They can't say if it is or not a match so they have to go after the individuals. Is that enough evidence for a warrant?
Someone in the court thinks it's true and can't prosecute?, oh, it got leaked.
--
Not every country has the same protections about innocent until proven guilty. And even then, we've seen cases in the US where someone has been held in jail indefinitely until they provide a password,
- https://arstechnica.com/tech-policy/2016/04/child-porn-suspe...
- https://nakedsecurity.sophos.com/2016/04/28/suspect-who-wont...
And yes, it's true that the governments could always mandate such scanning before. The difference is that it'll be much harder politically for Apple to push back against tweaks to the scheme (such as lowering the bar for manual review / notification of authorities) if they already have it rolled out successfully and publicly argued that it's acceptable in principle, as opposed to pushing back against any kind of scanning at all.
Once you establish that something is okay in principle, the specifics can be haggled over. I mean, just imagine this conversation in a Congressional hearing:
"So, you only report if there are 30+ CSAM images found by the scan. Does this mean that pedophiles with 20 CSAM images on their phones are not reported?"
"Well... yes."
"And how did you decide that 30 is the appropriate number? Why not 20, or 10? Do you maybe think that going after CSAM is not that important, after all?"
There's a very old joke along these lines that seems particularly appropriate here:
"Churchill: Madam, would you sleep with me for five million pounds?
Socialite: My goodness, Mr. Churchill… Well, I suppose… we would have to discuss terms, of course…
Churchill: Would you sleep with me for five pounds?
Socialite: Mr. Churchill, what kind of woman do you think I am?!
Churchill: Madam, we’ve already established that. Now we are haggling about the price."
Apple has put itself in the position where, from now on, they'll be haggling about the price - and they don't really have much leverage there.
Assuming said socialite was not in a committed relationship, why would they not take that money for what must be 30m of effort which may actually be pleasant?
5 pounds on the other hand is not only a small amount of money, but it’s also insulting to ask somebody that’s not a prostitute to sleep with one for such a pittance.
Fictional Churchill was acting like an asshole and the fictional socialite was acting rationally. She only should have replied instead “X million pounds is the best I can offer, but I should certainly hope you are good in bed Mr. Churchill”.
Haven’t they always been able to do that?
>And yes, it's true that the governments could always mandate such scanning before. The difference is that it'll be much harder politically for Apple to push back against tweaks to the scheme (such as lowering the bar for manual review / notification of authorities) if they already have it rolled out successfully and publicly argued that it's acceptable in principle, as opposed to pushing back against any kind of scanning at all.
>Once you establish that something is okay in principle, the specifics can be haggled over. I mean, just imagine this conversation in a Congressional hearing:
So Apple claims your threat model is not technically possible.
Besides, Govt. can just order Apple to hand over the photos themselves from iCloud Photos because those are not end-to-end encrypted.
That's not at all the same as proactively casting a net and starting an investigation based on the results.
Apple has designed the system so that 30 matches are required; they could include more key material in each safety voucher to reduce the number required, or make it only require one match by providing the whole key in each voucher, or forego the system entirely in favor of one without such restrictions (which they can do, given some time, with an iOS update). It isn't "not technically possible" it's just "how they designed it", which is what the poster is saying Congress would ask about.
NB: I'm not in favour of this system - I'm only commenting on this one specific scenario.
That isn't a bug, it is a feature and will be the main use of this functionality.
The "preventing child pornography" reasoning was specifically chosen so that Apple could openly coordinate with governments to violate your privacy while avoiding criticism.
> Perhaps the most concerning part of the whole scheme is the database itself. Since the original images are (understandably) not available for inspection, it's not obvious how we can trust that a rogue actor (like a foreign government) couldn't add non-CSAM hashes to the list to root out human rights advocates or political rivals. Apple has tried to mitigate this by requiring two countries to agree to add a file to the list, but the process for this seems opaque and ripe for abuse.
It's not like China, or India, who not only have huge markets, but could easily hold a chunk of Apple's supply chain hostage.
It's very easy to uphold human rights if it doesn't actually cost you anything.
What do you mean
I live in one of those countries and I'd want to be aware
but actually this is a good starting point: https://en.wikipedia.org/wiki/LGBT_rights_in_Poland
Apple will also refuse all
requests to instruct human reviewers to file reports for
anything other than CSAM materials for accounts that exceed
the match threshold.
[0]: https://www.apple.com/child-safety/pdf/Security_Threat_Model...The only thing they will have gained access to are the “derivatives” (presumably lower res versions) of the matched photos, which if this is done to frame you is strictly the fake CSAM.
If you trusted Apple not to stealthily run such technology before, the question is how much less (if any) you trust them now.
If you didn’t, I don’t think anything changed.
As someone not in the tech field, it is incredibly concerning that half the people here on Hacker News, people who help build this kind of technology, do not seem to be concerned with what Apple is doing.