http://www.libertyclick.org/propaganda-for-government-contro...
http://www.libertyclick.org/propaganda-for-government-contro...
But that's precisely what Apple's CSAM implementation doesn't do. It compares on-device image hashes with hashes of known CP images. It affords more privacy than other methods, which Apple is probably using anyway and which other cloud services are definitely using.
https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
This is a strong claim with zero evidence. The social costs of defending an accused perpetrator of this nature are insanely high.
While we're making unsubstantiated claims, I assert that intelligence agencies routinely exploit this. My only substantiation is that it's obvious and I would if I worked for them.
Also, there's the fun "you can't sue us because you have no standing/can't show harm, and showing harm to prove you have standing would be illegal".
Yes, here you go: https://en.wikipedia.org/wiki/Burden_of_proof_(philosophy)
No charges were ever filed, and the media outlets didn't bother to update their articles.
I think false accusations happen, especially to controversial figures, and assume most victims just don't want to call much attention to it.
Also, are you sure there were no charges filed? Some cursory googling turns up articles including a PDF of the indictment [1] and more-recent articles seem to refer to an ongoing process [2].
[1]: https://manchesterinklink.com/fbi-descends-on-keene-and-surr...
[2]: https://nymag.com/intelligencer/2021/08/bitcoin-ian-freeman-...
What matters is that the person is arrested, that their name is leaked to the mainstream news media, and that they're dragged through the mud - the same as seems to happen in literally every other child porn case.
The actual guilt or innocence doesn't matter at that point. Their lives have been sufficiently ruined, and, if they are actually innocent, the message has been clearly sent.
In any case, the police will not arrest anyone because they have only been flagged by the automatic system. As soon as Apple reviews the images that triggered the flagging, they will see that they aren't actually child porn, and hence they won't even contact the police.
https://nymag.com/intelligencer/amp/2021/08/bitcoin-ian-free...
No, it compares against hashes supplied by a government agency (NCMEC). Apple has no way to verify the hashes are in fact CP, as it is only re-hashing hashes.
Presumably at this stage is where malicious hashes would be detected and removed from the database.
An unaccountable "Apple Employee" who is likely (in the US and other countries) to be a LEO themselves will see a "visual derivative" aka a 50x50px greyscale copy of your content.
There is no mechanism to prevent said "employee" from hitting report 100% of the time, and no recourse if they falsely accuse you. The system is RIPE for abuse.
>Presumably at this stage is where malicious hashes would be detected and removed from the database.
Collision attacks have already been demonstrated. I could produce a large amount of false positives by modifying legal adult porn to collide with neural hashes. Anyone could spread these images on adult sites. Apple "employees" that "review" the "image derivatives" will then, even when acting honestly, forward you to prosecution.
Of course there is. The judicial system.
(Although, to be clear. I don't live in America and I might be more worried about this if I did.)
The recourse should be before this reaches the law.
1) Spent who knows how long in jail
2) Lost your job
3) Defaulted on your mortgage
4) Been divorced
5) Had you reputation ruined
Money can't fix everything, and trusting the courts to make you whole years after the fact is a foolish strategy.
How, if 1) the original content is never provided to Apple, and 2) the offending content on consumer devices is never uploaded to Apple?
This entire system was a way for Apple to avoid decrypting your photos on their servers and scanning them there.
Hypothetically, if Apple implemented this system and switched to E2E for the photo storage, you'd be more private overall because Apple would be incapable of seeing anything about your photos until you tripped these hash matches, as opposed to the status quo where they can look at any of your photos whenever they feel like it. (And the hash matches only include a "visual derivative" which we assume means a low res thumbnail.) I say hypothetically because Apple never said this was their plan.
You can argue about whether or not Apple should be doing this. But it does seem to be fairly standard in the cloud file storage industry.
I suspect the key would be that there'd be a team verifying that something is actually child pornography, because the system is a perceptual hash rather than a strict comparing-bytes so before someone looks at it they're not certain.
As a taxpayer and customer, I concur. I'm glad someone is doing that job. But I don't want it to be a corporation.
A "third party" paid by apple who is totally-not-a-cop who sees a 50x50pz grayscale "image derivative" is in charge of hitting "is CP" or "Is not CP".
I don't understand how anyone can have faith in such a design.
So, to get flagged, you need many hash collisions destined for iCloud. Then, to get reported, some number must get a false positives in the Apple review, and then some number must somehow fail the full review by NCMEC.
https://www.theverge.com/2017/4/12/15271874/ai-adversarial-i...
If we can, then, hypothetically we need to get non-CSA images onto important people's iPhones so they get arrested, jailed for years and have their lives ruined by Apple.
Disclaimer: I buy Apple products.
These images can be 100% indistinguishable from the real thing. Without knowing the source of the images that they are putting in the database, how do they know the images are actually illegal?