122 karma · joined March 7, 2021
>The decrypted vouchers allow Apple servers to access a visual derivative – such as a low-resolution version – of each matching image.
https://www.apple.com/child-safety/pdf/Security_Threat_Model...
To me it's pretty clear they are doing the absolute minimum possible to keep congress from regulating them into a corner, where they lose decision making control around their own privacy standards. The system they came up with is their answer for doing it in the most privacy conscious way (e.g. not decrypting user data in icloud) while balancing a lot of other threat model details, like what if CSAM-hash-providing organizations provide img hashes for a burning American flag, and lots of other scenarios outlined in the white paper.
But I'm unsure that the thumbnail is included with every CSAM "voucher" -- it's likely only included when you pass the 30 image limit. Need to read that section more clearly.
In summary, I’m guessing they tried to invent a way where their server software never has to decrypt and analyze original photos, so they stay encrypted at rest.
Btw a lot of words in English have multiple meanings, and transform meaning over time, which can be confusing sometimes. For example, in baseball you steal a base, which was being protected by the other team, but you don’t remove the base from the field and run off with it.
I think steal works better than copy here, more accurately conveying meaning and intention, and unjust access.
Digging deeper into types of ingredients that block sun, things get a bit more tricky. In general I’ve read dermatologists say “physical” sun screen ingredients are best, like zinc oxide, because they aren’t absorbed through your skin like a “chemical” ingredient. But they also leave your skin looking more white.
And beyond that, just wash your face in the morning and night with a face wash product, not bar soap. Something simple from Neutrogena (Liquid Neutrogena).
I agree there is nothing fundamentally less secure in general, but what you don’t get is being able to standardize around security for dev account protection, policies around immutability, DNS stuff, and some other centralized security measures. Neither are bullet proof, but there are some things you can’t protect against with random URLs.
I’d argue URLs are fine until you get massive use of a single package and it weaves itself into a complex dependency tree across multiple other critical projects. Then you worry about the what if’s.
Because it can accept any URL as a dep in the source files, you can in theory do some cuter, weirder things with it. But security wise I’d argue arbitrary URLs, for critical, high traffic deps, are harder to fix when bad things happen, without centralized control.
Wow, and it passed peer review.
I don’t see how the article you linked to explains how Apple can “scan iCloud” for the police. What do you mean? It seems like they just hand data over for a specific warrant related to individual users.
I think you just described flow programming. There are at least 10+ visual languages / environments that work like this.
Speculation: visual programming is a bit more beginner friendly, and more compatible with the brains of people designing stuff in UE. I wish blueprint was around when I was 13, messing around in UT’s version of UE and having no idea what unreal script could do. Visual language can break out all possible components into UI menus, just like everything else in UE. Visual oriented people really click with tools like visual programming.
Personally I think it’s cynical / arbitrary to pin the decision to corporate power struggles. Sometimes people propose new things out of interest or as a side project and then it grows from there.
Benefits to me are clear: giving a developer choice over how their source code is used with for-profit, opaque, next generation ML models.
But yes, drop in the ocean in terms of the full data set. But that shouldn’t be an excuse to remove user choice.
- how to fix my xaomi m365 battery
- Japanese
- basics of koi ponds, for a gift to my mother in law
- cooking with a instant pot
- ayurveda
How long does it take to scan a room? And when scanning something like an apartment with multiple scans, how do you piece them together / automatically offset the points collected in the next scan?
Early in vaccination, I believe sites were reserving 2nd doses for everyone who got the first. Then production became predictable enough where cdc instructed sites to not reserve in favor of increasing vaccine rates. Then sites always prioritized people returning for 2nd doses (internally, or through scheduling systems)
Same. I’m not upset, just wanted to walk through what goes through my head personally.
> And in public policy, the long game is always the important one
This is a key point. The policy did its job. Old and weakened people got their shots, line skippers are a blip on the radar. But maybe it worked because most people played their role and held back tiny personal infractions for the greater good.
> I mean, if politicians and VCs and the elite all want it ASAP, maybe it’s safe for almost everyone?
I think that is very theoretical psychoanalysis, but if it’s what people tell themselves to get that early jab, sure. In the end, this is an unprecedented global crisis and people are either going to fall in line or act in ways that help them cope with uncertainty and anxiety.
Even if I’m iffy on the morality now, I don’t want to look back 20 years later as a different person, thinking about how, as a healthy young person, I cut in front of the eligible.
Would that person who was turned away because of me get a shot the next day, or the next? Probably. It’s just principles for me, like a personal code. The morality is debatable, everyone is different.
There’s something nice too about working cooperatively with an entire country at a unique time in history, and helping the less fortunate by simply following the rules as best you can as a non-essential individual.
My 2 cents