A Screeching Voice of the Minority
meta.ath0.com
meta.ath0.com
Pop!_OS (no Ubuntu telemetry and OpenSnitch) over MacBook Air is working flawlessly. Company MacBooks are with Arch/Manjaro. Will run Catalina for specific tasks without internet until it breaks completely.
The hostile design decisions of Apple are unbelievable. After 20 days of public backslash Apple is preparing for massive iPhone 13 campaign and pushing this obviously flawed intrusion with "common good" goals, normalizing surveillance on a new level. And all of this after Pegasus/NSO.
But actually I am glad. No more shiny toys and marketing illusions for me. Expect everybody to follow suit. Year or two down the road this type of scanning and control will be mandatory.
So the only way to respond is to invest in your privacy. Not in user-hostile, dark pattern designed products.
Happen to have any suggestions for what a privacy-conscious consumer should look into?
If I need a photo - I grab my old Sony RX. If I know that I will shoot - my old Leica MP240 with Summilux and 24mpx is enough. If I have to communicate with text - email or signal on computer. If I need in car navigation - Garmin.
Deleted Facebook/Instagram spyware long time ago. Flickr also. Self-hosting is the way to go.
I am using my iPhone for calls and sms with clear knowledge that everything is recorded. Banking apps when I don't have access to computer.
I have iPad Pro 12"WIFI with faulty WIFI and no Apple care which I use only for drawing and digital painting.
People around me are switching to deGoogled smartphones with Lineage/Calyx.
Indeed, this article (despite many incorrect facts about the process) is right in that this is just a vocal minority 'screeching' to get the message out there to anyone willing to listen. The absolute majority of the population, or at least adult population, will always choose the path of least resistance - they just wants to live, work, avoid hardship, and partake in dopamine-inducing activity every day. There's a reason Google and Amazon are trillion-dollar enterprises and Hulu still has an ad-supported version that 70% of people choose[0] - people don't value privacy at all when dealing with these faceless companies. Society has always shifted the level of privacy they accept (think taxes, audits, search & seizure with probably cause), and this will just be another shift that people accept so that they continue on with their lives while not sacrificing any of their valuable time.
0: https://variety.com/2019/digital/news/hulu-ad-supported-subs...
Personally, I have no problem with ad-supported and generic/no-tracking. Ads themselves are not the privacy invasion, and have a reasonable history of helping to pay for things, and it is possible to rebuild ad companies to respect privacy (again). (It might take burning a few big players to the ground first, unfortunately.)
Hostile for sure, unbelievable, not really.
This type of "we know what's best for you" attitude is deeply ingrained in the DNA of Apple as a company.
The fact that they did get it right many time and that their batting average is above other tech companies is no excuse for the fact that the attitude is deeply flawed.
This was bound to happen.
You are holding it wrong. Here we go, we are removing "escape" but you have a touch-bar with customizable functionality, sorry this is the best laptop keyboard design - you will adapt to it.
We are removing ports - but you will have Dongles - lot of dongles and this MagSafe shit that you love so much - no more for you.
Innovation my TrashCan - not upgradable peace of trash, after 6 years - here we go MacPro - only for the Apple "elite hustler" club members, as a bonus 1000 dollars monitor stand.
We don't like MacOS - to much control for the user is not good for Apple Profits - we like iOS and we will make everything like it. You will adapt.
Now we are innovating on a geo-political stage, protecting our brand with the all time classic "Neural Cash" and bending a knee or two in the name of Apple dominance and antitrust avoidance. You will adapt, because you are trapped and we know you love us.
Privacy, my ass. :)
This kinda flies in the face of that except for the fact it's wrapped in, as you said, "common good" goals.
I've never been Apple, but I'm currently attempting to migrate to a LineageOS daily-driver mobile, although I still require some amount (nano) of Google to get by. Ironically, I needed a Windows machine to do this, whilst I'm already almost exclusively Linux (Ubuntu and Pop!_OS).
Maybe only a minority of Apple customers are aware of and understand the scanning issue and are giving feedback to Apple via the web. But here is a thought experiment: Does anyone think that if the majority of Apple customers were briefed on the issue and then asked if they agree/disgree with the minority of customers would they disagree with this informed minority.
"Tech" companies should know whats best for advertisers. They can be expected to ignore user feedback complaining about surveillance. OTOH, Apple should know whats best for users. Its users are telling the company and the company is irgnoring the feedback.
“We promise” is easily forgotten. “We can’t” requires dev teams to change.
For all the things that have been said about the issue, I don’t remember a single comment that has been directed at the US government, or China itself, or any discussions about how nation-states should be run and genuine introspections on what could prevent surveillance states from existing in the first place.
Indeed, you don't necessarily know what photos are on your phone.
That said, leaving your devices at home is a sensible idea.
After the Pegasus news that showed that a relatively small private company in a very small country could have complete remote access to your phone and sell it on the market, do you really think that a powerful government like China or the US can't already do it??? How could you be this naive? Especially after the Snowden revelations.
And about Apple's having a change of hearth in the future and using something like this against you. Have you stopped to think for one second and consider that they have complete control over the updates that your phone receives?? They can quietly do what ever they want without you ever knowing and you can't do sh*t about it. So drop the concerned citizen act. We all abdicate privacy a long time ago when we sold our souls for cool free services like google and sexy gadgets.
At the end of the day the "slippery slope" argument boils down to one thing: do you trust your institutions? Any law or service can be abused, and the only thing preventing that is the integrity of the people on your society and the institutions both public and private that they work for. The exact same law that is used to fight corruption in a great country like Norway or Denmark can be abused to persecute political opponents in a shitty country like North Korea or China.
If the answer is no, I don't trust my institutions and my people, then you have a far more severe and fundamental problem than an specific law or service. In that scenario, focusing in an specific issue is like trying to cover the sun with your hands.
These whataboutisms are a distraction and in no way support the idea that people shouldn't be worried about Apple implementing a new client-side system that's ripe for abuse.
If things are already bad, we should be working towards making them better instead of rolling over and apathetically allowing them to get worse.
Also I don't trust institutions. This is axiomatic and why separation of power is essential. So
> the only thing preventing that is the integrity of the people on your society and the institutions both public and private that they work for
is plainly wrong in my opinion. If you let people abuse this, they will. Also I don't think that can meet with reality. Police departments alone have quotas they must match, so they have to find criminals... It doesn't take a genius to figure out the repercussions. But it is still practiced in many countries.
Separation of powers is plainly ignored for everything under the guise of safety and a disease infecting politics the last few decades. That is due to incompetent leadership. Another reason why you should not trust "institutions". Instead, you check them and burn their asses if they fail as often they do today. The reaction that trust is falling in press and public officials is completely rational on the other hand.
There's definitely still a "slippery slope" argument here that in handling this specific use case they are going to feel more pressure to handle other specific use cases of government actors, but they are also setting the precedence that they still will not support a generic backdoor. That seems to me, at face value, a greater privacy win than a loss.
- government may use this in future to tag people for wrongthink imagery, but also
- CP is rampant on FB and FB reports it all but nothing happens so what difference does it make
Could a government not have a different level of interest in law enforcement over CP vs, say, political material that undermines government authority?
Indeed; I'm not sure this premise holds. I personally don't trust Apple's promises on privacy given its actions in China shows that it values market access more than its privacy values. But I find this argument weak.
Same with Microsoft. And Dropbox. And…
Recently I've seen a lot of "experts" trying to reassure the non-technically oriented about the fact that it's not true that "the cloud is not someone else's computer", that that's just a meme and it's not accurate. But they never thoroughly explain why that wouldn't be the case.
When you dig deeper, it turns out that more often than not those "experts" are people whose job is to sell cloud services, or who work for companies that sell cloud services.
>As applied in Chrome Cleanup, ESET’s technology is used by Google to alert users about unwanted or potentially harmful software attempting to get on users’ devices through stealth, for example, by being bundled into the download of legitimate software or content. Google Chrome, using ESET’s security technology, then provides users with the option to remove the unwanted software. Chrome Cleanup operates in the background, without visibility or interruptions to the user. It deletes the unwanted software and notifies the user once the cleanup has been successfully completed.
https://www.eset.com/int/about/newsroom/press-releases/compa...
This is where the slippery slope argument comes in. Apple would have to actively cooperate with governments to both detect and report other kinds of images. So if Tiananmen Square images were showing up in the review pile, Apple would have to know to pass those on to the Chinese government and be willing to.
The only other way they'd be passed on is if Apple drops the manual review portion.
It's utterly trivial to modify the image to avoid matching. Most minor modifications will do so.
The purpose of the hash is so that idiotic criminals that aren't trying to avoid getting caught don't accidentally avoid getting caught just by resizing or recompressing the images.
The flawed 'hashing' function also creates plausible denyability: If its somehow proved, perhaps via a whistleblower, that Apple was in fact matching the historic tank man photo, Apple or the government could easily hand over a piece of child porn with the same neuralhash due to the extraordinary vulnerability of the function.
A lot of research went into classifying images, mostly from the side that wanted visible or invisible watermarks in pictures. It is a cold war against image cropping, compression and modification that tends to not favor the classification side.
But here you only want to have a different hash, the operations for that are numerous and probably indeed often trivial.
I don't think you could just have a completely different picture create a collision though. Maybe they can because it is their hash-function, but that would be quite unusual and I doubt this is the case.
Allow me to introduce you to my posts on github: https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX/issue...
Where I post good looking examples of standard test images altered fairly subtly to give the specific hashes.
The apple neuralhash is broken as a 'hash function'.
It's much much easier to modify images to just have a different hash. A simple blemish on the image-- or, with whiteboxing using the hash function, no visually noticeable change is required at all.
But the price of that is that it's not secure against generating arbitrary preimages based on fairly arbitrarily targets, with results that look nothing like the original image you're matching (if one even exists).
They could do some downsample, transform, quantize, sha256 approach that would still survive some tiny amount of differences. ... but apple favors easily constructed false positives over false negatives, even though its trivial for anyone trying to avoid their function to get a false negative. Their scheme only protects against accidental false negatives. It's just a symptom of systematically favoring factors other than the privacy and security of the actual owner and user of the computer.
Killer argument. Why not focus here instead?
A title that has so little to do with the contents of article, that it might as well be a random reference to some throw-away line in some comment somebody uttered sometime, which might as well be left alone so a proper title could be selected.
Normally I would agree, but I'm fine with the subtle(?) implication of this one.
Didn't know about the memo until reading other comments.
> We know that the days to come will be filled with the screeching voices of the minority.
https://9to5mac.com/2021/08/06/apple-internal-memo-icloud-ph...
from a letter from NCMEC that Apple circulated in an internal memo.
Who of the two gets to decide how much expository context is right?
How is that supposed to appeal to right wingers? He thinks all right wingers want those rioters to escape justice? Most republicans oppose them according to several polls. The author may be a victim of political divisiveness due to paying too much attention to social media and news.
Not a partisan thing; effective left wing leaders also have their phones targeted. The swamp doesn't like change.
The article compares scanning to facial/object/scene recognition, which it can’t do.
The article talks about making it easier to find who took a photo, which is not the problem the Jan 6 sleuths were trying to solve.
The article worries about China, but ignores that matchable photos must appear in multiple jurisdictions’ databases.
The article also ignores the several points of third-party auditing and several layers of human reviews.
Or maybe, more directly, what do you think Apple employees reviewing these hits would do if those types of images started showing up in the triage list.
The photographers posted them publicly on Facebook and Twitter. That’s how we have them in the first place.
The problem wasn’t knowing who took the photos, it was knowing who was in the photos. And that needs facial detection, which this system can’t do.
However, my primary point is that there is no possibility of a technical control over the scope of the program. It’s a policy decision and is subject to explicit expansion or collusion/parallel construction.
They do report you to a private organization who is primarily funded from the US Government and has zero interest in not passing along any information about potential child abusers.
If you believe Apple, there will be a human review element. What sort of people would go after this kind of job? I can't imagine. And this group will also have a huge incentive to err on the side of reporting any potential abuse content.
Edit: A legitimate, almost definitely "wants to the the right thing" private organization in the US. Have we heard about who gets notified in other jurisdictions?
And why would the NCMEC give law enforcement info about people they know are innocent?
For unencrypted content uploaded to their servers. That makes it a "Them Problem". Apple's approach is to scan before it is uploaded (and like the article says, "for now" - this can change with only a configuration change for all we know). And this could be a per-jurisdiction option and again, no one would know.
You have a point that this is not completely novel problem but do we have actual data on the number of real vs. false positives on the "everyone but Apple" group? Matthew Green probably would know but he doesn't[0].
[0] https://twitter.com/matthew_d_green/status/14283829528580833...
The left side photos are all apparently kitten photos but what if it was a photo of the Nirvana baby and, as a human reviewer, you had no access to the right side photo because it was just a hash in an anonymous database?
After all, Youtube copyright strikes have never been abused thanks to the fact that there are human reviewers.
Also, no app has ever been incorrectly removed from the Apple App Store, for the same reason that there are human reviewers.
This is thanks to the fact that human reviewers never make mistakes, unlike the rest of humans.
What could go wrong if we adopt the same system for something that could potentially result in a criminal investigation?
Are you able to explain why this specific case would be different?
1. https://cases.justia.com/federal/appellate-courts/ca10/14-32...
> Representatives of multiple law enforcement agencies have offices in the NCMEC building, including the FBI, Department of Homeland Security, U.S. Marshals, U.S. Postal Inspection Service ...
> Your phone will run your images through NeuralHash, and compare to the list of forbidden hash codes. If there’s a match, some data will be uploaded to Apple’s servers when you upload the image.
Your phone doesn’t know whether there is a match or not. There is no “if match then upload”. The safety voucher is attached to every iCloud upload, not just the matches.
This is why Apple can’t just flip a setting and scan all your images regardless of whether you add them to iCloud or not. If they wanted to run this against all your images, they’d have to either upload all your images to iCloud (easy to spot; difficult for them to do without consent) or change the way this mechanism works (not “just flipping a setting”; if they wanted to scan all your images, then why build it this way in the first place?).
Technically, but not substantively, true since they report to the NCMEC, a government-funded government-established “private nonprofit” that is delegated a whole bunch of jobs for government, including gathering info on CSAM and distributing it to law enforcement for DoJ and processing child return/access requests under the Hague Convention on the Civil Aspects of International Child Abduction for the Department of State.
I found it incredible that there were so many deviants known by the police in my community, they eventually caught the killer. He turned out to be a neighbor and confessed.
I think the police are well aware of every download/upload of child porn or are atleast they are able to look it up when the need arises.
The time for concern of protecting ones privacy on any digital connected device has come and gone, best to assume anything You do on your device is readily available for the authorities(and others) to exploit.
*it was 21 years ago, and the only news report I found says 100 known but I am positive they said 15K.*
https://www.cbc.ca/news/canada/missing-girl-s-body-found-in-...
About 1/2 of 1% (estimates vary) of people are sexually attracted to children and an unknown number commit acts against children. Statistically if your kid gets abused it will probably be by someone you know and shouldn't have trusted.
You should probably have a healthy mistrust regarding men alone with your kid and the government without being paranoid.
Im not sure I understand what You mean by this, my thought or possible concern is that all web traffic, especially that which goes through known proxy addresses is being logged and flagged by local carriers and ISPs. Then in the event of a crime being commited in my area, my actions online including stuff from decades past will invite a knock on my door by the authorities or worse the media.
I must stress, Im not worried about anything sexual but have done a great deal of research on some other subjects that are not exactly above board.
I can appreciate the concern regarding apple scanning personal files and reporting matching files to the government, but feel the odds of a virus, vulnerability or exploit being used by a criminal ngo is just as big if not bigger risk and has been for a long time now.
Anyways, like I said...for a while now I have been of the mindset that anything I do on a connected device (even temporarily connected) leaves me exposed, now or in the future. Maybe cancel culture has encouraged my current way of thinking.