Apple Delays Rollout of Child Safety Features
macrumors.com
macrumors.com
[1] https://appleprivacyletter.com/
[2] https://act.eff.org/action/tell-apple-don-t-scan-our-phones
[3] https://www.eff.org/deeplinks/2021/08/apples-plan-think-diff...
As of right now, is there even a database other than the one NCMEC has? I suspect they are waiting for the NCMEC to spin up its European branch.
A decade ago, all those things were on the Internet worldwide.
https://www.bbc.com/news/world-asia-china-57759480
Many of the closed WeChat accounts display messages saying that they had "violated" Internet regulations, without giving further details.
The account names have also been deleted and just read "unnamed".
"After receiving relevant complaints, all content has been blocked and the account has been suspended," the notice said.
The crackdown is the latest example of what some call growing intolerance toward the LGBT community. Last year, Shanghai Pride week, modelled on Pride events in the West, was cancelled without explanation after 11 years of it going ahead.
In 2019, the Oscar-winning Freddie Mercury biopic Bohemian Rhapsody was released in Chinese cinemas, but references to the Queen singer's sexuality and AIDS diagnosis were censored.
In 2018, Weibo said all posts related to homosexuality would be taken down, although it backtracked after massive outrage.
I have a theory about this that isn't politically correct, but here goes. This has nothing to "conservative values" or homophobia or whatever you call sexual repression in places like Arkansas and Afghanistan. It's not based on religion or culture. It's just the CCP running an actuarial table.
The CCP is a blunt force instrument. It realized some time ago that the one-child policy had left it holding the bag on taking care of a rapidly aging population without enough young people to power the economy in 10-20 years. Not only that, you couldn't easily just repeal the policy and expect a baby boom. They took a look at Japan and realized they were about to hit a demographically driven, deflationary wall. So the party planners moved from repealing the 1CPolicy to actually offering cash bonuses for second children. This volte-face happened within a few short years. But it didn't work as well as expected. Their sudden magnanimous gesture didn't bump their 5-year plan's crop of new Han for a few reasons: A shortage of women (unexpected consequence of the 1CP), more women in the workforce who don't want to have children, video game culture which makes young men stay home instead of going out and impregnating girls -- which is why they're now limiting screen time, gender fluidity / queerness which suppresses baby-generation, and of course western individualism, the great bugbear of "harmony," which encourages people to wait for love and financial stability before having children. At the end of 5 years of encouraging people to have babies, they don't have enough babies. So now they have to get harder on the edge cases.
It's probably safe to assume that gays and lesbians represent at least 10% of the Chinese population as they do in most countries. So that's what, 120 million people? Let's say half of whom are young enough to have at least one child? So we're talking about an extra 30-60 million children if you can somehow get a replacement rate.
That's what I believe all these recent moves by the CCP have been about. And banning test study programs? Same thing. No point having more babies if you're also getting overproduction of elites. They need construction workers and factory workers. And someone was told, we ain't gonna become Germany by bringing them in from Tajikistan, so take this data and figure out how to squeeze as much Han production as possible out of it in the next 5 years.
In the West we have already tried to force LGBTQ people to accept the behavior of their assigned sex. Result? Increased suicides, depression and drug use.
Obviously, after decades/centuries of failure we finally decided to recognize the reality of the facts: you cannot force people into a heteronormative life, nor to make children.
They are in for a hard failure.
This is not even remotely the same as the Taliban banning music or China cracking down on LGBTQ stuff.
> Christopher Rufo reported[2] that 30 public school districts in 15 states are teaching a book, Not My Idea, that tells readers that “whiteness” leads white people to make deals with the devil for “stolen land, stolen riches, and special favors.” White people get to “mess endlessly with the lives of your friends, neighbors, loved ones, and all fellow humans of color for the purpose of profit,” the book adds.
> There are plenty of other examples that prove racial essentialism and collective guilt are being taught to young students. In Cupertino, California, an elementary school required[3] third graders to rank themselves according to the “power and privilege” associated with their ethnicities. Schools in Buffalo, New York, taught students[4] that “all white people” perpetuate “systemic racism” and had kindergarteners watch a video of dead black children, warning them about “racist police and state-sanctioned violence.” And in Arizona, the state’s education department sent out[5] an “equity toolkit” to schools that claimed infants as young as 3 months old can start to show signs of racism and “remain strongly biased in favor of whiteness” by age 5.
[1] https://www.washingtonexaminer.com/opinion/yes-critical-race...
[2] https://twitter.com/realchrisrufo/status/1413292881264005126
[3] https://www.city-journal.org/identity-politics-in-cupertino-...
[4] https://www.city-journal.org/buffalo-public-schools-critical...
[5] https://www.washingtonexaminer.com/news/arizona-education-ba...
From here[1]:
> Christopher Rufo, a prominent opponent of critical race theory, in March acknowledged intentionally using the term to describe a range of race-related topics and conjure a negative association.
> “We have successfully frozen their brand — ‘critical race theory’ — into the public conversation and are steadily driving up negative perceptions,” wrote Rufo, a senior fellow at the Manhattan Institute, a conservative think tank. “We will eventually turn it toxic, as we put all of the various cultural insanities under that brand category. The goal is to have the public read something crazy in the newspaper and immediately think ‘critical race theory.’”
[1] https://www.washingtonpost.com/education/2021/05/29/critical...
When it comes to teaching children Not My Idea, definitely seems to be more to the concern than just shadows:
The fallacy of ‘whiteness’ https://www.bostonglobe.com/2021/08/08/opinion/fallacy-white...
> According to recent reports, public and private elementary schools across the United States have used, as part of racial equity education, an illustrated children’s book called “Not My Idea,” in which a devil with a pointy tail offers the young reader a “contract binding you to whiteness.” The contract promises “stolen land,” “stolen riches,” and “special favors”; in exchange, whiteness gets “your soul” and power over “the lives of your friends, neighbors, loved ones, and all fellow humans of COLOR.”
I looked at some of the illustrations of "Not My Idea"... it's a bit wired and cringe worthy sometimes. Still compare that to the indoctrination that is in some of the schoolbooks:
Slavery was just "black immigration" https://www.theguardian.com/education/2021/aug/12/right-wing...
The kkk was not morally wrong ... ?? https://www.nbcnews.com/politics/politics-news/texas-senate-...
Banning of Black and Latino Authors https://www.mcall.com/news/pennsylvania/mc-nws-pa-banned-boo...
Teaching creationism: https://www.arkansasonline.com/news/2021/apr/08/house-advanc...
Are you as outraged about that as you are about a fringe law theory?
Can you name numbers comparing how many books with problematic woke content are used versus the books mentioned from the guardian?
These stories are lenses through which you can describe the world. They’re like software for the mind. And like software, they aren’t objectively right or objectively wrong. Each of these stories (dubiously) explain and obsesses over some aspects of the world, and ignores other aspects completely.
No, its not.
Though there is a mythic anti-”Critical Race Theory” story created by the American Right, and the thing within it called “Critical Race Theory” is a (particularly incoherent, because a number of unrelated and opposing things from the real world that share only that they concern race, and they are disliked by the American Right, and they are not actually Critical Race Theory, are jammed into it) mythic story.
> These stories are lenses through which you can describe the world. They’re like software for the mind. And like software, they aren’t objectively right or objectively wrong.
Actual critical race theory (like critical legal studies, from which it stems) holds the existence of objective features of social structures, with tangible, material, effects.
Like many hypothesized social phenomenon, the complexity of the systems involved may make falsification difficult on a practical level, but the claims it makes are fact claims which are objectively true or false.
I'm also always surprised how little US citizens know about their own history. Ask somebody about "Birth of a Nation" and see what they can tell you about it.
Ask them if they know about the "Pro American Rally" in 1939 and see what they say.
These things are not taught in school and it's a shame. I know what I'm talking about I'm German and I hated our history education in school as we were discussing the 3rd Reich nearly every year. Yet, reflecting on it and seeing that the same stupid ideas get a hold today again, it was not nearly enough. We should have taught more. The same holds for the German colonial history (that was not covered and is changing slowly).
If you don't know your past, you are condemned to repeat it.
https://www.washingtonpost.com/local/education/150-years-lat...
https://www.theguardian.com/education/2021/aug/12/right-wing...
Not quite. Rufo knows what CRT is, and importantly, what shares the same problems CRT does. That is to say, different branches of the same general ideology that operate on different topics. The CRT model is kinda like ideological lego, you can just plug in a topic). The demon is legion and has many names. Rufo's stuff is mostly about calling woke thought in general CRT, since the name stuck. I haven't yet seen Rufo label things that aren't wokeness or influenced by wokeness CRT.
It's the same kind of thing as when we call Catholicism, Eastern Orthodoxy and all the Protestant sects "Christianity" even though they are not the same, or how we still call Zen "Buddhism" even though it lacks the supernatural component of its older cousins. None of those things is the same, but they share a family resemblance, they have a character to them that makes them unique among the sea of ideologies, religions and philosophies. Rufo's nailing "CRT" to that family resemblance, because the family is there, the demon is real, and it needs a name to be talked about usefully, not a legion of them.
30 school districts (out of how many?) use a book Rufo doesn't like.
Any reason why anyone, aside from Rufo, should care?
Half of the nation doesn't teach sex ed because skyperson doesn't like when people bang without signing an exclusive banging agreement in public first. Half the nation teaches kids that the Confederacy was formed to protect "states' rights", carefully omitting that the right in question was to own black people as livestock[1]. But hey, 30 districts use a white-people-bad, and that's the real problem.
And what does the last part of your comment (about AZ) have to do with anything? Telling educators that 5-year-olds can absorb shitty beliefs is now a cOnTrOvErSiAl tHeOrY?
I don't even know where to start here, let's set this one aside.
So, let's focus on this question first: assuming the book you mentioned is bad, which percentage of pubic schools use it, and in which way?
[1] TX is my go-to example. They were teaching that slavery was a "side issue" in the Civil War when I was living there in 2010-2017.
I'm not even going to bother dissecting the bullshit they peddle these days. Feel free to dig in.
Texas oversees 1,247 school districts. Tell me more about the problem of CRT in schools though.
https://www.smithsonianmag.com/smart-news/texas-will-finally...
> this is happening and it's good
Rufo is trying to create the world's biggest molehill.
[1] https://ballotpedia.org/Public_school_district_(United_State...
Indeed, the NCMEC database does not have an especially good reputation, much like MCMEC themselves.
ICMEC is a fork of NCMEC.
So...
a) a bad actor is going to target someone, and have the resources to generate enough collisions that(b) look like CP, but aren't CP? but are close enough (c) to pass human review and cause an investigation so (d) they need the hash collisions to look like CP, but not be real CP? or ????
If a bad actor wants to frame someone, it's easy to do this today - hack their system or home network, open it to the internet, place the photos, call the FBI and report an anonymous tip, with the URL where it is hosted and open to the internet. Don't need hash collisions.
Hacking someone's iPhone (How do you get the photos on there without forensic logs that they were added?) or iCloud so that you can place hash collisions that look like crap and fail to pass the review doesn't make sense and leaves too much of a trail. Oh? And someone won't notice thousands of photos just added to their phone?
A bigger threat would be deepfake CP. When that becomes a reality, it will be a mess, because an attacker could theoretically generate an unlimited amount of it, and it will be extremely difficult to tell if it is authentic. Those hashes wouldn't be in the CSAM database, but if the attacker put them out on a server to be taken down, they would get added eventually and then show up in a scan elsewhere.
But I'd be pretty horrified (and definitely call my attorney, Apple, and local FBI field office) if thousands of CSAM images just showed up in my iPhone photo stream.
Edit: Downvotes are fine, and I completely understand other arguments against this, but this one has just not made sense to me...
Edit: Downvotes because?...
For example when CIA/NSA tools leaked, one of them had precisely this purpose.
Conversely, the governments of the world get to keep trying, over and over.
It's significantly harder to develop collisions for an algorithm you cannot inspect or obtain the output of.
(well also, emailing actual CSAM is way easier and mostly just gets the sender reported)
You're exposing the hashes to the world, you're not able to E2E encrypt anything if you need to server side scan, which you probably do since trusting the client no matter what is generally bad in potentially adverserial situations, and you get all this negative press and loss of reputation and potentially pressure from governments around the world to use this for other ends. Cui Bono?
The second scan applies only for those images which are flagged as positive, which are then accessible by Apple. This is applied to detect adversarial hashes. The rest of the images stays encrypted. So, indeed on-device scanning is the only way to enable at least partial E2EE with CSAM detection.
Yes, this was PR failure Apple. They rushed the announcement because of the leaks, and secondly they thought that people will understant the system when they did not. There is too much misundersting. That scanning for example is built-in so deep into the iCloud pipeline, that one does not simply change the policy for scanning the whole phone.
On a technical level I think you're correct. As a holistic approach to the problem, I still disagree. This is too cute for its own good. The PR misunderstanding is a symptom of that.
>The second scan applies only for those images which are flagged as positive, which are then accessible by Apple.
In the end, Apples software is scanning all of the images, why is it any more privacy respecting to do it this way? I guess reasonable people can disagree on that, personally I wasn't fully aware of the cloud side scanning either, and I don't think the public was either. This is similar to Snowden's revelations, if you were paying attention you probably already knew a lot of that, but the incident made everyone aware of it in a very blunt way.
>The rest of the images stays encrypted
I think this is unclear, Apple can still decrypt those other images, how else could you view them in a browser?
This goes back to what Stratechery said about capability vs policy.
Obviously there is change coming to iCloud. Otherwise whole PSI protocol is pointless.
Tangentially, I think keeping their servers clear of illegal material is actually Apple's main motivation. This, in turn, supports claims made by nay-sayers that Apple could scan for other types of images/content in more repressive countries (but not necessarily report the people who did it). However, this assumption also contradicts arguments that Apple will start scanning for pictures of (e.g.) drugs, or weapons. Such images are not inherently illegal and therefore of no interest to Apple.
My guess about this whole debacle is that - with pressure from the government to scan their cloud storage - that this is the alternate scenario to avoid giving up (or being forced to) the "encryption" guarantees of their cloud. I'm not sure what technical process they have in place to "only decrypt with valid law enforcement requests" or allow account rescue, but it seems likely that not just any employee can view whatever they want, before or after this system.
Saying that I can maybe see a way the pressures are on this doesn't mean that I'm saying this is a good solution though. Clearly technically implementing this is opening a can of worms that can't really be closed again and makes a lot of other scenarios "closer".
Also, evidently, people are a lot more comfortable with the idea of them actively scanning stuff people store in the cloud than transmitting the information in a side channel so they don't even need to handle decrypted data without a hit.
This is exactly the case. https://www.eff.org/deeplinks/2019/12/senate-judiciary-commi...
> I'm not sure what technical process they have in place to "only decrypt with valid law enforcement requests" or allow account rescue, but it seems likely that not just any employee can view whatever they want, before or after this system.
They have master keys that can be used to decrypt almost everything you upload. They can be compelled to decrypt and turn over information on anyone. Another (unsourced) comment in this thread indicated they do so 30,000 times per year. The new encryption scheme will effectively stop this for photos, and no doubt other files in the future.
Apple's side will begin using shared key encryption, which will require ALL ~31 keys to decrypt the offending images.
The decryption keys are only generated on-device, and only from a hash that results from a CSAM match. The other photos, simply won't have the decryption keys generated, so they don't even exist.
As an interesting side note, this means that a person who surpasses the CSAM threshold will still only reveal the images that actually match the CSAM database. Every other image, including those that have CSAM unknown to authorities remain encrypted. This is hardly a big win for the big scary government. They now have far less ability to search for evidence of any other crimes. You could upload video of your bank robbery to iCloud, and as long as your personal device remains secure, nobody will know.
Even if that was a goal (and I would argue they have a hard stance against it), this system as built is not usable for that.
While they can scan locally, every step of recording, thresholds, and subsequent automated/manual auditing is built to require content to be uploaded to iCloud Photos.
Even assuming that is true that iCloud is trivially “hackable” - and as I understand it, that was never clear how those leaks happened - how does uploading to iCloud help when it specifically needs to be uploaded from the users phone along with the scanning metadata.
In fact, isn’t apples proposed implementation here the _only_ cloud service that protects against your proposed attack - while other clouds scan stored data and can be triggered by your attack, Apple’s requires you to upload specifically from a registered phone on their account; data stored on-cloud is never scanned.
The response to this is “yeah but then a human will review it and nothing will happen to the victim of the attack, because it’s just some slightly blurry ordinary images”. But it ignores to entirely likely harms that could result from that.
1) Law enforcement use it as the basis of getting a search warrant, but conveniently leave the bit about the alerts being false alarms off the warrant application.
2) The list of people who have had CSAM alerts is inevitably leaked to the public, and the victim has to spend the rest of their lives explaining to people like employers why Apple flagged them as possessing child sexual abuse material.
At the end of the day, all the gaslighting about “no potential for inadvertent harm” is bs, because it’s my device, so get lost. Go run your anti-privacy software somewhere else, imo.
- Law enforcement doesn't get _anything_ unless it triggers a large number of images that match the perceptual hash
- It also needs to match a -private- perceptual hash, that isn't distributed to devices, and so we don't have a reliable way of generating collisions for or even knowing that collisions are generated
I mean this whole thing is bad enough on its own without having to artificially manufacture extremely specific scenarios and extrapolating from there to invent hysteric conclusions.
But you’re right though, the possibility of the list being leaked and ruining countless innocent lives is the much more likely of the two scenarios I described.
In that case, nothing is stopping them from scanning everything already uploaded anyway, and nothing is stopping them pushing code to your device to scan it without telling you about it. Nothing is stopping them or the government from making these "lists" anyway.
I'm not saying you (or anyone) should trust Apple, but if you already don't - then this changes literally nothing.
Feel free to respond to my point about the alert catalog inevitably being leaked and ruining lives. Or you could just have a go at gaslighting me a little more if you prefer.
- Send colliding images
- image gets uploaded to icloud automatically
- image _also_ collides with private hash <- completely unclear how this happens
- Only the colliding images are looked at by apple and are determined to be innocent
- user goes on a list (This is an imagined scenario)
- User is reported to law enforcement even though the images are innocent (This is an imagined scenario)
- Law enforcement uses this hypothetical report to file a warrant (This is an imagined scenario)
- Law enforcement uses the hypothetical warrant to extract images that are completely innocent, and somehow build a case around this
- The "List", which is entirely a hypothetical of yours, "leaks" (This is an imagined scenario)
Which also requires:
- Apple does not counter the meaning of "the list"
- Apple is not sued for vast quantities of money
I expect the first argument is that none of this matters as long as "the idea" is out there, the reputational damage is already done. Except if that's true, then none of this is necessary at all, just make the accusation.
So, sure, continue to thread the needle between "They are automatically sending all information to the government, so promises are meaningless" and "This new process, on top of them potentially sending all information to the government, somehow makes it worse".
I mean, this is all a million times more difficult and less likely than just, like, sending them CP in the first place. Or uploading it to their Gmail or any other cloud they use. Or just send a report that they have it to the police without actually doing anything.
All it requires is somebody to send somebody else a colliding image.
This will send an event to Apple. There is nothing imaginary about that, it is exactly how the system works.
Now that Apple has this information, the only thing left is for it to be leaked or compromised in some way.
This is much simpler than the scenario you’ve described, because they require the attacker to first commit the crime of possessing CP. Its also possible to do without tipping off the victim in any way.
Apple, in case you didn’t know, is a company that had already been the source of a couple of the most notorious data breaches ever (and has somehow managed to so far avoid getting “sued for vast quantities of money” for them).
What you’re trying to do here is quintessential gaslighting.
And again, there is the whole fact that you received the email and there is a log that you received it.
Additionally, the images sent to review are significantly downscaled versions of the original & could easily be made to be ambiguous.
The most difficult challenge in this SWAT story is that Apple has a secret secondary hash that's checked on a collision. That's the part of the SWATting story that feels difficult on a technical level. However, there are also really smart people out there so it wouldn't surprise me if a successful attack strategy is developed at some point given time.
No one is going to be prosecuted on "significantly downscaled ... ambiguous" versions of original fake images with a hash collision that flagged a review and was handed to the FBI accidentally because a "minimum wage" fatigued person passed it on.
I get the counter-arguments, but the hash collision thing is just, sort of... weird? I even get the argument that an innocent hash collision may have your personal and private images reviewed by some other human - and that's weird. But I can't really see it going further (you'll be arrested and sentenced to life in prison from the HASH COLLISIONS!).
It's just using technical terms to scare people who don't understand hashes and collisions and probability, and not really founded on reason.
Which typically will be a court case, or at least questioning by police. This can be quite a destructive event on someone's life. Also, there's no mechanism for whitelisting outlined in the paper, nor can I imagine a mechanism that would work (i.e. now you've got a way to distribute CP by abusing the whitelisting fingerprint mechanism or you only match exact cryptographic hashes which is an expensive CPU operation & doesn't scale as every whitelisted image would have to be in there).
Also, your entire premise is predicated on careful and fair review by authorities. At scale, I've not seen this actually play out. Instead either the police will be underworked & not investigate legitimate cases (too many false positives) or they'll aggressively police all cases to avoid missing any.
Even if uploaded to iCloud (such as pictures sent via WhatsApp by default), and above the threshold, they would still be scanned by a second algorithm and subject to human review. So, your "very simple" attack fails on at least three counts.
(I think) the complaint is: how is that different from just using CSAM images, no collision required?
And, to at least respond to two obvious counter-arguments I've looked into:
"But it's just one line of code to change it to scan images (that aren't uploaded to iCloud) (that are anywhere on the device)!" No, it isn't; if you read the technical documentation and the more technically-oriented interviews Apple's given on this, there isn't just one hash that needs to be matches, there are two hashes, one on the device and one on the server. (I think Apple did a very poor job of communicating this to a general audience; it certainly wouldn't have alleviated all the concerns, but if it was understand as "client-server scanning" rather than "client-only scanning" it might have at least changed the tenor of the conversation.) That doesn't mean they can't do a combination client-server scan on every single image or even file on the device, but it makes it both more difficult to do and more difficult to hide.
"But what if the system doesn't work as Apple's described it?" Well, if you don't trust Apple to some degree, all bets are off. They already do ML-based image analysis of all photos in your photo library regardless of iCloud status and they've literally demoed this on stage during iPhone keynotes, so if Apple was going to secretly give government access to on-device scanning, a different technology -- one that works (questionably well) on all images, not just already-learned ones -- is literally already there. The only way you "know" what Apple is doing with your data on or off device comes from a combination of what they tell you and what third-party security researchers discover.
If they get caught doing secretly this in China that would be a big blow. But if they are doing openly and it is known that the government provides the hash, they can wash their hands.
I think there _is_ an argument to be made about a system like this being used to track the spread of political material, and it's easy to see how such a system would be terrible for anyone trying to hide from an authoritarian power of some type, but that'd already require Apple is absolutely and completely compromised by an authoritarian regime, which isn't high on my list of concerns.
As recently posted on HN [1] one should be very wary of backdoors, no matter how much one believes only the right guys could ever use them. Once they're there, they're there: it's arrogant beyond believe to think that opponents of yours won't exploit them.
I won't use an apple product with this feature. I've been using apple's ecosystem since about 1994.
[1] https://twitter.com/matthew_d_green/status/14334701097425182... and https://news.ycombinator.com/item?id=28404219
I don't understand this, they can just be legally compelled.
But a motivated bad actor has a lot easier time just putting an image of the Taiwanese flag or propaganda on someone's phone than trying to make it a hash collision that triggers... If an attacker is really after someone, I would expect them to put the actual material on that person's phone...
... It's like trying to frame someone for drugs in their car and going through the hassle of synthesizing a chemical that triggers drug dogs to react, but it isn't actually the drug. Wouldn't they just... buy drugs and stick them in the car?
Maybe they want to create too many false positives deliberately, or maybe they do it just because they want to see if and how synthesizing such a chemical can be done.
When putting pictures on someone's phone or computer, there are ways to add false positives as well as maybe doing false negatives sometimes (e.g. by encrypting the picture or using an uncommon file format so that it must be converted, or using complicated HTML/JS/CSS to render it instead of just a picture file).
Also, if someone has the picture or drug or whatever to find if it is what they are, can you accuse them (maybe they are the police) of liking pictures and drugs, too?
But, to be clear, you make a legitimate point.
How so? Unlike other cloud providers, which do scan all uploaded images server side, this system is specifically designed to prevent this.
(As you say, if Apple is entirely compromised, then all bets are off anyway.)
So Apple called them out on it by letting the market decide. They now have that evidence.
Editing to add: I think this will play out more like the butterfly keyboard debacle. They won’t ever really acknowledge how bad the original thing was, but they’ll return to a solution the community finds palatable (server side scanning), and wrap it up in a bow like they did with the “magic keyboard, now on our laptops”.
My read is that Apple is trying to placate governments by throwing them a bone without totally abandoning their privacy stance, hence the drive to put the scanning on the actual device so all your photos don't have to be shared as-is with Apple. That way they can encrypt iCloud but still keep the feds from accusing them (in bad faith) of being a child porn trading platform.
The alternative is to keep iCloud unencrypted and scan in the cloud, which is what they and everyone else already does.
One of the pieces of feedback they got though is that people are more okay with that than with scanning on the device. People expect that things that go to the cloud are no longer private unless you run some kind of local encryption that you control.
The reason they don't care about photos not sent to iCloud is the trading platform angle. It's one thing to let people store shit on their own devices. It's another thing to be a large scale and easy to use secure channel that people can use to share CP. The nightmare scenario for Apple would be to become a de-facto standard in the CP underworld for sharing content.
Sure people can use Tor, private VPNs and mesh networks, PGP, or many other things, but that requires a level of technical knowledge that greatly reduces the size of the audience.
Maybe a better alternative for Apple would be to add iCloud encryption but to stipulate that any sharing of content disables encryption for the shared content. That way they could scan shared content only. For unshared content iCloud is basically just an encrypted backup.
You would believe this if you only read/watch Apple PR and ignore reality. The actual reality is that Apple always collaborates with all governments. The reality is that Apple did not announce any new end to end encryption that would use this feature and did not promise such a feature.
In China and other more authoritarian nations that means cooperating a lot. If you don't you do no business in China. In the USA they seem to be looking for a new minimum level of cooperation, or trying to enhance privacy a little without moving the needle.
In any case this particular strategy looks like a failure in the market. They might re-engineer it or backpedal or just toss the whole idea of encrypting iCloud.
Maybe if you define privacy that Google and FB do not track you and only Apple do. You open an application on your Mac and the event was sent insecure to Apple , find a definition of privacy that is not contradictory with what Apple was doing.
Morality barely matters and legality is something easily skirted around with the right legal argument. Apple, google etc with continue working with governments so long as their profit can flow from those countries.
https://www.reddit.com/r/MachineLearning/comments/p6hsoh/p_a...
It's like being asked to have an invasive, detailed scan of your body shown to TSA personnel (and recorded) when you fly. The motive is apparently to prevent violence. But there were still incidents on flights when that was being done. It wouldn't have caught the box cutters on 9/11. The stated motive ceases to be part of the equation for me.
There's also images that can be abusive if made public but non-abusive if kept private. For example what about a kid taking pictures of themselves nude (many kids don't have parental moderated accounts) and putting them on icloud (iphone does this automatically with default settings).
It's a complete nuthouse and there's no way to do it.
(Also don't get me started on drawn artwork (or 3D CG) that people can create that can show all sorts of things and is fully or partially legal in many countries.)
To add, there are natural neural hash collisions in ImageNet (a famous ML dataset). Images that look nothing alike to us humans.
The issue here is not the trustworthiness of the pinky swear...
In other words, a situation that seems to be a feature toggle away from becoming terrible is terrible in itself.
If you look at the tone of all of it, they also honestly felt this was the most privacy preserving way to do CSAM scanning - likely so they can enable E2EE on everything iCloud.
What they got very very wrong was the public reaction to it.
Refers to facts not in evidence.
Additionally, they have previously voluntarily declined to enable e2e on systems to aid government surveillance.
This is baseless speculation, and, given what we know about Apple's history with e2e, not only baseless but actually unlikely.
Apple has not announced E2EE for files stored on iCloud. If that is their intent, they likely would have had a somewhat improved public response by announcing it at the same time as the on-device spyware.
What they got very wrong is that this fundamentally changes the nature of iPhones -- they are no longer user agents; in fact, they're actively scanning user data on behalf of another party. That change doesn't just make people feel uncomfortable, it opens the door for untold myriads of abuses.
It's one thing if iCloud servers scan user data - those servers never were assumed to be user agents. It's entirely different when user-owned devices do this.
I'm afraid good faith is not gonna protect your privacy.
I doubt it , they will bring this up again very soon , if they cancel it, they’ll get very bad press too.
And second, a company that once shows its intention to breach your personal privacy while disregarding its user’s best interests altogether. Wont hesitate to do it again.
https://www.statista.com/statistics/276306/global-apple-ipho...
Apple is delaying this, I suspect, because it confuses the privacy message: If every time they talk about privacy someone can make them look like hypocrites by pointing out the on-device scanning, well that's just ugly for Apple. I suspect the on-device scanning element is going to be removed and it'll be on ingress to iCloud, which is what I said on my very first post to this. It was ill-considered to do it on device given Apple's privacy push.
More importantly, there is an oligopoly in tech and up until now, only one of the manufacturers of tech devices cared about privacy. And to that extent, I wouldn't be surprised if vast majority of developers who care about privacy have biased themselves towards apple. And now they have a reason to treat apple like every other privacy invading company.
That’s right. I like the idea that on android, I can use stock tools like rsync to manage the photos/music on my phone. With Apple it’s been a constant battle against iTunes to do those basic things. The only reason I chose Apple last time I bought a phone is because I’m willing to sacrifice a bit of convenience for the perception of better security/privacy. If they lose on that front, then I’ll hop to whichever phone is easiest for me to use the way I want to.
I remember, when that recalcitrant dentist was dragged of a United plane, endless predictions of United's imminent demise, people would never fly United again, yada yada yada. Needless to say, nothing much happened.
> I suspect the on-device scanning element is going to be removed and it'll be on ingress to iCloud, which is what I said on my very first post to this. It was ill-considered to do it on device given Apple's privacy push.
Not sure about that. Apple's approach (private set intersection run on half client, half server) preserves more privacy than scanning it in the cloud, and leaves the door open for E2EE.
The developers are going nowhere so long as the money is there to be made from iOS.
Did they all quit when it was revealed that Apple was part of PRISM? Of course not. They barely blinked.
It doesn't matter if a billion developers sign a petition. It's empty. The vast majority of them will promptly capitulate if Apple goes forward. By vast majority I mean 99%.
Did you see all the people desperately fleeing from Australia due to the rise of the extremist police state there? Nope. Did you see the tens of millions of people flee from the US when the Patriot Act was passed or PRISM was revealed? Nope. Did you see everyone rapidly flood over to mainland Europe as Britain became a police state? Nope. How about the hundreds of millions of people fleeing out of China over the past decade with the rise of Xi and the entire demolition of all human rights in China? Nope. Perhaps you're spotting a predictable human nature trend in all of this.
All the tech employees of Google, Facebook, Amazon, Microsoft, Apple, etc. They've all quit in droves over the past decade over human rights abuses - including vast privacy abuses - and concerns for what these companies are doing? Whoops, no, the exact opposite. There was a price for their integrity as it turns out, and they grabbed the money, which is what most people do.
The iOS developers are going nowhere, either. Besides the fact that their livelihoods depend on it, there's no vast green field to run to from what's happening. Sure, some might change jobs, or switch industry segments, it will be a small group though. It's going on in just about every liberal democracy simultaneously. What huge platform are developers going to flee to that's better and is never going to feature forced on-device scanning spyware? It's coming for Android too, bet on it.
iOS is where all the profitable users are. While that holds true, developers will be there to sell things to the profitable users.
The principled indie developers might leave in protest, and that would be a terrible loss for the platform's soul, but realistically the vast bulk of money flowing through the App Store is not going to the indie developers.
It'll go live around December when the Christmas sales push for iPhones is winding down and people are distracted with everything else going on.
When the tech news cycle is dominated by bad press about a move like this, and every tech nerd community is discussing this topic almost daily, it would be insane for Apple not to take some notice.
I know many are pessimistic about this, but Apple has learned from bad mistakes before. They rarely directly admit they're wrong, but conceding to pressure from the community is not unprecedented: see the return to the "Magic Keyboard" in their laptops.
Edit: removed the word “never” and replaced it with “rarely directly”.
It might not happen every day, but it happens frequently enough that it's easy to find a lot of examples.
Apple admits mistake, says it’s back in EPEAT https://channeldailynews.com/news/apple-admits-mistake-says-...
Apple Admits the Mac Pro was a mess https://www.theverge.com/2017/4/4/15175994/apple-mac-pro-fai...
Apple Admits iPhone 7 Manufacturing Fault https://www.theguardian.com/money/2019/feb/11/apple-iphone7-...
I could go on for pages, but I trust the point is made.
Mac Pro was a mess when one of their largest customer told them they will switch their whole studio away from Apple right in front of Eddy's Cue face before some thing was being done.
It's like the three seashells. They don't know how to use them.
These days it's hard to find an app that can get by without Cmd+click which is harder than click on the right button, which would be even easier if the right button was physically distinguishable. Long-press is super annoying as well as force click--I never want the action that comes up when I accidentally force-click. With the prevalence of touch phones, the two-finger-tap might be the easiest of them to remember (if not as precise).
People just dont realise how normal people have problem with mouse. Of course as we progress I think Two Button mouse could make sense as default. The role of PC also changed. The PC for everyone is now an Smartphone.
No, no, GP clearly has direct insight into the values, ulterior motives, and decision process of Tim Cook and other top brass at Apple.
Ten bucks says they take a page out of our politicians' handbooks and sneak it in as a small, vague footnote in a much larger, unrelated announcement once the initial bad press blows over.
Apple learned a valuable lesson here. Roll the panopticon out in secret, and don't announce it. They've done a very good job locking down their modern devices, enough that security researchers would have an exceptionally difficult time proving that they're doing it anyway.
GrapheneOS is still a viable option until Google ends upstream security updates in 2023. That's a solid two years for Purism, PinePhone, and anyone else working on linux phones to bring their performance and feature set up to modern standards.
The correct course of action is to buy a Pixel 5, run GrapheneOS for the next couple years, while donating to the main privacy-focused linux phone projects, and make the switch again in 2023.
That's a terrible idea. Apple knows that researchers are going through every bit of assembly code on the phone.
If all of a sudden they say "Hey we found some code that scans all your photos and sends information up to the cloud" how bad would that look? It's better to explain upfront rather than get found, because they will get found.
Not a jailbreaker at all, so happy to be completely wrong on this.
Alternatively, get a Linux phone right now and donate time by contributing bugfixes.
Did we? I suspect the real issue the original client-side proposal had a lot of holes. What if the bad guys upload CSAM which hasn't been tagged by NCMEC yet? What if they then delete it from the device (but keep it on iCloud)? Or what if they zip the CSAM images and backup that?
In order to be even semi-effective, the client-side scanning has to be more invasive, or they have to implement server-side scanning too. Apple may well be looking whether they can implement this scanning without even more backlash.
Sooner or later government and NCMEC will push them to complete the feature (understandably so from their POV), and when they do, Apple will have to expand scanning. Apple may have already been pressured to do so.
Sometimes choosing the middle ground is like choosing to drive on the white line in the middle of the road as a 'compromise' between the lanes.
Are you asking Apple to come out and say that they are supporting privacy against state-level actors? After snowyD, why would anyone believe that anyway?
I'm not advocating against or for - I'm only wanting to add more clarity to the discussion because I think it is an important distinction that is often left out.
Yeah, very few have the financial independence to be able to do something like that. However, over the next few years when everyone gets their free upgrades, I imagine we'll see some slower, yet more robust, switching.
The cat is out of the bag. You and I have realized Apple can make these type of changes whenever they want.
I'm disappointed to report that Linux needs a lot of improvement to be viable for most people. I'm forging ahead, donating to open source software and hardware projects, filing bug reports, and generally bringing the Mac spirit to Linux. "It just works."
What phone did you switch to?
But network location provider doesn't work, that's an issue.
Though proprietary hardware plus mostly open OS is better than proprietary everything.
I'm continually surprised that people are continually surprised by this. I'm sure this post will get a lot of anecdotal replies; of course it can work fine for many people, but that's not the point. I used it exclusively on the desktop from 1995 to 2002. I could make it work for me, today, if I wanted to.
> You and I have realized Apple can make these type of changes whenever they want.
Was this not obvious? I'm pretty shocked that, for example, Docker can decide to change their license, and now in a few months a bunch of companies owe them money for every single user they have, even if the users don't do anything different. If they opened the license agreement and chose NOT to upgrade. If they never use the software again. But bam, terms changed, now you owe us money.
I tried Ubuntu last year, briefly. Almost everything worked fine, except ... OK, I'm a trackpad user. I have a couple Apple Magic Trackpads and I prefer to use those over a traditional mouse.
It worked fine for, like, a day? And then out of nowhere it just stopped responding. Reset or reinstalled everything I could think of and it still failed to work. OK, whatever, I bought a traditional bluetooth mouse. Which went to sleep every time it remained still for more than a split second, rendering it basically unusable (not a problem on Windows on the same machine).
Maybe a whiz could have fixed one or both issues, but googling completely failed me. This was pretty basic stuff, surely? And yet I couldn't even get bluetooth mice to work on the most mainstream distro.
(Now, admittedly, the trackpad doesn't work properly out of the box in Windows either, since Apple doesn't provide drivers that work outside of Boot Camp. But at least there are paid drivers that work really well.)
Anyway, I don't know. People have all sorts of annoying issues with Linux that end up being things that I have never encountered before. I usually use wireless mice with USB transceivers, which have never had problems and I feel like not everyone has such a bad experience (although I know many people who do). Perhaps it's because it's Apple hardware or something, but, admittedly, I have had MacBooks work perfectly on Linux before.
I think that, however, you use Linux on a desktop rather than a laptop, you will find that the hardware experience is quite pleasurable and does not have nearly the same number of issues. Between the two, Linux does manage to shine decently on desktops.
Not really. I just had them ["non-bluetooth wireless devices"] laying around and I think the non-Bluetooth ones are cheaper.
> I'm wondering if the future of Linux might be abandoning bluetooth entirely.
Abandoning Bluetooth just because your experience was unsatisfactory is not something I agree with at all, sorry. IME, Bluetooth support is completely fine for all the Bluetooth devices I have (like speakers or my cell phone)—and I know others who haven't had any issues either.
Besides, Android uses the Linux kernel. While I don't know if Android uses Bluetooth drivers from the mainline kernel, if it does, that would just make Android's life harder while pointless removing something that usually works fine.
Get that Pangolin before they sell out! Is there a Labor Day sale or something?
My main disappointment is that it doesn't "just work" with the kernels shipped by Ubuntu. System76 provides their own kernel packages, but they sometimes cause weird conflicts with other low level packages, and it can't hold its charge when suspended. I haven't attempted to debug the issue because I usually stay plugged in when I'm working, but I suppose I ought to engage tech support. They have been helpful in the past.
At the end of the day, I'll probably still give them my first look if I'm shopping for another laptop.
Compare this to my migration to a M1 MacBook Pro: I love it, but it is rough doing deep learning on it.
My first was a Galago Pro, and my only complaint was that I went HiDPI. That was just a bad choice on my part. The software supports it fine, I just don't prefer it in a laptop unless it's literally a Mac-level Retina-quality panel. It wasn't, but it's half the price point.
My other is a Gazelle 15", which dual-boots Arch and Windows. I use it primarily as a gaming box when I travel (remember those days?). I spent a lot of raid nights on various MMOs from hotel rooms. It works great.
Really looking forward to the Pangolin. Mine is still in "building" status.
I see a lot of sh*t written about System76 because they are just rebranded Clevos. Well...yeah? They are, and they are fine. I would rather give money to a company like System76 a thousand times over than someone dripping with anti-consumer behavior like Dell.
Re: Clevo - obligatory copy pasta from System76 Chief Engineer right here on HN [1]
"System76 UX architect here! This vastly trivializes the work System76 does for months and sometimes years leading up to a product release. We don't simply take an off-the-shelf product that already exists, throw an OS on it, and sell it.
System76 works with upstream manufacturers (like, yes, Clevo for laptops) to determine what types of products to develop, including their specifications, design, etc. for months up to a release. These products do not exist before we enter into these conversations.
Once that has been determined, designed, and goes into production, we start on firmware. We ensure all components are working together and with the Linux kernel (often requiring changes to the components' low level interactions with the OS, since the upstream components themselves are often manufactured with the assumption they will be used by Windows).
Once that is complete, we test with Ubuntu and Pop!_OS specifically, ensuring the OS is working perfectly with the hardware. If there are any OS-specific changes to be done, we write that behavior into Pop!_OS and/or our "driver" which is preloaded on all machines (and available in any Ubuntu-based distro, Arch, Fedora, etc.), with the intent to upstream that into Ubuntu, GNOME, and/or Linux itself as quickly as possible. When this is more generic like ensuring HiDPI works great out of the box, this actually ends up benefiting competitors like Dell's XPS 13 probably as much as it benefits us, but we put in the effort to file the bugs, track them, write the code, and get it upstreamed.
Once all of that is complete, we finally offer it for purchase and market it with all of our pretty photographs, sales pages, etc.
What ends up happening, then, is Clevo offers a machine with a similar-looking chassis for sale as a barebones laptop. This is the result partially of the decision making System76 has made for what to produce in the first place. These products, however, do not contain any of the firmware or driver work that System76 has invested in. They do benefit from the nice photography and advertising System76 has done, and since they look similar, people assume they're going to get the same machine for cheaper "directly from the manufacturer."
Edit: regardless, this is a bit beside the point of the linked blog post, and is also becoming less and less true as we work on designing and manufacturing our products completely in-house."
Their work on both the firmware front and with Pop!_OS should not be overlooked. And, it should be mentioned, if one is familiar with their whole product line - they now go far beyond just laptops for the open source community. And their powerhouses are absolutely not from some other OEM.
If I could just get a decent higher-than-1080 panel from System76, I might consider it for my next laptop. I've been spoiled by Macs. As it is I might go with a Framework laptop instead.
IMO it would go a long way if we taught computer literacy and specifically Linux literacy to everyone in school. Microsoft and Google have all the school contracts and they bring people up on systems that "just work" (actually they have paid system administrators). If we taught people from a young age to use Linux and handle problems, then the small problems that often come up with open source need not be barriers to adoption. Even if every regular person can't always solve every linux problem, if they were familiar enough to use it and had at least one expert friend, they'd be fine.
That's not to say we shouldn't strive to make Linux "just work" for most people, but we can attack the problem from other angles as well.
But Linux is just far more than I can handle, even just to install apps and configure settings. For example just trying to get my mouse not to stutter, I dig and find a solution. I copy and paste it into the terminal. It doesn't work and I try 3 different solutions. I'm curious about solutions but it wears my curiosity out pretty fast. I need to get work done.
In the sense that computers are like cars, I'm okay not knowing how exactly it works under the hood.
Also FWIW I have learned, even though I run debian, to check the Arch Wiki for tips on problems like that. One more place to check in addition to stack overflow.
Evergreen.
With broad addaption use cases like this will be solved.
You can install and configure Linux Desktop nowadays without touching the terminal.
- The government is pressuring us to do things that don't fit with our "privacy is good" sales pitch
- Let's propose something, but in a ham-handed enough way that it gets a ton of public push back
- Now we can argue our point with the government in a way that has already has more public support and existing discourse/debate
Somewhat risky though, since it hurt their public image.
My favorite theory is this:
Apple wants to create a chilling effect on reverse engineering iOS. They're starting to catch regulatory attention and lost their recent suit against Corellium. By putting neural hashes in the encrypted OS image, they can accuse anyone who reverse engineers iOS of:
1. Being in cahoots with child abusers
2. Knowingly possessing CSAM
I would hope that most courts would see through that paper thin logic, but the idea would be simply to introduce enough doubt that most reverse engineers don't want to risk it.
What basis could there be for that? And I'd be even more skeptical if this originated from a single case of abuse.
How does Apple get leverage if Apple gets all the negative publicity, and can't even say "TLA made us do it"?
NSLs are routinely issued to silence companies.
It was that Apple somehow gets negotiating leverage with a three letter agency.
So how does Apple get negotiating leverage in a context with a TLA when they can't say "they made us do it"?
I won't be purchasing any more iPhones, and I've had every one.
Push to the level of their target's discomfort, then back off – without respecting the "no!", pretending to hear only "not now".
Come back later from a superficially-different angle, when the victim's defenses are down.
Couch the next attempt, or the next, or the next, in some combination of feigned sweetness ("but I waited & changed things for you"), or esteem-attacks ("you're so nasty you deserve this"), or inevitability ("this is going to happen whether you like it or not, so stop fighting").
• Unmasked proximity with non-household member
• Unlicensed gathering of more than 6 people
• Association with unidentifiable individuals (no faceprints on record)
These are your 2nd, 3rd, and 4th strikes so your phone has been disabled and you are now under arrest. Do not leave your immediate vicinity. As always, keep your phone on, charged, and in your personal possession at all times.
Due to large violation volumes, we are currently experiencing long physical arrest team hold times. Your arresting agents should arrive at your location in approximately... 5... hours.
Thank you for using Apple products, the leaders in Social Safety. 'Better Safe – Or You'll Be Sorry!'™"
It's a way to inch toward the unthinkable by obtaining concessions. You propose the unthinkable and after extreme push-back, the concession seems completely reasonable. However, if the concession would have been proposed alone instead of the unthinkable, it would have been rejected. It's an absolute deceptive manipulation technique.
Another example of manipulative Overton window shift at play: You may also recall deep state puppet Kathy Griffin showing Trump's severed head as the deep state testing the waters of a possible coup or assassination. The more you expose the public to the unthinkable, the more it becomes acceptable.
https://en.wikipedia.org/wiki/Overton_window
See also the Door-in-the-face technique and Foot-in-the-door technique
https://en.wikipedia.org/wiki/Door-in-the-face_technique https://en.wikipedia.org/wiki/Foot-in-the-door_technique
The door-in-the-face (DITF) technique is a compliance method commonly studied in social psychology.[1][2] The persuader attempts to convince the respondent to comply by making a large request that the respondent will most likely turn down, much like a metaphorical slamming of a door in the persuader's face. The respondent is then more likely to agree to a second, more reasonable request, than if that same request is made in isolation.[1][2] The DITF technique can be contrasted with the foot-in-the-door (FITD) technique, in which a persuader begins with a small request and gradually increases the demands of each request.[2][3] Both the FITD and DITF techniques increase the likelihood a respondent will agree to the second request.[2][3]
Foot-in-the-door (FITD) technique is a compliance tactic that aims at getting a person to agree to a large request by having them agree to a modest request first.[1][2][3]
This technique works by creating a connection between the person asking for a request and the person that is being asked. If a smaller request is granted, then the person who is agreeing feels like they are obligated to keep agreeing to larger requests to stay consistent with the original decision of agreeing. This technique is used in many ways and is a well-researched tactic for getting people to comply with requests. The saying is a reference to a door to door salesman who keeps the door from shutting with his foot, giving the customer no choice but to listen to the sales pitch.
Exactly. Note this description of the cycle of abuse:
"[The abuse] cycle involves four stages:
1) building tension
2) an incident of abuse
3) reconciliation
4) calm
Rinse and repeat."
Source: https://www.healthline.com/health/relationships/cycle-of-abu...
I think they cannot really sneak it in. Some people do read updated TOS. And I think a "featurechange" like this, requires one.
And yes, the question will be, if the broad attention to the topic can be brought back on to it, if that happens. And they clearly say it will come, only with some "improvements" (but I cannot think of any improvements, that can be made, without abondoning the basic concept):
"we have decided to take additional time over the coming months to collect input and make improvements before releasing these critically important child safety features"
The concept of scanning for CSAM during the upload process, or the concept of making the user's device do it? Apple could do the former on their own servers and essentially nobody would be upset.
The algorithms never work 100% right. That means there will be always humans in the loop, sorting through false positives etc. which means probably very private pictures here in this context.
And to the end user it does not matter, whether this happens on the server or on their device. The message is: your pictures are not private with apple.
If that's too abstract, it matters in that it's a foothold for further scanning of data on your device. Without this system, if a state wanted to pressure Apple to create spyware and add it to their operating system to look for something else, that would have been easy to refuse. With this system, the spyware is already there, and despite Apple's protests to the contrary, it's just a matter of a few tweaks to repurpose it.
The battle is not over though, as you say Apple might include the feature unchanged in a later release.
If they do, should come as no surprise that they will lose a lot of business.
The correct business decision will be to cancel the feature and double down on the privacy angle.
They were just out by 37 years.
It would be nice if the general public and the news therefore now picked up on the issue of opaque "automatic updates". To date, they have been trained to always every update without question.
Conventional wisdom: Never, ever question any particular automatic update. Don't think, just enable. All updates are created equal.
Assumptions: Every update is for users benefit. Software companies never operate out of self-interest. There are no trade-offs. Whats good for them is good for users and vice versa. Theres no reason for end users to trial updated versions of software ("A/B test") before deciding to use them "in production".
Thought experiment: User installs Software from Company to perform "Function #1". Company makes changes to Software, described as "Fixes and other changes." Software now performs Function #1 plus Function #2. User allows new software to be installed automatically. (Automatic updates enabled per "expert" advice.") When user downloaded and installed Software she based her desicion to use Software on its ability to perform Function #1; however, did she have any interest in Function #2. Did she agree to Function #2. Company says yes. Developers say yes. What does User say. The license agreeement places no limits on what might comprise Function #2. It could be anything. It could have no benefit whatsoever for User. Moreover, Company is under no oblgation to disclose Function #2 to User. With automatic updates, Company is free to keep changing Software. User originally chose Software for Function #1 but Software may look very different after many "automatic updates". Would she choose it again in its current state. Segue to discussion of "lock-in".
But to me, it did at least look like this scared the shit out of Apple PR.
Even if they somehow manage to make it do exactly the thing it is supposed to do and not slide into a feature for mass governmental control, I think a lot of people will loose trust into the devices they own.
Automatically scanning your stuff and reporting the bad things to the police is like the concept of God always watching. Even if you don't do anything wrong and you agree that the stuff they are watching for is bad and should be prevented, there is something eerie about always being watched and controlled.
The iPhones should mind their own business and leave the police work to the police.
That being said, I would be O.K. if the scan is performed on the device upon physical access by the authorities. You caught someone, You have enough evidence to investigate the person, you are allowed to search his/her home then maybe it can be O.K. to run a fingerprint scan on the phone to look for evidence.
Why? You have physical access to the device. Just look at the data. The CSAM scan will only ID known imagery. What if this person has new content that is unknown to the database? This is a non-sensical justification.
So it is a compromise, the data stays encrypted but the authorities can get an idea about the nature of the data.
Then it is up to the person to reveal their data as a part of a cooperation agreement. If there's a CSAM material match, the person can prove innocence by revealing the data(false positives) or the judges can increase the severity of the penalty for not cooperating.
Milage may vary depending on your jurisdiction however I think it is a good way to look at someones stuff for offensive material without actually looking at unrelated stuff. So no match, no reason to try to get into the device.
Also, this idea is even more dystopian than the original concept. The original idea was only going to scan content the user chose to push to Apple servers. This current suggests scanning the entire device just because johnny law has the device. That is soooo much worse of an idea.
I didn't say anything about Apple servers. They can implement a protocol that works over a wired connection only, gives the device the instruction to match all the files on the device against the given list of fingerprints and returns the results. No match, no results. If there's a match, return just enough to tell what fingerprints matched and nothing more.
And what is properly encrypted if you can take advantage of 0-day vulns to unlock the phone so you have access to the data in an unencrypted state. You're not playing this through to the end of what physical access to the device means.
I don't understand what are you arguing for, physical access is not a software thing and it is guarded by exactly the same mechanism that guard the access to you apple(the fruit) in your fridge.
On my proposal, all photos on the device are scanned, scan results(hashes) are stored on device but no attempts to pin you down are made. Once there’s a reason to suspect that you might be a criminal, only then the scan results are evaluated by the phone upon the request of the authorities to check on you as part of the investigation. This is blackbox system.
Yeah...
That's not a thing many people are really comfortable with in societies that are nominally non-authoritarian.
If you don't trust them to scan things on your device why are you trusting them to scan things in the cloud and why are you trusting them with both the hardware and software you run?
2. When scanning is done locally, it’s easier for them to secretly or openly modify the software to scan everything on your device, rather than just what’s just uploaded to iCloud. If they tried scanning everything (including non-iCloud images) in the cloud, the network traffic of uploading every image on your device to the cloud would be observable.
Where was this promise stated in these explicit terms, especially the definition of "personal files"? Because Apple is also promising that this only applies to file that are set to be uploaded to iCloud and the expectation of privacy is different for files uploaded to the cloud.
Either Apple's promises can be trusted or they can't. And if they can't, you can't trust anything about their devices.
Of course it is not an explicit promise and doesn't refer to "personal files" but I think it shows where OP is coming from. You can reasonably understand this message in the way they do.
You want "What happens on your iPhone to stay on your iPhone"? Turn off iCloud.
The marketing speak is marketing speak and obviously not literal.
Auto-sending all your photos to a server owned by someone else (and without end-to-end encryption!) by default cannot be described as "what happens on your iPhone stays on your iPhone" in my opinion.
They push arbitrary software updates to your device at their whim, therefore they own your device.
If it's not written in the law nothing is "supposed to"
Bad-faith actors want people to think that taking a picture of your baby in the tub will bring a SWAT team to your door the next day.
The method only returns positive on a hash-match with a known piece of CSAM from NCMEC.
The human process is looking at a picture somebody has already been convicted of child abuse for having, and comparing it with yours to see if they're the same.
You’re simply describing some of the details of how it happens.
It’s nice that there are some manual review steps, but that hardly changes what’s happening. Especially since the human reviewers are almost surely going to pass the case through to the next step if there is any ambiguity.
gov: "hey Apple, pedophiles are rampant rn, do you really need to wait before the devices upload photos to icloud before you use that on-device scanning? here's some cool proposed legislation to motivate the conversation. oh also here's some more images that are illegal."
This conversation will happen behind closed doors with much better wording and probably with real stakes for Apple. They've built a dream technology for control freaks in government across the world, something that we in the technology sphere have traditionally fought against for decades. All it just needs is a honest day's work to scan all the time vs on upload.
This is the fight to fight if you'd rather just not deal with a future when, surprise, the scope creeped but now its too normal to oppose. People will get vanned by less benign government who interpret things far more mundane than pedophilia as undesirable.
Apple could read your whole phone content and send it to governments without your consent if they wanted to, on device-scanning or not. Util they do, there is no breach of privacy.
If you believe Apple can implement one-party consent snitching on iPhone without telling anyone, then you shouldn't use closed source software in the first place, because there is zero reason to believe that they haven't already implemented this.
This misses the point. Apple has repeatedly assured its customers (I’m waiting for my Pinephone to get here so I no longer need to be one) that the devices they buy are theirs. This is how things always have been, and although you’re right they could in theory slip some law enforcement update on my phone, they’re publicly refused to do so before and I trusted them as a result.
They’re not secretly slipping in a government backdoor though, they’re backpedaling on their promises and openly installing a backdoor on my phone for no reason. Why let this slide like it’s normal, or pretend like this isn’t a betrayal? They refused to unlock an iPhone owned by a mass shooter!
Plus, for many people, Apple and Android are basically the only options for modern computing. Their decisions in this market normalize stuff like this. I don’t want future devices to be forced to implement easily-abused crap like this because Apple convinced people this is a solvable problem with machine accuracy. We’re already seeing this for open questions like moderation and copyright enforcement, with horrific results that are now just normal.
That is definetly not true. Apple has always been anti-ownership. By making the OS closed source, preventing installation of other OS, preventing sideloading applications, preventing self repair, preventing parts distribution etc etc.
What they used to say is that what's on your device stays on your device, and that you decide what you share. And they stay true to that promise. If you don't want to share you pictures with Apple, you don't use iCloud photos, end of the story.
> openly installing a backdoor on my phone
A backdoor is defined by two characteristics: one, the user do not know the existence of the backdoor. Two, the backdoor allows the attacker to bypass device security in order to gain access. You know the existence of the scanning feature, and this feature does not allow Apple nor anyone to gain access or information about what's on your phone without your consent. It is not a backdoor in any way you can think of it.
https://www.eff.org/deeplinks/2019/12/senate-judiciary-commi...
> This conversation will happen behind closed doors
It did.
> with much better wording and probably with real stakes for Apple.
Pretty much. Quote from the infamous Lindsay Graham (2019): “My advice to [big tech] is to get on with it, because this time next year, if we haven't found a way [to get at illegal, encrypted material] that you can live with, we will impose our will on you.”
And it looks like that worked, and apple got rid of this self reporting feature.
While technically correct, there is much power in the defaults that are set. iCloud photo sharing is on by default and provides some useful features, especially if you have multiple apple devices. Also apple doesn’t provide a good automatic way to do backups outside of iCloud.
And realistically speaking how many “normal” people will even be aware of how to turn this off and be willing to go to the effort? Will they have a choice? Sure, technically. Practically though the majority of people stick to the defaults.
> And realistically speaking how many “normal” people will even be aware of how to turn this off and be willing to go to the effort? Will they have a choice? Sure, technically. Practically though the majority of people stick to the defaults.
I fully agree with your point here, but also, how many "normal" people deal in CSAM? The vast majority of people just won't be affected by this in any noticeable way.
You say, and then go on to give as examples /things which haven't happened, but you fantasised might happen/. That isn't learning from history.
That's 100% not what the feature is about. People need to stop spreading this nonsense. Apple only get the result of the scans when the files are send to them via iCloud, then they, Apple, not your device, would report to the authorities. Also, they already were looking for CP in your iCloud content and report to the authorities anyway, as was shown recently with the doctor that was caught with 2k images. So whether you were or weren't using iCloud, privacy-wise on-device scanning makes literally 0 difference.
I can choose to not upload things to Apple.
If my iPhone decides to scan my photos just because, I can do nothing.
I won't accept my device being a snitch under someone elses control. Companies change values and Apple already brazenly allows the CCP to snoop on Chinese iCloud data.
You're basically upset that your operating system can read your files. Well good luck finding an operating system that cannot read your files.
Right now Apple says they only scan iCloud uploads. We can't verify that, but let's assume they aren't lying.
Why not scan your whole library? They can, they could make the argument it's to fight CSAM. I mean if you aren't uploading to iCloud because you're a pedophile, obviously we should scan your whole phone just in case. Think of the children!
> Why not scan your whole library?
That may very well be the case in the future, but nobody can say for sure. But even if they do scan other files on your phone, it's unlikely they will do that for files that don't sync to iCloud. If this bothers you, you can always just sign out of iCloud completely. You can still retain access to the app store and music subscriptions separately.
In the U.S., due to how the rules of evidence work, this would be of limited utility. You want the results of the scan to come from a trustworthy expert who can testify, who uses equipment and software that is tested and calibrated frequently. Because the suspect's own device won't have those calibration records, trying to use the results from such a scan would raise issues of foundation and authenticity.
If I were a prosecutor and I had a case like that come in, I would still send the device in to the lab for an expert forensic extraction.
(Edit to reply to a response below: Yes, theoretically, such an on-device scan could be used to establish probable cause, but that seems circular, since the authorities wouldn't be able to seize the phone in the first place unless they already had probable cause or consent from the owner, either of which would obviate the need to establish probable cause via the on-device scan.)
I guess the legislators and the tech companies can work something out on the practical issues instead of turning people's devices into always watching policemen.
There are even more when it comes to actual search warrants.
Probably not much, since there is very little that would be within third-party custody that they would need a search warrant rather than one of various forms of subpoena (including administrative ones like NSLs) for, and the latter would already be counted in the “without a search warrant” count.
What I find interesting is how our perspectives shifted over time. 1984 was considered a dystopian nightmare and within that world Big Brother wasn't always watching but rather _could_ watch at any time. The simple ability to be able to tune in was enough to create the fear and have people report others. We're well past that to be honest and interestingly our interpretations have shifted as well to Big Brother _is_ always watching and that being the dystopian nightmare. In this sense we're there in some areas of our lives and it has shifted to "I have nothing to hide" or "what can I do?"
So it is interesting to see that essentially the window shifts further and further in that direction and as long as the shift is sufficiently slow the general public seems not to care. I wonder if there is a turning point.
https://www.eff.org/deeplinks/2019/12/senate-judiciary-commi...
I'm always astonished that some (random) people feel more confident on their brand analysis than the best people at this specific topic paid thousands of dollars at Apple to do just that. Or maybe I'm the one who is wrong
While household analysts get things wrong all the time, companies are not infallible, including Apple.
How could Rome fall?
The sun never set on the British Empire.
Both me and my partner were very close to joining the apple eco system because we felt completely betrayed by G, now I'm researching alternative OS to flash my phone. We both abandoned Google search and browsers. The only FAANG I'm not actively avoiding is Netflix.
That comment looks like partly uneducated guess, partly a fallacy to refer to the “authorities of branding”. I’m always amazed to see people who assume that employees of large companies cannot make mistakes or that they have unlimited power over the decision making.
There is no authorities of branding, it is just that there are people who are paid for that, and it is very unlikely that shareholders will let Apple do things that decrease the market value over a long period of time.
People make mistakes everywhere. Teams make mistakes everywhere.
Of course it's much more likely that they know what they are doing and that they have weighed the pros and cons. But, then again, even if they still go forward with it, they have changed their course slightly. Do you believe it was part of their plan? (genuine question)
Do you trust that the code written by experts has no flaws? How about teams of experts? Do rockets not sometimes have bugs which cause them to fail? If a team of highly skilled programmers in N-version controlled critical systems can fail, why can't someone or some team in such unpredictable topics such as market analysis and brand perception fail as well?
Again: I share your sentiment that surely they have thought about this. It's just that I'm not so sure that they were as competent as you might think -- maybe because fundamentally it's a very reactive and unpredictable market!
I'm afraid you are wrong.
I'm also astonished that Google has allowed search to detoriate to a point where competition actually has a chance.
I'm astonished that Microsoft cheapest their brand by serving me ads on my Windows with Professional license.
and probably a few other things.
I already did and have moved on. And I was with them for a long time. Thousands of dollars, also. Thousands.
First, you hear a lot of people, including Snowden (while contradicting himself), say this isn't really about CSAM. That point is absolutely correct. This is ALL two things, each addressed here:
1. Legal liability, and the cost of processing as many subpoenas as they do.
Ultimately, Apple has the keys to the data they store on their servers. They could easily encrypt all the data using on-device keys, before uploading to ensure they can't actually see anything. But this would cause a huge backlash from law enforcement that would cause congress to pass legislation mandating backdoors. In fact, Apple (big tech) has been trying to hold off that legislation since at least 2019, when they met with the Senate Judiciary committee [1].
Quote from EFF article:
> Many of the committee members seemed to arrive at the hearing convinced that they could legislate secure backdoors. Among others, Senators Graham and Feinstein told representatives from Apple and Facebook that they had a responsibility to find a solution to enable government access to encrypted data. Senator Graham commented, “My advice to you is to get on with it, because this time next year, if we haven't found a way that you can live with, we will impose our will on you.”
Apple is doing exactly what Graham told them to do. They have come up with a system that manages to increase security for most users by ensuring that nobody - not even Apple - has the decryption keys for your data, while also satisfying law enforcement to the degree necessary to prevent really harmful anti-privacy legislation. They managed to do it in a really creative way.
It's not perfect of course. There are plenty of people with valid concerns, such as the potential for hash collisions and how a country like China might try to abuse the system and whether Apple would give into that pressure (as they did in the past). All of that is valid, and I'm glad to see Apple stop and examine all the complaints before pushing the release. But strictly on the topic of privacy, the new system will be a massive improvement.
2. User privacy. Yes, everyone thinks this is an invasion of privacy, but I just don't see how. The proposed on-device scanning solution provides MORE privacy than either the current iCloud system (in which Apple can be compelled to decrypt nearly all of your data) or the proposed [2] legislation – MORE privacy even for people found to meet the CSAM threshold!
It seems to me there must be a lot of misunderstanding surrounding the encryption mechanisms Apple has proposed. But having read the technical documents, my view (again, strictly from a privacy standpoint) is that it appears to be extremely sound.
Essentially, there are currently two parties that can decrypt your iCloud data with master keys – you and Apple.
In VERY greatly simplified terms the new system will set one master decryption key on your device. But Apple will now instead use shared key encryption, which requires ALL of the ~31 keys to be present to decrypt the photos. Apple will have one of those keys. The other 30 (the "threshold") keys will be generated by a hash (of a hash of a hash) of the match found in the CSAM database. If no match is found, then the shared key needed to decrypt that image is never generated. It doesn't exist.
One way to look at this is that it's the CSAM images that are the keys to unlocking the CSAM images. Without them, Apple cannot comply with a subpoena (for photos ... for now). Even people who meet the CSAM threshold, can only have the CSAM images decrypted. All other photos that have no match in the CSAM database cannot be decrypted without access to the suspect's phone.
On the flip side, Apple is bending to congress's demands by voluntarily sharing information with law enforcement. I can absolutely understand how this behavior could make even perfectly innocent people feel uncomfortable. But in the context of the understanding that you have more privacy for yourself, while exposing those who deal in CSAM (and are dumb enough to store it in their iCloud account), I have to push my logical understanding to overcome my natural but unwarranted discomfort. Anything that prevents the government from getting universal backdoor into everyone's phone is a win, in my opinion.
[1] https://www.eff.org/deeplinks/2019/12/senate-judiciary-commi...
[2] https://www.eff.org/deeplinks/2020/06/senates-new-anti-encry...
I realize this is a simplification of the actual method Apple has implemented and as it currently stands it would only scan photos that are destined to be uploaded to the cloud. If it were guaranteed that would never change then I think a lot more people wouldn't have a problem with it. But it will be abused. Every[1] single[2] time[3] this sort of system is implemented "for the children" it gets abused. The slippery slope here is real and well-demonstrated in various countries around the world.
For my part I have come across an imperfect analogy that I feel accurately captures how I feel about Apple's solution. My phone is like my diary. There's nothing illegal in there. But there is stuff that is deeply personal, private, and even some that would be terribly embarrassing if the wrong person saw it. As long as I keep my diary to myself and don't let anyone see it I have nothing to worry about. If I were to send my diary off to someone else known to read diaries then it's my own fault as much as anything else if it gets read and intimate details of my life known.
[1] https://en.wikipedia.org/wiki/Internet_censorship_in_the_Uni...
[2] https://en.wikipedia.org/wiki/Internet_censorship_in_Austral...
[3] https://en.wikipedia.org/wiki/Internet_censorship_in_Russia
This was an unreasonable and unnecessary capability, no amount of comprise makes it a good idea.
I don't want my devices to tattle on me. They exist to serve me, not the state.
Don't negotiate with terrorists.
... like all cloud providers scan your stuff and report the bad things (and Apple has not been doing it, but now proposed doing it in a more privacy preserving manner).
Your phone will listen to instructions from 3.rd parties to check on you and report you to the police(with Apple as a dispatcher).
As I said, your phone doesn't even know if anything matched.
Let me call Yet Another Insideous Concession (YAIC). It seems like this has the sell that "this has safe search built in so in the event of seizure, authorities won't have to do a full search". But actual situation is authorities would never be satisfied with things limiting their search on seizure but would be happy for this to be added where they'd wind-up using it primarily through some automatic mechanism.
You can change a product decision in a day, but it takes a LONG time to change a culture that thinks these sort of insane product decisions make any sense whatsoever. Making a long-term bet on Apple has become precarious at best.
[Edit, since I can't reply anymore because I'm "posting too fast"] I didn't say you thought that personally; in a sub-thread about Apple senior execs applying negative labels to people, and this being one of the most insulting labels applied, I think it's important to note that this label came from somewhere else. (and maybe important to note "the technical community" were not labelled "screeching voices"; the memo said "the air will be filled with the screeching voices of the minority". It didn't say "everyone who disagrees is a screeching voice").
[1] https://www.howtogeek.com/746588/apple-discusses-screeching-...
The key point is that the label did come from the collaboration that Apple engaged in.
> I wanted to share this note that we received today from NCMEC. I found it incredibly motivating, and hope that you will as well.
https://9to5mac.com/2021/08/06/apple-internal-memo-icloud-ph...
This means you've had your account sanctioned by Dang. You might want to send him an email and offer him your most profuse and sincere apology for whatever it is you did to anger him.
Assume Good Faith. If there's one thing I learned about sensationalist stories or situations, it's that the position of "the other side" / reality is far more nuanced than the story tellers would like to make you believe. The result still may be poor, but the steps that brought people there are not nearly as insidious as it's normally presented.
A system that is trivial to circumvent and which only catches people sharing pics that have already been added to a database is not going to move the needle on actual physical abuse of children.
I think it's important to note that Apple is late to this, and they're just playing catch-up in implementing this scanning. The only difference between Apple and others is that they do it completely (or partially) on-device rather than all on their servers. And they they explicitly told people exactly what and how they're doing it all.
It's kind of a funny situation where in Apple being more transparent than any other implementer of this same process, they've gotten themselves in more strife.
> According to NCMEC, I submitted 608 reports to NCMEC in 2019, and 523 reports in 2020. In those same years, Apple submitted 205 and 265 reports (respectively). It isn't that Apple doesn't receive more picture than my service, or that they don't have more CP than I receive. Rather, it's that they don't seem to notice and therefore, don't report.
> In 2020, FotoForensics received 931,466 pictures and submitted 523 reports to NCMEC; that's 0.056%. During the same year, Facebook submitted 20,307,216 reports to NCMEC.
https://www.hackerfactor.com/blog/index.php?/archives/929-On...
You can argue it's better to have neither type of scanning, but if Apple considers it a critical business issue that their cloud is the preferred hosting site of CSAM[0], then they presumably have to pick one or the other.
You can also argue that on-device seems creepier or more invasive, even if it doesn't result in Apple examining your photos, which is a reasonable reaction. It certainly breaks the illusion that it's "your" device.
But it's a fact that the on-device model, as described, results in less prying eyes on your iCloud photos than the on-server model.
[0] I'm not claiming this is the case, just saying for example
If we're looking at the end result, a mitigation of a loss of privacy is an increase in privacy compared to the alternative, no?
I mean clearly what you're saying here is "scanning always bad!". I understand that, I really do. I'm saying that scanning was never not on the table for a large corporation hosting photos on their server. Apple held out on the in-cloud scanning because they wanted a "better" scanning, and GP's point is that it's ironic that the one cloud provider willing to try to make a "less bad" scanning option is the one most demonized in the media.
None of this is to argue that scanning is anything less than a loss in security and privacy. Yes, yes, E2EE running on free and open source software that I personally can recompile from source would be the best option.
I guess you could say that in the same way that you can say that a gambler who just won $10 is "winning", even though their bank account is down $100,000. It only works if you completely lose all perspective.
I think that may be because it's far from clear that Apple's solution is "less bad".
Every single photo you upload is getting scanned -- it's just that Apple is doing the scanning on "your" device instead of their servers.
From the point of view of the privacy of your photos, I fail to see what the difference between the two is. I mean, if they did the exact same type of scanning on their servers instead of your device, the level of privacy would be identical.
In terms of general privacy risks, not to mention the concept that you own your devices, there is an enormous difference between the two, and on-device scanning is worse.
Good point. The question is privacy "from whom". For me, privacy "from apple" means mostly from malicious individuals working for Apple (indeed, if you have an iPhone running proprietary Apple software, you could never truly have privacy from Apple the corporation).
There are documented cases of employees at various cloud services[0] using their positions of power to spy on users of said services. Performing on-server scanning implies that servers regularly decrypt users' encrypted data as a routine course (or worse, never encrypt it in the first place), which provides additional attack vectors for such rogue employees.
On the other hand, taking the on-device scanning as described, the on-device scanning process couldn't be possibly used as an attack vector by a rogue employee, since Apple employees do not physically control your device. Maybe an attack vector here involves changing the code and pushing a malicious build, which is a monumentally difficult task (and already an attack vector today).
[0] https://www.telegraph.co.uk/news/2021/07/12/exclusive-extrac...
For me, privacy means that I have control over who I disclose what to. But context matters. If I'm in my own house, I (should) have almost total control over disclosure. When I'm in someone else's house, I have very little control as I'm subjecting myself to their rules.
A smartphone is probably the most intimate, personal device most people will ever own, and it's the equivalent of their house. However, if you're using cloud services, then you're in someone else's house and are subject to their rules.
That's why, in my view, doing the scanning on-device is not only dangerous, but unethical. Doing the scanning on the servers is neither of those things.
I get the argument about rogue employees, but I don't find it persuasive. I'm told that Apple keeps your data encrypted on their servers, although they hold the keys. If that's so, then "rogue employees" are something that Apple can, and should, control.
Arguing about where in the combined system the processing happens is shifting the deck-chairs on the Titanic, it's not making one part of the system more or less responsible than any other part.
CSAM scanning stops common proliferation of already identified materials and can help keep those from casually entering new markets. It does not protect children from being newly exploited by people using these services unless the services are also doing things they claim not to be doing.
In that case, Apple's claim of critical importance, if we interpret that as any more than rhetoric, doesn't mean what they imply it to mean.
Edit: I replied before you edited your comment. Leaving this one as is.
While I only know about this through anecdotes people share, I understand this systems generate leads so that agents (usually federal) can infiltrate groups and catch people uploading new material, thus preventing them for further victimizing minors.
Scaling up detection also makes it more tempting for bad actors to seed more content to fabricate the appearance of an epidemic. We already have inaccurate gunshot detection systems, field drug tests, and expert bite mark analysis being used to convict people. Would a jury even be able to examine the evidence if it involved CSAM?
The prosecutor will hire expert witnesses who will explain that their extensive training and education has led them to believe that the evidence is certainly illegal material.
Not sure if you are honestly asking about the jury thing but judges do have the legal superpower to see illegal images and they will usually instruct the jury to vote based on what they saw.
The US federal prison system being one of the biggest bullies on earth though, this cases rarely go to trial.
It’s not only a matter of Apple’s openness about it. It’s the fact of what they’re announcing.
The fact that cloud providers aren't building their systems in such a way that they are unable of conducting such spying is cause for concern. The fact that they are conducting such spying is outrageous.
One of the most common is “scanning” your location constantly, feeding your daily routines to marketing data aggregators, which is arguably more invasive of the average person’s privacy than CSAM flagging.
I’ve posted in the past a list of a short-list of offending SDKs frequently phoning home from across multiple apps from multiple developers. Since weather apps sending your location surprised people, I thought this problem would get more traction.
This Apple thing, where this is iCloud file upload client SDK doing a thing on upload, is an instance of this class of problem.
It’s not an Apple thing, it’s a client SDK thing, and the problem of trusting actions on “your” end of a protocol or cloud service is not a solved thing.
It isn't the same process, it's an on-device scanning process and Apple is the first to implement this. Had Apple said they were scanning iCloud directly nobody bat an eye (I, for one, assumed they already did).
I don't think this is a relevant distinction. If the device had known the result and just sent Y/N to Apple, what would change in your argument? Nothing. Your last sentence would be just as arguable.
>Isn't this like "scanning in iCloud" but without Apple needing to have a decrypted photos in their servers?
Note that Apple right now already has the decrypted photos since they have the decryption key. There's no evidence they are even considering E2EE right now, and since there are other legal requirements for scanning (e.g. terrorist material) I'm not sure this allows them to implement E2EE.
And I don't see how the client-side feature can remain as is. There are obvious cases that would be caught by the typical server-side scanning and won't be caught here, so once the door was opened, the government will pressure. For example:
* What happens when the NCMEC database updates? It could be that the phone rescans all your images. Or that apple keeps the hash and rescans that. Note that the second case is identical to some server-side scanning implementations.
* What happens when you upload something to iCloud, delete it from your phone and then the NCMEC database updates?
If Apple keeps the hash, it's just server-side again. If Apple doesn't keep it but uses client side scanning, the phone has to keep the hashes so you can't ever truely delete an image you've taken. If there's no rescan, the bad guys get to keep CSAM on iCloud so long as they passed the original scanning with the older NCMEC database - surely the government wouldn't accept that.
(I considered scanning on download but I don't know if Apple/the government would like this compromise, since with that approach CSAM can remain on iCloud undetected so long as it's not downloaded, anyway it's not in the original papers).
Basically, either they scan on client-side more than they let on or we end up in a world with both server-side and client-side scanning. The latter is arguably worst of both worlds, the former has implications which need to be looked at.
I would argue that 'scanning' is the process of collecting data, not necessarily of interpreting it.
Apple takes a photo, runs it through some on-device transformations to create an encrypted safety voucher, then it gets "interpreted" once it's uploaded to the cloud and Apple attempts to decrypt it using their secret key.
Google uploads a raw photo, which itself is essentially a meaningless value in the context of identifying CSAM, and Google "interprets" it on the server by hashing it and comparing it against some database.
In both cases, the values that are uploaded by the respective companies' devices don't mean anything, in the context of CSAM identification, until they are interpreted on the server.
Some of Apple’s management must ponder that if only they didn’t go to such lengths in denying themselves access to user data, they’d have it so much easier—given no other takers of such a challenge among mid- to high-end device manufacturers, we all would probably have settled for e2e just never being a feature of commonly available cloud services. I wonder how successful the privacy-focused promotion had been for Apple; they seemed pretty OK making people want their devices for all the other reasons.
This is wrong, photos (and most data on iCloud) is not e2e: https://support.apple.com/en-us/HT202303
Not really. I'm just saying it's laughable to think that CSAM scanning in its current form is critically important. Maybe it's critically important for feelgood and PR but not for actually preventing child abuse. It's almost like saying scanning for catalogued images of violence stops violence. If it only were that easy, damn, the world would be a good place.
Now as to what online providers should or shouldn't do, I can't say. But a part of me hopes that they continue the march towards egregious censorship and privacy violations so that people would eventually 𝐖𝐀𝐊𝐄 𝐓𝐇𝐄 𝐅𝐔𝐂𝐊 𝐔𝐏 and realize that there's no way to have freedom and privacy when you're handing your life to corporations and proprietary software. I really do wish for a world that is de-facto free software and fully controlled by the user.
As for iCould, I have no skin in the game. I've never used an Apple product.
Once the on-device scanning Pandora's box is open, it's trivial for governments to request more stuff to be added to the databases and Apple can't claim the defense of "we have no such ability currently" anymore.
If I was paranoid I'd wonder how much astroturfing is going on here.
This is a mischaracterization of many of the arguments.
short_sells: My goal here is meta-goal: I am not trying to change your mind on this issue; rather I want you to acknowledge the strongest rational forms of disagreement.
This is a complex issue. It is non obvious how to trade off goals of protecting kids, protecting privacy, minimizing surveillance, catching predators, and dealing with the effects of false positives.
It is too simplistic (and self defeating) to think that just because people disagree with a particular conclusion that they are not allies with many of your goals.
So what is it actually trying to accomplish?
I really struggle to believe that they are trying to protect kids (out of the goodness of their hearts).
The only explanation I can think of is that this is some attempt at appeasing government agencies.
> but we have seen in the past that privacy once lost is nigh impossible to regain
Yes, this is a key argument in the mix.
Some follow up questions:
1. As I understand it, here on HN, we are an international audience of various ages. With that in mind, I don't know your contextual experience. Are you scoping this (a) to the internet era (roughly 2000 to present)? / (b) to particular countries?
2. The statement quoted above is stated as if it is a fact, but I hope you realize it is actually a prediction. What is the historical context for this prediction? How far out into the future are you predicting?
3. Can you pin down your prediction more precisely? What does "nigh" mean? (There is a lot of variation in what "approximately" means to different people. Often the 'exceptions' are quite informative.)
4. The argument, as written, is quite general, which makes it hard to discuss. Whose privacy and in what context? Chinese citizens searching the internet? Journalists doing investigative reporting? Americans shopping in surveilled supermarkets? (Think of this as an opportunity to explain)
5. Do you mean all of the above? If you do, yes, people say that online privacy has eroded in many senses. At the same time, the tools for encryption have become more powerful, understood, and used. My point: if you make a very general statement, it is only fair if you cover the full range here.
In summary, with the above questions, I want to both better understand you -and- push back too. Unfortunately, I don't find the discussion chain above (the ~3 ancestors) particularly persuasive. I say this even though I agree with some aspects of it.
So you know where I'm coming from: in almost all situations, I've found it is more effective to understand, discuss, explain, persuade rather than 'writing off' a group of people because you don't really understand them.
P.S. I've addressed your other points in a sibling comment.
This form of question, as written is unnecessarily limiting ...
(a) there doesn't have to be one thing that Apple was trying to accomplish
(b) there doesn't have to be one motivation
... so I'm going to respond to the spirit of the question with a set of explanations, all of which may be true (to some degree) at the same time.
- parents are fearful of their kid's online activities;
- parents are open to trying new ways to give their kids freedom with some guardrails;
- yes, many people at Apple do want to protect kids out of the goodness of their hearts. This fundamental instinct is widely shared, particularly among parents.
- putting the 'why' aside, many customers perceive value and will pay for it;
- Apple executives are mostly profit-seeking (with certain constraints such as: mental models, brand constraints, regulations);
- shareholders seek profits and generally have less loyalty to any particular company's 'values' -- meaning they will 'shop around' for the best performing companies;
- as a group, shareholders see mostly upside and little downside -- don't perceive significant direct harm from these changes (at least, not until this became a public relations issue);
- generally, corporations benefit from playing nice with the U.S. government;
- Apple, in particular, has quite publicly pushed back on law enforcement's calls for decryption;
- in particular, with heightened scrutiny of the large tech companies, olive branches are particularly useful;
- some at Apple may prefer to lead with a proactive solution rather than wait for imposed regulations;
- some at Apple see this as a proactive branding opportunity;
- some Apple engineers are at the top of their field regarding encryption, security, etc and may have deemed their offering the best practical option available;
- some at Apple certainly understand the risks but assess the balance of false positives and false negatives differently than you do;
My hope is to make it a bit easier to recognize the complexity here. Though it may be true that organizations act as one entity, it is not true that they have singular intent. Attempts to claim a singular intent or goal are subjective interpretations.
Note: the list above is presented sequentially, but I am not claiming any causal ordering. They would be better presented as a network/graph connected by topics and relationships.
Ah, good old apophasis:
> a rhetorical device wherein the speaker or writer brings up a subject by either denying it, or denying that it should be brought up. - https://en.wikipedia.org/wiki/Apophasis
In relation to https://news.ycombinator.com/newsguidelines.html :
> Please don't post insinuations about astroturfing, shilling, brigading, foreign agents and the like. It degrades discussion and is usually mistaken.
If one was paranoid, they might wonder if you forgot to switch accounts /s
How so?
And that's what Apple has announced. Comparing that to:
> "No other company is scanning for CSAM on your phone"
Suggests that you think the Apple system is scanning more than what you upload to the cloud, which it isn't. Or, less charitably, suggests you /want people to think it is/. Your other comment here https://news.ycombinator.com/item?id=28405476 suggests the same. And your comment here https://news.ycombinator.com/item?id=28405502 the same again.
no, they're just doing it in the cloud, after everything was uploaded automatically :)
I'm genuinely curious about your thoughts but to be clear my focus is on this very narrow, nigh nitpick tangent.
See war on drugs or piracy, or alcohol prohibition for instance.
Now there's a million ways to share pictures online in a manner that bypasses the few big platforms' interference, and you really don't need to be a genius to use (say) password-protected archives. That's how a lot of casual online piracy happens.
This thing does very little to prevent spreading CSAM pictures, and it does nothing to prevent actual child abuse.
Which brings me to your example of a password protected archive. I'm ignorant on specifics so I'm just going to sketch a broad argument and trust that you'll correct me if my premise is incorrect or my argument otherwise flawed. Essentially, if something is opt-in instead of opt-out, a non-trivial portion of the population won't do it. Especially if it is even slightly technical, there are just a lot of people who will just stop thinking as soon as they encounter a word they don't already know. So if the preventative measure is something that is not automatic and built in to whatever tool they are using to share images, then that preventative measure will not protect most of them. So to bring it full circle, I think it would do much to prevent the spreading of CSAM because other bans have been effective and I don't think most people have the technical literacy to even be aware of how to protect themselves form surveillance. As you say you don't have to be a genius, but I'd suggest you'd need to be above average, which gives you over half the population.
Also thanks for responding, I hope I'm not coming across as unpleasantly argumentative, I mean all this in the most truth-seeking sense of a discussion (I was going to say 'sporting sense of a debate' when I realized I had never been part of a formal debate team and that might not mean what I thought it meant, heh).
Are you talking about a state where cannabis was de-criminalized?
I agree that ease of access does have an effect on people, but the effect of iCloud scanning is so marginal in the grand scheme of things that it's almost like fighting drugs by installing surveillance cameras in malls. They just go trade and smoke elsewhere. The friction is virtually zero, but the privacy concern of scanning on half a billion Apple devices is much worse.
It's worth keeping in mind that CSAM is already highly illegal and banned, whether Apple scans iCloud photos makes no difference on that front. So it's nothing like the difference between weed being de-criminalized or not.
Also, fact is you already have to jump through hoops to obtain CSAM. It's very rare to stumble upon it being casually shared online (I think the last I witnessed it must've been around 15 years ago on 4chan, and somewhere between 5 and 10 years ago in a spam attack on freenode). Trying to search for it on the clearnet is mostly going to yield nothing.
In general, people also tend to know when they're doing something highly illegal. And yet they still do it, just taking the steps to try avoid being caught. No difference with CSAM. They will jump through hoops, and "don't store child porn on iCloud" is the tiniest of hoops to jump for real.
Password protected archives were meant to be just one example of how to bypass scanning on cloud platforms, and one that happens to be widely used among casual pirates. Google drive might be one of the biggest pirate services around these days. The bigger point I was trying to make is just that there are countless ways to share files without exposing their contents to scanning. Nothing for people who are willing to jump through hoops to get CSAM.
Finally, one point I've had to try make over and over again is that detecting the storage or distribution of old (catalogued) CSAM photos is only very tangentially related to actual abuse of childen. Unfortunately that keeps happening even if you destroy the internet and make sure no photo is ever stored in the cloud again.
I've said it before: child abuse and violence existed before cameras and internet, and will continue to exist. Detecting images of abuse or violence is not going to stop abuse or violence.
And if someone makes a system that is efficient at detecting all catalogued (=old) images of CSAM, then that might just create a larger market for "fresh" (uncatalogued) child abuse. Credit to nullc for realizing this.
And on protecting-the-children front, there are much bigger problems than stashes of old CSAM. Like grooming, or chatrooms where child prostitutes are forced to stream for an audience..
1. There is not much overlap between people sharing pictures from the database and people sharing new child porn that is not in it.
2. People sharing child porn are a lot more smarter or security conscious than the average person.
https://www.missingkids.org/content/dam/missingkids/gethelp/...
Hundreds of thousands of people die each year due to filthy criminals driving too fast. Introducing this measure will save lives.
If you are uncomfortable with this measure, you drive too fast.
Over ONE HUNDRED people die per year from people not coming to a complete stop at stop signs, and at Apple, we care!!!!!! We'll never let the screeching voices of the minority stop us from invading your privacy for no good reason. We like the screeching, it makes us feel important and relevant. As the inventors of a small computer with a battery in it, we consider ourselves better than God.
In other words, we could improve the driving experience and save lives with a little bit of work if we had folks with a working brain in government and elsewhere.
https://about.fb.com/news/2021/02/preventing-child-exploitat...
"We found that more than 90% of this content was the same as or visually similar to previously reported content. And copies of just six videos were responsible for more than half of the child exploitative content we reported in that time period."
"we evaluated 150 accounts that we reported to NCMEC for uploading child exploitative content in July and August of 2020 and January 2021, and we estimate that more than 75% of these people did not exhibit malicious intent (i.e. did not intend to harm a child). Instead, they appeared to share for other reasons, such as outrage or in poor humor"
So a lot of this is memetic spreading, not pedos and child abusers sharing their stash of porn. And people don't react to child porn by spreading it like a meme on Facebook, so what are these pictures that get shared a lot? What's happening is people find a funny/hilarious/outrageous picture and share that. Funny moments might happen when kids play with pets, for example.
The other part is consenting teens sexting their own photos. And then there's some teens (e.g. 17-year-olds, which by the way is old enough to consent in some countries) getting accidentally shared along with adult porn by people who don't know the real age.
https://research.fb.com/blog/2021/02/understanding-the-inten...
"Unintentional Offenders: This is a broad category of people who may not mean to cause harm to the child depicted in the CSAM share but are sharing out of humor, outrage, or ignorance.
Example: User shares a CSAM meme of a child’s genitals being bitten by an animal because they think it’s funny.
Minor Non-Exploitative Users: Children who are engaging in developmentally normative behaviour, that while technically illegal or against policy, is not inherently exploitative, but does contain risk.
Example: Two 16 year olds sending sexual imagery to each other. They know each other from school and are currently in a relationship.
Situational “Risky” Offenders: Individuals who habitually consume and share adult sexual content, and who come into contact with and share CSAM as part of this behaviour, potentially without awareness of the age of subjects in the imagery they have received or shared.
Example: A user received CSAM that depicts a 17 year old, they are unaware that the content is CSAM. They reshare it in a group where people are sharing adult sexual content."
So there's reason to think that the vast majority of this stuff isn't actually child porn in the sense that people think about it. It might be inappropriate to post, it might be technically illegal, but it's not what you think. And if it's not child porn, you can't make the case that it's creating a market for child abuse. By reporting it, you're not catching child rapists.
I don't have a reference handy but I recall reading about the actual child porn that inevitably does get shared on every platform, much of it is posted by bots over VPNs or tor. So its volume isn't representative of the amount of child abusers on the network, and reporting these accounts is not likely to lead to anything.
Also: In May 2019 the UK’s Independent Enquiry into Child Sexual Abuse heard that reports received by the National Crime Authority from the United States hotline NCMEC included large numbers of non-actionable images including cartoons, along with personally identifiable information of those responsible for uploading them. According to Swiss police, up to 90% of the reports received from NCMEC relate to innocent images. Source: https://www.article19.org/resources/inhope-members-reporting...
Out of those remaining 10%, how much leads to convictions? Very little. Sorry can't dig up a source right now. Point is: millions of reports lead to mostly nothing. Meanwhile, children continue to be abused for real, and the vast majority of those who want to keep producing, sharing, and storing such imagery surely have heard the news and will find a different way to do it.
Platform operators are incentivized to report everything, if they're playing the reporting game. Tick box "nudity or sexual conduct", tick box "contains minors"? Report it.
It doesn't help the discussion at all that everything involving nudity and minors (even cartoons) gets lumped together as "CSAM" with actual child porn produced by adults who physically abuse kids.
I don't think the NCMEC shares numbers about how many of their reports result in actions by law enforcement agencies. They probably also don't really know, its kind of like a dragnet.
Also under the current "I'll know it when I see it" CSAM doctrine in US courts cartoons can actually be illegal and cartoons depicting the abuse of children are usually banned on most big media sharing platforms in the US, and most companies in the US won't host you or let you serve ads if you have that material. So yeah, it's not only muslim totalitarians that are ok with banning cartoons and punishing people for drawing them or sharing them, Uncle Sam may also send you to jail and deprive you of your rights if you draw the wrong thing.
I'm not surprised. Quantifiable accountability can be extremely problematic if you aren't actually making meaningful impact on the problem that you are claiming to help solve.
It's only production of new/novel CSAM that harms children. Sharing of existing, known CSAM (what this system detects) doesn't harm anyone.
Stupid child abusers who put known-pornographic images in their iclouds are still child abusers. The fact that fruit is low hanging isn't a reason not to pick it.
They were kind of a weird org, the police of the network, and they kind of kept to themselves but carried a ton of weight. When they were looped into a meeting for a new feature -- for example, "Should we let users send videos to each other?" -- they'd list out the evil ways people would use them, and then list out the various CSAM scans we'd be obligated to do if we hosted the content on our servers. They didn't have the means to block features, but they did put a healthy fear-of-God into us, and made it so we didn't have a lot of big public debacles of kids seeing porn on the home screen of the device, or things like that.
I can imagine that Apple has a similar group. I can imagine they went to some executive, told them that this would be their best way to comply with the law, of course you don't need to access the images themselves, that would be a privacy violation and we don't do that! We just need the hashes, may we remind you this is CSAM we're talking about? Then it went up the chain and people were excited to "protect the kids" and protect the brand, hashes != user data, everyone wins!
I'm guessing this move was mostly misaligned priorities, and possibly some genuine incompetence or perhaps people not speaking up when they saw the potential here.
And here we have it, a situation where the content a user generates on what's ostensibly "their machine" is being treated more and more, by companies and the state as being equivalent to "UGC", user generate content - stuff explicitly being shared. Obviously, the insidious thing is that no one will be able to create anything without even the creation process falling under someone's "terms of use".
No longer buying iPhones or Macs. I was planning on upgrading to the Mac Mini with M1 chip later this fall but now I plan on building a hackintosh instead. I also no longer recommend Apple devices to friends/family.
I got myself a cheap android phone which I have de-googled myself. I got this Android phone ($190 USD for a very good phone - 8GB ram, 12gb space):
https://www.amazon.com/UMIDIGI-Unlocked-4150mAh-Capacity-Sma...
I use Firefox for YouTube on it with the following add-ons:
1. uBlock Origin
2. Video Background Play Fix add-on
This allows me to use YouTube as a background playback music player. And if needed, I use YouTube-dl to get the audio files and put them on the phone.
You can check out several tutorials to de-google an android phone.
I'm not looking to start another android vs iOS debate here. There's plenty of that online that I and others can reference. I'm more interested in seeing how people are finding alternatives or what privacy tradeoffs they are willing to accept to avoid Apple's recent photo scanning move.
[1]: https://arxiv.org/pdf/2010.10088.pdf (PDF WARNING)
[2]: https://www.cnbc.com/2020/01/16/how-to-stop-google-maps-from....
The battery life is really good, not sure if that's just the hardware or whether the debloated OS means less power is consumed.
1. Apple announces the scanning feature (done)
2. People dislike it; backslash (happened)
3. Apple is worried about the brand, publishes statement that they are going to delay (happened)
4. People say "great", "wonderful" (ongoing)
5. Apple waits 5 months, release this crap feature anyway
6. People moved on, media does not want to repeat the same messages again, not many people care anymore
7. DONE.
This is the same thing that Facebook did with its TnC. People complained, Facebook took it back, re-introduced it 3 months later. Nobody cares anymore.
I stood my ground and actually took some action when something made me unhappy. This is the only way things change.
I've been on a flip phone and never owned a smartphone but a recent role I'm taking requires having a smartphone for email / Slack access.
I know it's a matter of picking between 2 lesser evils but has anyone avoided both and went with an open Linux based phone that has a really nice user experience and decent battery life? All of the research I've done leads to Linux / open phones just not being there yet, even phones that cost $900 like the Purism Librem 5. The Librem 5 looks like it came a long way in the last year and I am really rooting for them to succeed, but is anyone using a current one as of today or know of a viable alternative?
I think the easiest thing to do (aka the #1 method of de-Googling) is to run certain versions of Android that have the play store removed, that has a version of android built from the AOSP with an alternate store like F-Droid enabled.
If you search "AOSP phone" or "de-google android" you could get places.
The other thing I have thought about is getting a Pine phone.
tldr if you have an even somewhat recent unlock(ed)/(able) android device, you can probably drop a very pure AOSP build on it pretty easily.
I mean, you can buy "safe" smartphone, but first you can't prove beyond reasonable doubt that it is actually safe and private, and second, you attract more attention because the same phones are being bough by the criminals.
I use an older iPhone in airplane mode. I get over a week of battery life. I forward calls to my personal if I'm away from wifi and on-call, and they do not get my personal phone number.
But yes, the above has flaws in that there's always a 0.01% chance I send something to the wrong person if my contacts co-exist in 1 app. I'm dumb when it comes to smart phone capabilities, maybe there's a way to 100% silo off 2 sets of contacts or profiles? It's something I'll need to research.
This reminds me a bit of the DNS-over-HTTPS hand wringing as well. DoH points out that applications can run their own DNS and you can't easily control that behavior at a network level like with conventional DNS. That is pretty troubling from a technically literate user perspective but it's not actually new. Applications could always hard-code DNS. DNS-over-HTTPS just made us think about it.
Similarly Apple has complete control of your device. They always have, it's actually part of the value proposition. There has been a lot of debate about what Apple should or shouldn't do here but the fact is they could have pushed this out silently and it could be scanning your entire device right now, we just don't know. We have to trust Apple at their word and after their announcement that they would push this kind of capability I'm not sure how we can ever trust them again.
It doesn't matter if the end user doesn't audit everything themselves, that's impossible to do in a reasonable manner, but the constant auditing and testing by many independent entities gives, in my opinion, a better assurance of privacy than some marketing material saying they deeply care about me.
Somehow a large subset of the general public doesn't seem to understand this. And act all surprised when Apple, Google, Microsoft or whatever screws them over.
Really? What the fuck did Apple do, that you gave them total control to dictate _your_ walled garden in the first place?
I just don't get it. My best guess is Sunk-cost-color glasses,. From the moment they launched itunes (which is 15y old for me) I understood their value was a walled garden as a platform. Users as a commodity. Valuation as overlords.
What ever gave you a different idea?
The latter when it flags something in a message to the child warns the child and asks if they want to view it. If the child says "yes" and is 13+ it shows it to them and that is the end of it. If the child is 12 or under, they are warned again and told that if they view it their parents will be notified. If they say "yes" again they are shown the image and their parents are notified.
Note that no one is notified unless the recipient is an under 13 child and the child explicitly decides to allow their parents to be notified.
I've seen much fewer objections to this. I don't see why they seem to be tying this and the iCloud scanning together in one release.
6M/91d/24h is about 2700 units per hour, if those numbers from statista are true.
1: https://www.statista.com/statistics/263444/sales-of-apple-ma...
That's not a reason not to leave though.
On a Mac, you need to allocate a fixed amount of RAM to Docker, which isn't the case on other platforms where it can dynamically allocate and release as much as your containers demand.
It's very painful in workloads that need Docker. Especially on MacBooks where you can't upgrade the RAM to compensate.
(while on linux one can use the docker command line tool without any docker desktop thing, on mac docker desktop wraps together running a linux vm to run the docker daemon & containers inside, making it the most straight forward way of running docker on mac)
I can't officially say how Docker will implement DD on Linux but I have a hunch it will be optional.
If it's not optional then it means you will need to install DD on your servers to run Docker which I can't realistically see happening. I'm guessing DD on Linux will just provide a few quality of life enhancements that exist on Windows and Mac, such as the host.docker.internal address and a UI for certain things for the folks who prefer that.
But Linux is a side project for Dell and Lenovo. They put up with it but don't really support it. Support a vendor who is all in on Linux.
Build quality is a big deal. I feel like the midline for PC makers is pretty low -- Dell has mostly been kinda trashy, though the XPS machines have a good feel to them (it's a shame they've been kind of lemony for us).
Absent the keyboard kerfluffle, Apple's build quality has traditionally been very high -- IME, on par with the IBM-era ThinkPads in the sense that the hardware lasts longer than technical viability. How is S76 here?
The coworker did eventually move to a Mac, but has recently expressed dissatisfaction and may move back to Linux. Not sure if that'll be with a System76 machine, though.
(I'm not trying to argue. I'm always curious.)
I support all measures against child abuse, but child abuse is always the trojan horse.
I've migrated to a self-built Android (that was quick and mostly painless, I would recommend CalyxOS and/or Graphene to anyone) and have a long-term plan to completely pull myself out of Apple ecosystem.
Also it was a good reminder to degoogle myself, so I did.
The presumption of guilt is the problem. Freedom means that I shouldn't even be suspected, and certainly not searched or monitored, unless there is a clear reason.
If there is a reason to suspect me, all of these tactics are fair game. But not before that.
In Apple's implementation, the device never knows if a particular picture is a CSAM match. That determination is made in iCloud when the server attempts to decrypt the safety voucher. Until that point, it's just an encrypted payload that the device can't interpret one way or the other.
In your analogy, where "your home" is the equivalent of "your device", the police never enter the home to determine whether you have anything illegal. Instead, there's some process that boxes up all your stuff into nondescript, anonymous boxes that can only be opened if someone has the key.
To determine illegality, you'd have to voluntarily send them off to the police (police = iCloud), where they only have a handful of keys - they have a "gun" key, a "knife" key, and a few other keys for boxes containing illegal items. But the boxes are nondescript, so the police don't know whether you have anything illegal until they insert the key and turn it. If the "gun" key successfully opens the box, the box contains a gun, and you are reported. If all the police's keys fail on a particular box, then whatever is inside must not be illegal and the police never learn its contents.
Needless to say, this analogy is tortured because it's hard to apply Apple's tech to a physical process, but the point is that whether something is "illegal" isn't able to be determined until you voluntarily ship it off to an entity that has the keys to unlock it.
That's a distinction without a difference w.r.t the end result but I'll offer a more apt analogy regardless.
A better analogy would be the police installing a device in your house that's capable of seeing or hearing anything that happens and then claiming there's nothing to worry about. The device is only watching a specific door in your house and forwarding a hash of that information to their servers. Nevermind that it would only take a policy change and an OTA update that you have no visibility into, or chance of blocking, before it's watching your entire house in real-time.
But hey, you have several other doors to enter or exit your house from, and it's not like the camera actually knows anything, only the people on the other end do, so what's the big deal right?
Would you trust the police in that scenario?
A delay in either case is welcome.
I think/hope they'll just move to the simple compromise of scanning stuff on iCloud like everybody else, which is far less of an intrusion.
iCloud subs renew at the end of the months; I bet they were maybe surprised at the number of people not paying them money anymore for iCloud…
I bet you are overestimating how many people care about this kind of stuff.
If they finally roll this out, I think my next phone will be a Nokia 1100. I don't have anything to hide, but I'm tired of everyone trying to track and sneak into your personal stuff, for whatever reason.
Without knowing what their refinements actually do, it's too uncertain.
> Here's an extremely sophisticated mechanism that has insane negative potential ramifications for our users and our brand, but that's ok because it's all in the name of catching pedos.
> PS: And pedos can turn off this mechanism with one toggle.
Since this sounds too idiotic to be real, people conclude it must be evil, by Occam's Razor.
I have a deeper fear: That it's actually that idiotic.
This is good but not good enough. Why? Because delayed means it might still happen. What we're aiming for is "cancelled".
Scanning your phone and your content is a terrible capability to exist and precedent to set. It's a small step to extend that system to, say, scanning for DMCA violations, pirated content, etc. And those will be justified by those activities supporting terrorism.
It's interesting in that it talks about both server and client side scanning, and some of the things that WhatsApp does.
An interesting fact from the article: in 2020, Whatsapp made 400,000 reports to the NCMEC. Apple: 265
There's a big difference though between scanning a library (which is closer to what DropBox/OneDrive are doing) and when it's messaging platform whose ultimate goal is communication between people. It does make sense that those catch way more.
If Apple had roll those scans on iMessage attachements (which they didn't planned to, though the feature looked to be designed for it way more than it was for a library scan), you would probably see comparable numbers (modulo those platforms relative marketshares).
One big problem though is are those large numbers actually actionable ? I think I remember seeing a quote from Swiss (?) law enforcement that complained that the reports they got from NCMEC were nearly all of the time unactionable.
There are possibly many reasons from this, it could be differences in local laws, algorithms that wrongly report things, or other factors (maybe not enough to identify the user of the acount, etc).
This is where one feature of Apple's design was a bit better: they didn't plan to report every single occurence, but would only if 30 such images were detected. Part of the reason they did was because of the imperfections of the NeuralHash mechanism, sure, but in the end it doesn't matter.
One can argue doing this would at least generate more actionnable reports. It shouldn't be a numbers game.
It sounds like simply being able to say "This user was messaging with 4 known offenders,and sending something the size of images" is unlikely to be helpful to law enforcement.
Does anyone really think we're only another 20 million reports a year away from solving the CSAM problem?
I might say that it's possible there are actions that can reduce, but not eliminate, the problem. What if another 20 million reports saved one child from exploitation? 10 children? 1000 children?
At some level, this boils down to a society question. We all agree CSAM is evil. How does it stack up against other things we think are evil? I fear that, in the end, there is no middle ground that includes eliminating CSAM and keeping 100% privacy.
No plans to drop these features
I seem to recall gun trigger locks being pushed with the exact same phrase (because “self-defense obstacles” would be too accurate)
“For the children” is the last refuge of politicians and conmen.
So what’s the bottom line?
i’m guessing that scanning (for many things) is mandated by multiple governments, and on-device scanning is orders of magnitude cheaper than server-side scanning.
I hope this PR nightmare for Apple continues until the full extent of mandated surveillance is exposed
But it probably won’t - Apple’s mistake was in thinking that people would blindly accept this as a desirable feature, instead of just quietly implementing it.
Or, maybe Apple did it this way on purpose to expose the issue to public scrutiny.
It’s too late anyway. Their reputation is shot now. I don’t trust them.
I mean, I'm not surprised this whole thing backfired and that there was a strong uncanny valley reaction to the prospect of having parts of the workflow happening in your device ("a policeman in my pocket" I read somewhere).
I am surprised though that it seems impossible to resolve the issue (or at least making progress in the framing of) this with a honest and nuanced conversation.
Plenty of people think the same.
But let's face it, we're feet deep in it already: unless you control what code runs on your device you're never safe from code that scans data on your device.
I not sure I really buy the slippery slope argument. If in the future Apple wanted to be more intrusive, they would just be more intrusive and scan your photos on your device for real, not with a convoluted and probabilistic fingerprint method.
What is the weak point? To get people accustomed to being scanned? Aren't people already? Your content is already scanned the moment it reaches to the cloud.
What does this extra client-side scanning add to the dystopia that we're not already experiencing?
The floodgates are open now; politicians and other "interested parties" have watched this unfold very carefully and gleefully noted the majority didn't care as much as everyone expected, so they'll definitely be pushing for it now.
Imagine Windows Defender (an antimalware / antivirus distributed with all versions of Windows and enabled by default) starts scanning one's hard drive (and attached external drives) for image files (it already scans documents and executables and even uploads samples of malicious binaries to Microsoft for analysis): how would you / the world react?
But that's not what they want to do. They want to perform a client side fingerprint of a subset of images before they get uploaded to the cloud.
You can argue that they could in the future turn this into a scan of everything on the device. But you can also argue that if that's what they want to do in the future they'll do it in the future. It's all about trust. If you don't trust Apple to not push nefarious code on your devices, stay away from Apple, and that's true even before all this.
This is equivalent getting up set with Signal because it spell checks your text as you write it: “you are scanning what I write!!!!”
Apple holds the keys to all iCloud backups and regularly uses them in order to serve customers' data in response to data requests from the government.
Apple gives up US customer data for about 150,000 users/accounts a year[1].
If you want to upload anything on their cloud storage you need to pre-encrypt it with some other application and the upload it as a raw file.
That's incredibly charitable speculation.
So the alternative that everyone is happy with, is companies openly scan all your images as much as they want… but we are outraged at the company trying to improve the status quo on privacy… and we don’t want to talk about it. Just stop improving!
You will not have any of your images scanned at all, if you don’t load a certain number of images that’s metadata match known CSAM. That’s a superior position, than: everything you upload is scanned for visual features.
The usual reply is that since this pre-filtering happens on the device it "crossed the line" and it's evil because since the code exists in the device it's one step before midnight as it could be used to scan everything on the device.
I think this argument is not rational for a few reasons:
1.The mere absence of some code doesn't mean much in a platform that is designed to receive system software updates over the air.
2. You already have to trust Apple to do the right thing. The situation was ready pretty grim even before this. Apple may decide at any point in time to go full surveillance on any device. The fact that decide to do it or not is completely orthogonal to whether they ship this particular client side pre-uplpad CSAM fingerprinting tool. If you really don't trust Apple, stay away from their devices and fight them where it matters (e.g. to ensure that comply to interoperability so people who choose free and open devices are not locked out from the world)
3. If Apple didn't want to honestly push for e2e encryption, why on earth would they bother going through this extra hoop? If they had the master keys to all of your data they wouldn't need to run anything on your device before encrypting the data. The fact they are proposing such a system is a good indication they understand the consequences of end to end encryption: that they totally lose control on what they end up hosting on their cloud storages.
4. The time of most discussions here is that of people who already hate Apple and are just looking for a high-profile mishap to unload their guns. See point 2: there are already plenty of reasons to prefer open and free alternatives and stay away from Apple, IMO there is no need to fabricate additional outrage
Yeah, I trust them not to do stuff like this. Society is based on trust, it is normal. If you trust your friend, it doesn’t mean it is okay if they stab you, is it?
"This feature is dangerous because you cannot trust Apple to only use it for what they say they will use it, hence you cannot trust Apple since they doing something which can be abused"
Using your analogy that would be:
"A knife is dangerous because you cannot trust a criminal wielding a knife to not stab you, hence your friend by definition is a criminal since it wields a knife (she claims she's cutting bread but by definition she's no longer your friend because she broke your trust by wielding a knife which, slippery slope, could be used to stab you if she ever becomes a criminal, but we all know she will because ... the knife...)
all I'm saying is that this whole communication debacle has nothing to do with proving or disproving Apple's trustworthiness: they may be nefarious or not, independently of this feature. This feature doesn't make anything possible that wasn't possible before, and breaks the trust with the users only insofar users misunderstand what it is all about, and apparently that's what's happening.
It's a deflection because critics' objections don't necessarily hinge on the technical implementation details of the system, they object to it based on its value proposition to the user, and on principle.
Once we move past the core of those objections, then yes, some critics also object to the system's technical implementation, and some of them are correct in their analysis and some are less so.
Not sure everybody is on the same page what the value proposition to the user is. That's intimately tied on the "how the system works" which is not merely an implementation detail.
I'd like to talk about that. Most of the threads about this topic I found are full of flames without much content. Hopefully I found somebody who can help me clarify what is it that bothers so much.
I'm preparing to destroy any Apple devices in my possession (thankfully old and due for replacement) when my pine64 arrives. Don't care about any details. How's that for nuanced?
This corporation died long time ago, people just like the Idea of old Rebel Apple for creative minds and individuals.
People actually understand how this will work. A lot of educated and high level professionals reacted with vigor.
Spinning this towards "people don't understand" is blasphemy coming from serious self-delusion, no excuses given.
Resolving the issue is simple: Break Big Tech monopolies and create a climate for change. AT&T break up comes to mind. It is time to wake up. User data is the petrol of the world of tomorrow. Access to user data and implementation of solutions based on it must be regulated not towards some three letter agencies wet fantasy but towards respecting individual privacy and existing laws and democratic principles.
Even if Apple cancels this intrusion on user space, which I heavily doubt, and implements CSAM only on iCloud servers (as every one else), the image of Apple as an guardian of user privacy (false or not) is gone forever.
People are talking about alternatives and "moving off-cloud to NAS" which is actually the right thing to do in this situation.
Oh and Apple will continue to be loved. But this love will be more than biter-sweet, it will become dangerous. Some of us are old enough to know when to leave a sinking ship.
Who says they aren't using this as a fingerprint, or worse, as a way to correlate your behavior with that of a CP offender, or other types of criminal.
So this delay is preordained in the strat, right?
But Apple is only human and has had its share of monumental wtf, so this is just a huge gaffe? The spyware team didn't know about iphone 13 launch? This seems incredible.
There is some n-dimensional chess at play here. I feel like a popcorn munching audience member who is actually a pawn in another dimension.
(Corporations should never have been given "bodies" at all, IMO.)
Seeing how this situation was handled by Apple so far, my cynical take on this is that they want to wait for the storm to pass/get smaller and then will continue deployment of this tech but with better PR strategy. I hope to be wrong but the latest moves by Apple completely evaporated the remaining trust I had for them.
* they do want to help keep your children safe * they told you in detail how the system would work * they are holding off on releasing after the world gave them feedback
Who else is doing better? I get that you don’t like the system, but how do you solve it? Is it not worth solving? Too easy to nix ideas without contributing to the conversation.
They did not state that they are changing things to address the concerns. Deploy it now, or deploy it later, it's the same thing being deployed.
The full title (was cut from HN…)
> Apple Delays Rollout of Controversial Child Safety Features to Make Improvements
And the actual page with Apple’s words:
> Update as of September 3, 2021: Previously we announced plans for features intended to help protect children from predators who use communication tools to recruit and exploit them and to help limit the spread of Child Sexual Abuse Material. Based on feedback from customers, advocacy groups, researchers, and others, we have decided to take additional time over the coming months to collect input and make improvements before releasing these critically important child safety features.
They explicitly stated that they plan to make improvements. Only time will tell if those improvements are meaningful.
Well-meaning intentions are irrelevant to what's effectively happening on the bottom line.
> * they told you in detail how the system would work
This is great though. In any normal situation, this would build trust. Not so much in this case, because of the impact on privacy and potential for abuse.
> * they are holding off on releasing after the world gave them feedback
The crucial part is that they still intend to continue with their plan. They'll possibly modify it, but we'll have to see what that means. Well-intentioned backdoors are still backdoors.
> Who else is doing better?
That's completely irrelevant to the discussion. Just to humour the question: Android (AOSP), Pine (from PinePhone), Librem, CalyxOS and GrapheneOS are some products and operating systems that I could think off that respect the users' privacy better.
> I get that you don’t like the system, but how do you solve it? Is it not worth solving? Too easy to nix ideas without contributing to the conversation.
Customers don't have any responsibility to solve this. It's totally in the customers' right to complain and say "we don't want this feature". For good reasons, as shown by all the experts and privacy advocacy groups.
Wow, I love trillion dollar corporations now!
I think this is the part that far, far too many people are ignoring.
Do I, personally, think this is a good thing for Apple to add and do? Ehh....not at all sure. I do have concerns about both the precedent set by it doing the scanning on everyone's iPhones, and the potential technical issues I've seen raised about the actual functioning of the system.
But seriously, *who is doing better*??
Firstly: Is there anyone out there who has a better, more user-respectful method of scanning for CSAM? A method that doesn't essentially say "as soon as you give us any access to your photos, we will use them for any purpose we deem worthwhile to us"? Because despite all the brouhaha, that is absolutely not the attitude Apple has taken in this. They have made abundantly clear that they have no intention of ever using systems of this nature for anything other than scanning for CSAM.
And secondly: Even if Apple implemented this today, exactly the way it's been described, is there anyone who has a better track record on user privacy? Is there any device or OS manufacturer that has openly expressed and followed through on a commitment to protecting users' data?
I'm not aware of any.
Then they're either lying or delusional; creating the capability guarantees that someone will pass a law forcing them to use it in other ways.
Due to their actions, it's that simple.
On this particular issue, I don't trust them, because they've built a capability to surveil private data of millions of people, on their private devices. Basically, to default to "you're the criminal and we want to verify that you're not". They presented this capability as a "safety measure". With that, you can consider:
1. If they weren't aware of the potential consequences of the system they've built, it's just foolish and shows that their decisions/predictions can't be trusted. (I don't believe they weren't aware of the potential of the system to be abused)
2. They were aware of the potential negative consequences (massive at scale) and yet decided to use PR tactics to hide that. If that's the case, they can't be trusted due to misdirection and lying.
If you want other example, the first that comes to mind is their actions related to the butterfly keyboard fiasco. No (real) acknowledgement of the mistake, no apology but using PR to spin that into a new feature of the next model. Another is their monopolistic, rent-seeking behavior with App Store policies.
The problem with CSAM is definitely worth solving but spying on everybody's data is not the right level to look for solutions. I imagine it would make executives feel better about themselves but - as far as I understand - it doesn't meaningfully address the root of the issue.
Where do people get this idea I should trust a company? I should never trust a company. That's nonsense. It's like trusting a lawnmower to watch your hamster.
CSAM is more or less a documention of the crime. Isn't too late for keeping the children safe by that point? It should be a police matter and I don't think they are very much helped by some flawed automatic report system spamming them.
Damn I'm still confused why person like Tim who has earned everyone's respect for privacy is doing this kind of thing. It's hard to move from apple honestly at this point and it's annoying
I’ve been buying Macs exclusively for 15 years, but sadly it’s apparently time to change..
Every single executive at Apple should be figuratively “raked over the coals” by shareholders for pushing this kind of insane totalitarianism under a vague veil of “protecting children”.
Taking some time to let the news wave blow ove... errr reconsider and make improvements, i mean
I also don't like that they keep referring to this as "Child Safety" instead of what it is. Irremovable government spyware, that has no visible oversight.
This is a complex issue and there is a good reason why we don't let children consent to various things or sign legally binding contracts. Kid's are not just "little adults."
I will admit if apple did that it would be a pretty effective, but really sleazy.
It is VERY uncharacteristic of Apple to pause or walk back policy changes, so I wasn't very hopeful about this one. I'm glad they're at least re-evaluating.
Anyone reading that headline alone will think, man that's crazy. Why would Apple delay something that protects children?
However if I had to make a guess, they'll go server-side scanning only, and E2EE backups/Photos will never happen.
To me it's a pipe dream to believe they would offer E2EE, there's too much international pressure from governments around the world to keep iCloud backups open and going E2EE would trigger unpalatable retaliations.
They already do it for iMessage, and it makes it easier to turn down subpoenas if they can credibly claim that they can't even access the data themselves.
Likewise, offering an explicit choice also seems plausible. The full E2EE flow might have UX downsides (for example, the user might need to write down a recovery seed phrase on paper), so they might not force all users into that flow.
Most users opt-in to the convenience for iMessage making it, for all purposes, no longer E2EE.
I don't see them removing that precisely because of iMessage.
The real answer is the same it's always been, we need to abandon the cloud in favor of going back to self-hosting and bring back the fully distributed internet, the problem is just getting technology to the point where doing so is easy enough for non-technical users.
For reference, from 2014: https://techcrunch.com/2014/08/06/why-the-gmail-scan-that-le...
So you're right that the initial plan is indeed more privacy-friendly, but it has some major future privacy implications that are much worse.
Others providers do it and I don't expect Apple to sit and do nothing about it (governments, ngo pressure, etc.). Something worse is that the Apple brand could be labeled as a "CP enabler" which would very much hurt Apple way more than the current backslash.
They can expand client-side scanning massively or implement server-side scanning too. The latter will cause less objections, because 'Apple will not provide E2E' isn't a news item if they keep silent, while the client-side expansion will be.
If Google, Microsoft and Facebook are doing this for years then the question is why is Apple not doing it? Did they not think about the children until last month?
I can only imaging all the yelling and recrimination happening in executive meetings at Apple Spaceship. Oooff!
If it's the former, it may be best to stick with iOS 14.
Child = authoritarian Safety = control/censorship (depends on context) Features = restrictions
How much disk space will this require?
Apple's leadership must be quite confused.
There does seems to be an increasing tendency of FAANG companies to do that.
This backlash (including these NGOs) also protested the iMessage changes by equating "putting a nudity warning" with "breaking E2E encryption". I'm not a parent yet, but why prevent tech companies from adding this obvious (and desirable to many) feature?
It'll be interesting if they walk back their fears of "non-CSAM hashes being added" when that problem is still present with cloud-scanning. They didn't protest Google, Microsoft, and others using PhotoDNA, which presents identical risks. Will they now still complain about Apple if they propose cloud-scanning? They'd be hypocritical not to, since their current arguments would still apply. But then why haven't they complained when everyone else did it?
As long as Apple can’t do this client-side scanning scheme, they have to keep the keys to your data on their servers, which means law enforcement can subpoena them without you even being aware of it.
Soon enough every tinpot dictator in the world will be demanding their particular flavour of device scanning inside and outside of their jurisdiction.
(it is not a sarcastic rant, just a heads up on Apple's PR wording)
Maybe now is the time for the American part of HN to start applying the same pressure towards your politicians.
We have an election coming up and I've been quite vocal to the people on stand about how my people (the conservatives) sold us out by rubber stamping the surveillance bill last year.
I've also sent email and have sent one and will be sending one or more tweets the next few days.
Source: https://youtu.be/OQUO1DSwYN0?t=398
Side note, I like the quote:
Interviewer: Who owns this phone?
Craig Federighi: I think our customers own their phones... aaah for sure
:P
We have no alternative to being stuck with Apple. I had always thought I chose Apple. But it wasn't a choice really because there are no other viable alternatives.
I'm typing this from a new Linux machine I purchased in response to Apple's surveillance announcement. The hardware and support is terrific. But Linux falls short.
- For a casual user, Linux doesn't support bluetooth headphones, and the mic is basically impossible to get it to work. That means I can't have video calls.
- To get my mouse to work I have to clone a github from some random person.
- To install Brave I have to use the CLI and copy and paste a blob of commands I don't understand (https://brave.com/linux/).
I'm not a developer. I need to work. I just need a computer to work on and have video calls with a bluetooth mic. Not doable on Linux after spending $1500 on a new computer.
That said, open source, end to end encryption is the only path forward. Linux must be viable.
If you work on Linux, thank you. Please continue to be empathetic to users who have no idea what a CLI is and have no interest in learning and just want to work using open source systems.
If you are a regular person who wants to use Linux, be vocal about it. Donate money, file bug reports, complain and let people know what you need. Buy from companies leading the way like System76 and Purism. (I bought from System76, highly recommended)
Linux has been built and used by brilliant mechanics, but it is time for Linux to be used by all.
This is not generally correct. I've been using bluetooth headphones with my Linux desktop computer at work all day, and probably over a decade in total. Closer to two.
I don't doubt your negative experience or that it's an interesting data point, but let's not stick to factually incorrect things, either.
I’ve never been able to get AirPods to work and it took several hours and some custom code to get my Bose headphones to work. It’s not what I would consider to be even close to similar to macOS/Windows
Same, could not get Airpods to connect AT ALL. They would show up, "connect" for a second then disconnect.
- Samsung Galaxy Buds Live that came with my last smartphone
- Some fancy Jabra-brand headset we get from work
- My wife's Sennheiser Momentum Wireless when I don't bring my own
- Not headphones per-se, but in the office meeting rooms we have Logitech desk mics I connect to all the time
No config or installing additional software needed beyond pairing.
Based on my own samples the above makes me suspect "AirPods don't comply well with standards" or something along those lines.
These were Sony XM3 in particular. After installing a bunch of software through the CLI I got them to play sound.
But the mic never worked. I saw similar stories online of everyone just saying "stick with wired mics".
The very first DDG result for "airpods linux bluetooth" is this one: https://askubuntu.com/questions/922860/pairing-apple-airpods...
Re: airpods linux bluetooth -- CLI commands to get bluetooth headphones just to play sound is not viable for Linux to take off.
I'm just pointing out that Apple was doing something different. As far as that being not viable for Linux to take off... well, I respect your opinion.
Set ControllerMode = bredr or ControllerMode = dual by editing /etc/bluetooth/main.conf file using sudo nano /etc/bluetooth/main.conf command (or another text editor of your choice)
sudo /etc/init.d/bluetooth restart
Try to pair again.
Edited to clarify that while 3 pairs of headphones required fiddling to get 1 connected, the microphone was basically impossible to get working. The majority of threads I've found online have said basically not to bother with getting bluetooth headphones+mic, use a wired one or something else.
I can't imagine less computer savvy people putting up with this.
https://www.nongnu.org/synaptic/
But to install it you still need the cli. After that you get a GUI interface to search and install packages
They work as headphones, but not as a headset with microphone (for reasons that are not really Apple's fault)
Until Linux works out of the box for everyone it’s not going to see mainstream adoption.
Indeed, the number of glitches and irritating workaround I have to use to make something else than a mouse work with BT is something most people don't want to put up with their $1000 laptop.
Yes, BT is a shitty tech. But their phone works out of the box. Their Mac OS and Windows as well.
The fact we still get BT not pairing randomly (or wifi stop working, or sleep mode never awaking) is a huge problem in 2021.
We should not ignore that as a community.
That's why I report bugs, give money and help people online.
But it will not be enough if we close our eyes on the work yet to be done.
Where do you give money? I've looked into a few projects but it's pretty fragmented. Donating money to Ubuntu was a trip...required digging through forums and finally "Downloading" Ubuntu to trigger the "donate money" pop up.
Linux needs more options for people like me to pay for polish.
It's not just about the money, it's also a way for devs to feel that their work matters.
I very much agree with your sentiment, but I simply don't have any issues with BT headphones on Linux desktops specifically I could work on today.
Bluetooth is a very a complex set of standards - I work as a system architect for a well-known celestial car brand, and implementing Bluetooth and BLE is the bane of our existence; truly disastrous technology - and I'm sure things to improve are aplenty, though. In terms of desktop biz logic, the roll-out and maturation of the PipeWire stack is one ongoing effort to watch for.
What should we support instead? Is there another wireless standard?
I've noticed there are models that use some kind of non-Bluetooth USB dongle for example.
I record music on Linux, and one of the reasons that I never recommend it is that I can imagine people dropping real money on a sufficiently powerful laptop and finding things don't work without a lot of configuration, or perhaps not at all. That doesn't cut it for the average user.
Have you thought about donating to open source projects to support them along?
Linux is the only viable option. It must improve.
This will be a hard cultural shift to make for Linux culture given their starting point today.
Bluemon + pulseaudio + pavucontrol has served me well for years.
Pairing events, and switching between devices, is a dead easy with Apple gear. Non-Apple peripherals work very very smoothly, too, though when there's an Apple option I tend to pick that because of the additional ease of use.
Windows is materially worse. Linux lags Windows.
I spent 4 hours getting my Sony XM3 headphones to connect. They finally played sound. I never got the mic to work at all.
Linux is not ready for mainstream adoption. The fact that you need to mention 3 packages needed is proof.
That’s not true. I’ve been using Bluetooth on Linux since 2015, on at least 3 different machines. I hate to be a Linux trope, but you probably haven’t set it up right. Finding the right distro will be key to your Linux experience, because the good distros make these things easy. The right distro won’t require anything beyond a GUI to pair with your BT device, if that’s what you want.
it will be very hard for Linux to be used at home/corporate PC.
Apple/Microsoft started out in the home/corporate PC. Apple with Apple 1 and Microsoft's DOS. They are too entrench in the PC industry. Linux shine in server, mobile, IoT and embedded devices.
Looking back, that seems accurate. Though it was perhaps not entirely about viability but more about sheer convenience, sheer joy of shit just working, etc.
Unfortunately it seems we ended up sacrificing freedom at the altar of convenience..
For me it boils down to trading freedom for bluetooth headphones/mic that just work.
I feel like story of my move the Mac is not at all uncommon: in the very late 90s, when I was doing mostly consulting and not really any coding, my work life revolved around emails and office docs. Windows on laptops of the era was AWFUL -- long boot times, unstable/unusable device sleep, frequent crashes, etc.
I had a coworker using a G3 PowerBook, and his actual user experience was drastically better than mine by every metric (except, I guess, in that his Powerbook was significantly heavier than my super-sleek ThinkPad). Crashes were rare. Boot time was fast, but it mattered less because sleep actually worked.
I switched. Then the dot-com crash happened, and our company failed, and I hung my own shingle out -- and right about that moment, OS X happened.
My Mac went from being difficult to work on (for a LAMP-stack person) to being the IDEAL platform. I had a real bash prompt, on a machine that shipped with all the tools I wanted, and on which I could easily install most anything else (even if, early on, I had to build from source) -- and this same machine ran true Office, and had a host of really well-designed other applications and utilities that made my more productive and happier. It was a total win. And now, 20+ years later, I'm still here, typing on a Mac.
If OS X hadn't happened, then the work I had after the dot-com crash would've pushed me and a lot of other people like me to full-time Linux.
Ironically, the only gotcha moment I have ever had was when plugging my iPhone in to charge it, I kept noticing my network connection would get wonky, and I eventually realized Apple puts code injection into its USB cables that include a setting to automatically tether a device an iPhone get plugged into to use Ethernet over USB, so I was being disconnected from my WiFi access point and then being tethered through the iPhone back to the same WiFi access point, except mediated through the iPhone as a relay. Yet another user-hostile, annoying on by default Apple setting I had to discover by accident and then turn off.
I was attempting to use Sony XM3s.
Glad to hear you have some headphones that work, what model?
Running Fedora 34 on X1 Carbon. Bliss.
Linux is community driven, if somethings not working, try fix it?
> Linux has been built and used by brilliant mechanics, but it is time for Linux to be used by all.
OP is 100% correct. I also love how you basically say "well it works for me" which is a common answer I seem to hear from so many Linux users. It's like customer support responding "well, I can't recreate the issue."
It just works.
That works if you're 20 and studying at university. After wasting over half my awake day at work, the last thing I have energy left for is dealing with random bullshit and tracing down bugs.
I'm not a developer. I need a system to do my work. I need to do video calls using a bluetooth headset with a microphone.
I'm not in a position to spend time "fixing". But I am in a position to pay. But Linux seems to have few options available to pay for polish. I would pay $500 this instant to have the ease of connectivity that Apple has on this Linux machine.
In my experience, if a Chromebook can fit a user's use case, than so can desktop Linux.
Public uptake requires ease of use and consistency.
"It does too work, you're wrong. All I had to do was write some code, install a few things, and recompile the kernel and my headphones work most of the time. Have you tried writing a new driver for your headphones?"
Linux has to grow beyond being built by and for mechanics.
However, the 'average user' is going to be annoyed and lost with those commands.
FTFY: "Everyone except macOS doesn't support bluetooth well".
The Windows situation is a horrid mess - it was with w7 and at least three different commercial stacks, and my s/o can't use her brand new Sony headphones on her three year old w10 Lenovo laptop as it ends up in stuttering audio. Linux isn't better. Audio stacks are a mess (even independent of Bluetooth), BTLE is an even worse mess, and I have no idea why Android is relentlessly buggy. And the Nintendo Switch doesn't support anything except compatible controllers, you need an external, third party adapter that blocks the docking port for decent wireless capability.
The only ones who have managed something decent with Bluetooth are Apple, where everything you ordinarily need (headphones, mice, keyboards) just works (tm).
The core problem is that Bluetooth itself is an old, ugly, grown standard with lots of different stuff bolted on, not much in terms of interoperability testing and closed binary blobs everywhere.
Obligatory xkcd: https://xkcd.com/927/
I'm not sure. From an implementation POV, re-starting wUSB (https://en.wikipedia.org/wiki/Wireless_USB) again would be an easy way out - for a lot of things that can be done over Bluetooth there are USB device classes and drivers already, so all that would be required on the OS side is support for a discovery/secure pairing mechanism.
I have a 2+-year old Darter Pro, running Pop OS 20.10, which has been wonderful. Bluetooth just works (as long as there is only one user attempting to use it), the mic just works, the mouse just works. Also, System76 support is the best I've encountered since I bought my first computer in the 80s.
Yes support is terrific. What mic/headphones do you use?
I eventually got the Sony XM3s to play sound after a bunch of CLI commands and random Linux threads. But bluetooth mic never worked.
Support recommended getting a wired mic. I figured they would know, having talked to all sorts of users.
I'm running PopOS on a Surface Pro 3 and it's nearly flawless, including BT.
Does the mic in your headphones work? Let me know the model, I'll check it out for myself.
I've never had that much to do to get them to just work.
I have done some Bluetooth tinkering to:
(A) Get them to use high quality codecs, something which also requires tinkering for a Mac: https://medium.com/macoclock/how-to-enable-aptx-on-mac-osx-b... - that's with pulse. With newer, Pipewire using, systems, even that is not needed which for my use case puts Linux ahead of Mac OS for Bluetooth headphone support.
(B) my previous headphones would get super confused if I paired them on Linux and windows on my dual boot device as they'd see different keys on the same host and that broke them so copied my keys from my Linux config files to my windows registry so both would use the same keys. My newer headphones seem to "just handle" this situation though. This is a dual boot issue and not specifically a Linux issue. My Linux only devices are fine.
- Mouse. I have since 2005, never had any issues with any mouse on Linux ever. Not even for all the extra buttons on my current Logitech mouse where they just happily show up as mouse button 5-9 and I can bind them in games.
- Brave: Honestly I'm surprised Pop is not setting up a GUI package manager with proprietary software able to be installed from it with their target market, but I'll take your word for this one.
Brave: Just to clarify, it's Brave.com itself that only has CLI instructions
From https://brave.com/linux/ ---
sudo apt install apt-transport-https curl
sudo curl -fsSLo /usr/share/keyrings/brave-browser-archive-keyring.gpg https://brave-browser-apt-release.s3.brave.com/brave-browser...
echo "deb [signed-by=/usr/share/keyrings/brave-browser-archive-keyring.gpg arch=amd64] https://brave-browser-apt-release.s3.brave.com/ stable main"|sudo tee /etc/apt/sources.list.d/brave-browser-release.list
sudo apt update
sudo apt install brave-browser
Yes. I had to go into the audio settings to change between Headphones (high quality audio) and Headset (mic enabled) modes which is a bluetooth thing. But it works, and is a thing I need to do on Windows also.
(Actually on Windows I go out of my way to disable the headset device, because it just makes everything bad by being enabled - communication programs mute my everything, the audio playback becomes bad, and the microphone quality on my headphones is just worse than on my webcam, never mind my desk mic, so I never want to use it)
---
Yeah, that's a Brave thing. They probably (rightly to be fair) assume most current Linux users understand the command line enough to follow those steps and Brave would prefer users get the browser from their repos so they don't have to deal with users having potentially out of date browsers in support requests.
But you can get Brave in a snap, which to my understanding means you can get it in software center on Ubuntu, Manjaro, etc. And you can probably install the snap store on Pop also.
Chrome on the other hand just serves you a package you can double click to install, if you'd rather get it from them rather than your package manager/app store: https://www.google.com/intl/en_uk/chrome/
I think this was Apple calling the US government's bluff. I don't think they ever wanted to do anything like this because they know it destroys their claims of superior privacy. I think they have internal plans to roll out E2E iCloud encryption so that in addition to not being able to provide law enforcement the code to unlock any phone, they also won't be able to help law enforcement decrypt anything stored in iCloud, including those phone backups. So Apple sees the incoming fight where government cries foul to the public, making the same tried and true "think of the children" arguments, saying now all pedophiles will be free to save their CSAM on Apple servers. It's the government's way to try to get the public against Apple on this, and this is how Apple neuters that argument.
But I don't think anyone in the government really cares about the CSAM. What they really want is backdoor access to the devices for the high-value targets that they actually care about, or just to make their jobs a lot easier in other investigations, but that's a lot harder to sell to the public. Look at Facebook alone. They made 20 MILLION CSAM reports last year ALONE. That number was astounding to me. I haven't heard anyone discuss the sheer numbers yet. Think about that for a second. That's one company, making 55,000 CSAM reports PER DAY. The equivalent of a medium sized city being reported for CSAM materials every day! I don't know how many people work in government handling those reports, but I'd imagine the process of taking in reports, evaluating them, forwarding them to appropriate authorities, and then making arrests is not one that can possibly be automated away to deal with that kind of volume. And Apple would generate at least as many reports as Facebook I'd imagine, not to mention all the other sources of CSAM reports that are out there. Do we really think there's anyone in law enforcement who is saying "oh gee, if only we had an ADDITIONAL 55,000 CSAM reports coming in PER DAY then we'd really be able to get a handle on the problem." If anything, that just provides even more noise, making it harder to find real signals.
So now that they've shown they're willing to call law enforcement's bluff, I think law enforcement predictably has now said to them ok, it's not really about the CSAM, we still want backdoor access for other reasons, and now Apple is reevaluating their response.
The issue for Apple though is that even if they're legally allowed to say no to law enforcement requests to open up backdoors, they're probably being extorted by law enforcement threatening to come down on them for antitrust issues if they don't go along with it. Smaller companies that don't have antitrust issues to worry about would be able to put up a much more resilient fight.
Re: facebook the tiny number of court cases in the face of an astronomical number of reports is an indication that we really don't understand what is going on there or or the motivations.
However, macrumors has probably the most user-hostile gdpr modal I've encountered.
1. I used it on my android device. The modal popped up, I gave it several seconds to load in, everything seemed stable, I go to tap the settings dialog and... up jumps the modal and registers a click on the accept button.
2. Want to go fix it after the fact? Go to the footer, find the privacy link, find the link in the middle of the policy, now you get the desktop modal on the site.
3. Everything shows consent default off, so all good right? Nope. Expand out the toggles and you'll see under the "Personalised ads" a set of more granular toggles.
4. So toggle them off and you're good, right? Nope, each of them you need to tap into and get to a new screen. This new screen has two modals, one for consent, and one defaulted in for legitimate interest. One screen per sub modal, and the only way to go back to get to the others is to click "Back" in the top left, which leaves you at the root of the flow.
I have seen this particular modal on or two other sites, and finding yet another layer to bury the controls in seems to be a new "innovation" in this regard. Hopefully they're one of the sites targeted by noyb's enforcement complaints.
As you described, nothing would flag that at all.
>The planned features include scanning users' iCloud Photos libraries for Child Sexual Abuse Material (CSAM), Communication Safety to warn children and their parents when receiving or sending sexually explicit photos
This description seems to cover scanning original content. Database comparison seems to be one tool of many, and insufficient to meet the core functionality of stopping OC.
https://www.google.com/amp/s/www.nytimes.com/2021/09/03/busi...
Edit: after looking around, The CSAM hash compare is one of two tools. The other is using on-device machine learning to analyze message image attachments and determine if a photo is sexually explicit
https://www.macrumors.com/2021/08/05/apple-communication-saf...
e.g. if they made it so their software simply refused to upload a photo and inform the user why it refused to upload it, then there's no privacy issue (at least not until they do add a backdoor later on).
i.e. my iphone told me this photo was in the database, so I'll start adjusting it until it 'passes', and them I'm free to share it without detection.
Similarly, governments could take a known image they want banned (say of a national embarrassment), grab some CSAM, tweak the signature on the CSAM to match the photo they want banned, and add the tweaked photo to the CSAM DB.
The main problem is the precedent this sets: on device scanning is now possible.
Before this, if a government asked Apple to scan all the phones for something, Apple could say "we're sorry but we don't have the capability " and they could not be compelled by legal means.
Now, a large part of that argument has been eroded. Apple may have added in a few hurdles, but the first crucial step of on-device surveillance capability has been installed and is on path to being normalized.
It doesn't matter that they don't do this yet. We are undeniably closer to direct phone surveillance than we have been before.
That proposal probably wouldn't work for a lot of reasons though. The largest blocker being that (IIUC) the NCMEC won't share a DB of offending signatures without NDA, so Apple probably can't load it onto consumer devices.
One group of powerful people, better positioned to take advantage, want to analyze the personal contents of other powerful people. The more well positioned group always thinks they can be spared from their own creations, that they're in control of it. The politicians that passed the Patriot Act didn't personally fear it, they viewed themselves as the masters of it; it was to be applied to the other people.
For example, that's how you build an illegal dragnet spying operation against an inbound, democratically elected President. You do it courtesy of having the loyalty of the intelligence community top to bottom. And you avoid that illegal activity becoming a punished criminal deed by controlling at least half or more of the government. One power group targeting another power group, that's how Washington DC has always worked, and will always work (as well as most governments throughout history, it's endemic to politics/politicians).
Valuing and prioritizing privacy is not advocating for crimes against children.
All this did was make it more annoying for criminals and maybe make it easier to catch dumb criminals - who would have been caught by other means anyway.
What happens when Apple adds brainwave detection to their Airpods? Now all I have to do is have a fleeting thought about something that is deemed unacceptable by the ruling class and the authorities show up and arrest me.
So in your perfect little world where do you draw the line? Is it there or the next logical step where AI deems that based on it’s algorithm you are going to break some law tomorrow and now they are going to preemptively take action?
Privacy matters.
Worse-- this system only would detect old widely circulated images. Arguably, it may increase the incentive to create undetectable novel imagery for closed circulation, creating new instances of abuse in the process.
Police making random nighttime sweeps of homes in your community would also likely catch some serious criminals. Our decisions have to be based on more than just the potential of a narrow benefit. It's not sufficient to reduce one ill in the world if the result is a world less worth living in overall.