare for people to watch porn with the sound on?
Speaking as a frequent consumer of legal and ethical porn, I almost never turn the sound on. It's easier to contain leaks of light than of sound.
You can cast that net, I just doubt it'll catch many fish.
How does that work?
Worse - unless the "perceptual hash" tech is better than anyone suspects, most of the images flagged will be personal images of consenting adults.
So Apple - and possibly US.GOV - ends up with a huge collection of intimate photos of many of its users. Plus everyone's porn stash.
I'm finding it very hard to understand why no one at Apple realised this would be a PR disaster.
They turn over this data for over 30,000 users each year to the USG without a warrant, per their own transparency report.
Would you be comfortable with this? Would you be comfortable with a company searching our physical lives in the way Apple intends to search our digital lives? How are these 2 things any different?
I do wonder what China and other countries will do. Will this system be under the control of US authorities?
> To what extent should one trust a statement that a program is free of Trojan horses? Perhaps it is more important to trust the people who wrote the software.
2021 swatting
For the child iMessage system it would notify the parents, not law enforcement.
It's nothing like swatting
The whole point of this change is that they will scan content "before" it hits iCloud. (the verbage says "before" as if there is going to certainly be an intent that it goes to iCloud but that's not a given at all, sounds like Apples marketing speak to "assume the sale" so to say).
CSAM scanning of photos uploaded iCloud photos has already been in place for quite some time.
After Cook and co have this happened, they'll rethink this program real quick.
Who will audit false passive cases including reasons for unlocking data ? How false positive cases will be investigated and by whom ? (in case it was intentional data unlocking, eg. corporate espionage) How "victims" of false positive cases will be notified ?
It's a slippery slope.
New legislation in a given country could be passed forcing a Apple to do this. Someone who cares about such things would self store their own data IMO
WhatsApp, signal, email, slack, everywhere. Everyone would get flagged, mean that this tool is pointless.
If anything I’m seeing some very worrying minimisation and dismissals of the problem of CP, child trafficking and abuse and other privacy and ethics related issues such as counter-terrorism.
What’s the privacy and ethically aware solution to these problems?
When will they also start ratting on their costumers?
[0] https://en.wikipedia.org/wiki/Casio_F-91W#Usage_in_terrorism
Nobody is dismissing CP (or terrorism). Simply put, it’s not Apple’s problem to solve.
> Our commitment to lift up kids who have lived through the most unimaginable abuse and victimizations will be stronger.
Ah, yes, everyone that is vocally concerned about this is either misinformed or irrationally “screeching.” We, of course, are righteous defenders of children. Tighten those blinders, Team Apple!
Detect CP
Detect child abuse
Detect signs of child abuse
Detect signs of abuse
Detect signs of violent crime
Detect violent crime
Detect crimes
Detect "crimes"
People not believing me, then tell one example of a privacy encroaching policy that didn't expand its original scope of "think of the children" and "terrorism".
The worst part is that they are probably doing it and abusing it and are now seeking a way to normalize their conduct.
This is no different. Apple knows which way the wind blows.
Now there's a constant search warrant on your phone that can be used against you in a court of law.
1. https://www.apple.com/customer-letter/
Regarding the slippery-slope argument in this context though, it isn't the same. if Apple really wanted to silently transition from CP to Gov/Politics surveillance, they could have just released this feature without any announcement. I mean, if they wanted to be evil. Shouldn't we have thought about this eventuality before putting all our pictures in the cloud?
I don't back up anything to iCloud. Instead, I connect my iPhone to my laptop and run the excellent "iExplorer" utility from Macroplant[1].
This allows me to browse my iPhone like a filesystem and copy off all of the photos/videos to a directory where I can then rsync them to my local fileserver.
You can also dump iMessages and notes and all of those other thing but I just export photos ...
>We know that the days to come will be filled with the screeching voices of the minority.
aka "We are Apple and can't do no wrong and they are just haters"
On what basis? Is there precedence for this?
Then when the message settles in, they do exactly opposite.
Someone at Apple read 48 Laws of Power too many times.
Why would we trust law enforcement to a posse of private citizens (albeit with a congressional charter)?
What they're doing isn't law enforcement. Charging people with crimes, arresting them and throwing them in jail is law enforcement.
We do have international institutions and media that can handle this.
Was about to get an iPad Pro for work, will not get an iPad Pro ever.
I thought their strategy is similar to Valve's anti-cheat - Tell the offenders absolutely nothing up until you snap shut on them.
The consequences between cheating in pub Counter-Strike are obviously less serious, but Valve does let people cheat for a while and then bin people into "ban waves" (last I heard, anyway) to try to throw off the trail and prevent cheaters from figuring out exactly which actions got them in trouble. It's also similar to the concept of hellbanning trolls from a forum. They won't comply with kind messaging, they'll just instantly shed their accounts. So don't let them know they're banned.
There is a whole (even more fraught) conversation about how to get pedophiles in touch with psychiatrists before they commit any crimes, but telling them "pst, I'm onto you" peacefully probably isn't the way.
Second, the fact that everyone is now a suspect by default (instead of targeting specific individuals), is a very concerning development.
Just imagine Tim Cook retiring and being replaced by someone like Donald Trump. All the tools are now in place to start misuse.
On the other hand, it seems they did built a great tool, preserving privacy while still scanning Photos locally. I just feel it’s wrong to use this on all (innocent) people.
Each update, even if done manually, re-enables autoupdate, requiring that you go turn it off.
Apple is really into being able to run whatever code they want on your device without your intervention.
The world is not just black and white.
When the vendor can execute arbitrary code on your machine without intervention, that's effectively a backdoor of any/all kinds.
https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
and then replace
- "National Center for Missing and Exploited Children“ with „the new Trump administration“
- „child pornography“ with „LGBT content“
to see what 2025 might look like?
(use „the new Clinton administration“ and „images of guns“ if you are conservative)
If I browse internet and accidentally load a page with all images from this CSAM database => are these images automatically saved somewhere on my filesystem on iOS? So if this software was scanning not only iCloud but all images on my phone I would be reported automatically?
Hypothetical question.
> Keeping China safe is such an important mission. In true Apple fashion, pursuing this goal has required deep cross-functional commitment, spanning Engineering, GA, HI, Legal, Product Marketing, PR and the CCP. What we announced today is the product of this incredible collaboration, one that delivers tools to protect China, but also maintain Apple’s deep commitment to user privacy.
> We’ve seen many positive responses today. We know some people have misunderstandings, and more than a few are worried about the implications, but we will continue to explain and detail the features so people understand what we’ve built. And while a lot of hard work lays ahead to deliver the features in the next few months, I wanted to share this note that we received today from NCMEC. I found it incredibly motivating, and hope that you will as well.
> I am proud to work at Xinjiang with such an amazing team. Thank you!
There must be tremendous amounts of dirt on most powerful people but it rarely sees the light of day and how it is obtained is never revealed?
So the very fact that it is opt-in means it doesn't even try to "protect the children"; it just uses the children argument to promote the idea of total control, which will be then used for a host of other purposes.
technically you could not update to ios 15 or disable icloud, but it's not opt-in by any means.