Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light.
[EDIT]: Not the FBI, but a private company noticed this (h/t codeecan)
Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light.
[EDIT]: Not the FBI, but a private company noticed this (h/t codeecan)
Google, Microsoft etc we know for a fact do server side scanning of photos for CSAM. Apple should be assumed to do the same.
So what exactly is the difference if this is done client or server side. The person being hacked would still be investigated by the FBI.
I don’t know how often unintentional possessors are prosecuted, but the US system of prosecution makes it easy for an innocent to get railroaded by threats of massive charges and comparatively leanient plea deals, combined with punitive sentencing for those who reject the plea bargain. Think Aaron Schwartz, but without any intent to violate the law.
> The person being hacked would still be investigated by the FBI
As someone with family in the FBI (one on a relevant team) and a local LEO that was deputized to do this work for the US Marshals, that doesn’t reassure me. The best forensics employees in the FBI with enough resources can identify that there was a hack and that the account owner is innocent. We live in a world of scarcity where that much effort is not always invested.
I think the client-side versus server side is more about relative trade offs of who owns the client device (and what “ownership” means) and whether the equivalent server side search is technologically feasible (might not be if the client encrypts with a key only the client owns, as some have speculated about Apple’s future plans).
IANAL so I am very likely wrong.
US Code 18 Sec 2252 seems to state that possessing or looking at CSAM material requires that the action is done “knowingly”.
Edit: No if they use the same algorithm, but they could use other algorithm which are less abusable and no one would know the hashes in the database, so Yes I guess?
Apple knows the sync dates of all of the photos that are uploaded. So unless someone has hacked your account and has been directly trickle feeding CSAM for years (without you noticing) then it's going to look suspicious. A big dump of lots of CSAM at one particular timestamp is a pretty easy thing to spot.
And then in this case they aren't hacking the phone but the account which means Apple is going to notice a set of photos coming from an IP address they haven't seen used from that account before.
Seems like there could be some legal ramifications from the choice to bypass law enforcement under certain circumstances
Of course metadata could exonerate someone who is a victim in a case like this. The question is will it ever see the light of day?
Also known as a 20 line script which checks the last modified date for a bunch of recently uploaded files and validates the IP address against the recently known list.
Only if that system / heuristic has been built. The same could have been said about Apple’s systems for identifying bulk account hijacks, but Apple didn’t, which I suppose is the value of this story.
And companies aren’t allowed to Just inspect content once they identify CSAM. It is kryptonite for criminal liability. Companies are required to turn it over to the feds quickly and to try not to disturb metadata.
I suspect your line of thought would work given full ability to inspect (and some assumptions about what an IP change actually proves), but in practice Apple still hasn’t gotten the basics around account hijacks/fraud sorted out, so I’m hesitant to cheer them on as they try to quickly jump into the deep screaming “think of the children!”.
> A California company that specializes in removing celebrity photos from the internet notified an unnamed public figure ...
He was caught by random chance of this company.
The fact that those hacks quickly were flushed from the news cycle without a bunch of public lawsuits etc. makes me suspect Apple very proactively went out and made settlements with the more high profile victims of those hacks. Of course, I have no proof of this at all, so it's purely speculation, but it was odd to see almost nothing come out of those hacks.
Apple is not at fault here though.
These people have clicked on a phishing email no different to a banking or retail one.
In any case flagging multiple accounts logging in from a single public IP is not as useful a signal as you might think.
From the site guidelines:
> Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize.
Just a reminder because if a mod ends up viewing this they will probably change the title back to the original.
I assume each upload is tagged with device ID which first uploaded it etc. but maybe that can be spoofed as well?
If you are worried about the security of iCloud, then that can be read as more reason to prefer client side scanning. Of course the tweets are ambiguous about logical implications so you can’t engage with them directly.
However, stating my opinion as fact in an attempt to invalidate someone else's perspective on the matter would be debasing discourse so I wouldn't do that. None of us should.
Since you went ahead and stated opinion as fact (while cleverly pretending that you didn’t), can you provide an example where I dismissed a valid concern with a non sequitur? How do you reconcile the accusation that I assert “nobody should be concerned” with comments like this where I clearly outlined why the announcement should be concerning:
[1] https://news.ycombinator.com/item?id=28279776
[2] https://news.ycombinator.com/item?id=28165116
I’ll go further and say that I have sincere concerns with what was announced, but seeing how that Twitter account seeds legions of incorrect commenters who proliferate (and post intentionally clickbait material on HN, as the poster of this article themselves admitted on this very thread!) led me to the conclusion that Matt is doing plenty of harm, especially since he should know better.