The deceptive PR behind Apple’s “expanded protections for children”
piotr.is
piotr.is
The fact of the matter is that unless you possess a photo that exists in the NCMEC database, your photos simply will not be flagged to Apple. Photos of your own kids won't trigger it, nude photos of adults won't trigger it; only photos of already known CSAM content will trigger (and that too, Apple requires a specific threshold of matches before a report is triggered).
[1] "The threshold is selected to provide an extremely low (1 in 1 trillion) probability of incorrectly flagging a given account." Page 4 of https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
The parent poster does make the mistake of assuming that other pictures of kids will likely cause false positives. Anything could trigger a false positive - especially flesh tones. Like, say, the naughty pictures you've been taking of your (consenting) adult partner. I'm sure Apple's outsourced low-wage-country verification team will enjoy those.
There was a good article [0] that was on HN a couple days ago that touches on the flat out lie regarding "one in a trillion" and how PhotoDNA sounds poorly thought out.
[0] https://www.hackerfactor.com/blog/index.php?/archives/929-On...
Beyond that, assume that a false positive occurs and the innocent person is taken to court. Why would they have to fear being convicted if they don't actually hold any incriminating evidence? At most, that would become evidence against using perceptual hashing in future court cases.
The issue in that case is the violation of the innocent person's privacy, not that they have a risk of being falsely convicted. The courts would still need admissible evidence, and I don't believe that only having a perceptual hash and a set of legally photographed images clears that bar.
However, it becomes a completely separate issue if the false positives are "coincidentally" used to persecute marginalized groups in other countries where the same set of laws don't apply. But Apple has stated that they have no intention of expanding the system's scope to follow those laws. There isn't any evidence yet that Apple will do such a thing, or that they've already done it in the past. We are free to disbelieve them, but that's what they've stated. We can only hope that they won't change their minds.
I'm not sure they'll be able to after looking at CSAM all day...
What's relevant is the overall false positive rate. If they require 6 matches for example, it's enough for each match to have a 1% false positive rate in order to get 1 in trillion overall.
Don't you think Apple has independently arrived at that very same possibility? Maybe even thought about it and extensively tested it? Then put a probability on it? And then chosen the threshold such that the overall probability of falsely flagging an account is, indeed, minuscule?
What are you talking about? Ask anyone who has worked in this space: false positives are abound[1][2], especially when you're looking for fuzzy matches. And you have to look for fuzzy matches otherwise slight modifications to illegal images would bypass the detection system.
> Photos of your own kids won't trigger it, nude photos of adults won't trigger it;
This is also incorrect. In general, if two images kind of look like one another when you squint, they're going to have similar perceptual hashes. A lot of unrelated things look similar to one another when you squint, and a lot of unrelated things are going to have similar perceptual hashes. And, again, you'll be doing fuzzy matches on these hashes, so you're going to pick up those unrelated things even more so than when you just have hash collisions.
Even if the tech has 1 in a trillion chance, it will happen a lot with billions of people generatin thousands of ilage every years. And of course, the hash database being abused.
I assume they are just standard ML.
The other side started it first. Look at the government's dubious claims about terrorism prevention. John Walsh a founder of NCMEC testified to congress that millions of children were abducted every year and that america was "littered with mutilated, decapitated, raped, strangled children," (this was and is not true).
If fear mongering about Big Brother throwing normal people in prison for pictures of their children is what it takes to blunt the expansion of the surveillance state I say fair play.
How long until they try to machine-learn based on that database? The door's open.
Probability of N false positives (assuming independence) = p^N
Threshold N is chosen by Apple such that p^N < 10^-12, or N log p < -12 log 10, or N > -12 log(10)/log(p) [since log(p) < 0, since p < 1].
ETA: Suppose, just for the sake of the argument, that p = 10^-3 (one false positive in 1000, so really quite bad).
Then log(p) = -3 log(10), so N > -12 log(10)/(-3 log(10)) = 12/3 = 4.
Similarly, if p is one in a million (10^6), then N would be required to be > 12/6 = 2.
In practice, I'd expect N to be larger than 4, in other words, Apple being very conservative here.
ETA: The above doesn't take into account how many images M you have. The analysis gets more complicated, but N needs to be way larger than 4. I'll think about it some more.
While I fully admit that NCMEC could do a better job with transparency and auditing, they are currently being used by several other platforms right now (Facebook, Google, Microsoft) without issue.
Could bad actors inject hashes of non-CSAM content into the database somehow? Well even if they could do this, Apple employes human reviewers who must visually confirm that the flagged photo contains actual CSAM before they report the image. If the image does not contain CSAM, Apple is under no legal obligation to report it.
More information here: https://twitter.com/AlexMartin/status/1424703642913935374/ph...
You have to first get a “significant” number of photos flagged, then they have to pass Apple’s manual review (ie looking at photo thumbnails), and only then does Apple report the account.
This is a pandaora's box of trust. Once you open it, you have to trust in perpetuity.
For everyone else getting access to the phone and manually loading the pic would work.
Additionally it's possible to fool AI: https://slazebni.cs.illinois.edu/fall18/lec12_adversarial.pd...
1) During the course of investigation an officer infiltrates a CSAM sharing ring and/or poses as a customer for CSAM. Material is shared with the officer as it would be to an actual consumer of CSAM.
2) When someone is charged with child abuse, possession of child porn, etc, their physical and electronic lives will be methodically and forensically searched for CSAM material. They will likely find material they already know about, but potentially uncover new material and/or new social networks.
Any material acquired would need to be analysed and classified for the purpose of effective prosecution. My understanding is (from other comments made by people on other websites) that images in the NCMEC database are tagged based on the severity of their content and that Apple is only scanning for the most extreme "A1" material.
I wasn't sure what A1 meant so I googled it. According to this[0] PowerPoint presentation, page 22:
A = prepubescent minor
B = pubescent minor
1 = sex act
2 = "lascivious exhibition"
If you want to ruin your day, the PDF provides very specific—depressingly, grossly specific—definitions for the above.[0] https://www.prosecutingattorneys.org/wp-content/uploads/Pres...
True, but the wording of that condition was very vague... the threshold could be 1.
>"...report iCloud users who store known Child Sexual Abuse Material (CSAM) in their iCloud Photos accounts."
OK. They're not trying to tag and bag your images for 'abuse content'.
If you collect your child abuse porn on iCloud, we're going to report you?
But the truly sad thing is that there are trillions of instances, photos, moments that will never even see the light of day. and plenty of human children get abused, raped, murdered every single day.
Child abuse should be a capital crime.
like most privacy invasions these days, its casting a widenet to put a dent in a problem that sill inevitable just route around it, and soon enough itll just be turned into a copyright cashgrab
Be aware that almost all cloud providers screen photos. Facebook reported 20 million images in 2020, Google reported half a million. Dropbox, Box, and many, many others report images. See https://www.missingkids.org/content/dam/missingkids/gethelp/... to see a complete list of companies that screen and report images.
The other thing Apple announced which is completely separate from the CSAM photo scanning is additional parental controls for the Messages app. If a parent opts in for their under-13 children, a machine learning model will look for inappropriate material and warn the child prior to showing the image. The child is also told that their parent will be flagged if the child looks at it anyway. For 13-18 year olds whose parents opted in, the teen is warned first about the content. If the teen continues past the warning the image is shown and no further action is taken. Parents are not flagged for children 13 and over. As I said, this is a parental control for pre-adult kids. It requires opt-in from the parents and has no law enforcement implications.
1. Who is adding these photos to NCMEC? 2. How often are these photos added? 3. How many people have access to these photos - both adding and viewing?
Everyone is focused on Apple and no one is looking at MCMEC. If I wanted to plant a Trojan horse, I would point everyone towards Apple and perform all of the dirty work on the NCMEC end of things.
Can you imagine the chaos of a successful collision matching some explicit material being sent as a prank or targeted attack?
There are legitimate things to be concerned about, but 99% of internet discussion on this topic is junk.
There’s also the Op-Ed by Matthew Green and Alex Stamos, cyber security researchers: https://www.nytimes.com/2021/08/11/opinion/apple-iphones-pri...
I think John's article is better than Ben's, but they're both worth reading.
Ben takes the view that unencrypted cloud is the better tradeoff - I'm not sure I agree. I'd rather have my stuff e2ee in the cloud. If the legal requirements around CSAM are the blocker then Apple's approach may be a way to thread the needle to get the best of both worlds.
Linked articles and comments have said apple's brand is now destroyed, that apple is committing child porn felonies somehow with this (the logical jumps and twisting to get to these claims are very far from strong plausible interpretation).
How do you scan for CASM in an E2EE system is the basic question Apple seems to be trying to solve for.
I'd be more worried about the encrypted hash DB being unlockable - is it clear this DOES NOT have anything that could be recreated into an image? I'd actually prefer NOT to have E2EE and have apple scan stuff server side, and keep DB there.
> The laws related to CSAM are very explicit. 18 U.S. Code § 2252 states that knowingly transferring CSAM material is a felony. (The only exception, in 2258A, is when it is reported to NCMEC.) In this case, Apple has a very strong reason to believe they are transferring CSAM material, and they are sending it to Apple -- not NCMEC.
> It does not matter that Apple will then check it and forward it to NCMEC. 18 U.S.C. § 2258A is specific: the data can only be sent to NCMEC. (With 2258A, it is illegal for a service provider to turn over CP photos to the police or the FBI; you can only send it to NCMEC. Then NCMEC will contact the police or FBI.) What Apple has detailed is the intentional distribution (to Apple), collection (at Apple), and access (viewing at Apple) of material that they strongly have reason to believe is CSAM. As it was explained to me by my attorney, that is a felony.
Apple is going to commit child porn felonies according to US law this way. This claim seems actually quite irrefutable.
Instead of exclusively focusing on the authoritarian slippery slope like it's inevitable, it's worth wondering first: why do the major tech companies show no intention of giving up the server-side PhotoDNA scanning that has already existed for over a decade? CSAM is still considered illegal by half of all the countries in the entire world, for reasons many consider justifiable.
The point of all the detection is so that Apple isn't found liable for hosting CSAM and consequently implicated with financial and legal consequences themselves. And beyond just the realm of law, it's reputational suicide to be denounced as a "safe haven for pedophiles" if it's not possible for law enforcement to tell if CSAM is being stored on third-party servers. Apple was not the best actor to look towards if absolute privacy was one's goal to begin with, because the requests of law enforcement are both reasonable enough to the public and intertwined with regulation from the higher powers anyway. It's the nature of public sentiment surrounding this issue.
Because a third party insisting that user-hosted content is completely impervious to outside actors also means that it is possible for users to hide CSAM from law enforcement using the same service, thus making the service criminally liable for damages under many legal jurisdictions, I was surprised that this debate didn't happen earlier (to the extent it's taking place, at least). The two principles seem fundamentally incompatible.
My own guess is that the encryption is there so that people won't have access to an up-to-date database to test against. People who want to intentionally create false positive could abuse it, and sites that distribute images could alter images to automatic bypass the check. There is also always the "risk" that some security research may look at the database and find false positives from the original source and make bad press, as they have done with block lists (who can forget the bonsai tree website that got classified as child porn).
And how is that?
It seems like the Gruber article follows a common formula for justifying controversial approaches. First, "most of what you hear is junk", then "here's a bunch of technical points everyone gets wrong"(but where the wrongness might not change the basic situation), then go over the non-controversial and then finally go to the controversial parts and give the standard "think of the children" explanation. But if you've cleared away all other discussion of the situation, you might make these apologistics sound like new insight.
Is Apple "scanning people's photos"? Basically yes? They're doing it with signatures but that's how any mass surveillance would work. They promise to do this only with CSAM but they previously promised to not scan your phone's data at all.
I think their design is making some really smart trade offs, given the needle they are trying to thread. But it shouldn’t exist at all, in my opinion; it’s too juicy a target for authoritarian and supposedly democratic governments to find out how to squeeze Apple into using this for evil.
So, three different things.
I don't know how much you know about them, but this is what the EFF's role is. Privacy can't be curtailed uncritically or unchecked. We don't have a way to guarantee that Apple won't change how this works in the future, that it will never be compromised domestically or internationally, or that children and families won't be harmed by it.
It's an unauditable black box that places one of the highest, most damaging penalties in the US legal system against a bet that it's a perfect system. Working backwards from that, it's easy to see how anything that assumes its own perfection is an impossible barrier for individuals, akin to YouTube's incontestable automated bans. Best case, maybe you lose access to all of your Apple services for life. Worst case, what, your life?
When you take a picture of your penis to send to your doctor and it accidentally syncs to iCloud and trips the CSAM alarms, will you get a warning before police appear? Will there be a whitelist to allow certain people to "opt-out for (national) security reasons" that regular people won't have access to or be able to confirm? How can we know this won't be used against journalists and opponents of those in power, like every other invasive system that purports to provide "authorized governments with technology that helps them combat terror and crime[1]".
Someone's being dumb here, and it's probably the ones who believe that fruit can only be good for them.
"The Messages feature is specifically only for children in a shared iCloud family account. If you’re an adult, nothing is changing with regard to any photos you send or receive through Messages. And if you’re a parent with children whom the feature could apply to, you’ll need to explicitly opt in to enable the feature. It will not turn on automatically when your devices are updated to iOS 15."
https://www.hackerfactor.com/blog/index.php?/archives/929-On...
it happens all the time
People are furious with Apple, and there's no reason to discount the completely legitimate concerns they have. This is a slippery slope into hell.
It's a good thing congress is about to start regulating Apple and Google. Maybe our devices can get back to being devices instead of spy tools, chess moves, and protection rackets.
(read: Our devices are supposed to be property. Property is something we fully own that behaves the way we want. It doesn't spy on us. Property is something we can repair. And it certainly is not a machination to fleece the industry by stuffing us into walled and taxed fiefdoms, taking away our control. Discard anything that doesn't behave like property.)
[edit: I've read Gruber's piece on this. It's wish-washy, kind of like watching a moderate politician dance on the party line. Not the direct condemnation this behavior deserves. Let's not take his wait and see approach with Dracula.]
Context often matters more than the nature of the actual content. Police aquire thousands of images with little hope of ever knowing where they originated. If they are collected by pervs, and could be construed as illegal in the hands of pervs, the images become child porn and can be added to the databases.
What Apple announced is a new system for reading the existing hash lists of known CSAM images and doing the comparison on the device as part of the iCloud upload, rather than on the server after upload.
It's not as simple as that. Photos in the NCMEC database are tagged based on the severity of their content. The categories are A1, A2, B1, B2. According to this[0] PowerPoint presentation, page 22:
A = prepubescent minor
B = pubescent minor
1 = sex act
2 = "lascivious exhibition"
Apple are only searching for images tagged as "A1" by NCMEC and other agencies. This is the most extreme of the extreme. There is a massive gulf between the A1 category and anything you could even remotely conceive of being in anyone's family photos.[0] https://www.prosecutingattorneys.org/wp-content/uploads/Pres...
Protocol is rather device specific (while allowing multi-device), so it might not be enough to access or hack iCloud account to access the photos. So, things get complicated.
Did apple actually say photos would be e2ee or are we just assuming?
Parents can produce, distribute and sell CSAM of their own kids. That's one of the implications they'd face in court.
If you do choose icloud upload (most do), they were being uploaded already and stored and may be available to law enforcement.
If you do upload to icloud, NOW they will be screened for matches with "known" images in a database, and if you have more than a threshold number of hits, you may be reported. This will happen on device.
Apple will also scan photos in their cloud system as well from what I can tell (though once on device is working less should land in cloud).
Note that it is HIGHLY likely that google photos / facebook / instagram and others will or are already doing similar scanning and reporting. I've heard millions of reports go in a year.
I wonder what the false positive rates are for:
- A random image against the DB of perceptual hashes
- Images of a baby's skin against the DB of perceptual hashes
It seems like the second would necessarily have a higher false positive rate: similar compositions (contains baby's skin) would more likely have similar chunks. Is it just a little higher or several orders of magnitude higher?
I know hash collisions are rare, but wonder how much rarity of collisions decreases with perceptual hashes.
https://rentafounder.com/the-problem-with-perceptual-hashes/
the false-positive rate will be likely high. Given the billions of pictures going through this system there are going to be a lot of false accusations of child porn possession likely (and alone such an accusation can ruin lives).
HN discussion of that article from a few days ago:
I'd also like to know more about the specifics here, my guess is that threshold value is pretty high (their 'one in a trillion' comment not withstanding). It's probably targeting large CSAM dumps of matches which would not get flagged by different images.
Images then do get a manual review before a report is made which is good and may help provide feedback on alogs being used.
Going to be hard though for apple to set the second factor to high - I'd say 5 maybe? It's hard to say you had matches on potential CASM and ignored them I'd think.
Disabling iCloud does not remove the uploading system from your phone.
Pressing end recording on a video does not remove the video capture system from your phone.
on edit: later on of course this will make a great article in some place like the Atlantic with a stolid monochromatic picture of your family in the lead-in and we will all read about it on HN and talk about how this was an obvious problem with the whole system (if it gets posted at the right time and gets enough upvotes).
Current CSAM depends on humans to "verify" the imagery, this is something companies desperately want to get rid of, and so do the employees understandbly so. Nobody wants a job (99.99%) of comparing CSAM. It costs companies money in labor costs, and draws them bad PR when those employees inevitably develop permanent/semi-permanent mental health issues from it.
The only reason it hasn't happened yet is because a startup can't just start scanning CSAM. They need the blessing of the feds to do that, which requires political connections, and of course requires competing with companies that already have that blessing - something that politics prevents.
PhotoDNA and current CSAM scanning only gets known CSAM, but not new CSAM. The end goal is to detect CSAM before it's ever even distributed, to be "closer to the victim", rather than just those consuming it.
Even with current PhotoDNA you can generate hash collisions, which flag the image for review, and a real human compares the material. This is of course subject to change for the reasons stated above.
Secondarily, automatic scanning and ID'ing of imagery is how you can easily throw an FBI raid at someone. Apps like Telegram automatically download every image/video in the thread.
Ontop of that you can create images that appear different at differing resolutions. At one resolution a harmless meme, at another, CSAM. Meaning that you can again throw an FBI raid at someone using simple tricks.
* As addressed in the comments below, this isn’t entirely true: the hash looks for visually similar picture and there may be false positives.
https://www.hackerfactor.com/blog/index.php?/archives/929-On...
[1] you could "help" independence by requiring a certain distance between images you simultaneously flag.
No. If the number of matches to known CSAM in your library exceeds a threshold, then a person will look at a "visual derivative" of only those pictures whose perceptual hatch match that of known CSAM.
Note that, if I understand correctly, pictures that Android users sync to Google have already been scanned for some time. Where are all those false positives?
The NCMEC database and this hashing have been around for like 15 years. I’m curious as to how you know this.
In a TechCrunch interview Apple said that they are going after larger targets that are worth NCMEC’s time.
It's actually worse than this, if the hashes are similar then they'll get sent for review. Your picture could be a picture of an abstract painting[0] which has no visual similarity to anything in the db, but through the magic of crypto is similar and it too will be flagged.
[0] The reason I use this example is because someone posted a bunch of abstract art that was flagged by the algo.
So if your innocent baby pic looks similar enough to a previously tagged child abuse image then YES, it will flag you and send a copy to the feds.
And before you correct me, the Apple employee will see a picture of your naked baby and hit “forward to NCMEC”, which… upon investigation is actually just the feds
Are news filled with false-positive accusations by PhotoDNA, flagging wrong images in Google, Facebook, Instagram etc.?
This only catches ownership of illegal photos.
Enjoy explaining why your mugshot and arrest record had these charges attached to it!
(Actually, in this case the prosecution would probably use the other pictures on the phone that were not detected by the scanning tool as a way to get a guilty plea deal!)
But it can be a form of denial of service: saturate the system with hash collisions so that people can't keep up.
LEO's/FBI/every other institution/group that deals with child pornography and abuse have teams that go through a near infinite amount of pictures and videos of CP/etc.
These are then marked by said people as either - yes, CP/Abuse/etc - or marked false positive.
Once marked as what they're after, they're uploaded to a shared database between all groups involved.
Only what is in these worldwide national databases is what's going to be checked against. Your new pictures of your children will have obviously never made their way to any of these groups as they've never been shared/distributed in any areas of the internet/etc these people work in to track down trafficking rings (well, I'd hope you're not selling pictures of your children to them).
This is the way I understand it. I admit I haven't looked into it that much. If it's anything different than what I've said, then yeah, it's probably fucked. I don't get what people don't understand about checking against a database though. No, your new pictures of whatever are not in this pre-existing database
Apple uses two different approaches:
1. Some way to try to detect _known_ child pornographic material, but it's fuzzy and there is no guarantee that it doesn't make mistakes like detecting a flower pot as child porn. But the chance that your photos get "miss detected" as _known_ child pornographic material shouldn't be too high. BUT given how many parents have IPhones it's basically guaranteed to happen from time to time!
2. Some KI child porn detection on child accounts, which is not unlikely to labile such innocent photos as child porn.
The child account iMessage thing is really entirely separate from the CSAM related iCloud announcement. It's unfortunate people keep confusing them.
Oh come on. DOn't make it sound like it's that bad. Wifi is a solved problem for a long time now, and you can buy Lenovo, System76 or Tuxedo if you want to make sure 100% things work as expected. Don't be that guy.
Also, getting full USB3 support on Ubuntu is still a struggle. On Windows and Mac, the same USB camera "just works". On Linux, I need to learn how to download the kernel sources, checkout the correct branch, and recompile uvcvideo with different URB parameters, or else I get random disconnects.
And of course, "apt-get source" will produce the source code for the 4.x kernel that Ubuntu 18 had when I installed it, but they since upgraded it to 5.x so "apt source" is now utterly useless.
If I had to summarize my Linux experience:
"Pain only makes you stronger"
If I got random disconnects for my webcam in OSX I wouldn't bother with it, I'd just buy a better supported webcam. Maybe that's just me, but I appreciate the people who tirelessly tinker to get support going. Just make sure you send those changes upstream to whatever distro you are using.
As long as nobody tells non-technical people to patch their kernels, we're all good. Any modern Linux desktop from one of the major distributions (Fedora, Ubuntu, ChromeOS) is the most low maintenance computer you can find, but with that level of tinkering you'd soon find yourself on your own.
I cannot dismiss your experience. I think you are telling the truth.
But I was introduced to Ubuntu by a (mildly) enthusiastic 50 years old electrical engineer back in 2006, so I know it used to work for some ordinary people even back then.
I really don't know some HN-ers manage to break Ubuntu repeatedly while it just works for non technical users, but a qualified guess is a combination of exotic hardware and tinkering (a good thing).
It's more than that IMO, it's that we don't give up.
Your average non-technical user will just deal with the camera disconnecting occasionally, maybe swear at it once in a while, or (commonly) just not even notice. If you ask them how Ubuntu is, they will say "Yeah, works fine. No viruses!"
Your average HN'er will be bothered every time it disconnects, to the point where they are recompiling a bleeding-edge kernel and breaking 10 other things, but have a working camera that never disconnects. Then we complain here about Ubuntu being broken and terrible :)
On a tangent – I think that it's kind of worrying that Canonical seems to have Ubuntu on the desktop as super-low priority – all I hear about them these days is them trying to market some kind of server product, or their various kinds of managed Kubernetes offerings, which as far as I can tell, go up to $4k/node/year on your own hardware [1] I wonder how much success they are having with this.
----------
[1] https://assets.ubuntu.com/v1/b5f9ae49-Enterprise_Kubernetes_...
I always had to fix it in text mode with elinks, it was a complete nightmare and I switched to Nouveau.
Now I have an AMD based laptop and it has it's own problems (briefly had a mac on Intel) - they are all tricky.
In 2021 we are instead lumbered with inconsistent support for hidpi displays, lack of DTMF in linphone, and Evolution’s option to disable pc beep on new message being a plugin.
But that was just the last week. Next week will be better and the fight for freedom is indeed an eternal struggle.
Are you really complaining about GNOME software lacking options as if that wasn't what GNOME is all about. Please don't blame Linux for problems with one specific DE and its applications.
Those are not related complaints at all. Shifting goalposts much?
Click-click-done. I didn't have a hard time, not even with connecting my printer. I'm almost disappointed a bit, since there's no way I'm a cool computer guy if it's this easy.
Coincidentally, this is actually a good idea. Apart from using supported hardware (that others have checked actually works), contributing fixes for hardware that's not officially supported yet and hasn't been tested would benefit everyone in the future!
I remember having to dig through GitHub to find a repository that had the network drivers for my off-brand Chinese/Polish netbook (i'm somewhat poor and/or frugal) and they actually worked and turned a system that would otherwise not have any network connectivity into my daily driver for note taking. Now, the fact that i couldn't automate this lookup process and that there's nothing out there that lets you check for these drivers more easily (think something along the lines of https://appdb.winehq.org/ but for drivers) or maybe try multiple ones in a row, was disappointing because things felt needlessly hard. However, actually contributing or using the work of others isn't that much of a problem.
And, since the whole ecosystem is pretty much open, there's nothing actually keeping one from at least trying to address these problems for their particular configuration, apart from needing to learn how to do so. In a sense, working on open source is exactly putting your money where your mouth is, even if it's just alternative costs.
Every time I read how the great unwashed should just contribute fixes already to benefit everyone, I despair. I write code. I build my own PCs and I have a rather good knowledge of how to debug, fix, optimise and otherwise maintain all my software and hardware.
I happen to also LIKE my software and hardware.
If I were to start digging through Github repositories and... whatever other unknown resources I don't know the search terms to even search for I'd probably shoot myself.
The point isn't that Windows is good. The point is that *nix assumes everyone's a *nix rocket surgeon and has nothing else in the world to do than spend days getting the blasted thing to deliver an equivalent level of productivity I get from my Microsoft setup.
As much as I acknowledge everyone's right to like what they like, and agree that *nix might offer one or two better things than Windoze there's just no way...
There are devices where the vendor tries to support linux, e.g. Thinkpads, but if you're using Nvidia it's still a pile of hacks in the background.
I haven't needed to contribute any code myself nor use non-upstream drivers, but the process to use non-upstream drivers is usually pretty streamlined in arch (packaged in the aur).
And since we're in hacker news: Programming things close to the hardware can be a great learning experience, maybe not when done under pressure.
But i'm not saying that everyone should contribute, or even that everyone can. I know that i'm certainly not experienced enough in systems programming to do that, instead being more proficient with higher abstraction level languages.
That said, the fact that there's the possibility of contributing for at least some people is better than what Windows and other OSes let you do. Not only that, but if the problem is annoying enough and makes enough people frustrated enough, it's likely that there's actually someone amongst all of them who cares enough to fix the problem for everyone.
For the fix to land in the mainline might take a few months or years, but the end result is still better than looking at a black box and having literally no options to get it to do what you want.
If a new Debian updates break my GRUB install, it's likely that there will be people on GitHub discussing workarounds and fixes within minutes. If my off brand hardware doesn't work as i'd like, it's likely that i'll have to do some digging but the chances of me finding a fix aren't 0 either. If the same happened with Windows drivers, i'm not entirely sure what i could even do, since the hardware setup is something that almost noone actually cares about. In the case of *nix, if i were skilled enough, i could probably dig around the source myself and work on fixing it, as someone luckily had.
The package managers and their associated websites tell you exactly where the sources are; you don’t need to search for them yourself. This is how I found some quotes for `fortune` from CentOS that I liked which weren’t present in the macOS version.
I'm not an expert on hardware stuff so I haven't got the knowledge to dig deep and find what caused it. But on Windows this stuff "just works". My impression is that Windows has "solved" wifi.
In the end I just bit the bullet and connected the ethernet cable...
With proper cooling, the machine is near-quiet on light loads like browsing. The background noise in my house is generally higher than the idle fan noise. It's obviously noisier with higher loads, but that's what you get with a beefy graphics card. (the CPU cooler has a 24 db upper limit).
I also had no issues with BlueTooth or AX WiFi. Resume-after-suspend works solidly too. The only hickup I had was that my graphics card is too new (Radeon 6700 XT) and that I had to get a newer Manjaro ISO from GitHub, rather than the main website.
But yeah wifi and nvidia are solved - just a black screen and single mode startup the first time to deactivate the opensource drivers for some obscure reason (I understand they prefer it but why does it crashes... might as well just put the nvidia ones directly)
It is basically the surviving device I still bother to run GNU/Linux bare metal on, and it was sold with Linux support from the get go, yet....
I didn't try Ubuntu 20 because it has known incompatibilities with software that I use.
Apple has not disclosed who gets to add new hashes to the list of CSAM hashes or what the process is to add new hashes. Do different countries have different hash lists?
Because if the FBI or CIA or CCCP or KSA wants to arrest you, all they need to do is inject the hash of one of your photos into the “list” and you will be flagged.
Based on the nature of the hash, they can’t even tell you which photo is the one that triggered the hash. Instead, they get to arrest you, make an entire copy of your phone, etc.
It’s insidious. And it’s stupid. Why Apple is agreeing to do this is disgusting.
And it doesn’t make sense. If I were a pedophile and I took a new CSAM photo, how long would it take for that specific photo to get on the list? Months? Years? As long as pedophiles know that their phones are being scanned, they won’t use iPhones for their photos. And then it will be only innocent people like me that get scanned for CSAM and potentially getting that used against me in the future.
If they really cared about CSAM, this feature is useless and stupid. All it does is make regular people vulnerable to Big Brother tactics which we know already exist.
First: Apple has disclosed who gets to curate the hash list. The answer is NCMEC and other child safety organizations. https://twitter.com/AlexMartin/status/1424703642913935374/ph...
Apple states point-blank that they will refuse any demands to add non-CSAM content to the lists.
Second: Why can't the FBI / CCCP inject a hash into the list. Here's a tweet thread gamifying that scenario: https://twitter.com/pwnallthethings/status/14248736290037022...
The short answer is that at some point an Apple employee must visually review the flagged photo, and confirm that it does represent CSAM content. If it does not, then Apple is under no legal obligation to report it.
Third: You claim that abusers will simply opt not to use iPhones to distribute their CSAM content rendering the feature useless. This is in fact not how things have played out on other platforms like Google and Facebook that do already scan for CSAM. These organizations report on the order of millions of flagged images per year. [1] Clearly the abusers have simply not moved on to a different platform.
[1] https://www.businessinsider.com/facebook-instagram-report-20...
The FBI/NSA can absolutely inject something into the hash list. You're assuming that NCMEC needs to be involved. Or that it would be broadly known to Apple. The reality is that the hash list needs to be updated on a different cadence than iOS itself. So it's likely downloaded rather than baked into the OS build permanently. That means that you can't necessarily rely on an iOS build being signed to know if you have a different hash list from everyone else. Ultimately, a small team at Apple cooperating with a secret court order could release a different hashlist to a select set of devices. There's nothing really stopping that.
Even if Apple didn't comply, we've seen recently how sophisticated cybersecurity companies armed with zero days can manipulate devices easily. If the mechanism for hash lists scanning the device is already built in all it takes is an exploit changing the hashlist and where it reports to which might be much simpler than gaining full access to the device.
How will Apple know whether a hash is for non-CSAM content? Spoiler alert: they won’t.
And Apple claims it will be reviewed by a human. Sure, just like YouTube copyright claims? Or will it get automated in the near future? And what about in China? Or Saudi Arabia or other countries with less human rights?
The point is that it is completely an easy way to get tagged by a government or bad actors as a pedophile. It’s sickening that Apple would let this “technology” into their products.
How would Apple know if non-CSAM was added to the list? Apple does not and cannot curate the list. Apple only receives hashes from NCMEC (and other unnamed government agencies). The government does not allow Apple to verify that this list only contains CSAM. This pledge from Apple is at best misguided at worst intentionally dishonest. Of course nobody can make Apple add non-CSAM to the list: Apple doesn't maintain the list.
- You need several hash matches to trigger a review
- The reviewer can of course see what triggered the review (the visual derivative)
- The reviewer would see that the matches are not CSAM, and instead of the report being sent on to the NCMEC it would instead start an investigation of why these innocuous images were matched in the first place
- If the CIA or FBI or CCP wanted to arrest you, there are much easier ways than this
Apple basically controls you phone anyway and have done for years as they can issue patches and os updates.
Also you can turn iphotos off - I've never used the thing in spite of owning various apple devices. I do use Google photos and doubt they are much different in terms of checking for CSAM.
After a 12 hour flight - that was of course delayed - Liam was pretty exhausted, but was looking forward to getting to his hotel in the center of Munich. He got to the front of the queue, and handed his passport over to the customs officer. The officer scanned Liam's passport, took it off the reader, and after 20 seconds asked "You flew from Los Angeles today?". Liam replied "Yes...". The customs officer, with his firm German accent, said "I need to check something with my colleague, wait here.". Not that there was anywhere Liam would go.
The customs officer came back with someone else who was slightly older and clearly more senior. The senior officer said "Come with me please", and led Liam to a room at the side of the customs hall. The officer said "Sit down please", indicating to the chair in front of the desk. The room looked like any other office, with a computer on a desk and chairs either side. The officer sat behind the desk and started typing something on the computer. After a few minutes he said "You are wanted by Interpol".
The customs officer explained to Liam that he had been flagged as a photo he had taken 6 months before included a known terrorist, and so by association Liam had been flagged. Liam asked how they accessed his photos - he is tech savy and only takes encrypted backups onto his own devices. The customs officer explained that they didn't need to, as this flagging had been done entirely by his device. The customs officer gave the date of the photo, and Liam found it on his device. He had been on holiday with his girlfriend in Paris, and they had taken a selfie. There was someone clearly visible behind them, and the customs officer explained that the facial recognition had identified this person. Due to privacy laws he wasn't able to say (or even see themselves) who this person was, only that they were on the highest German terrorist watch list.
From the photo it looked quite obvious that this person was just a passer by who glanced at the couple just at the moment they were taking a photo. The customs officer took Liam's fingerprints and asked Liam questions about his trip to Paris - typing the answers into the computer - and then the computer decided that Liam could be released. However the customs officer told Liam that he would be closely monitored while in Germany, and may receive 'check in' calls from police. He told Liam he must answer them otherwise a team will be dispatched to intercept him. Liam was then allowed to go on his way. He was only delayed by 45 minutes, but it wasn't a great start to his holiday in Germany. 3 years later when he visited Germany again the same thing happened, at least he knew what to expect this time...
(This is partially based on something that actually happened to me. Nearly a decade ago my passport was stolen, and every time I go to Germany I need to have a fun conversation with customs officers. Every other country I've visited - including the US - let's me through without even mentioning it)
people really need to retire this meme. On the desktop in particular as a dev environment Linux is completely fine at this point. I can understand people not wanting to run a custom phone OS because that really is a ton of work but for working software developers Fedora, Ubuntu whatever any mainstream distro is at this point largely hassle free.
PinePhone is still in beta and according to its own creators "aimed solely at early adopters"[1], while Librem 5 is experiencing supply chain issues with backorder shipping now scheduled to resume in October[2]
There is a version of the Librem 5 which is made in USA and it's in stock and shipping now, but unfortunately outside of my budget[3].
I was also considering getting something like Fairphone and installing an alternative OS but looking at compatibility charts there are some things that may not work with one OS or another.
So, right now I can't have a daily driver that is not iOS or Android, I will hold onto my very old smartphone and hope that things will change in the next year or so. I'm working from home for the foreseeable future so I can wait a bit.
[1] https://pine64.com/product/pinephone-beta-edition-linux-smar...
I have 4 phones. None of them support lineage os.
Not sure what you mean. Pinephone and Librem 5 both have very well documented hardware with first-class support of desktop (!) Linux.
The Jolla phone was made by ex-MeeGo/Maemo devs from Nokia, but nobody bought them.
Now they're focusing on just the OS and they don't make any full fledged devices: https://jolla.com/
Packages were sometimes also different compared to vanilla Debian. This caused issues in stability (talking more about feature set). Some advanced software just did not work, which worked on equivalent vanilla Debian.
I might recommend Ubuntu for very beginner developer, but not to stick with it longer time. It will give you headache. There are also more privacy-friendly distributions.
X11's handling of different DPIs is annoying but workable; there's a couple of different possible methods of handling it that have their own pros/cons. Per-monitor scaling is supported, but I personally don't like the way it's handled, so instead I just pick a happy medium scaling that works OK for both monitors. My understanding is that Wayland makes this easier, but I haven't switched over yet because I'm waiting either for GPU prices to drop or for NVidia to figure out whether it's ever going to play nice with Wayland.
There are definitely pain points with Linux, but it's completely serviceable as a workstation computer, the meme is really dead at this point. If you're on a touchscreen device, Gnome's most recent release arguably has comparable if not better touch handling than Windows (admittedly not a high bar to clear, but remarkable considering how bad Linux's touchscreen support used to be). I use a Mac at work so I'll fit in with my coworkers, but outside of work I do not own a single computer with Windows installed on it.
I'm not going to tell everyone to switch to Linux, there are very valid reasons why someone might not want to, including an increased technical burden. That's real, it's just not the giant hurdle that a lot of people seem to think it is. The "year of the Linux desktop" is really out of touch in my experience, modern Linux as a desktop OS is fine; it's perfectly serviceable as a professional environment for a lot of people. I use Linux in part because it makes it easier for me to get an ergonomic setup for drawing tablets, device compatibility, etc...
And at some point I figured out that I don't really care what desktop Linux's market share is, because even <1% still seems to be big enough that the desktop stays usable for professional work and for more complicated device/media setups, which is all I need it to do.
Pop! OS, Ubuntu, and Linux Mint are among the distributions that flawlessly accommodate different scaling settings for multiple displays without any special adjustments.
On Wayland, both the GNOME and KDE desktop environments support multiple scaling factors.
For GNOME on Wayland, if you need fractional scaling, you'll need to turn on a setting if your Linux distro doesn't do it for you:
https://www.omgubuntu.co.uk/2019/06/enable-fractional-scalin...
Thanks for depicting people who care about privacy and act on their beliefs as "total nerds", that's an encouraging attitude.
And even if it was not, let's not get upset for every quip, I don't want to live in a world where bloggers have to ponder every word because they are afraid of offending someone. A bit of spice is ok, the dose makes the poison.
I don't find it offending, I find it stupid to write like that, that's not the same. So you write a long piece about how Apple is bad for privacy, just at the end to detract the available alternatives because you know, you don't like them for no particular reason? Who said that privacy was going to be easy anyway?
Apple is a private company and as such its actions amount to vigilantism.
To anyone upset or offended by the Linux/nerd paragraph: please chill, and please forgive my tone.
I am a nerd myself indeed, and what I wanted to convey by this not-as-funny-sa-expected paragraph was that "going full nerd" is not a solution. There are ways to protect your privacy that will not be available to less tech-savvy people, and it's a problem. HN crowd will use Thinkpads with Arch on them, and phones with Graphene or whatever, but most people won't.
Yours, Absolute nerd and lover of desktop Linux since SuSE 6.0
Non-nerds can just buy devices with preinstalled Linux and never care about the maintenance or support. I never had any problems with WiFi or suspend on my Librem 15. Same I expect from Librem 5 smartphone.
https://techcrunch.com/2021/08/10/interview-apples-head-of-p...
This is best explanation of the whole situation I have read.
Surely they know this will be abused to check user data before it is uploaded to iCloud. All it takes is a willing government.
Now the pandora box has been opened. They are adding capability to scan files on iPhones before it hits the cloud.
Any technical or financial excuse they might have used in the past to not scan files locally is now rendered null.
Governments can just say: "you know what? scan these arbitrary sets of hashes as well, they are illegal in my jurisdiction and since you've shown that you can, scan them regardless if the user is sending to iCloud or not."
> Taking action to limit CSAM is a laudable step. But its implementation needs some care. Naively done, it requires scanning the photos of all iCloud users. But our photos are personal, recording events, moments and people in our lives. Users expect and desire that these remain private from Apple. Reciprocally, the database of CSAM photos should not be made public or become known to the user. Apple has found a way to detect and report CSAM offenders while respecting these privacy constraints. When the number of user photos that are in the CSAM database exceeds the threshold, the system is able to detect and report this. Yet a user photo that is not in the CSAM database remains invisible to the system, and users do not learn the contents of the CSAM database.
https://www.apple.com/child-safety/pdf/Alternative_Security_...
Currently it's been activated for CSAM only and only scans photos backed up to iCloud.
That's the framing I prefer and which much better explains the issue with it.
I get why a safe environment is appealing. Parents know that their kids get milked by virtual goods in games or social media and don't know how to protect them from that. I think states are indeed responsible to set sensible boundaries for the industry to protect minors.
But this cannot lead to subject the whole net to it. Age verification is also not possible, so a protected environment is the way to go. The latter is difficult to advertise to developers because they also know about corporate ambitions to get their hands on market share.
Google isn't even the worst actor, more aggressive corps like Amazon are far more destructive in this field, but there isn't a single corp that is guilty here, so legislation also needs to protect free spaces. While seemingly in contradiction, this is also extremely important for digital education of future generations, even more so than questionable content in my opinion. Most here might have been subjected to that as kids. Was it that bad as generally assumed? This is a threat that should not be overblown. Parents feeling guilty neglecting their kids are extremely vulnerable to this line of thinking, even if they don't neglect their kids at all.
Many countries have rules against cartels, but there is a conflict of interest here. No country likes to split their most successful companies for nothing in an international market. So nobody does.
Indeed, it just looks like another move in the current crypto-wars.
It's repulsive how the NCMEC is pushing to deprive minors of privacy and agency, while simultaneously claiming to advocate for their benefit.
Then what? I would argue that what Google is doing already is way more privacy-compromising than this.
But I do have guesses why.
a. Apple intends to E2E encrypt iCloud data.
b. This is intended to extend to all photos on the device in the future.
I'm hoping it's (a), but it's probably (b). And in either case it sets a bad precedent for other companies to follow.
Edit: This also turns every jailbreak into a possible CSAM detection avoidance mechanism, giving the government plausible cover to treat them as serious, criminal actions. Apple would probably love that.
That makes absolutely no sense. There is nowhere such a requirement.
They could just E2E encrypt iCloud data. Point.
Apple's report count to the NCMEC is really low so it's probably true that they are not scanning on iCloud unless they receive a warrant.
Biggest mistake Apple has ever done was to roll out three different features at once and announce at the same time. This is creating all sorts of confusion.
However there is close to zero evidence to support this idea. I was just reading something the other day that directly contradicted this; it suggested the relationship has been excellent save for a single, well-publicised dispute over unlocking an iPhone. In other words, the publicly aired dispute was an anomaly, not representative of the underlying relationship.
Even more, unless the pontificator works for Apple or the government, she is not a good position to summarise the relationship. Plainly put, it is not public information.
What does such baseless speculation achieve. Is it like spreading a meme. I dont get it.
"The worst part is: how do I put my money where my mouth is? Am I going back to using Linux on the desktop (2022 will be the year of Linux on the desktop, remember), debugging wifi drivers and tirelessly trying to make resume-from-suspend work? Am I getting a Pixel and putting GrapheneOS on it like a total nerd? FUCK."
Is having a computer with closed source wifi drivers and proper ACPI support more important than having a computer with an open OS that does not include an intentional backdoor.
Maybe the problem is not how to put your money where your mouth is, its how to put your mouth where your money is. What does GrapheneOS cost. Maybe this is not about money.
Options like GrapheneOS, even the mere idea of GrapheneOS, i.e., that there can be alternatives to BigTech's offerings, get buried underneath Apple marketing. Much of that marketing Apple gets for free. It comes from people who do not work for Apple.
Bloggers and others who discuss computers can help change that. They can also help Apple sail through any criticism (and they do).
But there is. For example Apple used a lot of effort in this area, when they built their hardware security module (HSM), which is basically on every iPhone and iPad.
This module is built in such a way, that nobody, not even Apple can access security keys from this device, or reprogram it again. Locked iPhone or password vault stays locked or gets cleaned. One blog about this matter: https://blog.cryptographyengineering.com/2016/08/13/is-apple...
How about user tracking? Apple is one of the few companies which is not caught yet by selling data to third parties, nor even collecting more than needed to develop their products.
Our new fancy iCloud is maybe the biggest evidence? It is maybe the cleverest way to this date to enable somekind of E2EE while getting limited info about the content. Highly recommed reading that PSI paper.
(NB There is no reason to "sell user data". For example, Facebook does not "sell user data". Apple and Facebook provide access to consumers. These consumers are ad targets. In the case of Apple, they expected to purchase more stuff after they purchase an Apple computer. Apple intends to be an intermediary in those transactions.)
Besides a single anomaly, what is the other evidence.
For some people, it’s simply no worth it anymore, after primary commitment is gone..
The hashes are hard coded into each iOS release which is the same for all iOS devices. The database is not vulnerable to server side changes.
Additionally, FWIW, they do not want to start analyzing entire iCloud photo libraries so this system only analyzes new uploads.
https://techcrunch.com/2021/08/10/interview-apples-head-of-p...
Do you have a source on that? Since it is illegal to share those hashes in any way or form. Even people working with photo forensic and big photo sharing sites cannot get access to them. I very much doubt Apple can incorporate them into the iOS release without breaking multiple laws. The hashes themselves can easily be reversed to (bad quality) pictures so having the hashes equals having child pornography.
Edit:
https://www.hackerfactor.com/blog/index.php?/archives/929-On...
Where did you hear sharing hashes is illegal? How would anybody determine whether CASM at scale without those hashes?
Your hackerfactor source states, “In 2014 and 2015, NCMEC stated that they would give MD5 hashes of known CP to service providers for detecting known-bad files.”
Source? (The link you provide does not claim that, as far as I could see.)
This allows Apple to get to what is in their mind the best of both worlds: a truly private cloud for their valued users while not creating a safe haven for child abusers.
Apple's report count to the NCMEC is really low so it's probably true that they are not scanning on iCloud unless they receive a warrant.
The correction:
> This story originally said Apple screens photos when they are uploaded to iCloud, Apple’s cloud storage service. Ms Horvath and Apple’s disclaimer did not mention iCloud, and the company has not specified how it screens material, saying this information could help criminals.
And from the interview with TechCrunch:
> This is an area we’ve been looking at for some time, including current state of the art techniques which mostly involves scanning through entire contents of users’ libraries on cloud services that — as you point out — isn’t something that we’ve ever done; to look through users’ iCloud Photos.
[0] https://www.telegraph.co.uk/technology/2020/01/08/apple-scan...
Not that it matters when those Facebook sign ups are probably proxied with throwaway emails
I get a note in my fruit delivery with the name of the person and time they were at work packing my food. Yet I'm told that I cannot know anything about what is happening with at least a partially automated system that can potentially put me in jail for the next 20 years?
Would Apple report CSAM matches worldwide to one specific US NGO? That's a bit weird, but ok. Presumably they know which national government agencies to contact.
Opinion:
If Apple can make it so that
a) the list of CSAM hashes is globally the same, independent of the region (ideally verifiably so!), and
b) all the reports go only to that specific US NGO (which presumably doesn't care about pictures of Winnie the Pooh or adult gay sex or dissident pamphlets)
then a lot of potential for political abuse vanishes.
On iOS the camera can be accessed before unlocking the phone, and wouldn’t this effectively put illegal image(s) in the targets possession without their knowledge?
But OK, let's say that you've found a way to get the photos and you're comfortable with the criminal implications of that. At that point why don't you just hide the printed photos in your coworker's desk? My point is that if you have a disgruntled coworker who's willing to resort to heinous crimes in order to screw you over, there's many different things they could do that are less convoluted.
To stay on the topic of iCloud, my point is that it seems quite hard to protect yourself/device from even this most basic attack scenario.
Now imagine the same happening today with my dad shooting me a photo using his iPhone, only to trigger a CSAM alert somewhere an probably be investigated for child abuse. Just no thanks. Screw you Apple, and all those who pull your strings into creating this farce.
Furthermore, if you were using say Google Photos to store your images, then you were already subject to this vulnerability.
Voting with your wallet matters and works. It is why apple and Google still do so much marketing and hype about their phones and devices.
Sorry, but that backdoor has already existed for a long time. It exists in every IoT gadget, smart car, smart speaker, smart home and other connected device that phones home to its vendor and can receive arbitrary firmware updates. It exists for every app and every desktop software that will automatically update itself in the name of "evergreen software".
This is just the first time someone is publicly making use of the backdoor.
Another innovative 'gotcha' by Apple. A reminder that they are not your friends.
Yes, someone will have to struggle to get us there, but will have alternative if we don’t give up.
Associating with some of you has become a liability. One may be smart enough to avoid iPhone and Alexa et al. but what to do when one is surrounded by people who willingly expose themselves to nefarious technology?
In short, I don't want pictures of me being hoovered up along with your baby pics from your iPhone.
> You could of course say that it’s “a slippery slope” sort of argument, and that we should trust Apple that it won’t use the functionality for anything else. Setting aside the absurdity of trusting a giant, for-profit corporation over a democratically-elected government,
And then later it reads
> and has previously cancelled their plans for iCloud backups encryption under the pressure of FBI.
Isn't the FBI in place because of the democratically elected government? It seems like the for profit organisation is trying to do the right thing, and the government is stopping them.
This is the fundamental problem with arguments based on "trust" - the government seems to be doing the wrong thing.
Apple, if you care about children, you'll pay more than your legally owed taxes and push for improved access to education, nutrition, and free child care. They're only interested in the avenue that coincidentally dramatically increases their surveillance powers and the powers of the government.
Weird, can't figure that one out.
What does it mean? My (and your) photos are scanned and analyzed. I've heard literally zero noise about this feature - nobody was complaining (at least not loud enough to let me notice it).
So, why the hell all of that fuzz is being raised now? You're (and mine) photos will be scanned and analyzed AGAIN. Not by humans, by algorithms. In some really rare cases they might be checked by humans, but you 100% will not have troubles with the law if photos don't contain CSAM.
I have 2 kids and I’m not buying that argument “oh my library of naked photos of my child - I’m in danger”. If you are uploading naked photos of your child to iCloud - it's similar to publishing them. Everything that is uploaded to the Internet, will belong to the Internet, and you don't have so much control of it. If, for some awkward reason, you have sets of naked photos of your child and you want to save them - never ever send them to the Internet.
If you think that not-so-experienced users should not know about this rule - I’m pretty sure they don't even know (or care) about this “scandal”. All of that FUD wave is raised by the journalists and echoes on forums like this one.
Apparently tagging 'child porn' on your photos for searching isnt the killer feature someone thought it might be.
How about in 15 years when your small children aren't small? Is this the magical software that can tell the difference between 18 year old boobs and 17 year old? The danger isn't to child molesters, it's to people who get incorrectly flagged as child molesters and need to fight to prove their innocence.
Note: The above assume we're talking about a typical hash of data and not an image-analysis "hash" of what it thinks the content it. This is supported by the language they use.
Yes, it's a bit big-brother. But I already assume the authorities can fairly easily get ALL your iCloud data if they ask Apple the right way.
You know what's creepy AF? Having a private conversation and getting facebook ads the next day relating to the topic. Talk about an acquaintance acting schizophrenic and get ads about medications and treatment for that? Creepy as fuck. And that was on the wifes iPhone - I have Android and didn't get that stuff, but I seem to remember similar incidents where I got ads for stuff talked about. That's serious voice analysis, not just checking a file hash, and it happens when your phone is in your pocket.
Speaking towards what we can assume the authorities can do, we know the FBI cannot compromise an encrypted iPhone because they attempted to force Apple to do that via court order. From what I can tell, the objections to Apple's expanded protection tooling is similar to the objections to adding backdoors to iPhone encryption so the FBI can break into devices used by criminals. It's great to stop the crime today, but how could this be repurposed tomorrow.
This is what I THINK people are worried about. I don't have an Apple device so I haven't really fact checked all of this.
Now it's on _your_ phone in _your_ country. No handwaving, no sticking ones hand in the sand. The only hopeful argument being posited is that somehow this will "make iCloud more private in the long run"