Apple says photos in iCloud will be checked by child abuse detection system
reuters.com
reuters.com
Oh, all right: Apple, already being in possession of hard evidence of a hideous crime and already being required by law to forward such evidence to proper authorities, will also - pro bono publico! - sacrifice significant amount of time of a significant number of their in-house computer forensics experts, each enjoying a significant billing rate, to relentlessly look for "other signs of criminal hacking", until there is no significant doubt that the accused is, indeed, guilty. We're all safe, then.
I don't know whether to laugh or cry.
Not that I would ever advocate for such a thing of course.
Anyone here think Yahoo executives actually decided whether the company joined PRISM or not? Those executives also were not in charge. There is a bigger boss in DC, radically more powerful, and most everybody here knows what they're after. They're sick of waiting, they're going to attempt to make another big surveillence move during the relative calm of the Biden Admin (they couldn't do it effectively under Trump, there was too much chaos, the government wasn't functioning very well). What program is actually being put into place right now - that Apple is probably joining up to, as with PRISM - that we won't find out about for many years?
It's going to get a lot worse across the board over the coming decade.
So, how can Apple make any argument when they legally aren't allowed to talk about it? Do you think Cook believes in your privacy so much he will go to prison for revealing it? Nope, he's the one who let them in Apple to begin with and "privacy" is a sales pitch everyone laps up. They've been compromised for over a decade. There is no security. It's all lies on top of lies. Have you ever heard of what happens to people when they reveal top secret government spying programs? Snowden? Drake? Binney? Manning?
All we know is what they do. It's not a stretch by any means to suspect that when an American corporation adopts uncharacteristic policies that violate their customers' privacy, the government is probably involved. Difference here is that unlike TrueCrypt, Apple can't just shut down. Hell, even the rumor of Apple doing this has beneficial impact to law enforcement. The press release may be the product.
Let's take the effort at the most altruistic face value - defeating child porn mongers. If you're trying to herd such people to a very narrow set of solutions that you can monitor and/or control, simply undermining trust in the alternative options may be enough without actually implementing invasive tools being discussed. The comedy in some of this is how hammy the next act can get - if I were a cynical man, I'd expect a technology to come out in response to Apple's move, or maybe it's out there already but suddenly gets a new push for mindshare. I'm sure the security world has a term for solutions like this. Not really honey pots, but more like fly paper. A product the agencies have either straight up owned or surreptitiously gained control over, marketed to people who would use it for ill.
I'm just some guy with a beard, I honestly don't know anything about anything- in my eyes, it looks like less of a legal requirement and more of a stepping stone. Granted, those things aren't mutually exclusive and I'm not privy to any information others don't have, I'm just cynical.
> There is a bigger boss in DC, radically more powerful, and most everybody here knows what they're after.
OK, so tell us! Who is the mustache-twirling villain, and what are they after? I'd love to know. Be specific. Is it Joe Biden? If so, what's the end result? He gets money? OK, draw the lines for us between this technology and Joe Biden getting money. If it's somebody else leading this conspiracy, who specifically? What specifically are they after? Without these details, OP's post is just an episode of the X-Files: Something's out there, and you know what it is, I just won't tell you!
Not sure why the source of things like PRISM and all have to be a single evil person - I think you watch too many Bond films. I can't articulate any sort of form to the driving will behind what we see happening to the security state over the last twenty years in particular, but we do know that privacy continues to erode, that agencies basically dictate agendas to the press through "leaks" and even by putting retirees directly on their payrolls. That much is known. I don't know if it's productive to attempt the characterization of this phenomenon as some Scoobie-Doo mystery to be solved and unmasked. It's probably more important to oppose the policies, politicians, and press that seem to align with an agenda that promotes the bargain of us turning in freedoms for a promise of safety.
We know there is a global elite who have virtually unlimited financial resources and massive influence over nearly every key institution on the planet, including intelligence agencies. Some of them publicly attend meetings like the one in Davos. And yes, that includes names like Rothschild, Soros, and Gates. These are incredibly smart and hardworking people, and because of their powerful positions, they have an enormous responsibility over the governance of the planet. It's not all about money; this group has control over monetary policy, and are therefore above the fray of being divided into abstract economic units.
This group is making decisions like enacting free trade policies that reduce opportunities for the American middle class in order to more equally distribute opportunities to developing countries. Or creating surveillance networks to prevent catastrophic events which may include nuclear, biological, or cyber attacks that could threaten the global order and feasibly be deployed by a small group of individuals. Obviously, these policies give this group an enormous amounts of control over populations, but it's easy to argue it's for the greater good.
Something like CASM is more like a Noble Lie used to manufacture consent for a vital tool needed to advance their agenda, for lack of a better word. The tech community, for the most part, knows it's bullshit. But the media will control the narrative (or just ignore it), and the tech community will sound like paranoid nerdy pedophiles.
If you feel like CSAM is an overreach, then please continue to pay attention as the cyber-pandemic narrative gears up. Although anti-vaxxers are currently in the spotlight, you may have more in common with them than you think.
So, for 1. you mention a shadowy "global elite" but also name Rothschild (which one?), George Soros, and Bill Gates. OK. Another poster points to the CIA, NSA, and FBI. All right.
For 2. It's "deploys CASM on cell phones". I guess this means Tim Cook has to be another conspirator.
3. What is the end result? Now, we're getting hazy. But, don't worry, most conspiracies start getting vague at this step. You say "manufacture consent for a vital tool needed to advance their agenda." What does that mean? What is the tool and what is their agenda? You hint at "equally distribute opportunities to developing countries." Is that what's going on here? How do you connect the dots between CASM and that? Or, maybe it's "prevent nuclear, biological, or cyber attacks." How does CASM do that? What is the end game?
Finally, 4. How does this all benefit the Rothschilds, George Soros, and Bill gates? Beats me, these people already have everything. What benefit would motivate this shadowy conspiracy? This is where most of these conspiracies totally break down: Drawing the line back to how the conspirators benefit.
The Rothschilds are also reportedly working with PG&E, Jerry Brown, and Solaren to use space lasers to start wildfires, resulting in high speed rail in California. Even if you could connect those dots, I don't get how it benefits the conspirators.
No need to try to be silly to avoid reality.
Just read all the Snowden revelations. Those very same agencies, whose mission statement is to spy on everyone, are still working their jobs of spying on everyone. It's not like they were disbanded just because Snowden revealed a tiny slice of what they were doing then.
We factually know that a number of powerful three letter agencies work in tandem with each other and with other agencies in other allied governments around the world to maintain as much secretive information scooping as possible about the affairs and communications of civil society. This was blatantly revealed in 2013 for all the world to see and nothing has happened since then to indicate that it hasn't stopped happening only with some moderate adjustments to procedure.
If anything, a number of governments are now trying to normalize their efforts to the public enough that they can do it more overtly (see recent attempts at arguing for backdoors on major E2E-encrypted communications apps as an example). The simple inertia of massive state security and surveillance budgets is enough to explain much of it without resorting to any sort of James Bond-type villians, let alone pinning any specific blame on Biden as anything more than just one more president among many heads of state and previous presidents, who supports the status quo of the mission-creeping institutions around him.
This isn't even and shouldn't be viewed as a partisan-politics thing. It happens almost equally regardless of specific party in power. Obama was tacitly complicit in it just as Bush was, and Trump's administration was likely no different either, except for its internal chaos causing certain rather unique administrative problems. What evidence indicates anything sincerely changing under Biden now?
That you could be so condescending about these very established tendencies despite the absolutely concrete revelations of their existence is what's strange and disappointing.
1. https://news.ycombinator.com/item?id=8305925
2. https://www.businessinsider.com/marissa-mayer-its-treason-to...
Wow, very different search results when using google vs duckduckgo.
Don’t even have to use iTunes anymore, it’s all been moved to the Finder where the iPhone or iPad shows up as an external device.
seems like it almost confirms this system was created to make it easy to ruin people's lives, because you know plenty of bad actors will take advantage of this
Also, if you have full access to somebody's phone, it does not matter if Apple is scanning for CP or not, you can do much more sophisticated things.
Also 0-day non click exploits are not something random scriptkiddies running around with dropping CP on random phones as they are way too valuable.
> there is no additional gain from going though all the hops
The only thing I could see would be getting the victim locked out of their iCloud etc accounts with little/no immediate recourse, as from what I have read the process seems to be to lock their accounts as the CP detection alert is sent to law enforcement.
> Also 0-day non click exploits are not something random scriptkiddies running around with dropping CP on random phones as they are way too valuable.
I agree, 0-days are the far high end and wouldn't be used for things like this especially by trolls, but I have to imagine there are methods in the lower-hanging fruit levels available to malcontents to sneak content like this onto unsuspecting users devices. Like, custom ringtone/emoji apps and download packs, random QR codes that lead to downloading a place's menu but also a suspect image, or other usual suspects.
Nobody has put down a convincing difference for this attack yet, but people sure do love repeating it.
And this is a problem because Apple's proposal is really really awful. Apple is normalizing scanning your private phone for files and reporting them. They built the technical capability to do it for any photo, and they will be under enormous pressure to expand it both in the US and abroad. And the fact that they did it will be used to pressure other companies into doing the same and to legitimize laws that require scanning for any content the government can justify.
Apple built a surveillance mechanism that is incredibly powerful. One no government could ever force a company to design and build. But once it's built, the only thing stoping it from being abused is Apple's pinky promise they won't let it happen. If you believe that legal norms, big tech companies and some quasi governmental nonprofit like NCMEC will stop such an abuse if it happens .... where have you been living the past few years? Because it sure isn't the US, the UK, Turkey, or China.
There seems to be a vague idea floating around that this is built into the OS or the device just because the scanning happens on the device, but it’s not clear that’s the case. Apple doesn’t make the distinction between OS and app clear either.
This approach makes mass-sweeping of all server-side stored data harder to accomplish (whereas in, say, Google Photos, Google can break-glass server side to get into someone's private data, so they could hypothetically do a mass-scan if the government demanded it).
First line of their privacy policy is: “Apple is committed to your privacy.”
This is what I meant by mixing up (and blurring the lines between) app-level and OS-level capabilities. It might not actually be mixed up technically, but it seems to be the user perception.
Updated original comment.
Someone was worried about how they handle the keys. They have solution for that already: https://blog.cryptographyengineering.com/2016/08/13/is-apple...
(Caveat that if you have iCloud backup enabled - which it is by default, the backups aren't end-to-end encrypted. This feature is basically on the convenience side of convenience vs privacy / security - too many consumers would irretrievably lose their data if iCloud backup weren't enabled by default)
This is false. They present a web interface showing the photos. The UI isn’t locally generated entirely using JavaScript to decrypt the data. They only way this can happen is if Apple has the decryption keys.
iCloud Photo Library has never been private. Apple has always been able to view your photos.
https://9to5mac.com/2021/08/05/report-apple-photos-casm-cont...
Apple has the keys; the data is encrypted at rest and in transit, but they can be compelled to use them.
The only thing stopping your phone from keylogging your password to a server in the NSA somewhere if it recognizes a specific trigger pattern is Apple's willingness and ability to resist pressure from the US, etc.
Think of what would happen if you tried to make your average Silicon Valley dev team design, implement, and test a surveillance system they didn't want to build and that was immoral. They'd resit in an infinite number of ways that would delay the project virtually for ever. Short of summary executions, I bet you could not get a nice, efficient, effective system.
On the other hand, once the dev team has enthusiastically built the system that scans for any image, it's entirely easy to say "Now, make it look for these images." They have no avenue for resistance other and a up front no. And a government that wants to do totalitarian things knows many ways to force a yes.
In general, a company at that size would approach this problem by figuring out who in the company is willing to take on an unsavory challenge like this and then forming a skunkworks out of them, slightly sequestered from the rest of the company.
I'm not saying Apple has done it, or that they're incentivized to. But it's trust-turtles all the way down. Either we trust them to say "No, you can't use our tech to harm our users," or we don't.
It wouldn't be that. It would be defense contractors sitting at Lockheed or a few blocks from DARPA whose daily bread is making a Tech Sandwich whenever the Broad Agency Announcement for one shows up on sam.gov, or on the DARPA page, or the variety of procurement sites that the government doesn't expose to the internet. If they want it, they can get it -- no persuasion of liberal tech-bros needed.
Second, Apple almost assuredly will encrypt iCloud after this. So now we have the precedent of scanning encrypted messages. And that will then feed legislation that congress has been attempting to pass for years to kill any right to meaningful end to end encryption for messaging. https://blog.cryptographyengineering.com/2020/03/06/earn-it-...
”Antivirus cries in corner as forgotten...”
I know, iOS has no build-in AV (like MacOS) but still, it is a bit laughable that many existing tools provides this same power, and only now it is a concern. On a black box system. I am resilent, and I will join into mass of pitchforks and torches only when there is actual evidence of them expanding their promises or using these features for something else they are meant. They knew the risks when bringing this feature and know the cost when it is proved to be misused.
This has been going on for CSAM scanning for a while now. The latest version was called the EARN IT act [0]
The argument is not this is a slippery slope where you might miss step. IF that was the case, yes AV would be analogous. Instead, its that people are actively trying to push you into the spikes at the bottom of the pit, don't build things at the edge of the pit where the handrail is a pinky promise not to let others push you.
[0] https://blog.cryptographyengineering.com/2020/03/06/earn-it-...
People are afraid, that the use of these tools are expanded in secret (hidden) for more than they should. From that point of view, legislation motives and discussion does not matter, because capability is valid for many tools at any moment, hence same speculation has applied before.
However, if you want to apply surveillance publicly, then we indeed need legal base for pushing specified tools as mandatory. To expand it for more than CSAM, it will be quite slow process, and implementing something like that publicly before legal base is path for descruction for any company, because people can change for other company.
Is Apple now making that legal process faster?
While it feels like Apple is now closer to the edge of the pit, from techical perpective there is no difference yet. Tools have existed and system is closed source. Question is still the same; ”would you spy for us”? I don’t think that answer has changed from Apple because they changed the location of the image scan.
So, the question is, will legislation change towards more surveillance. Whatever the result is, I think it would have happened whether Apple added this feature or not, as it is not morale excuse. People find the way. In China, it is simply illegal to not install some app by muslims.
I think what we're seeing is Apple betting on using cryptography as part of the product design phase. Apple devices already do weird things like wake up to announce their physical location so that users can find their devices. The thought of a powered down or suspended laptop waking up to announce its location isn't something I particularly want, but Apple users seem to like it.
Anyone who has spent any time on spaces that are strongly encrypted and focused on privacy know how quickly they become havens for the sort of material that Apple doesn't want associated with its brand. How many "Apple protects child predator" news stories do you think Apple can withstand while still remaining a luxury brand?
Apples goal here is to have the reputation for end-to-end encryption and privacy while simultaneously not being seen as a phone for child predators. They don't have a lot of options if they want to thread that needle.
I've thought about this space quite a bit, and all options suck. Client side scanning is really the only choice with reasonable tradeoffs. The other option is scanning encrypted photos on cloud using secure enclaves to do the scanning. My guess is that when the tech makes that possible Apple will move in that direction.
I agree that this isn't the best for privacy nuts like me. But the iPhone isn't a blackphone, it's a luxury handbag. The phone isn't for privacy nerds, the privacy is there to make other mobile OS's look cheap and tacky.
They deserve to be raked over the coals for this, there's no world where their current design is a "good" or "right" one.
Child abuse is a serious problem, but building a surveillance panopticon is not an acceptable solution to it. Better investment in education, health care, and reporting hotlines are the way forward to stop this issue at its source.
Five years ago, the idea of Apple scanning photos on your phone would have been absurd.
Five years from now, what will people think about hotels installing AI-powered cameras in every room? The vendor swears they only start recording when they detect an act of abuse. It sounds absurd now, but where do you draw the line?
It does not really matter if the scanning happens on device or iCloud in this situation, because you have to always trust their closed source system. Google has scanned your images since 2009 in the cloud unencrypted, but now when Apple makes situation better, it is suddenly bad. All tools have been out there already. There are no really other options to get more privacy than this, but people refuse to see that.
Well, there is voting. Vote people who puts privacy over everything. That would make everything easy.
At the moment Apple's scanning policy is about the same as it was before. They claim they're only scanning photos if iCloud photos are enabled. The change they're advertising is doing the actual scanning process locally.
The problem is two fold. The first is Apple went from scanning only explicitly uploaded content to local content. Since they've decided to intrude on local content once "for the children" it's not out of the realm of possibility (if not likely) they will make further intrusions in the future for prima facie noble reasons. Are third party apps going to be restricted on saving data unless they allow access to Apple's CSAM scanner? Will it start scanning texts or e-mails tomorrow letting and rando flood a person's phone with CSAM and get them arrested? Adding a local scanning system like this is a slippery slope.
The second problem is the opaqueness of the system. This has multiple sub-problems. While the NCMEC has a laudable goal, involving them in the CSAM scanning process involves an outsize level of trust I don't think they have earned. They have law enforcement's unfortunate disdain for personal privacy coupled with a fanatical devotion to their cause. They believe their actions are always correct and just so long as they supposedly serve their goal of "protecting children".
Due to the opaque nature of their content library it's not crazy to think repressive regimes will get self-serving content added to the source libraries for CSAM scanning. There's plenty of places where homosexuality is punishable by death and even mildly anti-government content will land you in jail. Obviously you and I can't go look at NCMEC/ICMEC CSAM libraries to check for falsely added content. So how are we supposed to trust a system run by fanatics to not have simple errors?
Which leads to the other opaqueness sub-problem. Apple's design is interesting, if not laudable, but is closed source and full of black boxes. PhotoDNA, NeuralHash, and the like are not published algorithms anyone can verify. We don't even have a way of knowing if some image we have tripped a false positive and have to trust Apple's unknown "threshold" isn't 1. So not only does the public, the subject of these new intrusions, have no way of auditing the database but they have no way of auditing the code or process. A stupid bug in the scanning system could get a user reported to Apple which we then have to trust not to forward (and not to have additional bugs in their reporting system) them to law enforcement and ruin their life.
So I am concerned with scope creep and bugs/false positives. I can live with a bug that causes video playback to stutter or a black box system in Maps that gives me the wrong hours for a restaurant. It's much harder to live with bugs that can get me arrested or even killed thanks to trigger happy police. Apple's system might be technically adept but their promises of future behavior aren't trustworthy since they've already changed their behavior with this new system.
Major difference is, that they have no access for other images anymore as they used to have. They leave device as encrypted. Images used to be plaintext in the eyes of Apple.
> The problem is two fold. The first is Apple went from scanning only explicitly uploaded content to local content. Since they've decided to intrude on local content once "for the children" it's not out of the realm of possibility (if not likely) they will make further intrusions in the future for prima facie noble reasons. Are third party apps going to be restricted on saving data unless they allow access to Apple's CSAM scanner? Will it start scanning texts or e-mails tomorrow letting and rando flood a person's phone with CSAM and get them arrested? Adding a local scanning system like this is a slippery slope.
Emails have been scanned for long time in the cloud already. The rest is only speculation and against what they have told. It might be hard to trust, but in closed systems it is all we have. We should be worried when they actually say or start doing that.
> There's plenty of places where homosexuality is punishable by death and even mildly anti-government content will land you in jail.
It is fair to not trust third parties (NCMEC/ICMEC), but Apple is responsible for making the algorithm and testing that. Misuse must be part of their tests at this level. iCloud photos used to be plaintext so this hasn't changed from that perspective. If there is evidence that they are scanning other images outside of iCloud as well, then we should get the pitchforks and torches.
> We don't even have a way of knowing if some image we have tripped a false positive and have to trust Apple's unknown "threshold" isn't 1. So not only does the public, the subject of these new intrusions, have no way of auditing the database but they have no way of auditing the code or process.
This isn't true, since all math of their system is public and available on here: https://www.apple.com/child-safety/pdf/Apple_PSI_System_Secu... But code is as closed as always been. You have same level of trust for iMessage E2EE or even the screen lock of your phone.
Due to the way how system is expected to behave (it only looks existing matches from the provided data, with certain modifications), it is certainly possible that 1/1 trillion false positives is reachable, because they can validate it during development. They are not developing some AI to match totally new wild images. There is human validation, so nothing is automatically triggering police.
This is different from what your comment implies in two ways. First, they do not have an obligation to actively look for CSAM; they only incur an obligation if they find it. Second, the obligation applies to apparent illegal content rather than known illegal content. What qualifies as apparent could end up in court.
https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim...
This isn't that simple. If NCMEC comes with the properties of CSAM (e.g. hashes) and asks provider especially those to be removed from their cloud, it is hard to remove them without looking for them. This is different than an obligation to actively look for CSAM in general.
If NCMEC told a provider that a specific URL (or similarly unique identifier) contains CSAM, the provider would be obligated to destroy the associated file or be guilty of possession/distribution because at that point they know what they have. That's different from NCMEC providing hashes that could identify files the provider may or may not be storing.
Can you describe the two options they had?
Sorry, this was three options.
No form of apologetic or "technical" explanation can remove this from reality now. They are betting heavily on their "core" demographics to trust them automatically and without any form of critical thinking.
If this implementation has no effect on Apples bottom line. Things are over. We will live in badly implemented version of the Minority Report.
Not doing anything anti-consumer that the law doesn't force you to do is "radical"? I know you're not an astroturfer, but I had to double check because this is textbook astroturfing tactics.
Apple simply does not have to do this, as far as I'm concerned it's obvious they're either currying political favors or being incompetent. It's perfectly fine if they want to run it on their own unencrypted devices, they absolutely don't have to overstep into their user's devices.
* Think about what happens to CSAM uploaded to iCloud before NCMEC tags it. This has to happen for each new CSAM, since NCMEC can't tag what it doesn't see yet.
Surely Apple and NCMEC want to be able to catch these perps (which they easily would have with server-side). Doing it client-side requires expansion of scanning to do much more.
- Apple has over a billion devices out there.
- Child abuse is a rare problem, but with over a billion devices, there will be enough of it for a lot of newsworthy stories.
- Child pornography takes just one abused child for an arbitrary number of viewers. Arguably, by the time you're limiting the number of viewers, most of the harm has been done.
On the whole, I'm not quite sure how the Apple plan will protect actual children from rape (except to somewhat reduce the secondary harm of distribution). I can clearly see how it will protect Apple from bad press, though -- people won't use iPhones to record that.
On the other hand, an investment in education, health care, reporting, and enforcement could significantly reduce the amount of child abuse, but with 7 billion people in the world, no expense would bring it to zero. So long as it's not zero, the potential for bad press is there. Indeed, usually if something happens a few times per year, it receives more bad press than if it happens a few times per day.
Apple has every incentive to be (1) seen as doing something (2) do things which protect its brand value. Apple has no incentive to invest in education, health care, reporting, and enforcement. Those seem like good things to do, but if anything, if a scandal comes up, those sorts of things are used to say "See, Apple new, and was trying to buy an out."
As a footnote, if we value all children equally, a lot of this is super-cheap. This is a good movie:
https://en.wikipedia.org/wiki/Born_into_Brothels
And the problem it portrays could probably be solved with the same finances as the salaries of a few Apple engineers, and a focused, targeted effort to identify child prostitutes, help their families with the economics which force those kids to become child prostitutes, and get those kids into schools instead.
I'm guessing the $100k raised from this film will do more to protect kids than this whole Apple initiative will do.
You bring up the distinction between "possession offenses" (i.e., a person who has CSAM content) and "hands-on offenses" (i.e., a person who abuses children and possibly, but not necessarily, produces CSAM). Detecting possession offenses (as Apple's sytem does) has the second-order effect of finding hands-on offenders because hands-on offenders tend to also collect CSAM and form large libraries of it. So finding a CSAM collection is the best way to find a hands-on offender and stop their abuse. Ideally, victims would always disclose their abuse so that the traditional investigatory process could handle it -- but child sexual abuse is special in that offenders are skilled in manipulating children and families in order to avoid detection.
I think that the case of USA v. Rosenchein [0] is a good example because it shows the ins and outs of how the company->NCMEC->law enforcement system tends to work and how it leads to hands-on offenders. It's higher profile than most, perhaps because the defendant (a surgeon), seems to have plenty of resources for fighting the conviction on constitutional grounds (as opposed to actually claiming innocence). But the mechanism leading to the prosecution is by no means exceptional.
Caveat: Not a lawyer.
[0] https://www.anylaw.com/case/usa-v-rosenchein/d-new-mexico/11...
We are citizens of our country and we deserve a dignified existence. We are supposed to have rights, and they're being worn away, formally and informally, by our governments and megacorps acting like NGOs.
I'm sympathetic to the overwhelming horrors of drunks, drunk driving, violent actors, child abuse, child porn, economic crimes, etc.
I've done my calculus, and I got my vaccine and I wear my mask in the current circumstances of our pandemic. But in a similar calculus, what Apple has planned to subject a huge portion of our population to, by din of their marketshare in mobile and messaging. I personally can't accept the forces at play in this Apple decision, and I'm continually baffled by those who think this is overblown.
So what's next? There might be some time left to secure our rights on Mars...
No government, no police, no Wild West "run them out of town" option. You think they're going to want to spend $500,000 return flight cost to send potential criminals away or just "let them be" in an environment like that?
The idea that you might be able to go there and "demand your freedom" without being a billionaire owner of the colony is ill-thought-out. Subjects will have no leverage and no options, and leaders will have billions sunk into it and demand obedience like a Navy Submarine.
However, I'd rather voluntarily subject myself to a dictatorship like that than believe all my life I have rights that are sacred, only to look up and find myself in an authoritarian panopticon.
I do harbor fantasies of some day collaborating on a new system of government, or at least laying the groundwork. It's not going to be Musk's planet forever, and the first generation of Martians will be volunteers who want the project to succeed. Which makes it more like the 13 original colonies than the Wild West.
It's not all hard to find such places. Many children are abused at scale, globally. I think few of those kids are getting filmed or turned in CSAM.
I'm also not at all sold on your claim that hands-on offenders tend to collect CSAM materials either, but we have no way to know.
I am sold on the best way of reducing actual abuse involves some combination of measures such as:
1) Fighting poverty; a huge amount of exploitation is for simple economic reasons; people need to eat
2) Providing social supports, where kids know what's not okay, and have trusted individuals they can report it to
3) Effective enforcement everywhere (not just rich countries)
4) Places for such kids to escape to, which are safe and decent. Kids won't report if the alternative is worse
... and so on. In other words, building out a basic social net for everyone.
We would not accept having breathalyzers in every car.
Or to bring it closer to the child abuse problem: Would we accept cameras that take pictures of the occupants of the car to make sure that the minors in the care are not being trafficked?
lol, that's not up to us. It's in the infrastructure bill.
https://www.mediaite.com/news/infrastructure-bill-could-requ...
"If you want a vision of the future, imagine a boot stamping on a human face - forever." - George Orwell
How long until general computing is given up due to hackers and piracy ala The right to read(https://www.gnu.org/philosophy/right-to-read.html)?
Though requiring the driver to blow into a straw doesn't seem particularly "passive"--whatever that means.
But the text makes it seem like they would position cameras toward your face and do analysis on impairment indicators like eye movement.
Imagine a medical condition that makes it look like you are impaired. Now, you have to go to the dealer with a doctor's note to get this system disabled. Or when you want to rent a car.
Or, if there is a case when driving impaired would be better then the alternative. You and a friend are camping in the woods out of cell range, you both have some beers then one of you trips and gets a deep cut on the leg. Now you have to wait a couple hours before he can drive you to where you can get cell signal, hope you don't bleed out.
So the equivalent is that for every single trip you take, you must prove you are not under the influence.
If you're going to pay to use a hired car, expect to have to show the car hire company sufficient proof that you won't expose them to unnecessary risks. If you're going to pay to use a hired server to store your photos, why shouldn't you demonstrate to the owner that you aren't going to misuse their services or break their terms of service or break the law?
If you want to drive your car on your land, it doesn't need any of that.
So ... this is your hellish dystopia, your "boot stomping on a human face forever", Hertz rent-a-car?
[1] analogous to you using Apple's iCloud servers.
The public roadway, something I don't have a right to, is what I am accessing, just like the iCloud service.
https://www.drive.com.au/news/2008-nissan-gt-r-uses-gps-to-d...
Trucks have tachometers which track drivers aren't driving too long, and are taking sufficient breaks.
> "It will then connect to a DMV database that verifies the information is correct and then to the insurance database to verify coverage."
Wouldn't it be nice to know that if you're in an accident, the other party can't simply say "I'm not insured lol" and drive away and leave you and your insurance to pick up all the costs?
Funny you would bring that up. I think the new infrastructure bill requires that for cars built after 2029 (or some other "future, but not that far" date)
This is the thing that privacy advocates seem to ignore. Measures taken to reduce child abuse won’t reduce the circulation of whatever CASM does get created.
Some even seem to think, a la the ACLU, that viewing child abuse material is a victimless crime, and only the creators of the CASM should be punished.
Just to be clear, I am neither defending nor attacking Apple. I don't even own any Apple devices.
I'm just giving my interpretation of the dynamics behind what is going on.
I'd add that they probably consider the scheme to be better than the alternative (which is how others do it, including Google IIRC), namely checking photos once they have been uploaded. They have gone to some lengths to do more on the device instead of uploading user data, in Siri for example, but also Photos.app face recognition etc.
Privacy isn't a toy for nerds, though. It's not even a luxury item. It's a need and a right of all people. There is a good option: keep people's stuff private. It's the only option.
It's a while since the ruckus about privacy from techie types has penetrated the public discourse, and I think this is a very good thing. The non-tech-savvy people, if anything, overestimate the degree to which their privacy is compromised, convinced that every sound they make within earshot of their phone is scraped for ad targeting.
But not one of the people in my anecdotal dataset change their behavior on this basis, nor even seem to be particularly bothered by it. I don't think you can even chalk this up to technical ignorance. Bush's warrantless wiretapping had something like 40% approval, and that wasn't even transparent or consensual!
It really does appear there are a massive amount of people out there who look at the current cost/benefit tradeoff of compromising their privacy and decide that it's worth it. Awareness is still important, but I don't agree with your suggestion that everyone be effectively coerced into accepting the tradeoffs that you or I accept.
I don't agree with this characterization - it's too willful. To me, it seems more like a helpless coping mechanism. Since they "overestimate the degree to which their privacy is compromised", they resign themselves to not being able to do anything to protect their own privacy. The phone is listening to them, the satellites are tracking them [0], websites are recording them - basically every electronic device they encounter is not under their control. Their privacy is already gone.
Then, they watch TV and see actors using surveillance systems to capture Really Bad People. Since they've already resigned themselves to the collection, the only thing they have left is to hope that said surveillance results in things that are good and just. And when you try to bring up real-world problems, they revert to coping mechanisms of how it doesn't bother them - because if it did, they're still ultimately powerless to change anything.
To cross this divide, I think we need to give people actionable packaged-up solutions they adopt to protect their privacy. Part of the difficulty is that most people use their phone as their primary communication medium, and the phone ecosystem is a privacy dumpster fire. I don't have a recommendation for increasing phone privacy besides LoS+microg and also stop using your phone so much - do most of your communicating from a real computer running Free software.
Incidentally this is why this Apple news is so terrible - they had seemed to plot a course for more user privacy. Even with Apple retaining control, it could have let people see there can be boundaries. But now they've basically thrown away user empowerment in favor of putting a government agent on every phone. And so we're right back to the understanding of "everything I do is surveilled".
[0] I'm obviously describing their perspective. I've tried to explain to people that GPS satellites do not themselves track you, but rather let your phone figure out where you are. And by them taking an interest in the software on their phone, they could prevent it tracking their location. But I generally hit a wall of cognitive dissonance where the "satellite tracking" was really just some talking point, rather than something they think they could prevent.
I don't doubt that some contingent of the market feels this way, but I'm positing the existence of a large section of the market that truly doesn't really care that much about privacy. There's a reason that privacy advocates spend so much time arguing against "if you're doing nothing wrong, privacy doesn't matter", and it's because so many see big institutions (tech cos, banks, gov't) as detached institutions that for the most part do the right thing. It's the same reason that most people don't have a coherent sense of government's monopoly on legitimate violence and coercion: instead of grappling with the nuances and trade-offs of this bargain, it's easier to just model them as "the good guys".
Naturally, I'm going off of my perception here, as there aren't well-defined statistics that would give us a more reliable sense of the attitudes towards privacy that affect (or don't affect) people's purchase decisions. But a high enough proportion of my non-tech-employee acquaintances are unbothered by privacy concerns that I have to at least acknowledge that they likely represent a non-trivial segment of the market.
> they're still ultimately powerless to change anything.
This doesn't comport with my experience with these people. One finds niche cases here and there where the trade-off for privacy/autonomy provides a pretty decent ROI. I've occasionally been asked about some of these decisions of mine. In those conversations, the people I'm talking about don't look at these trade-offs and decide that the effort isn't worth the privacy benefit: they hear that the benefit is privacy and immediately go "oh this isn't relevant to me".
As the guy sitting on the client-side, how about “No”?
This doesn't work because secure enclaves only move trust from the software developer to the hardware manufacturer, who has the code signing keys to update the firmware on the secure enclave. Which in this case would still be Apple, or someone equivalently [un]trustworty and subject to external coercion.
Many other American companies have done business with totalitarian regimes over the years. Maybe there's too much money in that market for Apple to pass up. Given the growth of totalitarian strong men across the world it's probably a growth market these days.
Payment may not be overt. It could also come in the form of access to markets. The deal might be that Apple must demonstrate the ability to help a regime hunt down dissidents before it can sell domestically, or they could be offered a break from otherwise onerous import or sales taxes.
Seems like there is a way after all: https://daringfireball.net/linked/2021/08/09/apple-csam-faq
"Could governments force Apple to add non-CSAM images to the hash list?
Apple will refuse any such demands. Apple’s CSAM detection capability is built solely to detect known CSAM images stored in iCloud Photos that have been identified by experts at NCMEC and other child safety groups. We have faced demands to build and deploy government-mandated changes that degrade the privacy of users before, and have steadfastly refused those demands. We will continue to refuse them in the future. Let us be clear, this technology is limited to detecting CSAM stored in iCloud and we will not accede to any government’s request to expand it."
(Reminder: if you don't trust what they say, you can't trust that they haven't been doing this for years already).
Now I think my next mobile OS is going to be GrapheneOS.
Like others have mentioned, this is as big of a warning as anyone's going to get to get out of that locked-in ecosystem. On that note, the outrage is kind of useless if you don't skip buying the next iPhone. You should fully own what you fully pay for.
A; maybe, I'm not sure what extra that does above LTE.
B; I guess you could get a different phone that doesn't have it, for a little while longer.
B; It's actually a reference to the No Agenda show. https://noagendashow.net
One example to rule them all? Most banking apps refuse to start if you don't have GApps (i.e. SafetyNet). And no, microG does not count as solution.
Why banking apps as example? Because in the EU they are required after the PSD2 directive mandated "strong" auth requirements.
The only alternative they offer is SMS-based 2FA which, unsurprisingly, often has an additional cost.
And my banks still use SMS MFA, so I could login online using a dumber phone.
Anything that completely blocks Play services is a win in my book.
Sweden is pretty much a willingly fully cashless society and you can still function normally without banking mobile apps, or with a stay-at-home-usually-off phone that you can use for bank app when needed, though at that point you can just use the website.
In mine too, however...
Don't banks in Sweden require a mobile app for 2FA?
No. I recently set up an elderly neighbours online banking access. She has a laptop for some clerical work and email, but uses a dumbphone only.
All the bigger banks I have been using offer a hardware device to generate authentication codes. These usually come with some sort of camera (there are multiple systems) that reads a code of the screen and they require a your bank card.
I am sure not all the banks offer this, but it's so much better than some stupid app.
I guess banks suck in my country.
The situation really is unfortunate, though.
A cheap/used tablet is like $50-$100. Put your online banking apps and other surveillance-based-apps on it, and generally leave it at home. Mine has a red label on it that says "Full Take".
You're then free to secure your mobile device with things that will best protect your location and communications, without worrying about lazy/invasive apps complaining.
Also if you get mugged, an attacker can't make you sign into online banking and see that you have a bunch of money sitting in your accounts.
Back when everyone had a single device, trying out Linux used to be such a trepidatious affair because you had to write down all the installation steps, make sure you had the install media in good order, and hope that you'd come out of it with a computer that still booted some OS. These days $20 will get you an independent machine capable of running Linux, and you can tinker to your heart's content without affecting your existing environment.
The protocols and methods that can make the current ecosystem free feel like holdouts from a world that's passed already. I really really wish that the future is not closed, that we can still host our email and websites in 50 years, but when all key players want a closed and surveilled ecosystem, it's hard to imagine that remaining open is not a struggle.
Hence, "for now".
So to the extent that you need to engage with the locked down world, you need a locked down terminal that behaves like everyone else's (to within some margin that they keep trying to shrink). And to the extent you want freedom (computational autonomy), then you need a real computer that lets you run whatever code you want.
If the Internet became locked down to specific protocols, that could be a different story. But the same bifurcation seems to be happening to the network. MITM webapps are going censor-happy and implementing IP blocks and eager captchas, yet it has never been easier to set up a VPS running whatever protocol you want.
I will never forget the time iTunes deleted my music library, or it's inability to deduplicate identical songs.
Power.
Torrent the actual files.
I was so pissed of, i’ve avoided iTunes & Apple Music ever since.
Yup. Same here.
This is why I don't have my large collection of CD's in my phone and just use Pandora.
Going back to iPhone 3 days, iTunes did not allow me to import my CD's into my device and play them as entire CD's.
If I want to listen to Mozart's "Eine kleine Nachtmusik" or Pink Floyd's "The Wall", it's a nightmare. iTunes is song-based, not album based. Well, the above, and many others, are works you pretty much listen to in order as recorded. In some cases (The Wall, Brandenburg Concertos, etc.) the works span multiple CD's.
I stopped using iTunes and storing music on my iPhone because of this. I don't enjoy music the way Apple seems to think you should. I have no clue if they fixed this since iPhone 3 days. I would not be surprised if they have not.
In sharp contrast to this, I have not problem playing single or multi-CD works as intended using Windows Media Player on my desktop, where I have my entire CD collection stored.
This, for me, is the single reason I would instantly jump into a Windows phone if Microsoft got their heads out of their asses, committed to doing a good job and integrated a phone experience with the desktop. They would have to regain my trust, but as a life-long user of both Apple and MS desktop products, I would absolutely welcome a better phone experience than Apple has delivered over the years. I really want to abandon iPhone and go to a good Windows phone, but MS does not seem interested in creating that opportunity.
Oh, yes, and to address iCloud, back in the early days it managed to delete not only whatever I had on iTunes (which I own on CD's so I don't care) but all of my contacts. Thankfully I had my contacts stored in my prior phone (I think it was a Blackberry). After disconnecting from iCloud I entered them manually and never again enabled iCloud all the way up to my current iPhone X.
What could go wrong?
The same kind of problems existed on my Mac, iPhone, and the web UI, but each one had its own set of fucked up metadata.
I had the same music library since iTunes 1.0, moved from one Mac to the next for almost 20 years. I wanted my play counts and the last time I played things and all of the nice metadata that iTunes used to have.
Worst of all, I couldn't restore from a backup because the cloud library becomes the canonical library as soon as you enable it. I tried restoring my library from a backup, but as soon as the cloud library synced, it would screw everything up again. As long as I was offline, my restored backup was in perfect condition.
Apple support was useless of course. They just told me to delete and add my music again. That's thousands of songs, and doing that deletes the metadata I wanted to keep. All I wanted was for them to reset my cloud library as if I'd never synced anything, so my working library could sync up. The only way to do that would be to stop my subscription and then subscribe again.
I spent probably 30 hours trying to fix it but ended up just accepting that my personal metadata was gone, other than existing on the last working backup. Doing what Apple support suggested was not reliable either. Deleting music in one UI had unpredictable effects in another. Adding the music I own, ripped from CDs, failed often when Apple tried to match it and then get the various libraries in sync. I had to remove and import some albums 3 or 4 times before it was consistent across devices and the web UI.
My library is still fucked in a lot of ways, but the music I want to hear most often is mostly there.
The thing that prevents me from just going back to syncing to my phone is that some music is only available from their music subscription, and that can't be synced over a wire.
They're also the only streaming service that will actually upload music it can't match. I'd move to Tidal or Spotify or somewhere else if any of them offered that. I want to be able to hear my obscure music in the same app as I use for big label music.
Rant over, back to work.
But i tend to be cloud adverse. So my library is on a NAS.
When my mac mini blew it up, i had to restore my entire music library. Then every single file could not be found..So I deleted the entire itunes library (which deleted the music folder structure, i thought i told it not too, but it could have been my fault). So i restored the directory structure again, and then had to re-import and rebuild the library.
All playlists were gone. Play counts, favorites, checked songs (because itunes loves to convert things and make duplicates) were gone and needing to be redone.
And now it seems it wont recognize flaac files anyhow.
I have been meaning to setup something like Navidrome and be done with it but i dont really like the thought of another self hosted server.
"You’re going to find a way to do this or we’re going to do this for you. We’re not going to live in a world where a bunch of child abusers have a safe haven to practice their craft. Period. End of discussion." - Sen. Lindsey Graham
The system they recently announced is a step forward from how they currently do it. https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-...
https://nakedsecurity.sophos.com/2020/01/09/apples-scanning-...
This is about the new PSI system:
https://www.apple.com/child-safety/
In which photos are scanned on the users device. This appears to be a report of a new press conference after the initial announcement? Does anyone have a transcript of this press conference?
I do not want AI making such decisions affecting humans. No matter how good it is. I also don't want John from Apple looking at my profile and assigning me a score on a scale of 1-10 of how "pedo" am likely to actually be.
What I actually want is for people to stop thinking that technology will solve every human problem we have.
You have to be either naive, conceited or just lazy (avoiding the real work) to actually believe this is possible.
Your phone will backup when charging overnight on the same WiFi network as your designated backup Mac/PC. The backup files are encrypted with a different password chosen when you set it up so it doesn't rely on only keeping your backup computer secure.
Even if they did, you then have the chance of the user forgetting the password they used to encrypt the data, simply because you only need the password when you a) want to change the password b) use a local backup.
Side note - doesn't really have nothing to do with backups :-P: When I took my phone in for a battery swap (Apple did it for free so I didn't botrher replacing it myself) they asked if I had backed up my phone as there was a small tiny chance they would have to wipe the phone. I said I had. When they were booking it into the system the person booking it in questioned me on the backup because his software wasn't showing a backup. The person booking it in was looking for iCloud backups.
But it's pretty basic, unfortunately. If Apple would just spend a bit more effort, running iPhone backups to your mac via Wifi regularly would be totally viable. It still is, but not's not very convenient.
For example, I cannot exclude certain categories from these backups. I'd like to exclude photos, since they are already on my computer and I don't want needless duplicates of them. Same with e.g. downloaded podcast episodes. Similarly, it seems like I can't backup my contacts, since those are already in iCloud.
https://www.reddit.com/r/applehelp/comments/i936ov/how_to_ex...
The biggest iPhone is 256 GB. Hard drive space is cheap. Very cheap. So cheap that I would rather backup programs stopped trying to be so clever to save me space. Or allowing me to be that clever.
What about injecting code into a public website to download same pic into local browser cache without user’s knowledge?
The simplicity of the attack vectors here that would trigger the “manual” investigation is just dumbfounding and ripe for abuse/misuse.
It's an abomination that will destroy innocent people. The engineers behind this no doubt think it's fool-proof because they believe they're leagues smarter than any of those pesky naysayers ("hey, we're Apple").
If we've learned anything about Apple this year (as if we needed the reminder) is that their software is nowhere close to as flawless as they seem to think it is.
Combined with the unpatched remote-root-via-phone-number disclosed in the Pegasus leak this boils down to a single-click "destroy this person's life" tool.
Like when they arrested & charged someone for a poor facial recognition match that never had a hope of passing human review? [0] Just glancing at the original photo would have stopped that. Or checking his rock-solid alibi. Neither of those things happened.
[0] https://www.wired.com/story/flawed-facial-recognition-system...
In this example as well on iCloud shared galleries you can upload to other people’s ones you have been invited to. What could possibly go wrong?
I really think that the HN crowd is having a giant knee-jerk reaction to all of this.
Also people have a habit of 'forgetting' about it later. Until stories of how it is misused are found. And then it's another attack vector we need to be conscious of.
Revenue tax? Have to pay for that expensive WWI war effort, you understand? For all the good it did.
Same with the VAT. Have to rebuild after WWII, you understand.
We also have an "Exceptional and Temporary Contribution" (CET), recently renamed to "Technical Equilibrium Contribution" (still CET. Smart one, that one).
A funny one, for a change?
When the Germans invaded in WWII, they changed France's timezone to theirs. After the war, we still called it "the German time". There were talks of going back for a few years…
Guess who still has noon at 2pm in the summer, decades later?
Change, no matter how ridiculously small or sensical, even when nobody benefits from the status quo (ie the damn timezone) is horrendously difficult.
Thus one should always assume that once it’s here, whatever "it" is, it’s here to stay.
https://www.kansascity.com/news/special-reports/article23820...
You would think money would go into the "backend": caring for kids where the state is responsible for everything BEFORE more money goes into the frontend: finding more kids to throw into the hellhole that is child services.
Without the "backend" being in order and working well, raising well-educated, stable kids, the frontend is completely immoral. "Saving" kids from abuse, only to throw them into a slightly different kind of abuse ... if any person did that (e.g. a guy marrying a woman (or I guess vice-versa) with that resulting in that person abusing their new spouse's kids) would be considered a despicable crime. Somehow child services, who do the exact same thing (and they use violence to do it) is not a despicable crime.
Somehow just because the state does it, makes such things all a-okay.
But frankly this is merely the hole in the justification, all this should merely tell you one thing: any government that doesn't work hard to fix the child services backend does not have children's interests at heart when making these sorts of laws (and mostly they're making budget cuts in the backend, of course). Because fundamentally these laws throw children into the child services system. THAT is the real effect these efforts have on the actual children behind this. THAT is what is meant by "saving kids".
And if that system is full of abuse, how is that any better than what paedophiles do? It's not.
Which means the state is not attempting to help abused or disadvantaged children. In fact, they're doing the opposite.
This is amazing
Just an example. During a heatwave some summer over a decade ago, many elderly people died.
So what did the government do? They instituted a "day of solidarity", of course!
What does it mean? If you are salaried, then you get to work an extra day, during a holiday of your company’s choosing, and not be paid. The day’s salary will go to a public fund dedicated to helping promote the autonomy of elderly people. And your employer gets an extra day of employees supposedly producing value out of it.
Many people instead take the day, either on their paid leave or their Work Time Reduction days (RTT).
That’s on top of all the other social "contributions" (sounds better than taxes), of course.
Payslips used to be quite funny to decipher[1][2]. They’ve simplified those a bit since then; mostly by regrouping items[3].
[1]: http://cdn-s-www.ledauphine.com/images/F9FED7FA-778E-40CA-8F...
[2]: https://cap.img.pmdstatic.net/scale/http.3A.2F.2Fprd2-bone-i...
[3]: http://s-www.ledauphine.com/images/39A7BC0B-D6E2-456D-800D-5...
This is the type of dramatic over-the-top reaction that I'm talking about.
The only reason to do this clientside when the data is already readable on the server is to do it to images that aren't hitting the cloud.
You don't know that.
> The only reason to do this clientside when the data is already readable on the server is to do it to images that aren't hitting the cloud.
Or to eventually e2e encrypt all of iCloud. Or because Apple doesn't want to decrypt images server-side if they don't have to. Etc.
But the point is that currently, only photos that will be uploaded to iCloud Photo Library will be scanned. Making definitive points about possible future scenarios isn't particularly insightful, especially because the current system isn't much of a precondition of those scenarios.
Apple has made 3 announcements and released one research paper and held a press conference. Now we have to reconstruct what is likely going to be the truth from their carefully crafted statements.
The rest of my points still stand.
Clientside scanning will happen even without iCloud. Apple expects and pressures all users to use iCloud, defaults it to on without interaction or consent, and does not test the non-iCloud paths very well. You can't even setup a homepod to be a simple wifi speaker without iCloud.
Again, you don't know that. "Scanning" (whatever that even means) non-iCloud photos would be completely pointless.
And you said:
> The only reason to do this clientside when the data is already readable on the server is to do it to images that aren't hitting the cloud.
Again, you don't know that at all. You present your speculation as the "only reason" with no knowledge at all.
This is just a great point for if anyone is going to do anything. Apple is going to start scanning my phone looking for reasons to put me in jail. I don't want my phone's CPU time spent looking for reasons to imprison me and I don't want to be funding it either. This system will make mistakes.
[1] I seem to remember that RIM (of Blackberry fame) made devices which used combined radio and systems firmware so those would be an exception to this rule
I don't use any proprietary apps and only install them from fdroid or build them myself.
But if you do, you're going to have a different experience. Let's say you want to run Whatsapp. From what I can tell you basically have three options:
1) Install google apps.
When you install your rom you will also download a gapps bundle and install it. This will be a very vanilla android experience but with the ability to uninstall whatever you want, root, etc. You can open the play store and install Whatsapp. Everything should work OOTB. However you're running all of the google service including google play services, so privacy-wise this is not significantly different than stock android.
2) Install microg
When you install your rom you can also install microg. This is an install time option in Calyxos. Microg replaces many of the google apis. You can install Whatsapp through Aurora store, which can install apps from the play store. Whatsapp will use the microg FCM implementation. FCM is google's notification service. It allows your phone to make a single persistent connection to receive notifications, allowing for better battery efficiency b/c you don't have many apps activating the radio. FCM just communicates that an app has a notification, it doesn't carry the contents of the message. Unlike play services, microg registers the FCM connection with an anonymous.
So google knows your device is running whatsapp and when you get notifications, but not what they are.
3) No gapps / no microg
Don't do either of the above. You won't get push notifications with whatsapp. Many free/libre apps have alternative notification schemes involving separate persistent connections. This is less power efficient but works without involving google. I use Signal and Element like this and my battery still lasts >24 hours.
Several developments
From the f-droid store I use a ton of apps, games, mostly utilities. For navigation I like Organic Maps.
[1] "GrapheneOS vs CalyxOS ULTIMATE COMPARISON (Battery & Speed Ft. Stock Android & iPhone)", https://www.youtube.com/watch?v=7iS4leau088
lineageos and calyxos should as well, unless you opt-in. I guess they would still use the google captive portal detection? Is that what you're referring to?
> and is additionally hardened down to its memory allocation implementation
That's really interesting. Do you use GrapheneOS? Is it easy to lock the bootloader on Pixel devices?
They also pay Qualcomm more so you can re-lock the bootloader.
The Pinephone is great but it's most appropriate for developers interested in linux phones at this time.
Guess what?
Everyday people who didn't want to become informants:
https://www.cnn.com/2014/09/11/opinion/hu-shamas-no-fly-list...
https://www.nytimes.com/2020/02/24/us/supreme-court-case-no-...
https://ccrjustice.org/home/press-center/press-releases/laws...
>The lawsuit is brought on behalf of four American Muslim men with no criminal records who were approached by the FBI in an effort to recruit them as informants. Some of our clients found themselves on the No Fly List after refusing to spy for the FBI, and were then told by the FBI that they could get off the List if they agreed to become informants. Our other clients were approached by the FBI shortly after finding themselves unable to fly and were told that they would be removed from the List if they consented to work for the FBI.
Journalists
https://www.cnn.com/2008/US/07/17/watchlist.chertoff/index.h...
>A House representative said Thursday she is requesting an investigation after learning a CNN reporter was put on the federal no-fly list shortly after his investigation of the Transportation Security Administration.
Whistleblowers
https://www.latimes.com/archives/la-xpm-2010-apr-27-la-oe-ra...
https://whistleblower.org/in-the-news/buffalo-news-governmen...
>In my case, I started having trouble flying after I blew the whistle in the case of “American Taliban” John Walker Lindh, the first terrorism prosecution in the United States after Sept. 11. As the Justice Department ethics attorney in that case, I inadvertently learned that my e-mail records had been requested by the court. When I tried to comply, I found that the e-mails, which concluded that the FBI committed an ethics violation during its interrogation of Lindh, had been purged from the file. I managed to recover them from the bowels of my computer archives, gave them to my boss and resigned. I also took home copies in case they “disappeared” again. Eventually, in accordance with the Whistleblower Protection Act, I turned them over to the media when it became evident that the Justice Department withheld them from the court.
For more sensitive materials back up when the data changes and store in a disaster proof safe.
I think the fear of losing things is a problem. People take so many photos anyway and who even looks at all of them? Memories are great and we should cherish them but… this is one of those cases where folks don’t need to rely on big tech.
iCloud was just the start, it wasn't the end.
Could you elaborate? Totally unclear to me what kind of attack you're talking about.
This seems... implausibly convoluted. If you have full remote control of someone's phone, Apple or not, you could do all sorts of incriminating things "as them", and I don't think Apple's new system noticeably increases your risk from this.
It would take the flick of a switch for someone to ruin your life for a crime you could never explain yourself out of. Nobody will ever believe that you were framed because that means other convicted predators could also have been framed. As soon as your name hits an index-able news article, guilty or not, your life is over.
This is a blackmail machine.
I'm just saying that actually getting the attention of authorities is the most trivial part of this suggested attack. Apple's new stuff is a vector for that, sure, but anyone who is in a position to exploit it could easily do so in other ways as well.
I’ve been on the verge of doing this for a few years so had my exit strategy well planned.
No, that's not how the Apple's system works.
- Apple: “Backup your phone to iCloud, it will be safe there.”
- 5 minutes later: “We’ve wiped your account because of a photos of (porn actor here) which is not CP but technically minor at the time she filmed.”
- “Also we’ve wiped your iPhone because we couldn’t knowingly let you keep that. Good luck contacting your parents, we’ve deleted your contacts. Good luck! PS: We’ve reported you to the police.”
- Also you can’t connect to your iMac now.
We have a Tumblr set up for family to view pics of the kids. Several photos and videos of our kids when they were under 2 were taken down either temporarily or permanently by their CP algo.
These were a pic or video of kids in the bath or without a shirt. In none of them could you see bum or bits. Just a semi naked baby.
Algorithms like this get things wrong all the time
How could this be the case? If it's been determined to be CSAM then it is, by definition, illegal.
If it were true that the database is likely to contain legal material, how would we possibly know about it, given that the contents of the database are secret?
Certain images are CSAM by _context_. They do not necessarily require those within the image to be abused, but rather that the image at one time or another was traded alongside other CSAM.
> If it were true that the database is likely to contain legal material, how would we possibly know about it, given that the contents of the database are secret?
Tools like Spotlight [0] make use of the database, so certain well-known images are known to flag. Such as Nirvana's controversial cover for Nevermind.
[0] https://www.wired.com/story/how-facial-recognition-fighting-...
At the risk of sounding like a broken record, how can we know this is actually true? Every description of the NCMEC database's contents that I've seen is incredibly vague, and as of 2019 it seems like there were fewer than[1] 4 million total hashes available. I would think that if it genuinely did include innocent photos of people's kids, the number would be much higher.
> ...certain well-known images are known to flag. Such as Nirvana's controversial cover for Nevermind.
I've heard this multiples times now, but I've never been able to find any evidence of it actually happening. The only instance I could find was one where Facebook removed[2] that Nirvana cover once for containing nudity.
1. https://inews.co.uk/news/technology/uk-us-collaborate-crack-...
2. https://www.theguardian.com/music/2011/jul/28/facebook-nirva...
Remember, this isn't a porn detector strapped to a child detector.
Step 2: Manipulate pictures so that hash collides with CSAM
Step 3: Get pictures back on targets phone so they get scanned.
I don't have the skills or understanding of how the hashes are created but would this be possible?
• has an iPhone;
• has children;
• took photos of their children which could be mistaken for CSAM by a sloppy reviewer;
• is of sufficiently high importance to justify the effort.
And after that insane effort, all you've done is inconvenience your target for a little while until child safety people investigate your family situation and discover that the photos which got flagged were not actually CSAM.
Immediately after the investigation process discovers the hash fraud, Apple will immediately start delving into exactly how their hash algorithm failed in this instance, improving it to mitigate this exploit. So this target better be worth it!
If this was a plausible exploit, surely it would have already happened to people with Android phones since Google has been doing pretty much the exact same scanning of customer images for over five years. (The only difference with what Apple is now doing is where the hashing is performed—but this makes no functional difference to the viability of your hypothetical exploit.)
[1]: https://www.hackerfactor.com/blog/index.php?/archives/929-On...
[0] https://natmchugh.blogspot.com/2014/11/three-way-md5-collisi...
What you are describing is a second preimage attack-- creating a second input with the same hash as a target.
There is no currently known tractable way to create second preimages for MD5.
Obviously nobody should be using MD5, but it can be useful to understand there are circumstances where it's basically reliable unless you have an extremely sophisticated attacker.
Even though the author says they were 3 million MD5 hashes the second time, the first one he calls them SHA1 and MD5 hashes (even though SHA1 is considered weak too).
I wonder what kind of hashes Apple is planning to use. Will it be whatever is made available to them or will they only accept (what is now considered) secure standards?
Regardless, it's not both. Setting aside how the algorithm was created, it's incorrect to say that an algorithm "created with ML" is itself an ML algorithm.
NeuralHash was so named because it was optimised to run on the Apple Neural Engine for the sake of speed and power efficiency.
The image is not fed directly into the hashing function, like taking an MD5 hash of a file or something.
Rather, the image is first evaluated by a neural net that looks at specific visual details, and has been trained to match even if the image has been cropped or anything like that. The results of the neural net evaluation are what is then input for the hashing function.
This is explained in detail in Apple’s documentation they released with the announcement.
Hash collisions would fail human review. About the only consequence I can think of for hash collisions is that the person at Apple who performs the human review step has a slightly nicer day because they were about to look at an image... and then it wasn't CSAM.
The whitepapers provided by Apple do not say what the human reviews consists of. They could just look at the hashes to make sure there isn‘t a bug in their system.
At minimum what we know is that each flagged image generates a "safety voucher" which consists of metadata, plus a low-resolution greyscale version of the image. The human review process involves viewing the metadata and thumbnail content enclosed in each safety voucher which cumulatively caused that account to be flagged.
From Apple's FAQ:
Will CSAM detection in iCloud Photos falsely flag innocent people to law enforcement?
No. The system is designed to be very accurate, and the likelihood that the system would incorrectly flag any given account is less than one in one trillion per year. In addition, any time an account is flagged by the system, Apple conducts human review before making a report to NCMEC. As a result, system errors or attacks will not result in innocent people being reported to NCMEC.
I truly wish I could subscribe to this optimistic view. Experience tends to show this to be unlikely.
Two factors combine against it: 1. There is no negative consequence for a mis-flag (to the reviewer) 2. This set up is a tool, and like many tools, inventive humans will find a way to subvert it in the name of convenience. I am referring to NSLs from U.S. Patriot Act as an example. Since CSAM is such a toxic thing (let's stipulate that CSAM itself is unequivocally bad), there is less tendency to examine it closely for, well, CSAM-ness.
For the sake of argument, let's assume you're correct and Apple's review team are lazy shits who don't look at the images. Okay, so Apple then sends the report onto NCMEC. What are they going to do when they open the report and it turned out the images Apple reported were hash collisions?
And since “depiction” includes drawing, any consumer of Hentai (s. manga) is hosting what passes legally as clear child porn.
I wouldn’t be surprised if 25% of the youth could be taken to jail according to the law, so, definitely, a learning period or warnings are required.
It’s akin to all the US adults who are registered as sex offenders because they peed in a park at night. Apple is clearly help with law abuse here.
It doesn't take long to find those cases.
[0] https://www.nevadaappeal.com/news/2021/mar/21/public-urinati...
[1] https://law.justia.com/cases/california/supreme-court/3d/10/...
This isn't a porn detector strapped to a child detector.
The only argument left missing here is 'you have nothing to hide anyway, right?'.
I would be able to accept an inferior OS incapable of true multitasking and with very limited options to set. Closed system with no sideloading. I would even accept a lousy zoom on flagships cameras compared to, well, any competition. Proprietary connection port. Mediocre battery life. Overpriced accessories. But start removing security, and that's one step too far.
The picture can look normal to the human eye, but if it contains hidden content (in the least significant bit of each pixel for example so that the hash is unchanged), a forensic software will definitely notice, raise some flags, and extract the hidden offensive content automatically, leaving the human reviewer no other choice but to report you.
If Apple says they are not going to look for hidden content, then they are just handling a free pass which render the whole scanning thing pointless.
Apple have explicitly said that their hash algorithm is only concerned with visible elements of the image.
Traffickers and consumers of CSAM know that their content is illegal to possess and store so they sometime use steganography software to store the offensive data inside their innocuous photo library. This way when they can browse their private collection via the lens of the steganography software and they don't have some suspicious encrypted file that would attract attention of someone they share the computer with.
First you generate an innocuous image that has a bad hash collision. (This is easy because perceptual hash are not cryptographically secure). Then in a second step you hide some offensive content in it via steganography without changing the hash. Then you send the image to the target.
He stores it in his cloud, it gets flagged because of the hash collision, so it get a manual review. The manual review take the image through some forensic software, which will catch the steganography (because the attacker will have chosen a weak scheme) which will reveal the hidden offensive content and then report you.
But since a human should look at it should have enough details to distinguish subtle cases like the age of the people in the picture, otherwise it's even more concerning.
If some human has enough info to make this call then the low-res greyscale visual derivative should still raise some flags if it get through a forensic software, as steganography software usually offer some resistance against usual compression artifacts.
Allow me to be hypothetical for a moment; let's assume for a moment that the image has all chroma data stripped, it's downsampled to 1 megapixel, and then compressed to around 100 kilobytes using JPEG or HEIC. That would be sufficient for performing careful human review but would completely demolish any steganography.
> Hash collisions would fail human review.
This (pervasive, over the past couple days) idea that Apple (of all major tech companies, lol!) will be capable of manually reviewing tens of thousands of automated detections per day is... nuts.The "system as described by Apple" doesn't comport to reality, because it relies on human review. If you remove the human review, the system is fucked.
But no company on the planet has the capability to sanely and ethically (to say nothing of competently or effectively) conduct such review, at the scale of iOS.
In addition, consider how monumentally unlikely it is for any CSAM enthusiast to copy these illicit photos into their phone's general camera roll alongside pictures of their family and dog. This is only going to catch the stupidest and sloppiest CSAM enthusiast.
That summary number also includes accusations of child sex trafficking and online enticement. I wouldn't be surprised if reported allegations of trafficking and enticement were in excess of 99.9% of Facebook's reporting. But since they don't break it out, I can only guess.
Given that guesses aren't useful to anyone, it would be interesting if you know of any statistics from any of the major tech vendors, of the reporting frequency of just CSAM hash matches.
The majority part:
https://twitter.com/alexstamos/status/1424017125736280074
> The vast majority of Facebook NCMEC reports are hits for known CSAM using a couple of different perceptual fingerprints using both NCMEC's and FB's own hash banks.
Just admit you are wrong and leave it at that without continuing to try to put a false light on this.
Assuming that number is correct, it means there are orders of magnitude more reports than there are entries in the CSAM database. So even if I conceded that Facebook were reporting over 10 million CSAM images, how many distinct images does this represent? More than four? We have no idea.
How many of those four were actually illegal? Remember, there's a Venn diagram of CSAM and illegal. A non-sexual, non-nude photograph of a child about to be abused is CSAM but not illegal.
This is a serious topic; you don't seem to be taking it seriously.
"21.4 million of these reports were from Electronic Service Providers that report instances of apparent child sexual abuse material that they become aware of on their systems."
So those 20M seems to be images that Facebook looked at and determined to be CP. Apple's system is about comparing hashes against already known CP.
For the record: I don't support Apple's system here, but it's not the same kind of detection at all. Let's try to not make up random facts.
If you think that this is 20 million people mashing the report button, that is almost certainly wrong
> The vast majority of Facebook NCMEC reports are hits for known CSAM using a couple of different perceptual fingerprints using both NCMEC's and FB's own hash banks.
I don't know about anyone else but I've never had any issue with regular porn sloppily falling into my camera roll. And that's just regular legal porn. Maybe I'm more diligent than others but regardless, it's just not something that happens to me.
Being sloppy with material which you know is illegal? Material which, if stumbled upon by a loved one, could utterly ruin your life whether or not authorities are notified? Material which (I optimistically assume) is difficult to acquire and you'd know to guard with the most extreme trepidation? We're seriously expecting tens of thousands of CSAM enthusiasts to be sloppy with their deepest personal secret and have this stuff casually fall into their camera roll?
I'm not buying that.
I don't believe any of the information they've released thus far, gives any actual detail about what that derived image actually is.
One might guess it's a significantly detail-reduced version of the original image, that they would compare against the detail-reduced image that is able to be generated from the matching hash in the CSAM database.
So any photo sent to you would be scanned. If you someone sent you a bunch of files, that might trigger a manual review, that would most likely flag your account.
I wouldn't expect that immediately deleting them would stop the review process.
You mean like the absolutely perfect human review of appstore content that's known for both false positives and false negatives?
Neither automatic nor manual (human) review works 100% reliably. And believing otherwise will only ruin lives.
I would like to believe though that for this system to fully fail an innocent person, the following would all need to have failed:
1) Coincidental CSAM hash collision 2) Incorrect manual review by Apple 3) Incorrect subsequent review by NCMEC 4) Inability of a lawyer to obtain the original image for presentation during a trial/appeal
which seems kind of unlikely? (although it's certainly the case that once steps 1, 2 and 3 have failed, the person's reputation is likely damaged even if they are able to prove their innocence in court).
The wider question here is, should 100% accuracy be the bar by which we judge this? I don't think we expect the law enforcement system to be 100% right, hence principles like the presumption of innocence and right to appeal, and even then it gets things wrong sometimes.
And all this is assuming it will never be expanded from CSAM to other content. Apple is already rolling out a censored version of iOS in China.
[0] https://www.vice.com/en/article/qj8xbq/police-are-telling-sh...
Step 1: Get copies of pictures of targets kid in bath from phone/SNS
Step 2: Manipulate pictures so that hash collides with CSAM
Step 3: Get pictures back on targets phone so they get scanned.
If it were me, I would try and get a series of photos from the target, and manipulate several that look most borderline. That way it looks like more than a one off.
Now if there is an Apple review, the person who views them will see some suspect pictures and would confirm.
Now the target would have to get someone to review the original pictures vs the modified pictures. Good luck with the defense.
What you've described is pretty much the scariest thing I can imagine as far as computer crime goes.
Having 3rd party apps that have access to the photo album being able to do that makes it a bit risky to have iCloud.
> The executives acknowledged that a user could be implicated by malicious actors who win control of a device and remotely install known child abuse material. But they said they expected any such attacks to be very rare and that in any case a review would then look for other signs of criminal hacking.
What triggers them to look for signs of criminal hacking?
Does every manual review process involve such checks?
Are they searching device backups for indicators of compromise [IoC]?
What if there's no device backup or device image to scan?
What if the scan fails to notice IoC?
What if the device was compromised after the last backup?
What if the device was compromised via physical access?
What if the device isn't compromised and the material was pushed maliciously or via drive-by download?
It's dangerous to assume that all material on a network-connected device arrived with the consent of the user when it can accept incoming messages from strangers, trick people into downloading files, or be compromised without your knowledge.
“That isn't mine” is going to be a tough defence if you can't even take measures to log where content came from.
Client-side scanning seems to amplify this issue (which could still happen with cloud storage) because at least cloud storage doesn't generally ship with or integrate deeply with messaging apps, social media, a web browser, QR codes, App Clip Codes[1] etc.
The impact might be fairly low right now with the current proposal (images would have to be uploaded to iCloud, so cached browser images don't get scanned as far as we know), but the existence of the non-consensual scan in the first place is worrying, because it means such attacks are only a policy change away.
[1] : https://developer.apple.com/design/human-interface-guideline...
Since Google has been scanning your account for kiddie porn for the past decade, wouldn't this apply equally to Google accounts?
>a man [was] arrested on child pornography charges, after Google tipped off authorities about illegal images found in the Houston suspect's Gmail account
https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le...
All people have to do is email you kiddie porn and Google will have you arrested?
Since Google is saving a history of what you purchase from third party merchants by scraping invoices and receipts sent to you through your Gmail account, it's safe to say that they are scanning your emails.
In the case you linked to the person was reported for sending email to a friend with attached CSAM, not for receiving it.[1]
Apple's system scans images client-side if they're due to be uploaded to iCloud. That process can happen without user consent or action. For example, WhatsApp and other messaging apps save images to photos, which are auto-synced to iCloud. (If you use WhatsApp and iCloud you'll find your Photos section full of memes from WhatsApp group chats when you log in at icloud.com, for example. This was a surprise to me at first.)
So the risk of malice seems higher with Apple's system than with the long-running PhotoDNA implementations backing Gmail/Google Drive/OneDrive etc.
Gaining access to someone's email and sending attached CSAM is likely to cause them more issues than receiving it. But that's harder because you need their login info and not just their email address/phone number, which is all that an attacker potentially requires to trigger action from Apple's automated scans.
[1]: https://nakedsecurity.sophos.com/2014/07/31/google-tips-off-...
> The investigation was apparently sparked by a tip-off sent by Google to the National Center for Missing and Exploited Children, after explicit images of a child were detected in an email he was sending.
I was trying to figure out a way, but got side tracked on the issue, then my phone got stolen and I lost a bunch of family/baby pictures (thanks Google/apple).
Settings → Chats → Save to Camera Roll
Not sure about other messaging apps.
Is there some reason to imagine the person sending the message couldn't do so with burner email accounts or by abusing open/vulnerable email servers?
Has Google suddenly prevented spam from landing in your spam folder without anyone noticing?
It's much simpler to send email than it is to take control of someone's device.
Apple’s approach does not seem to provide the same safeguard. Your account will be flagged for review if there are n flagged images destined for upload on your device. The description of the process does not mention if or how provenance or intent to receive those images is established.
Anyone with your credentials to social media/any cloud service like gmail could send CP on your behalf to get you flagged and interrogated.
Good luck mounting a defense against a subject this taboo. Even if you win it will follow you forever.
(In the virus case, they also do a second scan when you open the message - with updated virus definitions to catch new viruses).
Very rarely will your life be completely ruined based on inaccurate information.
It's not a defense at all. This material is prosecuted under a "strict liability." It doesn't matter how you got it, you're liable.
You're overselling it.
First, there is a statutory affirmative defense: if I obtain CSAM and "promptly and in good faith" delete it or report what happened to law enforcement, liability does not attach.
Additionally, federal laws are clear that you have to knowingly receive CSAM. That's not just a legal flourish or a word – knowledge is an element that a jury or judge will rule on. If I ask you to send me an illegal video and you do, we've both knowingly violated federal law. If you send me to a webpage that purports to offer me a job, but actually has images hidden with CSS to poison my cache, I've not knowingly received anything.
And yet, i never want to be in this court case at all.
She was found guilty of "possessing an indecent image of a child". [1] She tried to argue that she hadn't noticed the message, but it's not surprising that wasn't believed given that she had immediately replied to her sister saying "please call". She was sentenced to 200 hours community service, and originally sacked from her job but recently reinstated after appealing. [2]
It seems that she wasn't immediately in trouble when she received the message ... so long as she had immediately reported her own sister for distributing it, even though it's clear that she hadn't deliberately done anything wrong. (In fact the sister had contacted her to ask what she should do about it. Probably her answer was "don't have already sent it me!")
To be fair, this is partially because the laws in the UK are, I think, fairly bonkers strict about CSAM - mere possession, whether you've looked at it or not, whether you downloaded it or not, whether you even know it's there or not, etc., is counted as criminal.
> At the same time, because of the First Amendment, child pornography offenses are not "strict liability" crimes like statutory rape: in order to convict a defendant, the government must prove that the defendant knew the material involved the actual abuse of a child
https://www.zmolaw.com/child-pornography-faqs#
I've found similar claims on the websites of a few law offices. For some reason, the official DoJ materials are pretty cagey on the topic.
That varies by jurisdiction. Some US states require criminal negligence or offer affirmative defenses with regard to the defendant's belief as to the victim's age.
I think its surprising that society does not want to talk about CP and just content locking up whoever they find and throwing away the key. Pretty shambolic response for something so common - no offense but we spend way too much time and resources undoubtedly useless social issues instead if hard questions like CP and what causes it. Even the academic literature is sparse but I would argue we need more people finding answers and we might learn something about the human condition - rather than putting so much money and intellectual capital on crap like cyber bullying or transgender pronouns or mental health. Not that those aren't important but they are low hanging fruit. We need to get our priorities straight. Tackle the hard questions instead of this absurd head in the sand approach to uncomfortable topics. FFS.
Rant over
https://www.bbc.co.uk/news/uk-england-london-58072822
This is another instance:
(It's a pity your comment was downvoted when it was the only meaningful reply. As always, we'll never know why. Maybe the downvoters didn't get the sarcasm. Or maybe they think handing your sister to the police when she asks for your help is the right thing to do...)
You are talking like collisions are trivial to make. I bet they have had a deep conversations in this area. At first, you would need a real hash to even try (which are hidden). Secondly, to get real material it means that it must be in their database to trigger anything. This tells a lot from sender already, and is worth to tell for police. It is quite easy to prove that someone just send it to you. And one photo is not triggering anything. Besides, sender must know that those photos must go automatically into the cloud to mean anything.
> What about injecting code into a public website to download same pic into local browser cache without user’s knowledge?
At least US legistlation is precise that user must willingly obtain/download CSAM material, and it must be proved. So this is not harmful for the user in the end.
A lot of speculation, but does not really lead for coencequences. Almost every system can be tried to be abused, but does it really mean something, is different story.
Except that a trial, even with an innocent verdict will SUCK and have terrible news stories about you and poison any google search for you with CSAM stories
Step 2: Manipulate pictures so that hash collides with CSAM
Step 3: Get pictures back on targets phone so they get scanned.
I don't have the skills or understanding of how the hashes are created but would this be possible?
>At first, you would need a real hash to even try (which are hidden).
How are the hashes hidden? It looks like they are shared: https://www.thorn.org/reporting-child-sexual-abuse-content-s...
These hashes are not generated by Apple and are not valid. (Must be generated by their new system) They are probably very strictly guarded.
They will be stored on every iOS from 15 version, somehow securely. This must limit the support of older iPhones.
The experience is not that bad. In-app purchases aren't working, GPay doesn't work either. And the camera is, well, bad. Apart of that everything seems to be smooth and fine.
Try it and donate the iPhone price difference to Calyx Institution.
You don't even have to give up on your old iPhone and update its OS.
Apple is - rightfully and understandably IMO - criticized for their plans, but does anyone know how Google handles this?
The false positive rate does not look great.
Instead of scanning you whole library they came up with a way to do it on device, which is the main difference between other services. If you don't enable iCloud photo storage the system can't work at all.
Very interesting stuff in their technical explanation: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
-Facebook's reporting overwhelmingly flags burner accounts signed up via tor etc, only absolute idiots would post actual CP on their real name account on facebook.
-Apples solution is highly invasive and dangerous, and your statement about "only running with iCloud upload" is false. It took less than a week for Apple to announce that they will open these APIs to 3rd party apps.
That just means they are allowing other apps to scan for CP if they want to (or if they are required to by law). As controversial as it may be, I would trust Apple's implementation way more than I would trust a random photo editor app's implementation.
Easiest thing is not to worry about that and just use the services as normal. You’d have to trigger the system multiple times before there was even a chance of having police involved and even then there’d be no actual evidence if you don’t have that content.
I have some respect for privacy absolutists that want to go down that path on principal but it sounds like a massive pain in the ass with no upside for most people.
If you support Apple on this, you support totalitarianism.
You want Google, for example, to hold false positive data on their servers forever where it can be subpoenaed and misused?
>Innocent man, 23, sues Arizona police for $1.5million after being arrested for murder and jailed for six days when Google's GPS tracker wrongly placed him at the scene of the 2018 crime
https://www.dailymail.co.uk/news/article-7897319/Police-arre...
The point I was trying to make was privacy reasons aside their motivation of doing it on the users device is scummy. Why don’t they mine Bitcoin on my iPhone while they are at it?
Apple's approach here is far superior from a privacy standpoint.
>1. Only if you're uploading files are the files matched. 2. Only if the matches are very close are they considered matches. 3. Only if you have multiple very close matches is Apple able to decrypt the low-res versions of the images themselves. 4. Only if a human reviewer discovers any of the decrypted low-res images to be illegal content is any of your information shared with anyone else.
At least with server side your images are being scanned when you are actively sharing photos with other users or to the internet. Thus making it more difficult to distribute CSAM material.
If iMessage was serious about preventing child abuse, they should be introducing mechanisms to prevent actual abuse from occurring on their platform.
A company well known for refusing to hire human beings when their flawed machine learning models are a less accurate but cheaper option?
Again, Apple is not scanning images until you try to upload them to the cloud. Just like Google.
I don’t want anything of mine to be scanned but these days it’s fair to assume that anything that is not self hosted is not private.
How can you prove that Google isn't intentionally turning in a huge number of unnecessary false positives because of their well known aversion to hiring human beings when flawed machine learning models are cheaper?
I don't trust Google and I don't trust Apple. Apple can perform the same process on their iCloud servers but choose not to. The way they are approaching the problem speeds up the erosion of privacy.
In other words I reject the false dichotomy you are presenting.
>Google has been able to track your location using Google Maps for a long time. Since 2014, it has used that information to provide advertisers with information on how often people visit their stores. But store visits aren’t purchases, so, as Google said in a blog post on its new service for marketers, it has partnered with “third parties” that give them access to 70 percent of all credit and debit card purchases.
https://www.technologyreview.com/2017/05/25/242717/google-no...
Sometimes I forget how messed up Twitter is.
What is messed up about that? The method of reporting is in the hands of the user, not an ML algorithm. The ML algorithm would prompt the kid to stop and think about what is happening, before actual abuse occurs.. I assure you Stamos is speaking from a place of experience, in having to prevent these kind of things.
It's just like trying to start discussing the Patriot act by starting with a recording from a plane on 9/11 (an irrelevant appeal to emotion that is so outsized it interferes with the dispassionate ability to weigh alternatives).
For all we know taking away cp from pedophiles makes them more likely to try it in person. Go after the creators.
It's a far better proposition than assuming everyone is guilty and mass-scanning photo libraries.
I was in complete agreement with most Apple-related comments until I saw this group of knee-jerk reactions to a reasonable attempt at discussion. wtf
I don't use iCloud. I have no need for it. Then again, most people on HN do not fit the profile of the average Apple user. When you are technically capable some of these things don't have the same value they may have for you parent, uncle or grandma. In my case, I had a couple of problems back in the iPhone 3 days and just opted to ignore it completely. Today, my iPhone X isn't using iCloud and all is well.
That said, I have seen people do things like take pictures of tax and other documents and message them to others. I can't possibly imagine what people take pictures of and unwittingly keep in their phones and on iCloud. ID, paychecks, that wart in their crotch, anything. The average user has no clue how any of this works. It's magical. And, yes, it's simple. And, yes, it comes with potential consequences.
And now, all of it is up for evaluation for potentially criminal activity? By an anonymous a team with no legal accountability to anyone? Without and before being accuse of anything?
Wow.
What doors are we opening?
Well, ransomware has been rare almost forever, then suddenly became the norm.
> "and that in any case a review would then look for other signs of criminal hacking."
Good luck finding a malicious app that downloads child porn from an encrypted remote server, plants it in the target device, sends "by mistake" an example to social media using the owner credentials, then deletes itself.
This is crazy. Child porn traffickers will find a way to circumvent this while it would offer governments just another weapon against people they don't like.
Also they completely ignore that we're talking about child porn; if someone is wrongly linked with the subject for just one second by the media, no matter how many times the news is being rectified afterwards, his life may be ruined forever. It's not like being accused of avoiding taxes or theft; any mental association with things like child porn or rape is not going away easily.
Any technology that could be (ab)used to plant evidence in such cases would be the ultimate weapon to destroy individuals without actually killing them. Better not to have it than to risk that it ends in the wrong hands.
https://news.ycombinator.com/item?id=28069528
I have come to one more nuance about the viewpoint. If people are spreading CP by signing into the same Apple account from multiple devices and using iCloud to automatically share the photos, I think that's a different situation than a single person signing into one computer and one phone that are mostly used on the same networks together.
Not that I've really changed my view that I wrote before, just there is a bit of grey here.
Those photos are usually taken on phones by spouses, doctors, schools, etc. to be passed to the above on their phone for evidence for a DNN or similar case.
Glad my kids have aged out of baby bath photos.
And those poor people who I know are going to have to provide an auditing safeguard. I hope they take care of their mental health.
How could it be? The list is literally property of the secret police, you can't know what's on it. No one can audit it except the police themselves.
: To be clear, I'd expect whistleblowing if these manual reviewers were tasked to 'accept' CSAM submissions that aren't CSAM.
Wheww that makes me feel better
I bet this stance changes in under five years.
Why not? They've told you in detail what they're going to do.
backtracking on promises after buying from them
Darth Vader: I am altering the deal. Pray I don't alter it any further. [departs in an elevator]
Apple as a whole organization doesn't care about end user privacy. People claiming such are ignorant of the facts and are repeating Apple's marketing narrative.
Legal compulsion or not, FBI was somehow obviously able to force them to abandon iCloud e2ee and now NCMEC (or whoever) was able to force them to do this.
https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
EARN IT seeks to deal with the scourge of online child exploitation by coercing service providers to more aggressively police such content on their platforms. https://www.congress.gov/bill/116th-congress/senate-bill/339... Similar laws in UK and others.
Maybe this will short circuit the need for a government backdoor to snoop in icloud photos?
Q2) Didn't people agree to no illegal KP with the icloud TOS? Doesn't all this do is move the scanning from apple's servers to the distributed ARM processors?
Q3) Is that more environmentally friendly or less? I am sure it is cheaper for apple to have the iphone scan than add additional servers, cooling, space, etc.
If one doesn't use icloud photos this does not affect them, for now.
https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
Cynical take- as pedos move to other means of storing and sharing CSAM, there will be far fewer photos flagged for review which requires fewer reviewers to be paid by Apple. If they wanted to do this for the greater good as some users claim, wouldn't they have been far more successful in catching criminals if they kept this system secret?
Disclaimer: I'm not in support of keeping it secret nor even the system itself, but this is a question worth considering when viewing the situation through the greater good lens.
-upload hash of meme you find offensive that the political opposition is using to subvert your authority
-receive addresses of ‘offenders’
Perhaps there's a real problem here that needs to be addressed (though not in this way that opens the door to all kinds of surveillance)?
To me this signals that they are going to start allowing E2E encrypted photos on iCloud but they need to compute the hashes on device to comply with the law because they cant hash them once they are encrypted.
The actual algorithm isnt accurate to 1/1T - they're claiming the human review process is that acacurate.
The former can enable the latter. And so much more. Organizing sex trafficking, terrorism and so forth. Nevermind the copyright protection stuff.
The latter can enable tax evasion, money laundering and financing unsavory activities. States don’t want people to be able to do that.
Yet many on HN applaud attempts to doxx everyone and every transaction in crypto, calling it a scam/for criminals, while at the same time decry any attempts to lessen encryption, however subtle or careful, of personal files and communication.
What is a consistent position on both these topics, given that there are dangers on both sides of the argument? I tried to present the core issue here:
See here: https://en.wikipedia.org/wiki/Perceptual_hashing
The goal of a perceptual hash is to generate a number that will be the same for all "similar" looking images.
Think like what Shazam does, but in the visual domain.
Developers created this and developers must suffer from this.
"Thousands of developers swept up in CP ring!" that later turns out to be malware planting CP would go a long way towards fixing this issue.
I really am surprised nobody has made a worm that's sole function is to hit every FBI honeypot in existence and archive it to hidden folders just to prove a point.
Yes, this definitely "dispels" my alarm. Thanks, Apple.