Apple's bright idea for CSAM scanning could start persecution on a global basis
theregister.com
theregister.com
Policy groups ask Apple to drop plans to inspect messages, scan for abuse images - https://news.ycombinator.com/item?id=28230248 - 284 points, 1 day ago, 190 comments
Policy Groups Urge Apple to Abandon Building Surveillance Capabilities - https://news.ycombinator.com/item?id=28232068 - 92 points, 1 day ago, 25 comments
Policy groups ask Apple to drop plans to inspect iMessages scan for abuse images - https://news.ycombinator.com/item?id=28231094 - 33 points, 1 day ago, 3 comments
I find exceedingly difficult to imagine that one of the most sophisticated companies in the world, with some of brightest minds out there, did not consider and calculate this precisely; that there is any way any of this has come as a surprise to Apple. Extending Apple the benefit of doubt does not seem possible in this case.
Yesterday we saw OnlyFans exit the adult industry. Two weeks ago we saw Apple exit the privacy industry.
EDIT:
Some are questioning whether Apple was ever in the privacy industry. That's a good question. Even though their devices were certainly not secure and could be compromised, I think they were certainly in the privacy industry in the sense that they marketed an intention to make their devices as private and secure as possible[0]. Which is basically all a consumer can ask from a computer company.
[0] https://9to5mac.com/wp-content/uploads/sites/6/2019/01/DwGoq...
https://mobile.twitter.com/benadida/status/14247649237170667...
> I don’t see a huge threat to privacy, but I’m not sure how this meaningfully stops CSAM. My guess: Apple is trying to stave off more heavy-handed gov intervention. Thread:
This is an interesting and charitable interpretation, but if so, then this tactic will fail.
As others here have pointed out: with this capability in place, the only thing stopping them from total intrusion is now merely policy. And that's scary and dangerous.
I just can’t even begin to imagine what a gigantic company like Apple’s real government relations are like however.
Downloading the list outside an iOS update would be a new 'feature' just for China. If we're in that mode, then Apple could also have just added scanning for only China.
Finally, the list is an intersection from at least two jurisdictions.
I think there is plenty of good debate to have around this feature, but I also think it's important to start with the discussing the feature as is today.
https://www.marketwatch.com/story/apples-hot-antitrust-autum...
Given that fact that Snowden’s revelations didn’t generate ANY actions within the public, I doubt to see any actions this time.
One is political give and take. As their people negotiate with particular political actors, "We'll give you nothing," works much less well than, "We can't give you X, but how about Y?"
The other is that the tech giants are looking unaccountable and antisocial. Privacy absolutism is popular here, but there are real social costs to it, so it's not popular everywhere. If Apple can say, "Yes, privacy is important, but we're not crazy; we agree we don't want to help out child pornographers", then that is much better positioning.
“After the 2016 FBI–Apple encryption dispute, Feinstein and Richard Burr sponsored a bill that would be likely to criminalize all forms of strong encryption in electronic communication between citizens”
Source: https://en.m.wikipedia.org/wiki/Dianne_Feinstein
She was on senate subcommittees that handles all sorts of legality for technology companies.
* Subcommittee on Crime and Terrorism * Subcommittee on Immigration, Border Security, and Refugees
* Subcommittee on Privacy, Technology and the Law
* Subcommittee on Human Rights and the Law (Chair, 117th Congress)
From her gov CV page: “The Judiciary Committee has one of the broadest jurisdictions in the Senate, ranging from criminal justice and immigration issues to antitrust and intellectual property law.“
Source: https://www.feinstein.senate.gov/public/index.cfm/thejudicia...
Again: > In the United States, there is effectively nobody in this position. The committee hearings on anti-trust and encryption have little overlap between interested parties or ideology.
> there is effectively nobody in this position.
Wrong. There are people and Feinstein is a great example of someone who worked quite hard to kill encryption while also being on various committees handling anti-trust.
If her anti-encryption bill passed or if she was able to push through some anti-trust through the Judiciary committee she would brag about it in her reelection campaign.
Feinstein is perfect model for someone who would gladly tout her legacy while on the judiciary committee and equally her accomplishments on a national security subcommittee.
You are wrong sir, now tuck your tail and go away. I’m done wasting my time with you. But now I know you quite well, you are a narcissist and you have to have the final word. So go ahead and prove me right…
I ask that question in curiosity but I'm super skeptical because this is actually surveillance.
Really, it’s probably the best way to keep the police state from destroying your business while trying to sleep at night.
Microsoft Zune. The Super League. 47 Ronin. Wonder Woman 1984. Google+. Big companies make big mistakes. No matter how many focus groups you collect, no matter how many phone surveys you do, things can go wrong.
https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
I wonder of the same is true re (broadly) government power. Tech companies are now balancing the power governments and other stakeholders would like them to wield with what people will tolerate. Its not really a surprise there are missteps again.
Clearly the majority opinion here (and mine also) is the first of these is worse, but it's not like I can't understand how people who believe the second is worse came to that opinion - I simply disagree with them.
The actual negative implications are slightly worse battery life and more network traffic if you use iCloud. The upside is people can inspect the perceptual hash. Also, the phone isn’t reporting anything it doesn’t have the database to compare it to.
- It’s not that bad (60% metacritic, 59%/73% Rotten Tomatoes)
- It at least broke even ($100MM lost theatrically, but during covid, and made up for by new HBO Max signups)
- The third WW movie is still happening
Sure? [1] says budget $200M, all-time worldwide $166M - given marketing of $100M (cheap, normally considered 2x the budget), those HBO Max signups would have to be $134M; which seems like a lot considering they only have about 13M subscribers[2].
[1] https://www.the-numbers.com/movie/Wonder-Woman-1984-(2020)#t... [2] https://www.businessinsider.com/wonder-woman-1984-helping-hb...
[1] https://www.hollywoodreporter.com/business/digital/hbo-max-s...
If it is on that list, there were mistakes made. I just pulled two titles of movie that, beyond being flops, I myself saw and did not like.
Why is that so difficult to imagine? Apple's security model has always been "just trust us and don't question it", questioning their own practices themselves just has never been done.
That's already what's happening with any other Apple software, their own services are off limit of their model, explicitly excluded & explicitly trusted. This opinion is also reflected in their security threat document they published, they never talk about themselves being in the list of potential threats.
That's just in the continuity on how they usually work.
Edit: It's also notable that news of this was leaked before Apple was able to officially announce anything. This means that Apple's marketing department was not able to control the tone/narrative as well as they normally do. The first thing many people heard was "Apple will be scanning your phone" without any of the nuances that came later.
iPhone is packed with software literally named "Digital Rights Management"
Tech companies have been left unregulated for so long and now governments have noticed how pivotal they are, that tech companies are trying desperately to head off regulation with self-regulation.
Just look at the mixed reactions to GDPR here on HN to see how controversial is it when governments do actually regulate things, it's not hard to understand that tech companies are eager to head that off.
Then in 2020, there was the EARN IT Act proposal, which nearly passed and would have required scanning for CSAM on pretty much every online platform that wanted Section 230 immunity.
Apple puts two and two together, realizes Congress is concerned about CSAM's spread and isn't interested in changing, and still wants E2EE on iCloud. OK, put the scanning client-side, then the way is paved for E2EE iCloud because the FBI's biggest argument against E2EE is neutralized, and so is Congress' argument for EARN IT (which would basically have banned E2EE).
http://cyberlaw.stanford.edu/blog/2020/03/earn-it-act-uncons...
2. If they scanned iCloud, they could never start encrypting that.
Did somebody raise the concern of push-back? I'm sure. But the moral questions around CSAM are something that was settled long ago internally. When I was at Twitter fighting abuse, the CSAM stuff was a separate group. My boss called them The Department of Mysteries because we almost never saw them or spoke to them. It was led by a serious person, an ex-FBI agent or something like that. They did what they did and we were all ok with it and grateful for it, because that shit is horrific and we didn't want it on our platform and we didn't want to have to deal with it ourselves.
My cousin was a PO for sex offenders, and one of our regular discussion topics at family reunions was how sex offenders were way more technologically savvy than a state parole department. How they really needed more help in making sure offenders weren't reoffending while on parole, while also not forcing them to just not use computers and phones altogether. If even I've heard this, I'm sure that Apple execs have heard it from law enforcement a zillion times.
It's also clear Apple put a lot of thought into addressing the privacy concerns for this. Technologically, it's sophisticated, impressive.
So I can easily believe the people at Apple said, "Sure, there are reasonable concerns, but we think we have addressed them." And that they're surprised by the level of sustained pushback.
> It's also clear Apple put a lot of thought into addressing the privacy concerns for this. Technologically, it's sophisticated, impressive.
I'm not sure about this. How is a perceptual hash sophisticated and impressive given that it can be abused by governments demanding Apple scan for political content, etc?
Now, will China follow this? Probably not. But Apple's defense there is that China could have directly ordered them to build this scanning tool at anytime in the last decade anyway. It's not like China has a magical new tool for invading privacy when they could have (and actually have) just ordered tools to be built as desired.
It's quite possible that countries would do the same thing interested parties on both sides are accused of doing with membership and voting in the International Whaling Commission: find countries that have no interest in the matter either way, and buy their support (or in this case, their addition of images to databases), which can be quite cheap when the matters don't actually affect the country.
"Five Eyes" ring a bell?
As it's setup today it can't be. The list is the intersection of at least 2 jurisdictions, and is only checked when items are going to iCloud.
Of course this could change, but it's important to recognize what it is now vs. speculation about what it could become.
> incurious
Hurts to read this. But maybe you're right: my mind kind of shut off when I read the abstract (client side scanning). I can't say I've looked into the details.
It doesn't make the whole system any less fundamentally flawed, but I think the technical "Wow!" factor certainly helped many people be OK with it. In this view, the shiny new PSI system is a trojan horse for the totally unaccountable and opaque hash set that they've feeding into it.
It's pretty sophisticated when you look at everything implemented and also consider the infrastructure / review pipelines that are required. See the link below:
https://www.apple.com/child-safety/pdf/Security_Threat_Model...
It's based on perceptual hashing, but the whole end-to-end system is clearly sophisticated when operating on Apple's scale.
All those things can make things interesting and sometimes misfire in a form of an idea that is not received that well in the real world.
1. Photos (and other documents) are currently uploaded to iCloud un-encrypted
2. These photos are already scanned for CSAM after upload
3. Because the photos are not encrypted, at any point, any government can file a court order to release those photos.
4. The court order can require Apply to not notify the user, or the public in general.
5. [Speculation] Such orders might already exist and be somewhat common within Apple
Apple wanted to fix this and introduce end-to-end encryption on all photos uploaded to iCloud, but scanning for CSAM was non-negotiable (due to internal or external politics?). They must keep doing it.
So they implemented this big mess of a workaround to scan for CSAM before upload and attach a cert with a decryption key only to photos that match so that they could later human verify once a user had enough matches and weed out false positives (which Apple acknowledge will happen) before notifying law enforcement.
Because of the direction that Apple came from, and how much effort they put into designing this system to maximize privacy, they saw this solution as a large privacy win over the existing situation. It's not surprising Apple might have been blinded to the privacy concerns of doing AI scanning of photos on user devices, they were looking at it from the wrong angle.
Maybe they have restarted those efforts, but with some modifications (like this?). It's hard to tell since Apple is a very secretive company, but the exact design of this system does strongly suggest end-to-end encryption of photos. (Why attach a decryption key to positive matches if the photo isn't encrypted?)
I guess it's also possible this was a project kicked of years ago before they abandoned the idea of end-to-end backups and it lived on as a zombie.
BTW, while I see Apple's PoV here, I don't think I agree with it. I think I'd rather they stick with the status quo. I'm curious what other people prefer: un-encrypted and subpoenable iCloud photos, or on-device CSAM scanning?
[1] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Apple has not come out and said this.
This may be what people hope is the motivation, but I would think they would be immediately coming out to say this if it were the case, as it could be used as ammunition against some of the criticism they've been getting recently.
But I'll point out their technical summary[1] explictly talks about attaching decryption keys to positive matches, which you don't need to do if there is no end-to-end encryption.
[1] https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
No, they are encrypted, just not e2e. Apple holds the encryption key, though.
> 2. These photos are already scanned for CSAM after upload
No, they are not.
> 3. Because the photos are not encrypted, at any point, any government can file a court order to release those photos.
Not because they are unencrypted, but because Apple can decrypt them on demand, since they gold the key(s).
Incorrect. Photos and documents are encrypted both in transit and at rest. They are not E2EE, however - i.e. Apple has decryption keys.
> 2. These photos are already scanned for CSAM after upload
Apple does no scanning in iCloud. All of your data (except email) is stored encrypted and it cannot be scanned. Apple escrows the decryption keys, which are provided only to comply with legal requests for user data.
> 3. Because the photos are not encrypted, at any point, any government can file a court order to release those photos.
The second part is true, but the first is not.
> 4. The court order can require Apply to not notify the user, or the public in general.
This is simply the law. If there is no non-disclosure order, it's Apple's policy to notify.
iCloud encryption docs: https://support.apple.com/en-us/HT202303
Legal process docs: https://www.apple.com/legal/privacy/law-enforcement-guidelin...
And yes, Apple have been scanning uploaded photos since about 2019. At least, that's when they modified their terms and conditions to allow it.
https://www.macobserver.com/analysis/apple-scans-uploaded-co...
If Apple were scanning iCloud Photos, one would expect there to be hundreds of thousands if not millions of reports to NCMEC (last year Facebook reported 20 million). Reporting is compulsory, the information is public, and Apple reported 265 last year. Do the math. Apple is not scanning Photos.
I have my issues with Apple. But they have such a deep tradition of user research and customer focus. When they tell customers what they want, it's often because they have really good data indicating it's what customers do want but don't totally know it yet.
One of those two statements I disagree with.
Apple exiting the privacy industry would look like this to me: "we've decided from now on that, like almost all other cloud providers, we'll give ourselves access to your stuff for (ahem) legitimate purposes".
Not like this: "we'll implement a neuralhash on the client device rather than on the servers, and then do a cryptographic private-set-intersection protocol with them on the server".
That's a lot of cost and effort to prevent themselves, as a company, misusing the CSAM detector for other purposes. If there are government agencies involved, Apple is also making sure that they can't just use this as a backdoor to get access to everyone's files, it's as if the government said "we need to prevent child abuse, give us a backdoor" and Apple went "ok we'll give you a small backdoor that's ok at detecting abuse images and nothing more" - if the government was expecting to use the backdoor for more than this, they'll be disappointed.
(I'm pretty sure they have other backdoors already, by the way. My guess would be a zero-day on the baseband processor firmware.)
I'm not saying I agree or disagree with Apple's latest move, but "exit the privacy industry" feels a bit a strong statement to me. You have less privacy than you did three weeks ago, and an option on even less privacy in the future (but then again Apple could just change the T&C), but you're still better off than with competitors that offer similar functionality.
I think that a number of folks at high levels in the SV executive suite have accepted a manufactured consensus along with their peers in Washington, and that consensus is something like: "people don't care about the privacy of what's on their device and they'll put up with anything to stop CSAM, even if it means scanning personal backups and local files (as opposed to shared files.)"
This seems like a reasonable thing to believe, since server-side scanning of (mostly shared) files has been going on for years and nobody has pushed back very hard on it. But what I think the consensus missed is that the reason for this lack-of-pushback is that nobody in the wider world had really been asked to weigh in on it before. It was something that a few elite tech busybodies were aware of, and most people accepted the idea that providers needed to check out photos that lived (unencrypted) on their servers. Apple accepted this logic and extended it unthinkingly beyond shared photos to unshared private photo libraries on the user's personal device (even if they are staged for backup as part of the iCloud Photos synchronization service, which is just a policy choice.) This was a second mistake because it assumed that because users mostly ignored the scanning of shared server-hosted files, they had somehow given consent to having their private files searched on their device. I don't think they had.
Overall, this announcement is the first time anyone has attempted to have an actual public debate to see how real users feel about this kind of surveillance, particularly automated surveillance of private photos (and an automated system with potential flaws.) Apple's mistake here was to assume that their user base had already given consent -- when they'd just never been asked. It's a very human mistake to make, frankly. The question is whether Apple will listen to their users or if they'll double down and push this through against their users' pushback. I can forgive Apple for misunderstanding their users once, but continuing down this path will be a lot harder to understand.
ETA: To illustrate how much more pervasive Apple's surveillance is than the standard (ignoring the PSI protocols), consider this quote from an EU Parliament briefing: "Others, such as Dropbox, Google and Microsoft perform scans for illegal images, but 'only when someone shares them, not when they are uploaded'." (I can only trust that this is factually true.) In this sense, Apple's move to scan all photos in your library is a significant functional escalation.) https://www.europarl.europa.eu/RegData/etudes/BRIE/2020/6593...
Next, it claims that consent is ambiguous when in reality the system doesn’t exist and users who don’t consent have a means and plenty of time to opt out.
Finally, there are people who argue the exact opposite: Alex Stamos has claimed one issue with Apple is that they didn’t engage the industry and academics like him enough when developing this solution.
Next, arriving at “practically the same solution” is a necessary but not sufficient condition for having the same assumptions. Arguing about practical functionality doesn’t even prove your point.
Finally, I explained why it’s a bad take so I’m not sure what you find unhelpful.
What is different about the Apple system is that unlike many companies (as of 2019) [0] they are not simply scanning shared photos intended for distribution. They are scanning all photos in your library, even unshared ones. This to me is much more significant than the use of PSI or adding a threshold of 30 reports. You can agree or disagree but it's much more helpful to argue this based on the merits than to be rude about it.
[0] page 8: https://www.europarl.europa.eu/RegData/etudes/BRIE/2020/6593...
> arriving at “practically the same solution” is a necessary but not sufficient condition for having the same assumptions. Your evidence doesn’t even prove your point.
On Windows, it's kind of routine that everything from your keystrokes to your searches gets used "to improve our products", for all I know Win10 looks at the files on your disk too. They certainly don't offer Apple levels of privacy even for private folders on your Onedrive.
It's also par for the course in multiplayer online games that while the game is running, it monitors your PC for known cheating services - sometimes even when the game is not running, although that still causes a bit of a huff if the program doing this gets caught.
They check for a finite set of "bad" things that no one is allowed to have. Because they went so far out of their way to avoid learning anything else about your photos, I think the argument is going to get very messy if we try to argue the surveillance angle. It gets very nuanced very quickly, and public opinion doesn't do nuance well.
It's a censorship tool. This argument is straightforward and easy. China can add Tank Man to the list of bad hashes, and now nobody is allowed to see him. The entire argument is now about what information should be censored, and who do we trust to maintain the badlist.
(Edit: Otherwise I agree with everything that matthewdgreen wrote above.)
I know I have been surprised at how little specifics are present in the criticisms that have been published. As an example, if one is asserting that governments can force Apple to do a thing, it seems like one should be able to articulate how, exactly, that would happen.
If it’s pressure under the rule of law (U.S. law enforcement, for example) I would expect organizations who employ lawyers to articulate the laws and precedents that would enable law enforcement to compel Apple to do something they don’t want to do.
And if it is pressure happening outside the rule of law (authoritarians targeting dissidents), I would expect activists to be able to articulate what levers those regimes have to pull against Apple.
I have not even seen basic before/after comparisons explained. Like, if Apple could resist altering their OS for the FBI in the San Bernardino case (and get applauded for it), why could they not resist altering their OS for the FBI in the future (and get mocked for suggesting they could)? How, legally, is a demand to develop a targeted approach to image scanning configuration different from a demand to develop a targeted approach to device encryption configuration?
And if authoritarian regimes can force Apple to search client devices for offending material, why haven’t they already done so?
There is a ton of content that basically starts with engineering topics like “it’s easy to add entries to a hash list” or “it’s possible to find collisions” and just go from there. But engineering is not the issue. What the FBI asked Apple to do in 2016 was not difficult. And it’s not difficult to scan client files on client devices for signatures. It’s not difficult to make software phone home to a server. A simpler version of what Apple announced (scan client files for signatures) would have been trivial for Apple to develop at any time since the iPhone launched. If someone could force Apple to do it, why didn’t they?
There may be solid answers to these questions but that is not the conversation I’m seeing. What I’m seeing seems primarily to be an emotional conversation that builds on people’s ignorance of the current state of technology and the law to power activist engagement.
I think Apple was expecting to announce something technical and legal and deal with technical and legal objections. But what they did was introduce fodder and fuel for what is essentially a set of intersecting social movements around the issues of privacy, censorship, and corporate power. And like many broad social movements, the details are maybe not as important as collective emotion and alignment.
Maybe that’s what you mean by elite consensus. Personally I would not consider myself elite, but I do find the lack of specifics frustrating.
Regarding extra-legal compulsion, the only thing I can point out is that there is no US law on the books that requires Apple to deploy this on-device scanning system. But Apple is deploying it anyway. If you speak to anyone at Apple off the books they’ll tell you bluntly that they’re doing this to satisfy pressure from law enforcement and regulators (along these lines [0].) So the existence of powerful extra-legal compulsion is not debatable. The question is how far it might extend? Only Apple can answer that question, not “technical critics.” Unfortunately Apple’s public communication has been to mostly avoid addressing the existence of the pressure at all, even though everyone agrees it exists in some form.
[0] https://www.google.com/amp/s/mobile.reuters.com/article/amp/...
Can you clarify the nature of what you call extra-legal compulsion? (Edit to clarify: what you hear from folks in Apple) Is it the pressure to help stop the transaction of CSAM, a pressure that all image- and video-handling networked software providers experience? Or is it to deploy a client-side scanning service specifically?
Especially “all content must be reviewed for child porn before publishing, or in real time if streaming”.
It now seems not at all implausible that Apple’s half-baked attempt to scan everything for child porn is due to this too.
They have serious problems admitting they did something stupid historically. Butterfly keyboards, reliability issues, you’re holding it wrong etc.
After having read a lot of internal Apple emails between executives[0], I find it extremely easy to imagine that they were completely dumbfounded that the rest of the world did not see things the same way they did.
This is another step towards total global surveillance of citizens. I don't see what can be done about it, technology makes it possible so it will happen, it is just too juicy for governments, they can't resist it.
https://www.nytimes.com/2021/05/17/technology/apple-china-ce...
They already scan and classify ALL your photos locally, not just the ones destined for iCloud, that's a widely touted feature.
But that's not the point, the point is that they have known for a while if you have photos of Winnie the Pooh, trees, lakes etc. That's why you can search your photo library.
If they wanted to report that to Xi Jinping, they could just do that. It's unrelated to the CSAM measure.
Apple didn't give them a new tool that China will abuse. China could just order the tool to be built and abuse it if they desired.
Now, you might say that China would force Apple to scan for things anyway - and they might. But at the same time, China could have ordered this at any moment in the last decade. It's not like the Chinese government wouldn't force this tool to be made anyway.
https://money.cnn.com/2018/01/10/technology/apple-china-iclo...
"We here at Apple do not want our servers to host images of exploited children, but we also respect your privacy. So you're free to use your phone with the photos stored locally, but if you'd like to enable iCloud we need you to press the button below to *install* our CSAM detector."
Then the argument basically goes away. It's like a virus scanner that you voluntarily installed. But having it baked into the phone as it ships rubs me the wrong way.
Personally, I'd rather have the detection happen on my phone than in the data centre. And I don't mind opting in to have my photos analyzed before upload. But the thing I don't like about Apple's CSAM thing is that it comes with my phone. And you know someone somewhere is going to accidentally enable iCloud and then claim they never did. Or maybe they didn't? Bugs do happen after all.
And it was not a goal that the unsecured boulder at the top of the hill should come tumbling down over the road and into the house, it just so happens that when an unsecured boulder lies on the top of a large hill where teenagers gather and it doesn't stay there for too long.
Same goes for liberties and certain politicians.
For this reason we secure boulders, teach teens about consequences, keep invasive tech out of reach from wanna be authoritarian politicians and teach history in school.
Not really. Virus scanners don't snitch on users to governments.
I'm joking, but only halfway.
But for the future I probably need Android phones with custom ROMs. Without spyware.
I'm at least old enough to remember it and I have a very strong feeling that the same is happening these days with Linux on the desktop.
Also on phones the alternatives are shaping up nicely so do talk well about them, don't say people should swith now but say you are considering a switch next time you upgrade etc.
> Also on phones the alternatives are shaping up nicely so do talk well about them, don't say people should swith now but say you are considering a switch next time you upgrade etc.
This is excellent advice, thank you!
Companies try to do stupid things and end up with egg on their face all the time.
They'll backtrack from this and people will forget it ever happened in a few months.
I am unconvinced they've lost it. There is a lot of noise right now, but how much of that is coming from people who already hated Apple?
Out in the real world, even people who've heard something about this largely don't care. It's a tempest in a teapot -- granted, a little larger than usual, but it's easy to fall into the fallacy that everyone else should care the way HN does about something. And this topic seems to be pretty divisive, almost political in nature.
Kinda reminds of GOT and the biggest mistake of the "good guys", they left the dead dragon in the ice which then later burned down the wall and accomplished the "impossible".
FB might use this to crush Apple in the future.
Remember, Google was so nice and held in so high esteem that even valid criticism could be downvoted mercilessly.
Today you can run a karma farm on criticizing Google here on HN.
Google had mountains of goodwill, but with smart people, dedication and hard work one can burn true it like they did.
I'm afraid Apple can manage this too...
The second market is bigger and less discerning. Its a purely economic decision: come and bring your kids to our nice safe child-proof walled garden.
There is also the parallel requirement in places like China and Russia to police what people have on their phones. This move clearly differentiates Apple from other Western tech companies and maybe protects them from bans in big and fast growing markets.
Remember those NSO iOS security revelations from a few weeks back? It might be quite possible that the government(s, specifically the US) are handling some information over in exchange for this. It would make sense for Apple to reach out to the government and get information about some of the vulnerabilities in exchange for brownie points, because this CSAM system is totally controllable by Apple while unknown security issues aren't.
Now whether Apple designed this only with CSAM and actually ignored/forgot its possible issues.. that's another question.
> why they enables CSAM in the first place?
Apple's privacy measures, such as not scanning your Cloud photos, is what helps enable CSAM.
Sexual abusers very often take photos and often upload these to their communities, and Apple has given them a secure device with which to do that. This is becoming increasingly widespread — the number of reported CSAM material grew by more than 50% last year, to nearly 70 million images and videos [1].
Due to Apple's privacy, the numbers look like this: Facebook reported over 50 million combined images and videos, Google reported 3.5 million, Dropbox, Microsoft, Snap, and Twitter over 100,000 images and videos. Apple reported only 3,000 photos in the same period, and no videos. [1]
Sexual abuse is experienced at some point in childhood by around 1 in 9 girls, and 1 in 53 boys. 93% of perpetrators are known to the victim. In 2016, CPS substantiated or found strong evidence to indicate sexual abuse of 57,329 children [2]. That's CPS, meaning in the US alone.
> They must have known the consequences, PR and otherwise.
The PR consequences of that have gone largely unnoticed, interestingly, and it's more so their attempts to curb it that are getting flak from the media.
I suspect this is because we can't create statistics on what we can't detect. There can be no "Apple is enabling, and allowing to continue, the sexual abuse of 50,000 children a year."
[1] https://www.nytimes.com/2020/02/07/us/online-child-sexual-ab... [2] https://www.rainn.org/statistics/children-and-teens
Secondly, I don’t believe those statistics at all. You’re telling me 11% of girls have been sexually abused? That’s preposterous. There’s gotta be some selection bias or misreporting.
The numbers are correct and it's shocking and heart-wrenching; here's a linked study [1], but there are many.
I went to college in Boston, where the Boston Globe broke a scandal that around 150 Catholic priests in Boston were accused of sexual abuse, with more than 500 victims [2] [3].
It was immensely tough to grasp and accept that in a small city like Boston, that many priests were sexually abusing children.
[1] http://www.unh.edu/ccrc/pdf/9248.pdf [2] https://www.theguardian.com/world/2010/apr/21/boston-globe-a... [3] https://en.wikipedia.org/wiki/Catholic_Archdiocese_of_Boston...
None of the stories I've heard about would remotely have been helped by this tech.
Every woman I know has a story to tell. Nearly all of them would make you weep.
We could do so much better, but then people like yourself just straight up don’t believe it.
this is what baffles me.
I'm sure a good number of iphone customers have their photos automatically uploaded to icloud.
For all intents and purposes, the end result is the same for most people. Apple is scanning your photos, and doing so on your phone feels much more intrusive.
For what it's worth, Apple has nothing to gain with this much of a privacy stir, especially when they're accomplishing the same level of detection that other companies accomplish with the simple cloud scanning.
While it's possible that something nefarious is going on with Apple and the U.S. government, it's more likely that Apple got really 'big-brained' about this, had a lot of talks of "we want to retain privacy" and the iCloud team pushing against scanning, and so they ended up with this as a "more private" solution.
Then in 2020, there was the EARN IT Act proposal, which nearly passed and would have required scanning for CSAM on pretty much every online platform that wanted Section 230 immunity.
Apple puts two and two together, realizes Congress is concerned about CSAM's spread and isn't interested in changing, and still wants E2EE on iCloud. OK, put the scanning client-side, then the way is paved for E2EE iCloud because the FBI's biggest argument against E2EE is neutralized, and so is Congress' argument for EARN IT (which would basically have banned E2EE).
> If a company actively screws its users in broad daylight, then what's going on behind closed doors?
At least previously Apple had the pastiche of a privacy and user-centric company. No more if this goes through.
Your right to privacy, in the face of government agencies executing their mission, does not matter.
Your right to free movement, in the face of a flu that overburdens the hospital system, does not matter.
Your right to free speech, in the face of the need to eliminate outsider politicians, does not matter.
Your right to election security, in the face of the establishment getting their preferred candidate, does not matter.
Your right to raise your children with traditional values, in the face of social engineering guidelines, does not matter.
Your right to bodily autonomy, in the face of globally coordinated medical interventionism, does not matter.
Your right to closed borders, in the face of foreign policy expediency, does not matter.
Your right to eat what you want, in the face of “climate change” activism, will not matter.
Your preferences are simply not safeguarded by your rights, which can be overruled by the whim of “experts.” If you want to imagine how any particular future scenario unfolds, just ask yourself whether your rights would be an inconvenience to the plans of, say, Bill Gates. As a sort of stand-in for the general careerpol/NGO/billionaire/Harvard class running things.
(and most of the media and many of the public intelligentsia merrily support this)
Furthermore, "right to closed borders" ? You previously invoked "free movement" yet there is also a right to closed borders? It appears you've just cloaked the same tired red team talking points in the language of freedom. Please, as a libertarian, stop trying to use freedom to justify what is a highly authoritarian movement. You're doing freedom no favors.
These are not in conflict. Freedom of movement WITHIN YOUR COUNTRY is not the same thing as open borders, which will dilute and destroy a culture.
Compliance with the COVID response is more a indicator of trust in public institutions than it is an IQ test. You could argue noticing the untrustworthy behaviors and picking upon on that trend is an indication of learning quickly...
The sheer number of people still rejecting this straightforward mitigation indicates that their bad decisions have little to do with distrusting institutions. Rather the problem is their trusting malevolent leaders who have been misleading them.
As for "closed borders", I've never seen this referenced as a natural "right". Yet here it is dressed up as one, even though it is ultimately a collectivist action rather than an individual ability.
You can of course still argue the benefits of closed borders, and five years ago I would have been sympathetic (the enthusiastic ignorance movement has since burned my assumption of their good faith). It's just specious to call it a "right".
Since time immemorial, a fundamental right has been warding off invaders of varying forms, armed or not. Exclusion of uninvited parties from a piece of land is one of the oldest things in Western civ.
Mixing together a bunch of weak arguments does not create a strong argument.
I thought this was some auto correct perversion of codswallop but it's a thing:
https://en.wikipedia.org/wiki/Gish_gallop
TIL