After criticism, Apple to only seek abuse images flagged in multiple nations
mobile.reuters.com
mobile.reuters.com
This problem is the capability, not what it's used for. Any such capability will be abused by new use cases be it terrorism, drug trafficking, human trafficking or whatever. Plus there will inevitably be unauthorized access.
The only way to prevent all this is for the system not to exist.
I don't buy into theories that Apple is being pressured or coerced on any of this. I believe it's far more likely this is just tone-deaf but well-intentioned incompetence. It's classic "why won't anyone think of the children?" and we've seen it time and time again with encryption backdoors and similar.
The big question for me is how and why Tim Cook and Apple's board signed off on a plan to do huge damage to Apple's reputation and user trust. If they didn't know, it's a problem. If they knew and didn't realize the inevitable backlash, well that's a different problem.
Apple even says it themselves[1]:
> This program is ambitious, and protecting children is an important responsibility. These efforts will evolve and expand over time.
This has totally pushed me over the edge, though I'll admit I was oblivious to begin with. My plan is to replace the MacBooks with a Thinkpad P15 gen 2 running Ubuntu and replace the iPhone with something running Ubuntu Touch (Volla Phone, Fairphone, OnePlus One). Screw not having control.
Or, perhaps they feel really strongly about child exploitation?
In literally 30s looking at your comments it shows that you're an HR and an amateur pilot.
Seeing the number of comments, with slightly more time, your place of residence and political leaning would probably become apparent.
Why am I paying 100s of $$$ to own a device that is adversarial?
we all know this is gonna be dmca 2.0
And you know who that gun is aimed at first?
Apple employees.
Even if you trust Apple and NCMEC to not add out of scope hashes that some government or law enforcement or intelligence agency “asks” them to, does anybody who’s ever worked for Apple have any doubt at all they they’d use this to check employee’s personal devices for Apple IP? Especially if a big spectacular leak hits the media? Apple’s IP enforcement goons are legendary. And not in a good way in most people’s opinion. Particularly Gizmodos…
Kind of surprising how tone deaf Apple's response has been despite this.
When Uncle Bob asks the family computer engineer about the pros and cons of a given platform and hears that one of them scans your device and a false positive could get you arrested for child pornography, Uncle Bob may develop an aversion to that platform.
eta: It makes way more sense to me than Apple actually thinking this was a good idea.
Snowden exposed that Apple was actively part[1] of the PRISM data collection and surveillance program targeting Americans.
Apple also voluntarily gives up customer's data when requested by the US government for about 120,000 individuals a year[2]. They also hand over the data for over 31,000 users/accounts in response to FISA and NSL requests[2] in a six month period.
> eta: It makes way more sense to me than Apple actually thinking this was a good idea.
Based on the company's own messaging, they simply seem proud of the project and find it ambitious[3]. They're also excited about the project's expansion and evolution[3].
[1] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)#/...
We don't know what goes on in the secret courts these days but we have been assured watchdogs are in place and certain programs are no longer in use [1]. This is all speculation based on past behavior, but I assume new reasoning has been constructed that passes watchdog's interpretation of the law but requires new hoops for three-letter agencies to jump through to get the mountains of data they so yearn for.
[1] https://reason.com/2015/11/29/the-nsa-will-stop-collecting-y...
Now it kind of sounds like I'm playing 5D chess, but since we don't know what takes place under secret Executive Orders...
That might make sense if CSAM detection is just the start, and they plan on detecting all those other things, as well.
They got what they wanted. It did sting a bit, but it was calculated.
They won't suffer any massive losses over that, they have the moral high ground among non tech people, who mistakenly believe that they're doing something to protect children.
> The only way to prevent all this is for the system not to exist.
I've been having trouble following this argument over the last week. Isn't it clear that the capability already exists? Whether or not Apple goes through with its CSAM plan, the capability is evidently there.
In other words, since Apple is a closed system, the capability was there before they announced the CSAM plans. Their announcement has changed nothing about capability other than reminding people that Apple has privileged access to the data on iPhones.
I guess the question is, if Apple does the CSAM program does that make them more likely to cave to government pressure to search for other things? And to do so without telling users?
Apple could always go ahead and add that functionality in an update, but then there would be a big backlash and the opportunity to not update or switch providers.
I guess I don't see the huge difference between the surveillance code existing on the phone but not used for objectionable purposes versus the line of code sitting in a different branch in git and not deployed on actual phones (yet).
I'm completely against this move by the way -- I'm not trying to defend it. But I want to be able to argue effectively against it.
Then someone says "what if they change it so it sends the video if someone says 'do you want some pot?'"
And your argument would be "wouldn't you just move if they did that?" - this argument is pointless, because it's not the "help" part that bothersome, it's the always recording camera in a black box, for which you never know what's recording and what's it sending to apple. Let's say hypothetically they do this, and modify the database to trigger on the "tank man" photo, and give that photo such weight, that it triggers manual review by the CCP observer (remember, apple data for chinese users is hosted in china) - you'll never know the image got flagged, you'll never even know that it was sent anywhere, but your social score will go down and you might "vanish" during the night. Imagine some new wikileaks happening... 15 journalists around the world get the data, NSA/CIA/FBI has hacked one of them and found some photos of USA doing something bad.... add those photos to the database, have apple scan all the phones, you find the other 14 journalists, and possible even the leaker who took the original photo. If this is expended to macbooks (which it probably will), even worse, because people keep more sensitive stuff on ther computers than their phones.
And all this for what? Child molesters and rapists (the worst of the pedos) create new photos and videos, that are in none of the databases, so you never catch them. Their direct sponsors (paying customers) get the photos first, and again, before they're in the database. So all you've caught is someone browsing 4chan.
I hadn’t considered that. This would seem to create a market incentive to abuse more children and create a greater variety of new abusive content. Has that been considered at all?
Isn't that exactly what is happening now?
If you think it's bad that Apple can push software updates to iPhones, then by all means make that argument. But "the only way to prevent bad changes to this system down the road is for this first version of the system to never exist" is a very poor argument, given that the only "system" that needs to exist is the ability to push software updates, and that system existed long ago.
Thus this is seen as a marketing backdoor to the actual backdoor. This is seen as a ploy that later gives Apple the plausible deniability argument that the government is making them do it (other forms of content) even though they created the means (on device scanning) for the government to exploit.
Why limit it to content that will be uploaded to iCloud? Why limit iMessage scanning to kids? Why not also let the government know? Why limit it to child porn since the system works for any image? Why limit it to 30 hits?
Any sane marketing person would try to find a way to sugarcoat it first.
Apple relied on that argument 5 years ago successfully.[1]
[1] https://en.wikipedia.org/wiki/FBI–Apple_encryption_dispute
Neither courts nor legislative bodies are capable of explicitly requiring the invention of technology that doesn't yet exist, although in some cases they could make it an implicit requirement of a law.
At least in the US most lawmakers are varying shades of technologically illiterate and don't have a grasp of what is possible or not possible. If technology doesn't exist yet, you can say to them "this is impossible", and with enough of a bribe, they will believe it.
Apple by building this technology, has put it on the map and announced that this technology both possible and is ready.
and then this. Apple intentionally injects uncertainty and controversy? what were they thinking?? sure its just phones right now but im sure mac users are wondering about workstations and laptops? the damage control being spun right now is absolutely overwhelming.
im also surprised to see no other players like MS or Google rushing to take advantage of the outrage. even players like Purism seem to be ignoring the event.
[1] https://en.m.wikipedia.org/wiki/Proles_(Nineteen_Eighty-Four...
WhatsApp has "Save pictures to camera roll" on by default. Someone can send you a bunch of CSAM via WhatsApp and now you are in trouble.
Purism addressed it yesterday[1]. Here's the HN thread[2].
I suspect, with no inside knowledge, that there's someone high up in Apple who feels very, very passionately about child abuse/these sorts of images due to some personal connection, and they are championing the idea internally. And tbh not the worst bugbear to have, but obviously this isn't the way to address it.
As for why the big players aren't jumping on this - it's a tricky line to walk, you don't ever want to be seen as pro child abuse.
Honestly, I’m pretty impressed by what this approach accomplishes. Your comment says this obviously isn’t the way to do it— what’s better than this?
In a legal context where detecting CSAM is a strong requirement, what’s preferable to this approach?
It's not a strong requirement though? Only if the company sees it (unencrypted) do they need to report it, detecting it on-device is wholly different. It would honestly be better if they adjusted their TOS and started scanning the files on upload (on server side). They have the encryption keys already.
Apple is planning to install on all (recent) iPhones software that will let them scan for any image similar (using perceptual hashing) to some set of images. Right now, that's CSAM, and only on upload to iCloud. But what do you want to bet China is salivating at the idea of including images of Tank Man and other "seditious" content? And maybe checking images anytime they're added to the phone, or sent to someone else, not just up to iCloud?
It completely ruins the idea that Apple has your privacy/security in mind.
According to that article, in the last year Apple only submitted 265 reports to the NCEMC while Facebook submitted 20 million. Would law enforcement believe they'd be missing out on catching abusers after seeing this disparity?
If a company is found to allow criminals to store CSAM on their servers for extended periods of time, the law is going to want to know why they let it pass, irrespective of the extent the company chose to scan for it. Apple probably doesn't want to deal with that fallout, so maybe they figured that being proactive about scanning for CSAM in a way that could enable the use of E2EE wouldn't hurt, and that pushing the privacy narrative would satisfy enough people - which it didn't.
[1] https://www.nytimes.com/2021/08/05/technology/apple-iphones-...
I'd bet dollars to doughnuts that AWS, GCP, Azure, et al. have terabytes of CSAM stored within their data centers - because users have uploaded encrypted files and the companies (rightly) don't have the keys. I'll also bet there are many WD hard drives full of CSAM, many Linux servers hosting it, many nginx or apache installs serving it up, etc. Should we mandate that all hard drives scan files as they're written to see if it's CSAM? Or maybe nginx should alert law enforcement anytime a CSAM image is served.
Apple should have actually let their users have E2EE or given up on that and just scanned stuff server-side.
I'll go one step further. Apple should have implemented a system that makes these kind of backdoors impossible. I don't know how or if such a system is possible, but given Apple's track record, they are in a position to attempt it.
Signed updates (which they already have) that are not designed to spy on their customers and bog-standard E2E would achieve that.
But then they couldn't even scan the stuff on icloud.
"Do us a favor or the AG launches an investigation into your business practices."
We know TV makers scan what you watch, even from other inputs, for ad targeting. This sort of capability is already widespread and basically a commodity - who else is using it that hasn't told us? And can we do anything about it short of only using hardware and services where trusted parties have verified the source?
Comments like this make me wonder how in touch HN is with the average person because I genuinely don't believe most people care or even know that this is happening. I may be wrong but Apple could've pretended this backlash doesn't exist and did nothing about it and they would lose nothing for it.
I think a lot of people blindly trust Apple as a reputable corporate entity and this definitely shakes that trust.
Of course they were.
It’s well known that Apple chose not to introduce e2e encrypted iCloud backups back i 2017/18 or so, due to FBI complaints.[1]
This is clearly Apple’s play to be able to introduce that again and tell law enforcement “Look, we ‘thought of the children’, if you want further access to our customers data, you’re going to need to come up with a better justification than that.”
If Apple pull that off, adopting client side image scanning with this quite impressive privacy preserving system behind it, and then e2e encrypt everything they upload to iCloud, that’d arguably be a very big win for Apple customers privacy.
Whether that’s an acceptable trade off for having a device I purchased run code I didn’t ask for and don’t want to monitor where or not I’m a paedophile, possibly snitching on me for false positives or bad-faith additions of non CSAM hashes into the database, or not is a good question still.
1: https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
"Make it so we are the only ones on that list, or we ban iphones in China".
This is the time to make a donation to a foss project related to the Linux desktop. Off the top of my head, there is Debian, Ubuntu, mint, gnome, plasma, the fsf, wine, or other projects that could use contributions of code or cash. It adds up and could help one of them hire an extra full timer if enough people set up recurring donations
Their point is that they don't care about that other point.
The prosecution can hire more expert witnesses with excessive credentials than you can, and they will explain how there's a one in one trillion possibility that the system is wrong, and that the defendant is assuredly a monster.
Juries eat that up when it comes to bogus DNA, bite mark, fingerprint, or other forensic evidence claims. Most people think computers can't be wrong or biased, and people's perceptions of what can be deemed reasonable doubts or not seem to shift when computers are involved, or when smart, credentialed people tell them their reasonable doubts aren't reasonable at all because of that one in a trillion chance of the computers being wrong.
² - reason for the scare quotes is because I have first hand knowledge of non-CSAM content being in NCMEC’s database (most likely via data entry errors, but I can’t be for sure).
Ha! Come to think of it, I think that was one example. The main examples that came to memory (it’s been almost 8 years since I was involved) when discussing this last week were essentially extremely common photos (like the stock Windows XP background, among others).
If they don’t kill this program soon, it’s going to overshadow the entire upcoming iPhone event, and will follow Apple around like a dark cloud for years.
I can see the headlines now: “New iPhone launches amid massive new privacy concerns.”
Anytime someone praises Apple for privacy, anywhere on the internet, there will be a tidal wave of people bringing up this program in rebuttal. From people who would have previously defended Apple to the grave!
I cannot fathom how on earth anybody thought this was a good idea. It’s like taking decades and billions of dollars worth of hard won reputation for privacy and throwing it in the garbage at the worst possible moment.
My two concerns are that Android as an ecosystem is almost certainly still worse, and that the vast majority of users will not care.
I’m tempted to jailbreak my devices going forward, although I guess the folks at Apple would say that makes me a pedophile.
Edit: seeking recommendations for Android phones with strong performance and reasonable privacy protections. Ideally one that can be used without a Google account.
I just recently migrated everything to Apple + iCloud, but now it appears to be time to switch to synology+pixel/graphene+Firefox
Apparently obsidian.md can be end-to-end encrypted through their service, for anyone else planning to ditch iCloud.
Unlike Apple, Android devices are not vendor locked into just one OS.
How gullible Apple users are to think that their closed-source ecosystem was ever about privacy, but I still don't think they'll learn. It is a cult and will continue being a cult.
I've talked around and nobody I know is even aware of this, when I brought it up, they didn't care about the issue.
It's not news in the commons, it's not on CNN, Fox or MSNBC right now as a headline.
It's one of those tertiary concerns that frustrates some groups, but most people are not aware and would only marginally maligned, and a good 2/3 of people really don't care. I suspect most people would have a difficult time with the 'slippery slope' issue and would accept the 'it's for the children' terms at face value.
It is what it is, but it's worth understanding how regular people think about these issues.
“Apple creates authoritarian government wet dream” will be the main narrative coming out of the iPhone event. Not the new phone. And investors will not be happy.
It’s the on-device scanning that is the massive overreach. It’s like being forced to allow a government employee to live in your home and watch your behavior 24/7 for anything they don’t like.
“Oh but John is only looking for specific bad behavior like drug use, you don’t have to worry. He would never report you for anything else, we promise! If you have nothing to hide, you shouldn’t be upset that John is living with you now!”
The large number of people here who want iCloud to be E2E have a problem with it.
> (don’t they do it already?).
Apparently not for files and photos. They may well do it for email.
The fact that WSJ did a story on this with and a lengthy interview with Apple SVP means this is already a mainstream story.
Look at Google trends data for the search term “Apple.” It spikes every September by like 70% for a week.
I can guarantee you, every average joe learning about the new iPhone from mainstream media, is going to hear a sound byte about this fiasco as well.
I’ll be surprised if this program isn’t dead within 2 months.
They can just go along with what other cloud storage providers have been doing all along... that is, "we won't snoop into your phone, because that's yours. but if you upload photos to iCloud, onto OUR servers, then we reserve the right to scan for images in CP database.."
And I think most people will be perfectly fine with that idea.
Just like you sign away some rights and accept risk when you decide to store items in physical storage facility, same thing will happen when you use iCloud.
Nobody is against them trying to prevent child sexual abuse, pretty sure we all agree that fighting that is important, but doing so by creating what is essentially a back door of sorts into my devices isn't the right approach to doing so.
It sounds to me that this is still allowing them that access, so this changes absolutely nothing.
What do you think will happen when e.g. the Chinese government demand that they scan all photos for hashes provided by the government, upload them regardless of whether iCloud is enabled, and let a Chinese company handle the reviews? If they couldn’t stop the CCP from gaining full control of iCloud in China then they most definitely can’t prevent this either.. and other authoritarian governments will copy the CCP and make similar demands.
Scan every single file. I don't care. Because once in iCloud, files are sitting on Apple's server and hard drives. I don't have much expectation that those files are 100% private.
They're completely missing the point.
The perceptual CSAM hash database is included, in an encrypted form, as part of the signed operating system. It is never downloaded or updated separately over the Internet or through any other mechanism. This claim is subject to code inspection by security researchers like all other iOS device-side security claims.
Could someone tell me how that inspection works? Are there researchers who are given the source code?
[0]: https://www.apple.com/child-safety/pdf/Security_Threat_Model...
> the Finnish National Bureau of Investigation (NBI), had compiled a secret blacklist of websites that it deemed to contain child pornography and sent it to Finnish Internet service providers.
> Analyzing the address list, Nikki also noted that the first three Google search results for "gay porn" are censored. Electronic Frontier Finland (EFFI) have noticed that the blacklist includes non-pornographic websites also, including a Windows advice forum, a computer repair service and the Internet Initiative Japan server nn.iij4u.or.jp that, among others, hosts websites for a violin factory, a doll store and a hearing aid manufacturer.
> This program is ambitious, and protecting children is an important responsibility. These efforts will evolve and expand over time.
People don't want their property spying on them and reporting them to the police. They don't want people looking at their photos or thumbnails. It's patronizing, invasive and embarrassing to have your privacy violated like that.
Security Threat Model Review of the Apple Child Safety Features [pdf] (apple.com) https://news.ycombinator.com/item?id=28173134
> Building a version of iOS that bypasses security in this way would undeniably create a backdoor. And while the government may argue that its use would be limited to this case, there is no way to guarantee such control.
How ironic of you, Apple
They are probably completely flabbergasted that people are upset about this so they make this change after a week, completely missing the point.
Go back to their response over the iPhone 4 reception problems ("you're holding it wrong"), same asshole culture then as now, and that culture has been in place for decades:
https://www.engadget.com/2010-06-24-apple-responds-over-ipho...
(Hard to find a good citation link on a phone, bit the story's out there.)
This sounds like one of those errors where they double down on it and call it a "solution".
Sounds like they're misunderstanding people's concerns pretty badly. Sorry if we miscommunicated. Kill this "feature" yesterday. Thanks Tim!
Expect an App Store rule soon - all photos apps must scan for CSAM.
In a year, expect Signal to be banned from all app stores, just like how it's already banned from some countries.
I'm hoping for something along the lines of "iOS will reject hashes that haven't been signed by independent organisations in US, Russia, China, and India" to make it very difficult to push through anything except actual CSAM. Won't be much of a guarantee if it's just Apple saying "we promise we're only using hashes that have been checked by Australia and the US".
They've really bought into a ton of complexity at all levels by doing this instead of just scanning stuff on their own servers, which would at least have been a clear dividing line. Privacy is really all about control, and on-device scanning dangerously blurs that line.
Almost no one held the National Center for Missing & Exploited Children in low regard prior to last week. Why would we? It's one of the best, most noble causes that have ever existed.
Then, Marita Rodriguez, an executive director at NCMEC, reassured employees in an internal memo that was unfortunately leaked:[1]
"I know it’s been a long day and that many of you probably haven’t slept in 24 hours. We know that the days to come will be filled with the screeching voices of the minority.
Our voices will be louder."
The "screeching voices of the minority" phrase got picked up and (perhaps unfairly) has become a kind of rallying cry, exposing the arrogance of the NCMEC.
I say "unfairly" because I do believe that their hearts were in the right place with this initiative, although they are desperately naive when it comes to the principles of privacy. "Let's save the children - how can we stop this toxicity of child porn - let's set something up with the cloud providers!"
But the damage has been done. Now the only tenable outcome is for Apple to simply cancel the project.
I, for one, was looking forward to upgrading from an Android to an iPhone 12 Pro Max later this year. That plan is now on hold! I doubt it will affect their sales too badly, at least at first. Maybe it will after the Chinese government starts using the back door to round up dissidents, or some Middle Eastern governments use it to crack down on homosexuality, or... the mind boggles.
[1] https://www.howtogeek.com/746588/apple-discusses-screeching-...
So what's gotten better by this? In the kindest interpretation, you'll be safe from Fascististan's hashes. But what if Fascististan has been bribed by China or the US? And so on.
A line which should never have been crossed was crossed.
https://en.m.wikipedia.org/wiki/Foreign_Intelligence_Surveil...
[1] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)#/...
Security Threat Model Review of the Apple Child Safety Features [pdf] (apple.com) https://news.ycombinator.com/item?id=28173134
The key issue here is the very concept of "Apple turns your iPhone into a snitch", and I haven't seen any misunderstanding around that.
There is no misunderstanding of that fact by anyone with sufficient technical know-how. There is also no misunderstanding of what comes next once this Pandora box is opened.
Currently, bad actors are randomly sharing illegal content in an unsolicited way to people who did not ask for it (1).
Let's imagine this happens to you. Suddenly, you have illegal content on your device you didn't ask for.
Maybe you are busy when the message with the content is received and you don't even know about it, or you think it's random spam from someone you don't know and just ignore it.
Then, the content scanner picks it up and notifys authorities.
What will happen in this scenario?
(1) https://www.news4jax.com/news/2018/02/05/beware-child-porn-m...
To be factually accurate, the commenter didn’t mention a number. Sending 30+ images of anything to someone’s number is trivial.
1. Devaluing general-purpose computing.
2. Disposable devices with soldered-in batteries and no upgradeability.
3. Removing headphone sockets so they can nickel-and-dime with irritating dongles and ridiculously expensive wireless headphones.
4. Disallowing personal backups using your own key to incentivize the use of expensive icloud storage.
5. App-store corruption.
6. Dodging tax in my country.
7. A million examples of shitty hardware design and then blaming the customer somehow, eg "you're holding it wrong", dust-attractant garbage keyboards, overheating gpus, etc etc
What a shitty, penny pinching piece of shit company. The most expensive devices and they still want to squeeze their customers more.
Literally everything they do trades privacy/usability for money, and the cherry on the shit sundae is always insulting their customers intelligence by somehow claiming it's for their own good.
And now we get probably the very worst thing they've done:
7. Legitimizing on-device scanning and adversarial devices.
I dearly wish they would go out of business because they're ruining technology, something I've loved my whole life.
I never even bought one of their bullshit locked-down garbage disposable devices and they're still ruining things for me with their influence on the market.
Fuck you, Apple. Fuck you in every way. You're the worst hardware manufacturer and the worst software manufacturer.
Go to hell.
Lets push that idea so allies in the government can go looking and void it
I think they commented because they expected a brief storm of outrage that quickly dies down, but instead it has become a growing wave that is spilling into mainstream media, with a mostly negative reaction, and threatening to completely destroy their "Privacy. That's iPhone" mantra that has been the core of their marketing campaign this year.
For example imagine creating a new tax for 1% of purchases. People would be outraged. Now imagine raising sales tax instead by 1% (ex 7% to 8%.) Sure some people would be upset, but it would be a smaller number than the "new" tax. The reason is because people are already used to paying a sales tax. What is "normal" is more easily accepted.
If Apple can get past the initial outrage (like when sales tax was implemented in many countries in history) they can increase the surveillance once scanning local files becomes the "new normal".
It's quite simple: the culture of bureaucrats that have dominated Washington DC and its policies in the post WW2 era, they acquired a position of power the likes of which has rarely been seen in all of human history. Now, ask yourself: do you really think they're ready to give that power up? They're ready to stop treating the rest of the planet like it's their toy, to do with as they please. Then ask yourself: what do you think they're prepared to do to stave off risks to that power? The risk that they might lose their precious. And there you go, you have your answer. They're willing to do many of the same things other authoritarians have been willing to do. The US isn't Soviet Russia, that's not the suggestion; it doesn't need to be to start putting political opponents (fringe rabble rousers; whether libertarian or socialist - see: Clinton vs Sanders; that's globalist establishment vs domestic socialist) into prison and surveiling everyone in a desperate attempt to retain their power. That kind of power is an intense drug, they're addicts of the worst kind, you can tell by how they behave in regards to the rest of the world, how they treat the rest of the world.
To ensure they keep their power, to keep their globalist forever war machine (and everything that goes with it), they need to put the boot on rising domestic risks to that power.
a) it means they have to publicly admit that what they did was a bad idea, which will fuel another news cycle
b) backing out of it will get them criticized for "protecting pedophiles", maybe even the NCMEC (who privately praised them in the "screeching voices of the minority" memo) will now publicly criticize and shame them to get what it wants
c) now that they've put this idea on the table, there will be even more government pressure to mandate/implement it. Even if they back out of the implementation, just by bringing this proposal up, Apple may have just destroyed not just the privacy of their users, but of everyone.
If the problem is "We need to scan stuff on iCloud for CSAM" then "Let's build a client-side scanning agent and distribute it to hundreds of millions of devices and figure out a way to protect the hashes from the end user and then figure out a way to lock it down so it can't be used to scan other things even if we wanted to or somebody ordered us to" is a singularly (and suspiciously) inelegant solution to the problem.
Just scan the files on your own servers, like everybody else does. Anything else is rightly going to make people suspicious that you've got some ulterior motive.
Right now, they have to hand over anyone’s photo library if they are ordered to do so.
If they turn on E2E that will no longer be possible, and this will be strictly better and harder to abuse.
That doesn’t mean this mechanism isn’t offensive. It just is better from a privacy point of view for them to do this and enable E2E.
So the reasonable approach is to make clients that only upload photos that are not CP. The problem is that the implementation of that feels creepier than they anticipated.
My bet is on Canada, UK, Australia, and New Zealand.
While Apple deserves all the fallout they're getting and more, I'm disappointed that the NCMEC that pushed for this isn't also receiving more scrutiny and criticism. Multiple people have now pointed out that their database contains false positives, which is absolutely terrifying. Completely legal, harmless, no-nudity-no-humans pictures can get your life ruined. The truth coming out later doesn't matter when your home gets raided and it slips out that you were caught sharing multiple images that matched hashes from the NCMEC child porn database.
I’m going to actively evangelize alternatives to Apple devices and that’s coming from someone who has been doing Apple evangelizing since OSX Panther days. Tens of thousands of dollars of bought devices and services not including all the people I convinced to make the switch over the years.
I’m sure I’m not the only one in this regard.
Android probably is not much different. But and this a big one, android devices are not tied to the host google OS and are waaaay way more open than Apple. This is because of Apple's ir tight grip on their hardware ecosystem and lobbying against right to repair. Also, the abundance of android phone makers means you get features at a variety of price points.
The OS options are LineageOS (my daily driver), CalyxOS worth more google support, microG lineage.
More different OS are Ubuntu touch (very active), postmarket OS with multiple frontends just like on Linux desktop, Manjaro Mobile, etc.
And hardware wise, there is Pine phone and Purism. But the more people paying for these, the more there is money for the competition.
Apple id already sitting on a staggering $200billion dollars. $200 billion.
And I would also like to get some real numbers about children abuse cases compared to drugs/domestic/gangs/organized/etc. crimes. In other words, how much they impact the society. Wanna bet that in the world there are for example a lot more normal citizens abused by the police every day than old men wanking to a kid picture? When will come the scanning of cops iPhones to catch the "bad apples"?
I'm very serious. Child abuse is a cancer and must be stopped, but if they're employing all that technology for this and not for that, well, dear Apple, I want to see some numbers that would justify the choice.
And don't reply "even saving only one child is worth ... yadda yadda yadda" You know what I mean.
[1]: https://www.apple.com/customer-letter/
Chilling indeed, Tim, chilling indeed.
Soon your pictures will be subject to a 3-week review period to decide whether they 're fit to be scanned
The platform is not in danger. But if it were, then yes, I think they'd still risk it. It's either that or getting shut out of markets gradually by law enforcement and governments.
How come that's not happening to desktop Linux then?
Personally I do think it's likely we'll see a successful anti-Linux smear campaign and/or laws in the next few years, but I have to admit that's a pretty pessimistic take.
It's somewhat funny to me that switching to a Mac and eventually to multiple Macs is what had me thinking that I could probably be fine just using Linux for my day-to-day computing that doesn't involve gaming (I've a Windows desktop for that) and now this has me thinking "yeah, I can pretty much make the switch and realistically not feel like I'm missing out on too much, anyway.".
If Apple says "we heard the backlash, we're sorry, we'll never do it again", I'll be more of a supporter than I had been before.
Until they do, trust lost.
It's the practical scenarios where people in the United States have previously been indicted and their lives ruined over "child pornography" or "statutory rape" that stretches the definition to the breaking point. Young men just barely 18 years old have gone to jail because they have taken pictures of their technically under-aged girlfriends. Often their real crime is that they've simply upset someone rich and powerful, or that they were guilty of being black and dating a blonde white girl. I wish I was being facetious, but this happens all the time.
More importantly, in this digital age, many stupid teenagers upload nude pictures of their under-aged girlfriends to the Internet. Sometimes as revenge for the girl breaking up with them, sometimes because they "hacked" a girl's account and downloaded their selfies, or they legitimately have the photos and just wanted those sweet internet karma points.
Imageboards like 4chan are full of what is technically CP, even though nobody was directly harmed in its creation. Other stupid teenagers download these photos, as do older paedophiles that trawl these websites looking for CP. Some of them will share it with other paedophiles, internationally even.
So what happens if one of these paedophiles gets arrested for a serious child sex crime? Their PCs and their phones will be searched, and the pictures will end up on the CP hash database, of course. Even with this "multiple nations" requirement, that just requires two arrests for the hash to be added. Nothing really changed, there's just a delay.
Now what will happen to the stupid teenagers that downloaded the same photo? Teenagers that aren't child molesters! Teenagers that aren't paedophiles!
Apple will probably say: No worries, we filter out the phones belonging to under-aged children from the results.
... until they turn 18.
Get it? This is a legal landmine in the pocket of every stupid kid. YOUR stupid kid, that looks at porn on the internet, just like every other stupid kid.
This is just one scenario where this could lead to a false positive that totally and irrevocably destroys someone's life. I can think of several more, and dozens once you start adding the political pressure from various other nations.
There is just no way to make this kind of dragnet surveillance safe. Even a tiny false positive rate is unacceptable when there are hundreds of millions of people playing this distopian lottery.
Furthermore, I am fairly sure NCMEC’s due diligence process involves confirming the depicted individual was abused.
[1] https://www.missingkids.org/theissues/csam
[2] https://www.hackerfactor.com/blog/index.php?/archives/929-On...
How many people have to lose their lives in the service of some pedantic idea of "privacy"? It's a computer looking at it, it's not even a human person.
I think tech companies need a hippocratic oath similar to "first do no harm". Apple should not be engaging in misinformation trafficking, and should at the very least be working to minimize harm by preventing people form falling victim to dangerous, unsubstantiated, and un-fact-checked information. This is especially important when our elected officials use the considerable power that has been gifted to them by the people to put peoples' lives in danger by spreading dangerous misinformation.
What role did apple's inaction on this have in the pandemic? In the January 6th insurrectionist's attempt to overturn a validated, secure, and duly certified democratic election? What role did Apple's inaction play in the attempted kidnapping of the governor of Michigan?
By refusing to help, they are partially responsible for these things. It's time for us to demand that they do their fair share of helping. Inaction is itself an action.
--
This is sarcasm, of course. For how long?
By this becoming such a hot topic, I think this will push the activity to more underground.
I bet most people didn't even know that other cloud companies did search for CP.
How many children is this going to protect, to weigh against the loss of privacy across the whole userbase [in US] [for now]?
It does mean that Apple is able and willing to manage country-specific blacklists.
GHCQ agent 2: No worries we got you covered we’ll add it to our list as well.