[1] https://appleprivacyletter.com/
[2] https://act.eff.org/action/tell-apple-don-t-scan-our-phones
[3] https://www.eff.org/deeplinks/2021/08/apples-plan-think-diff...
[1] https://appleprivacyletter.com/
[2] https://act.eff.org/action/tell-apple-don-t-scan-our-phones
[3] https://www.eff.org/deeplinks/2021/08/apples-plan-think-diff...
As of right now, is there even a database other than the one NCMEC has? I suspect they are waiting for the NCMEC to spin up its European branch.
A decade ago, all those things were on the Internet worldwide.
https://www.bbc.com/news/world-asia-china-57759480
Many of the closed WeChat accounts display messages saying that they had "violated" Internet regulations, without giving further details.
The account names have also been deleted and just read "unnamed".
"After receiving relevant complaints, all content has been blocked and the account has been suspended," the notice said.
The crackdown is the latest example of what some call growing intolerance toward the LGBT community. Last year, Shanghai Pride week, modelled on Pride events in the West, was cancelled without explanation after 11 years of it going ahead.
In 2019, the Oscar-winning Freddie Mercury biopic Bohemian Rhapsody was released in Chinese cinemas, but references to the Queen singer's sexuality and AIDS diagnosis were censored.
In 2018, Weibo said all posts related to homosexuality would be taken down, although it backtracked after massive outrage.
I have a theory about this that isn't politically correct, but here goes. This has nothing to "conservative values" or homophobia or whatever you call sexual repression in places like Arkansas and Afghanistan. It's not based on religion or culture. It's just the CCP running an actuarial table.
The CCP is a blunt force instrument. It realized some time ago that the one-child policy had left it holding the bag on taking care of a rapidly aging population without enough young people to power the economy in 10-20 years. Not only that, you couldn't easily just repeal the policy and expect a baby boom. They took a look at Japan and realized they were about to hit a demographically driven, deflationary wall. So the party planners moved from repealing the 1CPolicy to actually offering cash bonuses for second children. This volte-face happened within a few short years. But it didn't work as well as expected. Their sudden magnanimous gesture didn't bump their 5-year plan's crop of new Han for a few reasons: A shortage of women (unexpected consequence of the 1CP), more women in the workforce who don't want to have children, video game culture which makes young men stay home instead of going out and impregnating girls -- which is why they're now limiting screen time, gender fluidity / queerness which suppresses baby-generation, and of course western individualism, the great bugbear of "harmony," which encourages people to wait for love and financial stability before having children. At the end of 5 years of encouraging people to have babies, they don't have enough babies. So now they have to get harder on the edge cases.
It's probably safe to assume that gays and lesbians represent at least 10% of the Chinese population as they do in most countries. So that's what, 120 million people? Let's say half of whom are young enough to have at least one child? So we're talking about an extra 30-60 million children if you can somehow get a replacement rate.
That's what I believe all these recent moves by the CCP have been about. And banning test study programs? Same thing. No point having more babies if you're also getting overproduction of elites. They need construction workers and factory workers. And someone was told, we ain't gonna become Germany by bringing them in from Tajikistan, so take this data and figure out how to squeeze as much Han production as possible out of it in the next 5 years.
In the West we have already tried to force LGBTQ people to accept the behavior of their assigned sex. Result? Increased suicides, depression and drug use.
Obviously, after decades/centuries of failure we finally decided to recognize the reality of the facts: you cannot force people into a heteronormative life, nor to make children.
They are in for a hard failure.
This is not even remotely the same as the Taliban banning music or China cracking down on LGBTQ stuff.
> Christopher Rufo reported[2] that 30 public school districts in 15 states are teaching a book, Not My Idea, that tells readers that “whiteness” leads white people to make deals with the devil for “stolen land, stolen riches, and special favors.” White people get to “mess endlessly with the lives of your friends, neighbors, loved ones, and all fellow humans of color for the purpose of profit,” the book adds.
> There are plenty of other examples that prove racial essentialism and collective guilt are being taught to young students. In Cupertino, California, an elementary school required[3] third graders to rank themselves according to the “power and privilege” associated with their ethnicities. Schools in Buffalo, New York, taught students[4] that “all white people” perpetuate “systemic racism” and had kindergarteners watch a video of dead black children, warning them about “racist police and state-sanctioned violence.” And in Arizona, the state’s education department sent out[5] an “equity toolkit” to schools that claimed infants as young as 3 months old can start to show signs of racism and “remain strongly biased in favor of whiteness” by age 5.
[1] https://www.washingtonexaminer.com/opinion/yes-critical-race...
[2] https://twitter.com/realchrisrufo/status/1413292881264005126
[3] https://www.city-journal.org/identity-politics-in-cupertino-...
[4] https://www.city-journal.org/buffalo-public-schools-critical...
[5] https://www.washingtonexaminer.com/news/arizona-education-ba...
From here[1]:
> Christopher Rufo, a prominent opponent of critical race theory, in March acknowledged intentionally using the term to describe a range of race-related topics and conjure a negative association.
> “We have successfully frozen their brand — ‘critical race theory’ — into the public conversation and are steadily driving up negative perceptions,” wrote Rufo, a senior fellow at the Manhattan Institute, a conservative think tank. “We will eventually turn it toxic, as we put all of the various cultural insanities under that brand category. The goal is to have the public read something crazy in the newspaper and immediately think ‘critical race theory.’”
[1] https://www.washingtonpost.com/education/2021/05/29/critical...
When it comes to teaching children Not My Idea, definitely seems to be more to the concern than just shadows:
The fallacy of ‘whiteness’ https://www.bostonglobe.com/2021/08/08/opinion/fallacy-white...
> According to recent reports, public and private elementary schools across the United States have used, as part of racial equity education, an illustrated children’s book called “Not My Idea,” in which a devil with a pointy tail offers the young reader a “contract binding you to whiteness.” The contract promises “stolen land,” “stolen riches,” and “special favors”; in exchange, whiteness gets “your soul” and power over “the lives of your friends, neighbors, loved ones, and all fellow humans of COLOR.”
I looked at some of the illustrations of "Not My Idea"... it's a bit wired and cringe worthy sometimes. Still compare that to the indoctrination that is in some of the schoolbooks:
Slavery was just "black immigration" https://www.theguardian.com/education/2021/aug/12/right-wing...
The kkk was not morally wrong ... ?? https://www.nbcnews.com/politics/politics-news/texas-senate-...
Banning of Black and Latino Authors https://www.mcall.com/news/pennsylvania/mc-nws-pa-banned-boo...
Teaching creationism: https://www.arkansasonline.com/news/2021/apr/08/house-advanc...
Are you as outraged about that as you are about a fringe law theory?
Can you name numbers comparing how many books with problematic woke content are used versus the books mentioned from the guardian?
These stories are lenses through which you can describe the world. They’re like software for the mind. And like software, they aren’t objectively right or objectively wrong. Each of these stories (dubiously) explain and obsesses over some aspects of the world, and ignores other aspects completely.
No, its not.
Though there is a mythic anti-”Critical Race Theory” story created by the American Right, and the thing within it called “Critical Race Theory” is a (particularly incoherent, because a number of unrelated and opposing things from the real world that share only that they concern race, and they are disliked by the American Right, and they are not actually Critical Race Theory, are jammed into it) mythic story.
> These stories are lenses through which you can describe the world. They’re like software for the mind. And like software, they aren’t objectively right or objectively wrong.
Actual critical race theory (like critical legal studies, from which it stems) holds the existence of objective features of social structures, with tangible, material, effects.
Like many hypothesized social phenomenon, the complexity of the systems involved may make falsification difficult on a practical level, but the claims it makes are fact claims which are objectively true or false.
I'm also always surprised how little US citizens know about their own history. Ask somebody about "Birth of a Nation" and see what they can tell you about it.
Ask them if they know about the "Pro American Rally" in 1939 and see what they say.
These things are not taught in school and it's a shame. I know what I'm talking about I'm German and I hated our history education in school as we were discussing the 3rd Reich nearly every year. Yet, reflecting on it and seeing that the same stupid ideas get a hold today again, it was not nearly enough. We should have taught more. The same holds for the German colonial history (that was not covered and is changing slowly).
If you don't know your past, you are condemned to repeat it.
https://www.washingtonpost.com/local/education/150-years-lat...
https://www.theguardian.com/education/2021/aug/12/right-wing...
Not quite. Rufo knows what CRT is, and importantly, what shares the same problems CRT does. That is to say, different branches of the same general ideology that operate on different topics. The CRT model is kinda like ideological lego, you can just plug in a topic). The demon is legion and has many names. Rufo's stuff is mostly about calling woke thought in general CRT, since the name stuck. I haven't yet seen Rufo label things that aren't wokeness or influenced by wokeness CRT.
It's the same kind of thing as when we call Catholicism, Eastern Orthodoxy and all the Protestant sects "Christianity" even though they are not the same, or how we still call Zen "Buddhism" even though it lacks the supernatural component of its older cousins. None of those things is the same, but they share a family resemblance, they have a character to them that makes them unique among the sea of ideologies, religions and philosophies. Rufo's nailing "CRT" to that family resemblance, because the family is there, the demon is real, and it needs a name to be talked about usefully, not a legion of them.
30 school districts (out of how many?) use a book Rufo doesn't like.
Any reason why anyone, aside from Rufo, should care?
Half of the nation doesn't teach sex ed because skyperson doesn't like when people bang without signing an exclusive banging agreement in public first. Half the nation teaches kids that the Confederacy was formed to protect "states' rights", carefully omitting that the right in question was to own black people as livestock[1]. But hey, 30 districts use a white-people-bad, and that's the real problem.
And what does the last part of your comment (about AZ) have to do with anything? Telling educators that 5-year-olds can absorb shitty beliefs is now a cOnTrOvErSiAl tHeOrY?
I don't even know where to start here, let's set this one aside.
So, let's focus on this question first: assuming the book you mentioned is bad, which percentage of pubic schools use it, and in which way?
[1] TX is my go-to example. They were teaching that slavery was a "side issue" in the Civil War when I was living there in 2010-2017.
I'm not even going to bother dissecting the bullshit they peddle these days. Feel free to dig in.
Texas oversees 1,247 school districts. Tell me more about the problem of CRT in schools though.
https://www.smithsonianmag.com/smart-news/texas-will-finally...
> this is happening and it's good
Rufo is trying to create the world's biggest molehill.
[1] https://ballotpedia.org/Public_school_district_(United_State...
Indeed, the NCMEC database does not have an especially good reputation, much like MCMEC themselves.
ICMEC is a fork of NCMEC.
So...
a) a bad actor is going to target someone, and have the resources to generate enough collisions that(b) look like CP, but aren't CP? but are close enough (c) to pass human review and cause an investigation so (d) they need the hash collisions to look like CP, but not be real CP? or ????
If a bad actor wants to frame someone, it's easy to do this today - hack their system or home network, open it to the internet, place the photos, call the FBI and report an anonymous tip, with the URL where it is hosted and open to the internet. Don't need hash collisions.
Hacking someone's iPhone (How do you get the photos on there without forensic logs that they were added?) or iCloud so that you can place hash collisions that look like crap and fail to pass the review doesn't make sense and leaves too much of a trail. Oh? And someone won't notice thousands of photos just added to their phone?
A bigger threat would be deepfake CP. When that becomes a reality, it will be a mess, because an attacker could theoretically generate an unlimited amount of it, and it will be extremely difficult to tell if it is authentic. Those hashes wouldn't be in the CSAM database, but if the attacker put them out on a server to be taken down, they would get added eventually and then show up in a scan elsewhere.
But I'd be pretty horrified (and definitely call my attorney, Apple, and local FBI field office) if thousands of CSAM images just showed up in my iPhone photo stream.
Edit: Downvotes are fine, and I completely understand other arguments against this, but this one has just not made sense to me...
Edit: Downvotes because?...
For example when CIA/NSA tools leaked, one of them had precisely this purpose.
Conversely, the governments of the world get to keep trying, over and over.
It's significantly harder to develop collisions for an algorithm you cannot inspect or obtain the output of.
(well also, emailing actual CSAM is way easier and mostly just gets the sender reported)
You're exposing the hashes to the world, you're not able to E2E encrypt anything if you need to server side scan, which you probably do since trusting the client no matter what is generally bad in potentially adverserial situations, and you get all this negative press and loss of reputation and potentially pressure from governments around the world to use this for other ends. Cui Bono?
The second scan applies only for those images which are flagged as positive, which are then accessible by Apple. This is applied to detect adversarial hashes. The rest of the images stays encrypted. So, indeed on-device scanning is the only way to enable at least partial E2EE with CSAM detection.
Yes, this was PR failure Apple. They rushed the announcement because of the leaks, and secondly they thought that people will understant the system when they did not. There is too much misundersting. That scanning for example is built-in so deep into the iCloud pipeline, that one does not simply change the policy for scanning the whole phone.
On a technical level I think you're correct. As a holistic approach to the problem, I still disagree. This is too cute for its own good. The PR misunderstanding is a symptom of that.
>The second scan applies only for those images which are flagged as positive, which are then accessible by Apple.
In the end, Apples software is scanning all of the images, why is it any more privacy respecting to do it this way? I guess reasonable people can disagree on that, personally I wasn't fully aware of the cloud side scanning either, and I don't think the public was either. This is similar to Snowden's revelations, if you were paying attention you probably already knew a lot of that, but the incident made everyone aware of it in a very blunt way.
>The rest of the images stays encrypted
I think this is unclear, Apple can still decrypt those other images, how else could you view them in a browser?
This goes back to what Stratechery said about capability vs policy.
Obviously there is change coming to iCloud. Otherwise whole PSI protocol is pointless.
Tangentially, I think keeping their servers clear of illegal material is actually Apple's main motivation. This, in turn, supports claims made by nay-sayers that Apple could scan for other types of images/content in more repressive countries (but not necessarily report the people who did it). However, this assumption also contradicts arguments that Apple will start scanning for pictures of (e.g.) drugs, or weapons. Such images are not inherently illegal and therefore of no interest to Apple.
My guess about this whole debacle is that - with pressure from the government to scan their cloud storage - that this is the alternate scenario to avoid giving up (or being forced to) the "encryption" guarantees of their cloud. I'm not sure what technical process they have in place to "only decrypt with valid law enforcement requests" or allow account rescue, but it seems likely that not just any employee can view whatever they want, before or after this system.
Saying that I can maybe see a way the pressures are on this doesn't mean that I'm saying this is a good solution though. Clearly technically implementing this is opening a can of worms that can't really be closed again and makes a lot of other scenarios "closer".
Also, evidently, people are a lot more comfortable with the idea of them actively scanning stuff people store in the cloud than transmitting the information in a side channel so they don't even need to handle decrypted data without a hit.
This is exactly the case. https://www.eff.org/deeplinks/2019/12/senate-judiciary-commi...
> I'm not sure what technical process they have in place to "only decrypt with valid law enforcement requests" or allow account rescue, but it seems likely that not just any employee can view whatever they want, before or after this system.
They have master keys that can be used to decrypt almost everything you upload. They can be compelled to decrypt and turn over information on anyone. Another (unsourced) comment in this thread indicated they do so 30,000 times per year. The new encryption scheme will effectively stop this for photos, and no doubt other files in the future.
Apple's side will begin using shared key encryption, which will require ALL ~31 keys to decrypt the offending images.
The decryption keys are only generated on-device, and only from a hash that results from a CSAM match. The other photos, simply won't have the decryption keys generated, so they don't even exist.
As an interesting side note, this means that a person who surpasses the CSAM threshold will still only reveal the images that actually match the CSAM database. Every other image, including those that have CSAM unknown to authorities remain encrypted. This is hardly a big win for the big scary government. They now have far less ability to search for evidence of any other crimes. You could upload video of your bank robbery to iCloud, and as long as your personal device remains secure, nobody will know.
Even if that was a goal (and I would argue they have a hard stance against it), this system as built is not usable for that.
While they can scan locally, every step of recording, thresholds, and subsequent automated/manual auditing is built to require content to be uploaded to iCloud Photos.
Even assuming that is true that iCloud is trivially “hackable” - and as I understand it, that was never clear how those leaks happened - how does uploading to iCloud help when it specifically needs to be uploaded from the users phone along with the scanning metadata.
In fact, isn’t apples proposed implementation here the _only_ cloud service that protects against your proposed attack - while other clouds scan stored data and can be triggered by your attack, Apple’s requires you to upload specifically from a registered phone on their account; data stored on-cloud is never scanned.
The response to this is “yeah but then a human will review it and nothing will happen to the victim of the attack, because it’s just some slightly blurry ordinary images”. But it ignores to entirely likely harms that could result from that.
1) Law enforcement use it as the basis of getting a search warrant, but conveniently leave the bit about the alerts being false alarms off the warrant application.
2) The list of people who have had CSAM alerts is inevitably leaked to the public, and the victim has to spend the rest of their lives explaining to people like employers why Apple flagged them as possessing child sexual abuse material.
At the end of the day, all the gaslighting about “no potential for inadvertent harm” is bs, because it’s my device, so get lost. Go run your anti-privacy software somewhere else, imo.
- Law enforcement doesn't get _anything_ unless it triggers a large number of images that match the perceptual hash
- It also needs to match a -private- perceptual hash, that isn't distributed to devices, and so we don't have a reliable way of generating collisions for or even knowing that collisions are generated
I mean this whole thing is bad enough on its own without having to artificially manufacture extremely specific scenarios and extrapolating from there to invent hysteric conclusions.
But you’re right though, the possibility of the list being leaked and ruining countless innocent lives is the much more likely of the two scenarios I described.
In that case, nothing is stopping them from scanning everything already uploaded anyway, and nothing is stopping them pushing code to your device to scan it without telling you about it. Nothing is stopping them or the government from making these "lists" anyway.
I'm not saying you (or anyone) should trust Apple, but if you already don't - then this changes literally nothing.
Feel free to respond to my point about the alert catalog inevitably being leaked and ruining lives. Or you could just have a go at gaslighting me a little more if you prefer.
- Send colliding images
- image gets uploaded to icloud automatically
- image _also_ collides with private hash <- completely unclear how this happens
- Only the colliding images are looked at by apple and are determined to be innocent
- user goes on a list (This is an imagined scenario)
- User is reported to law enforcement even though the images are innocent (This is an imagined scenario)
- Law enforcement uses this hypothetical report to file a warrant (This is an imagined scenario)
- Law enforcement uses the hypothetical warrant to extract images that are completely innocent, and somehow build a case around this
- The "List", which is entirely a hypothetical of yours, "leaks" (This is an imagined scenario)
Which also requires:
- Apple does not counter the meaning of "the list"
- Apple is not sued for vast quantities of money
I expect the first argument is that none of this matters as long as "the idea" is out there, the reputational damage is already done. Except if that's true, then none of this is necessary at all, just make the accusation.
So, sure, continue to thread the needle between "They are automatically sending all information to the government, so promises are meaningless" and "This new process, on top of them potentially sending all information to the government, somehow makes it worse".
I mean, this is all a million times more difficult and less likely than just, like, sending them CP in the first place. Or uploading it to their Gmail or any other cloud they use. Or just send a report that they have it to the police without actually doing anything.
All it requires is somebody to send somebody else a colliding image.
This will send an event to Apple. There is nothing imaginary about that, it is exactly how the system works.
Now that Apple has this information, the only thing left is for it to be leaked or compromised in some way.
This is much simpler than the scenario you’ve described, because they require the attacker to first commit the crime of possessing CP. Its also possible to do without tipping off the victim in any way.
Apple, in case you didn’t know, is a company that had already been the source of a couple of the most notorious data breaches ever (and has somehow managed to so far avoid getting “sued for vast quantities of money” for them).
What you’re trying to do here is quintessential gaslighting.
And again, there is the whole fact that you received the email and there is a log that you received it.
Additionally, the images sent to review are significantly downscaled versions of the original & could easily be made to be ambiguous.
The most difficult challenge in this SWAT story is that Apple has a secret secondary hash that's checked on a collision. That's the part of the SWATting story that feels difficult on a technical level. However, there are also really smart people out there so it wouldn't surprise me if a successful attack strategy is developed at some point given time.
No one is going to be prosecuted on "significantly downscaled ... ambiguous" versions of original fake images with a hash collision that flagged a review and was handed to the FBI accidentally because a "minimum wage" fatigued person passed it on.
I get the counter-arguments, but the hash collision thing is just, sort of... weird? I even get the argument that an innocent hash collision may have your personal and private images reviewed by some other human - and that's weird. But I can't really see it going further (you'll be arrested and sentenced to life in prison from the HASH COLLISIONS!).
It's just using technical terms to scare people who don't understand hashes and collisions and probability, and not really founded on reason.
Which typically will be a court case, or at least questioning by police. This can be quite a destructive event on someone's life. Also, there's no mechanism for whitelisting outlined in the paper, nor can I imagine a mechanism that would work (i.e. now you've got a way to distribute CP by abusing the whitelisting fingerprint mechanism or you only match exact cryptographic hashes which is an expensive CPU operation & doesn't scale as every whitelisted image would have to be in there).
Also, your entire premise is predicated on careful and fair review by authorities. At scale, I've not seen this actually play out. Instead either the police will be underworked & not investigate legitimate cases (too many false positives) or they'll aggressively police all cases to avoid missing any.
Even if uploaded to iCloud (such as pictures sent via WhatsApp by default), and above the threshold, they would still be scanned by a second algorithm and subject to human review. So, your "very simple" attack fails on at least three counts.
(I think) the complaint is: how is that different from just using CSAM images, no collision required?
And, to at least respond to two obvious counter-arguments I've looked into:
"But it's just one line of code to change it to scan images (that aren't uploaded to iCloud) (that are anywhere on the device)!" No, it isn't; if you read the technical documentation and the more technically-oriented interviews Apple's given on this, there isn't just one hash that needs to be matches, there are two hashes, one on the device and one on the server. (I think Apple did a very poor job of communicating this to a general audience; it certainly wouldn't have alleviated all the concerns, but if it was understand as "client-server scanning" rather than "client-only scanning" it might have at least changed the tenor of the conversation.) That doesn't mean they can't do a combination client-server scan on every single image or even file on the device, but it makes it both more difficult to do and more difficult to hide.
"But what if the system doesn't work as Apple's described it?" Well, if you don't trust Apple to some degree, all bets are off. They already do ML-based image analysis of all photos in your photo library regardless of iCloud status and they've literally demoed this on stage during iPhone keynotes, so if Apple was going to secretly give government access to on-device scanning, a different technology -- one that works (questionably well) on all images, not just already-learned ones -- is literally already there. The only way you "know" what Apple is doing with your data on or off device comes from a combination of what they tell you and what third-party security researchers discover.
If they get caught doing secretly this in China that would be a big blow. But if they are doing openly and it is known that the government provides the hash, they can wash their hands.
I think there _is_ an argument to be made about a system like this being used to track the spread of political material, and it's easy to see how such a system would be terrible for anyone trying to hide from an authoritarian power of some type, but that'd already require Apple is absolutely and completely compromised by an authoritarian regime, which isn't high on my list of concerns.
As recently posted on HN [1] one should be very wary of backdoors, no matter how much one believes only the right guys could ever use them. Once they're there, they're there: it's arrogant beyond believe to think that opponents of yours won't exploit them.
I won't use an apple product with this feature. I've been using apple's ecosystem since about 1994.
[1] https://twitter.com/matthew_d_green/status/14334701097425182... and https://news.ycombinator.com/item?id=28404219
I don't understand this, they can just be legally compelled.
But a motivated bad actor has a lot easier time just putting an image of the Taiwanese flag or propaganda on someone's phone than trying to make it a hash collision that triggers... If an attacker is really after someone, I would expect them to put the actual material on that person's phone...
... It's like trying to frame someone for drugs in their car and going through the hassle of synthesizing a chemical that triggers drug dogs to react, but it isn't actually the drug. Wouldn't they just... buy drugs and stick them in the car?
Maybe they want to create too many false positives deliberately, or maybe they do it just because they want to see if and how synthesizing such a chemical can be done.
When putting pictures on someone's phone or computer, there are ways to add false positives as well as maybe doing false negatives sometimes (e.g. by encrypting the picture or using an uncommon file format so that it must be converted, or using complicated HTML/JS/CSS to render it instead of just a picture file).
Also, if someone has the picture or drug or whatever to find if it is what they are, can you accuse them (maybe they are the police) of liking pictures and drugs, too?
But, to be clear, you make a legitimate point.
How so? Unlike other cloud providers, which do scan all uploaded images server side, this system is specifically designed to prevent this.
(As you say, if Apple is entirely compromised, then all bets are off anyway.)
So Apple called them out on it by letting the market decide. They now have that evidence.